Skip to main content
Phishing Scams

You're One Phish Away From Losing $19,372: How to Fight Back

Phishing is the most-reported cybercrime, with 193,407 complaints in 2024. Here's how to spot it, resist it, and delete it before it costs you.

Here's a number that should make you pause: in 2024, the FBI's Internet Crime Complaint Center (IC3) received 193,407 complaints about phishing and spoofing — more than any other crime category (FBI IC3, 2024 Internet Crime Report). And the average reported loss per complaint across all cybercrimes that year was $19,372 (FBI IC3). That's not a typo. One successful phish can cost you nearly twenty grand—or worse, unlock your entire digital life.

You're not a tech wizard. You don't work in security. You're just someone with an email account, a bank app, and a phone that buzzes with texts you half-trust. That's exactly who phishers want. They're not breaking into your computer with code; they're breaking into your brain with psychology. But here's the blunt truth: you can stop most of these attacks by learning a few habits that take seconds. And the most important habit is this: treat every unexpected message as a potential phish until proven otherwise.

Imagine You're a Small Business Owner

Let's make this real. You run a small online store. You have three employees, a website, and a business email. One morning, you get an email that looks like it's from your bank: "Urgent: Your account has been locked. Verify your identity within 24 hours or your account will be suspended." There's a button that says "Confirm Now." Your heart skips. You're busy. You've got orders to ship. What do you do?

If you click that button, you might land on a fake login page that steals your credentials. Or you might download malware that encrypts your files and demands a ransom. Phishing is often the entry point for ransomware, which encrypts your data and demands payment for decryption (CISA, StopRansomware Guide). And ransomware complaints to the FBI rose 9% from 2023 (FBI IC3). Your business could be next.

The Anatomy of the Bait

Phishers are masters of urgency and fear. They want you to act before you think. CISA's advice is simple: pause, hover over links to see the real URL, and check the sender's address for misspellings (CISA, Secure Our World). In the email above, the sender might be "[email protected]" instead of "[email protected]." That's a red flag.

But here's the new twist: AI has made phishing emails nearly flawless. Gone are the days of obvious grammar mistakes. CISA warns that in the era of AI, phishing emails may have perfect grammar and spelling, so you must also watch for urgent language and requests for personal information (CISA, Recognize and Report Phishing). The email might even use your name and reference your actual bank. That's because your data may have been leaked in a breach—check Have I Been Pwned to see if your email has appeared in known breaches (Have I Been Pwned, About).

The Step-by-Step Defense: Recognize, Resist, Delete

CISA's guidance boils down to three actions: Recognize, Resist, Delete (CISA, Recognize and Report Phishing). Let's walk through that with the bank email.

  • Recognize: Spot the signs. Urgent language? A request for personal information? A link that looks off? If yes, treat it as a phish.
  • Resist: Do not click any link or call any number in the message. Instead, look up the bank's official website or phone number separately (CISA, Recognize and Report Phishing).
  • Delete: Report the phish, then delete the message without replying or clicking anything—including "unsubscribe" links (CISA, Recognize and Report Phishing).

In our scenario, you'd close the email, go to your bank's website by typing the URL yourself, and log in normally. You'd find no lock on your account. Crisis averted.

Phishing Isn't Just Email: Smishing, Vishing, and Quishing

Phishing has gone mobile. CISA notes that phishing variants include smishing (SMS), vishing (voice), and quishing (malicious QR codes) (CISA, Secure Our World). And Verizon's 2026 Data Breach Investigations Report says mobile devices are a new favorite target—people are often more likely to fall for a fake text or scam call than a traditional email (Verizon, 2026 DBIR).

So imagine you get a text: "Your package is on hold. Click here to reschedule delivery." That's smishing. Or a caller claims to be from Microsoft support, saying your computer has a virus—that's a tech support scam, which drew 21,403 complaints to the FBI in 2024 with reported losses of about $1.46 billion (FBI IC3). The same rules apply: don't click, don't call, don't engage. Delete and report.

Why MFA Is Your Best Friend (But Only If You Use It Right)

Even if a phisher gets your password, you can still stop them with multi-factor authentication (MFA). MFA requires you to present two or more different authenticators—something you know (password), something you have (phone or key), or something you are (biometric) (CISA, Implementing Phishing-Resistant MFA). Microsoft reports that enabling MFA can block over 99.9% of account compromise attacks (Microsoft Security Blog). That's a staggering statistic.

But not all MFA is equal. CISA documents four ways traditional MFA is bypassed: phishing, push bombing (push fatigue), SS7 vulnerabilities, and SIM swapping (CISA, Implementing Phishing-Resistant MFA). Phishing-resistant MFA, like hardware security keys (FIDO2) or passkeys, is the gold standard because it's resistant to all four (CISA). So, if you can, use a security key or passkey for your email and banking. If not, use an authenticator app or mobile push with number matching. SMS codes should be a last resort (CISA).

In our small business scenario, if you had MFA enabled, even if the fake login page captured your password, the attacker wouldn't be able to get the second factor. They'd move on to an easier target.

The Comparison: What to Use and When

Authentication MethodPhishing-Resistant?How It WorksBest For
Hardware security key (FIDO2)YesPhysical key that uses cryptography to verify your identityEmail, banking, cloud services
PasskeyYesBuilt into your device, uses biometrics or PINMost online accounts
Authenticator app / push with number matchingNo (but strong)Generates a code on your phone or prompts you to approve a loginWhen a security key isn't available
SMS or voice codesNoTexts or calls you with a codeLast resort only

As CISA puts it, FIDO/WebAuthn is the only widely available phishing-resistant authentication (CISA, Implementing Phishing-Resistant MFA). If you're not using it, you're leaving the door open.

What I'd Actually Do

Here's my blunt recommendation: assume every unsolicited message is a phish. That's not paranoia; it's practical. In 2024, phishing was the most-reported crime to the FBI, and the average loss per complaint was over $19,000 (FBI IC3). That's money you can't afford to lose.

Concretely, I'd do this today:

  • Turn on MFA for every account that supports it, preferring phishing-resistant methods like passkeys or security keys, especially for your email and bank.
  • Use a password manager to generate and store unique, random passwords for each account—no more reusing the same one (CISA, Secure Our World). Check your passwords against Have I Been Pwned and change any that are compromised.
  • When you get a suspicious message, don't click. Look up the official contact separately and verify. Then delete and report it.

You're not helpless. You're just one step away from being a hard target. Make that step.

Sources

  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
  • CISA (Recognize and Report Phishing) - https://www.cisa.gov/secure-our-world/recognize-and-report-phishing
  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • Have I Been Pwned (About) - https://haveibeenpwned.com/About
  • Verizon (2026 Data Breach Investigations Report) - https://www.verizon.com/business/resources/reports/dbir/

Share this article:

Comments (0)

No comments yet. Be the first to comment!