Learn › Account takeover & Phishing › Phishing & Smishing
Account takeover & Phishing

Phishing & Smishing

Phishing is the most common scam on the internet and the entry point for nearly every other kind. A convincing text or email points you to a fake login page, and your credentials are instantly sold or used to empty accounts.

$1,400
Avg. loss
8,910
Reports in database
Under 60 seconds
Avg. grooming time
SMS + email
Top channel

How it worksThe anatomy of the scam

Every case follows roughly the same playbook. Recognize the pattern, stop it early.

1. The hook

A text, email, or call claiming to be your bank, the post office, a tax authority, or a subscription service.

2. The urgency

'Your account will be closed', 'package held at customs', 'unauthorized charge'. You have hours, not days.

3. The clone

A link to a page that looks identical to the real site but lives on a lookalike domain (amazn.com, paypaI.com, etc.).

4. The credential harvest

You log in. They capture everything — including your 2FA code in real time.

5. The drain

Within minutes, funds are moved, accounts locked, or personal data sold on.

Warning signsRed flags to watch for

If you're seeing two or more of these, assume it's a scam until proven otherwise.

!

Unexpected urgency

Real institutions give you days, not hours.

!

Lookalike domains

amazn.com, paypa1.com, usps-delivery.shop — always read the URL carefully.

!

Generic greeting

'Dear Customer' instead of your actual name.

!

Asks for your password or 2FA

Real companies never do this.

!

Link doesn't match the text

The visible text says paypal.com but the actual link goes somewhere else.

Real storiesVictims, in their own words

All anonymized. Submitted through our report form.

Priya S., 29 · LondonMarch 2026
A text from 'Royal Mail' said there was £2.99 to pay on a package. I was expecting one so I tapped the link and entered my card. Twenty minutes later they called pretending to be my bank's fraud team, walked me through 'moving my money to a safe account,' and took £4,200.
Lost £4,200
Royal MailSMSFake fraud call

Protect yourselfDo this. Not that.

✓ Do

Hover over links before clicking. On mobile, long-press to reveal the actual URL.

✗ Don't

Never enter credentials from a link you didn't expect.

✓ Do

Go direct — open the company's app or type the URL yourself instead of tapping links from texts or emails.

✗ Don't

Never move money to a 'safe account' on instruction from a phone caller — real banks never ask this.

Has this happened to you?

Your story could stop the next person from losing their savings. Submit anonymously in about two minutes.

Report your experience Check a URL
🚨 Report a Scam