Think twice before you click, submit, pay, download or reply.
Phishing scams are designed to trick you into taking an action that benefits a fraudster. That action could be clicking a malicious link, opening an attachment, providing personal or banking information, entering your login credentials on a fake website, sending money or downloading malicious software. Phishing can happen through email, text messages, social media, websites and phone calls. Smishing is a type of phishing that uses SMS or text messages.
These scams can look surprisingly convincing. A fraudulent message may appear to come from your bank, a government organization, a delivery company, a utility provider, an online retailer or even someone you know. And today, a message can look legitimate even when it isn't. Fraudsters can spoof phone numbers and sender information, use familiar logos and branding, create convincing fake websites and use personal information to make their messages more believable.
What is phishing?
Phishing is a type of social engineering scam in which a fraudster impersonates a trusted person or organization to trick you into revealing information, clicking a malicious link, opening an attachment, downloading malware or transferring money.
Phishing is commonly associated with email, but it can take many forms.
Common examples include:
- Email phishing: Fraudulent emails designed to steal information, money or account access.
- Smishing: Phishing through SMS or text messages.
- Vishing: Phishing through voice calls or voicemail.
- Quishing: Phishing that uses malicious QR codes to direct you to a fraudulent website.
- Spear phishing: Highly targeted phishing messages customized for a specific person or organization.
- Business email compromise: Impersonation of an executive, employee, supplier or business partner to convince someone to make a payment or disclose information.
What is smishing?
Smishing is a phishing scam delivered through a text message. A smishing message may pretend to come from your bank, a delivery company, a government organization, a retailer or another business you recognize.
The message may claim:
- Your account has been locked.
- There has been suspicious activity.
- Your payment was declined.
- You need to verify your identity.
- A package could not be delivered.
- You are owed a refund.
- You have won a prize.
- You need to make a payment.
- You need to update your account information.
The goal is usually to make you act quickly without stopping to verify the message.
Why smishing can be difficult to spot
You might assume a message is legitimate because it appears in a familiar conversation thread or appears to come from a number or sender you recognize. Unfortunately, that is no longer a reliable way to verify a message. Cybercriminals can spoof sender information, including legitimate-looking phone numbers and short codes. In some cases, fraudulent messages can even appear in the same message thread as legitimate communications from an organization.
Never rely on the sender name or phone number alone to determine whether a message is legitimate. Instead, verify the request independently.
Common warning signs of phishing and smishing
1. The message creates urgency
Scammers want you to act before you have time to think.
Watch for messages saying:
- "Your account will be closed today."
- "Immediate action required."
- "Your payment failed."
- "Your account has been compromised."
- "Click now to avoid a fee."
- "You have 24 hours to respond."
Urgency is one of the most common tactics used in phishing and smishing. Pause. A legitimate request can be independently verified.
2. You're asked for sensitive information
Be especially cautious if a message asks you to provide:
- Passwords
- Banking credentials
- Debit or credit card information
- PINs
- Security codes
- Social Insurance Numbers
- Personal identification information
- Answers to security questions
Don't provide sensitive information simply because a message claims to be from a trusted organization.
3. You're asked to click a link
A phishing message may contain a link that takes you to a fake website designed to look like the real one. The website may ask you to enter your username, password, card information or other personal details.
Don't click the link. Instead, open your browser or the organization's official app yourself and navigate to the account or service directly.
4. The website address looks unusual
Before entering information online, check the website address carefully.
Fraudsters may use:
- Misspelled domain names
- Slight variations of legitimate addresses
- Shortened URLs
- Deceptive subdomains
- Domains that look similar to a trusted organization
A website can look exactly like the real thing and still be fraudulent.
5. There's an unexpected attachment
Don't open unexpected attachments, even if the message appears to come from someone you know. Malicious attachments can contain software designed to compromise your device or steal information. If you're unsure, contact the sender using a separate, trusted method.
6. You're being pressured to make a payment
Be especially cautious about unexpected requests to:
- Send a wire transfer
- Purchase gift cards
- Send an e-transfer
- Make a cryptocurrency payment
- Change payment information
- Pay an unexpected invoice
If a payment request seems unusual, verify it independently before sending money.
QR codes can also be used for phishing
QR codes are convenient, but they can also be used in phishing attacks.
Quishing is a type of phishing that uses a malicious QR code to direct you to a fraudulent website. QR codes can appear in emails, text messages, posters, advertisements or other materials. Before scanning a QR code, consider where it came from and where it is supposed to take you. After scanning, check the website address carefully before entering any information.
Don't assume a message is legitimate because it looks professional
Phishing messages are becoming increasingly convincing. Fraudsters can copy logos, branding, writing styles and familiar communication patterns. They can also use information that is publicly available online to create more personalized messages.
Artificial intelligence is making some phishing and social engineering attacks even more convincing by helping fraudsters create realistic and personalized communications. Spelling mistakes can still be a warning sign, but perfect spelling and professional-looking branding do not prove that a message is legitimate.
How to protect yourself from phishing and smishing
Stop before you click
If an unexpected email or text asks you to click, pay, download, reply or provide information, stop. Don't allow urgency, fear or excitement to make the decision for you.
Verify independently
If you receive a message claiming to be from your bank or another organization, don't use the contact information or link provided in the message.
Instead:
- Open the organization's official website or app yourself.
- Use a trusted phone number, such as the number on the back of your debit or credit card.
- Contact the organization directly and ask whether the message is legitimate.
The Canadian Centre for Cyber Security recommends independently contacting the organization through official channels rather than using the contact information contained in a suspicious message.
Use strong, unique passwords
Use a different strong password or passphrase for each important account. Consider using a reputable password manager to create and store unique passwords. If one password is compromised, unique passwords help prevent the same credentials from being used to access your other accounts.
Turn on multi-factor authentication
Enable multi-factor authentication (MFA) on your important accounts whenever it is available. MFA provides another layer of protection if your password is stolen. Where possible, consider phishing-resistant options such as passkeys or hardware security keys. Authenticator apps can also provide stronger protection than SMS-based authentication in some situations.
Keep your devices and software updated
Install operating system, browser and application updates when they become available. Updates often include security improvements that help protect your devices against known vulnerabilities.
Be careful with personal information
Think carefully about how much personal information you share publicly. Information posted on social media can sometimes be used by fraudsters to create more convincing targeted scams.
Use official apps and websites
When accessing online banking or other sensitive services, navigate directly to the organization's official website or use its official mobile app. Avoid logging in through links received unexpectedly by email or text message.
What should you do if you clicked a phishing link?
Don't panic. If you clicked a suspicious link but didn't enter information, close the page and avoid interacting with it further. If you entered a password, change it immediately using a trusted device and make sure you aren't using the same password anywhere else.If you provided banking or payment information, contact your financial institution immediately using a trusted phone number.
If you downloaded a suspicious file or believe your device may have been compromised, disconnect it from the internet and take appropriate security steps. The Canadian Centre for Cyber Security recommends disconnecting a potentially compromised device and changing passwords using a different device. Monitor your financial and other important accounts for unusual activity.
What should you do if you receive a suspicious text?
If you receive a suspicious text message:
- Don't click the link.
- Don't reply.
- Don't provide personal or banking information.
- Verify the request independently if necessary.
- Report the message.
- Delete it and block the sender.
In Canada, suspicious spam text messages can be forwarded to 7726 (SPAM) through participating mobile providers. You can also report suspected fraud to the Canadian Anti-Fraud Centre.
What should you do if your banking information was compromised?
If you believe you've provided your banking information, password, card information or other sensitive financial information to a fraudster, act quickly.
YNCU members: Contact YNCU's Service Excellence Centre at 1-800-413-YNCU (9628) as soon as possible if you believe you've been the victim of phishing, smishing or another cyber scam and your banking information may have been compromised. You should also consider reporting the incident to the appropriate authorities and monitoring your accounts for suspicious transactions.
Remember: stop, verify and report
Phishing and smishing scams work because fraudsters want you to react before you have time to think. The most important habit you can develop is simple:
Stop. Verify. Report.
Stop before clicking, replying, paying or providing information.
Verify the request using a trusted, independent source.
Report suspicious messages and fraud attempts to the appropriate organization.
You don't need to be a cybersecurity expert to protect yourself. Taking a few extra seconds to verify an unexpected request can help protect your money, identity and personal information.
For more information, watch "How the SHADY? Technique Can Help Prevent Phishing and Smishing" or explore additional financial security resources from YNCU.
Frequently asked questions about phishing and smishing
What is phishing?
Phishing is a scam in which a fraudster impersonates a trusted person or organization to trick you into revealing sensitive information, clicking a malicious link, opening an attachment or transferring money.
What is smishing?
Smishing is phishing conducted through SMS or text messages. Fraudsters may impersonate banks, government organizations, delivery companies or other trusted businesses to convince you to click a link or provide sensitive information.
How can I tell if a text message is a scam?
Common warning signs include unexpected messages, urgent requests, suspicious links, requests for sensitive information, unexpected payment requests and messages claiming your account is locked or compromised. However, legitimate-looking sender information is not proof that a message is safe because fraudsters can spoof numbers and sender IDs.
Should I click a link in a text from my bank?
If you weren't expecting the message, don't click the link. Instead, access your bank through its official website or mobile app, or contact the bank using a trusted phone number.
What is quishing?
Quishing is phishing that uses a QR code to direct someone to a malicious or fraudulent website. Always verify where a QR code will take you before entering sensitive information.
What should I do if I accidentally clicked a phishing link?
Close the page and don't provide additional information. If you entered a password, change it using a trusted device. If you provided banking or payment information, contact your financial institution immediately. If you downloaded something suspicious, disconnect the device from the internet and follow appropriate security guidance.



