goJumboGPT

Security Scams: how they work and what to do if you fall for one

Phishing explained: how fake messages get past smart people

What phishing is, the psychology that makes it work, how targeted spear phishing differs, and the habits that protect you when you are tired and busy.

5 min read How we write

The short answer

  • Phishing is any message that borrows someone's identity to get a password, a code, a payment or permission from you.
  • It works on careful people because it targets your attention, not your knowledge.
  • Spelling mistakes and odd grammar are no longer reliable signals, so stop using them as your main test.
  • The habit that holds up everywhere is refusing to act from a link in a message you did not request.
  • If a login page appears right after you clicked a link, assume it is fake and close it.

Phishing is a message that pretends to come from someone you trust so that you will hand over something valuable: a password, a one time code, a payment, or permission to install software. It can arrive as email, a text, a chat message, a social media reply, a phone call or a QR code pasted over a real one. The channel matters much less than the request. If a message you did not ask for pushes you toward a link, a sign-in screen or a payment, treat it as phishing until you have checked through a route you chose yourself.

What the attacker is actually collecting

Almost every phishing message is after one of four things, and naming them makes the messages easier to sort.

The first is credentials. You land on a copy of a familiar sign-in page, type your email and password, and the page forwards them to the attacker, then often redirects you to the real site so nothing seems wrong.

The second is a one time code. Modern kits sit between you and the real service in real time, so the code you type is used within seconds, before it expires. This is why a code is worth stealing even though it lasts only 30 to 60 seconds.

The third is money, usually moved by you rather than stolen from you: an invoice with changed bank details, a fee to release a parcel, a transfer to a "safe account".

The fourth is access. An attachment or download installs something, usually one of the ordinary malware families, or a prompt asks you to approve an app's access to your mailbox, which quietly survives a password change.

Why intelligence is not the defense

People assume phishing works on the inattentive. It works on nearly everyone, because it does not attack what you know. It attacks the conditions you are in.

Urgency compresses thinking. A message that says your account closes in 24 hours, or that a payment of 480 dollars was just taken, moves you from judging to reacting. The same wording works in pounds or euros; only the currency symbol changes.

Authority borrows a name you already obey: your bank, a tax office, a delivery company, your own IT department, your chief executive.

Fear of loss is stronger than hope of gain. A blocked account, a suspended tax refund or a missed parcel will outperform a prize.

Routine is the quietest lever. If you approve invoices all day, an invoice does not stand out. Attackers deliberately send messages that match the boring parts of your job at the hour you do them, often Friday afternoon.

None of these care whether you have a doctorate. They care whether you are busy, which most people are.

Spear phishing: when the message is about you

Spear phishing is a message built from public information about a specific person. Your employer and job title come from a professional network, your manager's name from a company page, your travel from a conference post, your suppliers from a press release. The message then references things that are true, which is what makes it land.

The strongest version does not invent anything at all. Someone gains access to a mailbox at a company you deal with, finds a genuine conversation about a real payment, and replies inside it. The subject line, the signature, the earlier messages and the tone are authentic, because they are. Only the final instruction is new, usually a changed bank account or a link to a "revised" document.

That is why a message looking correct proves very little. Correctness is now cheap. The red flags checklist still has value, but it works best as a filter for volume, not as proof of safety.

The channels, and what each one hides

ChannelWhat it hidesThe reliable check
EmailThe real sending address, behind a friendly display nameExpand the sender, read the domain after the @
Text messageWhere the shortened link goesNever tap; open the company's app instead
Phone callThe caller ID, which the caller suppliesHang up, call the number on your card
Chat and DMsA hijacked account belonging to a real friendAsk them on another channel
QR codeEverything, until the page loadsCheck the domain before you enter anything

Understanding the address bar helps more than any of this: the part just before the first single slash is the real site, and everything before it can be anything the attacker wants. If that is new to you, the anatomy of a URL is worth ten minutes.

Four habits that survive better fakes

These are deliberately dull. Dull is what works when you are tired.

  1. Never act from an inbound link. Open a new tab and type the address yourself, or use the app on your phone. This single habit defeats most credential phishing regardless of how good the message looks.
  2. Verify any money or access request on a number you already had. Not the number in the message, not the number in the signature, and not the caller ID, which a caller can set to whatever they like. A number from your card, a statement or a previously saved contact.
  3. Treat a sign-in prompt that appears right after a click as hostile. Real sites do not usually ask you to log in again because you followed a link from your inbox. Close the tab, go to the site directly, and see whether you were signed in all along.
  4. Refuse to read out codes. No legitimate bank, courier, marketplace or IT department needs a code that was sent to you. The code exists specifically to prove it is you.

Reducing the damage before anything happens

Phishing gets far less profitable when a stolen password is not enough on its own. Two-factor authentication raises the cost of every theft, and passkeys go further, because the secret never leaves your device and a fake site cannot ask for it.

Also keep your recovery details current. Many takeovers are not discovered for weeks, and people lose accounts they could have saved because the backup email had not been used since 2019.

What to check first

If you think you have just been phished, start with what you typed, not what you clicked. Did you enter a password? Did you approve a prompt? Did a file download and open? Those three answers decide how urgent the next hour is. The step by step version is in what to do after clicking a phishing link, and doing it calmly, in order, matters far more than doing it fast.

Common questions

Is phishing only an email problem?

No. The same trick works over text message, WhatsApp, LinkedIn, Instagram, phone calls and QR codes stuck over real ones. The channel changes, the request does not: a link, a code, a payment or access to your device.

Can I get phished just by opening an email?

Opening a plain message is almost always harmless. The risk begins when you click a link, open an attachment, or type something into the page that opens. Most modern mail apps block remote images and scripts by default.

Why do scammers still send obvious junk?

Badly written mass mail filters out anyone cautious and leaves the people most likely to keep going. Targeted attacks on a business or a specific person look nothing like it and are usually flawless.

What if my password was already typed into a fake page?

Change that password from a different device, sign out all sessions, and check the account for new recovery addresses or forwarding rules. Then do the same anywhere you reused the password.