Table of Contents
Phishing scams, which try to trick people into sharing sensitive information, are getting more sophisticated and harder to avoid, largely due to artificial intelligence (AI). In the past, phishing attempts might have contained spelling mistakes and awkward phrasing. But today, scammers can use AI to create convincing emails and text messages, clone voices in phone calls, and personalize messages using data pulled from your social media accounts.
Knowing how the newest phishing scams work is important to help you spot red flags and protect yourself.
Key Points
• Phishing is a social engineering fraud where scammers often pose as trusted businesses or government agencies to trick victims into revealing personal information such as Social Security numbers, passwords, or bank account details.
• Phishing arrives via email, while smishing targets victims through text messages, and vishing occurs over the phone — all three methods impersonate legitimate institutions to steal personal information.
• Warning signs include unexpected messages requesting you click links, download files, scan QR codes, provide personal information, or bypass established security procedures — even if they appear professional.
• Protective measures include enabling multi-factor authentication, using strong unique passwords, keeping software updated, and independently verifying unexpected requests by contacting the organization directly through official channels.
• Legitimate organizations will never ask you to share a one-time passcode or multi-factor authentication code, as these are intended solely for the account holder’s personal use.
What Is a Phishing Scam?
Phishing is a type of social engineering fraud in which a con artist poses as a trusted person or business and tries to trick victims into giving away personal information. Typically, scammers target an individual’s Social Security number, credit card numbers, bank account information, or passwords.
According to the Federal Trade Commission, scammers often pose as banks, credit card companies, utility companies, online payment sites, or even the government. A phishing attempt may arrive as:
• An email claiming there’s a problem with your savings or checking account or your credit card account
• A text asking you to verify a payment
• A phone call from someone pretending to be a bank representative
• A QR code directing you to a fake login page
While the methods vary, the goal is usually the same: to gain access to your personal information or financial accounts. In some cases, scammers might also sell your information to other scammers.
How Does Phishing Work?
Like a number of common bank scams, many phishing scams follow a similar pattern. First, the scammer creates a convincing message that appears to come from a legitimate source. The message typically includes a sense of urgency — for example, it might say that there has been suspicious activity on your bank account or credit card account, or claim you have an unpaid bill that must be paid immediately.
You’re then encouraged to click a link, scan a QR code, call a phone number, download an attachment, or provide personal information. If you do any of those things, the scammer may be able to gain access to your accounts, your financial information, and even your computer and phone.
Phishing scammers generally create a sense of fear and urgency to get victims to act quickly without stopping to question the message.
The Rise of AI-Generated Phishing and Hyper-Personalization
In the past couple of years, generative AI has made phishing attacks more challenging to spot. The FBI warns that criminals can now use generative AI to create messages without grammatical errors, which used to be one tell-tale sign of a scam email.
Generative AI also enables scammers to create fake social profiles and websites much more quickly, and they can use AI chatbots on fraudulent websites to help convince victims to click on malicious links.
But AI enables scammers to go far beyond emails, texts, and websites. Criminals are now using AI-generated imagery to do such things as create images of fake natural disasters to encourage people to donate money. They can also use AI in impersonation schemes, such as creating fraudulent credentials to give the impression that they are law enforcement or government officials.
With AI, scammers can also generate audio and video impersonating a victim’s loved ones in an attempt to get them to share personal information or send money.
Finally, scammers can use AI to quickly access publicly available information, like victims’ social media profiles and networking sites. This enables them to learn enough about the person so that they can hyper-personalize messages to them via email, texts, phone calls, or videos.
Multi-Channel Attacks: Email, SMS (Smishing), and Voice (Vishing)
Phishing has evolved to the point where scammers can use multiple channels, including SMS texts (sometimes called “smishing”) and voice calls to a victim’s phone (called “vishing”).
According to IBM, phishing victims are more likely to click text messages (smishing) than any other links. Vishing attacks often involve criminals calling and posing as a victim’s bank or credit card company, a government agency, or technical support representatives to try to gain private, sensitive information. Many vishing attacks are scams targeting seniors or new employees at a company.
In some cases, scammers combine multiple channels in the same attack. For instance, a victim might get a text about suspicious account activity, and then shortly after, receive a follow-up phone call from someone claiming to be a fraud investigator. This combination can make the scam seem more legitimate.
Recommended: How Do Banks Investigate Unauthorized Transactions?
5 Common Phishing Examples to Watch For
Phishing scams are constantly changing, but there are certain tactics that criminals continue to use. Here are some scams to be on the alert for.
1. AI-Voice Deepfakes and “Hi Grandma” Scams
Voice cloning has made it easier for scammers to impersonate a victim’s family and friends over the phone. For instance, you might get a call from someone that sounds like your grandparent, telling you there’s an emergency and they need money right away.
Before sending any money, you could try to verify their identity by asking them an obscure question about a memory the two of you share, like “What TV show did we watch together on Saturday mornings when I was growing up?” or “What did I get you for your 60th birthday?” Or hang up and call your grandparent using the number you have for them in the contacts list on your phone and ask them if the emergency call was actually from them.
2. Quishing: Malicious QR Codes in Public Spaces
Quishing refers to a tactic scammers use by sending or posting QR codes. When the code is scanned, it redirects victims to a malicious website or encourages them to download malware.
These QR codes might be sent via email, or they may be posted on social media sites or even on flyers in your neighborhood. Be careful before scanning random QR codes or those that seem suspicious, and never enter personal information on a website until you’ve fully vetted the site to make sure it’s legitimate.
3. Fake “Urgent” MFA and Security Alert Notifications
Scammers also use fake security alerts to get victims’ information. For example, you might get a text or email claiming that:
• Your account’s been locked
• A login attempt was detected
• Your password needs to be reset immediately
• A security verification is required
The message often includes a link or requires you to divulge a one-time passcode (OTP). The goal is to get you to provide sensitive information in a panic, because you believe your information has been compromised.
4. Tax Refund and IRS Impersonation (2026 Dirty Dozen)
Each year, the IRS releases a “Dirty Dozen” list of tax scams that criminals are using to target victims. These scams include phishing attempts via email or text that offer refunds or deductions and include QR codes that send victims to fake websites, or they may be calls demanding immediate payment or threatening arrest.”
The IRS says it generally contacts taxpayers through the mail first, so you should immediately be suspicious about emails, texts, and phone calls claiming to be from the agency. The IRS also won’t threaten to call law enforcement or demand immediate payment. If you receive a concerning communication that appears to be from the IRS, contact the agency to find out whether it’s real.
5. Job Offer and “Sugar Baby” Scams Targeting Gen Z
Criminals may target younger people with fake job offers or through online relationship scams. For example, a “recruiter” might offer a high-paying remote job and ask for a victim’s bank information or require you to pay upfront fees.
Other scammers might promise victims financial support (lavish gifts, trips, or even cash) in return for companionship through a “sugar baby” arrangement. Eventually, they will usually ask for the victim’s bank information saying it’s to give them a direct deposit — but in reality, they plan to access the account for themselves.
Recommended: Top 10 Crypto Scams to Watch Out For in 2026
How to Spot Phishing: 2026 Red Flags
Even though these attacks have gotten more sophisticated in recent years, there are red flags that could help you spot phishing. These are some of the signs to watch out for.
Flawless Grammar but “Off” Context (The AI Signature)
In the past, bad grammar and misspellings in emails and texts made it easier to spot phishing scams. But with generative AI, criminals can now craft error-free messages with professional formatting — and even proper branding, when they’re posing as a company.
If you get a message that’s unexpected (even one that looks professional) from someone you don’t know asking you to click on a link, download a document you didn’t ask for, scan a QR code, or provide personal information, those are signs that it could be a scam.
Pressure to Bypass Security Protocols or Shared Passwords
Another warning sign of a phishing scam is being asked to bypass established security procedures. According to guidance from the Office of the Comptroller of the Currency, individuals should be cautious of unsolicited requests for account credentials and personal information, including passwords and multi-factor authentication (MFA) codes, and any requests that ignore normal verification procedures.
Legitimate companies typically have established procedures for verifying identity and protecting customer information without asking consumers to divulge private account information.
How to Prevent and Avoid Phishing Scams
Even as scammers continue to evolve their phishing attacks with high-tech tools like AI, some standard safety habits can still reduce the risk of becoming a victim, including:
• Enabling MFA whenever possible
• Using strong, unique passwords
• Keeping your devices and software updated
• Avoiding clicking on suspicious links or downloads
• Verifying unexpected requests independently (such as looking up the official phone number of a company or agency and calling them to ask if the request is legitimate)
Bank account protection, such as fraud protection and account monitoring, may also be worth considering.
Use “Speed Bumps” and Out-of-Band Verification
Phishing scams succeed when a criminal can create a sense of urgency and pressure a victim to act immediately. Adding “speed bumps” to the process, like multifactor authentication, requires an individual to take multiple steps and slow down, which can give them time to think about and question the request before divulging information.
Another method that may help prevent a phishing attack is out-of-band authentication. This is when you use a separate communication channel to verify the authenticity of the communication. For instance, if you receive an email from your bank asking for personal information, instead of responding to the email, look up the main customer service number and call the bank to ask if the email is legitimate.
Why You Should Never Share an OTP or MFA Code
One-time passcodes (OTP) and MFA codes are designed to verify that you’re the authorized account holder before you log in. Scammers frequently attempt to trick victims into sharing these codes, which might allow them to bypass account security protections.
Legitimate organizations will never ask you to share an OTP or MFA code. That code is for you and you alone to use when accessing your account.
The Importance of Direct-to-Source Navigation
One way to help avoid getting phished is to ignore links in any messages or calls that are unexpected, out of the blue, and trying to get you to take action. Instead, you can navigate directly to the source — such as by going to the website for your credit card company or calling their official phone number instead of clicking a link in an email supposedly from the company.
What to Do If You’ve Been Phished
If you suspect you’ve been phished and your information stolen, it’s important to report fraud right away.
You can go to the Federal Trade Commission’s Identity Theft website, which has multiple guides addressing what to do depending on the type of information stolen, including Social Security numbers, debit or credit card numbers, bank or investment account information, or driver’s license information.
Depending on the type of scam it is, some of the steps you may need to take to protect yourself might include:
• Freezing your credit to make it more difficult for a criminal to open a credit account in your name
• Getting credit monitoring to track your accounts and alert you to suspicious activity
• Changing your passwords
• Freezing compromised debit and credit cards and getting new cards with new account numbers
• Installing or updating security software on your computer or mobile device
• Reporting the phishing to the FTC on the Report Fraud website
The Takeaway
Phishing attacks are getting more sophisticated and harder to spot due to criminals using AI. Learning how to spot phishing attempts and enabling security protection, including unique passwords and multifactor authentication, are steps individuals can take to help avoid phishing scams.
Interested in opening an online bank account? When you sign up for a SoFi Checking and Savings account with eligible direct deposit, you’ll get a competitive annual percentage yield (APY), pay zero account fees, and enjoy an array of rewards, such as access to the Allpoint Network of 55,000+ fee-free ATMs globally. Qualifying accounts can even access their paycheck up to two days early.
FAQ
Can a phishing scam happen through a QR code?
Yes, phishing scams can happen through a QR code. This is called “quishing.” The code may send victims to a fraudulent website or encourage them to download malware that can infect their digital devices. It’s a good idea to be very careful before scanning random QR codes, codes sent by email or text that you didn’t ask for, or codes that just seem suspicious.
How can I tell if a bank email is a phishing scam or legitimate?
A bank email might be a phishing scam if it requests private and sensitive information, pressures you to act quickly, or sends a link you didn’t ask for. If you’re not sure, or you have any doubts at all, call the bank directly to ask about the email.
Does SoFi ever ask for my password or MFA code over the phone?
No, SoFi will never ask you to share your password or MFA code over the phone. If someone calls you asking for these things, it is a scam. Don’t share these codes with anyone, even if they claim to be from your bank.
What is the difference between phishing, smishing, and vishing?
Phishing typically refers to scams sent via email, in which the criminal poses as a representative of a business or government agency, like a bank or the IRS, and tries to trick victims into giving away personal information, downloading a document, or clicking a link. Smishing is essentially the same thing, only it is done via text message. Vishing is done over the phone by a scammer who pretends to be from a bank or a government agency, for example, in an attempt to get a victim’s personal information.
Can AI-generated phishing emails have perfect grammar?
Yes, modern AI tools have enabled criminals to send phishing emails with perfect grammar and spelling. That’s why it’s important to evaluate the request itself, not just the quality of the writing. If the email is unexpected and the request is for sensitive personal information or you’re asked to click a link or download a document, proceed with caution. It might very well be a scam.
Photo credit: iStock/draganab
SoFi® Checking and Savings is offered through SoFi Bank, N.A. ©2026 SoFi Bank, N.A. All rights reserved. Member FDIC. Equal Housing Lender.
^Early access to direct deposit funds is based on the timing in which we receive notice of impending payment from the Federal Reserve, which is typically up to two days before the scheduled payment date, but may vary.
Annual percentage yield (APY) is variable and subject to change at any time. Rates are current as of 5/28/26. There is no minimum balance requirement. Fees may reduce earnings. Additional rates and information can be found at https://www.sofi.com/legal/banking-rate-sheet
Eligible Direct Deposit means a recurring deposit of regular income to an account holder’s SoFi Checking or Savings account, including payroll, pension, or government benefit payments (e.g., Social Security), made by the account holder’s employer, payroll or benefits provider or government agency (“Eligible Direct Deposit”) via the Automated Clearing House (“ACH”) Network every 31 calendar days.
Although we do our best to recognize all Eligible Direct Deposits, a small number of employers, payroll providers, benefits providers, or government agencies do not designate payments as direct deposit. To ensure you're earning the APY for account holders with Eligible Direct Deposit, we encourage you to check your APY Details page the day after your Eligible Direct Deposit posts to your SoFi account. If your APY is not showing as the APY for account holders with Eligible Direct Deposit, contact us at 855-456-7634 with the details of your Eligible Direct Deposit. As long as SoFi Bank can validate those details, you will start earning the APY for account holders with Eligible Direct Deposit from the date you contact SoFi for the next 31 calendar days. You will also be eligible for the APY for account holders with Eligible Direct Deposit on future Eligible Direct Deposits, as long as SoFi Bank can validate them.
Deposits that are not from an employer, payroll, or benefits provider or government agency, including but not limited to check deposits, peer-to-peer transfers (e.g., transfers from PayPal, Venmo, Wise, etc.), merchant transactions (e.g., transactions from PayPal, Stripe, Square, etc.), and bank ACH funds transfers and wire transfers from external accounts, or are non-recurring in nature (e.g., IRS tax refunds), do not constitute Eligible Direct Deposit activity. There is no minimum Eligible Direct Deposit amount required to qualify for the stated interest rate. SoFi Bank shall, in its sole discretion, assess each account holder's Eligible Direct Deposit activity to determine the applicability of rates and may request additional documentation for verification of eligibility.
See additional details at https://www.sofi.com/legal/banking-rate-sheet.
We do not charge any account, service, or maintenance fees for SoFi Checking and Savings. We do charge transaction fees for outgoing wire transfers, Instant Transfers, and global remittance transfers. Our fee policy is subject to change at any time. See the SoFi Bank Fee Sheet for details at sofi.com/legal/banking-fees/.
*Awards or rankings from Forbes are not indicative of future success or results. This award and its ratings are independently determined and awarded by their respective publications.
Financial Tips & Strategies: The tips provided on this website are of a general nature and do not take into account your specific objectives, financial situation, and needs. You should always consider their appropriateness given your own circumstances.
External Websites: The information and analysis provided through hyperlinks to third-party websites, while believed to be accurate, cannot be guaranteed by SoFi. Links are provided for informational purposes and should not be viewed as an endorsement.
SOBNK-Q226-162