Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Phishing scams still work because a convincing message can borrow a familiar name, create urgency, and steer someone toward a fake website, harmful attachment, or fraudulent payment before they verify it. The best defense is layered: pause, avoid the message’s links and attachments, check the request through a contact method you already trust, and protect important accounts with multifactor authentication (MFA).

Why do phishing scams still work?

Phishing is an attempt to impersonate a person or organization to get someone to reveal information, transfer money, visit a fake site, or open a harmful attachment. It can arrive by email, text, voice call, or another channel. The tactic works by making a request feel familiar and time-sensitive, so a recipient acts before checking whether it is genuine.

A familiar name or logo is not proof

Scammers may pose as a company you use, a vendor, a manager, or another trusted contact. The FBI explains that spoofing can disguise an email address, sender name, phone number, or website address; a fake address may differ from a real one by only a character. A polished logo or website is not enough to establish authenticity. The FBI’s spoofing and phishing guidance describes these tactics.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Urgency discourages independent checks

A message might claim that an invoice is overdue, an account needs attention, a password must be reset, or payment details have changed. In workplaces, a request that appears to come from a boss or vendor may push for a quick transfer or credential disclosure. Treat unexpected urgency as a reason to slow down, not as proof that the request is real.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The same trick appears in calls and texts

The FBI calls phishing by voice or VoIP “vishing” and phishing by SMS “smishing.” Apply the same caution to an unexpected call or text as to an email: do not rely on the number or link in the message to verify the sender.

How can you recognize and prevent a phishing attempt?

Do not try to decide based on appearance alone. If a request is unexpected, avoid interacting with it and verify through a route you already know is legitimate.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Pause before acting. Be especially cautious about unexpected requests involving payments, account access, password resets, or sensitive information.
  2. Do not use the message’s links or attachments. The FTC advises, “Don’t click links or download attachments in unexpected messages.” The FBI’s advice is, “Don’t click on anything in an unsolicited email or text message.” Read the FTC’s consumer guidance on protecting yourself from phishing scams and the FBI guidance.
  3. Verify independently. Type the organization’s known web address yourself, or call a trusted number from a card, statement, or saved contact. Do not use contact details supplied in the suspicious message.
  4. Confirm unusual workplace requests another way. For a payment change or sensitive request, contact the supposed requester through a separate, established channel before proceeding.
  5. Use MFA on important accounts. Start with email and financial accounts, then protect other services that matter. MFA adds a sign-in check beyond a password. CISA says any MFA is better than none, while recommending stronger phishing-resistant methods where available. Its MFA guidance for small and medium businesses discusses options including number matching as an interim measure when phishing-resistant authentication is not available.
  6. Prefer phishing-resistant sign-in when supported. CISA says, “The only widely available phishing-resistant authentication is FIDO/WebAuthn authentication.” This method can block an attempt to authenticate through a fake website. A compatible hardware security key is one way to use the standard, but check that the account, browser, device, and key work together. A security key does not prevent every kind of phishing or replace verifying unexpected requests. See CISA’s More than a Password guidance.
  7. Keep spam filtering active and mark messages that get through. The FTC says popular email providers have spam filters enabled by default. Mark suspicious messages as spam or junk so the filter can handle them.

What should organizations do to reduce email spoofing?

Organizations can configure SPF, DKIM, and DMARC to help receiving mail systems assess whether messages claiming to come from their domain are authorized. These domain protections address a different part of the problem from user verification and MFA: they help receivers evaluate mail associated with the organization’s domain, but they do not establish that every message a person receives is safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configuration requires care and expertise. A misconfiguration can interfere with legitimate mail, so organizations should implement and test these controls with appropriate technical support. The FTC explains these protections in its Cybersecurity for Small Business guidance.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What should you do if you received or acted on a phishing message?

If you only received it

Do not reply, click links, open attachments, or provide information. Mark the message as spam or junk. If you need to check whether the underlying request is real, contact the organization using a known website or phone number rather than the details in the message.

If you entered a password or other account information

Go directly to the genuine service’s website or app and use its account-recovery process. Change the affected password, and change it on any other account where you reused it. If the service offers MFA, enable it. If you disclosed financial information or authorized a transfer, contact the relevant financial institution using its established contact details and explain what happened.

Rank #4
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Report the attempt

  • In the United States, report suspected fraud to the FTC at ReportFraud.ftc.gov. The FTC also accepts forwarded phishing emails at reportphishing@apwg.org.
  • Report spoofing and phishing to the FBI’s Internet Crime Complaint Center at IC3.gov.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What phishing statistics can—and cannot—tell you

Official complaint counts and loss totals show that scams are a significant problem, but they do not tell you the probability that a particular message is malicious or that any one phishing attempt will succeed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The FTC reported that consumers lost $3.5 billion to imposter scams in 2025, and that nearly one in three fraud reports that year concerned imposter scams. Those scams used multiple channels, including text, phone, email, social media, and search results. This is a broad imposter-scam figure, not a phishing-only loss estimate. See the FTC’s 2026 release on 2025 imposter-scam losses.
  • Phishing and spoofing were among the three most frequently reported cybercrime categories in the FBI’s 2024 Internet Crime Report. The FBI said IC3 received 859,532 suspected internet-crime complaints and reported losses exceeding $16 billion overall in 2024. The overall losses cover many kinds of internet crime; they are not phishing losses. See the FBI’s 2025 release on its annual Internet Crime Report.

How the defenses fit together

Defense What it helps address What it does not replace
Spam filtering Reduces how many unwanted messages reach the inbox. Checking suspicious requests that get through.
Independent verification Reduces the chance of acting on a deceptive request. Account protections if a password is exposed.
MFA, especially phishing-resistant sign-in Adds protection against account takeover after password exposure; FIDO/WebAuthn can prevent sign-in through a fake site. Caution with calls, texts, payment requests, and other phishing channels.
SPF, DKIM, and DMARC Helps receiving systems assess mail claiming to come from an organization’s domain. Verifying every sender or request a recipient encounters.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.