Email Phishing
Phishing emails impersonate trusted organizations — banks, Medicare, Amazon, the IRS, or even family members — to trick recipients into clicking malicious links, entering login credentials, or opening attachments that install malware. Older adults are frequently targeted because they may be less familiar with how convincing fraudulent emails can look.
Warning Signs
- An email asks you to "verify your account," "confirm your identity," or "update your payment information" by clicking a link.
- The sender's email address looks almost right but has subtle misspellings or an unusual domain (e.g., amazon-support.net instead of amazon.com).
- The message creates urgency — your account will be suspended, a package cannot be delivered, or a charge will post unless you act immediately.
- Links in the email lead to a website that looks legitimate but has a slightly wrong URL.
- You receive an unexpected receipt, shipping notification, or invoice for something you did not buy.
Immediate Steps
- Do not click any links or open any attachments in a suspicious email.
- Go directly to the organization's website by typing the address yourself — never use a link from the email.
- If you clicked a link and entered credentials, change your password immediately from a different device.
- Run a malware scan if you opened an attachment (Windows Defender or Malwarebytes).
- Report phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org and forward to the FTC at spam@uce.gov.
Report & Get Help
AARP Fraud Helpline (free, confidential): 1-877-908-3360