Phishing Email Scam
A fraudulent email impersonates a trusted company or contact, urging the recipient to click a link and log in on a fake page that steals their username and password, or to open an attachment that installs malware.
An email is crafted to look like it comes from a trusted company, coworker, or service — spoofing the sender name and copying real logos and formatting — and creates a reason to click a link, such as a "suspicious login," an invoice, or an account suspension warning. The link leads to a convincing fake login page that captures whatever username and password the victim enters, or the email carries an attachment that installs malware when opened, giving the attacker access to accounts, files, or the ability to launch further attacks from the victim's own contacts.
- The sender's actual email address doesn't match the company it claims to be from.
- A generic greeting like "Dear Customer" instead of your actual name.
- Urgent language about account suspension, security alerts, or unpaid invoices.
- A link that, when hovered over, points to an unfamiliar or misspelled domain.
- Hover over links to check the real destination before clicking.
- Look closely at the sender's actual email address, not just the display name.
- Never enter your password after clicking a link in an unsolicited email.
- Enable two-factor authentication so a stolen password alone isn't enough to break in.
VerifyGuard scans photos, links, and messages in seconds and flags exactly these kinds of red flags automatically.
Protect Yourself with VerifyGuard →