CRITICAL THREATUpdated 23 September 202612 min read

Phishing is the most-reported cybercrime in America. Here's how it works.

Spelling errors can be a clue, but a polished message can still be phishing. Criminals can copy branding, personalize a request and use AI to improve the wording. Verify sensitive requests outside the message rather than treating good grammar as a sign of safety.

191,561
FBI phishing reports in 2025
62%
Of breaches involve a human
$216M
US phishing losses in 2025
$893M
AI-related fraud losses in 2025
The short answer

Phishing is a scam where attackers send fake emails, texts, or messages that impersonate a trusted company or person to trick you into revealing passwords, financial details, or clicking malicious links. Good grammar does not establish authenticity. Spelling errors may be a clue, but sensitive requests need independent verification. If you've already clicked something or shared details, skip ahead to our scam recovery guide.

A polished message can still be phishing

Phishing can be generic or carefully tailored. A message may copy a familiar brand, refer to real events or come from a compromised account. The requested action and independent confirmation matter more than how professional it looks.

The FBI counted 191,561 phishing/spoofing complaints and about $216 million in associated reported losses in 2025. Those are complaint statistics, not a count of every attack or a measure of AI use. If you need help identifying which checks fit a message, use our scam checker.

Sources:FBI IC3 2025 Internet Crime Report ↗APWG Phishing Activity Trends Report ↗
FROM THE FIELD

A plausible message can reach someone while they are distracted or busy. That is an analytical explanation of why a familiar-looking request may escape scrutiny, not a claim of documented personal casework. The practical response is to verify sensitive requests through an independently chosen channel.

The 8 types of phishing you'll actually encounter

"Phishing" is an umbrella term. The attack that hits you depends on the channel and the target. Here are the eight variants worth knowing, each with the tell that identifies which one you are looking at. Those tells name the attack. They do not settle it. Independent verification steps follow the list; no single clue settles every case.

Email phishing

The classic: a mass email impersonating a bank, delivery service, or login page, hoping a small percentage click. Volume is the strategy.

The tell: The sender's real address (not the display name) doesn't match the company's true domain.

Spear phishing

A targeted email crafted for one person, referencing your real name, employer, or a recent event to feel legitimate.

The tell: It knows just enough about you to feel personal — but still pushes you toward a link or payment.

Whaling

Spear phishing aimed at executives and finance staff, usually impersonating a CEO or a key vendor to authorize a transfer.

The tell: Urgency plus authority: a 'CEO' asking for a wire or gift cards, often while 'travelling' and unreachable by phone.

Smishing (SMS)

Phishing by text message — fake delivery notices, bank alerts, or toll/road-fee notices with a short link.

The tell: A link in an unexpected text. Check an unexpected request through the official app or a site you locate independently.

Vishing (voice)

A phone call impersonating your bank's fraud department, a government agency, or tech support, pressuring you to act 'to protect your account.'

The tell: They called you, create panic, and ask you to move money, share a code, or install software.

Quishing (QR code)

A QR code — on a flyer, parking meter, email, or fake invoice — that opens a credential-stealing page when scanned.

The tell: A QR code is asking you to log in or pay. Many phone cameras preview the destination before opening it. Read the address, and use the organization’s official app or site instead if the code is unexpected.

Business Email Compromise (BEC)

A compromised or spoofed business account sends a real-looking invoice or payment-detail change to redirect funds.

The tell: A last-minute change to bank details, or a new invoice that breaks the normal process.

Clone phishing

A copy of a genuine email you already received, resent with the links or attachments swapped for malicious ones.

The tell: A 'resend' or 'updated version' of a message you recognise — but the links now point somewhere new.

The hardest version to judge is the one where the service being impersonated is real: bank fraud alerts arrive unprompted, at odd hours, about money, which is exactly the shape of a scam. If yours came from a name you did not recognise, see whether an EnFact notification is real or a scam — verify it with your card issuer; formats can vary, so a single message-format rule is not enough. The channel changes, but the goal never does: get you to act quickly, on their link, before you think. Voice and QR variants use channels outside ordinary email filtering. Several of these — especially vishing and deepfake calls — now overlap with AI-powered scams. The same unsolicited-message playbook also kicks off task scams — the fake "easy online job" that arrives by text, WhatsApp, or Telegram out of nowhere. And the whole pattern inverts if you are the one selling: instead of a fake login page aimed at a buyer, the seller gets a forged payment confirmation and a reason to ship before the money lands, which is how the Wompi scam in Colombia works.

Sources:APWG Phishing Activity Trends Report ↗

For a text claiming to be from a US bank, our bank-text verification guide compares published sender details and explains how to check the alert independently. The number on the screen alone cannot authenticate it.

An unexpected code is a different question from a fake bank alert. Our guide to why Link sends verification codes explains Stripe’s checkout connection and why even a genuine code should not be handed to an unsolicited caller.

Why grammar is not authentication

Spelling and formatting mistakes can raise suspicion. Their absence does not make a message safe: templates, copied legitimate text and AI-assisted writing can all produce convincing copy. We do not have a reliable measure showing that most phishing messages use AI.

Here's what AI actually changed about the attacker's playbook:

What to check instead

Stop judging the writing. Judge the request and the route: Does it create urgency? Does it ask you to log in, pay, or share a code via a link? Would the real organisation ever contact you this way? When unsure, ignore every link and go directly to the official site or app yourself.

FTC: recognizing, responding to and reporting phishing

Verify the request outside the message

Look back at the eight tells above and notice what they have in common. Every one of them is a property of the message: the address behind the display name, the link in the text, the QR code, the changed bank details. The sender controls all of it. With AI writing the copy, cloning the branding and spoofing the number, they now control it well enough that a careful reader can be wrong.

There is one thing the sender does not control: the channel you use next.

The route test

Leave the message. Do not use its link, its number, its attachment or its reply button. Find the organisation yourself: the number printed on your card, the app you already have installed, the address you type in. Ask your question there.

Independently contact the organization through its verified app, site or phone number and check the request. This reduces dependence on details supplied by the sender. A calm reaction from the sender is not proof of legitimacy; the independent confirmation is what matters.

A request to avoid independent checking is a warning. But a cooperative sender can still be fraudulent, so assess what the real organization confirms rather than relying on the sender’s reaction. Our guide to official-sounding claims explains why presentation deserves a separate check.

None of this means stop reading the message. The eight tells above still earn their place: they tell you what you are dealing with, and plenty of phishing is still careless enough to be caught on sight. The claim is narrower and it matters. Inspecting the message is no longer sufficient on its own to decide whether to act. Use the tells to recognise the attack, and use the route test to decide.

Source: FTC, How To Avoid a Scam.

You clicked a phishing link: what to do right now

Clicking happens — to careful people on bad days. What matters is the next few minutes. Work through these in order:

  1. 1.

    Don't enter anything else — if a login or payment page opened, close it. Do not type credentials, codes, or card details into it.

  2. 2.

    Do not open unexpected downloads — if you ran suspicious software or granted remote access, disconnect the affected device from the network and seek technical help.

  3. 3.

    Secure exposed accounts — if you entered a password or code, use a trusted device to change it, review sessions and change reused passwords. A click alone does not prove every account is compromised.

  4. 4.

    Turn on two-factor authentication — add 2FA to email and financial accounts so a stolen password alone isn't enough.

  5. 5.

    Run a malware scan — if you suspect harmful software, update your security tools and scan; seek qualified help if the device may be compromised.

  6. 6.

    Alert your bank — if you entered card or account details, tell your bank immediately and ask them to watch for or block fraudulent activity.

If money already moved, or you shared sensitive personal details, speed matters even more — follow the full playbook in our scam recovery guide, and if your personal data may be exposed, see identity theft.

How to report a phishing email

Reporting takes a minute and helps providers and investigators shut down the campaign for everyone else. Send it to as many of these as apply:

For a full country-by-country directory of where to report different kinds of fraud, see our reporting guide.

Sources:APWG Phishing Activity Trends Report ↗FBI IC3 2025 Internet Crime Report ↗
P
Written by Peter
Founder, Tutela Digitalis • Updated 23 September 2026

Research and educational guidance by Peter. Sources and material corrections are linked on this page.

Frequently Asked Questions

What is phishing?
Phishing is an attempt to obtain information, account access or money through a deceptive message or contact. Email, SMS and voice variants overlap. The FBI counted 191,561 phishing/spoofing complaints in 2025; complaint counts are not the total number of attacks.
How can I check a suspicious message?
Read the exact sender and destination address, but do not rely on appearance alone. Independently contact the organization through its official app, a known website or a number you already have before taking a sensitive action.
What should I do if I clicked a phishing link?
Close the page and do not enter information. If you shared credentials, secure affected accounts from a trusted device and change reused passwords. If you ran suspicious software or granted remote access, disconnect the device and seek technical help. Contact your bank if payment details or money were involved.
How do I report phishing?
Use your email service’s built-in phishing report feature and the impersonated organization’s official reporting route. The FTC also directs phishing emails to reportphishing@apwg.org. Do not guess a provider’s abuse address.

Reviewed 23 September 2026. We corrected overbroad verification and recovery claims during our launch-content review. See the corrections log for the material changes.

Sources & References

Every statistic in this guide is sourced from verified organizations. Click to verify any claim.

FBI IC3 2025 Internet Crime Report ↗Verizon 2025 Data Breach Investigations Report ↗APWG Phishing Activity Trends Report ↗

Think you've been phished?

Don't guess. Get expert guidance on your specific situation.

Book a Consultation →

Continue reading

INVESTMENT

Inside the $11.4 billion crypto scam machine

AI SCAMS

How voice and video impersonation works

RECOVERY

I've been scammed — the first 24 hours