Skip to main content
Phishing Scams

Phishing Scams Are Worse Than You Think: What to Do Now

Phishing remains the top cybercrime, with over a million attacks in a single quarter. Here's how to spot it, stop it, and protect yourself with MFA and smart habits.

Over one million phishing attacks were recorded in the first quarter of 2025 alone (APWG). That's not a typo. The bad guys aren't slowing down, and they're getting better at fooling you. But here's the thing: you don't need to be a tech wizard to fight back. You need to know what to look for and what to do when you see it. Let's bust some myths and answer the questions you actually have.

Is phishing really that common?

Yes, it's the most-reported cybercrime in the country. The FBI's Internet Crime Complaint Center (IC3) received 193,407 complaints about phishing and spoofing in 2024 (FBI IC3). That's more than any other crime category. And it's not just email—phishing shows up as fake texts (smishing), voice calls (vishing), and even QR codes (quishing) (CISA). The volume is staggering, but the good news is that most attacks follow a pattern. Once you know the pattern, you can spot the trap.

Can't I just spot a phishing email by bad grammar?

Nope. That's a dangerous myth. AI has changed the game. Many phishing emails now have perfect grammar and spelling (CISA). So stop looking for typos and start looking for the real signs: urgent language, threats, requests for personal info, and links that don't match the stated destination. Hover over any link before you click—if the URL looks weird or doesn't match the company, don't click. And if a message seems urgent, pause. That's your gut telling you something's off.

What should I do if I get a suspicious message?

Follow the three R's: Recognize, Resist, Delete (CISA). Recognize the signs—urgency, unusual sender, unexpected attachment. Resist the urge to click, reply, or call any number in the message. Even the 'unsubscribe' link can be a trap. Then delete it. If you think the message might be real, don't use the contact info in the message. Look up the company's official website or phone number separately and reach out that way (CISA). That's the safe move.

Will multi-factor authentication save me?

Mostly, yes, but you have to do it right. Turning on MFA blocks over 99.9% of account compromise attacks (Microsoft). That's huge. But not all MFA is equal. SMS codes can be intercepted through SIM swapping, and attackers can use push bombing to trick you into approving a login. The gold standard is phishing-resistant MFA—like a hardware security key or passkey (CISA). If you can't do that yet, use an authenticator app or push notification with number matching. Avoid SMS unless it's your only option.

Is it safe to write down my passwords?

Yes, as long as you keep the paper somewhere safe (NCSC). But honestly, the better move is to use a password manager. It generates and stores unique, random passwords for every account, so you never reuse the same one twice (CISA). That's important because password reuse is how attackers get in—they take a password from one breach and try it on your bank account (Microsoft). So let a password manager do the heavy lifting. And check if your email has been in a breach using a service like Have I Been Pwned (CISA).

Quick tip: If you get a text from your 'bank' asking you to verify a charge, don't click the link. Call the number on the back of your card.

Bottom line

The single best move you can make is to turn on phishing-resistant MFA on your most important accounts—especially email and banking. It's one step, and it blocks nearly all account attacks (Microsoft). Do that today.

Sources

  • APWG Phishing Activity Trends Report - https://apwg.org/trendsreports/
  • CISA Recognize and Report Phishing - https://www.cisa.gov/secure-our-world/recognize-and-report-phishing
  • CISA Turn On MFA - https://www.cisa.gov/secure-our-world/turn-mfa
  • FBI IC3 2024 Internet Crime Report - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • Microsoft Security Blog - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • NCSC Three Random Words - https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words

Share this article:

Comments (0)

No comments yet. Be the first to comment!