Can I fall for phishing?
Yes — no one is exempt from being targeted. Even people who know exactly what phishing
looks like can be caught off guard by a convincing enough attempt. Assuming you are
immune is, if anything, what makes someone an easier target.
What types of phishing exist?
Phishing can arrive through almost any channel — email, text message, phone call, social
media, a website, or even a QR code. Since none of these are off-limits to attackers, it
pays to stay cautious no matter how the message reaches you.
Gift cards & cryptocurrencies
Gift cards and cryptocurrency are favorite tools of scammers looking to take your money.
Being told to buy a gift card or send crypto — especially under threat of some
consequence if you don't — is a near-certain sign of a scam, and even more so when the
person claims to be calling from a government office or a bank. No legitimate
institution asks to be paid this way instead of through ordinary means.
Put simply: a request to pay with gift cards or cryptocurrency can almost always be
treated as a scam in progress.
Opening links
A message claiming to be from someone you trust that asks you to click a link should not
have that link clicked. Open a new browser tab instead and search for the site directly,
or run the link through VirusTotal first if you want to check it. Either way,
a link inside the message itself should stay unclicked.
Downloading files
A file you're unsure about should not be opened right away. Run it through VirusTotal
first — it checks the file against more than 70 antivirus engines and tells you whether
it's considered safe. If doubt remains even after that, the safest move is to delete the
file without opening it.
One caveat: anything you upload to VirusTotal gets shared with the wider security
community, so it is not the place for sensitive or private files.
Common scams
- Fake Delivery Scam: A message claims a package could not be
delivered and asks you to confirm your details or pay a small fee to release it. This
is a scam almost every time. Regardless of whether a delivery is actually expected,
skip the link entirely and type the courier's website address in yourself.
- Pegasus spyware scam: This is a pure extortion attempt. The message
claims your device has been infected with spyware, that you were recorded doing
something embarrassing through your own camera, and that the recording will be
released unless you pay up. In reality, no such footage exists and no infection took
place — the message is the entire attack.
- Advance Fee Scam: The details vary endlessly, but the mechanism stays
the same: pay a small amount now, and a much larger payout is promised later. That
payout never arrives. Because it shows up in so many disguises, it's one of the
hardest scams to fully guard against — treating any "pay now, profit later" offer
with suspicion is the best you can do.
- Recovery Scam: Aimed specifically at people who already lost money to
an earlier scam, this one promises to recover those funds — for an upfront fee, of
course. It's simply an advance fee scam wearing a different disguise. Outside of law
enforcement or a genuine financial institution, no one is in a position to get your
money back.
Reporting a scam
Finding out you've been scammed is not a reason to stay quiet about it — report it. It
happens to a lot of people; 73% of US adults have experienced an online scam at some
point, so there's no shame in joining that number. What matters is that reporting it
gives someone else a chance to avoid the same trap. Where you report it depends on how
the scam reached you.
- A scam of any kind is always worth reporting to your local law enforcement.
- Lost money to a scam? Get in touch with your bank or financial institution right
away — they may still be able to recover it.
- A scam website can be reported directly to us using our report form.
- An email scam should be marked as spam and reported to whoever provides your
email.
- A scam call or text can usually be reported straight to your mobile carrier.
- A scam on social media is best reported through that platform's own reporting
tools.