How to Report Phishing
Example of common phishing warning signs. Illustration by Isochrone, Wikimedia Foundation, and Philip Metschan, licensed CC BY-SA 4.0.
Quick Answer
To report phishing, first avoid clicking links, opening attachments, replying, or calling a phone number shown in the suspicious message. Preserve the evidence by taking screenshots and saving the original message when possible. Use your email provider’s “Report phishing” or “Report spam” control, forward suspicious emails to the organization being impersonated through a verified reporting address, and submit fraud reports to the appropriate national authority. In the United States, phishing emails can be forwarded to the Anti-Phishing Working Group at reportphishing, suspicious texts can be forwarded to 7726, and scams can be reported to the Federal Trade Commission through ReportFraud.ftc.gov.
If you clicked, entered credentials, downloaded a file, sent money, or disclosed personal information, reporting is only one part of the response. Change affected passwords from a clean device, enable multifactor authentication, contact your bank or card issuer using a trusted number, scan and update devices, review account activity, and follow identity-theft recovery steps when sensitive information may have been exposed.
What Phishing Means
Phishing is a form of social engineering in which a criminal pretends to be a trusted person, company, agency, employer, bank, delivery service, or online platform. The message is designed to create urgency, fear, curiosity, or excitement so that the recipient acts before checking whether the request is genuine. The attacker may want a password, payment-card number, bank login, authentication code, tax information, Social Security number, cryptocurrency transfer, remote access to a device, or installation of malicious software.
The word is commonly associated with email, but the same technique appears in many channels. Phishing sent by text message is often called smishing. Voice-based impersonation is commonly called vishing. Social-media direct messages, fake customer-support chats, QR codes, calendar invitations, cloud-document shares, job offers, and fraudulent invoices can all serve the same purpose.
A phishing report is useful even when you did not lose money. Reporting helps service providers block accounts and domains, gives investigators evidence about campaigns, improves filters, warns an impersonated organization, and may protect other recipients. A report is most useful when it preserves technical details and is sent to the right destination promptly.
Recognize the Warning Signs Before You Report
No single clue proves a message is fraudulent. Skilled attackers copy logos, writing styles, signatures, and layouts. Instead of relying on one sign, consider the whole situation.
- Unexpected urgency: The message says your account will close, a payment will be charged, a package will be returned, or legal action will begin unless you respond immediately.
- A request for credentials or codes: Legitimate support staff should not ask you to send your password or one-time authentication code by email, text, or chat.
- A mismatched sender: The visible display name may be familiar while the actual email address uses an unrelated or misspelled domain.
- A suspicious destination: The text of a link may name a legitimate company, but the real destination is different. On a computer, hovering may reveal it, but do not click merely to investigate.
- Unusual payment instructions: Gift cards, cryptocurrency, wire transfers, payment apps, and cash couriers are common in scams because recovery can be difficult.
- Unexpected attachments: Files described as invoices, voicemail messages, delivery notices, resumes, or secure documents may carry malware or direct you to a fake login page.
- A request to bypass normal procedures: The sender tells you to keep the matter secret, move the conversation to another platform, disable security controls, or ignore warnings from your bank.
- A story that does not fit: The message refers to an order you did not place, a service you do not use, or a supervisor who normally communicates differently.
Grammar and spelling mistakes can be warning signs, but professional wording does not prove legitimacy. Modern phishing messages may be polished, personalized, and based on information obtained from public profiles or previous data breaches.
Step 1: Stop Interacting With the Message
Do not click links, download files, scan QR codes, call numbers in the message, reply, or unsubscribe. A fake unsubscribe link can confirm that your address is active or lead to another malicious page. Do not forward the message casually to friends or coworkers because they may click it.
If the message appears to come from an organization you use, open that organization’s official app or type its known web address yourself. You can also call a number printed on your card, statement, or official website. Ask whether the request is genuine without relying on any contact details contained in the suspicious message.
For workplace messages, follow the company’s incident-reporting process. Many organizations provide a dedicated security mailbox, ticket form, or “Report phishing” button. Prompt reporting can allow the security team to remove similar messages from other inboxes, block a malicious domain, and determine whether any employee credentials were compromised.
Step 2: Preserve Useful Evidence
Before deleting the message, preserve enough information for investigation. A screenshot is helpful, but the original email contains headers and routing data that a screenshot does not capture. When your email provider allows it, use “Show original,” “View source,” “Download message,” or a similar function to save the message in its original format. Do not alter the file.
Record the following where relevant:
- Date and time received
- Sender address, display name, and reply-to address
- Phone number or social-media account used
- Subject line and message text
- Displayed links and their destinations, without opening them
- Attachment names
- Cryptocurrency wallet addresses or payment instructions
- Order, invoice, or case numbers
- Any money sent and the payment method
- What information you disclosed
- Actions already taken
Do not upload sensitive evidence to a public forum. Screenshots may contain your email address, account number, QR code, authentication code, address, or other private data. Redact information before sharing publicly, while keeping an unedited copy for banks, service providers, insurers, or law enforcement.
Step 3: Use the Email Provider’s Report Function
Most major email services include a reporting control. Select the message and choose “Report phishing,” “Report spam,” or the closest available option. This does more than move the email to junk. It can provide the provider with technical data needed to identify related messages, malicious senders, and dangerous links.
If the message reached a work account, use the company’s approved button or process instead of simply deleting it. Security teams often need the original message to analyze headers, attachments, and links in a controlled environment.
Do not mark a legitimate marketing email as phishing merely because you no longer want it. Use the provider’s spam function or a verified unsubscribe mechanism for ordinary commercial email. Phishing reporting should be reserved for deceptive attempts to steal information, money, or access.
Step 4: Report the Impersonation to the Real Organization
When a scam pretends to represent a bank, retailer, delivery company, government agency, payment service, university, employer, or technology platform, notify that organization through a channel independently verified from its official website or app. Many companies publish a fraud or phishing reporting address.
Forward the suspicious message as an attachment when the organization requests that format, because ordinary forwarding may remove useful header information. Include a brief statement explaining whether you clicked, entered information, paid, or downloaded anything. Do not include passwords or full card numbers in your report.
After reporting, contact the organization’s account-security team separately if your real account may be affected. A general phishing mailbox may collect intelligence but may not initiate account recovery.
Step 5: Report to Fraud and Cybersecurity Organizations
The correct destination depends on your country and the nature of the incident. In the United States, common options include:
- Forwarding phishing emails to the Anti-Phishing Working Group at reportphishing.
- Forwarding suspicious text messages to 7726, which spells SPAM on a telephone keypad. Your mobile carrier may request the sender’s number afterward.
- Submitting a report through the Federal Trade Commission’s fraud-reporting system.
- Using IdentityTheft.gov when personal information was stolen or used.
- Reporting serious internet-enabled crime through the FBI’s Internet Crime Complaint Center when appropriate.
- Notifying local police when money, threats, stalking, account takeover, or identity crime creates an immediate local concern.
Outside the United States, use your national cybercrime center, consumer-protection authority, police reporting portal, telecommunications regulator, or bank-fraud reporting system. Search for the official government domain directly rather than following a reporting link sent by an unknown person.
A report does not guarantee recovery or an individual investigation. Its value includes creating a record, connecting related incidents, supporting takedowns, and helping authorities understand the scale of a campaign.
Step 6: Report Suspicious Text Messages
Do not tap the link, reply, or call a number in a suspicious text. Use the messaging app’s report-and-block feature. In the United States, forward the text to 7726. Depending on the device, you may press and hold the message, choose forward, and send it to that short code. When asked, provide the sender’s number.
Take a screenshot that shows the sender, date, time, and full message. If the text concerns a bank, delivery service, toll, tax authority, or account alert, verify the issue through the official app or a known website.
Be especially cautious when a text asks for a one-time code. Criminals sometimes trigger a real password reset and then impersonate support to persuade the victim to reveal the code. Whoever controls the code may gain access to the account.
Step 7: Report Suspicious Calls and Voicemails
End the call without providing information. Do not trust caller ID; numbers can be spoofed. Contact the organization through a trusted number and ask whether it called you. Save the voicemail and note the time, number shown, name used, and request made.
If the caller claimed to represent a bank or card issuer, use the number printed on the physical card. If the caller claimed to be a government agency, find the agency’s official contact page independently. Legitimate agencies do not resolve surprise legal or tax problems through gift cards, cryptocurrency, or threats of immediate arrest.
Step 8: Act Immediately if You Clicked a Link
Clicking does not automatically mean an account was compromised, but it increases the need for caution. Close the page and do not enter information. If a file downloaded, do not open it. Disconnecting the device from the network may be appropriate if malware appears to be running, especially in a workplace environment. Contact the organization’s security team before attempting extensive cleanup on a managed device.
Update the operating system, browser, and security software, then run the recommended scans. Review browser extensions and recently installed applications. If the page requested notification permissions or installed a profile, remove the permission through device settings.
Use a different, trusted device to change passwords for affected accounts if you suspect malware or credential theft. Start with the email account because access to email can allow attackers to reset many other accounts.
Step 9: Respond if You Entered a Password
Change the password immediately through the legitimate website or app. Create a unique password that you do not use elsewhere. If the same or a similar password was reused, change it on every affected service.
Enable multifactor authentication, preferably with an authenticator app, passkey, or security key when available. Review account recovery email addresses, phone numbers, forwarding rules, filters, connected apps, active sessions, and recently trusted devices. Attackers may create a forwarding rule or add a recovery method so they can return after the password changes.
Sign out other sessions and revoke unfamiliar app permissions. Check sent mail, deleted mail, social-media posts, cloud files, and payment activity. Warn contacts if the compromised account sent messages to them.
Step 10: Respond if You Shared Financial Information or Sent Money
Contact the bank, card issuer, payment platform, wire service, or cryptocurrency exchange immediately using a trusted contact channel. Ask whether the transaction can be stopped, recalled, disputed, or traced. Speed matters, especially for transfers and account takeover.
Replace compromised cards, reset online-banking credentials, review beneficiaries and transfer settings, and ask whether additional account monitoring is available. Keep case numbers, names of representatives, dates, and copies of documents.
Be cautious of “recovery” services that contact you after a loss and promise to retrieve money for an upfront fee. Victim lists are sometimes resold, and the second approach may be another scam.
Step 11: Respond if Personal Identity Information Was Exposed
If you disclosed a government identifier, date of birth, address, tax information, driver’s-license image, passport image, health-insurance data, or answers to security questions, create a written recovery plan. In the United States, IdentityTheft.gov can generate steps based on the information involved.
Consider fraud alerts or credit freezes with the major credit bureaus when the exposure creates a risk of new-account fraud. Monitor credit reports, bank accounts, tax records, insurance claims, and mail. Replace documents when the issuing authority recommends it.
A credit freeze does not prevent every form of identity crime. It mainly restricts access to credit files for new-credit decisions. Existing-account fraud, tax fraud, medical identity theft, and account takeover require separate monitoring.
How to Write a Useful Phishing Report
A concise report is usually more useful than a long emotional narrative. Use a structure such as:
- What happened: “I received an email pretending to be my bank.”
- When: Include the date, time, and time zone.
- Channel: Email, text, call, social media, QR code, or website.
- Sender information: Address, number, username, and display name.
- Requested action: Login, payment, attachment, remote access, or authentication code.
- Your interaction: State whether you clicked, downloaded, entered information, or paid.
- Loss or exposure: Describe amounts and categories of data without placing full sensitive numbers in ordinary email.
- Evidence: Mention screenshots, original messages, receipts, transaction IDs, and bank case numbers.
Be accurate. Do not exaggerate, edit screenshots to change meaning, or accuse a specific person without evidence. Technical and financial records are more valuable than speculation.
Common Mistakes to Avoid
- Deleting the message before preserving useful evidence.
- Clicking a link to “check whether it is fake.”
- Calling the phone number shown in the suspicious message.
- Replying to challenge or threaten the sender.
- Posting unredacted screenshots publicly.
- Changing one password while leaving reused passwords unchanged elsewhere.
- Assuming multifactor authentication prevents every attack.
- Waiting several days before contacting a bank.
- Paying a recovery company that guarantees results.
- Believing a report alone secures a compromised account.
Phishing at Work: Extra Steps
Report workplace phishing immediately, even if you are embarrassed that you clicked. Early disclosure can reduce damage. Tell the security team what happened, on which device, and whether credentials or files were involved. Do not erase logs, reset a managed device, or run unapproved tools unless instructed.
Organizations should avoid punishing good-faith reporting. A blame-heavy culture encourages employees to hide incidents. Effective programs make reporting easy, acknowledge reports quickly, preserve evidence, remove similar messages, reset exposed credentials, inspect authentication logs, and communicate lessons without revealing unnecessary personal details.
Writer’s Opinion
The most important distinction is between reporting a message and responding to an incident. A person who merely receives a suspicious email may only need to preserve it, report it, and delete it. A person who entered credentials, installed software, or sent money has an active security or fraud incident that requires immediate containment.
Many guides focus on spotting awkward wording, but that advice is no longer sufficient. The stronger habit is independent verification: leave the message, open the official app or known website, and check the issue there. This works even when the phishing message is grammatically perfect and visually convincing.
Reporting should also be proportional. Send evidence to the provider, impersonated organization, and relevant authority, but do not circulate it widely. The goal is to reduce harm, not to give a malicious link more exposure.
Frequently Asked Questions
Should I forward a phishing email or take a screenshot?
Do both when practical. A screenshot preserves the visible content, while forwarding as an attachment or saving the original message can preserve headers and routing information. Follow the recipient organization’s instructions.
Can I get hacked just by opening an email?
Modern email services limit many automatic risks, and merely viewing a message is generally less dangerous than clicking a link or opening an attachment. However, vulnerabilities and tracking techniques exist. Keep software updated and avoid interacting with suspicious content.
What should I do after reporting?
Delete or quarantine the message after preserving needed evidence. If you interacted with it, secure accounts, devices, and financial information based on what was exposed.
Should I reply to tell the sender I know it is a scam?
No. Replying can confirm that the address is active and may invite further manipulation. Report, block, and delete instead.
Can a legitimate company ask me to verify my account?
A legitimate company may send an alert, but you should verify it through the official app or a web address and phone number you already trust. Do not use the message’s link or contact details.
What if the phishing email came from someone I know?
Their account may be compromised. Contact them through another channel, report the message, and do not open the link or attachment. Encourage them to secure their account.
Will reporting guarantee that the website is removed?
No. Takedowns depend on evidence, hosting arrangements, jurisdiction, and provider response. Reporting still helps connect incidents and may contribute to blocking or removal.
Final Checklist
- Do not click, reply, call, scan, or download.
- Verify the request through a trusted channel.
- Preserve screenshots and the original message.
- Use the provider’s report-phishing function.
- Notify the impersonated organization.
- Report to the appropriate fraud or cybersecurity authority.
- Secure accounts if credentials were entered.
- Contact financial providers immediately after a payment or data exposure.
- Update and scan affected devices.
- Document every report, case number, and recovery step.
Conclusion
Effective phishing reporting is a combination of evidence preservation, correct routing, and rapid damage control. Do not investigate by interacting with the suspicious content. Preserve what you received, report it through trusted channels, and then respond according to what happened. The faster you secure exposed accounts and contact financial institutions, the better the chance of limiting harm.
