I got an email from "my bank" last week warning that my account would be locked in 24 hours. Right logo, right font, even that boring legal disclaimer nobody reads in the footer. I almost clicked without thinking. Stopped a second before the link. And that second is why I'm writing this. Because here's the uncomfortable truth: phishing isn't that crooked email full of typos promising a Nigerian prince inheritance anymore. That's over. Today, with generative AI writing flawless text in any language, bad grammar as a warning sign is basically dead. Anyone still teaching "watch out for poorly written emails" is teaching something that barely applies anymore. So where do you actually start. First, the sender. Not the name that shows up — anyone can type "Chase" or "PayPal" in the name field. What matters is the actual address, whatever comes after the @. And here's a boring habit that saves you: hover over the name before trusting it, or on your phone, hold your finger down until the full address shows up. Real banks don't bill you from randomdomain@gmail.com. Sounds obvious written out like that, but in the heat of the moment, heart racing because "your account will be locked," nobody stops to check. Artificial urgency is probably the single most effective trigger out there, and it's psychological before it's technical. "24 hours," "last chance," "click now or lose access permanently" — that kind of language exists to shut off the part of your brain that thinks and switch on the part that reacts. Real banks, tax agencies, serious providers don't usually give you hours to resolve something. If an email gives you less than a day to act, that alone is more suspicious than any typo could ever be. Links deserve their own attention because that's where the actual damage happens. A link can look completely normal and still take you somewhere else entirely — swap an "m" for "rn" together, swap a lowercase "l" for a capital "I," build subdomains that look legit like chase.secure-login.com when the real domain is just secure-login.com and "chase" up front means nothing, it's decoration. I almost fell for a "usps.package-tracking.net" myself once, and in a rush it genuinely looked right. Worth breaking down by channel too, since each one has its own trick. Email is still the classic, but texting — smishing — has grown a lot, especially the "your package is on hold, pay this fee here" one that catches people who are actually expecting a delivery. WhatsApp and similar apps have the relative-in-trouble scam, sometimes now with AI-cloned voice, which is unsettling in a new way. Phone calls — vishing — usually come from someone "from the bank" asking you to confirm details "just for security," and no real bank asks for your full password or SMS code over the phone, ever, no exceptions. Then there are the fake sponsored ads on Google or Instagram mimicking known stores, prices too good to be true, that exist purely to steal your card. In practice, what you do in that moment of doubt matters more than memorizing a checklist. Never click the link in the email or message. Open your browser, type the official address yourself, or use the app you already have installed. If it's a call, hang up and call back the number already saved in your contacts, not the one the caller gave you. Sounds basic, almost repetitive to write out, but it's literally the habit that breaks 90% of scams before they even start. And if you already clicked. Because a lot of people reading this right now aren't preventing anything, they're putting out a fire. First, change the password on the compromised account immediately, and if you reuse that password anywhere else — which, let's be honest, almost everyone does at least a little — change it there too. Turn on two-factor authentication if you haven't already. Check your statements and recent activity. Notify the bank or company through their official channel, not the one that messaged you, obviously. Don't beat yourself up for falling for it; today's scams are built by people who test this professionally, against normal people living normal lives, tired, in a hurry. Falling for it isn't stupidity, it's statistics. There was a recent, pretty sophisticated case where a crime ring used a deepfake of a CEO's voice to convince a company's finance team to wire millions during a video call — the person on the other end wasn't even real, it was an AI reconstruction built from that executive's public videos. Not science fiction, it already happened, more than once. That changes the bar for what "looking trustworthy" even means. Voice alone isn't enough anymore. Video alone isn't enough anymore either. What's left, in the end, is the habit of checking through a second channel before acting — sending a separate message, calling the saved number, confirming another way — because attack technology will keep getting better, but that few-second pause remains, practically, unbeatable.

