Don't Take the Bait
Section 01 — what you are up against

What "phishing" actually is

Phishing (said like "fishing") is a stranger sending you a message while pretending to be someone you trust — your bank, a delivery company, your workplace, even a family member — so that you hand over something valuable.

Put it in the physical world. Someone knocks on your door in a convincing uniform and says there is a gas leak and they must come in right now. The uniform is fake. The urgency is fake. But in the moment, you open the door.

A phishing message is that same trick delivered to your phone. The "uniform" is a familiar logo and a sender name that looks right.

What they are actually after

Your password

They send you to a fake copy of a real login page. You type your password, and it goes to them instead of the company.

Your money

A fake invoice, a fake customs fee, a refund that needs your card details first. Usually a small, believable amount.

Your security code

The six digits your bank texts you. Handing that over is handing over the key. No real company will ever ask you for it.

Control of your device

They talk you into installing a program so they can "fix" a problem. Now they see your screen and everything you type.

The four ways it reaches you

Email

The classic. A fake alert, receipt, or password reset.

Text message

Missed deliveries, unpaid tolls, "Hi Mum, this is my new number."

Phone call

Someone claiming to be your bank's fraud team, or technical support.

QR codes

A sticker stuck over the real code on a parking meter or a restaurant table.

Section 02 — detection

The five warning signs

Nearly every scam message carries at least two of these. Spot two, and stop — you are almost certainly looking at a fake.

  1. It is urgent, and there is a threat

    "Your account closes in 24 hours." "Respond immediately or face legal action." Panic stops people thinking, so scammers manufacture it. Real organisations give you time and are happy for you to call them back.

    If a message is rushing you, that is the scam.

  2. You were not expecting it

    A parcel you did not order. A refund you did not request. An invoice from a company you have never used. Unexpected, plus asking you to act, equals suspicious.

  3. It asks for something no real company asks for

    Your full password. The six-digit code texted to your phone. Payment in gift cards, crypto, or a transfer to a "safe account". Remote access to your computer. Every one of those is a scam, every time, no exceptions.

  4. The sender's address is slightly wrong

    The name says "Apple Support" but the address is support@apple-account-verify.co. Scammers cannot use the real address, so they use one that looks close. Tap or hover the sender name to reveal the true address.

  5. The link does not go where it says

    A button reading "Visit your bank" can point anywhere. On a computer, hover the link without clicking and the real address appears at the bottom of the screen. On a phone, press and hold it to preview.

    Read an address from the left. Everything before the first single slash is the real destination.

[ the one habit that beats all of this ]

Never use the contact details inside the message. If "your bank" contacts you, close it and reach the bank the way you always would — the number on the back of your card, the app on your phone, the address you type yourself. A real message survives that check. A fake one cannot.

Section 03 — teardown

Take a real scam apart

Three scam messages, rebuilt safely. The orange ⚑ marks are the parts that give the game away — select one and the explanation appears underneath.

SIMULATED — every example below is a harmless recreation. The companies are invented. Nothing here is clickable.

From NorthPoint Bank Security
To
Subject

We have detected unusual activity on your account originating from a device we do not recognise. For your protection, access has been temporarily limited.

Verify My Account Now
→ resolves to

▸ show the raw technical headers (optional — you do not need these)
Return-Path: <bounce-8827@mail-relay-04.vps-host-cheap.ru>
Received: from mail-relay-04.vps-host-cheap.ru ([45.147.x.x])
From: "NorthPoint Bank Security" <security@northpoint-bank-alerts.com>
Reply-To: recovery.dept.9931@gmail.com
SPF:   fail  (domain does not authorise this sender)
DKIM:  none (message is not signed)
DMARC: fail

Plain English: the mail was sent from a rented server in another country, the reply would go to a free Gmail address, and all three automatic authenticity checks failed. You never have to read this. The From address and the link told you the same thing in two seconds.

6 warning signs marked in this email.

> awaiting selection — choose any ⚑ mark above

Section 04 — assessment

Real or scam?

Eight messages. Some are genuine — the goal is not to distrust everything, it is to know the difference. You get an explanation either way.

QUESTION 1 / 8 SCORE 0

Section 05 — incident response

You clicked it. Now what?

First: this happens to careful, intelligent people every day. Embarrassment makes people wait, and waiting is the only thing that genuinely makes it worse. Work down this list.

[ do these in order ]

  1. Call your bank if money or card details were involved

    Use the number on the back of your card. Say "I think I have been scammed" — banks have a team for exactly this, and acting within hours dramatically improves your chances of getting money back.

  2. Change the password you typed in

    From a different device if you can. If you used that same password anywhere else, change it there too. That is the step people skip, and it is how one mistake becomes five.

  3. Turn on two-step login for that account

    It means a stolen password alone is no longer enough to get in. In settings it is called "two-factor authentication", "2FA", or "two-step verification".

  4. If you installed anything, or let someone control your screen

    Disconnect from the internet, uninstall the program, and run a full scan with the security software already on the machine. Not confident doing that? Take it to a repair shop — this is a routine, unembarrassing request for them.

  5. Warn the people it can spread to

    Work account? Tell IT immediately — they will not be angry, they would far rather know in the first hour. Personal account? Tell family, because scammers use a stolen account to target the contacts inside it.

  6. Report it

    US: reportfraud.ftc.gov. UK: Action Fraud, and forward scam texts to 7726. Elsewhere, search for your country's national cyber security centre. Reporting is how these networks get shut down.

[ if you clicked but typed nothing ]

You are very probably fine. Simply opening a link or an email rarely does damage on a device that is kept up to date. The harm comes from what you enter afterwards. Do not panic — close it, and do not go back.

Section 06 — hardening

Four things that protect you in advance

Set these up once and most attacks simply stop working on you.

Turn on two-step login

The most valuable thirty minutes you will ever spend. Even with your password, a scammer cannot get in without the second step. Do your email account first — whoever controls your email can reset everything else you own.

Use a password manager

It remembers a different password for every site, so one leak cannot unlock the rest. It also quietly protects you from fake pages: it will not offer to fill in your password on a lookalike site, because it checks the address exactly.

Accept the updates

Those "update available" prompts are mostly repairs to holes criminals are already using. Switch on automatic updates for your phone, computer and browser, then stop thinking about it.

Agree a family safe word

Pick a word only your household knows. If a call or text claims to be a relative in trouble and needing money now, ask for the word. It defeats "Hi Mum, this is my new number" and AI voice-cloning alike.

[ and the one that costs nothing ]

Give yourself five minutes. Scams are engineered for someone reacting instantly. Almost nothing genuine is destroyed by waiting five minutes and checking through a channel you chose yourself. That single pause defeats the majority of what is on this page.

Section 07 — FAQ

Questions people actually ask

The email had the correct logo. Doesn't that prove it's real?

No. A logo is a picture, and anyone can copy one off a website in seconds. Same for the layout, the colours, the small print, and the unsubscribe link. Scam messages are often pixel-perfect copies. Judge the sender address and the link, never the artwork.

It knew my name and the last four digits of my card. How?

Almost certainly from a data breach at some company you once used — those lists are bought and sold in bulk. It feels deeply personal, which is exactly why it works. Personal details prove your information leaked somewhere, not that the sender is genuine.

My phone showed my bank's actual number when they called.

Caller ID can be set to display any number the caller chooses, and nobody verifies it. That is why the advice is always to hang up and dial back yourself. On a landline, wait a minute or use a different phone first, because the original call can stay connected.

Isn't the padlock in the address bar a sign the site is safe?

It only means the connection is private, not that the owner is honest. Fake sites get that padlock in minutes, for free. A padlock on a scam page means your details are being sent to the criminal securely.

Why would anyone target me? I'm not rich or important.

You are not being targeted personally. These go out to millions of addresses at essentially zero cost, so a success rate of one in ten thousand is still profitable. It is not about you — which also means being caught says nothing about your intelligence.

The message was written perfectly. I thought scams had bad spelling.

That advice is out of date. Poor spelling used to be a filter the scammers wanted, because it weeded out cautious people early. Today plenty of scam messages are flawless. Good English is no reassurance at all — check the address and the link instead.

What if I reply just to ask whether it's real?

Don't. A reply confirms your address or number is live and read by a real person, which makes you more valuable and gets you more of them. It also starts a conversation, and conversations are where scammers do their best work. Delete it, then check with the company directly.

Someone I know sent me a strange link. Is their account hacked?

Very possibly, and it is worth telling them — through a different channel. Call them, or message them on another app. If the account really is compromised, the person replying to you in that chat may not be them.

Section 08 — distribution

Pass it on

The people most at risk are usually the least likely to find a page like this on their own. The printable checklist is designed to sit on a fridge or next to a phone.