Phishing: recognise the shape of the message, not the stories
The stories change weekly: a parcel, a fine, a refund, a password reset. The structure underneath does not, and the structure is what you can teach a nine-year-old to spot.
Nobody can keep up with the individual stories. What survives is a shape: an urgent claim about an account or a payment, a link that is not quite the address it pretends to be, and a request for something only you have. Learn the shape and the story stops mattering.
The three things every phishing message wants
First, your attention on a deadline. A missed delivery, a suspended account, a charge you did not make, anything that makes the next thirty seconds feel urgent, because urgency is what stops the second thought.
Second, a click. The link is the payload; the text is only the reason to press it. It will usually resemble a real address closely enough to pass a glance and not a reading, which is why reading it letter by letter is the whole defence.
Third, something only you can supply: a password, a code from your authenticator, a card number, occasionally just a reply that confirms the number is live. If a message wants one of those three, that is the tell regardless of how plausible the rest is.
The one-time code is the modern target
Passwords are increasingly worth less than the six-digit code that follows them, and the scripts have moved accordingly: they will already have your password and will phone to collect the code, often claiming to be the bank’s fraud team.
No legitimate organisation ever needs that code read back to them. It exists so that a stolen password is not enough, and reading it out returns the situation to the point where it is. This is worth saying as its own household rule, because it is not obvious from the message.
What this looks like on a child’s device
Children rarely get bank phishing. They get account-takeover attempts dressed as their own interests: a free in-game currency generator, a giveaway that needs a login, a friend’s hacked account asking them to click something.
The rule that covers all of it is short: a platform never hands out its own currency or prizes somewhere else. Pair it with the house rule about asking out loud, which is rule ten on the ten rules page, and most of the category closes.
How to check without becoming an expert
Go to the organisation yourself, through an address you already have or an app you already use, and look for the thing the message claimed. If a parcel really is waiting, the courier’s own app knows. If the account really is suspended, logging in normally will say so.
That single habit replaces every technical check, because it does not require you to judge the message at all. The message becomes a prompt to look somewhere trustworthy instead of something to evaluate on its own terms.
What a genuine message from your bank looks like
Worth knowing the other side of this, because permanent suspicion is exhausting and eventually gets ignored. A real bank will contact you and will not object to being called back. It will not ask for a full password, a PIN, or a one-time code. It will not ask you to move money to a “safe account”. No such thing exists, and that phrase is close to diagnostic on its own.
It also will not be annoyed by the delay. The scripts apply pressure precisely because a real conversation survives being paused, and a fraudulent one does not. If a caller resists you hanging up, that resistance is the answer.
The same test works for a school, a delivery company or a tax office. You are not judging the story; you are checking whether the other party will tolerate you verifying it independently.
What to do
- Do not click. Open the organisation’s own app or type its address yourself.
- Never read a one-time code to anyone, whoever they say they are.
- If a password was entered, change it, and change the email account’s password first.
- Turn on two-factor authentication where it is offered, starting with email.
- Report the message to the platform and to your national fraud body.
- Tell the household what arrived. The same wave hits everyone in a family within days.
Questions about phishing
The message came from a real company’s number. Does that prove it is genuine?
No. Sender names and numbers are trivially forged, and messages can arrive inside a genuine thread from the same shortcode. Treat the channel as unverifiable and go to the company yourself.
I clicked but did not enter anything. Am I at risk?
Usually much less, but not necessarily none, because a click can also start a download. Close the page, do not install anything it offered, and if a file arrived, delete it without opening it.
Why do the messages have such obvious mistakes?
Some are careless, but poor spelling also filters for people who do not read closely, which is the audience the sender wants. A well-written message is not more trustworthy; the best ones are word-perfect.
Should I reply to tell them to stop?
No. A reply confirms a real person reads that number or address, which raises its value. Report and delete instead.
Is a password manager useful against this?
Very. It will not auto-fill your credentials into a look-alike domain, which means it notices the mismatch before you do. That single behaviour catches a large share of these attempts.
My child’s account was taken over. What order do I do things in?
Recover the email account first, then the affected account, then check what else used the same password. Then talk about how the login was given away, without making the telling the expensive part.
Sources
- Canadian Anti-Fraud Centre · checked 2026-09-02