Security & Privacy

How to Avoid Online Scams: A Calm, Practical Guide

A reassuring, jargon-free guide to spotting and avoiding online scams, with simple habits to recognize red flags, pause before acting, and stay safe.

A person looking thoughtfully at a smartphone showing a suspicious message
Photograph via Unsplash

The fastest way to defeat almost any online scam is to verify through a channel you chose yourself: your saved bank number, the app on your phone, the address you type by hand, never the link or phone number the message handed you. Every scam below depends on you reacting inside a manufactured window of urgency, so breaking that window matters more than memorizing every trick.

The one question that stops most scams#

Before you click, reply, or pay, ask: "Did I initiate this contact, and am I verifying through a route I picked?" If a text, email, or call arrived out of the blue and is steering you toward its own link or number, treat that as the scam until proven otherwise. Legitimate organizations expect you to reach them independently; scammers need you to stay inside the conversation they control.

Urgency is the tell. "Your account will be suspended in 24 hours," "a package needs a small redelivery fee," "we detected a $499 charge, press 1 to dispute." A real bank does not resolve fraud by having you read a code aloud, and a real courier does not hold a $2 parcel hostage over a card payment. When your pulse jumps, that feeling is the alarm.

The scams actually hitting phones right now#

Knowing the current playbook makes the fakes obvious. These are the dominant forms in 2025 and 2026:

  • Smishing (scam texts): fake USPS, Royal Mail, DHL, or toll-road ("unpaid E-ZPass") messages with a link to "confirm your address" and a tiny fee. The fee is a decoy to harvest your card and address.
  • Bank and payment impersonation: a call or text claiming fraud on your account, then asking you to "move money to a safe account" or approve a login. No bank ever asks you to transfer your own money for safekeeping.
  • Tech-support pop-ups (vishing): a full-screen browser warning claiming to be Microsoft or Apple with a phone number and a blaring alarm. Neither company puts a support number in a pop-up. Close the tab; if it won't close, force-quit the browser.
  • Marketplace and overpayment scams: a "buyer" on Facebook Marketplace or eBay overpays, then asks for the difference back, or sends a fake Zelle "pending until you upgrade to business" email.
  • Pig-butchering investment scams: a friendly stranger from a "wrong number" text or dating app slowly builds trust, then guides you to a slick crypto app showing fake gains. Withdrawals work at first, then a "tax" or "fee" is demanded before you can cash out.
  • Quishing (QR codes): stickers over real parking-meter or menu QR codes, or codes in emails, that route to a phishing page. Treat an unexpected QR like an unexpected link.

The most useful five seconds you can spend is checking where a link actually goes.

Read the domain from right to left#

Look at the word immediately before the first single slash. In paypal.com.secure-login-verify.xyz/login, the real domain is secure-login-verify.xyz, not PayPal. Scammers stack trusted brand names as subdomains because most people read left to right and stop at "paypal.com." On a phone, press and hold the link (don't tap) to preview the true URL; on a computer, hover and read the status bar.

The padlock proves nothing#

An https:// padlock only means the connection is encrypted, not that the site is honest. The majority of phishing pages now use HTTPS precisely because people were taught the padlock equals safe. It doesn't. Judge the domain name, not the lock icon.

Let your password manager be the detector#

If you use a password manager like Bitwarden or 1Password, it ties each saved login to an exact domain. When you land on a lookalike site, the manager stays silent and refuses to autofill, because the domain doesn't match. That silence is a genuine warning worth trusting.

Lock the doors before anyone knocks#

A few settings changes make you a hard target even on a distracted, tired day.

Turn on strong two-factor authentication#

Two-factor authentication (2FA) means a stolen password alone isn't enough. But not all 2FA is equal. SMS codes are the weakest form because they can be intercepted through SIM-swapping, where a criminal ports your number to their phone. Prefer an authenticator app (TOTP) such as Google Authenticator or Authy, or better still a passkey, which uses the FIDO2/WebAuthn standard and is phishing-resistant because it is cryptographically bound to the real website and simply won't work on a fake one.

Where to enable it:

  • Google: myaccount.google.com > Security > How you sign in to Google > 2-Step Verification (add a passkey here too).
  • Apple ID: Settings > [your name] > Sign-In & Security > Two-Factor Authentication.
  • Instagram/Facebook: Settings > Accounts Center > Password and security > Two-factor authentication.

One unique password per account#

Reusing one password means a single leaked site unlocks your email, and your email unlocks everything else through password resets. A password manager generates and remembers a different long password for each site, so one breach stays contained. Protect the email account itself most fiercely, since it is the master key.

Common mistakes that catch careful people#

Even cautious, tech-literate people get caught, almost always through one of these:

  • Trusting the sender name or caller ID. Both are trivially spoofed. A call showing your bank's real number, or a text landing in the same thread as genuine bank messages, proves nothing.
  • Reading a one-time code aloud. That six-digit code is the second factor a scammer is missing. Anyone phoning to "confirm" it is trying to finish logging into your account. No legitimate agent ever needs it.
  • Googling a support number and calling the top result. Scammers buy search ads that impersonate airlines, banks, and crypto exchanges. Use the number on the back of your card or inside the official app instead.
  • Clicking "unsubscribe" on a spam text. Replying or tapping unsubscribe on an unknown scam message confirms your number is live, inviting more. Delete and, in the US and UK, forward it to 7726 (which spells SPAM).

If you already clicked or paid: the first 30 minutes#

Do not waste energy on embarrassment. These operations are run by professionals; speed matters more than blame.

  1. Contact your bank immediately. Call the number on your card or, in the UK, dial 159 to reach many major banks directly. Ask them to stop the payment and freeze the card. Card and bank-transfer payments are sometimes recoverable if reported fast.
  2. Change the exposed password, starting with your email, then any account that shared it. Turn on app-based 2FA or a passkey while you're there.
  3. Revoke active sessions in the account's security settings so an attacker already logged in is kicked out.
  4. Report it. In the US, file at reportfraud.ftc.gov and, for financial crime, ic3.gov; if your identity is exposed, use identitytheft.gov. In the UK, report to actionfraud.police.uk and forward phishing emails to [email protected].
  5. Consider a credit freeze with Equifax, Experian, and TransUnion if personal details leaked, which blocks new accounts opened in your name.

Reporting helps even when no money was lost, because each report feeds the pattern that lets banks and investigators shut these operations down and warn the next target.

Frequently asked questions#

Are text-message (SMS) codes still safe to use for 2FA?#

They are far better than no second factor, so keep them if that's all a site offers. But they're the weakest option because of SIM-swap interception, so upgrade to an authenticator app or passkey wherever you can, especially for email, banking, and crypto accounts.

How can I tell a real bank call from a scam?#

You can't reliably tell from the caller ID, because it's spoofable. Hang up and call back on the number printed on your card or inside your banking app. A genuine bank will never object to you verifying this way, and will never ask you to move money to a "safe account."

Is it dangerous just to open a scam text or email?#

Simply reading it is almost always harmless; the danger is in tapping links, opening attachments, or replying. Don't tap "unsubscribe" or reply "STOP" to unknown scam texts, as that confirms your number is active. Delete it, and forward scam texts to 7726.

What payment methods should make me suspicious?#

Any demand for gift cards (Apple, Google Play, Amazon, Steam), wire transfers, or cryptocurrency is a near-certain scam, because those payments are hard or impossible to reverse. No real government agency, utility, or tech company collects debts or fees this way.

Theo Vance
Written by
Theo Vance

Theo writes about online safety the way a good friend would — clearly, calmly, and without trying to scare you. He's interested in the simple habits that stop most problems, and he thinks staying private online is a skill anyone can learn.

More from Theo