How to detect – and avoid — phishing scams

This increasingly common scam can be costly for you or your company. Here’s how to spot the five telltale signs of a phishing email.

5 minute read

Some 40 years after phishing first emerged, the criminals behind it are as successful as ever at tricking individuals into believing they are dealing with a legitimate party — costing people and organizations billions of dollars.

 

The FBI describes phishing as the use of unsolicited email, text messages, and telephone calls purportedly from a legitimate company requesting personal, financial, and/or login credentials. Phishing was the number one cybercrime complaint in the 2024 FBI IC3 report, with over 193,000 complaints.  How has this scam been so successful for so long?

 

Cybercriminals rely on deception, urgency or too-good-to-be-true promises to convince their targets to give up sensitive data like login credentials and passwords, credit card numbers, account details, corporate contacts, vendor names or other proprietary information.

 

A phishing email may spoof a company, such as a bank or online shopping site, or look like it’s from someone you know. These emails can include a link to a spoofed website that looks just like the real one. When an individual navigates to this fake site, cybercriminals will collect usernames, passwords and other data they can use to commit identity theft or drain bank accounts.

 

Criminals use information gathered from data leaks and social media accounts to deliver phishing scams that are more believable than ever — whether through text, voicemail or web search results. But you can outsmart the scammers by maintaining a healthy level of skepticism when receiving any kind of digital communication and shoring up your best defense: awareness.

 

Remember that Bank of America — like most other reputable companies — will never ask for account details unless you contact us first. If there’s any doubt, go directly to a trusted source, such as the company’s website, or call to check using a phone number you can independently verify belongs to the company or individual who apparently sent the email.

The telltale signs of phishing

There are often clues that an email is a phishing scam. The following five are the most common.

 

  1. There are grammatical, spelling and/or formatting errors in the content. If the email is unsolicited and contains multiple spelling, formatting or other errors, it’s best to investigate further before clicking.
  2. The “from” address doesn’t match the authentic email address of the sender, especially if it says it’s from a business. If you can’t see the email address, either hover over the sender name or right click on it to show details. Cybercriminals often use fake company email addresses from common, public domains. Or they might create an address that spells the company name just slightly incorrectly.
  3. The email contains a hyperlink that doesn’t match the destination it claims to be when hovered over. For example, if an email purports to be from a favorite online store needing you to update account information, but the URL shows an unfamiliar address, do not click on the link.  Instead, directly type in the store’s website into your browser and navigate to your account details to confirm if anything needs updating.
  4. The email contains attachments from unknown sources that you were not expecting. Don’t open the attachments since they may contain malware that could infect your system.
  5. The tone of voice is urgent. Criminals love to use urgency to trick users into taking action without looking too closely. Email with phrases like, “Update your password before we close your account!” should be treated as highly suspect. Never call the phone number on an email you suspect might be a scam.

Fraud & Cybersecurity

New threats emerge every day that can negatively impact transactions and businesses. Explore the latest insights and resources to help prepare and protect you and your business.