Four of these signs settle it on their own. The other eleven only matter when they stack up. Knowing which is which is what lets you judge a message, a call, a shop or an offer without knowing anything about the particular scam.
A movement history contains no messages or photos, and it still reveals where you live, work, and who you spend nights with. Here is what is actually collecting your location - apps, ad code, photo metadata, Wi-Fi scanning - and how confident you can be that it is really private.
Change the password on that account first, then sign out every device. That second step is the one people miss, and it is the one that actually removes the attacker. Here is the full order, and what changes if you also gave a code.
A QR code is a link you cannot read. That single property removes every habit built around checking where a link goes, which is why attackers are sending millions of them every day.
Pretexting is the invented scenario that makes a request seem reasonable. It is the part of a scam that happens before any message is sent, it is illegal in several forms, and it explains why the best attacks ask for nothing at first.
Any second factor is a large improvement over none, but they are not equivalent. SMS codes can be intercepted, app codes can be relayed by a live phishing proxy, and only hardware keys and passkeys resist phishing outright.
A text demanding a few dollars for an unpaid toll, with a threat of late fees attached, is one of the highest-volume scams in circulation. Here is how to tell it's fake in seconds, and what to do if you already tapped the link.
Almost every scam contains a deadline, and the deadline is rarely about the story. It is there to remove the interval in which you would have checked — which is the only interval that matters.
A call that says it's your bank, the police or tech support can feel completely convincing in the moment. Here is how to check without staying on the line - and why hanging up and calling back yourself is the only test that works.
A dozen apps on your phone are probably still holding location, contacts or microphone access from years ago. Here is which permissions are worth turning off, which are safe to keep, and the ten-minute review that finds them on iPhone and Android.
Reusing a password means your security is set by the least careful company you ever signed up to. It is the single behaviour that converts an unrelated breach into a break-in on your accounts.
The FBI's 2025 report included artificial intelligence for the first time in the IC3's near-25-year history — 22,364 complaints and roughly $893 million. AI has not invented new scams; it has removed the tells that used to expose the old ones.
Credential stuffing is not password guessing. It is taking email-and-password pairs already leaked from one service and trying them, automatically, on hundreds of others — which works because people reuse passwords.
A full-screen warning or an unexpected call claiming your computer is infected is designed to make you act before you think. Here is what to do right now, and how the refund overpayment trick works if it goes further.
A caller says they are the police, the tax office or immigration, and that you must pay now or face arrest, deportation or a fine. Here is how to tell within seconds whether the call is real, and what to do instead of paying.
Your name, address, relatives and estimated income are already for sale on people-search sites you have never heard of. Here is how to find what is exposed, remove it from the brokers that matter most, and reduce how quickly it comes back.
A passkey is a cryptographic key your device holds instead of a secret you know. Because there is nothing to reveal, there is nothing to phish — which makes it the first authentication method that removes the problem rather than managing it.
Tracking is not one technique but four, layered — cookies, pixels, identity resolution and offline data. Understanding which is which explains why blocking cookies changed much less than it seemed to.
Got a text that feels off? Here is how to check it safely - how to preview a link without tapping it, the scam patterns currently circulating, and why replying (even STOP) makes things worse.
An unfamiliar shop that looked fine in the ad and fine on the site can still be fake. Here are the checks that take under a minute - the domain, the contact details, independent reviews - plus why the payment method matters more than anything else.
If someone you met online feels off - won't video call, moves too fast, or the story doesn't add up - here is how to check who you are really talking to, and the warning signs that actually hold up once you know where to look.
The objection to password managers is that they put every password in one place. The answer is that the realistic alternative is not perfect memory — it is reusing six passwords across two hundred accounts.
A cookie is something you have, so you can throw it away. A fingerprint is something you are — the configuration of the device in your hand — and clearing your browser data does nothing to it.
Length beats complexity, uniqueness beats both, and the character-substitution tricks you were taught do essentially nothing. Here is what current NIST and NCSC guidance actually asks for.
A call, text or email claims to be your bank, a government agency, a delivery firm or even a relative - and something about it feels off. Here is the one check that verifies who is really contacting you, and the requests that are always fraudulent, no matter how convincing the rest sounds.
A trading platform that shows a rising balance, permits a small withdrawal, then demands a fee to release the rest is the single most common structure behind investment fraud. Here are the checks to run before you send another payment.
An unexpected text offering flexible, well-paid remote work is one of the fastest-growing scams there is. Here is how to tell if a job offer is genuine before you reply, and what the task-scam app is actually designed to do.
Social engineering is manipulating a person into doing something against their own interest. It is the common ancestor of phishing, impersonation, romance scams and fraud calls, and it works on a small number of predictable psychological levers.
Online privacy is not about having something to hide. It is about who holds a record of your behaviour, how precisely you can be identified without cookies, and which of those things you can practically change.
Ordinary phishing is a net cast at millions. Spear phishing is a message written for you specifically, using real details about your life or work — which is why the usual detection advice fails against it.
Most password advice is a decade out of date. The current guidance from NIST and the NCSC is shorter, simpler, and contradicts almost everything you were taught about symbols, capitals and changing your password every ninety days.
Clicking alone is rarely the harmful step. What matters is what happened next — and the right response depends entirely on whether you entered a password, a code, card details, or nothing at all.
Americans reported losing about $16 billion to fraud in 2025, the highest figure on record. The categories that account for most of it are surprisingly few, and each has a recognisable structure.
Six phishing messages taken from patterns currently in circulation, each broken down line by line — what the attacker is doing, why it works, and the specific detail that gives it away.
Phishing emails are designed to be skimmed, not read. Four checks — sender, urgency, link, and request — catch the overwhelming majority before you click anything, and they run in about ten seconds.
A phishing attack has five stages, and only one of them is the message you see. Understanding the other four explains why the messages look the way they do, and where the chain is easiest to break.
Phishing is any attempt to trick you into handing over a credential, a payment or access by pretending to be someone you trust. The pretext changes constantly; the underlying request almost never does.