Phishing and Social Engineering: How Scammers Trick You and How to Stay Safe
Phishing and social engineering attacks are the entry point for most financial fraud. Scammers use fake emails, texts, phone calls, and manipulation tactics to steal passwords, account numbers, and money. Here is how to spot and stop these attacks.
Phishing is a type of cyberattack where criminals impersonate legitimate organizations — banks, brokerages, government agencies, or trusted companies — to trick you into revealing sensitive information. Social engineering takes this further by psychologically manipulating you into taking actions that compromise your security. Together, they are the most common starting point for identity theft, account takeover, and investment fraud. The FBI's Internet Crime Complaint Center reported over 300,000 phishing complaints in 2024 alone, with adjusted losses exceeding $50 million. But the real number is likely far higher, as many attacks go unreported.
Real-world example: In 2024, a sophisticated phishing campaign targeted Fidelity and Charles Schwab customers. Victims received emails that appeared to come from their brokerage, warning of "suspicious login activity." The email contained a link to a fake login page that looked identical to the real site. When victims entered their credentials, the scammers captured them and immediately transferred funds to offshore accounts. Victims lost an average of $15,000 before the scam was shut down.
Types of Phishing Attacks
Email Phishing
The most common form. Scammers send mass emails that appear to come from legitimate companies, government agencies, or financial institutions. These emails typically create urgency — "your account has been compromised" or "you have an unclaimed tax refund" — and include a link to a fake website or an attachment containing malware. Look for generic greetings ("Dear Customer" instead of your name), spelling and grammar errors, mismatched or suspicious sender addresses, and URLs that differ slightly from legitimate domains (e.g., "amaz0n.com" instead of "amazon.com").
Smishing (SMS Phishing)
Phishing attacks delivered via text message. Smishing has grown rapidly because people tend to trust text messages more than email and are more likely to click links on their phones. Common smishing lures include fake package delivery notifications ("your package is on hold — update your address"), bank fraud alerts, and fake account verification requests. Never click links in unsolicited text messages. Verify directly with the company using their official website or phone number.
Vishing (Voice Phishing)
Phone call-based phishing. Scammers call posing as bank fraud departments, IRS agents, tech support, or utility companies. They use caller ID spoofing to make the call appear to come from a legitimate number. Common vishing tactics include claiming your computer has a virus (remote access scams), threatening arrest for unpaid taxes, or asking you to verify account details. Legitimate organizations will never ask for your password, PIN, or two-factor authentication code over the phone.
Spear Phishing
Targeted phishing aimed at specific individuals or organizations. Unlike mass phishing, spear phishers research their targets — using LinkedIn, company websites, or social media — to craft personalized messages. A spear phishing email might reference a real colleague, a recent project, or a specific vendor. This makes it far more convincing than generic phishing. Business email compromise (BEC) attacks are a sophisticated form of spear phishing that target executives and finance departments to initiate fraudulent wire transfers.
Clone Phishing
Scammers take a legitimate email you have received, clone it, and resend it with malicious links or attachments substituted for the originals. The cloned email appears genuine because it is almost identical to a message you have seen before. The scammer might claim it is an updated version or a correction of the previous email.
Social Engineering Tactics
Pretexting
The scammer creates a fabricated scenario (pretext) to extract information. For example, someone might call posing as an IT support technician needing your password to fix an "urgent security issue," or a researcher conducting a survey that asks about your banking habits. Pretexters often have researched their target in advance and use specific details to build credibility.
Baiting
Scammers offer something enticing — free software downloads, USB drives left in parking lots, or "exclusive investment opportunities" — that contains malware or leads to a phishing site. The bait exploits curiosity or greed. Once you take the bait, your device is compromised.
Quid Pro Quo
A scammer promises a service or benefit in exchange for information. Common examples include "free credit report" offers that ask for your Social Security number, or "free portfolio review" calls from fake financial advisors who want your account details.
Tailgating (Piggybacking)
An attacker physically follows an authorized person into a restricted area. While less common in digital fraud, tailgating is often used in corporate espionage and can lead to physical access to financial records.
Deepfake Social Engineering
An emerging threat. Scammers use AI-generated voice clones or video deepfakes to impersonate executives, family members, or business partners. In one documented case, criminals used a deepfake of a CEO's voice to authorize a fraudulent $243,000 wire transfer. As AI technology improves, these attacks will become more common and harder to detect.
Red Flags and Warning Signs
Urgency and Pressure
Phishing emails and calls almost always create a false sense of urgency. "Act now or your account will be closed." "Your payment is overdue — immediate action required." "Limited time offer." Scammers use urgency to bypass your critical thinking. Legitimate organizations give you reasonable time to respond.
Requests for Sensitive Information
No legitimate company will ask for your password, PIN, Social Security number, credit card CVV, or two-factor authentication code via email, text, or phone. If someone asks for these, it is a scam. Period.
Unsolicited Contact
Be skeptical of any unexpected contact from a financial institution, even if the caller ID or email address looks legitimate. Hang up and call the official customer service number. Do not use any phone number provided in the suspicious message.
Suspicious Links and Attachments
Hover over links before clicking to see the actual URL. Look for slight misspellings (g00gle.com instead of google.com), unusual domain extensions, or URLs that do not match the supposed sender. Never open attachments from unknown senders — they may contain ransomware or keyloggers.
Poor Grammar and Branding
Many phishing emails contain spelling mistakes, awkward phrasing, or low-quality logos. However, sophisticated attacks may use perfect grammar and professional branding. Do not rely on grammar alone as a warning sign.
Ransomware: When Phishing Leads to Data Hostage-Taking
Ransomware is a type of malware that encrypts the victim's files and demands payment — usually in cryptocurrency — for the decryption key. Ransomware is most commonly delivered through phishing emails containing malicious attachments or links. The email might appear to be an invoice, a shipping notification, a resume, or a document from a colleague. When the victim opens the attachment or clicks the link, the ransomware encrypts their files and displays a ransom note. The ransom demand typically ranges from a few hundred to thousands of dollars. Paying the ransom does not guarantee you will get your files back — some victims pay and receive nothing. The FBI advises against paying ransomware demands because it funds criminal operations and encourages more attacks. The best defense is prevention: regularly back up your files to an external drive or cloud storage that is not continuously connected to your computer; keep your operating system and software updated; use reputable antivirus and anti-malware software; never open unexpected attachments or click links in unsolicited emails; and use email filtering that blocks suspicious attachments. If you are infected with ransomware, disconnect your device from the network immediately, do not pay the ransom, and report the attack to the FBI's IC3 at ic3.gov. Learn about data breach response →
Screen Sharing Scams
Screen sharing scams are a hybrid of phishing and tech support fraud. The scammer convinces the victim to install remote access software — such as AnyDesk, TeamViewer, or GoToMyPC — on their computer. The scammer claims to need remote access to fix a computer problem, install security updates, or help with a banking issue. Once they have access, the scammer can see everything on the victim's screen, including banking websites, passwords, and account balances. They may directly transfer money from the victim's accounts or install malware that captures future keystrokes. The scammer often walks the victim through logging into their bank account "to verify the fix," then secretly transfers funds while the victim watches. Legitimate tech support companies never ask you to install remote access software unsolicited. If someone you do not know asks you to install remote access software, it is a scam. If you have installed remote access software for a scammer, immediately uninstall it, change all your passwords, contact your bank to freeze your accounts, and run a full antivirus scan. Report screen sharing scams to the FTC and the FBI's IC3. Learn about impersonation scams →
How to Protect Yourself
Enable two-factor authentication (2FA) on every financial account and email account. Use an authenticator app rather than SMS-based 2FA when possible, as SIM-swapping attacks can bypass text message verification. Never share your 2FA codes with anyone — legitimate companies will never ask for them. Use a password manager to generate and store unique, complex passwords for each site. Do not reuse passwords across financial accounts. Verify unexpected communications by contacting the organization directly through their official website or phone number — never use contact information from the suspicious message. Keep your devices, browsers, and antivirus software updated. Be cautious about what you share on social media — scammers use personal details to craft convincing spear phishing attacks. If you receive a suspicious email or text, report it. In the US, forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org. Report phishing to the FTC at reportfraud.ftc.gov.
What should I do if I fall for a phishing attack?
Act quickly. First, change the password for the compromised account immediately. If you use the same password elsewhere, change it there too. Second, contact your bank, brokerage, or credit card company to freeze the account and reverse any unauthorized transactions. Third, enable 2FA if it was not already active. Fourth, check your accounts for any changes to contact information, automatic transfers, or beneficiary designations. Fifth, report the attack to the FTC at reportfraud.ftc.gov and to the FBI's Internet Crime Complaint Center at ic3.gov. If you shared your Social Security number, place a fraud alert on your credit reports and consider freezing your credit. Monitor your accounts closely for at least six months after the attack, as scammers often wait before using stolen information.
Related Resources
Identity Theft Protection
How to safeguard your personal information and recover if your identity is stolen.
Business Email Compromise
How BEC attacks target companies and how to implement payment verification protocols.
Impersonation Scams
How scammers impersonate government agencies, banks, and trusted organizations.