Skip to Content

How to Recognize and Avoid Phishing Scams

By Dale West,

Phishing is a deceptive practice in which criminals impersonate legitimate companies, government agencies, or people you know. Their goal is usually to trick you into revealing passwords, account numbers, payment information, or other sensitive data. Phishing messages may also contain links or attachments that install malicious software.

Although phishing does not cause most data breaches by itself, it remains a significant threat. Verizon's 2025 Data Breach Investigations Report found that phishing was involved in approximately 14% of confirmed breaches, while human involvement—including phishing, stolen credentials, and mistakes—played a role in 60%.

What Does a Phishing Email Look Like?

Suppose you receive an email that appears to be from Amazon. It claims that payment was declined for a recent purchase and urges you to update your payment information immediately.

The message may look convincing. It might include an Amazon logo, familiar colors, professional formatting, and language similar to a genuine notification. Modern phishing emails may contain perfect grammar, so spelling mistakes are no longer a reliable way to identify every scam.

Instead, watch for several warning signs:

  • The message creates a false sense of urgency.
  • You were not expecting the email.
  • It asks you to provide a password, verification code, or payment information.
  • The sender's address contains a misspelling or unfamiliar domain.
  • The link leads somewhere other than the company's official website.
  • The message includes an unexpected attachment.
  • The greeting or account details do not match your information.
  • The sender asks you to bypass normal procedures or keep the request secret.

Examine the Sender Carefully

Email programs display sender information differently. When possible, inspect the complete "From" address rather than relying only on the displayed name.

For example, a fraudulent message might come from:

support@amason.com

instead of:

support@amazon.com

The misspelling may be easy to overlook. However, even a sender address that appears correct does not prove the message is legitimate. Email addresses and display names can be spoofed to make a message appear to come from a trusted source.

Inspect Links Without Opening Them

On a desktop computer, hovering over a link may display its actual destination. On a mobile device, pressing and holding the link may show a preview, depending on the device and email application.

Do not open the link merely to investigate it. Look for:

  • Misspelled domain names
  • Unfamiliar web addresses
  • Additional words placed before or after a legitimate company name
  • Shortened links that hide the destination
  • Links that do not match the company supposedly sending the message

Remember that a padlock icon or an address beginning with https does not guarantee that a website is legitimate. Scam websites can also use encrypted connections.

How Phishing Scams Cause Damage

A phishing attack may succeed when someone opens a malicious attachment, clicks a fraudulent link, or enters information on a fake website.

If you provide a username and password, the attacker may be able to access the associated account. The attacker could then:

  • Make unauthorized purchases
  • Steal personal or financial information
  • Change the password and lock you out
  • Use the account to target your contacts
  • Attempt the same password on other websites
  • Request password resets for connected accounts

Multifactor authentication can provide an additional layer of protection, but you should never approve an unexpected login request or share a verification code.

What to Do When an Email Looks Suspicious

Do not use the links, phone numbers, QR codes, or contact information in the suspicious message.

Instead:

  1. Open your browser or the company's official app.
  2. Manually enter the website address you already know and trust.
  3. Sign in directly and check your account.
  4. Contact the company using a verified phone number or website.
  5. Report the message as phishing or junk.
  6. Delete it after reporting it.

For an Amazon-related message, for example, open Amazon directly and review the Your Orders section rather than using the email's link. Amazon also provides a method for reporting suspicious communications.

Emptying your trash folder is not normally necessary to neutralize a phishing email. The important steps are avoiding its links and attachments, reporting it, and deleting it.

What to Do If You Clicked the Link

Clicking a suspicious link does not always mean your account or device has been compromised, but you should act promptly.

If you clicked a link or opened an attachment:

  • Close the page without entering information.
  • Update your security software.
  • Run a malware scan.
  • Install pending operating-system and browser updates.
  • Notify your company's technology administrator if the device is used for work.

If you entered a password:

  • Change it immediately through the legitimate website or app.
  • Change the password anywhere else you reused it.
  • Enable multifactor authentication.
  • Review recent logins, purchases, and account changes.
  • Sign out of other active sessions when that option is available.

If you provided banking, credit-card, Social Security, or other sensitive information, contact the affected institution immediately and follow the recovery steps at IdentityTheft.gov.

The Best Rule to Remember

Do not click links or download attachments in unexpected messages.

When a message claims that something is wrong with an account, go directly to the company's official website or app. A few extra seconds of verification can prevent account theft, financial loss, and a tremendous amount of frustration.

Have questions about this article or how we can help? Contact the Mad Scientist