Everything we were taught about spotting a scam email has stopped working. The advice was reasonable for its era: watch for broken grammar, generic greetings, odd formatting, a sender address that does not match the company. Every one of those tells was a byproduct of the scam being cheap to produce. Generative AI removed the cost, and with it the tells.
The FBI’s Internet Crime Complaint Center documented roughly $215.8 million in reported phishing losses from about 191,561 complaints in its most recent annual report — an average of a little over $1,100 per complaint — with business email compromise accounting for a further $3 billion or so on its own. Those are reported figures, which means they are floors rather than estimates.
If you are the person in your household who pays the bills, manages the accounts, or handles a parent’s finances, you are the target of this category by function. Here is what has actually changed and what still works.
Stop Screening for Bad Writing
The most important adjustment is to abandon a habit. A well-written, correctly formatted, personally addressed message is no longer evidence of legitimacy. It is now the baseline for fraudulent messages too, because producing one costs essentially nothing.
Worse, AI-assisted phishing can be personalized at scale. Details that used to signal authenticity — your name, your bank, a recent transaction type, your employer, a family member’s name — are assembled from data breaches, social media, and public records, then written into a message that reads as though someone who knows you wrote it. The old mental model was “does this look sloppy?” The new one has to be “am I being asked to act on information delivered to me, rather than information I went and found?”
That shift in question is the whole defense, and everything below is a version of it.
Quishing: Why QR Codes Are the Weak Point
QR code phishing — “quishing” — grew roughly 400% between 2023 and 2025 and has continued climbing sharply through 2026, with Microsoft’s own detection telemetry showing QR phishing volumes rising steeply quarter over quarter.
The reason is structural rather than clever. Email security tools scan links. They read the destination of a URL, compare it against reputation databases, and flag or rewrite it. A QR code is an image. The destination is encoded in pixels, so a scanner that reads links finds nothing to read. The malicious address travels inside a picture, straight past the filter, and then gets opened on your phone — which is typically the device with the smallest screen, the most truncated address bar, and the least protection.
Quishing shows up in some predictable places:
- Fake package-delivery notices, by email or a card left at the door, asking you to scan to reschedule
- Parking meters and EV chargers with a fraudulent sticker placed over the legitimate code
- Utility or toll “final notice” mailings, which have become common enough to warrant real suspicion of any physical letter urging a QR payment
- Restaurant table codes overlaid with a sticker pointing somewhere else
The physical-sticker versions are the ones worth internalizing, because they defeat the instinct that paper mail and real-world objects are safer than email. A sticker costs nothing to apply. If you are standing at a parking meter, look at whether the code is printed into the surface or stuck on top of it.
The rule that covers all of these: do not scan a QR code to pay for something or to log into an account. Type the address yourself, or use the app you already have installed. A QR code is fine for a menu. It is not a payment channel.
Voice Cloning and the Family Emergency Call
A few seconds of recorded audio — a voicemail greeting, a social media video, a work presentation — is sufficient to produce a convincing clone of someone’s voice. The scam that follows is old, and the technology has made it much harder to resist: a call from a grandchild, a daughter, a spouse, in distress, needing money immediately, asking you not to tell anyone else.
The countermeasure is embarrassingly low-tech and it works: agree on a spoken passphrase with the people whose voices could be used against you. Something no one could look up, that you would ask for in an emergency call. Then use it, every time, without apologizing for using it.
The second countermeasure is to hang up and call back on the number you already have. A cloned voice cannot survive a callback to a real phone. This matters especially for women managing an aging parent’s finances, since the same technique is turned around and used on the parent — a call claiming to be from you, asking them to move money.
What Actually Protects the Money
Never use the contact information in the message. Not the phone number, not the link, not the “verify here” button. Open a new browser tab and type your bank’s address, or call the number printed on your physical card. Every legitimate institution can wait the ninety seconds this takes.
Move off SMS-based two-factor authentication where you can. Text-message codes are vulnerable to SIM-swap attacks and can be phished in real time by a convincing fake login page. An authenticator app is better; a passkey or hardware security key is better still and cannot be handed over to a fake site even if you are fooled, because it will not authenticate to the wrong domain.
Freeze your credit at all three bureaus. It is free, it takes about twenty minutes total, and it prevents new accounts being opened in your name. You can thaw it temporarily when you actually need credit. This is the highest-value hour of financial admin available to most households, and almost nobody does it.
Turn on transaction alerts. Real-time notifications on every card and account turn a fraud you discover at statement time into one you discover in a minute.
Treat urgency itself as the signal. Since the content-based tells are gone, the remaining reliable indicator is pressure — a deadline, a threatened suspension, a limited window, a request for secrecy. Legitimate financial business is almost never urgent in that way, and any message that needs you to act before you can think is telling you what it is.
If something does get through, report it to the FBI’s IC3 and to your bank immediately. Speed matters enormously for recovery on wire and transfer fraud, and the reported-loss figures above are lower than reality largely because people are embarrassed. These scams now defeat careful, intelligent people by design. Getting caught is not a character finding; staying quiet is what makes it expensive.


