Social Engineering & Phishing

Spotting Scams & Fake Messages

  • Beware of urgency triggers: Pause and verify any communication that demands immediate action out of fear, panic, or strict time limits. Fraudsters frequently manufacture false crises, such as claiming your debit card has been frozen due to fraud or that an unauthorized transfer is currently clearing. Taking a moment to pause disarms the high-pressure tactic, allowing you to check your account status calmly.
  • Inspect the sender’s actual address: Look closely at the actual domain name of the sender’s email address, not just the display name. Scammers can easily change their display name to look like a trusted institution. Verifying the exact domain suffix (ensuring it perfectly matches the official domain) prevents you from falling for deceptive look-alike emails.
  • Verify via an independent channel: If you receive a suspicious text or email claiming to be from an organization, contact them directly through a known, trusted method. If an alert claims to be from your bank or even an urgent directive from your supervisor regarding a wire transfer, do not reply to the message or use the numbers provided inside it. Look up the official customer service line independently to verify the request.
  • Be skeptical of AI-cloned voice calls: Establish a private family “safe word” to use if you receive an unexpected distress call claiming a loved one is in immediate trouble. Artificial intelligence allows criminals to clone a person’s voice using only a few seconds of audio. If a caller claims an emergency requires you to wire funds or send money via a peer-to-peer app, hang up immediately and dial that family member’s known number directly to confirm.
  • Watch out for “Smishing” (Text Phishing): Treat text messages containing clickable links with extreme caution. Deceptive texts disguised as delivery updates, tax rebates, employment opportunities, or urgent bank alerts are incredibly common. Clicking these links often sends you to spoofed login portals designed to capture your bank username, password, or MFA codes.
  • Do not trust Caller ID: Never assume a phone call is legitimate simply because the name on your screen matches a trusted identity. Phone numbers are easily spoofed. Cybercriminals can manipulate caller ID systems to display the exact name of local businesses, government agencies, or your financial institution when calling to fish for your personal data.
  • Inspect unknown links before clicking: Hover your cursor over a link to preview the actual destination URL before clicking it or navigate to websites manually. A link may read as an official login page in text, but hovering over it reveals an entirely malicious external address. Typing the official web address directly into your browser eliminates this risk.
  • Never grant remote access to unsolicited callers: Do not download remote desktop software or grant device access to anyone who contacts you out of the blue. Tech support scammers call pretending to represent major software companies, claiming your machine has a virus. Once you grant them remote control, they can look through your desktop files, log your keystrokes, and access open banking sessions.
  • Slow down and think twice: Dedicate 10 full seconds to rationally analyze a request before responding or providing data. High-pressure scams rely on catching you off guard. Giving yourself a tiny window of time to consciously step back helps you identify logical inconsistencies in a fraudster’s story before making an irreversible mistake.