How Fraud Travels Through Email, Text, and Phone Calls
By the end of this lesson, you'll understand:
Email, text, and phone remain the three most common channels for financial fraud, precisely because they reach almost everyone and can be sent at massive scale for very little cost. Understanding how each channel is specifically exploited makes the warning signs from the previous lesson much easier to spot in practice.
Phishing refers to fraudulent emails designed to look like they're from a legitimate organization, a bank, employer, or well-known company, to trick you into clicking a malicious link, downloading an attachment, or entering login credentials on a fake website.
What to check: Hover over (don't click) a link to preview the actual destination URL before clicking, and look closely at the sender's actual email address, not just the display name, which can be set to anything.
Smishing is phishing conducted via text message, often including a shortened or disguised link. Vishing is voice phishing conducted over a phone call, sometimes using a real recording of an executive's or family member's voice generated with AI to increase credibility.
What to check: Never click a link in an unexpected text message from an unfamiliar or unverified number, and be aware that a familiar-sounding voice on a call is no longer reliable proof of identity given current AI voice-cloning capabilities.
Spoofing allows a scammer to display a caller ID or sender name that looks like a legitimate, familiar number or organization, even though the actual call or email is coming from somewhere else entirely. This means a call appearing to come from your bank's real phone number is not, by itself, proof it's actually your bank.
What to check: Regardless of what caller ID or sender name displays, verify any unexpected request by contacting the organization back through a number or address you look up independently.
Spear phishing targets a specific individual using personal details, your name, employer, job title, or even a real colleague's name, gathered from social media, data breaches, or public records, making the attempt significantly more convincing than a generic mass phishing email.
What to check: Be especially cautious of unexpected requests that reference accurate personal or workplace details, since personalization itself doesn't confirm legitimacy, it may simply mean the scammer did more research.
Nia receives an email that appears to be from her company's IT department, with the correct logo and a display name matching her actual IT team, asking her to click a link and "verify her credentials" before a system update. The sender's display name looks right, but hovering over it reveals the actual email address is from an unrelated, unfamiliar domain.
Recognizing this as a spoofed sender name, a classic phishing tactic, Nia doesn't click the link and instead contacts her actual IT department directly through the company's internal messaging system, confirming no such update or request was ever sent.
If a call shows my bank's real phone number on caller ID, it must actually be my bank.
Caller ID can be spoofed to display any number, including a legitimate organization's real published number. Caller ID alone is not reliable proof of who's actually calling.
Phishing emails are always easy to identify because of bad grammar and obvious fakes.
Modern phishing, especially spear phishing, can be well-written, personalized, and visually convincing. Relying on spotting obvious mistakes is no longer a reliable detection method on its own.
Don't enter any information on the resulting page. Close it, run a security scan if you downloaded anything, change your password for the affected account from a device you trust, and monitor that account closely for unusual activity.
Navigate to the company's official website by typing the address yourself (not clicking a link) or use their app directly, and check for account alerts or messages there instead of trusting the email's content or links.
They're a growing and increasingly accessible tactic, particularly for urgent "family emergency" scams. A simple, pre-agreed verification question or callback to a known number is an effective, low-effort defense regardless of how convincing the voice sounds.
The next time you receive an unexpected email, text, or call, apply one specific check from this lesson, hovering over a link, checking a sender's actual address, or calling back independently, before responding.
With phishing and impersonation channels covered, the next lesson, FPS104: Government and Business Impersonation Scams, looks at one especially common and effective category of impersonation.
That's where Financial Confidence becomes your personal message verifier.
Financial Confidence can help you check suspicious links and sender addresses, verify calls through official channels, track spoofing and impersonation patterns, and organize a safe response plan for a suspicious message.
Explore More LessonsLet us know if this lesson was useful, it helps us know what to keep improving.
Thanks for letting us know!