Highlighted wordsare glossary terms — tap one for a plain-language definition.
PhishingWhat it means: A deceptive email or message designed to make you click, share information, send money, or give account access.Example: An “unpaid delivery fee” text with a link to a page that looks like the post office.What to do: Don't tap links in unexpected messages — open the company's app or type its address yourself.Important: Real companies never ask for your password or a login code by message.What does this mean? is still the front door to most account takeovers, but it is also one of the most preventable attacks. Three habits cover almost every email scam: verify the sender through a channel you control, read the link before you click, and let a Password managerWhat it means: Software that generates, stores, and fills unique account passwords, and may also manage passkeys or other credentials.Example: The manager generating and filling a 20-character password you never have to recall.What to do: Set one up and move your email, banking, and cloud passwords into it first.Important: Protect it with one strong passphrase plus MFA, and never share that passphrase.What does this mean? guard the sign-in. [1, 2, 3]
Verify the sender, not the display name
The name at the top of an email — and even the logo — costs a scammer nothing to fake. The FTC's guidance is unambiguous: legitimate companies don't ask for passwords, payment details, or personal data by email, and any message that creates urgency ("your account will be closed today") is a pressure tactic. When a message claims to be from a company you actually deal with, don't reply or call the number in the email — reach the company through the number on your card, your app, or the address you type yourself. [2, 3]
- Expand the From details and compare the reply-to address with the sender's real domain.
- Treat urgency, threats, and limited-time offers as red flags, not proof.
- Verify any request to pay or update details using a phone number or website you look up yourself.
- Unexpected attachments — even invoices — stay unopened until you confirm them.
Read the link before you click
A link's visible text can say anything; the real destination is in the address. Hover (or long-press) to preview the URL and read the domain from right to left: in login.yourbank.com.secure-check.example.net, the actual site is example.net — everything before it is decoration. Scammers also lean on lookalike characters and short links that hide the destination. And remember the padlock proves the connection is encrypted, not that the site is honest — plenty of phishing pages have valid HTTPSWhat it means: A protected connection between your browser and a website. It encrypts the connection but does not prove that the website itself is trustworthy.Example: The padlock and “https://” shown in your address bar.What to do: Read the domain spelling carefully, not just the padlock.Important: Scam sites use HTTPS too — the padlock is not a trust badge.What does this mean?. [1, 3]
- Hover or long-press a link to preview the full destination address.
- Read the domain right to left — the part just before the first single slash is who you're really visiting.
- Watch for lookalike characters (rn for m, 0 for o) and be wary of shortened links.
- Prefer bookmarks or typing the address yourself when you need your bank, school, or a government site.
- Not sure about a link? Check it with Google Safe Browsing or VirusTotal before opening it.
Let a password manager be your gatekeeper
A password manager does more than remember logins — it quietly detects phishing. It saves each password against the exact site address, so it will only fill the form on the genuine domain. When a convincing 'bank' page appears and the manager offers nothing, that silence is the alarm. CISA recommends password managers as the easiest way to use strong, unique passwords everywhere, and NIST 800-63B backs the approach: length beats complexity tricks, so let the manager generate long random passwords and don't reuse or rotate them on a schedule. [1, 2, 4]
- Use a reputable password manager to generate a long, unique password for every account.
- Treat a manager that won't autofill on a familiar site as a phishing warning — stop and check the address.
- Never copy and paste a saved password into a page you arrived at from an email or text.
- Skip 'compose a clever password' rules — length and uniqueness are what matter.
Report it, then move on
Reporting makes everyone safer: your workplace's report button lets defenders pull the campaign before others click, and forwarding scam texts to 7726 (SPAM) helps carriers block the sender. If you did click and entered a password, act fast — change that password everywhere it was reused, sign out other sessions, and turn on Multifactor authenticationWhat it means: Using more than one type of authentication evidence before an account grants access.Example: Entering your password and then approving the login through an authenticator app.What to do: Turn it on first for your email, financial, social-media, and cloud accounts.Important: Never give an unexpected login code to someone who contacts you.What does this mean?. The full recovery sequence lives in the Security incident plan lesson. [1, 3]
- Report suspicious email through your email provider's or workplace's report option, then delete it.
- Forward scam texts to 7726 so your carrier can act.
- Clicked and typed a password? Change it now, sign out other sessions, and enable MFA.
Why Hygi. recommends this — the guidance above follows these published sources:
CISA
Recognize and Report Phishing (Secure Our World)(opens in a new tab)Spotting phishing red flags and reporting scam messages through the right channel.
CISA
Use Strong Passwords and Password Managers (Secure Our World)(opens in a new tab)Password managers as the easiest route to long, unique passwords for every account.
FTC
How To Recognize and Avoid Phishing Scams(opens in a new tab)Legitimate companies don't ask for sensitive data by email, and out-of-band verification steps.
NIST
Digital Identity Guidelines: Authentication (SP 800-63B)(opens in a new tab)Password length and uniqueness over composition tricks or scheduled rotation.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary