Don’t Take the Bait: How to Spot Phishing and Spoofing Scams
Posted on Jul 1, 2026
We’ve all received them: a text claiming your account has been locked, an email asking you to verify your information, or a phone call that appears to come from your financial institution. These messages are designed to make you act quickly, and unfortunately, scammers are getting better at making them look legitimate.
The good news? Knowing what to look for is one of the best ways to protect yourself.
What Is Phishing?
Phishing is a scam where criminals try to trick you into sharing sensitive information such as passwords, account numbers, debit card information, or one-time verification codes.
These scams often arrive as:
- Emails
- Text messages (sometimes called “smishing”)
- Fake websites
- Social media messages
The goal is simple: convince you to click a link, download an attachment, or provide personal information.
What Is Spoofing?
Spoofing is when scammers disguise themselves as someone you trust. They may make an email, text, or phone call appear to come from your financial institution, a government agency, or another familiar organization.
Caller ID can even be manipulated to display what looks like a legitimate phone number. While seeing a familiar name or number may make you feel more comfortable, it doesn’t always mean the message is genuine.
Common Warning Signs
Scammers rely on urgency and emotion to catch people off guard. Be cautious if you receive a message that:
- Says your account has been locked or compromised.
- Asks you to verify personal or financial information.
- Requests your online banking password or one-time security code.
- Pressures you to act immediately.
- Includes unexpected links or attachments.
- Contains spelling or grammar mistakes, or uses unusual wording.
If something feels rushed or too good to be true, it’s worth taking a moment to verify before responding.
How to Protect Yourself
A few simple habits can go a long way in preventing fraud:
- Pause before clicking links in unexpected emails or text messages.
- Never share passwords or one-time verification codes with anyone.
- Type the organization’s website directly into your browser instead of using links from suspicious messages.
- Enable multifactor authentication whenever it’s available.
- Keep your devices and software up to date.
Most importantly, trust your instincts. If something doesn’t seem right, it’s okay to slow down and verify first.
When in Doubt, Contact Us Directly
If you receive a suspicious email, text, or phone call claiming to be from us, don’t respond using the contact information provided in the message.
Instead, contact us directly by calling us at 800-522-6611, visit our official website, or stop by your nearest branch. Our team is happy to help you determine whether a message is legitimate.
Don’t Take the Bait
Scammers are constantly looking for someone to “bite,” but a few extra seconds of caution can make all the difference.
Before clicking a link, sharing personal information, or responding to an unexpected message, pause and ask yourself: Does this seem legitimate?
If the answer is “I’m not sure,” don’t take the bait. Reach out to us directly. We’d much rather answer a quick question today than help you recover from fraud tomorrow.