Phishing attacks surged over 1,200% in 2025, driven by AI tools that generate flawless, personalized scam messages at scale. The old advice — "look for bad grammar and typos" — no longer works. AI-generated phishing has a 54% click-through rate compared to 12% for traditional phishing. This guide teaches you the new red flags and how to protect yourself.
AI-generated phishing looks perfect — no typos, proper branding, correct formatting. The new red flag is what the message asks you to do. Any message that creates urgency ("Your account will be locked!", "Act within 24 hours!", "Suspicious login detected!") and asks you to click a link or provide credentials is suspect — even if it looks exactly like it came from your bank, Apple, or Amazon. Legitimate companies almost never email you with urgent demands to click a link.
Before clicking any link in an email, hover your cursor over it (don't click). Your browser or email client will show the actual URL. Check: does the domain match the real company? paypal.com is real. paypa1-secure.com or paypal.com.account-verify.xyz is not. Attackers use subtle misspellings, extra words, and different top-level domains to fool you. If in doubt, don't click the link — open your browser and go directly to the company's website by typing the address yourself.
The display name can say anything — "Apple Support," "Your Bank," "Netflix." Click or tap the sender's name to reveal the actual email address behind it. A real Apple email comes from @apple.com. A phishing attempt might come from apple-support@secure-notification.com or noreply@apple.co.xyz. If the domain after the @ doesn't match the real company domain exactly, it's a scam.
This is the golden rule: never log into any account by clicking a link in an email or text message. If you receive a message saying there's a problem with your account, open a new browser tab and navigate to the service directly by typing the URL. Log in from there. If there's actually a problem, you'll see it in your account dashboard. This one habit alone blocks the vast majority of phishing attacks.
Attackers can now clone someone's voice from as little as 3 seconds of audio. If you receive an unexpected phone call from a family member, boss, or friend asking for money, passwords, or personal information — especially with urgency — hang up and call them back at their known number. Don't trust the number on your caller ID; it can be spoofed. Deepfake video calls are also emerging. If something feels off about a video call, verify through a separate channel.
"Quishing" (QR code phishing) is growing rapidly. Attackers place malicious QR codes on flyers, parking meters, restaurant tables, and in emails. When scanned, they redirect to fake login pages. Before scanning any QR code: consider the source. If it's a sticker placed over another QR code, or in an unexpected location, don't scan it. If you do scan one, check the URL your phone shows before proceeding. Never enter credentials on a page reached via a QR code you didn't expect.
Even if an attacker gets your password through a phishing page, 2FA stops them from logging in. But not all 2FA is equal — SMS codes can be intercepted via SIM-swap attacks. Use an authenticator app (Ente Auth, Aegis) or ideally a hardware security key (YubiKey) for your most critical accounts. Hardware keys are the only 2FA method that's truly phishing-proof because they verify the website's domain before authenticating — a fake login page simply won't work.
Your password manager will only autofill credentials on the correct domain. If you land on a phishing page that looks exactly like your bank's login but is actually on a different domain, your password manager won't offer to fill in your password. That silence is a signal — if your password manager doesn't recognize the site, you probably shouldn't enter your credentials there. This is one of the most underrated security benefits of using a password manager.
Reporting helps protect others. Forward phishing emails to reportphishing@apwg.org (the Anti-Phishing Working Group). If it impersonates a specific company, also forward it to that company's abuse address (e.g., phishing@paypal.com). In Gmail, click the three dots → "Report phishing." On your phone, report phishing texts by forwarding them to 7726 (SPAM). If you already clicked a link or entered credentials, immediately change your password and follow our "What to Do If You've Been Hacked" guide.
If you've received a message you're unsure about, or you think you may have already clicked a phishing link, we can help you assess the situation and secure your accounts before any damage is done.