Newburyport Five Cents Savings Bank

10/01/2026 | Press release | Distributed by Public on 10/01/2026 13:56

Phishing – What You Know, and What You Don’t

When you hear the word "phishing," you might picture an email with a suspicious link and a message full of spelling mistakes.

That picture is getting outdated.

Phishing is a type of scam designed to trick you into revealing sensitive information, clicking a malicious link, opening an attachment, sending money or taking another action that benefits a criminal. And it doesn't happen only through email.

Phishing can show up in a text message, phone call, social media message, fake website or even a communication that appears to come from someone you know.

The goal is the same: make the request seem legitimate enough that you act before you stop to verify it.

And today, scammers have more tools to make that happen.

Phishing Has Become More Convincing

The days when a phishing message was easy to spot are not necessarily gone-but scammers have gotten much better at making their messages look legitimate.

Artificial intelligence can help criminals create polished language, personalize messages and imitate the communication style of specific people or organizations. It can also help them use information gathered from public sources to make a message feel more relevant to its target.

That means a well-written message isn't automatically trustworthy.

A scammer may know your name. They may know where you work. They may know the name of your bank or a company you do business with.

They may even make the communication look and sound like something you would normally receive.

So rather than asking, "Does this look like a scam?" it helps to ask:

"Was I expecting this, and have I independently verified it?"

Common Types of Phishing

Phishing can take several forms. Knowing what they look like can help you recognize the tactic, even when the details change.

Email Phishing

This is the traditional form most people think of when they hear "phishing."

You might receive an email that appears to come from your bank, a retailer, a delivery company, a government agency or another organization you know.

The message may ask you to:

  • Log in to your account.
  • Verify personal information.
  • Reset your password.
  • Review a transaction.
  • Open an attachment.
  • Click a link.
  • Respond to an urgent request.

The link may lead to a fake website designed to capture your login credentials or other sensitive information.

Smishing: Phishing by Text

Phishing doesn't stop at your inbox.

A text message might claim there's a problem with a package delivery, bank account, payment or online account.

You may be asked to click a link or provide information to resolve the supposed problem.

Because most of us are accustomed to receiving legitimate text notifications from businesses, it's easy to respond without giving the message much thought.

The same rule applies: Don't click simply because the message looks familiar. Verify first.

Vishing: Phishing by Phone

Phishing can also happen through a phone call.

A caller may claim to be from your bank, a government agency, a business you work with or another trusted organization. They may ask you to verify information, provide a code or take action on an account.

The caller may even know personal information about you or use a phone number that appears legitimate.

That's one reason caller ID should never be your only way of verifying who's calling.

If an unexpected caller is asking you to take action involving your money or personal information, end the call and contact the organization yourself using a trusted phone number.

Spear Phishing: When the Message Is Targeted

Some phishing attempts are sent broadly. Others are designed specifically for one person or organization.

This is sometimes called spear phishing.

A scammer may use information about your job, company, relationships or online activity to create a message that feels especially relevant.

For example, an employee might receive what appears to be a message from a supervisor. A business owner might receive an email that appears to come from a vendor. A customer might receive a message that appears to come from a financial institution.

AI can make this kind of personalization easier to produce at scale.

The more specific a message is, the more important it is to verify the request independently.

Business Phishing

Businesses can face phishing attempts that imitate everyday business communications.

A message might appear to be:

  • An invoice.
  • A vendor request.
  • A payment notification.
  • An employee survey.
  • A business partnership opportunity.
  • A message from an executive or coworker.
  • An account security alert.

The goal may be to steal employee credentials, gain access to business accounts or convince someone to make a payment or other financial change.

Phishing can affect businesses of every size, which is why verification should be part of normal business processes-not something employees do only when an email "looks suspicious."

What Do These Scams Have in Common?

The delivery method may change, but many phishing attempts use the same basic tactics.

Watch for:

Urgency:
You're told you need to act immediately or something bad will happen.

Pressure:
You're discouraged from hanging up, checking with someone else or taking time to verify the request.

Unexpected requests:
You're asked to log in, provide information, open a file, make a payment or approve something you weren't expecting.

Suspicious links or addresses:
A website address or sender's email may look almost-but not quite-right.

Requests for sensitive information:
You're asked for a password, multifactor authentication code, Social Security number or financial information.

Impersonation:
The message appears to come from someone you know, a company you use or an organization you trust.

These are all common phishing indicators.

Don't Let a Familiar Name Do the Thinking for You

One of the hardest parts of phishing is that the message may come from someone or something you recognize.

A trusted person's email account could have been compromised.

A familiar company logo can be copied.

A scammer can imitate the appearance of a legitimate website.

And a message can contain accurate information about you.

None of those things, by themselves, prove that the communication is legitimate.

If a message asks you to do something involving your money, accounts or personal information, take a moment to verify it through a trusted channel.

Pause Before You Click, Reply or Act

When something unexpected lands in your inbox, on your phone or in your social media messages, give yourself a moment.

Stop.

Don't click the link or open the attachment just to see what happens.

Check.

Look at the sender, phone number, website address and request. But remember that scammers can spoof addresses and create convincing copies of legitimate websites.

Verify.

Go directly to the organization's official website or app, or use a phone number you already know is legitimate. Don't use the contact information provided in the suspicious message.

And never provide a password or multifactor authentication code to someone who unexpectedly asks for it.

A Few Simple Habits Can Help

You don't have to become a cybersecurity expert to make phishing more difficult.

A few everyday habits can help:

  • Use strong, unique passwords for your accounts.
  • Enable multifactor authentication whenever it's available.
  • Keep your devices and software updated.
  • Be cautious with unexpected links and attachments.
  • Navigate directly to websites instead of clicking unexpected links.
  • Review account alerts for unusual activity.
  • Verify unexpected requests for money or sensitive information through a trusted channel.

What If You Already Clicked?

If you clicked a suspicious link, entered your credentials or provided information to a scammer, don't assume it's too late to do anything.

Act quickly.

Change the compromised password and any other account passwords that were reused. Enable multifactor authentication if you haven't already. Monitor your accounts for unusual activity and notify the organization that was impersonated.

If you downloaded something suspicious, consider running a malware scan on your device.

The sooner you respond, the sooner you can begin protecting your accounts and information.

Phishing Doesn't Always Look Like a Scam

That's the biggest thing to remember.

A phishing attempt can arrive as an email, text, phone call or social media message. It can look polished and professional. It can use your name. It can reference your job or a real company you do business with.

And with AI helping criminals create more personalized and convincing messages, relying on spelling mistakes or awkward wording isn't enough.

Instead, build one simple habit:

Pause. Verify. Then act.

When something unexpected asks for your information, your money or access to your account, take the time to make sure you're dealing with the real person or organization.

A few extra seconds can make a big difference.

Newburyport Five Cents Savings Bank published this content on October 01, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 01, 2026 at 19:56 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]