A phishing email is a message built to steal a password, a bank or card number, a Social Security number, or a click that installs malware. The FTC says scammers impersonate companies you already know, invent a problem with your account, and push a link or attachment. CISA’s household advice is short: recognize the bait, resist the click, then delete—do not reply and do not use an “unsubscribe” link in a suspect message. If you already clicked, stop using that inbox or bank site from the same session, change the password from a device you trust, turn on multifactor authentication, and scan the PC. This page is for recognition and after-click recovery. It is not a how-to for building or testing phishing kits.

How to tell it is phishing

Treat unexpected “fix your account now” mail as phishing until you prove it from a number or site you already trust.

The FTC lists the usual storylines: fake “suspicious activity,” a billing problem that is not real, a request to confirm personal or payment details, an invoice you do not recognize, a government refund, or a coupon for free stuff. CISA adds urgent or emotional language, requests for personal or financial information, shortened URLs you did not ask for, and look-alike addresses such as amazan.com. Poor spelling used to be a giveaway. CISA notes that AI-written mail can look clean, so grammar alone is no longer the test.

Signs that are still useful in a home inbox:

  • You were not expecting the message, even if the logo looks right.
  • The greeting is generic (“Dear customer”) on an account that normally uses your name.
  • The sender display name says your bank, but the actual address is a free mailbox or a look-alike domain.
  • The only way to “fix” the problem is a link or attachment in the message.
  • The tone is a countdown: account closed today, payment failed, warrant, package held.

A real company may email you. The FTC’s point is narrower: legitimate companies will not email or text a link that asks you to update payment information. When in doubt, open a new browser tab and type the site yourself, or use a phone number from a statement or the back of the card—not the number in the message. CISA says the same: if you think it might be real, do not click or call anything in the message.

Fake virus pop-ups are a cousin of phishing. If a browser page starts screaming that Windows is infected, close it and read 8 ways to tell a virus warning popup is fake.

What to do if you have not clicked

  1. Do not click the link, open the attachment, or tap “unsubscribe.”
  2. Ask the FTC’s first question: do I have an account with this company, or do I know this person? If no, treat it as phishing.
  3. If yes, verify on a channel you already have: the bank app you installed last year, a bookmark, or a phone number from a paper statement.
  4. Report the message in your mail app (Report phishing / Report junk).
  5. Forward the email to the Anti-Phishing Working Group at reportphishing@apwg.org, as the FTC recommends. Forward a phishing text to 7726 (SPAM).
  6. Report the attempt at ReportFraud.ftc.gov.
  7. Delete the message.

CISA’s three words are enough for the fridge: recognize, resist, delete.

What to do if you already clicked

Stop, then contain the account damage before you shop for new software.

Follow the FTC’s after-click steps and the related malware article, in household order:

  1. Stop logging into money and mail on that PC. The FTC malware guide says to stop using usernames, passwords, and other sensitive information for shopping or banking until you have scanned.
  2. If you typed a password on a fake site, change it from a different device (phone data, not the same Wi-Fi session if you can avoid it). Change email first if that inbox is the reset path for everything else. Use a new unique password.
  3. Turn on multifactor authentication on email, bank, and the impersonated brand. The FTC lists this as a primary defense; CISA calls it MFA. An extra code or prompt stops many stolen-password logins.
  4. Update Windows Security and run a scan. The FTC: if you think a link or attachment downloaded harmful software, update security software, run a scan, and remove what it finds. On Windows, that is Defender in the Windows Security app. If leftovers from another brand are blocking Defender, use How to uninstall McAfee or Avast and use Windows Defender.
  5. Watch the accounts. Look for new forwarding rules in email, new payees, and password-reset mail you did not request.
  6. If a Social Security number, bank account, or card number was typed, go to IdentityTheft.gov. The FTC uses that site for a personal recovery plan.
  7. If the PC now looks infected (new toolbars, constant pop-ups, files you cannot open), switch to the cleanup and backup guides instead of repeating them here: 9 steps to clean a virus-infected Windows PC and How to back up files from a virus-infected computer.

Do not call a number from the email. Do not install a “security tool” the page offered. Do not send cryptocurrency to “unlock” a warning.

Reduce the next one

The FTC’s four protections: keep security software updating, keep the phone updating, use multifactor authentication, and back up files. CISA adds strong unique passwords (a password manager helps) and installing software updates without delay. None of that requires a paid antivirus suite. Defender plus habits is enough for many homes; extras are optional and listed in 5 antivirus extras worth paying for in 2026.

Tell family members: hover is not a skill test for a phone. On a phone, do not tap. Open the real app.

Passwords, multifactor authentication, and a Defender scan come first. A paid extra is optional after that. Buying nothing after passwords and a scan is valid.

FAQ

The email uses my bank’s logo and my name. Can it still be fake?

Yes. Logos are copied. The FTC’s example of a fake billing email still uses a real-looking header. Verify on a site or number you already trust.

I only clicked, I did not type a password. Am I fine?

Maybe. Treat it as a maybe. Update Defender, run a scan, and watch the account the mail pretended to be. If a file downloaded, do not open it again.

Should I reply “stop” or click unsubscribe?

No. CISA says do not reply and do not click any attachment or link, including unsubscribe. Delete after you report it.

Where do I report it in the United States?

FTC: ReportFraud.ftc.gov. Email copies to reportphishing@apwg.org. Texts to 7726. If personal data was given, use IdentityTheft.gov.

Is this the same as a tech-support pop-up?

Related, not the same. Phishing usually arrives as mail, text, or a social message. A full-screen “virus detected, call us” page is a tech-support scam. Use the fake-popup guide linked above.