Phishing emails are the single most common way scammers steal money and identity information from American families. The FBI reports that phishing was the #1 cybercrime complaint in 2025, with losses exceeding $3.5 billion. And despite decades of awareness campaigns, these emails keep getting more convincing — not less.
Here is exactly what to look for, with real examples of the most common phishing emails hitting inboxes right now.
What is a phishing email?
A phishing email is a fake message designed to look like it came from a trusted source — your bank, Amazon, the IRS, Medicare, PayPal, or even a friend. The goal is always the same: get you to click a link, enter your login credentials, or provide personal information that the scammer can use to steal your money or your identity.
The email address and the display name are two different things. A scammer can make an email display as "PayPal Security" while the actual sending address is paypal-alert@scam-domain.xyz. Always check the full email address — not just the name.
Real example: The PayPal account suspended email
This is one of the most common phishing emails in circulation right now. Here is what it looks like:
Dear Customer,
We have detected unusual activity on your PayPal account. Your account has been temporarily limited until you verify your information.
Please click the button below to restore full access immediately or your account will be permanently suspended.
Restore My Account
PayPal Security Team
The 7 red flags in every phishing email
- The sending domain doesn't match — "paypa1.com" instead of "paypal.com", "amazon-security.net" instead of "amazon.com". Always check the full address after the @ symbol.
- Urgency and threats — "Act within 24 hours", "Your account will be closed", "You will be arrested". Legitimate companies don't threaten you into clicking.
- Generic greeting — "Dear Customer", "Dear Account Holder", "Dear User". Real companies know your name.
- Suspicious links — hover over any link before clicking. The actual URL that appears at the bottom of your browser often reveals the real destination.
- Requests for personal information — your bank, the IRS, Medicare, and Social Security will never ask for your password, SSN, or full account number by email.
- Unexpected attachments — never open attachments in emails you were not expecting, even from people you know (their account may be hacked).
- Too good to be true — unexpected refunds, prize winnings, or inheritance offers are almost always phishing attempts.
Most common phishing emails right now
1. IRS tax refund
Emails claiming the IRS is holding a tax refund and you need to click a link to claim it. The IRS does not send refund notifications by email and only communicates by mail.
2. Bank fraud alert
Fake alerts from your bank saying suspicious activity was detected and you need to verify your account. Your bank's real fraud alerts will never ask for your password or full account number.
3. Amazon order problem
Emails saying there is a problem with a recent order and you need to click to resolve it. Go directly to amazon.com and check Your Orders — never click links in these emails.
4. Medicare benefits notification
Emails claiming your Medicare benefits are changing or new benefits are available. Medicare communicates by mail, not email, and never asks for your Medicare number by email.
5. Package delivery failure
Emails from "USPS", "FedEx", or "UPS" saying a delivery failed and you need to click to reschedule. Go directly to the carrier's official website to check any real shipment.
- Do not click any links or open attachments
- Check the full sending address — not just the display name
- Go directly to the company website by typing the address yourself
- If you are unsure, paste the email text into ProtectMyCircle for an instant verdict
- Report phishing emails to the FTC at reportphishing@apwg.org
- Delete the email
If you clicked a phishing link
Do not panic — but act quickly. If you clicked a link and entered any information, change your password for that account immediately using a different device. If you entered banking or credit card information, call your bank right away and let them know. File a report with the FTC at reportfraud.ftc.gov. Check your credit report for any new accounts you did not open.
Got a suspicious email?
Paste the text into ProtectMyCircle and get an instant plain-English verdict — free, no account needed.
Check it now — free