Phishing Email Red Flags: How to Spot a Scam
Phishing is the #1 reported cybercrime. Learn the critical phishing email red flags that protect your money, identity, and accounts from fraudsters.
Your inbox is the most targeted attack surface in the digital world. Phishing — the practice of sending deceptive emails designed to steal your credentials, money, or personal data — is not just common; it is the single most reported category of cybercrime in the United States. According to the FBI's 2024 Internet Crime Report, phishing and spoofing accounted for 193,407 complaints, more than double the next most-reported crime category. And the financial damage is accelerating: by 2025, reported losses tied directly to phishing jumped to $215.8 million — a 208% year-over-year increase — while business email compromise, which frequently begins with a phishing email, added another $3 billion in losses. These are not abstract statistics. They represent real people who missed a red flag that you can learn to spot today.
What Is Phishing and How It Works
Phishing is a form of social engineering in which a criminal sends a fraudulent email impersonating a trusted entity — a bank, a government agency, a shipping carrier, a workplace colleague, or even a friend. The FTC explains that scammers send phishing emails pretending to be companies you might know and trust, with the goal of getting you to click links or open attachments. Once you do, one of two things happens: you are redirected to a fake login page designed to harvest your username and password, or a malicious file downloads malware onto your device. What makes phishing so dangerous is that it bypasses technology entirely. As security researchers note, phishing emails exploit cognitive biases related to urgency, authority, and familiarity rather than technical vulnerabilities — meaning even organizations with mature security infrastructure remain exposed when individuals cannot identify the red flags at the point of delivery. AI is sharpening the threat further: AI-related fraud complaints crossed 22,000 in 2025, with scammers using large language models to craft grammatically flawless, highly personalized lure emails that are increasingly difficult to detect on style alone.
Warning Signs to Watch For
Knowing the red flags of a phishing email is your most reliable defense. Here are the key indicators to scrutinize before you click anything:
**1. Urgent or threatening language.** Phishing emails manufacture a crisis to short-circuit your judgment. Watch for phrases like 'Your account will be closed,' 'Immediate action required,' or 'Verify your information now or lose access.' Legitimate companies do not threaten customers with adverse action on a tight deadline.
**2. Mismatched sender addresses and spoofed domains.** The display name of an email can say anything �� always inspect the actual sending address. Fraudsters register lookalike domains (e.g., 'Amaz0n.com' instead of 'Amazon.com') or use free email services to impersonate corporate accounts. If the sender's email address does not precisely match the organization it claims to represent, treat it as suspect.
**3. Generic, impersonal greetings.** Phishing emails often address recipients as 'Dear Customer,' 'Dear Account Holder,' or 'Dear Valued Member' because attackers are blasting the same message to millions of people. A legitimate company that has a relationship with you will typically address you by name.
**4. Requests for personal information or payment credentials.** The FTC is clear: while real companies might communicate with you by email, legitimate companies won't unexpectedly email or text with a link to update your payment or account information. Any email asking for your Social Security number, bank account number, passwords, or credit card details is a major red flag.
**5. Suspicious links and attachments.** Hover over any link before clicking — the URL that appears in the status bar is the real destination, and it may reveal a completely unrelated or misspelled domain. Unexpected attachments, even from senders you recognize, should be treated with extreme caution, as they may install malware on your device.
**6. Unusual requests dressed as ordinary communications.** The FTC has warned specifically about a wave of fake event invitation emails spoofing services like Evite and Paperless Post. These emails ask victims to input login credentials, a phone number, or a special code just to 'open' or 'RSVP' to the invitation — that is not how real invitations work. Any email that asks you to log in or register to perform a basic action is a red flag.
**7. Odd URLs and mismatched branding.** Even if the logo and color scheme look right, inspect every link. A phishing page may live at a subdomain like 'paypal.secure-login.xyz' — where the trusted brand name appears but the actual domain belongs to the attacker.
How to Protect Yourself
Awareness is the first layer of defense, but it must be paired with consistent habits. The FTC recommends several concrete protective measures. First, do not click links or download attachments in unexpected messages — if you think a message might be legitimate, go directly to the company's website by typing the address in your browser or use a phone number you find independently. Second, enable two-factor authentication (2FA) on every account that supports it. Even if a phisher captures your password, 2FA creates a second barrier they cannot easily bypass. Third, keep your security software updated; current antivirus and anti-malware tools can intercept known phishing payloads and malicious domains before they do damage. At the organizational level, Massachusetts state cybersecurity guidance recommends using email filters that can prevent phishing messages from ever reaching employee inboxes, and verifying any unusual financial or credential request by contacting the supposed sender through a known, separately verified phone number or email — never through contact information provided in the suspicious message itself.
What to Do If You're Targeted
If you receive a phishing email, do not engage with it: do not click links, do not reply, and do not download attachments. Report the message using your email client's 'Report Phishing' function, which helps train filters and alerts providers. Forward phishing emails impersonating a federal agency or major company to reportphishing@apwg.org and to the FTC at ReportFraud.ftc.gov. If you believe you clicked a malicious link or entered your credentials on a fake site, act immediately: change your passwords on the affected accounts and on any other account that uses the same password, enable 2FA if you have not already, and monitor your financial accounts for unauthorized transactions. If sensitive personal information such as your Social Security number was compromised, visit IdentityTheft.gov for step-by-step recovery guidance tailored to your situation. Finally, file a complaint with the FBI's Internet Crime Complaint Center at IC3.gov. The FBI urges everyone to 'Take a Beat' — resist pressure to act quickly, assess the situation, and report suspected fraud. Every complaint helps law enforcement map criminal networks and protect future victims.
- 01How To Recognize and Avoid Phishing Scams | Consumer Advice— FTC
- 02FBI Releases Annual Internet Crime Report— FBI / IC3
- 03FBI IC3 2025 report: Email fraud is now a $4 billion problem— Red Sift
- 042025 Cybersecurity Awareness Month: Recognize and Report Phishing— Commonwealth of Massachusetts
