How to Spot Phishing Before You Hand Over the Key
- Urgency Is the Delivery System
- A Lock Icon Can Protect the Wrong Destination
- The Second Prompt May Be the Real Theft
- Attachments Ask Your Device to Take the Risk
- QR Codes Hide the Link Until the Phone Opens It
- Your Password Manager Can Notice the Wrong Site
- If You Responded, Match the Fix to What Escaped
- Slow Down Outside the Message
Phishing doesn't need to break encryption. It needs you to open the door from the inside. The message creates a believable problem, the fake page offers a fast solution, and your own hands carry the secret across.
At 8:14 a.m., Nina gets a text: a package needs a $1.47 address fee before delivery. She is expecting a package. The link opens a polished page with a lock icon, a familiar logo, and a card form that works perfectly.
The tiny charge isn't the real product. Her card details, password, one-time code, or trust in the next message may be worth far more.
Urgency Is the Delivery System
Phishing arrives by email, text, direct message, phone call, QR code, search ad, or a compromised account belonging to somebody you know. The story changes—missed parcel, frozen bank account, unpaid invoice, shared document, job offer—but the pressure is remarkably consistent.
Act now. Keep it secret. Use this link. Move away from the normal process.
Don't make bad spelling your main test. A well-written message can be malicious, and a clumsy message can be genuine. Test the requested action instead: did you expect it, does it demand a secret or payment, and can you verify the claim through a channel you already trust?
The FTC's phishing guidance recommends contacting the company through a phone number or website you know is real—not through the message—when a request might be legitimate.
A Lock Icon Can Protect the Wrong Destination
HTTPS encrypts the connection between your browser and the site it reached. It doesn't certify that the site belongs to your bank, courier, employer, or tax agency. A phisher can use HTTPS too.
A VPN has the same boundary. It can protect covered traffic on the way to its server and change the public IP the page sees. If Nina types her card number into the fake delivery page, the VPN can carry that submission securely to the attacker.
Look at the domain before the page design. On a phone, expand the address bar and read from the registered domain backward, not just the first reassuring word. delivery.example.com belongs to example.com; example.delivery-help.com belongs to delivery-help.com. A padlock says the connection is encrypted. It doesn't settle ownership.
For high-value accounts, skip message links altogether. Open the official app, use a bookmark you created earlier, or type the known address yourself. If the warning is real, it should appear inside the account.
The Second Prompt May Be the Real Theft
Some phishing pages collect a password and immediately relay it to the genuine service. When the service asks for a one-time code, the fake page asks Nina for that too. She sees a familiar sequence and completes the attacker's live login.
Multifactor authentication still matters: it blocks many attacks that stop with a stolen password. But manually entered text and authenticator-app codes can be relayed. NIST's current authenticator guidance doesn't treat manually entered one-time codes as phishing-resistant because an impostor can relay them.
Passkeys and FIDO security keys work differently on supported services. The cryptographic sign-in is bound to the real service's domain, so the imitation site can't simply collect and replay a reusable secret.
- Connects through USB-C or NFC, covering many newer computers and compatible phones
- Adds a phishing-resistant physical check to passkeys and supported multi-factor logins
- Works without a battery, code display, or wireless pairing process
The YubiKey 5C NFC supports FIDO sign-ins over USB-C or NFC on compatible accounts. Check each service's support, register more than one recovery path, and keep a spare safely; a strong login that locks out its owner isn't a finished setup.
Attachments Ask Your Device to Take the Risk
An attachment doesn't need your password if it can persuade the device to run code. Office files may ask you to enable content. Archives may hide an executable. Fake installers and browser updates can look routine because the attacker copied the real branding.
Don't open an unexpected attachment just because the sender name is familiar. Accounts get compromised, display names are easy to fake, and invoices can be aimed at the person whose job makes them plausible. Verify through a known phone number or a fresh message to a saved contact.
Keep the operating system, browser, document reader, and security tools updated. CISA's everyday security guidance pairs phishing recognition with prompt updates because user judgment and patched software cover different failure points.
QR Codes Hide the Link Until the Phone Opens It
A QR code pasted over a parking meter or printed in a fake benefits notice turns a visible address into an opaque square. The phone still opens a URL; you just didn't type or read it first.
Preview the destination before continuing. If the code claims to represent a bank, government office, payment service, or employer, use the official app or known site instead. Never install a configuration profile, remote-support app, or device-management tool because an unsolicited message or caller directs you to one.
The same rule applies to phone calls. Caller ID can be spoofed. Hang up and call the number printed on the card, statement, or official website. A real fraud department can tolerate verification; a scammer needs control of the channel.
Your Password Manager Can Notice the Wrong Site
A password manager does more than remember complicated passwords. It associates a saved login with a domain. When it refuses to fill a page that looks right, pause—the mismatch may be the warning your eyes missed.
Don't defeat that warning by copying the password from the vault and pasting it anyway. Open the saved site's entry directly. Use a unique password on every account so one successful phish doesn't become a skeleton key for email, shopping, work, and social accounts.
If a digital manager isn't workable for someone, a securely stored paper record can still help prevent password reuse. It should stay in a private physical location, omit unnecessary account-recovery details, and never travel as a complete map of a person's online life.
- Stores passwords on paper instead of syncing them through another online account
- Uses alphabetical sections and a compact spiral format to make entries easier to find and update
- Works best when kept in a secure physical location and never carried as an unprotected master list
An organized password book is an offline storage option, not phishing protection. It can support unique credentials, but it won't verify a domain or stop someone from typing a recorded password into a fake page.
If You Responded, Match the Fix to What Escaped
Merely opening a message is different from entering credentials, approving a sign-in, installing software, or sending money. Start by naming the event.
If you entered a password, use a known-clean device to change it on the real site. Change every account where it was reused. Revoke active sessions, review recovery email and phone numbers, remove forwarding rules you didn't create, and turn on stronger MFA.
If you supplied a one-time code or approved a push notification, assume the attacker may already have a session. Resetting the password may not end it; use the account's “sign out everywhere” or session-management controls.
If you shared card or bank details, contact the institution using a trusted number, watch transactions, and follow its replacement or freeze instructions. If you disclosed identity information, the FTC directs U.S. consumers to IdentityTheft.gov for a recovery plan based on what was exposed.
If you installed a file or app, disconnect the affected device when continued access could cause harm, run supported security checks, and get qualified help if the device handles valuable accounts. Change credentials from a different, trusted device.
Report the message through the platform or organization it impersonated, then report U.S. fraud attempts at ReportFraud.ftc.gov. Reporting won't undo the click, but it can help filters, investigators, and the impersonated organization block the next route.
Slow Down Outside the Message
Nina's safest move is small: close the delivery text and open the courier's official app. No outstanding fee appears. The story collapses as soon as the attacker loses control of the path.
That's the durable phishing habit. Don't try to become better at judging logos under pressure. Leave the message, use a channel you chose before the emergency, and let the real account tell you whether anything needs attention.

