How to Recognize a Phishing Email or Message
Treat unexpected urgency, requests for credentials or unusual payment, mismatched sender details and unsolicited links or attachments as reasons to stop and verify through a contact method obtained independently from the message.
Timeline
- Stop: Do not click, reply, open an attachment, share a code or send money while the request is unverified.
- Verify: Contact the person or organization using a known app, saved number or independently found official website.
- Report and recover: Use the platform's phishing report, alert the impersonated organization, and act quickly if credentials, money or personal data were exposed.
Phishing is a message designed to make someone reveal credentials or personal information, send money, open malware or visit a fraudulent site. The story may claim suspicious account activity, an unpaid invoice, a delivery problem, a refund or an urgent request from a colleague. FTC guidance emphasizes that tactics change, so no single spelling error, logo or greeting can prove a message is safe or fraudulent. [1][2]
Pause when contact is unexpected or creates pressure. Threats of account closure, a short payment deadline, secrecy, emotional emergencies and promises that seem unusually valuable are common manipulation techniques. Be especially cautious when the sender dictates a hard-to-reverse payment method such as gift cards, cryptocurrency, wire transfer, cash or a payment app. Slowing down and consulting a trusted person defeats the attacker's effort to prevent verification. [1][2][3]
Inspect the full sender address and domain, not just the display name or logo. Look for extra words, substituted characters or a reply-to address that differs from the apparent sender. On mobile, expand hidden address details. Still, a correct address is not conclusive because a real account can be compromised. The FBI describes business email compromise as fraud that can involve compromised legitimate accounts as well as social engineering. [3][4]
Do not use the link, phone number or reply address in a suspicious message to verify itself. Open the organization's known app, type a previously saved address, use the number on a card or statement, or contact the person through an established channel. For a payment or bank-detail change, the FBI recommends a secondary channel or two-factor verification with the intended recipient. Never send a password or multifactor code in response to an unsolicited request. [1][4][5]
Links and attachments deserve separate scrutiny. A visible link label can hide another destination, and a familiar document may lead to a counterfeit sign-in page. Hovering can expose a mismatch on a computer, but it is not a complete safety test. Avoid opening unexpected attachments, including invoices or shared documents, until the sender and context are verified. Navigate independently to the service rather than signing in through the message. [1][5]
If the message is fraudulent, use the mail, messaging or social platform's report-phishing function, then delete it. Businesses should follow their security team's reporting process so defenders can warn others and preserve evidence. FTC guidance also lists consumer reporting routes, while the FBI's IC3 accepts business email compromise complaints. If money was sent, contact the financial institution or payment provider immediately because rapid action may improve recovery chances. [1][4]
After entering a password on a suspicious page, change it immediately from the real service, sign out other sessions, review recovery details and enable phishing-resistant multifactor authentication where available. Change reused passwords on other accounts and check for forwarding rules or unauthorized transactions. If an attachment ran, disconnect the device if advised, update security tools and follow trusted incident-response guidance. For exposed identity or financial data, use the relevant institution and official identity-theft recovery resources. [1][4][5]
Sources
- Federal Trade Commission — How to Recognize and Avoid Phishing Scams
- Federal Trade Commission — What Are the Signs of a Scam?
- FBI Internet Crime Complaint Center — Business Email Compromise and Gift Cards
- FBI Internet Crime Complaint Center — Business Email Compromise
- FBI Internet Crime Complaint Center — Malicious Messaging Impersonation Guidance