Read the address, not the name
The name shown in the From line is free text, and anyone can type your bank's name into it. What counts is the address behind it, and in a link what counts is the domain, which is the part immediately before the first single slash. Read it from right to left. An address that begins with your bank's name and ends in some other domain belongs to the other domain. On a computer, hover over a link to see where it really goes, and on a phone, press and hold it until a preview appears.
The scripts in circulation
Spelling mistakes are no longer the giveaway, because writing software produces flawless copy for anyone. The stories are a better tell.
- A delivery could not be completed and a small fee will release the package.
- An unpaid road toll or parking fine will double by Friday.
- Your account has been suspended, or a login from another country needs confirming.
- A colleague has shared a document that needs your work password to open.
- Your boss, writing from a personal address, needs gift cards bought quietly before a meeting ends.
- An invoice thanks you for a purchase you never made and gives a phone number to call for a refund.
The last one contains no link at all. The phone number is the trap, and the person who answers will ask for remote access to your computer.
Newer tricks
A QR code in an email or stuck over the real one on a parking meter is simply a link you cannot read, so treat it as one. A friendly text from a wrong number is the opening move of a long con, and the right reply is none.
If you already clicked
On an updated device, merely visiting the page is rarely a disaster. Typing is what costs you. If you entered a password, go to the real site yourself and change it at once, along with every other account that shares it. If you entered a card number, call the number on the back of the card. If you opened an attachment and approved anything it asked for, disconnect from the internet and run a full security scan.
Tip Forward a scam text to 7726, which spells SPAM, and your carrier will use it to block the sender. Use the report phishing button in your mail program rather than just deleting, because that report trains the filter for everyone.


