Skip to main content

Phishing scam: the fake message hoping you won’t look closely

  • Key takeaways

    • A phishing scam uses fake emails, texts, or websites to trick people into revealing passwords, account numbers, or other sensitive information.

    • Scammers send thousands of phishing attempts daily, and they’re often successful specifically because they mimic trusted, familiar brands.

    • Common phishing hooks include a fake account problem, a suspicious login alert, or an unexpected invoice.

    • Verifying through a company’s official app or a phone number already known to be correct, not the one in the message, is the safest response.

    • Remitly will never ask for a password or a one-time login code through email, text, or a phone call.

A phishing scam is a fake message designed to look exactly like it’s from someone trusted. Here’s how to spot one before clicking.

What is a phishing scam?

According to the FTC(opens in new window), scammers use email or text messages to trick people into giving up personal and financial information, hoping to gain access to an email, bank, or other account, or to sell that information to other scammers. Phishing attacks are launched by the thousands every day, and they’re often successful specifically because they closely mimic a company or service the recipient already knows and trusts.

Common phishing hooks worth recognizing

A phishing message often claims an account has a problem or has detected suspicious login activity, creating urgency to click a link and “verify” information. Others include a fake invoice for something never purchased, or a notification about a package delivery issue, both designed to prompt a quick click before careful thought. Some newer phishing attempts even mimic a CAPTCHA verification screen, which can trick someone into unknowingly installing harmful software rather than simply revealing information.

How to verify before you click or respond

The FTC recommends a simple test: if a message claims to be from a known company, contact that company directly using a phone number or website already known to be real, not the information provided in the message itself. Verifying the issue independently through the company’s own official channel quickly reveals whether the original message was legitimate or fake, without ever needing to click a potentially malicious link.

How Remitly protects you

Remitly will never ask for a password, a one-time login code, or full account credentials through email, text, or a phone call. A message requesting this information that claims to be from Remitly shouldn’t be responded to or clicked; instead, logging in directly through Remitly’s official app or website is the way to check account status.

Red flags to watch for

  • An unexpected message claiming an account has a problem or unusual activity. Verify independently rather than clicking any link in the message itself.

  • A link that, when hovered over, shows a web address that doesn’t match the company it claims to be from. This mismatch is one of the most reliable signs of phishing.

  • A request to confirm personal or financial information that wouldn’t normally be needed this way. Legitimate companies rarely ask for sensitive details through an unprompted message.

  • Urgent language warning of an account suspension or similar consequence without immediate action. This pressure is designed to prevent careful thinking.

Why even careful, tech-savvy people fall for phishing

Phishing succeeds not because targets are careless, but because a well-crafted message exploits normal, reasonable instincts, responding promptly to what looks like a legitimate account issue, trusting a familiar logo and layout, or simply moving quickly through a busy inbox. Building in a brief pause before clicking any unexpected link, regardless of how confident anyone feels in their own general caution, protects against the moments when even a careful person’s guard is naturally lower.

The role of AI in making phishing harder to spot

Increasingly sophisticated tools have made phishing messages considerably more polished than the poorly worded, obviously fake emails of years past, removing one of the traditional warning signs many people relied on. This shift makes independent verification, rather than looking for spelling errors or awkward phrasing, an even more essential habit going forward, since a phishing message can now look just as professional as a genuine one.

Building a habit of pausing before every unexpected link

Beyond any single technical tip, the most durable protection against phishing is building a consistent personal habit of pausing before clicking any unexpected link, regardless of how convincing or urgent the surrounding message seems. This pause, even just a few seconds to ask whether the message was expected and whether a link actually goes where it claims, catches the overwhelming majority of phishing attempts before any harm occurs.

Why company logos and formatting are not reliable proof

A scammer can copy a company’s logo, color scheme, and email formatting with near-perfect accuracy using tools that are widely and easily available, meaning visual polish alone reveals nothing meaningful about whether a message is genuine. Judging legitimacy by the specific request being made and independent verification, not by how professional the message looks, remains the more reliable approach. For a look at how these tactics show up specifically in a money transfer context, this guide to common money transfer scams(opens in new window) covers several related patterns worth recognizing.

Phishing targeting specific communities and languages

Phishing attempts are increasingly crafted in multiple languages and tailored to specific communities, meaning a message in one’s native language claiming to be from a familiar service is not automatically more trustworthy simply because it feels more personally relevant. The same verification principle, checking independently rather than trusting the message itself, applies regardless of what language a phishing attempt arrives in.

Common questions about phishing scams

  • What should I do if I clicked a phishing link or opened a suspicious attachment?

    Update the device’s security software immediately and run a full scan to check for and remove any harmful software. Change passwords for any account whose information may have been entered, particularly if the same password was used elsewhere.

  • How can I report a phishing email or text?

    Forward a suspicious email to the Anti-Phishing Working Group at reportphishing@apwg.org, and forward a phishing text message to 7726 (SPAM). The attempt can also be reported to the FTC at ReportFraud.ftc.gov.

  • Is phishing the same as spoofing?

    They’re related but distinct. Phishing refers to the overall scam of using a fake message to steal information. Spoofing refers specifically to disguising the sender’s identity, such as a faked email address or caller ID, which is often one of the specific techniques used to make a phishing message look more convincing.

In Summary

A phishing scam relies entirely on trusting a fake message enough to click or respond without verifying independently, which is exactly why that independent verification step is the most reliable protection available.

This publication is provided for general information purposes only and is not intended to cover all aspects of the topics discussed herein. This publication is not a substitute for seeking advice from an applicable specialist or professional. The content in this publication does not constitute legal, tax, or other professional advice from Remitly or any of its affiliates and should not be relied upon as such. While we strive to keep our posts up to date and accurate, we cannot represent, warrant, or otherwise guarantee that the content is accurate, complete, or up to date.

Ready to send money internationally with Remitly?