Phishing, Smishing, and Fake Texts
The fake bank email, the 'your package is held' text, the call from 'fraud prevention', and the one rule that beats all of them.
What you'll learn
- Phishing is a fake message designed to make you click or hand over a secret.
- It comes by email, text (smishing), and phone, pretending to be someone you trust.
- Look for mismatched links and requests for codes or passwords.
- Never click. Go to the real app or site yourself, or call the number on your card.
is a fake message pretending to be someone you trust: your bank, the IRS, a delivery company, a job, even a friend. It's built to get you to do one of two things: click a link that steals your login, or hand over a password or security code directly. By text it's sometimes called 'smishing'; by phone, '.' Different channels, same trick. These messages have gotten good, with clean logos and real-sounding language, so 'it looks official' proves nothing. You need a habit instead.
What these messages tend to look like
- 'Suspicious activity on your account. Click to verify.' The link goes to a fake login page that captures whatever you type.
- 'Your package couldn't be delivered. Update your details here.' You weren't even expecting a package, but you click anyway.
- 'This is your bank's fraud department. Read me the code we just texted you.' That code is the key to your account, and they're trying to get in.
- 'You owe back taxes. Pay now or face arrest.' Real agencies don't operate by surprise text or threatening call.
The tells
The universal red flags all apply here: urgency, threats, strange payment demands. Phishing adds a few tells of its own.
- The link doesn't match. Hover over it or long-press it, and the real address is some random site, not your bank's.
- It asks for something no real company requests by message: your full password, a , your full , your card's PIN.
- Small weirdness: odd grammar, a greeting with no name, an email address that's almost-but-not-quite right.
A real bank or company will never ask for your full password or for a one-time code they sent you. Those codes exist to keep people out of your account. If someone asks you to share one, they're the person trying to get in.
The golden rule
Don't click the link. Don't call the number in the message. Instead, reach the company the way you normally would: open their official app, type their website address yourself, or call the number printed on the back of your card. If the alert was real, you'll see it there. If it wasn't, you dodged a scam and lost nothing.
You don't have to figure out whether each message is fake. You have to refuse to act inside it. Go to the source yourself, every time, and phishing stops working on you. If you already clicked a link or shared a code, What to Do If You've Been Scammed covers the cleanup, starting with your passwords.
Hover or tap a highlighted word for a quick definition, or browse the full glossary.
See where you stand
The 2-minute quiz checks what you know and points you to what to read next.
Test yourself
