If you think you can spot a phishing email, think again. In the first quarter of 2025 alone, the Anti-Phishing Working Group (APWG) logged 1,003,924 phishing attacks—the highest quarterly total since late 2023. That's over a million chances for someone to fool you, and the stakes are huge: phishing and spoofing was the most-reported crime to the FBI's Internet Crime Complaint Center (IC3) in 2024, with 193,407 complaints. You need a practical, step-by-step plan to keep from becoming the next victim. Here it is.
Who This Is For
This is for anyone who uses email, texts, or phone calls to do business—which is everyone. Whether you're an individual managing personal accounts or a small business owner trying to keep your company safe, phishing is the entry point for most cyberattacks. The UK's National Cyber Security Centre (NCSC) notes that 1 in 2 small businesses suffer a cyber incident every year, and phishing is often how it starts. So, this guide is for you if you want to stop attacks before they happen.
Step 1: Know the Enemy—Phishing's Many Faces
Phishing isn't just emails anymore. It comes as smishing (SMS texts), vishing (voice calls), and even quishing (malicious QR codes) (CISA). The attackers are clever: they create false urgency or fear to get you to act fast. They might pretend to be your bank, a delivery service, or a government agency. In 2024, tech support scams alone drew 21,403 complaints to the FBI's IC3, with losses of about $1.46 billion. So, the first step is to recognize that these attacks are everywhere and they're constantly evolving.
Step 2: The Telltale Signs of a Phish
When you receive a suspicious message, pause. Don't fall for the urgency. Check the sender's email address for misspellings (like 'amaz0n.com' or 'paypa1.com'). Hover over any links to see the real URL—if it doesn't match the supposed sender, it's a phish. Be wary of requests for personal information, even if they seem official. CISA notes that in the era of AI, some phishing emails now have perfect grammar and spelling, so you must also watch for urgent language and requests that seem out of the blue. Remember the golden rule: if a message seems even slightly off, don't click anything.
Step 3: What to Do When You Spot a Phish
If you suspect a message is a phish, your response should be quick and definitive: Recognize, Resist, and Delete (CISA). First, recognize the signs. Second, resist the urge to click any link, reply, or call any number in the message—even the 'unsubscribe' link. Instead, if the message might be real, look up another way to contact the company directly, such as visiting their official website or calling a number you know. Finally, delete the message without forwarding it. If it's a work email, report it to your IT department immediately.
Step 4: Why You Need Multi-Factor Authentication (MFA)
Even if you do fall for a phish, MFA can save you. Microsoft states that enabling MFA can block over 99.9 percent of account compromise attacks. That's a massive safety net. But not all MFA is equal. CISA recommends phishing-resistant MFA, such as authenticator apps, hardware security keys (FIDO2), or passkeys, over SMS codes, which can be vulnerable to SIM swapping. CISA documents four ways traditional MFA is bypassed: phishing, push bombing, SS7 protocol vulnerabilities, and SIM swapping. So, when you set up MFA, choose an app or a key, not just SMS. And if you're still using SMS, at least turn on MFA—it's far better than nothing.
Step 5: Check Your Exposure—Use Breach Data
Even if you're careful, your passwords may already be compromised. Use a service like Have I Been Pwned to check if your email address has appeared in a known data breach. This free service, run since 2013 by Troy Hunt, lets you see if your credentials are floating around the dark web. If they are, change your password immediately. CISA recommends rotating any compromised passwords. This simple check can prevent a credential-stuffing attack before it happens.
Step 6: Build a Strong Password Habit
Long, random, and unique passwords are your first line of defense. CISA recommends passwords of at least 16 characters—'longer is stronger'—and suggests using a password manager to generate and store them. You can also use a passphrase made of 4-7 unrelated words, which may include spaces. The UK NCSC recommends building passwords from three random, unrelated words, like 'applenemobiro', so they're long and easy to remember. Avoid common passwords, birthdays, or pet names. And never reuse passwords across accounts; a password manager is essential for keeping track of them all.
What Can Go Wrong: A Real-World Example
Imagine you receive a text that looks like it's from your bank, saying your account has been locked and you need to verify your identity immediately. You click the link and enter your username and password. Within minutes, the attacker uses those credentials to log in to your account. Even if you have MFA, they might bypass it with a SIM-swap attack, convincing your carrier to transfer your phone number to their SIM. By the time you realize it, your savings are gone. This is exactly what happened to many of the 193,407 phishing victims reported to the FBI in 2024. The average loss per IC3 complaint in 2024 was $19,372. Don't let that be you.
Bottom Line
The single best move you can make today is to enable phishing-resistant MFA on your most important accounts—especially your email and banking—and to check Have I Been Pwned for any past breaches. Do that, and you'll block the vast majority of phishing attacks before they can do damage.
Sources
- CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
- CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
- APWG (Phishing Activity Trends Report) - https://apwg.org/trendsreports/
- Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
- NCSC (Three Random Words) - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!