Security & Privacy
How to Avoid Online Scams: A Calm, Practical Guide
A reassuring, jargon-free guide to spotting and avoiding online scams, with simple habits to recognize red flags, pause before acting, and stay safe.
Security & Privacy
A reassuring, jargon-free guide to spotting and avoiding online scams, with simple habits to recognize red flags, pause before acting, and stay safe.
The fastest way to defeat almost any online scam is to verify through a channel you chose yourself: your saved bank number, the app on your phone, the address you type by hand, never the link or phone number the message handed you. Every scam below depends on you reacting inside a manufactured window of urgency, so breaking that window matters more than memorizing every trick.
Before you click, reply, or pay, ask: "Did I initiate this contact, and am I verifying through a route I picked?" If a text, email, or call arrived out of the blue and is steering you toward its own link or number, treat that as the scam until proven otherwise. Legitimate organizations expect you to reach them independently; scammers need you to stay inside the conversation they control.
Urgency is the tell. "Your account will be suspended in 24 hours," "a package needs a small redelivery fee," "we detected a $499 charge, press 1 to dispute." A real bank does not resolve fraud by having you read a code aloud, and a real courier does not hold a $2 parcel hostage over a card payment. When your pulse jumps, that feeling is the alarm.
Knowing the current playbook makes the fakes obvious. These are the dominant forms in 2025 and 2026:
The most useful five seconds you can spend is checking where a link actually goes.
Look at the word immediately before the first single slash. In paypal.com.secure-login-verify.xyz/login, the real domain is secure-login-verify.xyz, not PayPal. Scammers stack trusted brand names as subdomains because most people read left to right and stop at "paypal.com." On a phone, press and hold the link (don't tap) to preview the true URL; on a computer, hover and read the status bar.
An https:// padlock only means the connection is encrypted, not that the site is honest. The majority of phishing pages now use HTTPS precisely because people were taught the padlock equals safe. It doesn't. Judge the domain name, not the lock icon.
If you use a password manager like Bitwarden or 1Password, it ties each saved login to an exact domain. When you land on a lookalike site, the manager stays silent and refuses to autofill, because the domain doesn't match. That silence is a genuine warning worth trusting.
A few settings changes make you a hard target even on a distracted, tired day.
Two-factor authentication (2FA) means a stolen password alone isn't enough. But not all 2FA is equal. SMS codes are the weakest form because they can be intercepted through SIM-swapping, where a criminal ports your number to their phone. Prefer an authenticator app (TOTP) such as Google Authenticator or Authy, or better still a passkey, which uses the FIDO2/WebAuthn standard and is phishing-resistant because it is cryptographically bound to the real website and simply won't work on a fake one.
Where to enable it:
Reusing one password means a single leaked site unlocks your email, and your email unlocks everything else through password resets. A password manager generates and remembers a different long password for each site, so one breach stays contained. Protect the email account itself most fiercely, since it is the master key.
Even cautious, tech-literate people get caught, almost always through one of these:
Do not waste energy on embarrassment. These operations are run by professionals; speed matters more than blame.
Reporting helps even when no money was lost, because each report feeds the pattern that lets banks and investigators shut these operations down and warn the next target.
They are far better than no second factor, so keep them if that's all a site offers. But they're the weakest option because of SIM-swap interception, so upgrade to an authenticator app or passkey wherever you can, especially for email, banking, and crypto accounts.
You can't reliably tell from the caller ID, because it's spoofable. Hang up and call back on the number printed on your card or inside your banking app. A genuine bank will never object to you verifying this way, and will never ask you to move money to a "safe account."
Simply reading it is almost always harmless; the danger is in tapping links, opening attachments, or replying. Don't tap "unsubscribe" or reply "STOP" to unknown scam texts, as that confirms your number is active. Delete it, and forward scam texts to 7726.
Any demand for gift cards (Apple, Google Play, Amazon, Steam), wire transfers, or cryptocurrency is a near-certain scam, because those payments are hard or impossible to reverse. No real government agency, utility, or tech company collects debts or fees this way.
Keep reading
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.