.jpeg)
Phishing messages used to be easier to spot. An unexpected email might contain obvious spelling errors, unusual formatting, or a request that did not make much sense. Today, phishing attempts can look polished, personalized, and surprisingly legitimate.
Fraudsters may impersonate a bank, delivery company, government agency, coworker, executive, vendor, or another trusted organization. The message may use a familiar logo, reference a real service, and create a convincing reason for you to act. It might arrive by email, text message, phone call, social media, or even a QR code.
Although the technology behind these attacks continues to change, the objective is often the same: to convince you to reveal sensitive information, click a malicious link, open an unsafe attachment, or authorize a transaction.
Understanding how modern phishing works can help you slow down, recognize the warning signs, and protect your personal and financial information.
Phishing is an online scam that uses deceptive or misleading communications to persuade someone to share private information. The information fraudsters seek may include usernames, passwords, payment details, account information, one-time passcodes, or multifactor authentication codes. CISA describes phishing as an online scam that entices users to share private information through deceitful tactics.
While phishing is commonly associated with email, it can take several forms:
Modern attacks may combine several of these methods. For example, a person might receive a text about suspicious account activity, followed by a phone call from someone claiming to represent the bank’s fraud department. CNB has previously identified this type of sequence in bank impersonation scams.
Many people were taught to look for poor grammar, generic greetings, and obvious spelling mistakes. Those are still potential warning signs, but they should no longer be the only things you consider.
Modern tools can help fraudsters create messages that are clear, professional, and tailored to a particular audience. A message may refer to a recognizable company, a recent purchase, an invoice, a delivery, or an apparent account problem.
Fraudsters may also use information from public sources, social media, or prior data breaches to make a message or phone call sound more credible. Knowing your name, employer, phone number, or other personal details does not prove that the person contacting you is legitimate.
Caller ID is not proof either. Through a practice known as spoofing, an incoming call may appear to originate from a familiar number or organization.
Instead of relying only on how a message looks, focus on what the message is asking you to do.
Fraudsters often want you to react before you have time to think. A message may claim that your account will be closed, a payment has failed, suspicious activity has been detected, or immediate action is required.
Treat unexpected urgency as a reason to pause. A legitimate organization should give you a safe way to verify the situation independently.
Be cautious if someone unexpectedly requests your password, online banking credentials, one-time passcode, token code, or multifactor authentication code.
City National Bank will never ask clients to provide online banking credentials or authentication codes through an unsolicited communication. CNB’s internal fraud-prevention guidance also emphasizes that employees should never request or accept client online banking credentials.
A fraudulent website may resemble a legitimate company’s website but use a slightly different address. The difference could be a missing letter, an extra word, or an unfamiliar ending.
Instead of using a link in an unexpected message, open your browser or mobile application and navigate to the organization through a trusted address you already know.
A fraudster may claim that you need to transfer money to a “safe” account, reverse a suspicious payment, or send funds to protect your account.
Do not initiate or approve a transaction based solely on an unexpected call, text, or email. End the communication and contact your bank directly using a trusted telephone number.
Even a polished message deserves additional scrutiny if the request falls outside the normal process. This may include an unexpected invoice, a sudden change in payment instructions, a request to purchase gift cards, or a demand to keep the situation confidential.
For businesses, payment requests and changes to account instructions should be independently verified through an established contact and a known communication channel.
If something does not feel right, do not respond immediately. A few simple actions can help protect you:
If you clicked a suspicious link or provided information, act quickly. Change affected passwords through a trusted device, review account activity, and notify the appropriate financial institution or service provider.
Phishing attacks are designed to take advantage of trust, urgency, and routine behavior. A message does not need to look suspicious to be dangerous.
The most effective response is often the simplest: pause, verify, and use a trusted channel. Never allow an unexpected communication to pressure you into sharing confidential information or moving money.
Visit City National Bank’s Fraud Prevention & Security Center for additional resources and practical guidance to help protect yourself and your finances.
Please note: The content in this article comes from individual opinions and experiences. The content should not be taken as advice coming from City National Bank of Florida. City National Bank of Florida does not offer tax, legal or accounting advice. CNBFL Member FDIC.