A Phishing101 resource

Scam Field Guide

Twelve scams, each with how it works, the detail that gives it away, the one move that stops it, and what it costs. None of these require you to be careless. They require you to be busy, helpful, or frightened, which everyone is sometimes.

If you remember one thing

Verify on a channel you chose, never the one they contacted you on.

Every entry below falls apart the moment someone hangs up and dials a number they already had, or types a company's address themselves instead of tapping a link. An attacker controls the channel they reached you on. They do not control the one you pick.

The twelve

Six that come for people, six that come for organizations. Most of the techniques work on both.

Who it targets
Channel

Showing all 12

01PersonalReported pattern

Grandparent scam

The granddaughter who was never in jail

Incoming, unfamiliar number6:40 a.m.

Caller, cryingGrandpa? I have been in an accident and they have arrested me. Please do not tell Mom.

Second voice, calmSir, I am the attorney assigned to your granddaughter. Bail is $9,400 and the bond office closes at eight. Can you get to a store and buy prepaid cards while we talk?

The tell

Three things arrive together: a deadline, a demand for secrecy, and a payment method no court has ever used. Bail is not paid in gift cards or cryptocurrency. Ever.

The secrecy is the clearest signal of all. It is not protecting your granddaughter; it is preventing the single phone call that ends the scam. The script needs you isolated to work.

What stops it

Hang up. Call your granddaughter on the number already in your phone. If she does not answer, call her mother. No genuine emergency is made worse by thirty seconds of checking. Agree a family code word now, while nobody is panicking, so there is something to ask for later.

The damage

Losses in individual cases commonly run from a few thousand dollars into the tens of thousands, and because gift cards and wire transfers are effectively irreversible, recovery is rare.

The financial figure understates it. People who fall for this one describe lasting damage to their confidence and to their standing in their own family. Adult children start managing their money and independence narrows. Shame also keeps most of it unreported, so the published totals are a floor rather than a measure.

Reported pattern, not one person's account. Documented in Federal Trade Commission and FBI Internet Crime Complaint Center reporting on family emergency scams. Seconds of public audio are now enough to clone a voice.
Read more: https://consumer.ftc.gov/articles/scammers-use-fake-emergencies-steal-your-money

02PersonalReported pattern

Government impersonation

Your Social Security number has been suspended

Incoming, caller ID shows a federal agency2:05 p.m.

CallerThis call is regarding suspicious activity linked to your Social Security number. Do not hang up. Ending this call will be treated as non-cooperation.

CallerTo protect your funds while the investigation proceeds, we need you to move your balance to a secure federal account. I will stay on the line with you the entire time.

The tell

Government agencies do not call to threaten arrest, do not demand payment by gift card or cryptocurrency, and never ask you to move money to keep it safe. There is no such thing as a secure federal account for a private citizen's savings.

"Stay on the line" is the instruction to watch for. It exists to stop you consulting anyone, and it is the same isolation tactic as the grandparent scam wearing a uniform.

What stops it

Hang up without explaining yourself. You owe an unsolicited caller nothing. If you want to be certain, look up the agency yourself and call its published number. Genuine matters can always be handled that way, and no real investigator objects.

The damage

Government impersonation fraud is consistently among the most reported categories to the Federal Trade Commission, and the per-victim losses are high because the pretext justifies emptying entire accounts rather than making one payment.

Some victims stay on the phone for hours across multiple calls, and a share of life savings can go in a single afternoon. The people targeted hardest are those who most believe that cooperating with authority is the right thing to do.

Reported pattern, not one person's account. Documented in Federal Trade Commission consumer protection data and Social Security Administration Office of the Inspector General advisories.
Read more: https://www.ssa.gov/scam/

03PersonalFollows a real case

Refund scam

The mistake she never made

From
Billing Department <receipts@[lookalike-domain]>
Subject
Your subscription has been renewed, $400.00

Thank you. Your annual protection plan has auto-renewed and payment has been taken from the card on file.

If you did not authorize this renewal, contact our cancellation line within 24 hours on the number below to arrange a full refund.

The tell

The email gives a phone number instead of a link, a trick known as callback phishing, and that reverses who starts the conversation. She called him, so by the time they spoke she had already decided the company was real and she was the one who wanted something. Every instinct that guards you against a cold call is switched off when the call was your idea.

No legitimate refund has ever needed remote access to your computer. That one fact ends this scam wherever it appears.

And then the move that carries the whole thing: the error was manufactured and handed to her. He typed the extra zeros and told her she had typed them. From that moment she was not being cautious about a stranger, she was hurrying to fix a costly mistake of her own, and a person doing that stops checking anything.

What stops it

Never call a number printed in an unexpected invoice. If you are worried a charge is real, open the company's own site yourself, or phone the number on your bank card. That takes a minute and settles it completely.

Turn on multifactor authentication with your bank. A password stolen by a keylogger is far less useful to someone who does not also have your phone.

Never install software so that someone who contacted you can see your screen. And if anyone who reached out to you first tells you that you have made an expensive mistake, that sentence is the scam. Put the phone down and call your bank on the number on your card.

The damage

$40,000, in mid-transfer, and it was her house deposit. The bank stopped the transfer and cut the attacker out of her account. None of that happens if they do not make the call.

The bank caught it. She did not, and nothing she knew would have helped, because she was being careful about a problem the attacker had invented. That is worth sitting with: her judgment was fully engaged the whole time and it was pointed in the wrong direction.

The money was also not the only loss. The remote access tool came with a keylogger, so her name, her bank account number and her banking login had all been captured before the call ended, and the machine stayed compromised after he hung up.

She said at the outset that she was embarrassed to even talk about it, which is the ordinary response and is exactly why so little of this is ever counted. Asked whether she had told the police or the FBI, she had not. Whether she ever did is unknown.

She was told it was not her fault. That was not a kindness, it was accurate. The mistake she was hurrying to repair had been typed by the man on the phone.

Follows a real case. The sequence, the amounts and the order of events are as they happened. No name, date, location, employer or company is given, and nothing here identifies the person involved. The technique is documented generally by the Federal Trade Commission.
About this type of scam: https://consumer.ftc.gov/articles/how-spot-avoid-and-report-tech-support-scams

04PersonalReported pattern

Delivery smishing

The parcel that needed 40 cents

Unknown number, 11:04
Your package is on hold. Unpaid postage of $0.40 is required for delivery. Update payment: [carrier-lookalike-domain]/track

The tell

The domain is not the carrier's, and carriers do not collect postage shortfalls by text message. On a phone screen a lookalike address is hardest of all to inspect, which is exactly why this arrives by text rather than email.

The target was never the forty cents. It was the card details you typed to pay it.

What stops it

Do not tap the link. If you are expecting a parcel, open the carrier's own site or app and enter the tracking number yourself. If you are not expecting one, there is nothing to resolve.

The damage

The immediate loss is usually small and often refunded by the card issuer. The real cost is what the card details enable next: fraudulent purchases, the card added to a digital wallet, or the details used to sound convincing on a follow-up call.

Delivery notification texts are among the highest volume scam categories reported anywhere, and a harvested card commonly resurfaces weeks later, by which point the link between the two is no longer obvious.

Reported pattern, not one person's account. Delivery notification smishing is among the most reported text message scam categories in Federal Trade Commission and carrier data.
Read more: https://consumer.ftc.gov/consumer-alerts/2025/04/think-text-message-usps-it-could-be-scam

05PersonalReported pattern

Relationship investment fraud

The wrong number who became a friend

Unknown number, March 2
Hi Michael! Confirming our lunch Thursday at 1?
Sorry, wrong number.
Oh how embarrassing, apologies! Hope your week is going well anyway.
Eleven weeks of daily conversation later
My uncle manages a fund and he let me in. I have pulled out $40k since January. Happy to show you the platform if you are curious, no pressure at all.

The tell

The wrong number was not wrong. The eleven weeks were the investment. By the time money is mentioned, the relationship feels real enough to override caution, and being told "no pressure" is itself the pressure.

The structural tell is the permitted early withdrawal. A real platform does not need to prove it will let you have your money. A fake one must.

What stops it

Nobody you have not met in person directs where your money goes. Not after eleven weeks, not after a year. Make it a rule about the situation rather than a judgment about the person, because by then the person seems genuinely lovely. Tell one friend about any new investment before you fund it.

The damage

This category produces some of the largest per-victim losses of any fraud reported to the FBI, routinely six figures, because the target is not a single payment but everything a person has: savings, retirement accounts, home equity, and often borrowed money on top.

The relationship is the second loss and victims consistently describe it as the worse one. Many are then approached by recovery services, which are run by the same networks and take a further payment to retrieve money that no longer exists.

Reported pattern, not one person's account. Documented extensively in FBI Internet Crime Complaint Center annual reporting on investment and confidence fraud. The accidental first message is the standard opening.
Read more: https://www.ic3.gov/CrimeInfo/Investment

06PersonalReported pattern

Breach notification

The breach notice that was the breach

From
Account Security <security-alert@[lookalike-domain]>
Subject
Immediate action required: your data was exposed

We are writing to inform you that credentials associated with your account appeared in a data set published after a third-party security incident.

To protect your account, verify your identity and reset your password using the secure link below within 24 hours. Accounts that are not verified will be suspended as a precaution.

The tell

A real breach notice never asks you to sign in through a link in the message. It tells you what happened and leaves you to go to the service yourself, because the people sending it know perfectly well what a link in an email is worth.

Urgency about security is itself the anomaly. Genuine security processes are patient; they do not threaten to suspend your account because you did not click quickly enough.

There is also a logical flaw sitting in plain sight. The notice concerns an account you would have to be signed in to act on anyway, so the login page it kindly provides is redundant by definition.

What stops it

Do not use the link. Open the service the way you normally do, by typing the address or using your own bookmark, and look at your account from there. If there was a genuine breach, the service will tell you once you are signed in.

Better still, stop waiting to be told. You can check which breaches have included your address yourself at https://haveibeenpwned.com, an independent service that catalogs known breaches. And freeze your credit before anything happens, so that a breach notice is never urgent in the first place.

The damage

It converts unusually well precisely because the victim believes they are doing the protective thing, and the password goes directly into the account the message claimed to be defending. Where that password is reused elsewhere, which it usually is, one entry opens several accounts.

There is a second wave. After a genuine breach, victims are approached by fake identity protection and recovery services offering to monitor or undo the damage. The same people are sold the remedy twice.

The slower harm is the one nobody counts. After enough false alarms people stop reading security notices altogether, and the real one, when it arrives, goes unopened with everything else.

Reported pattern, not one person's account. Documented in Federal Trade Commission guidance on data breach notifications and identity theft recovery.
Read more: https://consumer.ftc.gov/consumer-alerts/2022/09/did-you-get-email-saying-your-personal-info-sale-dark-web

07BusinessDocumented incident

Help desk pretext

Phone calls took over 130 Twitter accounts

Inbound, "Internal IT"July 2020

CallerHi, we are seeing VPN errors on a handful of accounts after last night's change, and yours is one of them. I will walk you through re-authenticating so you do not lose access.

CallerJust sign in at the portal I am sending across now and approve the prompt on your phone.

The tell

The research made the call credible, but no amount of research changes the one structural fact: an inbound caller asked an employee to authenticate during the call. That is the request no genuine help desk needs to make.

Accurate internal knowledge is not proof of identity. Names, team structures and current incidents are all discoverable from outside.

The regulator that investigated found the attack used "no malware, no exploits, and no backdoors." It was phone calls and nothing else.

What stops it

Never authenticate during an inbound call. Hang up and reach your own help desk on the number published internally. A real technician will wait; a fake one cannot afford to, and that difference is the test.

The regulator also concluded that hardware MFA, a physical security key plugged into the computer, "would have stopped the Hackers." A key like that only works on the real site, so a copied login page gets nothing from it.

The damage

130 accounts were compromised and 45 were used to send tweets, with the public defrauded of roughly $118,000 in bitcoin, a small sum against the rest of the fallout. Verified accounts were temporarily unable to tweet, a financial regulator published a detailed investigation into how a handful of phone calls reached the controls of a global platform, and criminal charges followed.

The lasting damage was to the assumption that verified accounts are trustworthy, and it prompted a broad re-examination of how much power internal support tooling should hold.

Sources: New York State Department of Financial Services investigation report, October 2020; U.S. Department of Justice charging documents.
Regulator: https://www.dfs.ny.gov/reports-and-publications/other-reports/Twitter_Report
Prosecution: https://www.justice.gov/opa/pr/three-individuals-charged-alleged-roles-twitter-hack

08BusinessDocumented incident

MFA fatigue

Uber: the approval that would not stop asking

Prompt. Denied. Prompt. Denied. Prompt.

Then, on WhatsApp, from someone claiming to be Uber IT: "This will stop if you accept."

The tell

Prompts you did not trigger mean somebody already has your password. That is the only way the prompts can exist, and it makes them a security incident rather than a malfunction.

The flood is not a bug. It is pressure, and the helpful message exists solely to convert your irritation into a single tap.

What stops it

Approve nothing you did not start. Report repeated prompts right away and change the password immediately. Real IT never asks you to approve a prompt they sent. Organizationally, hardware security keys stop this attack, because there is no prompt to accept. Number matching, where you type in a number shown on the login screen, makes it much harder, though an attacker who is already messaging you can still tell you which number to enter.

The damage

The attacker reached several employee accounts and, through them, a broad set of internal tools. Uber said it had not seen the attacker reach the systems that run its apps, any user accounts, or sensitive user data such as card numbers, bank details or trip history. It took many internal tools offline as a precaution while it investigated, and blamed a hacking group called Lapsus$.

One tap, by one contractor, on one prompt, was enough to reach all of that.

Sources: Uber's own published security update, September 16, 2022. The WhatsApp message is not in Uber's update; it comes from the attacker's own account to a security researcher, first reported by BleepingComputer.
Uber: https://www.uber.com/newsroom/security-update/
The WhatsApp message: https://www.infoq.com/news/2022/09/Uber-breach-mfa-fatigue/

09BusinessDocumented incident

Voice cloning

Retool: the colleague on the phone was synthetic

Unknown number, August 2023
IT here. The open enrollment change has locked a few payroll accounts, yours included. Sign in through this link so your deductions go through this cycle.
Then a phone call

A caller claiming to be from IT, speaking in a deepfake of a real employee's voice and knowing the office inside out, asked for one more code.

The tell

The text got a password. The call got the rest, because a familiar-sounding voice and inside knowledge of the office retire most people's doubt, and a voice is now cheap to fabricate from any public recording such as a conference talk or a podcast.

The pretext was also well chosen. A threat to someone's own pay produces compliance faster than almost anything else.

What stops it

A recognized voice is no longer proof of identity. Call the person back on the number you already hold, or ask something only they would know. Both take seconds and neither can be cloned. Codes are never shared with anyone, including people you recognize.

The damage

Retool reported that 27 of its cloud customers, all in the crypto industry, were affected, a chain of consequence that began with a single text message about payroll.

Retool itself stressed the syncing. Codes kept in the cloud turned one stolen account into every code the employee had, which is exactly what a second factor is supposed to prevent.

Sources: Retool's own published incident write-up, September 13, 2023.
https://retool.com/blog/mfa-isnt-mfa

10BusinessDocumented incident

Business email compromise

Two internet giants sent $120 million to the wrong bank account

From
Accounts Receivable <billing@[supplier-lookalike]>
Subject
Outstanding balance, updated remittance details

Please find attached the statement for hardware supplied this quarter, together with our revised banking details.

Please note our banking details have changed. All payments from today should go to the new account below.

The tell

Nothing was hacked and no password was stolen. The only false thing in the whole sequence was a change of bank account, and that is the single detail this fraud always depends on.

Scale is no defense. These were two of the most technically capable companies in the world, and the attack bypassed all of that by targeting a finance process rather than a network.

What stops it

Require voice confirmation on a previously held number for every change of payment details, with no exception for urgency or seniority. Make it a process rather than a judgment, so nobody has to be suspicious in the moment. That is the only version that survives a busy quarter.

The damage

Over $120 million was sent. He was arrested in Lithuania in 2017, extradited to New York, pleaded guilty to wire fraud in March 2019, and in December 2019 was sentenced to five years in prison. The judge also ordered him to forfeit $49.7 million and pay $26.5 million in restitution.

Business email compromise was the second-largest reported loss category in the FBI's 2025 Internet Crime Report, over $3 billion, behind only investment fraud and far ahead of ransomware.

Sources: U.S. Department of Justice prosecution of Evaldas Rimasauskas: guilty plea, March 20, 2019, and sentencing, December 19, 2019. FBI Internet Crime Complaint Center 2025 annual report for the loss ranking.
Guilty plea: https://www.justice.gov/usao-sdny/pr/lithuanian-man-pleads-guilty-wire-fraud-theft-over-100-million-fraudulent-business
Sentencing: https://www.justice.gov/usao-sdny/pr/lithuanian-man-sentenced-5-years-prison-theft-over-120-million-fraudulent-business
Loss rankings: https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf (page 26)

11BusinessReported pattern

Piggybacking

The man with his hands full

"Oh thank god, could you? These are for the ops standup and I am already late."

Hands full. Uniform. Mild self-deprecation. An errand nobody would invent.

The tell

Every detail is engineered so that refusing feels rude: the full hands, the plausible errand, the uniform, the apologetic tone. The twisted badge is deliberate.

This is not a technical attack. It is an attack on your manners, and it works because the social cost of challenging someone feels larger in the moment than the security cost of letting them through.

What stops it

"Happy to walk you around to reception." It is friendly, it is not an accusation, and it is unanswerable. A colleague will shrug and follow you. Anyone who argues has told you what you needed to know. An organization that says out loud that nobody will be criticised for asking removes the social cost entirely.

The damage

Physical access converts directly into everything else: an unattended unlocked workstation, a device plugged into a meeting room network port, documents photographed, credentials read off a monitor. It also produces the raw material for the next attack, because names, projects and internal language make a later phone call far more convincing.

Because it leaves no log entry, it is frequently discovered only when the consequence surfaces somewhere else entirely, and often never attributed to the morning someone held a door.

Reported pattern, not one organization's account. Piggybacking is a standard technique in authorized physical penetration testing and is documented in published assessment methodologies. Government sources, including the Department of Homeland Security, treat tailgating and piggybacking as one behavior. Security practitioners separate them by whether the person let the intruder in.
Read more: https://www.dhs.gov/sites/default/files/publications/ACT-HB_0915-508.pdf (definition on page A-3)

12BusinessReported pattern

QR code phishing, or quishing

The square that was not a link

From
IT Service Desk <no-reply@[enrollment-portal-lookalike]>
Subject
Action required: re-enroll your authenticator by Friday

Our multi-factor provider is migrating this week. All staff must re-enroll before Friday at 5 p.m. or sign-in access will be suspended.

Scan the code below with your phone camera to complete enrollment. This takes about two minutes.

Go ahead and scan this one. It holds a short message, not a web address, so your phone will only offer to search the web for the words. Notice what your camera shows you before you tap anything.

The tell

A QR code is a link with its address concealed. That is the whole of what it adds, and it is worth asking why a message that wants your password would prefer you could not see where it is sending you.

Genuine security migrations do not depend on a camera, and they do not arrive with a suspension deadline attached. Real IT publishes this sort of thing through a route you already know.

What stops it

Do not scan codes that arrive by email. If an enrollment is genuinely required, reach it the way you always do: type your company's portal address, or ask the service desk on a number from the intranet.

When you do scan a code anywhere, most phone cameras show the address before opening it. Read it. If it does not match the organization whose code you think you are scanning, close it. For an organization, the durable fix is to publish enrollment through one known internal route, so that a code in an email is obviously wrong to everybody.

The damage

What is captured is a password and a working second factor, entered on a device outside the corporate perimeter. Because the phone is generally not logged or managed, the theft frequently leaves no trace on the organization's side at all, and the first sign of trouble is a successful login from somewhere unexpected.

There is a physical version of this that costs individuals directly. Printed stickers are placed over legitimate QR codes on parking meters, payment terminals, restaurant tables and charity posters. The same principle applies and so does the same defense: read the address the camera shows you before you let it open anything.

Reported pattern, not one organization's account. QR code phishing is documented in Federal Trade Commission consumer alerts and in guidance from the Cybersecurity and Infrastructure Security Agency.
Read more: https://consumer.ftc.gov/consumer-alerts/2023/12/scammers-hide-harmful-links-qr-codes-steal-your-information

The machinery

Eleven things scams use on you

The twelve stories above are all different. What makes them work is not. The same eleven tricks keep turning up. Learn to spot a trick and you are protected against far more than twelve scams, including the ones nobody has invented yet.

Rushing you

A deadline. The bond office closes at eight. Verify within 24 hours or your account is suspended. Re-enroll by Friday or you lose access.

The deadline is not really about time. It is there to stop you checking, because checking takes a few minutes and the whole thing falls apart if you have those minutes. So the message spends all its effort convincing you that you do not have them.

What to do

Treat the deadline itself as the warning. Real organizations do not punish you for taking an hour to confirm something. If a thing genuinely cannot wait, it will still be true in ten minutes, after you have called back on a number you chose.

Used in Grandparent scam, Government impersonation, Delivery smishing, Breach notification, Help desk pretext, Voice cloning, QR code phishing

Acting official

The caller is IT, the police, your bank, a government agency, the service desk. Something you were brought up to cooperate with.

Most people are not deciding whether to obey. Cooperating with officials is a habit, and habits do not get examined. It also flips the pressure around, so that asking a question starts to feel like you are the one being difficult.

What to do

Authority is a claim, not a proof. Anyone can say they are from IT, and the number shown on an incoming call can be set to anything at all. Look the organization up yourself and call it back. Nobody genuine has ever minded.

Used in Government impersonation, Help desk pretext, MFA fatigue, Voice cloning, Business email compromise, Piggybacking, QR code phishing

Someone you know

A voice you recognize. A name already in your contacts. A brand you use every week. A colleague, a supplier, a grandchild.

Recognition switches off judgment almost entirely. You do not verify people you know, which is normally sensible and is exactly the shortcut being borrowed. A voice can now be copied convincingly from a few seconds of public audio, so sounding right has stopped being evidence.

What to do

Call back on the number you already had, or ask something only the real person could answer. Agree a family word in advance, while nobody is panicking, so there is something to ask for later.

Used in Grandparent scam, Relationship investment fraud, Voice cloning

Faking the sender

A number that displays as your bank. An address one letter different from the real one. A copied logo and layout. Forged invoices and contracts.

People check whether something looks right, and looking right is the one thing a forger can always manage. Displayed phone numbers are trivial to change, and a near miss web address is hardest of all to spot on a phone screen.

What to do

Never judge by appearance. Hover over a link and read where it really goes. Better still, ignore what arrived and reach the organization by a route you picked yourself.

Used in Government impersonation, Delivery smishing, Breach notification, Help desk pretext, Business email compromise

Posing as the fix

The message is not the problem, it is the solution. Your data was exposed, secure your account. You were overcharged, here is your refund. The prompts will stop if you approve one.

The victim is not being careless. They are being responsible, and every instinct that would normally raise an alarm is pointing the wrong way. It also collects on the advice everybody has been given for years: change your password, check your statements, act quickly.

What to do

Help you did not ask for is not help. If the problem is real you can deal with it by going to the organization yourself, and that route is always open. It never requires the message that told you about it.

Used in Refund scam, Breach notification, MFA fatigue

Blaming the target

He types the wrong figure and tells you that you typed it. Your account was suspended because you did not act in time. Hanging up will be treated as refusing to cooperate.

Once you believe you caused the problem, you stop assessing the stranger and start trying to repair your own error. Guilt works better than fear for this, because fear feels like something being done to you and guilt feels like something you owe. A person rushing to put right a mistake of their own checks nothing at all.

What to do

If someone who contacted you first tells you that you have made an expensive mistake, that sentence is the scam. You cannot have fumbled a transaction you never started. Put the phone down and check with your bank on a number you already had.

Used in Refund scam. Only one card here shows it, but it runs through the whole refund scam family, and through any script that treats your hesitation as wrongdoing.

Moving you to your phone

The message starts in one place and asks you to continue somewhere else. A code to scan. A number to ring. A different app.

Every hop sheds protection. A work computer has filtering and logging behind it and your own phone does not. A small screen hides a lookalike address. A phone call lets a person talk you past doubts that a web page could never argue you out of.

What to do

Notice when you are being moved, and treat the move as the signal. Finish where you started, or start again somewhere of your own choosing.

Used in Refund scam, QR code phishing

Using your manners

His hands are full and the door is heavy. She only needs one small thing and she has clearly had a long day. He is new and does not want to bother his manager about it.

It costs nothing to be kind, and refusing feels like an accusation. In the moment, the social price of saying no feels far larger than the security price of saying yes. The whole attack is built on that mismatch, and on the fact that most people would rather be robbed than rude.

What to do

Find a polite no that is not a refusal. Happy to walk you around to reception. Let me call you straight back. Both are friendly, neither accuses anyone of anything, and both end it.

Used in Piggybacking. Only one card here turns on it, but it is the whole basis of physical access work and of any request that makes refusing feel unkind.

Keeping you alone

Do not tell Mom. Do not hang up. Keep this between us until the investigation is closed.

Nearly every scam on this page collapses the moment the target says it out loud to another person. So the script spends its energy keeping you by yourself, and it almost always dresses that up as protecting somebody you love.

What to do

This is the clearest single signal in the whole guide. Anyone insisting that you tell nobody is telling you to tell somebody. Do that.

Used in Grandparent scam, Relationship investment fraud

Asking for something tiny

Forty cents of unpaid postage. Just approve one prompt. Just hold the door.

Small things do not get investigated, because looking into them costs more than they are worth. But the small ask was never the target. It is the doorway, and what comes through it is a card number, an account, or a building.

What to do

Judge a request by what it opens, not by what it costs. A trivial payment that needs your full card number, expiry and security code is not a trivial payment.

Used in Delivery smishing, MFA fatigue, Piggybacking

Taking its time

Weeks or months of ordinary, friendly contact before anything at all is asked for. A wrong number, a conversation, a friendship.

Everybody is watching for the pushy stranger, and patience defeats that completely, because by the time money comes up the person is not a stranger any more. The absence of pressure gets read as proof of honesty, which is precisely backwards.

What to do

Make it a rule about the situation rather than a judgment about the person, because by then the person seems lovely. Nobody you have not met face-to-face directs where your money goes. Tell one friend before you fund anything new.

Used in Relationship investment fraud, Business email compromise

The uncomfortable part

Why people click anyway

In simulated phishing exercises, people click links that read do.not.click.this.link followed by a string of obvious gibberish. They have been told to hover. They hover in the classroom. Then the real message arrives and they click.

That is not stupidity, and treating it as stupidity is why so much awareness training fails. Four things are going on.

Clicking is not a decision

Read the subject, read the first line, click. That is one motor routine, not three judgments. The click happens before any evaluation begins, which means people are not assessing the link and getting it wrong. They are not assessing it at all.

Suspicion needs a trigger

Researchers who asked people to think aloud while judging messages found that, without being prompted first, participants raised the possibility of deception less than 10% of the time. Prompt them first and it rises to around 40%. Doubt is not a background state you can rely on. Something has to switch it on.

An obvious bad address proves nothing

A ridiculous link only becomes evidence to someone who is already looking at it, and the whole problem is that looking never started. Anyone who inspects the address passes however subtle it is. Anyone who does not inspect it fails however absurd it is. The ugliness of the link barely changes the outcome.

Being careful all the time does not work

You click hundreds of links a week and essentially all of them are fine, so the instinct to trust them is correct almost every time. A rule that says check everything loses to that arithmetic within two weeks. A rule tied to a few specific situations survives, because it is cheap to follow.

So what actually helps

Learn the trigger, not the technique. Hovering is a conscious step inserted into an automatic sequence, so it only happens if something upstream has already said this one. Four situations are worth stopping for, and they cover most of what reaches you: a message that asks you to log in, a message about money, a message you were not expecting, and a message with a deadline attached. When one of those turns up, check the address. The rest of the time, carry on.

On a phone, hovering does not exist. A great deal of advice about checking links quietly assumes a mouse. Press and hold instead, read the address in the panel, then slide your finger away from the link to cancel. Almost nobody is taught this.

Clicking is often not the failure anyway. What causes harm is what happens next: typing your password into the page, opening the attachment, approving the prompt, reading out the code. There is almost always a second step, and it is a far better place to stop than the click.

And tell someone. One person reporting a message protects everyone else who received it. An organization where nobody clicks but nobody reports is in worse shape than one where people click and say so immediately.

If you think it is happening right now

  1. Stop talking and stop typing. Pressure is the whole method. Nothing legitimate gets worse because you paused.
  2. Break the channel. Hang up, close the message, shut the tab. Do not keep the conversation going to learn more.
  3. Reach the organization your own way. A number from your card, a bookmark, an address you typed. Never a detail from the message itself.
  4. Tell one other person. Saying it out loud breaks the spell faster than anything else, and secrecy is exactly what the script was built to buy.
  5. If money has already moved, call your bank immediately and say "I have been defrauded." Speed matters more than a tidy explanation.

Where to get help

Every address below is written out in full, so you can read where it goes before you decide to click. All of them are official bodies. If you would rather not click at all, type the address into your browser yourself, or phone the number.

If it happened to you

FBI Internet Crime Complaint Center

The primary US reporting point for any internet enabled crime. File here even if no money was lost.

https://www.ic3.gov
FTC, report fraud

Reports feed the Consumer Sentinel database used by law enforcement across the country.

https://reportfraud.ftc.gov
AARP Fraud Watch Network Helpline

Free to anyone of any age, member or not. Trained volunteers, many of them former victims, will talk it through with you.

877-908-3360 https://www.aarp.org/money/scams-fraud/
DOJ National Elder Fraud Hotline

Case managers who stay with you through reporting and recovery, for anyone aged 60 or over.

833-372-8311 https://ovc.ojp.gov/program/stop-elder-fraud/
IdentityTheft.gov

If details were taken rather than money, this builds you a personalized recovery plan.

https://www.identitytheft.gov
Social Security fraud reporting

For calls claiming your Social Security number has been suspended or linked to a crime.

https://oig.ssa.gov/report/

If it happened to your organization

IC3, and ask for the Recovery Asset Team

For a fraudulent wire, IC3 can work with banks to freeze funds that have not yet been withdrawn. This works best within roughly 72 hours, so report before you finish investigating.

https://www.ic3.gov
CISA, report an incident

US federal cybersecurity agency. Reporting point plus free guidance and services for organizations of any size.

https://www.cisa.gov/report
Your bank, first and immediately

Before the internal investigation, before the incident call. Only the bank can attempt a recall, and the window is measured in hours.

US Postal Inspection Service

For anything that arrived by post, or where payment was mailed.

https://www.uspis.gov/report
FCC, unwanted calls and texts

For spoofed caller ID and robocall campaigns targeting your staff or customers.

https://www.fcc.gov/consumer-complaints

If money moved in the last few hours

Call your bank before doing anything else and use the words "I have been defrauded." Recall attempts succeed far more often in the first hours than in the first days, and you do not need a complete account of what happened to start one. Report it afterward. Reporting is never the thing that recovers the money, but speed sometimes is.

Report it even when the money is gone and even when you feel foolish. Almost all of this goes unreported out of embarrassment, and that silence is what keeps the problem under-measured and under-prosecuted.

Who wrote this

Dennis J Walsh

A security professional who runs social engineering awareness training, and a doctoral student researching how older adults recognize and resist digital scams across email, text message and voice.

The accounts here are drawn from published records and from patterns seen in practice.