Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
•Founder and engineer, SafeSurf IQ
•Writes and reviews the platform's phishing, scam and privacy curriculum
•Works from primary incident and fraud reporting, cited on every article
Investment fraud accounts for nearly half of all scam-related losses reported to the FBI. The reason is structural — every other scam takes money once, and this one takes it repeatedly while showing you a balance that grows.
Job scam losses tripled between 2020 and 2023, and the growth is almost entirely one variant — the task scam, where an app shows your earnings rising and then asks you to deposit money to release them.
Social engineering is manipulating a person into doing something against their own interest. It is the common ancestor of phishing, impersonation, romance scams and fraud calls, and it works on a small number of predictable psychological levers.
Online privacy is not about having something to hide. It is about who holds a record of your behaviour, how precisely you can be identified without cookies, and which of those things you can practically change.
Ordinary phishing is a net cast at millions. Spear phishing is a message written for you specifically, using real details about your life or work — which is why the usual detection advice fails against it.
Most password advice is a decade out of date. The current guidance from NIST and the NCSC is shorter, simpler, and contradicts almost everything you were taught about symbols, capitals and changing your password every ninety days.
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.
Americans reported losing about $16 billion to fraud in 2025, the highest figure on record. The categories that account for most of it are surprisingly few, and each has a recognisable structure.
Six phishing messages taken from patterns currently in circulation, each broken down line by line — what the attacker is doing, why it works, and the specific detail that gives it away.
Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.
A phishing attack has five stages, and only one of them is the message you see. Understanding the other four explains why the messages look the way they do, and where the chain is easiest to break.
Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.