Practice: three real messages, you tell me what's wrong
We have now covered the package text, the spoofed internal email, and the unsubscribe trap. That completes the theory. What remains is practice, because reading about these tactics and catching them in the moment are two separate skills.
I am going to walk you through three messages from my notebook. Genuine ones, sent to real people I know, with names and account numbers changed. For each, before I explain what is wrong, examine it yourself. Slow down. Check the elements we have discussed. Then we will review it together.
Work through it once here, so you have done it before it counts.
Message one: the bank text
"Alert: unusual activity detected on your account ending in 4471. Verify your identity now to avoid suspension: [link]"
First question, every time: does it rush you? Yes. "Now," "avoid suspension." That is the tell before you examine anything else.
Second: hover over the link; do not tap it. On a phone, press and hold rather than tapping, and the real address appears. If it reads something like "secure-bankverify.net" instead of your actual bank's website, you have your answer.
Third, and this is the step people skip: even if the link looks fine, your bank does not text you to verify your identity through a link. If you are concerned, close the message, open your banking app separately, or call the number on the back of your card. Not a number from the text. The one on the card.
This is the same rule I keep returning to. Your bank will never ask you to move money or "verify" anything through a link it sent you. Without exception. If it happens, hang up, close the text, and reach them through a channel you already trust.
Message two: the parking ticket
This one I know well, because it happened to me.
I received a text claiming I had an unpaid parking ticket from a trip up the canyon, with a link to pay before a late fee applied. I was halfway through typing my card number when something made me stop. It was the URL. It simply did not match. It contained the city name, technically, but padded with extra words and an odd ending that did not resemble a government site.
I stood there for a moment feeling a little foolish. But that is exactly why I teach this one. If it can get me halfway to the payment page, and I do this for a living now, it can reach anyone. That is not carelessness on your part. That is the scam performing as designed.
What saved me was the habit we keep practicing: I checked the address before I paid. Not before I clicked the link, unfortunately, but before I entered anything. A second chance still counts. The objective is to build the habit early enough that your chance comes before the payment screen rather than on it.
Message three: the "grandkid" text
"Hi Grandma, I lost my phone, this is my new number. Can you send me a gift card for my birthday? I'll explain later, kind of embarrassed to ask."
This one contains no link at all, no bad URL to inspect. It works on emotion rather than technology, which is why I placed it last. It exploits the wish to help someone you love quickly, before you have had time to verify.
The remedy here is not technical either. It is a phone call. Call the grandchild's actual number, the one already in your phone, not the new one they supposedly texted from. If they do not answer, call a parent. No legitimate person is too embarrassed to explain later rather than simply answering when you call.
What to actually do this week
Select two messages currently sitting in your own phone or email, ones you have not dealt with. Run them through the process we just used. Does it rush you? Inspect the link. If money is involved, go around it through a number or app you already trust, nothing from the message itself.
Record them in your notebook under whichever category they fit. That is the entire exercise.
Before next time
Bring one message from your own phone that you genuinely were not sure about. We will review several together as a group, and there is no wrong answer for asking.
~kenneth