How to recognize fake emails, texts, and calls before they cause harm — and exactly what to do if you already clicked.
Phase 1 teaches you to recognize phishing across every channel. Phase 2 walks you through what to do if you clicked, entered credentials, or gave out personal info. Phase 3 covers how to report it. Phase 4 closes the gaps so it can't happen again.
No single flag is definitive — real companies sometimes send rushed, poorly-written emails. But two or more flags in the same message is a strong signal to stop and verify before clicking anything.
Real examples of the patterns attackers use, and why they work.
SMS phishing has surpassed email phishing in click-through rates because people are less skeptical of texts.
Voice phishing is the hardest to dismiss in the moment — a real human voice feels authoritative.
Clicking a link alone rarely installs malware on a fully-patched device. Your risk is low but not zero.
This is credential phishing — the most common outcome. Move fast; attackers use stolen credentials within minutes.
This is identity theft territory. Move through these steps today.
This is the highest-risk scenario — downloaded files can install malware, keyloggers, or ransomware.
Tech support scams almost always end here. The attacker likely installed software or viewed saved passwords.
Screenshots and email headers are useful if you need to file a fraud claim or police report.
Phishers don't pick targets at random. They buy data broker lists that include your name, email, phone number, home address, employer, and family members — all used to craft convincing, personalized attacks. Removing yourself from these lists reduces targeting upstream, before an attack ever happens.
Even if a phisher gets your password, 2FA stops them from getting in. Prioritize: email, bank, Apple ID / Google account. These are the keys to everything else.
Credential phishing is only catastrophic when you use the same password in multiple places. A password manager generates and stores unique passwords for every site — you only remember one.
Browser exploits that allow drive-by infection from clicking a link are almost always patched in current versions. Being one update behind is enough to be vulnerable.
The most targeted people in a household are often the least warned. A 10-minute conversation prevents most phishing incidents.