Your boss wants a gift card for a client, right now, and she's in meetings all day.
The message is short, friendly, and slightly urgent.
It is also, quite possibly, a stranger in another time zone trying to empty an account.
Phishing is the practice of impersonating someone trustworthy to get you to hand over passwords, card numbers, or access to your accounts.
The name comes from "fishing" — bait, a hook, and a wait.
A single operator can fire off millions of texts and emails before lunch, and the tools to do it cost less than a streaming subscription.
A bank wrote in broken English from an address like security@bank-verify-ru.com.
So the scammers stopped writing like scammers.
Today's messages arrive from spoofed numbers that match your bank's real one, land in the same text thread as legitimate alerts, and use your actual name, which they bought from a data breach.
The newest wave doesn't even ask you to click a link.
It asks you to call a number, where a polite person walks you through "verifying" your identity.
Or it impersonates a delivery service and asks for a small redelivery fee — eighteen cents — because nobody agonizes over eighteen cents.
Some versions target job seekers with fake interviews, then request a photo of your driver's license "for onboarding." The damage isn't only financial.
Once someone has your email password, they can reset everything else tied to it.
They can message your contacts from your account, which makes the next scam far more convincing.
Recovering a hijacked identity can take weeks of phone calls, frozen cards, and credit monitoring — a part-time job nobody applied for.
What makes this a societal problem rather than a personal one is the asymmetry.
The scammer needs one success in ten thousand tries.
You need to be perfect every single time, on a device that pings you at red lights and in checkout lines.
We built a world where every account, bill, and relationship runs through a screen, then handed the keys to anyone with a laptop.
The fix isn't complicated, but it is inconvenient.
Never trust a link or number from an unexpected message — open the app or call the number on your card.
Turn on two-factor authentication everywhere, preferably with an app rather than texts.
Slow down when a message makes you feel rushed, because that feeling is the product being sold to you.
The uncomfortable truth is that we've quietly outsourced fraud prevention to exhausted individuals and called it personal responsibility.
Banks save billions by pushing that burden onto us, then blame us when we slip.
Final Thoughts
Until the institutions that profit from these systems are held accountable for securing them, the hook will keep finding new water.