Scam Prevention

Spot & Stop Phishing Attacks

How to recognize fake emails, texts, and calls before they cause harm — and exactly what to do if you already clicked.

How this guide works

Phase 1 teaches you to recognize phishing across every channel. Phase 2 walks you through what to do if you clicked, entered credentials, or gave out personal info. Phase 3 covers how to report it. Phase 4 closes the gaps so it can't happen again.

Phase 1 of 4

Spot It — Recognize Phishing Before You Click

Phishing works because it looks real. These are the signals every family member should know.

1

The 5 red flags that appear in almost every phishing attempt

No single flag is definitive — real companies sometimes send rushed, poorly-written emails. But two or more flags in the same message is a strong signal to stop and verify before clicking anything.

  • Urgency or fear: "Your account will be suspended in 24 hours," "Unusual sign-in detected," "Immediate action required." Legitimate companies do not threaten instant consequences in email.
  • Sender address doesn't match: The display name says "Apple" but the actual email is support@apple-id-verify.net. Always click the sender name to reveal the real address.
  • Hover-over link mismatch: The link text says "Click here to verify" but hovering shows it goes to a different domain than the company. On mobile, hold-press a link to preview the URL.
  • Requests credentials, payment, or personal info: No legitimate company emails you asking for your password, SSN, or credit card number directly. Banks do not do this.
  • Generic greeting: "Dear Customer," "Dear Account Holder," or no greeting at all. Real account emails use your name.
2

Email phishing — what it looks like in the wild

Real examples of the patterns attackers use, and why they work.

Phishing example
From: "Apple Support" <no-reply@apple-securityalert.co>
Your Apple ID has been locked — verify now
We detected a sign-in attempt from an unrecognized device. Your account will be permanently disabled unless you verify within 12 hours. Click below to restore access.
⚠ Wrong domain (.co not apple.com) ⚠ Artificial urgency (12 hours) ⚠ Threat of permanent loss
Phishing example
From: "Chase Bank" <alerts@chase-secure-messages.com>
Suspicious transaction on your account — $847.00
We've placed a temporary hold on your account due to suspicious activity. To restore full access and dispute this charge, click here to verify your identity.
⚠ Not a chase.com address ⚠ Specific dollar amount creates panic ⚠ "Verify identity" = credential harvest
💡 The safe move: Never click the link in the email. Open a new browser tab and go directly to the company's website, or call the number on the back of your card. The message will still be there when you log in if it's real.
3

Text message phishing (smishing)

SMS phishing has surpassed email phishing in click-through rates because people are less skeptical of texts.

  • USPS, FedEx, and UPS do not text you unsolicited tracking links — if you got a delivery text you didn't sign up for, it's a smish.
  • Your bank will never text you a link to log in. They may text a verification code, but never a login link.
  • Short URLs (bit.ly, t.co, tinyurl) in texts hide the real destination — hold-press before clicking to preview on mobile.
  • "Reply STOP to unsubscribe" in a phishing text does the opposite — it confirms your number is active and increases targeting.
  • Government agencies (IRS, SSA, Medicare) contact you by mail first, not text.
⚠️ Common smishing scripts: "Your package could not be delivered. Update your address: [link]" / "Your bank account has been suspended. Verify now: [link]" / "You've been selected for a $1,000 reward. Claim here: [link]"
4

Phone call phishing (vishing)

Voice phishing is the hardest to dismiss in the moment — a real human voice feels authoritative.

  • Caller ID can be spoofed. A call from "Bank of America 800-432-1000" may not be from Bank of America.
  • Legitimate callers will never ask for your full SSN, PIN, or online banking password over the phone — not even your bank's fraud team.
  • Common scripts: "This is Microsoft/Windows support — we've detected a virus on your computer." "This is the IRS — you have a warrant for unpaid taxes." "This is Social Security — your number has been suspended."
  • If unsure: hang up and call back on the official number. A real institution will not pressure you to stay on the line.
  • Never let a stranger who called you access your computer remotely — no matter what they claim.
5

How to verify a suspicious message in under 2 minutes

  • Go directly to the company website (type it yourself, don't use the link in the message) and check your account — if the alert is real, it will appear in your account dashboard.
  • Call the official number from the company's real website or the back of your card.
  • Forward suspicious emails to the company's phishing report address (phishing@paypal.com, reportphishing@apple.com, abuse@amazon.com) — most major companies have one.
  • Check the sender's actual email domain against the company's real domain. One extra character or a different TLD (.net vs .com) is a giveaway.

Phase 2 of 4

If You Clicked — Act Fast, Don't Panic

What you do in the next 30 minutes determines how much damage gets done. Follow the steps that match what happened.

⚠️ First: disconnect from Wi-Fi if you downloaded anything or allowed remote access. If you only clicked a link and saw a webpage, staying connected is fine. If you downloaded a file, ran an attachment, or gave someone remote access — disconnect now, then work through the steps below.
1

I clicked a link but didn't enter anything

Clicking a link alone rarely installs malware on a fully-patched device. Your risk is low but not zero.

  • Close the browser tab immediately — do not go back to see what it loaded.
  • Make sure your browser and OS are up to date (Settings > Software Update on iPhone/Mac, Windows Update on PC).
  • Run a malware scan if you're on a computer: Windows Defender (built-in, free) or Malwarebytes Free.
  • If your browser shows any new extensions you didn't install, remove them immediately.
  • Monitor the accounts associated with whatever the phishing message claimed to be about over the next few days.
Modern browsers run in sandboxed tabs — a click without a download or login is usually contained. You likely caught it in time.
2

I entered my username and password

This is credential phishing — the most common outcome. Move fast; attackers use stolen credentials within minutes.

  • Change your password on the real account immediately — go directly to the site, do not use any link.
  • Enable two-factor authentication on that account right now if it isn't already on.
  • Sign out of all other sessions (most accounts have "Sign out everywhere" in security settings).
  • If you use the same password anywhere else, change it on every site — this is why password reuse is dangerous.
  • Check account activity for any logins, purchases, or changes you didn't make.
  • If it was your email account: change the password first, then check for forwarding rules or filters the attacker may have set up to silently copy future emails.
💡 Check email forwarding rules: Gmail > Settings > See all settings > Forwarding and POP/IMAP. Outlook: Settings > Mail > Forwarding. Attackers set these to receive a copy of every email you get, even after you change your password.
3

I entered credit card or financial information

  • Call the number on the back of your card immediately — report it as potentially compromised and request a replacement card.
  • Ask the fraud team to place a temporary hold on the account while a new card is issued.
  • Review recent transactions for any charges you don't recognize.
  • Set up transaction alerts if you haven't already — most banks offer real-time text/email alerts for any charge.
  • If you entered a bank account number or routing number, call the bank to discuss adding additional authentication requirements for outbound transfers.
4

I gave out my Social Security number or government ID

This is identity theft territory. Move through these steps today.

  • Place a free credit freeze at all three bureaus: Equifax, Experian, TransUnion. A freeze is free, doesn't affect your credit score, and prevents new accounts from being opened in your name.
  • File an identity theft report at IdentityTheft.gov — this creates a legal record and generates a recovery plan.
  • Check your credit reports at AnnualCreditReport.com for any accounts or inquiries you don't recognize.
  • If your SSN may have been used for tax fraud, file Form 14039 with the IRS to flag your account.
5

I downloaded a file or ran an attachment

This is the highest-risk scenario — downloaded files can install malware, keyloggers, or ransomware.

  • Disconnect from Wi-Fi or ethernet immediately to prevent any malware from phoning home or spreading to other devices on your network.
  • Do not use the device to log into any accounts until it has been scanned.
  • On Windows: boot into Safe Mode and run Windows Defender or Malwarebytes. On Mac: run Malwarebytes for Mac (free version covers this).
  • If the scan finds something it can't remove, or if behavior is still suspicious after cleaning: consult a professional. Do not attempt to continue using a compromised device for sensitive activity.
  • Change passwords for any account you were logged into on that device — from a different, clean device.
⚠️ Don't diagnose it yourself: If you downloaded and ran a .exe, .dmg, or .pkg file from an unknown source, assume the device is compromised. OhanaSecure can walk you through remediation — email us before taking further action on the device.
6

I gave remote access to my computer

Tech support scams almost always end here. The attacker likely installed software or viewed saved passwords.

  • Disconnect immediately — pull the ethernet cable or turn off Wi-Fi.
  • Uninstall any remote access software they asked you to install: AnyDesk, TeamViewer, UltraViewer, ScreenConnect, Zoho Assist.
  • Change every password stored in your browser — these are visible to anyone with screen access.
  • Change passwords on your email, bank, and any accounts you were logged into during the session — from a different device.
  • If they asked you to log into your bank "to verify your account," call your bank immediately.
  • Consider a full factory reset of the device if you're unsure what was installed — a clean slate is the only guarantee.

Phase 3 of 4

Report It — Create a Record and Protect Others

Reporting takes less than 10 minutes and creates documentation you may need later for banks, insurers, or law enforcement.

1

Report to the right agency for your situation

  • FTC (ReportFraud.ftc.gov): Start here for almost anything — phishing attempts, credential theft, fake websites. Takes about 5 minutes and creates a legal record banks accept.
  • FBI IC3 (ic3.gov): If money was actually transferred or lost, file here in addition to the FTC. The FBI aggregates IC3 reports to pursue organized phishing rings.
  • Anti-Phishing Working Group (reportphishing@apwg.org): Forward the phishing email here — APWG aggregates reports to get malicious domains taken down.
  • Your email provider: Gmail has a "Report phishing" option in the three-dot menu; Outlook has "Report" > "Report phishing." This helps train spam filters for everyone.
  • The impersonated company: Most major companies want to know when someone is impersonating them — find their security contact on their official site.
2

Preserve evidence before deleting anything

Screenshots and email headers are useful if you need to file a fraud claim or police report.

  • Screenshot the full phishing email or text, including the sender address and timestamp.
  • In Gmail: open the email, click the three-dot menu, select "Show original" to see the full headers — copy and save this.
  • Note the URL you were sent to, even if you didn't enter anything (check browser history).
  • Keep this documentation for at least 12 months — insurance claims and fraud disputes sometimes take time to surface.

Phase 4 of 4

Harden — Close the Gaps

Phishing works when one thing fails. These four changes make the whole household dramatically harder to compromise.

1

Remove yourself from data broker lists

Phishers don't pick targets at random. They buy data broker lists that include your name, email, phone number, home address, employer, and family members — all used to craft convincing, personalized attacks. Removing yourself from these lists reduces targeting upstream, before an attack ever happens.

  • Data brokers like Spokeo, WhitePages, BeenVerified, and hundreds of others aggregate and sell your personal info to anyone who pays.
  • A phishing email that uses your real name, your bank's name, and your city is far more convincing than a generic one — brokers make that possible.
  • Manual opt-outs exist but there are 200+ brokers and each requires a separate request. Automated removal services do this continuously.
  • Start with a free scan at Optery to see exactly how many brokers have your data before paying for anything.
2

Turn on two-factor authentication everywhere

Even if a phisher gets your password, 2FA stops them from getting in. Prioritize: email, bank, Apple ID / Google account. These are the keys to everything else.

  • Use an authenticator app (Authy, Google Authenticator) — not SMS/text codes, which can be intercepted.
  • If a site only offers SMS 2FA, it's still better than nothing — enable it.
  • Email and social accounts compromised via phishing would have been blocked by 2FA in nearly every case.
3

Use a password manager — stop reusing passwords

Credential phishing is only catastrophic when you use the same password in multiple places. A password manager generates and stores unique passwords for every site — you only remember one.

  • Every account gets its own unique password. If one is stolen, the damage is contained to that one account.
  • Password managers also warn you when you're about to enter credentials on a site that doesn't match the saved domain — a built-in phishing check.
4

Keep software and browsers updated

Browser exploits that allow drive-by infection from clicking a link are almost always patched in current versions. Being one update behind is enough to be vulnerable.

  • Turn on automatic updates for your OS, browser, and apps — all major platforms support this.
  • iPhone: Settings > General > Software Update > Automatic Updates. Android: Settings > System > System update.
  • On Mac: System Settings > General > Software Update > turn on "Install updates automatically."
  • On Windows: Settings > Windows Update > turn on "Get the latest updates as soon as they're available."
5

Talk to your household — especially seniors and kids

The most targeted people in a household are often the least warned. A 10-minute conversation prevents most phishing incidents.

  • Establish a household rule: call a family member before clicking any link that asks for login information or payment.
  • Seniors: remind them that Microsoft, Apple, and the IRS will never call unsolicited about a problem with your device or taxes. Hang up, then call a family member.
  • Kids and teens: teach them that urgent messages ("Your account will be deleted in 1 hour!") are designed to short-circuit thinking — pause and ask a parent.
  • Practice: send each other a fake "phishing test" — a link to Google with a convincing subject line — and see who catches it. No shame in clicking; it's training.
Questions?

Email hello@ohanasec.io — Andrew or Ashley will get back to you directly.

Get in Touch