Twenty years ago a scam email was easy to spot: bad spelling, a strange greeting, a logo that looked wrong. Those days are over. A fake message from a bank, from Amazon, from the Post Office or from Microsoft now looks exactly like the real thing, because it was copied from the real thing. The way to stay safe has changed too.
Stop judging the look
The logo, the layout, the footer, the legal wording: all of it can be copied in seconds. A perfect-looking email proves nothing. Likewise, a real email can look a little odd, because companies change their designs. Looks are not evidence either way.
What the message wants you to do
Every scam email has the same shape: something urgent has happened, and you must click a link or open an attachment to deal with it. Your account is locked. A payment failed. A package could not be delivered. Someone signed in from a new device. A refund is waiting.
Real companies send messages like this too, which is why the trick works. The difference is what happens next. A scam needs you to act through its link, right now, before you think. So the rule is simple: never act through the link in the email.
The habit that makes you safe
If an email says something is wrong with an account, go to that account the way you normally would. Type the bank's address into the browser, or open its app, or use the bookmark you already have. Sign in there. If something is really wrong, it will be waiting for you. If nothing is wrong, the email was a fake, and you have lost nothing.
This works for every company, every time, and it does not depend on you spotting anything. It is the one habit we most want people to have.
Checks that still help
If you want to look closer before deleting, these are worth a moment:
- The sender's actual address. Tap or hover over the sender name to see the address behind it. A message from "Chase" sent from a random address is a fake. Be aware that a convincing address can be faked too, so a good-looking address is not proof.
- Where the link really goes. On a computer, rest the mouse over the link without clicking, and the real address appears at the bottom of the window. On a phone, press and hold the link to preview it. If the address is not the company's own, it is a fake.
- How it addresses you. Your bank knows your name. "Dear customer" is a mark against it, though not proof.
- Attachments you did not expect. An invoice, a statement or a document from a company you do not deal with is a trap. Do not open it.
Text messages and phone calls
The same scam arrives by text, usually about a package or a toll charge, and by phone, usually claiming to be your bank's fraud department. Treat them the same way. Do not tap the link. Do not give any information to a caller. Hang up and call the number on the back of your card.
Real banks will never ask you to move money to a "safe account", to read out a code that was just texted to you, or to install software. Anyone who asks for those things is a criminal, however calm and professional they sound.
If you already clicked
- If you only clicked and looked, and entered nothing, you are almost certainly fine. Close the page.
- If you entered a password, change it now, from a different device if you can, and turn on two-step sign-in. Change it anywhere else you used the same password.
- If you entered card or bank details, call the bank on the number on your card, and tell them what happened.
- If you opened an attachment or installed something, disconnect the computer from the internet and have it checked before using it for anything important.
Turning on two-step sign-in
The reason a stolen password matters so much is that on its own it opens the account. Two-step sign-in, where a code from your phone is also needed, means a stolen password is useless by itself. Our guide to passwords and two-step sign-in explains how to set it up for the accounts that matter most.