Phishing isn't broken English from a fake prince anymore — modern scammers use AI to write flawless emails that look exactly like your bank, your boss, or your delivery service. One careless click can hand over your passwords and your money. The best defense is a trained eye, not better software.
The Red Flags That Never Change
Urgency is the oldest trick: "Your account will be closed in 24 hours!" Legitimate companies don't pressure you like that. Hover over links before clicking — the real destination often looks nothing like the text. Check the sender's full email address, not just the display name. Any message demanding you act NOW deserves a pause and a second look.
New Tricks in 2026
AI now clones voices from short audio clips, so "your son calling from a police station" can sound terrifyingly real. Deepfake video calls and QR-code phishing (stickers swapped on parking meters and restaurant tables) are rising fast. Business-email scams now include entire fake threads that look like ongoing conversations. If a voice on the phone asks for money urgently, hang up and call back on a number you trust.
What To Do With a Suspicious Message
Don't click, don't download, don't reply. Go to the company's site yourself by typing the address — never through the link in the message. Report phishing emails to your provider's spam button and forward them to your country's fraud-reporting address. When in doubt, verify through a channel YOU start, never one the message provides.
Lock Down Your Accounts
Turn on two-factor authentication everywhere — an authenticator app beats SMS codes. Use a password manager so every site gets a unique, unguessable password. Set up account-login alerts so you hear about break-ins immediately. Two-factor auth blocks most account takeovers even if your password leaks.