Stop before interacting
Leave links, buttons, QR codes, attachments, and reply fields untouched. A message can look polished, use a familiar logo, or appear in an existing conversation and still be fraudulent. Urgency is a reason to slow down, not a reason to bypass verification.
Ask whether the request makes sense
Did you expect this message? Did you initiate the password reset, delivery change, invoice, refund, or security check? The FTC says phishing messages commonly try to obtain passwords, account numbers, or Social Security numbers.[1]
Evaluate the action, not just the sender name
A display name or logo is not proof. Be cautious when a message asks you to sign in, confirm payment details, reveal a one-time code, install software, open an unexpected file, move money, or keep the request secret. Do not rely on a phone number or address included in the message to confirm itself.
Verify through an independent channel
Open the official app, type the known website address yourself, use the number printed on a card or statement, or contact the person through a previously saved number. If the real account shows no matching alert or request, treat the message as suspicious.
Report the message, then delete it
Use the mail or messaging provider’s phishing-report feature when available. The FTC also accepts fraud reports at ReportFraud.ftc.gov and explains that reports help identify patterns and support law-enforcement work, although it does not resolve individual reports.[2]
Act promptly if you clicked or responded
If you entered credentials, open the real service directly, change the password, sign out unfamiliar sessions, and enable MFA. If you shared financial information, contact the financial provider through an official channel. The FTC advises using IdentityTheft.gov for steps tailored to identity information that was lost or stolen.[1]
This checklist is general educational information. If money, identity data, or account access is at risk, contact the affected provider promptly through a verified channel.
