🚨 Scams & Fraud · Lesson 2 of 7 · 8 min
Phishing, Smishing & Vishing
🎣 Phishing is just fishing — they cast a million fake emails and texts hoping one person clicks. The bait looks like your bank, a delivery company, or the IRS. And clicking 'just to check' is exactly the bite they're waiting for.
💡 Key idea
Phishing/smishing/vishing = fake messages from 'trusted' senders. Never click the link in the message — verify by opening the real site or app yourself.
🧠 Why it matters
These scams arrive as messages pretending to be someone you trust. PHISHING (email), SMISHING (text), and VISHING (voice call) all work the same way: a convincing fake message with an urgent hook — 'suspicious login,' 'package held,' 'verify your account' — and a link or number that leads to a fake site or a scammer. Red flags: urgency, slightly-off sender addresses or URLs, generic greetings, and any request for passwords, codes, or payment. The golden rule: NEVER click links or call numbers FROM the message. Instead, open the company's real app or type its website yourself, or call the number on the back of your card. Legit companies never need your password or a one-time code over the phone.
🌍 In the real world
💡 A text says 'USPS: your package is held, tap to pay a small fee.' The link goes to a perfect fake. The person who types the real site themselves instead of tapping the link never gets hooked — same two seconds, opposite outcome.
📌 Takeaways
- Phishing (email), smishing (text), vishing (call): fake messages from 'trusted' names
- Never click links or call numbers from the message — go to the real site yourself
- No legit company asks for your password or one-time code by phone or text
📖 Terms in this lesson
Phishing: Fake emails, texts or calls that imitate a bank or company to steal your passwords or money.
✅ Test yourself
You get a text from 'your bank' with a link to fix a problem. Best move?
- Tap the link
- Don't tap it — open your bank's real app or call the number on your card
- Reply with your password
- Forward it to friends
Answer: B · Don't tap it — open your bank's real app or call the number on your card
Never use links from the message; verify directly through the real app or your card's number.
A company that calls or texts YOU out of the blue will legitimately ask for which of these?
- Your full password and one-time code
- None of those — legit companies never need them
- Your PIN
- Your security answers
Answer: B · None of those — legit companies never need them
Legitimate companies never need your password or one-time codes — that request is a scam.
Quiz, XP and streaks in the app. No sign-up needed.