Skip to main content
Phishing Scams

Phishing Isn't About Spelling: How to Spot the Real Scams

Phishing scams today are sophisticated, AI-crafted, and bypass MFA. Learn to spot the real signs and protect yourself with phishing-resistant MFA and smart habits.

The Old Rules Are Dead

You've heard it a thousand times: phishing emails have bad grammar and weird spelling. That's the warning you've been given, and it's wrong. In the era of AI, phishing emails can be grammatically perfect, polished, and utterly convincing. CISA now says that users must look for other signs—urgent language, requests for personal information, and unusual URLs—because the old tell is gone. So, let's drop the myth and get real about what phishing looks like today.

Meet the Attack: A Typical Tuesday

Imagine you are a small business owner. At 9:15 AM, you receive an email from your bank. The subject line screams, "URGENT: Unauthorized Transaction Detected." The email says your account was accessed from a foreign IP, and you need to verify your identity within 24 hours or your account will be frozen. The grammar is fine. The logo looks right. The sender address appears to be from your bank's domain, but if you hover over the link, it points to a URL you've never seen. This is a classic phishing attempt, and it's playing on your fear.

The Numbers Behind the Threat

Phishing isn't a niche problem. In the first quarter of 2025, the Anti-Phishing Working Group observed a staggering 1,003,924 phishing attacks—the largest quarterly total since late 2023. And these attacks work: Verizon's 2024 Data Breach Investigations Report found that more than two-thirds (68%) of data breaches involve a non-malicious human element, meaning someone clicked something they shouldn't have. The FBI's Internet Crime Complaint Center (IC3) received 193,407 complaints about phishing and spoofing in 2024, making it the most-reported crime category.

Why MFA Isn't a Silver Bullet

You might think, "I have MFA, so I'm safe." Not so fast. Traditional MFA—like SMS codes—can be bypassed. CISA documents four ways: phishing (yes, attackers can trick you into entering your code on a fake site), push bombing (where you're spammed with push notifications until you accidentally accept), exploitation of SS7 protocol vulnerabilities, and SIM swapping. That last one is a form of social engineering where attackers convince your cellular carrier to transfer your number to their SIM card. So, if you're using SMS codes, you're still vulnerable. The gold standard, according to CISA, is phishing-resistant MFA, such as hardware security keys (FIDO2) or passkeys. Microsoft says that enabling MFA can block over 99.9% of account compromise attacks—but only if it's the right kind. Don't settle for SMS if you can avoid it.

Spotting the Phish: Beyond Grammar

So, what should you look for? CISA's advice is to Recognize, Resist, and Delete. Recognize the signs: a sense of urgency, requests for personal or financial information, or a link that doesn't match the supposed sender. Hover over links to see the real URL. Check the sender's email address for misspellings or odd domains. If a message seems off, don't click any link or call any number in the message. Instead, contact the company directly using a known, trusted method. And remember, these attacks come in many flavors: smishing (SMS), vishing (voice), and quishing (malicious QR codes). Verizon's 2026 DBIR notes that mobile devices are a favorite target, and people are often more likely to fall for a fake text than an email.

What to Do If You've Been Hooked

If you do click a suspicious link or enter your credentials on a fake site, don't panic. Act quickly. Change your passwords immediately, and check Have I Been Pwned—a free service run by Troy Hunt since 2013—to see if your email has appeared in a data breach. If you've lost money, report it to the FBI's IC3 at www.ic3.gov. In 2024, IC3 received 859,532 complaints with reported losses of $16.6 billion. Don't be part of that statistic.

The Only Way to Win: Phishing-Resistant MFA and Good Habits

Here's my recommendation, plain and simple: enable MFA on every account that supports it, and prefer phishing-resistant options like hardware keys or passkeys. CISA identifies FIDO/WebAuthn as the only widely available phishing-resistant authentication. If you can't use a hardware key, use an authenticator app that generates a new code every 30 seconds, or mobile push with number matching. Avoid SMS codes unless it's your last resort. And remember the basics: use a password manager to generate unique, random passwords for every account—at least 16 characters long, per CISA. Check for breached credentials regularly. Update your software promptly. These habits, combined with phishing-resistant MFA, will keep you out of the 99.9% that Microsoft says MFA blocks.

Takeaway

Phishing is no longer a rookie's game. It's sophisticated, AI-powered, and targets your fear. Don't rely on grammar checks. Recognize the real signs, resist the urgency, and delete suspicious messages. Enable MFA—phishing-resistant if possible—and use a password manager. You don't need to be a security expert, just a skeptic. That's your best defense.

Sources

  • CISA (Recognize and Report Phishing) - https://www.cisa.gov/secure-our-world/recognize-and-report-phishing
  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • APWG (Phishing Activity Trends Report) - https://apwg.org/trendsreports/
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/

Share this article:

Comments (0)

No comments yet. Be the first to comment!