The Phishing Attempts That Almost Worked On Me
I get asked a lot whether I've ever nearly fallen for a phishing attempt myself, as if running a business about online safety makes me immune to it. I haven't fallen for one, not fully, but I've come closer than I'd like to admit a few times, and each of those near-misses taught me something a checklist alone never would have. Here are three of the closest calls, stripped of anything that could identify who else was involved, along with what actually saved me in the moment.
The Delivery Fee Text That Nearly Had My Card Details
The first one arrived as a text message, not an email, which is worth mentioning because I'd spent years mentally filing phishing under an email problem. It said a parcel was being held pending a small customs charge, with a link to pay it. I was expecting a delivery that week, the amount was small enough to not trigger much suspicion, and the page it linked to looked convincing, right down to a version of the courier's logo. I had my card out before I stopped to ask myself why a courier would need payment by text rather than on delivery, which is how every legitimate parcel charge I've ever encountered has actually worked. That one detail, the payment method itself, is what made me close the tab.
The Your Account Will Be Locked Email That Looked Exactly Right
The second was an email claiming my email account itself would be suspended within twenty four hours unless I verified my details, formatted almost identically to genuine account emails I'd received before, right down to the footer. What saved me wasn't spotting a spelling mistake or a wrong logo, because there weren't any, it was that I typed the provider's actual website address into my browser directly instead of clicking through, and logged in to check my account status there. There was no warning waiting for me, which told me everything the email itself couldn't. I've since learned that a password manager would have caught this automatically too, since it simply won't fill in a saved login on a domain that doesn't match, and a fake page always fails that test even when it fools your eyes.
The Fake Colleague Message That Tested My Guard at Work
The third one was different again, an email that appeared to come from someone I'd worked with, asking me to review an attached invoice urgently before month end. It used the right name, a plausible reason, and arrived at a time when that kind of request wasn't unusual. What made me pause was a small inconsistency in how the message was phrased, something the real person wouldn't have written that way, more than any obvious red flag. I called instead of replying, and confirmed they'd never sent it. Business email compromise like this is one of the newer formats these tactics show up in, and it's often harder to spot than the obvious too-good-to-be-true kind because it uses a real, trusted name.
What Each of These Had in Common, Once I Looked Back
Looking at all three together afterwards, none of them were caught because I recognised a scam template. Each one asked me to act somewhere I could verify independently, whether that was a courier's actual payment process, a login page I could reach myself, or a phone call I could make. The pressure to move quickly was present in all three, which lines up with the thread running under nearly every scam I've come across, but urgency alone wasn't what saved me. What saved me was refusing to complete the action inside the channel the message arrived through.
The One Check I Now Run Before I Trust Any Message
These days, before I act on anything that asks for money, login details, or an urgent decision, I move to a channel I chose myself rather than one supplied in the message, whether that's typing an address in directly, calling a known number, or checking an app I already have installed. It sounds like a small habit, but it would have caught all three of the examples above on its own, without needing to spot a single technical red flag. The NCSC has further guidance on verifying contact from organisations if you want a second opinion on a specific message you've received. I also keep a password manager running in the background for exactly the login page scenario above, since it does the domain checking automatically, faster than I ever could by eye. Phishing keeps evolving, and my free Safety Toolkit walks through the verify-independently habit alongside the rest of what I actually rely on.
