ScamsPhishing & quishingThe "verify your account" email is a trap: how to spot phishing before you click
High

The "verify your account" email is a trap: how to spot phishing before you click

A polished email warns of an "unusual sign-in" or a failed payment and links you to a login page that steals your password. The branding is copied; the link is the bait. Here is how it works and the free move that beats it.

Sources checked:CFPBUK NCSCACCC ScamwatchAARP

Email phishing turns a moment of worry into a stolen password. A message that looks like it’s from your bank, a retailer, or a service warns of a problem — an “unusual sign-in”, a failed payment, an account about to be closed — and links you to a login page that’s a perfect copy of the real one. Whatever you type there goes straight to the scammer.

How the scam works

The con borrows a trusted brand and adds a deadline:

  • The lure. A branded email claims something urgent: verify your account, confirm a payment, review a suspicious login — act now or lose access.
  • The look-alike. The link goes to a page that mimics the real site, often on a domain that’s close but not quite right.
  • The harvest. You enter your username and password (and sometimes a one-time code), and the scammer captures it in real time.
  • The takeover. With your login they drain the account, change the password, or use it to phish your contacts.

The fact to anchor on: real companies don’t email asking you to confirm your password. As the CFPB puts it, banks and credit unions never ask for account information by email or text.

How to spot it

The tells are in the box below, but the shortcut is: urgent “account problem” + a link asking you to log in = don’t click. The pressure to act “within 24 hours” is itself a red flag, and so is a sender address or link that’s slightly off.

What to do instead

You don’t need to click anything to check this — the free move comes first (see the defense box). The habit here is Two-Channel Verification: never act on the message itself; confirm through a separate, known channel and open the site yourself. The text-message version is covered in delivery smishing, and the QR-code version in quishing scams. If you did enter your details, follow the steps in what to do after a data breach. For more, see our defense moves and the 60-second quiz.

Warning signs
  • An email pressures you to act fast — "verify your account", "unusual sign-in", "payment failed", or "your account will be closed in 24 hours".
  • A generic greeting ("Dear customer"), a sender address that doesn't match the real company, or a link whose address is slightly off.
  • It asks you to click a link and enter your password, or to open an unexpected attachment.
Defense move — Two-Channel Verification
  • Don't act on the email itself. Open the site by typing the address yourself or using your saved bookmark or app — never the link in the message.
  • Verify any "problem" through a second, known channel: call the number on the back of your card or on the company's official website, not a number from the email.
  • Turn on two-factor authentication (MFA). Even if your password leaks, it blocks the login.
  • Check before you trust: a real company won't email asking you to "confirm" your password, and a look-alike sender domain is a red flag.
Editor's note

I've stopped trying to judge whether an email 'looks legit' — that's exactly the game the scammer is good at and I'm not. I replaced judgment with a reflex: any message telling me to log in or fix an urgent account problem, I don't touch the link. I open the app or type the address myself. It costs ten seconds and it makes the whole category of attack bounce off.

Frequently asked

The email looked exactly like my bank's, logo and all — how can it be fake?

Logos, colors, and layout are trivial to copy, so looking real proves nothing. The reliable rule comes from the CFPB: banks and credit unions never ask for your account information through email or text. If a message wants you to "verify" or log in via a link, don't — open the site yourself or call a number from a different, trusted source.

I clicked the link and entered my password. What do I do now?

Act fast. Go to the real site (by typing the address yourself) and change that password immediately, then turn on two-factor authentication. If you reused that password anywhere else, change it there too. Watch your account for unfamiliar activity, and report the message to the company being impersonated.

How can I tell a real sender from a fake one?

Check the "From" address, not just the display name. If a message claims to be a big company but comes from a free email account or a domain that's slightly off (extra words, odd spelling), treat it as phony. Hover over links to see where they really go. When in doubt, ignore the email and reach the company through its official website.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›