Home / Learn / Privacy / Protect Yourself from Phishing

Protect Yourself from Phishing: Complete Guide to Recognizing and Avoiding Online Scams

A practical phishing protection guide covering email, SMS, phone, QR codes, fake logins, MFA, passkeys, business scams, and recovery steps.

Phishing is one of the most persistent forms of online fraud because it does not require an attacker to break sophisticated encryption or defeat a firewall. Instead, the attacker tries to persuade a person to hand over something valuable: a password, authentication code, bank information, Social Security number, payment, recovery phrase, document, or access to a device.

Modern phishing is no longer limited to badly written email. Scams can arrive through text messages, phone calls, social media, messaging apps, QR codes, fake search advertisements, collaboration platforms, online marketplaces, cloud-sharing invitations, calendar invites, and even convincing video or voice impersonation. Generative AI can make fraudulent messages more fluent and personalized, while information from old data breaches can give scammers enough real details to sound legitimate.

The best defense is not memorizing a list of suspicious phrases. It is adopting a repeatable verification process.

This FreeTempTools Learning Center guide explains how phishing works, how to recognize suspicious messages, how to verify requests independently, how phishing-resistant authentication changes the risk, what to do after clicking a malicious link, what to do after entering a password or authentication code, how businesses should respond, and how to reduce the amount of personal information attackers can use against you.

The guide is written primarily for general users and small organizations. Where it discusses NIST, CISA, FTC, IdentityTheft.gov, or U.S. reporting systems, those references are U.S.-focused. Readers elsewhere should use equivalent national consumer-protection, cybercrime, and data-protection resources.

Quick Answer: How Do You Protect Yourself from Phishing?

Use this simple rule:

Do not act through an unexpected message. Verify the request through a channel you already trust.

If a message asks you to click, sign in, pay, download, call, scan a QR code, share a code, or provide personal information:

  1. Stop before interacting.
  2. Identify what the message wants from you.
  3. Do not use the link, phone number, or QR code supplied in the suspicious message.
  4. Open the company's official app or type a known website address yourself.
  5. Contact the person or company using contact information you already trust.
  6. Use multi-factor authentication, preferably phishing-resistant authentication where available.
  7. Report suspicious messages to the relevant provider or authority.
  8. If you already interacted, take recovery action immediately.

The goal is not to prove every strange message is fraudulent. The goal is to avoid giving an unverified message control over your next action.

Key Takeaways

What Is Phishing?

Phishing is a form of social engineering in which an attacker impersonates a trusted person, organization, or service to persuade a victim to take an unsafe action.

Typical goals include:

The attacker may pretend to be:

Phishing is successful when the victim trusts the message enough to act before verifying it independently.

Why Phishing Still Works

Security technology has improved, but phishing targets human decision-making.

A strong phishing message often combines:

Examples:

The message does not need to be perfect. It only needs to reach you at the right moment.

Types of Phishing

Email Phishing

Mass or targeted emails that imitate a real company or person.

Common lures:

Smishing

Phishing through SMS or messaging apps.

Common themes:

Vishing

Voice phishing through telephone calls or voice messages.

Attackers may impersonate:

Spear Phishing

Highly targeted phishing designed for a specific person or organization.

Attackers may research:

Business Email Compromise

Fraud that impersonates executives, vendors, employees, or business partners to redirect payments or obtain sensitive information.

QR Phishing

A malicious or misleading QR code directs the victim to a fake login, payment, or malware page.

Search-Engine Phishing

Fraudulent websites appear through advertisements, malicious SEO, or lookalike domains when users search for a company.

Social Media Phishing

Fake support accounts, hacked friends, prize scams, verification requests, and malicious direct messages.

Collaboration-Platform Phishing

Messages through Slack, Teams, Google Workspace, Microsoft 365, project-management platforms, or shared documents.

Calendar Phishing

Fraudulent invitations or events contain malicious links or phone numbers.

OAuth Consent Phishing

A user is asked to authorize a malicious application rather than entering a password.

MFA Phishing

Attackers capture one-time codes or trick users into approving push notifications.

Clone Phishing

A legitimate message is copied and modified to include a malicious link or attachment.

The Anatomy of a Phishing Message

A phishing message usually contains four components.

1. Identity

Who does the attacker claim to be?

2. Story

Why are they contacting you?

3. Pressure

Why must you act now?

4. Action

What do they want you to do?

For example:

Identity: "Your bank"

Story: "Suspicious transaction"

Pressure: "Your account will be frozen"

Action: "Click here and sign in"

The action is the most important part.

Ask:

What would happen if I ignored this message and contacted the company independently?

If the problem is real, the company should still know about it through an official channel.

The FreeTempTools Phishing Verification Rule

Use this five-step process.

Step 1: Pause

Do not click, reply, scan, call, download, or approve.

Step 2: Identify the Request

Is the message asking for:

Step 3: Leave the Message

Open the real company independently.

Step 4: Verify

Use:

Step 5: Act Only After Verification

If the request is legitimate, complete it through the trusted channel.

This process works even when you cannot identify every technical clue.

Red Flags in Phishing Emails

Look for combinations of warning signs.

No single red flag proves fraud.

Conversely, perfect grammar does not prove legitimacy.

How to Check a Sender Address

Do not rely only on the display name.

A message may say:

PayPal Security

while the actual sender domain is unrelated.

Check:

Examples of suspicious patterns:

Do not assume a familiar-looking domain is legitimate.

When in doubt, ignore the message and open the real service independently.

Lookalike Domains

Attackers register domains designed to resemble legitimate sites.

Techniques include:

A URL can look convincing at a glance.

Do not manually analyze a complicated URL when an easier option exists.

Open the real company from:

On desktop systems, hovering may reveal the destination.

This can help, but it is not a complete defense.

Problems include:

The safest approach for important accounts is to avoid unsolicited login links entirely.

Phishing Attachments

Attachments can contain:

Unexpected attachments deserve caution.

Common dangerous or suspicious types include:

Even PDFs and ordinary-looking documents can contain links designed to redirect you.

If a known person sends an unexpected attachment, verify with them separately.

PDF and Document Phishing

A phishing email may attach a PDF that says:

The attachment may be designed to bypass email-link filtering.

FreeTempTools provides Image to Text and Document Scanner for legitimate document workflows, but extracting or scanning content does not prove that a document is trustworthy.

Treat the origin of the document as the primary question.

QR Code Phishing

QR codes are convenient because they move a user from physical or digital material to a website.

The problem is that the destination is hidden until scanning.

QR phishing may appear on:

Before acting:

FreeTempTools' QR Code Generator can create QR codes for legitimate destinations you control. A QR code is only an encoding mechanism; it does not make the underlying destination trustworthy.

Smishing: Phishing by Text Message

Text messages create urgency because people read them quickly.

Common smishing themes include:

Do not click a link simply because the text knows:

Those details may come from public data or breaches.

Vishing: Phishing by Phone

Caller ID can be spoofed.

A caller may know:

This does not prove legitimacy.

End the call and contact the organization independently.

Never provide:

because an unsolicited caller asks.

"Safe Account" Scams

A scammer may claim your bank account is compromised and instruct you to move money to a "safe account."

Do not do it.

Call your financial institution directly through the number on your card or official app.

Moving money because an unsolicited caller tells you to can make recovery difficult.

Gift Card Phishing

Gift cards are frequently requested because they can be difficult to reverse.

Common stories:

Legitimate organizations generally do not demand gift cards as payment for debts, fines, or account security.

Cryptocurrency Phishing

Attackers may seek:

Never type a seed phrase into a site because an unsolicited message tells you to "verify" a wallet.

Do not send cryptocurrency to "protect" funds.

Use bookmarks for exchanges and wallets.

Fake Technical Support

A fake support message may claim:

The attacker may request remote-access software.

Do not install remote-access tools because of an unexpected popup, call, email, or text.

Close the message and use official support.

Fake Login Pages

A fake page may perfectly copy:

Visual design is not authentication.

Before entering a password:

A password manager may refuse to autofill on a lookalike domain.

Search Engine Phishing

A user may search:

Attackers may attempt to appear in advertisements or results.

Do not assume the first result is official.

For important services:

NIST treats phishing as phishing regardless of whether a user reached the impostor through email or search results.

Social Media Phishing

Common tactics:

If a friend sends an unusual link, contact them another way.

Job and Recruitment Phishing

Fake recruiters may request:

Verify the employer independently.

Be cautious when:

Invoice and Vendor Phishing

Businesses should treat changes to payment instructions as high-risk.

Attackers may compromise:

Then request:

Verify payment changes using a previously known phone number.

Do not verify using the number inside the change request.

Executive Impersonation

A message appears to come from:

It asks for:

Create a business rule:

High-risk requests require independent verification even when they appear to come from leadership.

Payroll Diversion Phishing

Attackers may request a change to employee direct deposit.

Businesses should require a secure process for payroll changes.

Employees should verify unexpected payroll messages through HR systems rather than email links.

An attacker may avoid stealing your password and instead ask you to authorize an application.

The permission screen may request:

Before granting access:

If you authorized a suspicious app:

MFA Phishing

Multi-factor authentication reduces account takeover, but some MFA methods can be phished.

An attacker may:

  1. Steal the password.
  2. Trigger a one-time code.
  3. Ask the victim to enter the code on the fake site.
  4. Relay the code to the real service.

NIST states that manually entered one-time passwords are not phishing-resistant because they can be relayed.

Use MFA anyway when phishing-resistant methods are unavailable.

Better is not the enemy of perfect.

MFA Push Fatigue

Repeated push prompts may be used to pressure you into approving a login.

If you receive unexpected prompts:

Never approve merely to make the prompts stop.

Phishing-Resistant Authentication

NIST defines phishing resistance as an authentication protocol's ability to prevent disclosure of valid authentication secrets or outputs to an impostor without relying on the user's vigilance.

Examples can include properly implemented:

The important distinction is that the authenticator is cryptographically bound to the legitimate service rather than requiring a user to manually copy a code.

Phishing-resistant authentication does not stop every scam.

It does not prevent:

It specifically strengthens authentication.

Passkeys and Phishing

Passkeys can reduce phishing risk because they are designed to authenticate to the correct service.

A fake site cannot simply collect the same secret that a password form can.

Use passkeys where supported and where recovery is understood.

Protect:

Password Managers as a Phishing Defense

A password manager can help in two ways.

First, it makes unique passwords practical.

Second, it may refuse to autofill a credential on a lookalike domain.

Do not override that warning casually.

A missing autofill does not prove phishing, but it is a reason to verify the domain.

Protect Your Primary Email

Your primary email deserves strong protection because it may reset other accounts.

Use:

If your email account is compromised, attackers may:

Fewer sign-ups, fewer phishing emails

Phishing needs your address first. A disposable inbox for low-stakes sign-ups keeps your real one out of the lists attackers buy.

Open Temp Mail →

Temporary Email and Phishing Exposure

Using one permanent email address everywhere increases exposure.

For low-risk disposable registrations, FreeTempTools Temp Mail can reduce how often your permanent address is shared.

Do not use temporary email for:

Temporary email reduces contact exposure in appropriate situations; it does not make a fraudulent site safe.

How Data Breaches Make Phishing Better

A data breach may expose:

Attackers combine data from multiple sources to create believable messages.

This is why a message containing real information is not proof of legitimacy.

Phishing After a Data Breach

After a public breach, scammers may impersonate the affected company.

They may offer:

Verify through the company's official site.

Do not enroll through an unsolicited link unless you have independently confirmed it.

Fake CAPTCHA Phishing

Fraudulent pages may display a fake CAPTCHA and instruct you to:

A real CAPTCHA should not require you to run operating-system commands or install unknown software.

If a verification challenge asks you to execute commands manually, leave the site.

Browser Notification Scams

A website may ask for notification permission and later send fake:

Review browser notification permissions and remove unknown sites.

A browser notification is not proof that your device is infected.

Fake Security Alerts

Scam pages may imitate:

They may use:

Close the page.

Do not call the provided number.

Use the operating system's real security tools.

AI-Generated Phishing

AI can improve:

Therefore, old advice such as "look for spelling errors" is no longer enough.

Focus on:

Voice Cloning and Family Emergency Scams

A voice may sound like a family member.

Create a family verification method:

Do not send money based only on voice recognition.

Deepfake Video and Executive Fraud

Video calls can also be manipulated.

For high-value business actions, use process rather than appearance.

Examples:

How to Verify a Message from Your Bank

Do not click the message link.

Instead:

  1. Open the official banking app.
  2. Check alerts.
  3. Call the number on the card.
  4. Review transactions.

If the bank has a real concern, the issue should be visible through official channels.

How to Verify a Government Message

Government impersonation is common.

Do not assume:

proves legitimacy.

Use the agency's official website and published contact information.

How to Verify a Delivery Message

Open the merchant or carrier app.

Use the tracking number from your original purchase.

Do not pay an unexpected "redelivery fee" from a text without verification.

How to Verify a Coworker Request

Use:

Sensitive requests should have a known process.

How to Verify a Family Message

Call the family member through a stored number.

If they claim they cannot speak freely, verify with another trusted relative.

Do not let urgency override verification.

Do not panic.

Actions:

  1. Close the page.
  2. Do not download anything.
  3. Review the URL and message.
  4. Update browser and device.
  5. Run trusted security checks if anything downloaded.
  6. Watch for suspicious activity.

Simply visiting a page does not automatically mean account compromise, but malicious downloads or browser exploits can create additional risk.

If You Entered a Password

Act immediately.

  1. Open the legitimate service directly.
  2. Change the password.
  3. Change every reused version.
  4. Revoke active sessions.
  5. Review MFA.
  6. Review recovery settings.
  7. Review account activity.
  8. Review connected applications.

If the password belongs to primary email, prioritize it.

If You Entered an MFA Code

Treat the account as potentially compromised.

The attacker may have used the code immediately.

If You Approved an MFA Push

Take the same action as if a code was stolen.

An approved prompt may authorize an attacker.

If You Downloaded a File

Do not continue opening or executing it.

If You Installed Remote-Access Software

Disconnect the device from the network if safe to do so.

Contact:

Review:

Remote access may allow an attacker to see or control more than the original scam interaction.

If You Sent Money

Contact the financial institution immediately.

Depending on the method:

there may be different recovery options.

Do not pay a "recovery service" that contacts you unexpectedly.

If You Sent Cryptocurrency

Contact the exchange or platform immediately if one was involved.

Cryptocurrency transactions may be difficult or impossible to reverse.

Watch for "recovery" scammers who promise to retrieve funds for another payment.

If You Shared Identity Information

If you disclosed:

consider identity-theft protections.

Monitor:

Use IdentityTheft.gov if your information is misused.

If You Shared Card Information

Contact the issuer.

Discuss:

Review recent charges.

If You Shared Bank Information

Contact the bank.

Review:

Ask about protective measures.

If Your Email Was Taken Over

Review:

Attackers may create forwarding rules to retain access to sensitive messages.

Phishing Incident Checklist

Reporting Phishing

FTC consumer guidance recommends reporting phishing attempts and using ReportFraud.ftc.gov.

Email providers, mobile carriers, social networks, and businesses also provide reporting tools.

For business accounts, notify the appropriate security or IT team.

Report quickly when:

Why Reporting Matters

Reports can help:

You may not receive a personal response, but reporting still has value.

Phishing Prevention for Families

Create household rules:

Phishing Prevention for Older Adults

Scammers may use:

Useful protections:

Phishing Prevention for Students

Students may receive:

Use official school portals and known contacts.

Phishing Prevention for Small Businesses

Businesses should combine people, process, and technology.

Use:

No training program should rely entirely on users noticing visual clues.

Business Email Compromise Controls

Use:

A business process can stop fraud even when a phishing email looks perfect.

Training Employees

Good training teaches behaviors.

Instead of:

"Look for spelling errors"

teach:

"Never change payment instructions based solely on email."

Teach:

Simulated Phishing Programs

Organizations may use simulations.

A good program should:

The purpose is resilience, not punishment.

Email Authentication: SPF, DKIM, and DMARC

Businesses can use technical email controls to reduce some forms of domain impersonation.

These technologies help receiving systems evaluate whether messages are authorized.

They do not stop:

Email authentication is one layer.

Secure Email Gateways and Filters

Filters can detect:

But attackers adapt.

Users still need verification habits.

Protecting Your Domain

Business owners should protect:

with strong authentication.

If an attacker controls the domain, phishing can become more convincing.

FreeTempTools Resources Relevant to Phishing

Temp Mail

Temp Mail can reduce exposure of your permanent email during low-risk disposable registrations.

QR Code Generator

QR Code Generator helps create legitimate QR codes for destinations you control. Always verify the destination before distribution.

What Is My IP

What Is My IP displays the public IP address your connection presents to websites. It does not identify whether a message is phishing.

Self-Destructing Notes

Self-Destructing Notes can support short-lived sharing, but recipients can still preserve content. Do not use it as a substitute for proper credential-sharing systems.

Temporary Pastebin

Temporary Pastebin should not be used for passwords, authentication codes, API secrets, seed phrases, or regulated sensitive information.

Image to Text

Image to Text can extract text from screenshots or images for legitimate analysis. OCR output does not establish that the underlying message is genuine.

A 10-Second Phishing Test

Before acting, ask:

  1. Did I expect this?
  2. What does it want?
  3. Is it asking me to leave my normal process?
  4. Can I verify independently?
  5. Would I still do this if I had received no message?

If you cannot verify it, do not act.

A 60-Second Verification Test

Sender

Who actually sent it?

Context

Was I expecting this?

Action

What am I being asked to do?

Pressure

Why must it happen now?

Verification

Can I confirm it independently?

This test is more reliable than grammar alone.

Phishing Decision Tree

Unexpected message?

If no, still verify sensitive requests.

If yes, continue.

Requests login, money, code, download, or personal information?

If no, remain cautious.

If yes, do not act through message.

Can you independently verify?

If yes, use trusted channel.

If no, wait.

Already interacted?

Move to incident response.

Phishing Myths vs Facts

MythFact
Phishing emails always have bad grammarModern scams can be fluent and professional
A real logo proves legitimacyLogos are easy to copy
Caller ID proves who is callingCaller ID can be spoofed
MFA stops all phishingSome MFA can be relayed or socially engineered
QR codes are safer than linksQR codes can lead to malicious sites
HTTPS means a site is legitimateHTTPS only protects the connection to that site
A message with my real name must be realPersonal information can come from breaches or public data
Antivirus stops phishingPhishing can steal information without installing malware

HTTPS and the Padlock

HTTPS means the connection between your browser and the site is encrypted.

It does not prove the organization behind the site is legitimate.

A phishing site can use HTTPS.

Verify the domain.

Why Urgency Is So Effective

Urgency reduces reflection.

Common deadlines:

Ask:

What happens if I take five minutes to verify?

Legitimate organizations generally allow verification.

Why Authority Is Effective

Attackers impersonate:

Authority can make people comply.

Verification is not disrespectful.

Why Curiosity Is Effective

Messages such as:

create curiosity.

Do not let curiosity bypass security habits.

Why Fear Is Effective

Fear may involve:

Use official channels.

Why Rewards Are Effective

Scams promise:

Unexpected rewards deserve verification.

Phishing and Public Wi-Fi

Public Wi-Fi is not the primary cause of phishing.

Phishing works on any network.

HTTPS and modern apps protect many network communications, but users still need to verify sites.

Do not confuse network privacy with authentication security.

Phishing and VPNs

A VPN does not stop you from entering a password into a fake site.

A VPN changes network routing.

Phishing resistance requires:

Phishing and Incognito Mode

Private browsing does not:

It mainly limits local browser history and storage after the session.

Phishing and Antivirus

Antivirus can help detect malware.

It cannot reliably stop:

Use layered defense.

Phishing and Browser Password Warnings

Take browser and password-manager warnings seriously.

Do not bypass warnings casually.

Phishing and Account Recovery

Attackers may target recovery rather than passwords.

Protect:

Remove outdated methods.

Phishing and SIM Swapping

Phone numbers may be targeted to intercept SMS codes.

Protect carrier accounts with:

Prefer stronger MFA when available.

Phishing and Children

Teach children:

Phishing and Online Dating

Romance scammers may eventually request:

Be cautious when a relationship quickly becomes financial.

Phishing and Marketplace Sales

Scammers may send:

Use the marketplace's official payment and messaging system.

Phishing and Charities

After disasters or major events, scammers impersonate charities.

Donate through the charity's verified site rather than an unsolicited link.

Phishing and Taxes

Tax phishing increases around filing season.

Use official tax portals.

Do not trust refund messages merely because they reference tax season.

Phishing and Health Insurance

Scammers may impersonate insurers or healthcare providers.

Verify through the member portal or number on the insurance card.

Phishing and Password Expiration

A common business lure says:

Your password expires today.

Open the organization's normal sign-in portal independently.

Do not use the email button.

Phishing and Shared Documents

Document-sharing emails can be legitimate or malicious.

Verify:

If a document asks you to sign in again unexpectedly, verify.

Phishing and CAPTCHA Scams

The FTC reported in 2026 that fake CAPTCHA-style scams may instruct users to take unusual actions that can install malware.

A legitimate verification challenge should not require you to copy commands into your computer.

Phishing and Reward-Points Scams

FTC alerts in 2026 highlighted texts claiming reward points are expiring.

Open the retailer or loyalty program independently instead of using the text link.

Phishing and Traffic-Violation Scams

Government and toll-themed text messages can pressure users with legal consequences.

Verify through the official agency.

Do not pay through an unsolicited text.

Phishing and Refund Scams

A fake refund can be used to collect:

Verify refunds from the original merchant account.

The Strongest Practical Phishing Defense

There is no single product that eliminates phishing.

The strongest approach combines:

  1. Independent verification
  2. Unique passwords
  3. Password manager
  4. MFA
  5. Phishing-resistant authentication
  6. Secure recovery
  7. Device updates
  8. Financial controls
  9. Reporting
  10. Reduced public exposure

Personal Phishing Protection Checklist

Small-Business Phishing Checklist

What to Do Today

If you want to improve immediately:

  1. Turn on MFA for primary email.
  2. Use a password manager.
  3. Replace reused passwords.
  4. Bookmark banking and important services.
  5. Review recovery phone and email.
  6. Add carrier PIN.
  7. Teach family not to share codes.
  8. Establish verification for financial requests.
  9. Use passkeys where supported.
  10. Report phishing rather than merely deleting it.

Advanced Phishing Scenarios You Should Recognize

The most dangerous phishing attempts often appear during ordinary events. The message feels believable because the timing is believable.

Account Security Alert Phishing

A fake alert may say:

The safest response is to open the service independently.

Do not use the alert's login button.

If the alert is legitimate, the same event should normally appear in the account's security dashboard or official app.

Subscription Renewal Phishing

A scammer may claim:

The message may include a phone number rather than a link.

Do not call the number in the message.

Open the real subscription account and review billing there.

Cloud Storage Phishing

Messages may say:

Attackers know that cloud accounts are valuable because they often contain personal and business files.

Verify through the official cloud service.

Bank Fraud Alert Phishing

A fraud alert creates immediate fear.

The scammer may ask you to:

Use the bank's official app or number printed on the card.

Payment App Phishing

Attackers may impersonate popular payment services.

Common lures:

Do not trust screenshots supplied by a buyer or seller.

Open the payment app yourself.

Phishing Through Compromised Real Accounts

One of the hardest phishing scenarios occurs when the message comes from a real account that has been taken over.

Examples:

The sender address may be genuine.

That is why sender verification alone is insufficient.

Look for changes in behavior:

Use a second communication channel.

Thread Hijacking

Attackers who compromise an email account may reply inside an existing legitimate conversation.

The message may contain:

Then the attacker changes:

Business users should treat payment changes as a new high-risk event even when they appear inside an old trusted thread.

Conversation Hijacking in Messaging Apps

The same principle applies to:

If a known contact suddenly requests money or credentials, verify separately.

An authentic account can be controlled by an attacker.

Phishing Through Shared Cloud Files

Attackers may send a legitimate Google Drive, OneDrive, Dropbox, or other cloud-sharing notification.

The platform notification may be real, but the shared content may contain:

A legitimate delivery platform does not guarantee trustworthy content.

Test suspicious links safely

Never sign up with your real address to check whether a site is legitimate. Use a throwaway inbox and let it expire.

Get a temporary inbox →

Phishing Through Online Forms

Attackers can use legitimate form platforms to collect:

The form provider may be legitimate.

Ask whether the organization would normally request that information through a generic form.

Phishing Through Calendar Invitations

A malicious calendar invite may appear automatically.

It may contain:

Do not trust an event merely because it appears on your calendar.

Verify the organizer and purpose.

Phishing Through Browser Search Ads

Search ads can create a dangerous shortcut.

A user may think:

I searched for the company myself, so this must be safe.

But advertisements can imitate:

Use bookmarks for critical services whenever possible.

Phishing Through Fake Customer Support

A fake support representative may appear:

Official companies rarely need:

Use support links from the company's official site.

Phishing Through Online Marketplace Buyers

A buyer may claim:

Use only the marketplace's built-in transaction system.

Phishing Through Sellers

A seller may redirect you away from the platform.

Red flags include:

Staying inside the marketplace may preserve important fraud protections.

Phishing Through Fake Invoices

Fake invoices may be designed to create confusion rather than credibility.

The recipient thinks:

Maybe someone else ordered this.

Then they call the number in the invoice.

That call begins the scam.

Verify invoices through known vendor records.

Scammers may claim:

Fear creates urgency.

Verify through official court or government systems.

Phishing Through Tax Refunds and Credits

A message may promise:

Do not provide tax credentials through unsolicited messages.

Use the official tax agency portal.

Phishing Through Insurance

Attackers may impersonate:

Verify through the number on your insurance card or official portal.

Phishing Through Schools

Students, parents, and staff may receive:

Use official school systems.

Phishing Through Real Estate Transactions

Real estate transactions involve large transfers and many participants.

Attackers may compromise:

Then send fraudulent wire instructions.

Never rely solely on emailed wire instructions.

Verify through a known phone number before sending funds.

Phishing Through Payroll and HR

Attackers may target:

Organizations should require authenticated workflows rather than email-only changes.

Phishing Through Password Managers

A scammer may imitate your password-manager provider.

The message may say:

Open the password manager directly.

Your master password should never be entered because an unsolicited message directed you to a page.

Phishing Through Mobile Carrier Messages

Attackers may claim:

Open the carrier app or official website.

Protect the carrier account because phone access can affect SMS recovery.

Phishing Through Cryptocurrency Giveaways

Common themes:

Do not connect a wallet or sign a transaction merely because a social account promotes it.

Phishing Through Browser Extensions

A malicious or compromised extension can:

Review extension permissions and remove unnecessary extensions.

How to Read a URL More Safely

For ordinary users, the most important part is the actual registered domain.

Example:

https://login.bank.example.com

The important domain is example.com.

An attacker might use:

https://example.com.fake-site.net

The actual destination is fake-site.net.

Because URL interpretation can be confusing, independent navigation is usually safer than manual analysis.

URL Shorteners

Shortened URLs hide destinations.

If an unexpected message contains a shortened URL:

Internationalized Domain Names

Modern domain systems can represent non-ASCII characters.

Some characters may resemble Latin letters.

Browsers provide protections, but lookalike domains remain possible.

Again, bookmarks and official apps reduce reliance on visual domain inspection.

Messaging platforms may display a preview image and title.

Those previews can be manipulated.

Do not treat the preview as proof of destination.

Phishing and Redirects

A legitimate-looking link may redirect.

Marketing and tracking systems legitimately use redirects, which makes manual analysis difficult.

For sensitive login requests, avoid the message link entirely.

Phishing and URL Parameters

A URL can contain:

That personalization does not prove legitimacy.

Attackers can create personalized URLs.

Phishing and Authentication Codes

A one-time code may say:

Do not share this code.

Believe that instruction.

No legitimate caller should need you to read it back.

Authentication codes are generated for the person actively signing in.

Phishing and Push Notifications

If a login prompt appears when you are not signing in:

Phishing and Recovery Codes

Recovery codes can bypass MFA.

Treat them like master keys.

Do not enter a recovery code into a page reached through an unsolicited message.

Phishing and Passkey Enrollment

An attacker may try to trick a user into enrolling an attacker's authenticator or approving a new device.

Review security notifications about:

If you did not initiate the change, investigate immediately.

Phishing and OAuth App Permissions

Review connected apps periodically.

Remove:

A revoked app should no longer have authorized access.

Phishing and Session Theft

A sophisticated attacker may steal a session rather than the password.

After serious compromise:

Changing a password alone may not end every session.

Phishing and Browser Cookies

Cookies maintain sessions.

Do not copy browser cookies or developer-console values for anyone who contacts you.

Those values may allow account access.

Phishing and Developer Tools Scams

A fake CAPTCHA or support page may tell you to:

Do not execute commands copied from an untrusted site.

This technique can install malware.

Phishing and Remote Desktop Tools

Scammers may request:

Remote tools are legitimate products, but installing them at the direction of an unsolicited caller is dangerous.

Phishing and Screen Sharing

A scammer may ask you to share your screen.

Your screen may reveal:

Do not screen-share sensitive accounts with an unverified person.

Phishing and QR Codes in Public Places

A malicious sticker can be placed over a legitimate QR code.

For parking or payment:

Phishing and NFC Tags

Physical tags can also open URLs.

Treat an unexpected NFC prompt like an unexpected QR code.

Verify before entering information.

Phishing Protection for High-Risk Accounts

Prioritize:

  1. Primary email
  2. Password manager
  3. Banking
  4. Mobile carrier
  5. Cloud storage
  6. Government/tax
  7. Business administrator accounts
  8. Social media

Use the strongest authentication these services support.

Personal Phishing Incident Log

If you were targeted repeatedly, keep:

Patterns may become visible over time.

Business Phishing Incident Log

Businesses should record:

Incident records improve future defenses.

Phishing Recovery: First 15 Minutes

If you interacted:

  1. Stop.
  2. Disconnect from scammer.
  3. Secure affected account.
  4. Revoke sessions.
  5. Contact financial provider if money involved.
  6. Notify IT for business systems.

Speed matters.

Phishing Recovery: First Hour

Phishing Recovery: First Day

Phishing Recovery: First Week

When to Consider Identity-Theft Recovery

If a phishing scam obtained identity information and it is misused, transition from phishing response to identity-theft recovery.

Examples:

In the U.S., IdentityTheft.gov provides recovery planning.

When to Contact Law Enforcement

Consider law enforcement when:

Preserve evidence.

When to Contact a Cybersecurity Professional

Seek help when:

Phishing Protection for Remote Employees

Remote employees should:

Phishing Protection for Executives

Executives are attractive targets.

Protect:

Organizations should create verification processes that apply even to executives.

Phishing Protection for Finance Teams

Finance teams should require:

This reduces dependence on email trust.

Phishing Protection for HR Teams

HR handles valuable identity data.

Protect:

Require secure workflows for sensitive changes.

Phishing Protection for IT Help Desks

Help desks are targets for social engineering.

Use strong identity-verification procedures for:

A weak support process can bypass strong authentication.

Phishing Protection for Developers

Developers may be targeted for:

Use phishing-resistant authentication and hardware-backed methods where practical.

Phishing Protection for Domain Administrators

Domain registrars and DNS providers can control business identity.

Use:

Phishing Protection for Content Creators

Creators may receive:

Use a separate business contact channel and verify contracts and attachments.

Phishing Protection for Travelers

Travel-related scams may imitate:

Use official apps and reservation records.

Phishing Protection for Online Shoppers

Use:

Do not trust refund or delivery texts without verification.

Phishing Protection for Parents

Teach children to bring unusual messages to an adult.

Protect:

Phishing Protection for Older Adults and Caregivers

Create a trusted verification plan.

Examples:

Build a Family Verification Phrase

Choose a phrase not posted online.

Use it when:

Do not rely solely on voice.

Build a Business Verification Phrase

For extremely sensitive actions, organizations may use predetermined procedures or challenge-response methods.

Avoid static secrets that become widely shared.

Process-based controls are generally stronger.

Why "Trust but Verify" Is Not Enough

For phishing, a better principle is:

Verify before trusting.

The message itself is untrusted input.

Independent verification creates trust.

The Zero-Click Habit

For critical accounts, develop a habit:

Do not log in from an unsolicited link.

Instead:

This eliminates many phishing opportunities.

The No-Code-Sharing Rule

Never share:

with someone who contacted you unexpectedly.

The No-Remote-Access Rule

Do not install remote-control software for unsolicited support.

The No-Payment-Change-by-Email Rule

Businesses should never change bank details solely from email instructions.

The Known-Channel Rule

Verify through a channel established before the suspicious message.

The Two-Person Rule

For high-value business transactions, require another authorized person.

Monthly Phishing Security Review

Once a month:

Quarterly Business Phishing Review

Review:

Annual Phishing Resilience Review

Ask:

Phishing Protection Scorecard

AreaStrong practice
Unexpected messagesIndependent verification
PasswordsUnique and manager-generated
MFAEnabled
High-value authenticationPhishing-resistant where supported
Primary emailStrongest protection
PaymentsIndependent callback/dual approval
QR codesDestination verified
Remote accessNever from unsolicited contact
RecoveryCurrent and protected
ReportingPrompt

Frequently Asked Questions

What is phishing?

Phishing is social engineering in which an attacker impersonates a trusted person or organization to trick someone into revealing information, sending money, installing software, or authorizing access.

How can I tell if an email is phishing?

Look at the requested action, sender domain, context, urgency, links, attachments, and whether the message can be verified independently. Professional writing and familiar branding do not prove legitimacy.

What should I do with a suspicious link?

Do not click it. Open the company's official app or type a known website address yourself.

Can phishing happen through text messages?

Yes. Text-message phishing is commonly called smishing.

Can phishing happen over the phone?

Yes. Voice phishing is commonly called vishing.

Are QR codes safe?

QR codes are an encoding mechanism, not a security guarantee. Preview and verify the destination before entering information.

Does HTTPS mean a website is legitimate?

No. HTTPS protects the connection to the website; fraudulent sites can also use HTTPS.

Does MFA stop phishing?

MFA greatly improves security, but some methods can still be phished. NIST states that manually entered one-time codes are not phishing-resistant.

What is phishing-resistant MFA?

It is authentication designed to prevent valid authentication secrets or outputs from being disclosed to an impostor. Properly implemented FIDO/WebAuthn authenticators and passkeys can provide phishing resistance.

What should I do if I entered my password on a phishing site?

Go to the legitimate site directly, change the password immediately, change reused passwords, revoke sessions, review MFA and recovery settings, and monitor account activity.

What if I entered an authentication code?

Treat the account as potentially compromised. Change the password, revoke sessions, review MFA devices, and inspect recent account activity.

What if I clicked a link but entered nothing?

Close the page, avoid downloads, update your device and browser, and investigate if anything was downloaded or installed.

What if I downloaded an attachment?

Do not execute it further. Use trusted security tools and contact IT if it is a work device.

What if I sent money to a scammer?

Contact the bank, card issuer, payment service, or other financial provider immediately. Recovery options depend on the payment method and speed of reporting.

Can a scammer spoof caller ID?

Yes. Caller ID is not reliable proof of identity.

Can AI make phishing harder to detect?

Yes. AI can improve grammar, translation, personalization, voice imitation, and message variation. Verification habits are more reliable than spelling-error detection.

Should I use temporary email to avoid phishing?

Temporary email can reduce exposure of your permanent address for low-risk disposable registrations, but it does not make a fraudulent website safe.

Can a VPN stop phishing?

No. A VPN changes network routing but cannot stop a user from entering credentials into a fraudulent website.

Can antivirus stop phishing?

Antivirus can help detect malware, but it cannot prevent every credential theft or fraudulent payment.

How should a business verify a vendor bank-account change?

Use an independently known phone number or established verification process, not the contact details supplied in the change request.

Why do scammers ask for authentication codes?

Authentication codes may allow them to complete a login after obtaining a password.

Should I trust a message that knows my name and account details?

No. Real personal information may come from breaches, data brokers, public records, or previous compromise.

How do I report phishing?

Use the reporting tools provided by your email, mobile, social, or business platform and, in the U.S., report fraud to the FTC through ReportFraud.ftc.gov.

What is the best single habit for avoiding phishing?

Do not act through unexpected messages. Verify sensitive requests using a trusted channel you reached independently.

Final Recommendations

Phishing succeeds when a message controls the victim's next action.

The safest habit is to separate the message from the action.

If an email says your bank account is locked, do not use the email link. Open the banking app.

If a text says you owe a toll, do not pay through the text. Visit the official agency.

If your boss requests a wire, verify through a known internal process.

If a caller says your computer is infected, do not install remote-access software. Contact support independently.

If a website asks for an authentication code, confirm that you intentionally initiated the login.

Strong technical controls matter. Use unique passwords, a password manager, MFA, and phishing-resistant authentication where available. Protect your primary email and recovery methods. Keep devices updated. But technology should reinforce a simple human rule:

Unexpected requests deserve independent verification.

That rule works across email, text, phone, QR codes, search results, social media, and whatever phishing channel appears next.

Continue Learning

Additional guides in PLANNED_RELATED_GUIDES should be activated only after their URLs are confirmed live in an updated FreeTempTools sitemap.

Frequently asked questions

What is phishing?

Phishing is social engineering in which an attacker impersonates a trusted person or organization to trick someone into revealing information, sending money, installing software, or authorizing access.

How can I tell if an email is phishing?

Examine the requested action, sender domain, context, urgency, links, attachments, and whether the request can be verified independently. Professional writing and familiar branding do not prove legitimacy.

What should I do with a suspicious link?

Do not click it. Open the company's official app or type a known website address yourself.

Can phishing happen through text messages?

Yes. Text-message phishing is commonly called smishing.

Can phishing happen over the phone?

Yes. Voice phishing is commonly called vishing.

Are QR codes safe?

QR codes are an encoding mechanism, not a security guarantee. Preview and verify the destination before entering information.

Does HTTPS mean a website is legitimate?

No. HTTPS protects the connection to the website; fraudulent sites can also use HTTPS.

Does MFA stop phishing?

MFA greatly improves security, but some methods can still be phished. NIST states that manually entered one-time codes are not phishing-resistant.

What is phishing-resistant MFA?

It is authentication designed to prevent valid authentication secrets or outputs from being disclosed to an impostor. Properly implemented FIDO/WebAuthn authenticators and passkeys can provide phishing resistance.

What should I do if I entered my password on a phishing site?

Go to the legitimate site directly, change the password immediately, change reused passwords, revoke sessions, review MFA and recovery settings, and monitor account activity.

What if I entered an authentication code?

Treat the account as potentially compromised. Change the password, revoke sessions, review MFA devices, and inspect recent account activity.

What if I clicked a link but entered nothing?

Close the page, avoid downloads, update your device and browser, and investigate if anything was downloaded or installed.

What if I downloaded an attachment?

Do not execute it further. Use trusted security tools and contact IT if it is a work device.

What if I sent money to a scammer?

Contact the bank, card issuer, payment service, or other financial provider immediately. Recovery options depend on the payment method and speed of reporting.

Can a scammer spoof caller ID?

Yes. Caller ID is not reliable proof of identity.

Can AI make phishing harder to detect?

Yes. AI can improve grammar, translation, personalization, voice imitation, and message variation. Verification habits are more reliable than spelling-error detection.

Should I use temporary email to avoid phishing?

Temporary email can reduce exposure of your permanent address for low-risk disposable registrations, but it does not make a fraudulent website safe.

Can a VPN stop phishing?

No. A VPN changes network routing but cannot stop a user from entering credentials into a fraudulent website.

Can antivirus stop phishing?

Antivirus can help detect malware, but it cannot prevent every credential theft or fraudulent payment.

How should a business verify a vendor bank-account change?

Use an independently known phone number or established verification process, not the contact details supplied in the change request.

Why do scammers ask for authentication codes?

Authentication codes may allow them to complete a login after obtaining a password.

Should I trust a message that knows my name and account details?

No. Real personal information may come from breaches, data brokers, public records, or previous compromise.

How do I report phishing?

Use the reporting tools provided by your email, mobile, social, or business platform and, in the U.S., report fraud to the FTC through ReportFraud.ftc.gov.

What is the best single habit for avoiding phishing?

Do not act through unexpected messages. Verify sensitive requests using a trusted channel you reached independently.

Authoritative references

Protect your inbox

Use a disposable address for the sign-ups that do not deserve your real one, and keep your personal email for accounts you need to keep.

Open Temp Mail →

Related guides