How to Spot Phishing
Phishing is one of the most widespread and dangerous cyber threats. Unlike other attacks, which seek to exploit technical vulnerabilities, phishing aims to use social engineering to trick people into clicking links, visiting fake websites or sharing sensitive information.
The goal is to steal account numbers, passwords and Social Security numbers. This data can be used to empty a checking account, run up bills on credit cards or even do damage to your personal reputation that may take years to repair. It can also be sold to other criminals who may use it to commit more serious crimes such as identity theft and tax fraud.
Often, the message is designed to overwhelm your better judgement with fear or urgency. For example, a message claiming that your bank account will be shut down or you’ll lose your money is meant to overcome your good judgment and force you to act quickly and click a link. This is also a common technique used in ransomware attacks, where hackers threaten to destroy data or shut down your computer until you pay them a sum of money.
The grammar, spelling and format of the email can be another warning sign. Legitimate communications from banks, credit card companies or payment services will often be well written and address you by name. Phishers are often international and work in multiple languages, so grammatical errors or inconsistencies can be a red flag. Using search engines to verify unfamiliar websites and typing the site URL directly into your browser instead of following a link can help you determine if it’s legitimate. And always enable multifactor authentication for any accounts that offer it.