
How to back up your phone and computer with the 3-2-1 rule
Learn the 3-2-1 backup rule and how to back up your iPhone, Android phone, Windows PC and Mac, so a lost device or dead drive never takes your files.
Cybersecurity · How-to
How to spot phishing in emails, texts, calls and QR codes, including AI voice-clone scams, plus a step-by-step plan for what to do if you clicked.

Key takeaways
Phishing is any message, call or code that pretends to come from someone you trust so you’ll hand over a password, a payment or access to your device. You can catch most of it by slowing down, knowing a handful of red flags and checking through a channel you already know is real. If you’ve already clicked, jump to the step-by-step plan below.
Whatever the channel, the script barely changes. The FTC’s guide to avoiding scams boils it down to four signs:
Add one more: a request for something only you should have, such as a password, a verification code or remote access to your computer. Apple says it will never ask for your password, device passcode or two-factor authentication code.
Here are the most common tricks by channel, based on FTC, CISA and FBI guidance.
| Channel | Common hooks | Red flags | Safer move |
|---|---|---|---|
| Account alert, invoice, refund, shared document | Sender address doesn’t match the company, generic greeting, unexpected attachment, link that doesn’t match its text | Open the company’s app or type its web address yourself | |
| Text message | Missed delivery, unpaid toll, bank fraud alert, prize | Unknown number, short or odd link, deadline or late fee | Don’t reply; report it as junk and forward it to 7726 |
| Phone call or voicemail | Bank fraud team, tech support, government agency, family emergency | Asks for a code, remote access, or payment by gift card or crypto | Hang up and call back on a number you already know |
| QR code | Parking meter, flyer, package notice, email or text | Sticker placed over another code, code in a message you didn’t expect | Use the official app or website instead of scanning |
The sender name in your inbox can say anything, so check the actual address behind it. The FTC’s phishing guide flags generic greetings, fake “suspicious activity” warnings and invoices you don’t recognize, and notes that “legitimate companies won’t email or text with a link to update your payment information.” Some fake invoices list a phone number to call instead of a link. That number reaches the scammer.
In 2024 the FBI warned about texts claiming people owed unpaid road tolls and linking to fake payment sites. The FTC’s advice on spam texts is blunt: legitimate companies won’t ask for information about your account by text.
Caller ID is easy to fake, so a call can look like it’s from your bank and still be a scam. Treat anyone who asks you to read out a code, install an app that lets them control your computer, or move your money as a scammer until you’ve confirmed otherwise.
The FTC warns that scammers stick their own QR codes over real ones on parking meters and send codes by email and text. The code can open a fake login page or install malware. Most phone cameras show the web address before opening it, so read it first.
Clumsy spelling used to be a giveaway. CISA’s phishing guidance now warns that in the era of AI, some phishing emails will have perfect grammar and spelling, so watch for the other signs.
In a December 2024 public service announcement, the FBI said criminals use generative AI to write convincing messages, create fake profile photos and ID documents, clone voices and even run real-time video chats posing as executives or law enforcement. The FTC explains that a scammer may need only a short clip of a family member’s voice, which can come from content posted online. In May 2025 the FBI also warned about AI-generated voice messages impersonating senior US officials.
You can’t reliably out-listen a good clone, so check the story instead:
The safest way to check a link is not to use it. If a message says your account has a problem, open the company’s app or type its address yourself, as the FTC advises.
When you do need to look at a link:
paypal.com.account-check.net/login, the real site is account-check.net, not PayPal.Two tools do some of this checking for you. A password manager won’t autofill your saved login on a lookalike domain, which is a useful alarm bell. And passkeys only work on the real site they were created for, so a fake page gets nothing it can reuse.
Clicking a link isn’t a disaster on its own. What matters is what came next: whether you typed in a password, shared card details, downloaded a file, let someone connect to your device or sent money. Work through these steps and skip any that don’t apply.
Close the page, and don’t reply or call any number the message lists. If you downloaded a file or gave someone remote access, the FTC’s malware guidance says to stop signing in to online accounts, like shopping or banking, right away. Don’t use that device for them until it’s clean.
Go to the website or app yourself and create a new, strong password. Change it anywhere else you reused it, and change your email password too, since email is the key to resetting everything else. If you suspect malware, use a different device you trust. If you’re locked out, the FTC’s guide for scam victims says to follow the site’s account recovery steps.
Turn on multifactor authentication (MFA) so a stolen password alone isn’t enough. Our guide to two-factor authentication methods explains which options resist phishing best. In the account’s security settings, sign out other sessions, remove devices you don’t recognize and confirm the recovery email and phone number are yours. In your email, check for forwarding rules you didn’t set up.
Update your security software and run a scan, as the FTC recommends. On Windows, Microsoft says to run a quick scan in Windows Security right away if you suspect malware. On Android, Google Play Protect checks apps and periodically scans your device. On any device, install the latest software update and remove apps you don’t recognize.
Use the number on the back of your card, never one from the message. The FTC says to report the problem right away and ask for the payment to be reversed. For gift cards, contact the card’s issuer immediately and keep the card and receipt. If you shared your Social Security number, go to IdentityTheft.gov; if it’s been misused, you’ll get a customized recovery plan. Also consider a free credit freeze with each of the three bureaus: Equifax, Experian and TransUnion.
Reporting helps block the next wave:
reportphishing@apwg.org, as the FTC suggests. Fakes posing as Apple can go to reportphishing@apple.com.Scammers sometimes return pretending to help. The FTC warns about recovery scams, where someone offers to get your money back for an upfront fee: “That’s a scammer.” The IC3 also says it will never contact you directly for information or money. Watch your statements and account activity for the next few weeks.
Phishing works by rushing you, so slow down. Treat any unexpected message that asks for a login, a code or a payment as suspect, and check it through an app, website or phone number you already trust. If you do slip up, act quickly: secure the account, scan the device, call your bank and report it. For more plain-English security help, browse our cybersecurity guides or visit RedAndWhiteMagz.com.
Opening a phishing email usually isn't enough to harm your device, especially if your email app and operating system are up to date. The real risk comes from clicking links, opening attachments, scanning codes or replying with information. Report it as phishing in your email app and delete it.
It's better not to. CISA advises deleting suspicious messages without replying or using unsubscribe links, and any reply tells the sender someone is reading. Report the text with your messaging app's junk option or forward it to 7726, then delete it.
Yes. The FTC says scammers use technology to change the phone number that appears on caller ID, and the sender name shown in an email can be set to anything. That's why you should hang up and call back on a number you already know, or check the account through the company's own app.
No. A verification code is meant to be typed into the real app or website by you, and anyone asking you to read one out is probably trying to sign in to your account. Apple, for example, says it will never ask for your two-factor authentication code. Hang up and call the number on the back of your card.
First published . Spotted an error? Read our editorial policy and tell us.
Contact RedAndWhiteMagz.com
Spotted a new gadget, a scam making the rounds or a mistake in one of our guides? Tell us. We read every message and reply as quickly as we can.
