In today’s digital age, cyber threats have become a growing concern for everyone, especially older adults. Scammers have become increasingly clever, finding ways to steal personal and financial information through manipulative messages and phone calls. In 2023 alone, people over the age of 60 reported roughly $3.4 billion in total fraud losses, with an average loss of $34,000 per case. These staggering numbers highlight the importance of staying vigilant and learning how to protect yourself from these scams.
According to the FBI’s Internet Crime Complaint Center (I3C), phishing (including its sub-types, smishing and vishing) is the most common type of cybercrime. In this post, we’ll explain how to spot phishing attempts and provide some basic tips to protect yourself from these all-too-common scams.
What Is Phishing, Vishing, and Smishing?
Phishing is a type of online scam where criminals send fraudulent emails designed to trick you into revealing sensitive information like passwords, credit card numbers, or Social Security numbers. These emails often look like they come from trusted organizations, such as banks or government agencies, and include malicious attachments or links to fake websites where victims unknowingly provide their personal information.
Vishing (voice phishing) involves phone calls from scammers posing as legitimate entities. These fraudsters often use high-pressure tactics, claiming there’s an urgent issue with your account or pretending to offer a solution to a problem. For example, a scammer might call pretending to be “tech support” from a company like Microsoft or Apple, claiming that your computer has been infected with malware, requesting access to remove it.
Smishing (SMS phishing) is similar to phishing but takes place through text messages. These texts may appear to be from a trusted source, such as your bank or a delivery service, and typically include a website link or a phone number. When you tap the link or call the number, the scammers attempt to gather your personal information.
What to Watch for
Phishing, vishing, and smishing attempts try to reach you through different channels, but they all work the same way: they use deception and impersonation to steal your personal information. Here are some common warning signs that a message you received may be a scam:
- Suspicious website links: The link in the message may be shortened, obscured, or have extra characters. For example, a message claiming to be from Amazon urging you to verify account activity containing a link that goes to a URL like shorturl.at, bit.ly, or amazonn.com
- Urgent or threatening language: Scammers often create a sense of urgency to pressure you into acting quickly. For example, a message might say, “Your account will be locked unless you respond immediately.”
- Requests for personal or financial information: Legitimate organizations rarely ask for sensitive information via email, text, or phone.
- Unusual email addresses or phone numbers: A phishing email might come from an address that looks almost right but has small discrepancies, such as extra numbers or misspellings. Or, the sender’s name may look legitimate, but the email address is not (for example an email sent from “Samsung Customer Service” using the email address “samsuncom@scamsite.net”
- Poor spelling and grammar: The message may contain spelling or grammar mistakes.
- Generic greetings: Instead of addressing you by name, the message might start with something like “Dear Customer.”
- Contains offers too good to be true: The message claims you won a prize for a contest you did not enter, or that you are “eligible” for a prize if you click a link or provide information.
How to Protect Yourself
Follow these tips to stay safe from phishing, vishing, and smishing attempts:
- Be skeptical of unexpected messages: If you receive an email, text, or call out of the blue, verify the source before responding. For example, if you get a message warning you of suspicious activity for one of your online accounts, go log in to your account like you normally do to check on it instead of clicking the message’s link. For phone calls, hang up and go to the organization’s website and call their corporate phone number.
- Do not click on suspicious links: Hover over links in emails to see where they lead. If the URL looks strange or does not match the sender’s organization, do not click.
- Join the National Do Not Call Registry: The National Do Not Call Registry can reduce the number of telemarketing—and vishing—calls you receive.
- Educate yourself: Stay informed about the latest scams and how they work.
- Secure your accounts and devices: Follow best practices for cybersecurity by using strong and unique passwords, enabling two-factor authentication (2FA) or multi-factor authentication (MFA), and keeping your devices’ software and security settings updated to protect against vulnerabilities.
What to Do if You Have Been Scammed
If you have fallen victim to a phishing, vishing, or smishing scam, do not panic. Follow these steps to minimize the damage:
- Act quickly: Change your passwords for any compromised accounts immediately.
- Contact your bank: If you shared financial information, notify your bank or credit card company right away.
- Place a fraud alert: Contact one of the three major credit bureaus (Equifax, Experian, or TransUnion) to place a fraud alert on your credit report.
- Report the scam: File a report with the Federal Trade Commission so they can help protect others. You can also file a complaint with IC3.
- Seek support: Talk to a trusted family member or friend for help with securing your accounts. Organizations like AARP’s Fraud Watch Network Helpline (877-908-3360) can also provide assistance.
By understanding these scams and taking proactive steps, you can protect yourself and your loved ones from falling victim to cybercrime. Stay vigilant and remember: When in doubt, do not respond!



