Last year, the FBI's Internet Crime Complaint Center logged 193,407 phishing and spoofing complaints (FBI IC3). That's more than any other crime category. And it's not just the volume that stings—Verizon found that 68% of data breaches involve a human element, meaning someone clicked, typed, or trusted when they shouldn't have (Verizon). You don't want to be that stat. This drill is for anyone who uses email, texts, or QR codes—which is everyone. I'm going to walk you through a five-step, threat-alert drill you can run in under two minutes. By the end, you'll have a habit that blocks most attacks cold.
Step 1: Pause Before You Click—Urgency Is a Red Flag
Phishing works because it makes you feel rushed. 'Your account will be locked in 24 hours.' 'Unusual sign-in detected, verify now.' That urgency is the hook. The fix is simple: pause. Before you click anything, take a breath. Hover over the link and look at the actual URL. Does it match the sender's claimed domain? Check the sender's email address for misspellings—like '[email protected]' instead of 'amazon.com.' This is step one because it's the cheapest and fastest way to filter out the obvious junk. It's not foolproof, but it stops a huge chunk of attacks.
Step 2: Know the Phishing Family—Smishing, Vishing, Quishing
Phishing isn't just email anymore. It's SMS (smishing), voice calls (vishing), and even QR codes (quishing). All of them play the same game: fake urgency, fake authority, and a request for credentials or money. The same pause-and-verify rule applies. If a text from your 'bank' asks you to click a link, call the number on your card instead. If a QR code in a parking garage promises a discount, think twice—that QR could take you to a lookalike site. CISA calls out these variants explicitly, and they're all part of the same threat family (CISA).
Step 3: Turn On Phishing-Resistant MFA—Now
If you don't have multi-factor authentication (MFA) on your email, banking, and cloud accounts, stop reading and go enable it. Microsoft says MFA blocks over 99.9% of account compromise attacks (Microsoft). That's the single most effective control you can add. But not all MFA is equal. SMS codes are vulnerable to SIM swapping—a social engineering attack where a criminal convinces your carrier to transfer your number to their phone. Instead, use an authenticator app or a hardware key. CISA calls phishing-resistant MFA (like FIDO2 keys or passkeys) the gold standard because it resists phishing, push bombing, SS7 attacks, and SIM swaps. If you can't use that yet, app-based one-time passwords are better than SMS. Make the switch today.
Step 4: Check Your Breach Exposure—and Rotate Stolen Passwords
Here's a scenario: You reuse the same password for your email and a random forum. That forum gets breached. Now your email is exposed. How do you know? Use Have I Been Pwned—a free service that checks your email or username against known breaches. It was created after the Adobe breach, which exposed millions of accounts, and it's been running since 2013 (Have I Been Pwned). If you find your credentials in a breach, change that password immediately. And if you're reusing passwords, stop. Use a password manager to generate and store unique, random passwords for every account. That's non-negotiable. It's the only way to prevent credential stuffing, where attackers try your leaked password on other sites.
Step 5: Run the Drill—And Know What Can Go Wrong
Here's the drill: When you get an unexpected message asking for credentials, money, or urgent action, do this: 1) Pause. 2) Verify the sender through a different channel. 3) Check the URL. 4) Don't use the link they gave you—navigate directly to the site yourself. 5) If it's a business email compromise (BEC) attempt, report it to your IT team or the FBI's IC3. What can go wrong if you skip this? In 2024, the average loss per IC3 complaint was $19,372 (FBI IC3). That's a real number. One click can cost you that much. Don't let it be you.
Bottom Line
The best move you can make today is to enable phishing-resistant MFA on your most important accounts. It blocks 99.9% of attacks. Everything else is a safety net.
Sources
- CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
- CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
- Have I Been Pwned (About) - https://haveibeenpwned.com/About
- Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
- Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!