SECTION TechnologySUBJECT SecurityPUBLISHED Jun 6, 2026READ TIME 8 MIN
Technology Explainer / Strong
How to Recognize and Contain Phishing
Phishing was the single most reported cybercrime to the FBI in 2024, ahead of every other category by a wide margin. CISA and the FTC both build their guidance around the same core move: verify urgent or unusual requests through a channel the sender didn't hand you.
CCBy Culture Column EditorialPublished Jun 6, 2026
The argument
Phishing succeeds by manufacturing urgency and supplying its own verification, a link, a phone number, a reply address, all controlled by the attacker; the single move CISA and the FTC both center their guidance on is refusing that supplied channel and instead verifying the request through contact information you already had before the message arrived.
The question
What this page answers
I get texts and emails that look like they're from my bank or delivery services constantly. How do I actually tell a real one from a scam, and what should I do when I'm not sure?
The points
What to take from this
01
Phishing/spoofing generated 193,407 complaints to the FBI's Internet Crime Complaint Center in 2024, more than double the next most common category (extortion) and nearly three times personal data breaches.
02
The FTC and CISA both recommend the same core check: contact the company or person through a phone number or website you already know is real, never through the link, number, or reply address the suspicious message itself provided.
03
Business email compromise, a targeted form of phishing that impersonates an executive or vendor, caused $2.7 billion in reported losses in 2024 from just 21,442 complaints, roughly 100 times the average per-incident loss of ordinary phishing.
04
Reporting a phishing attempt (forwarding it, using the built-in report function, or filing with IC3) helps providers block the sender and warn others, and takes less effort than most people assume.
In 2024, the FBI's Internet Crime Complaint Center received 193,407 complaints classified as phishing or spoofing, more than double the number of the next most common crime type (extortion, at roughly 96,900) and nearly triple the number of personal data breach complaints. That single category made up close to a quarter of all 859,532 complaints IC3 received that year. Phishing isn't a niche threat that occasionally slips through; it's the primary way most other online crime gets started, which is why CISA's joint guidance with the FBI describes it as "phase one" of the broader attack cycle rather than a category of crime on its own.
The mechanics behind nearly all of it are the same, whether it arrives as an email, a text message (sometimes called smishing), or a phone call (vishing): a message manufactures urgency, then supplies its own way to resolve that urgency, a link, a phone number, a QR code, all controlled by whoever sent it. The fix CISA and the FTC both converge on isn't a list of red flags to memorize. It's refusing the channel the message hands you and using one you already had.
Start with what makes a message worth pausing on. CISA's guidance names urgency as the mechanism to watch for specifically, messages that claim dire consequences for not responding immediately, or that pressure you to act before you'd normally have time to think it through. The FTC's consumer guidance describes the same pattern from the other direction: phishing messages "often tell a story to trick you into clicking on a link or opening an attachment," typically posing as a company or person you already trust, a bank flagging suspicious activity, a delivery service with a package problem, a coworker sending an urgent file. The story exists to short-circuit the pause where you'd normally check whether the request makes sense.
A second, more mechanical check: CISA recommends hovering over any link before clicking it. If the URL that appears doesn't match the text describing it, or routes through a domain that isn't the company's actual domain, that mismatch alone is enough reason to stop. This catches a large share of phishing attempts, but it's not sufficient on its own; sophisticated attempts now register domains that are one character off from the real one, or use link-shortening services that hide the destination entirely until you've already clicked.
FIG. 01
What to do when a message asks you to act urgently
You get an unexpected message asking you to click a link, verify an account, or send information right away. What now?
01
Does the message supply its own way to verify it?
A link to "confirm your account," a phone number to "call immediately," or a reply address are all channels the sender controls.
Yes, it wants you to use the link/number/address in the messageDo not use it. This is the exact pattern CISA and the FTC flag: legitimate urgent requests don't require you to use a channel a stranger just handed you.
No specific action requested, just informationalLower urgency doesn't mean automatically safe, but it removes the time pressure. Take the extra minute to check sender details before doing anything.
02
Find contact information you already had
Go to the company's app, a past statement, the number on the back of your card, or type the company's known web address directly rather than searching or clicking.
The claim checks out through the independent channelProceed through that verified channel, not the original message, even if it turns out to be legitimate.
The claim doesn't check out, or the company has no record of itIt was phishing. Don't reply, don't click anything else in the message, and report it.
03
Report and delete
Use your email or messaging app's built-in report/spam function, or forward to the FTC and IC3.
ReportedHelps providers block the sender and improves spam filtering for others receiving the same message.
FIG. 02FBI IC3 complaints by crime type, 2024
Phishing/Spoofing193407Losses exceeded $70 million
Extortion96900Roughly half of phishing's complaint volume
Personal Data Breach64882$1.45 billion in reported losses
Business Email Compromise21442$2.7 billion in reported losses despite far fewer complaints
Phishing was the single most-reported cybercrime category to the FBI in 2024 by a wide margin, but business email compromise, a targeted phishing variant, caused far more financial damage per complaint, showing that volume and severity are separate problems.
2024 Internet Crime Report · accessed 2026-08-11 · Complaint counts and loss figures as reported to the FBI's Internet Crime Complaint Center for calendar year 2024.
That gap between phishing's complaint volume and business email compromise's dollar losses is worth sitting with. Ordinary phishing, the mass-sent fake delivery notice or bank alert, is a numbers game: attackers send huge volumes hoping a small percentage of recipients click. Business email compromise is the same underlying technique, an impersonated sender manufacturing urgency, but aimed narrowly: an email that appears to come from a company's CEO or a known vendor, asking someone in finance to wire money or change a payment account, sent to someone specifically positioned to act on it. IC3 recorded $2.7 billion in reported losses from BEC in 2024 from only 21,442 complaints, an average loss per incident roughly 100 times higher than what ordinary phishing produces. The lesson isn't that BEC deserves more fear than mass phishing; it's that the same verification habit, confirming any request to move money or change account details through a separate, known channel, like calling the person directly on a number you already had, stops both.
Signing in through a link in a message deserves its own specific caution beyond the general urgency check, because it's a distinct pattern from being asked to send information directly. A message that says "sign in to verify your account" and provides a link is, structurally, asking you to type your username and password into a page the sender built. Even when that page is a near-perfect copy of the real login screen, it's capturing whatever you type rather than checking it against the real service. The safer path is the same independent-channel principle applied to sign-in specifically: open the app you already have installed, or type the company's address into your browser directly, rather than trusting a link to take you to the real thing.
None of this requires spotting a scam through visual polish or a familiar-looking sender name, and that's an important qualifier, because attackers have gotten good enough at both that neither is a reliable signal anymore. A phishing email can use a company's real logo, matching fonts, and a spoofed sender address that displays the real company name. The verification move doesn't depend on catching a design flaw; it depends on refusing to use any contact method the message itself supplied, no matter how convincing that message looks.
The steps
Recognizing and containing a suspected phishing attempt
01
Notice the urgency, then treat it as a signal, not a reason to hurry
Legitimate account or security issues rarely require action within minutes; the pressure itself is often the tell.
02
Never use the link, phone number, or reply address the message provides
Go to the company's app, a saved bookmark, or a document you already had, like a billing statement or the number on your card.
03
Check where a link actually goes before clicking
Hover over it (on desktop) or long-press it (on mobile) and compare the real destination to the text describing it.
04
Treat requests to move money or change payment details as high-risk regardless of who appears to be asking
Confirm by phone, using a number you already had, especially for anything resembling business email compromise.
05
Report it, then delete
Use your email or SMS app's built-in report function, or forward to the FTC at reportfraud.ftc.gov and file with IC3.gov for anything involving financial loss.
The questions
Questions
01
I already clicked a phishing link but didn't enter any information. Am I at risk?
Clicking a link alone is lower risk than entering credentials, but the FTC recommends running a security scan and updating your device's software if you clicked, since some phishing links attempt to install malware just from the page loading, not only from what you type into it.
02
What should I do if I already entered my password on a phishing site?
Change that password immediately on the real site, and change it anywhere else you reused it. If the account offers MFA, this is also the moment to confirm it's still enabled, since some phishing kits attempt to disable it during the compromise.
03
How do I report a phishing text message specifically?
Most phone carriers and messaging apps support forwarding suspicious texts to 7726 (SPAM) or using a built-in report function; the FTC also accepts reports for text-based scams at reportfraud.ftc.gov.
Phishing's scale, the largest single crime category the FBI tracks online, comes from how cheaply it can be sent and how few responses it needs to be profitable. That scale is also why the defense doesn't need to be sophisticated to work. The independent-channel check, confirming any unexpected or urgent request through contact information you already had rather than what the message supplied, closes off the entire mechanism phishing depends on, regardless of how convincing the message looks or which channel it arrived through.
A password manager only fixes the problem it was built for: reused, weak, or memorized passwords. What determines whether it's actually worth adopting is how it handles the vault's own protection and what happens the day you lose access to it.