Cybersecurity · How-to

How to spot a phishing message, and what to do if you clicked

How to spot phishing in emails, texts, calls and QR codes, including AI voice-clone scams, plus a step-by-step plan for what to do if you clicked.

Hands tapping a smartphone screen in a dark room, lit only by the phone's glow

Key takeaways

  • Most scams impersonate someone you trust, invent a problem or prize, rush you, and push a hard-to-reverse payment method.
  • Never use the link, phone number or QR code in an unexpected message; open the company's app or website yourself.
  • Perfect grammar and a familiar voice no longer prove a message is genuine, so confirm it through a channel you already trust.
  • If you clicked, secure the account on the real site, turn on multifactor authentication, scan your device and call your bank if money is involved.
  • Forward scam texts to 7726 and report fraud to the FTC at ReportFraud.ftc.gov.

Phishing is any message, call or code that pretends to come from someone you trust so you’ll hand over a password, a payment or access to your device. You can catch most of it by slowing down, knowing a handful of red flags and checking through a channel you already know is real. If you’ve already clicked, jump to the step-by-step plan below.

The four signs almost every scam shares

Whatever the channel, the script barely changes. The FTC’s guide to avoiding scams boils it down to four signs:

  1. They pretend to be someone you know, such as a bank, delivery company, government agency or relative.
  2. They say there’s a problem or a prize, like a locked account, an unpaid bill or a refund.
  3. They pressure you to act right now. In the FTC’s words, scammers “want you to act before you have time to think.”
  4. They tell you how to pay. Gift cards, cryptocurrency, wire transfers and payment apps are favorites because the money is often hard to get back.

Add one more: a request for something only you should have, such as a password, a verification code or remote access to your computer. Apple says it will never ask for your password, device passcode or two-factor authentication code.

Red flags by channel: email, texts, calls and QR codes

Here are the most common tricks by channel, based on FTC, CISA and FBI guidance.

Channel Common hooks Red flags Safer move
Email Account alert, invoice, refund, shared document Sender address doesn’t match the company, generic greeting, unexpected attachment, link that doesn’t match its text Open the company’s app or type its web address yourself
Text message Missed delivery, unpaid toll, bank fraud alert, prize Unknown number, short or odd link, deadline or late fee Don’t reply; report it as junk and forward it to 7726
Phone call or voicemail Bank fraud team, tech support, government agency, family emergency Asks for a code, remote access, or payment by gift card or crypto Hang up and call back on a number you already know
QR code Parking meter, flyer, package notice, email or text Sticker placed over another code, code in a message you didn’t expect Use the official app or website instead of scanning

Email

The sender name in your inbox can say anything, so check the actual address behind it. The FTC’s phishing guide flags generic greetings, fake “suspicious activity” warnings and invoices you don’t recognize, and notes that “legitimate companies won’t email or text with a link to update your payment information.” Some fake invoices list a phone number to call instead of a link. That number reaches the scammer.

Text messages

In 2024 the FBI warned about texts claiming people owed unpaid road tolls and linking to fake payment sites. The FTC’s advice on spam texts is blunt: legitimate companies won’t ask for information about your account by text.

Phone calls and voicemail

Caller ID is easy to fake, so a call can look like it’s from your bank and still be a scam. Treat anyone who asks you to read out a code, install an app that lets them control your computer, or move your money as a scammer until you’ve confirmed otherwise.

QR codes

The FTC warns that scammers stick their own QR codes over real ones on parking meters and send codes by email and text. The code can open a fake login page or install malware. Most phone cameras show the web address before opening it, so read it first.

AI-written scams and voice cloning

Clumsy spelling used to be a giveaway. CISA’s phishing guidance now warns that in the era of AI, some phishing emails will have perfect grammar and spelling, so watch for the other signs.

In a December 2024 public service announcement, the FBI said criminals use generative AI to write convincing messages, create fake profile photos and ID documents, clone voices and even run real-time video chats posing as executives or law enforcement. The FTC explains that a scammer may need only a short clip of a family member’s voice, which can come from content posted online. In May 2025 the FBI also warned about AI-generated voice messages impersonating senior US officials.

You can’t reliably out-listen a good clone, so check the story instead:

  • Agree on a family safe word. The FBI recommends a secret word or phrase that confirms who’s really calling.
  • Hang up and call back on a number you already have, not the one that called you.
  • Treat secrecy and speed as warnings. “Don’t tell anyone” and “I need it in an hour” are pressure tactics.
  • Look closely at photos and video. Our guide to spotting AI-generated images covers the clues, though the best fakes may show none.

The safest way to check a link is not to use it. If a message says your account has a problem, open the company’s app or type its address yourself, as the FTC advises.

When you do need to look at a link:

  • Preview before you tap. On a computer, hover over the link and check the address that appears, as Google suggests. On a phone, pressing and holding a link usually reveals the address, though some apps also load a preview of the page.
  • Find the real domain. Look at the part just before the first single slash after “https://”. In paypal.com.account-check.net/login, the real site is account-check.net, not PayPal.
  • Watch for lookalikes. CISA’s example is “amazan.com” instead of amazon.com.
  • Distrust shortened links. CISA lists untrusted shortened URLs as a red flag, since they can hide where you’re headed.
  • Don’t trust the padlock alone. A padlock or “https” means the connection is encrypted, not that the site is honest.

Two tools do some of this checking for you. A password manager won’t autofill your saved login on a lookalike domain, which is a useful alarm bell. And passkeys only work on the real site they were created for, so a fake page gets nothing it can reuse.

What to do if you clicked: a step-by-step plan

Clicking a link isn’t a disaster on its own. What matters is what came next: whether you typed in a password, shared card details, downloaded a file, let someone connect to your device or sent money. Work through these steps and skip any that don’t apply.

1. Stop and don’t enter anything else

Close the page, and don’t reply or call any number the message lists. If you downloaded a file or gave someone remote access, the FTC’s malware guidance says to stop signing in to online accounts, like shopping or banking, right away. Don’t use that device for them until it’s clean.

2. Change your password on the real site

Go to the website or app yourself and create a new, strong password. Change it anywhere else you reused it, and change your email password too, since email is the key to resetting everything else. If you suspect malware, use a different device you trust. If you’re locked out, the FTC’s guide for scam victims says to follow the site’s account recovery steps.

3. Turn on multifactor authentication and look for changes

Turn on multifactor authentication (MFA) so a stolen password alone isn’t enough. Our guide to two-factor authentication methods explains which options resist phishing best. In the account’s security settings, sign out other sessions, remove devices you don’t recognize and confirm the recovery email and phone number are yours. In your email, check for forwarding rules you didn’t set up.

4. Scan your device

Update your security software and run a scan, as the FTC recommends. On Windows, Microsoft says to run a quick scan in Windows Security right away if you suspect malware. On Android, Google Play Protect checks apps and periodically scans your device. On any device, install the latest software update and remove apps you don’t recognize.

5. Call your bank or card issuer if money is involved

Use the number on the back of your card, never one from the message. The FTC says to report the problem right away and ask for the payment to be reversed. For gift cards, contact the card’s issuer immediately and keep the card and receipt. If you shared your Social Security number, go to IdentityTheft.gov; if it’s been misused, you’ll get a customized recovery plan. Also consider a free credit freeze with each of the three bureaus: Equifax, Experian and TransUnion.

6. Report it

Reporting helps block the next wave:

  • Texts: forward them to 7726 (SPAM) and use your messaging app’s report-junk option.
  • Emails: use your email app’s report-phishing button or forward them to reportphishing@apwg.org, as the FTC suggests. Fakes posing as Apple can go to reportphishing@apple.com.
  • Any scam: report it to the FTC at ReportFraud.ftc.gov.
  • Online fraud, especially if you lost money: file a complaint with the FBI’s Internet Crime Complaint Center (IC3).
  • Work accounts: tell your IT team, as CISA advises.

7. Watch for the follow-up scam

Scammers sometimes return pretending to help. The FTC warns about recovery scams, where someone offers to get your money back for an upfront fee: “That’s a scammer.” The IC3 also says it will never contact you directly for information or money. Watch your statements and account activity for the next few weeks.

The bottom line

Phishing works by rushing you, so slow down. Treat any unexpected message that asks for a login, a code or a payment as suspect, and check it through an app, website or phone number you already trust. If you do slip up, act quickly: secure the account, scan the device, call your bank and report it. For more plain-English security help, browse our cybersecurity guides or visit RedAndWhiteMagz.com.

Frequently asked questions

Is it dangerous to just open a phishing email?

Opening a phishing email usually isn't enough to harm your device, especially if your email app and operating system are up to date. The real risk comes from clicking links, opening attachments, scanning codes or replying with information. Report it as phishing in your email app and delete it.

Should I reply STOP to a scam text?

It's better not to. CISA advises deleting suspicious messages without replying or using unsubscribe links, and any reply tells the sender someone is reading. Report the text with your messaging app's junk option or forward it to 7726, then delete it.

Can scammers fake a phone number or email address?

Yes. The FTC says scammers use technology to change the phone number that appears on caller ID, and the sender name shown in an email can be set to anything. That's why you should hang up and call back on a number you already know, or check the account through the company's own app.

Is it safe to share a verification code if the caller says they're from my bank?

No. A verification code is meant to be typed into the real app or website by you, and anyone asking you to read one out is probably trying to sign in to your account. Apple, for example, says it will never ask for your two-factor authentication code. Hang up and call the number on the back of your card.

Sources

First published . Spotted an error? Read our editorial policy and tell us.

Contact RedAndWhiteMagz.com

Have a tech question or a story tip?

Spotted a new gadget, a scam making the rounds or a mistake in one of our guides? Tell us. We read every message and reply as quickly as we can.

Close-up of a black mechanical keyboard with glowing red backlit keys in a dark room