How the Scam WorksHow to Protect Yourself

Banking Websites

A spoofed bank website can look identical to the real one. It will use the same logos, fonts, and layout. A careful look at the URL usually reveals a small difference.

  • Before clicking any link, hover over it to preview the URL and judge whether it’s legitimate.
  • Watch for misspellings, accent marks, or extra characters.
  • Confirm the URL starts with “https://” — the “s” stands for secure.
  • Be skeptical of sites with poor grammar, typos, or an unpolished look.

E-Commerce Platforms

A fraudster spins up a fake version of a popular online store, dangling too-good-to-be-true deals to lure your credit card details.

  • Keep your browser and security software up to date.
  • Be password-smart: build hard-to-crack passwords, change them regularly, and use a different one for every account.
  • Turn on two-factor authentication for an extra layer of security.

Social Media Sites

An email links to what looks like a social media site and asks you to log in to see a message. Do it, and the spoof site pockets your credentials.

  • Approach unsolicited emails with skepticism, and never click links or open attachments from unknown sources.
  • Don’t respond to emails insisting on urgent action.
  • Ignore promises of business opportunities that sound unrealistic.

Email Providers

A phishing email sends you to a fake email login page. It’s a dead ringer for the real one, but whatever you type goes straight to the attacker.

  • Bookmark your email provider’s real login page and use that bookmark instead of links from messages.

Professional Sites

A spoofed version of a professional or corporate site is used to harvest login credentials or push malware.

  • When in doubt, type the organization’s address directly into your browser rather than following a link.