
To learn the motivation behind this series (and my own personal experience with scammers read the intro post.
This week, we’ll look at phishing (a term that’s been around a while), smishing (that’s a new one), and how an unusual message from a trusted source probably isn’t FROM that trusted source.
Ding. “You’ve got mail.” A message arrives in your inbox. It appears to be Amazon (or PayPal or pick your popular site that a vast majority people have actually used). There’s an urgent request. You must call this number or click on this link. The messages look legitimate. They’ve got official logos. And this sounds urgent. Shouldn’t I at least call?
A chirp goes off. You look at your phone and see a message that appears to be from your bank: “We’ve detected unusual activity on your account. Click here to verify your identity immediately.” Wow. Aren’t you lucky that your bank is looking out for you?
The above scenarios are two of the most widespread scams.
The email-that-looks-like-it’s-from-a-trusted source? That’s a Phishing attack.
The text message that urges you to tap on a link? That’s referred to Smishing (an amalgam of SMS and phishing).
How They Work
Scammers craft these messages to exploit trust and urgency. They may claim:
- your account has been locked
- a package is delayed
- a payment failed
- or a security breach occurred.
The goal is simple: get you to click a link that leads to a fake login page, download malware, or reply with personal information such as passwords, one-time codes, or bank details. Once they have that information, they can drain accounts, open new lines of credit, or sell your data.
Modern versions are increasingly sophisticated.
Attackers use AI to generate polished writing with few of the old spelling errors that once gave them away.
They spoof sender addresses so the message appears to come from a real domain.
Some even use QR codes (“Quishing”) that take you to the same fraudulent sites when scanned.
Others combine the message with a follow-up phone call that appears to come from the company’s real number through caller ID spoofing.
What to Look Out For
Red flags are consistent. Legitimate companies almost never ask you to click a link in an unsolicited message to “verify” account details. They do not demand immediate action under threat of account closure. Hovering over links (without clicking) often reveals strange web addresses that do not match the real company. The sense of urgency itself is a major warning sign—scammers want you to act before you think.
How to Protect Yourself
Protect yourself by never clicking links or opening attachments in unexpected messages. Instead, open a new browser window and go directly to the company’s official website or app by typing the address yourself.
Contact the organization using a phone number from their official site or the back of your card, not any number provided in the message.
Enable multi-factor authentication on important accounts, preferably using an authenticator app rather than SMS when possible.
Keep your software updated and use reputable security tools that can flag known phishing sites.
What If You Already Responded?
If you already clicked or shared information, act quickly.
Change passwords immediately from a different device.
Enable extra security features.
Monitor accounts for suspicious activity.
Report the incident to the company involved and to agencies such as the FTC (reportfraud.ftc.gov) or your local equivalent.
