ClearPath PublishingGuides for real life

Guide 03  ·  Outsmart the Scammers

The Email That Looks Like It Came From Your Bank

It arrives looking entirely ordinary. The logo is right. The layout matches messages you have received before. It says there is a problem with your account, and that you need to sign in and confirm your details.

You click. You type your username and password into a page that looks exactly like your bank’s. And in that moment, a criminal on the other side of the world has everything they need.

This is the most common way people lose control of their accounts. It does not require any clever hacking. It only requires that you believe the email.

Why these are so convincing now

There used to be a reliable clue: bad English. Misspellings, strange grammar, sentences that read like they had been through a machine.

That clue is gone. Criminals now use the same writing tools everybody else does, and the messages come out polished, personal, and in perfect English.

So the old advice — watch for spelling mistakes — no longer protects you. You need something that still works, and there are three things that do.

The three checks that still work

Look at the actual sending address, not the name.

The name at the top of an email can say anything at all. Anyone can put “Chase Bank” or “Amazon” there.

What matters is the address behind it. On a computer, hover your mouse over the sender’s name and the real address appears. On a phone, tap the sender’s name to expand it.

You are looking for the part after the @ symbol. A real message from Amazon comes from an address ending in @amazon.com. Criminals use things like amazon-security@gmail.com, or support@amaz0n.com with a zero in place of the letter o. At a glance they look right. That is the point.

Notice how the message greets you.

Your bank knows your name. It is printed on your statements. A message that opens with “Dear Customer” or “Dear Valued Member” is a message sent to thousands of people at once.

Notice whether it is trying to frighten you.

Your account will be suspended. Unusual activity detected. Payment overdue, action required today.

Real organisations do not operate on threats and deadlines. Criminals do, because fear stops you checking.

The habit that makes all of this unnecessary

Here is the thing that would protect you even if you never learned a single one of those checks.

Never sign in by clicking a link in an email.

Not sometimes. Not when it looks legitimate. Never.

If a message says there is a problem with your bank account, close it. Then call the number on the back of your card, or type your bank’s address into your browser yourself, or open the app the way you normally do. If the problem is real, you will see it there.

This costs you thirty extra seconds, and it makes the entire category of scam stop working. It does not matter how convincing the fake page is if you never go to it.

The same goes for text messages and phone calls. A text saying a package could not be delivered, a call saying your card has been used in another state — same rule. Do not use the link or the number they gave you. Go to the company yourself.

And a rule with no exceptions: no legitimate organisation will ever ask you to send a password, a Social Security number, or a security code by email or over the phone. If someone asks, that is the whole answer.

If you already clicked

It happens. You were tired, or distracted, or the message arrived on a day when it happened to be plausible. This is not a moral failing and there is no time for embarrassment — there is only the next hour.

Change that password immediately, going to the real website yourself. If you used the same password anywhere else, change it there too — this is exactly why using a different password everywhere matters so much.

Turn on the phone-code step for that account if it is not already on, so a stolen password alone is not enough.

Check the account’s settings for anything that was added. In email especially, criminals set up a rule that quietly forwards copies of your messages to them, so they can keep watching after you lock them out. Look for anything about forwarding, and remove what you do not recognise. If that is unfamiliar territory, this is a good moment to call a family member and go through it together.

If money is involved, call your bank now. Use the number on your card. Banks deal with this every single day, and they can usually limit the damage if they hear from you quickly. Speed matters far more than tidiness here.

Tell someone in your family. Not for permission — for a second pair of eyes over the next few days, and because if the criminal sends messages from your account, your family should know they were not from you. If more than one account seems affected, the first-hour guide walks through the rest in order.

What to remember

The messages will keep getting better. That is simply true, and pretending otherwise would not help you.

But every one of them depends on you following their link instead of going to the company yourself. That is the hinge the whole thing turns on.

Close the message. Call the number you already trust. Everything else is detail.

From the book

Outsmart the Scammers

Get the free preview chapter — the introduction plus “Why You, Specifically” — and learn how scammers choose their targets.

Get the free preview