Do not use the message’s link or phone number to verify it. Open the company’s known app or contact it through a trusted website. If you already responded, choose your next steps based on the information, money, or device access you gave away.
Check the request outside the message
Phishing messages try to obtain information or persuade you to open a link or attachment. A familiar logo, display name, or account reference does not confirm the sender’s identity.
- Open the service’s app yourself and look for the claimed account problem.
- Use a phone number from your card, statement, or the company’s known website.
- Avoid opening attachments or entering information while you investigate.
- Treat a request to disclose a login code or password as a reason to stop.
If you already responded
| Situation | Next step |
|---|---|
| Read the message only | Do not reply or follow its instructions. Report it through the mail or messaging service. |
| Clicked a link or opened a file | Close the suspicious page. If you suspect a harmful download, update security software and scan the device. |
| Entered a password | Change it at the real service, change reused passwords, and turn on multi-factor authentication. |
| Shared payment details or sent money | Contact the payment provider and follow the scam response checklist. |
| Shared identity information | Use our identity-theft guide to find the relevant protection and recovery steps. |
Clicking a link does not, by itself, tell you whether an account or device was compromised. Record what you did so you can give support an accurate description.
Report the phishing attempt
The FTC recommends forwarding phishing texts to SPAM (7726) and phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org. You can also use your email or messaging app’s report function.
Report suspected fraud at the FTC’s official ReportFraud website. Also notify the platform where the contact or listing appeared. A fraud report does not replace contacting your payment provider or securing an affected account.
Keep the useful details
Keep messages, profile or listing URLs, dates, amounts, and transaction references in a private folder. Save the evidence before blocking the account. Do not post passwords, verification codes, card numbers, or identity documents in public complaints.
For a support request, write a short timeline: when the message arrived, what it claimed, which link or attachment you opened, and what you entered. Do not send passwords or verification codes as evidence.
Common questions
Does correct grammar mean a message is safe?
No. Verify the request through the real organization. Appearance and writing quality cannot establish who sent a message.
Should I reply to ask if the sender is legitimate?
Use a separate trusted contact route. A reply to the suspicious message goes back to the sender you are trying to verify.
What if the message is about a settlement payment?
Use our settlement-notice verification guide to match the case and administrator before sharing claim information.
Keep going
Your next useful guide
Scams & Fraud
Find help with phishing, impersonation, fake stores, romance scams, and job scams, plus practical steps after sending money or sharing information.
Scam response guideBank and government impersonation
Recognize impersonation tactics, verify calls through trusted contacts, and respond if you shared money, codes, or computer access.
Notice verification guideVerify a settlement notice
Check a settlement email, text, or letter against case records and administrator sources before sharing information or following payment instructions.
Sources and page information
Official source links checked September 26, 2026. Requirements can change; use the relevant agency’s current instructions.
Prepared with AI assistance. Examples and worksheets are illustrative. This is general information, not legal advice. We do not submit complaints, determine eligibility, or guarantee a result.