Home AI Threats Free Help Services About IT Support Contact Book Consultation →
Back to Free Help
15 minutes9 steps

How to Spot & Avoid Phishing Scams

Phishing attacks surged over 1,200% in 2025, driven by AI tools that generate flawless, personalized scam messages at scale. The old advice — "look for bad grammar and typos" — no longer works. AI-generated phishing has a 54% click-through rate compared to 12% for traditional phishing. This guide teaches you the new red flags and how to protect yourself.

1

Focus on what it asks, not how it looks

AI-generated phishing looks perfect — no typos, proper branding, correct formatting. The new red flag is what the message asks you to do. Any message that creates urgency ("Your account will be locked!", "Act within 24 hours!", "Suspicious login detected!") and asks you to click a link or provide credentials is suspect — even if it looks exactly like it came from your bank, Apple, or Amazon. Legitimate companies almost never email you with urgent demands to click a link.

2

Hover over links before clicking

Before clicking any link in an email, hover your cursor over it (don't click). Your browser or email client will show the actual URL. Check: does the domain match the real company? paypal.com is real. paypa1-secure.com or paypal.com.account-verify.xyz is not. Attackers use subtle misspellings, extra words, and different top-level domains to fool you. If in doubt, don't click the link — open your browser and go directly to the company's website by typing the address yourself.

On mobile: Press and hold a link (don't tap) to preview the URL. This is especially important because mobile screens hide the full URL.
3

Check the sender's actual email address

The display name can say anything — "Apple Support," "Your Bank," "Netflix." Click or tap the sender's name to reveal the actual email address behind it. A real Apple email comes from @apple.com. A phishing attempt might come from apple-support@secure-notification.com or noreply@apple.co.xyz. If the domain after the @ doesn't match the real company domain exactly, it's a scam.

4

Never enter credentials from an email link

This is the golden rule: never log into any account by clicking a link in an email or text message. If you receive a message saying there's a problem with your account, open a new browser tab and navigate to the service directly by typing the URL. Log in from there. If there's actually a problem, you'll see it in your account dashboard. This one habit alone blocks the vast majority of phishing attacks.

This applies even if you're "sure" the email is real. Sophisticated phishing can perfectly replicate legitimate emails. Going directly to the website costs you 10 seconds and eliminates the risk entirely.
5

Watch for AI voice cloning and deepfakes

Attackers can now clone someone's voice from as little as 3 seconds of audio. If you receive an unexpected phone call from a family member, boss, or friend asking for money, passwords, or personal information — especially with urgency — hang up and call them back at their known number. Don't trust the number on your caller ID; it can be spoofed. Deepfake video calls are also emerging. If something feels off about a video call, verify through a separate channel.

6

Be suspicious of QR codes from unknown sources

"Quishing" (QR code phishing) is growing rapidly. Attackers place malicious QR codes on flyers, parking meters, restaurant tables, and in emails. When scanned, they redirect to fake login pages. Before scanning any QR code: consider the source. If it's a sticker placed over another QR code, or in an unexpected location, don't scan it. If you do scan one, check the URL your phone shows before proceeding. Never enter credentials on a page reached via a QR code you didn't expect.

7

Enable phishing-resistant 2FA

Even if an attacker gets your password through a phishing page, 2FA stops them from logging in. But not all 2FA is equal — SMS codes can be intercepted via SIM-swap attacks. Use an authenticator app (Ente Auth, Aegis) or ideally a hardware security key (YubiKey) for your most critical accounts. Hardware keys are the only 2FA method that's truly phishing-proof because they verify the website's domain before authenticating — a fake login page simply won't work.

8

Let your password manager be your phishing detector

Your password manager will only autofill credentials on the correct domain. If you land on a phishing page that looks exactly like your bank's login but is actually on a different domain, your password manager won't offer to fill in your password. That silence is a signal — if your password manager doesn't recognize the site, you probably shouldn't enter your credentials there. This is one of the most underrated security benefits of using a password manager.

9

Report phishing attempts

Reporting helps protect others. Forward phishing emails to reportphishing@apwg.org (the Anti-Phishing Working Group). If it impersonates a specific company, also forward it to that company's abuse address (e.g., phishing@paypal.com). In Gmail, click the three dots → "Report phishing." On your phone, report phishing texts by forwarding them to 7726 (SPAM). If you already clicked a link or entered credentials, immediately change your password and follow our "What to Do If You've Been Hacked" guide.

Worried about a suspicious message or call?

If you've received a message you're unsure about, or you think you may have already clicked a phishing link, we can help you assess the situation and secure your accounts before any damage is done.

Contact Us