Phishing Scams: Fake Emails, Texts & Renewal Alerts
Short answer
Phishing is a fake email, text, or message designed to make you click a link, open an attachment, or call a fraudulent support number so criminals can steal your passwords, card details, or remote access to your computer. Retirees see it most often as fake antivirus renewals, delivery notices, and bank alerts. The safe response is always the same: never use the link or number in the message — reach the company through the app or a number you already have.
Reviewed and updated by the Safe Retire Watch Research Team.
- Most common lures in 2026
- Antivirus renewal invoices, package delivery fees, toll violations, bank 'security alerts'
- Newest twist
- No link at all — just a phone number, so a human can talk you into remote access
- Biggest tell
- Any pressure to act within minutes
- Where to report
- reportphishing@apwg.org, SPAM (7726) for texts, ReportFraud.ftc.gov
How do I spot a phishing email?
- Check the sender's full address, not the display name. 'Norton Support' can send from a Gmail or random domain.
- Hover over links before clicking and read the real destination in the status bar. On a phone, press and hold to preview.
- Look for a charge you did not make. Fake invoices work because your instinct is to stop the charge, and the 'cancel' path leads to the scammer.
- Watch for generic greetings, odd spacing, mismatched logos, and amounts written like $349.99 for a product you never bought.
- Treat attachments as hostile unless you were expecting them, particularly PDFs and ZIPs claiming to be receipts.
- Notice pure phone-number emails. If there is no link and no detail, only a support number, it is a call-back phishing scam designed to end with remote access to your PC.
What do phishing texts look like?
Smishing — phishing by SMS — has overtaken email for retirees because texts arrive with fewer defenses and feel more personal. The dominant 2026 formats are unpaid tolls, an undeliverable package needing a small redelivery fee, a bank asking you to confirm a transaction by replying YES or NO, and a friendly 'wrong number' message that slowly becomes an investment pitch.
The small dollar amount is intentional. A $3.95 redelivery fee does not feel worth scrutinizing, but the card details you enter are worth hundreds, and the page often harvests your billing address and one-time passcode as well.
What should I do if I clicked a phishing link?
- 1Do not enter anything else. Close the page. Clicking alone rarely causes harm; entering credentials does.
- 2If you typed a password anywhere, change that password now and change it anywhere else you reused it. Start with your email account, because it resets everything else.
- 3Turn on two-factor authentication on your email and bank accounts.
- 4If you entered card details, call the number on the back of your card and ask for a new card number and a fraud watch on the account.
- 5If you installed anything or allowed remote access, disconnect from Wi-Fi, then have the device checked before using it for banking.
- 6Report it: forward phishing emails to reportphishing@apwg.org, forward scam texts to 7726 (SPAM), and file at ReportFraud.ftc.gov.
How do I reduce phishing before it reaches me?
- Use a password manager so every account has a unique password and fake sites fail to autofill — a quiet but powerful warning sign.
- Turn on two-factor authentication for email first, then banking, then shopping accounts.
- Keep your phone and computer updated; most drive-by attacks target old software.
- Enable your email provider's spam and phishing protection, and mark rather than delete so filters learn.
- Run any suspicious message through our free AI scam email explainer before you act on it.
Direct answers on this topic
Frequently asked questions
Is it dangerous just to open an email?
Opening an email is nearly always safe on modern providers like Gmail, Outlook, or Yahoo. The danger begins when you click a link, open an attachment, call a number in the message, or type your password into the page it opens. If you opened a suspicious email and did nothing else, delete it and move on.
How can I tell if an antivirus renewal email is real?
Check your own records rather than the message. Real subscriptions appear in your bank or card statement and in your account on the vendor's own site. Fake renewal invoices from 'Norton,' 'McAfee,' or 'Geek Squad' typically show a large charge, a support phone number instead of a working account link, and a sender address that does not belong to the company. Never call the number in the email — sign in to your account directly instead.
What is the safest way to check a suspicious link?
Do not visit it to find out. Preview the destination by hovering on a computer or long-pressing on a phone, then compare the domain to the company's real domain, reading right to left before the first single slash. If you are unsure, paste the link into a link-checking tool rather than opening it, and reach the company through its app or a number you already have.
Sources and further reading
Guidance on this page is based on current advisories from these authorities.
- CISA — Recognize and report phishing
- Federal Trade Commission — How to recognize and avoid phishing scams
- Anti-Phishing Working Group — Report phishing
