Decorative image of monitor with fished email

 

We are continuing our monthly series about cybersecurity and fraud. Each month, MSRS shares best practices to give you the tools you need to protect yourself and your finances.

About Phishing

Phishing (pronounced fishing) is a technique where scammers use email to trick you into giving them your personal or financial information.

Common phishing examples include:

  • Claiming there’s a problem with your account or your payment information
  • Stating you need to confirm personal or financial information
  • Wanting you to open an attachment to the email
  • Sharing that you’re eligible for something (often too good to be true)

Similar techniques include:

  • Vishing: phishing by phone, voice email, or voice over internet protocol (VoIP) calls
  • Smishing: phishing by text (SMS) messages
  • Pharming: installing malicious code on your computer to redirect you to fake websites

Phishing often uses spoofing techniques to trick you into believing the message is from a trusted company or person. Spoofing disguises an email address, sender name, phone number, or website by changing a letter, symbol, or number so it looks real. Scammers use small differences to trick your eye and gain your trust.

Protect Yourself From Phishing

To protect yourself from phishing,

  • Stay suspicious and alert.
    • Carefully examine email content and look out for generic greetings, misspellings, and bad grammar.
    • Be suspicious of urgent calls to action or threats.
    • Don’t click or download anything in an unsolicited email or text message.
    • If you’re still unsure, look up the company separately and call to ask if the request is legitimate.
  • Be mindful of what you share online.
    • By openly sharing personal information (pet’s name, birthday, high school, etc.), you can give a scammer all the information they need to guess your password or answer security questions.
  • Use multifactor authentication (MFA).
    • Adding this second step makes it harder for scammers to access your account.
    • Keep the MFA code safe, and never share the code with others.
  • Create strong, unique passwords for each account.
    • Use a different password for every account, ideally 16 characters long.
    • Use a password manager to help you organize and remember passwords.
  • Keep your software updated.
    • Software updates fix security vulnerabilities or bugs that a fraudster may try to exploit.

What to Do if You Receive a Phishing Message

If you receive a phishing message,

  1. Don’t click or reply to the message.
    • Don’t click on links in the email, download attachments, or respond to the sender.
    • Even unsubscribe links or buttons can be malicious—do not click them.
  2. Report the message.
    • At work, report the email to your IT or security team.
    • At home, use your email provider’s Report Phishing feature.
    • Forward the phishing email to the Anti-Phishing Working Group at reportphishing@apwg.org or the smishing text message to SPAM (7726).
    • Report the phishing attempt to the Federal Trade Commission (FTC) at ReportFraud.ftc.gov.
    • Report any identity theft and get a recovery plan at IdentityTheft.gov.
  3. Block the sender.
    • Prevent future messages from the same source.
  4. Delete the message.
    • Remove the email from your inbox after you report it.
    • Deleting the message prevents you from accidentally clicking on it in the future.

If you think you’ve been successfully phished, change your password on all affected accounts and anywhere else you used the same password. If you've lost money or if you are a victim of identity theft, report the crime to local law enforcement immediately. Contact banks or other impacted companies to alert them of possible fraud.

Additional Resources

Additional phishing resources include: