Phishing
Phishing is a message that impersonates someone you trust, such as your bank, your employer, or a familiar brand, in order to steal your passwords, your money, or your personal information. It is the most reported cybercrime in the United States: the FBI logged roughly 192,000 phishing and spoofing complaints in 2025, more than double the next-largest category.
How It Works:
- The Lure: A message arrives claiming something needs your attention right now. A locked account, a failed payment, a shared document, an unexpected refund.
- The Fake Login Page: The link opens a copy of a real sign-in page. Modern phishing kits reproduce the branding exactly, run on a valid HTTPS certificate, and sit on a lookalike domain, so the padlock icon proves nothing.
- Real-Time Credential Theft: Attacker-in-the-middle kits pass whatever you type straight through to the real site. When it asks for your six-digit code, the attacker uses it within seconds and steals your logged-in session. This is why a text-message code on its own no longer protects you.
- The Payoff: Your account is used to reset your other passwords, drain funds, or phish your contacts from an address they already trust.
Key Red Flags:
- A link or attachment you did not ask for, especially one that leads to a login page.
- Manufactured urgency: a threat to close, suspend, or charge your account unless you act immediately.
- The sender's address is subtly wrong (service@microsott.com), or a real company name is displayed on top of a consumer email address.
- A QR code standing in for the link. See QR Code Scams.
- A request to approve a login prompt or read back a one-time passcode. No legitimate company will ever ask you for your code.
- Note that poor spelling used to be a reliable tell. AI-written phishing has made it unreliable, so judge the request rather than the grammar.
How to Protect Yourself:
- Use passkeys wherever they are offered: This is the strongest defense available. A passkey is tied to the real website's address, so it simply will not work on a lookalike domain.
- Prefer an app or a security key over SMS: An authenticator app or a hardware key is much harder to intercept than a text-message code.
- Go to the source yourself: Do not click through. Type the address in yourself, or use your own bookmark.
- Use a password manager: It fills your credentials only on the genuine domain, so a lookalike site silently gets nothing.
- Treat any request for a code as an attack: If a caller or a message asks you to read out or type in a one-time passcode, stop.
If You've Been Phished:
- Change the password from a device you trust, starting with your email account.
- Sign out all active sessions in the account's security settings. A stolen session survives a password change until you do this.
- Turn on or reset multi-factor authentication, and check whether the recovery email address and phone number have been altered.
- Contact your bank or card issuer if payment details were exposed.
Where to Report It
Report scams even if you didn't lose money. Every report helps investigators spot patterns and warn others.
- FBI Internet Crime Complaint Center (IC3): ic3.gov
- Federal Trade Commission: reportfraud.ftc.gov
- AARP Fraud Watch Network Helpline: 877-908-3360