Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

Phishing = Fake emails/messages designed to trick you into revealing passwords, credit card numbers, or other sensitive information.
How it works:
Warning signs:
Protection: Never click links in unexpected emails. Go directly to the website by typing the URL yourself.
Two months ago, my dad called me in a panic.
“I just got an email from Amazon saying my account was hacked. I clicked the link and changed my password like they said. But now I can’t log into the real Amazon. What happened?”
He’d fallen for a phishing scam.
The email looked exactly like it came from Amazonβsame logo, same formatting, even a fake order number. But it was a trap. By “changing his password” on the fake site, he’d handed his real Amazon password directly to criminals.
Within an hour, they’d:
My dad isn’t stupid. He’s a retired engineer. But phishing emails have become so sophisticated that even tech-savvy people fall for them.
Let me show you exactly what phishing is, how to spot it, and what to do if you fall for it.

Think of phishing like this:
Real fishing: You put bait on a hook, throw it in water, wait for fish to bite.
Phishing: Criminals put bait in an email (fake urgent message), send it to thousands of people, wait for victims to “bite” (click and enter their info).
The goal is always the same: Trick you into voluntarily handing over:
Why it’s called “phishing”: The “ph” instead of “f” comes from old-school hacker culture. In the 1990s, hackers who hacked phone systems were called “phreaks” (phone + freaks). The spelling stuck for internet scams.
Here’s a typical phishing attack:
Step 1: Criminal creates fake email
Step 2: Criminal sends email to thousands of people
Step 3: You receive the email
Step 4: Fake website looks exactly like the real one
Step 5: You enter your credentials
Step 6: Criminal now has everything
Step 7: Damage is done
The scary part: You voluntarily gave them everything. No hacking required.

Phishing isn’t just emails anymore. Here are the main types:
What it is: Fake emails pretending to be from companies you know.
Common impersonations:
Example subject lines:
What it is: Personalized phishing aimed at a specific person, using information about them.
How it’s different: Instead of “Dear Customer,” the email uses your real name, mentions your job, references recent activities.
Example:
“Hi Sarah,
I noticed you recently purchased a MacBook from our store. We need to verify the shipping address before we can process your order
#847392. Please click here to confirm.
- Apple Store Team”
This is scarier because it feels personal and credible.
What it is: Phishing via text message instead of email.
Common examples:
Why it works: People trust text messages more than emails. We’re used to getting legitimate shipping notifications and bank alerts via text.
What it is: Phishing via phone call.
How it works: Someone calls claiming to be from tech support, your bank, the IRS, etc. They convince you to give info over the phone or install remote access software.
Example:
“This is Microsoft Technical Support. Your computer has been infected with a virus and is sending out your personal information. We need to remote into your computer immediately to fix this.”
What it is: Phishing aimed at high-value targets like CEOs, CFOs, executives.
Example:
Email to CFO that looks like it’s from the CEO: “I’m in a meeting with our lawyers finalizing the acquisition. Need you to wire $50,000 to this account for closing costs. Urgent, can’t talk now, just do it.”
This has cost companies millions.
What it is: Criminal intercepts a real email you’ve received, creates an identical copy with malicious links, and resends it.
Example: You get a real email from Dropbox with a file link. Days later, you get what looks like the same email, but the link now goes to a phishing site. You think “Oh, I already got this” and click without scrutinizing.
Let me show you actual phishing attempts I’ve received recently:
Subject: “Unusual Activity Detected – Verify Your Account”
Email body:
Dear Valued Customer,
We detected unusual activity on your Amazon account from an IP address in Russia. For your security, we have temporarily suspended your account.
To restore access, please verify your identity by clicking the link below:
[VERIFY MY ACCOUNT NOW]
If you do not verify within 24 hours, your account will be permanently closed and you will lose access to your order history and Prime membership.
Thank you, Amazon Security Team
Why it looks real:
Red flags:
What would happen if you clicked: The link takes you to a site that looks exactly like Amazon’s login page. You enter your email and password. The site says “Verifying…” then redirects you to the real Amazon (so you think it worked). Meanwhile, criminals now have your login.
Subject: “You’ve received $487.50”
Email body:
Payment Received
John Smith sent you $487.50
Message: “Refund for item not received”
[VIEW PAYMENT DETAILS]
This payment will be held until you confirm receipt. Click above to release funds to your account.
Why it looks real:
Red flags:
What would happen if you clicked: You’d log in thinking you’re claiming money. Instead, you’ve given criminals your PayPal credentials. They immediately send themselves money from your account.
Subject: “You Are Eligible for a Tax Refund – $1,247.00”
Email body:
Internal Revenue Service
After reviewing your 2025 tax return, we have determined that you are eligible for a tax refund of $1,247.00.
To receive your refund via direct deposit, please verify your banking information:
[CLAIM MY REFUND]
Note: Failure to claim within 30 days will result in refund being forfeited.
Internal Revenue Service
Why it looks real:
Red flags:
What would happen if you clicked: You’d enter your Social Security number, bank account info, and other personal data. Identity theft would follow.
Subject: “Your password will expire today”
Email body:
Your Microsoft password will expire today.
To prevent losing access to your account, confirm your current password and set a new one:
[CHANGE PASSWORD NOW]
If you do not update your password, you will be locked out of Outlook, OneDrive, and all Microsoft services.
Microsoft Account Team
Why it looks real:
Red flags:
What would happen if you clicked: You’d enter your current password (which the criminals now have), then your “new” password (which they also have). They’ve gained access to your entire Microsoft account.

Learn to spot these and you’ll catch 95% of phishing attempts:
Look closely at the email address, not just the display name.
β Display name says “Amazon” but email is amazon-security@amaz0n.com
β paypal@secure-payment-center.com
β noreply@bankofamerica-alert.net
β apple@icloud-support.com
β amazon.com (legitimate)
β paypal.com (legitimate)
β bankofamerica.com (legitimate)
Pro tip: Hover your mouse over the sender name (don’t click) to see the actual email address.
Legitimate companies use your name in emails.
β “Dear Customer”
β “Dear Valued Member”
β “Hello User”
β “Dear Sir/Madam”
β “Hi Sarah,” (using your actual name)
Exception: Newsletters and marketing emails sometimes use generic greetings. But emails about account security should be personalized.
Professional companies proofread their emails.
β “You’re account has been compromised”
β “Please to verify you’re identity”
β “We has detected suspicious activity”
Note: Some phishing emails in 2026 are perfectly written (AI helps scammers now). But obvious errors are still a red flag.
Phishing emails create panic so you act without thinking.
β “Act now or account will be closed!”
β “You have 24 hours to respond”
β “Failure to comply will result in legal action”
β “Unusual activity detected – respond immediately”
Real companies give you time and don’t threaten.
No legitimate company will email you asking for:
If an email asks for this, it’s phishing. Period.
Before clicking any link, hover your mouse over it (don’t clickβjust hover). Look at the URL that appears.
β Link says “amazon.com” but URL is amazon-security.verify-account.com
β URL has weird characters or numbers: amaz0n.com or arnaz0n.com
β URL shorteners: bit.ly/xH7kL (hides the real destination)
β Goes directly to company’s real domain: amazon.com, paypal.com, etc.
Never open attachments you weren’t expecting, even from people you know (their account might be hacked).
Dangerous file types:
If you weren’t expecting an attachment, don’t open it. Contact the sender through a different method to verify.
β “You’ve won a $1,000 Amazon gift card!”
β “Claim your tax refund of $5,000!”
β “You’re eligible for a government grant!”
β “Congratulations! You’ve been selected for a special offer!”
If you didn’t enter a contest, you didn’t win anything.
The link text says one thing, but when you hover, it goes somewhere else.
Example:
Always hover before clicking.
β Your “boss” emails asking you to buy gift cards
β A “friend” emails asking you to click a link and vote for them
β Your “bank” asks you to verify your account by clicking a link
β A company asks you to send money via wire transfer, Bitcoin, or gift cards
When in doubt, contact the person/company directly using a phone number or website you looked up yourself (not from the email).
Here’s the honest truth about antivirus and phishing protection:
β Block known phishing websites
β Warn you about suspicious links
β Scan email attachments
β Detect fake websites
β Stop brand-new phishing sites
β Read your mind
β Protect you from giving information over the phone
β Stop you from falling for sophisticated social engineering
Bottom line: Good antivirus with web protection is essential, but your brain is the most important defense.
Don’t panic. Act fast. Here’s your recovery plan:
You’re probably fine. Just clicking a link usually doesn’t do damage by itself.
What to do:
Time-sensitive. Act NOW.
Immediate steps (within minutes):
Within 24 hours: 4. Check account activity
VERY time-sensitive. Act IMMEDIATELY.
Right now (within minutes):
Within 24 hours: 4. File a fraud report
CRITICAL. This is identity theft territory.
Immediate actions:
Ongoing:
When you receive a suspicious email, here’s how to check if it’s real:
Never click links in the email.
Instead:
If the issue mentioned in the email is real, you’ll see it in your account.
Never call a number provided in the suspicious email.
For tech-savvy users:
If you’re not technical, skip this method. Just go direct instead.
If the URL looks weird, don’t click.
Let me share some real stories (names changed for privacy):
What happened: Jennifer received an email saying her Amazon account showed suspicious orders totaling $12,000. She panicked and clicked “Dispute These Charges.” She entered her Amazon password, credit card info, and even her Social Security number (the site claimed it needed to “verify her identity”).
The damage:
Recovery time: 18 months of dealing with credit bureaus, police reports, and fraudulent accounts.
What she wishes she’d done: Gone directly to Amazon.com to check her account instead of clicking the email link.
What happened: Marcus got excited when he saw an email saying he’d received $487 on PayPal. He clicked to “claim the payment” and logged in. The site looked exactly like PayPal. He entered his credentials.
The damage:
Recovery time: 3 weeks to regain account access and dispute the fraudulent transfer. PayPal did refund him eventually, but it was stressful.
What he wishes he’d done: Opened PayPal directly in a new tab to check for the payment instead of clicking the email link.
What happened: Linda received an email saying her Windows license was expiring. She called the number provided. The “Microsoft tech support” person convinced her to install remote access software so they could “fix the issue.”
The damage:
Recovery time: Had to wipe computer completely and start over. Changed all passwords. 6 months of monitoring accounts.
What she wishes she’d done: Realized Microsoft NEVER cold-calls customers or sends emails asking people to call them.
These stories aren’t meant to scare you. They’re meant to show you the cost of clicking without thinking.
β Install antivirus with web protection
β Never click links in unexpected emails
β Verify before you trust
β Use different passwords for different sites
β Look at sender email addresses carefully
β Enable two-factor authentication (2FA)
β Use a password manager
β Check URLs before entering credentials
β Be skeptical of attachments
β Update your software
β Use separate email addresses
β Enable identity theft monitoring
β Use hardware security keys
β Regular security audits
β Educate family members
Simple rules:
Use parental controls:
They’re common targets because:
How to help:
Helpful phrase for them: “Real companies don’t threaten to close your account by email. If it’s urgent, they’ll send a letter or you can call them yourself.”
Here’s what I told my dad after he fell for the Amazon phishing scam:
Phishing works because it creates panic. When you’re scared or excited, you don’t think clearly. That’s exactly what criminals count on.
The solution is simple: Slow down.
When you get an email that makes you feel:
STOP. Take a breath. Do not click.
Instead:
This 30-second delay will save you from 99% of phishing attempts.
And if you’re ever unsure, ask someone. Call a tech-savvy family member. Contact the company directly. Post in a tech forum. Don’t let embarrassment stop you from asking.
My dad isn’t embarrassed anymore that he fell for a phishing scam. He’s actually grateful it happened with “only” $800 in fraudulent chargesβhe learned his lesson before something worse happened.
Now he’s the one teaching his friends to spot phishing emails.
Step 1: Protect your devices
Step 2: Enable 2FA on critical accounts
Step 3: Audit your passwords
Step 4: Practice skepticism
Step 5: Educate your family
How do criminals get my email address?
Data breaches, buying lists on the dark web, scraping websites, hacked company databases, or you gave it to a sketchy website that sold it.
Can I get hacked just by opening a phishing email?
Usually no. Just opening it is generally safe. The danger is clicking links or downloading attachments. (Exception: very old email clients had vulnerabilities, but modern email is safer.)
Why do phishing emails have obvious spelling errors?
Sometimes it’s because scammers aren’t native English speakers. But sometimes it’s deliberateβthey want to filter for only the most gullible victims who won’t notice errors.
If I didn’t enter my password, am I safe?
Probably. Just clicking a link might download malware, so run an antivirus scan to be sure. But you haven’t given them your credentials yet.
Can antivirus stop all phishing?
No antivirus catches 100%. They block 90-95% of known phishing sites, but brand-new sites might slip through. Your awareness is the final defense.
What should I do with phishing emails?
Delete them. Or, if you’re feeling helpful, report them:
Are phishing attempts getting more sophisticated?
Yes. AI helps scammers create perfect grammar, personalized messages, and convincing fake websites. In 2026, even tech-savvy people can fall for well-crafted phishing.
Why doesn’t my email filter catch these?
Email filters catch millions of phishing emails, but some get through. Criminals constantly adapt to bypass filters. You’re the last line of defense.