Learning to Think Before You Click

You’ve probably heard the advice: don’t click suspicious links.

But today’s scams aren’t always easy to spot. A message may look like it came from your bank, your employer, a delivery company, or someone you know—but it could really be a scammer. They’ve gotten very good at making messages seem legitimate, and artificial intelligence is making it easier than ever for them to create convincing emails, texts, images, videos, and voices.

The good news: You don’t need to be a cybersecurity expert to spot common scams. You just need to know what to look for!

Avoiding risky links, attachments, and senders is a key part of Stay Cyber SMART, North Dakota’s cybersecurity campaign:

  • Set strong, unique passwords.
  • Make multifactor authentication a habit.
  • Avoid risky links, attachments, and senders.
  • Regularly update software and devices.
  • Take care with personal information.

 

Trust Your Instincts

Ever receive a message that makes you think, “Wait…is this real?” Pause. That feeling is worth listening to.

Scammers often try to get you to act before you have time to think. They may say your account is about to be closed, a payment is overdue, a package is waiting, or your boss needs something immediately.

When something feels unusual, slow down and take a closer look.

Know the Most Common Types of Scams

Many scams rely on social engineering—manipulating someone into revealing information, transferring money, or clicking a malicious link.

Common examples include:

  • Phishing – Fraudulent emails designed to trick you into clicking a link, opening an attachment, or sharing information.
  • Smishing – Phishing delivered through text messages.
  • Vishing – Scams carried out through phone calls or voice messages.

Scammers may also impersonate coworkers, friends, family members, government agencies, or other trusted organizations. AI can make these attempts more convincing by mimicking writing styles or cloning voices.

Always remember: A familiar name or professional-looking message doesn’t automatically make something legitimate.

Spot the Red Flags

Here are a few things to watch out for:

High-Pressure Urgency

“Act now!” “Final warning!” “Your account will be closed!”

Scammers want you to rush. Instead, slow down.

Unexpected Links

Be cautious with links, especially ones you didn’t expect. To see where a link leads, hover over it on a computer, or avoid tapping unfamiliar URLs on your mobile device. If something seems off, go directly to the organization’s official website or app instead.

Unexpected Attachments

Don’t open attachments unless you were expecting them. Verify before clicking.

Requests for Sensitive Information

Be suspicious of unexpected requests for:

  • Passwords
  • Social Security numbers
  • Banking information
  • Other sensitive personal or business information

Also, never share a multifactor authentication (MFA) code with someone who contacts you unexpectedly. 

Unfamiliar or Look-Alike Senders

Check the sender’s full email address, not just the display name.

For example:

One small change can be a big red flag.

Unusual Language or Requests

Does a message just feel…odd? Or perhaps it contains an unusual request? Poor grammar can be a warning sign, too, but modern scams can be incredibly well-written.

It pays to trust your gut. That said, be extra cautious if someone asks you to:

  • Buy gift cards.
  • Transfer money.
  • Change payment information.
  • Send sensitive documents.
  • Pay a new or unfamiliar account.


Even if the request appears to come from someone you trust, verify it through another method.

What to Do If You Receive a Suspicious Message

If you haven’t clicked anything: Don’t click, respond, or open attachments. Report the message and delete it.

If you clicked a link: Don’t enter any information. Close the page and report it if you use the device for work.

If you entered a password: Change it immediately using the real website—not the link in the message. 

If you shared sensitive information or sent money: Act quickly. Contact the appropriate organization, financial institution, or IT support team and report what happened.

How to Report Phishing, Smishing, & Vishing

If you see something, say something.

At Work

Use your email Phish Alert button or the appropriate reporting process. Don’t forward suspicious messages to coworkers just to ask if they’re legitimate. Report them through the appropriate channel instead.

At Home

Report scams to the Federal Trade Commission through ReportFraud.FTC.gov. Use your phone’s tools to block or report spam texts, as well.

Pause, Think, Then Click

Cybersecurity doesn’t require you to be suspicious of everything. It means pausing when something doesn’t seem right.

The next time an unexpected message lands in your inbox or pops up on your phone, pause, think, and verify. Then click if you’re confident it’s safe.

Stay safe. Stay secure. And as always—Stay Cyber SMART.

Stay Cyber Smart logo.