| Most common scam contact method | Email (FTC Consumer Sentinel Network, 2023) |
| Americans who reported losing money to fraud | More than 2.6 million (FTC Consumer Sentinel Network, 2023) |
| Reported fraud losses in the U.S. | $10 billion+ (FTC Consumer Sentinel Network, 2023) |
| Top scam category by reports | Impersonator scams (FTC Consumer Sentinel Network, 2023) |
| Where to report online scams (U.S.) | ReportFraud.ftc.gov and IC3.gov |
Why Scam Vocabulary Matters
When a scam targets you, it often works because the tactic has a name — and knowing that name gives you power. Recognizing that a suspicious email is a phishing attempt, or that a caller claiming to be the IRS is using vishing, breaks the spell before you hand over anything valuable.
This reference covers the core terms used in cybersecurity and online safety reporting. It's organized so you can scan quickly or read straight through. For a broader look at staying safe online, see our guide to online privacy for everyday users.
Phishing
A fraudulent message — typically an email — designed to trick you into revealing passwords, financial details, or other sensitive information. Phishing messages usually impersonate a trusted organization and include a link to a fake website.
Smishing
Phishing conducted via SMS text message. The message typically contains a link or a phone number and creates a sense of urgency — a package held for delivery, a suspicious charge, or a prize to claim.
Vishing
Voice phishing — a scam carried out over the phone. Fraudsters may impersonate government agencies, banks, or tech-support teams to pressure victims into sharing account credentials or sending money.
Spoofing
Disguising a communication's true source. Email spoofing fakes the sender address; caller ID spoofing makes a call appear to come from a trusted number. It does not require hacking the actual organization.
Social Engineering
Manipulating people psychologically rather than hacking systems. Social engineers exploit trust, fear, or urgency to get victims to volunteer information or take actions they otherwise wouldn't.
Credential Harvesting
Collecting usernames and passwords — usually through fake login pages that look like real sites. Once harvested, credentials are used to access accounts or sold on criminal marketplaces.
Malware
Software designed to damage, disrupt, or gain unauthorized access to a device or network. It includes viruses, ransomware, spyware, and trojans, and is often delivered via malicious email attachments or compromised downloads.
Ransomware
A type of malware that encrypts a victim's files and demands payment — usually in cryptocurrency — to restore access. Ransomware attacks target both individuals and organizations.
Two-Factor Authentication (2FA)
A login security method requiring a second proof of identity beyond a password — such as a one-time code sent to your phone. Enabling 2FA makes it significantly harder for attackers to access an account even if they have your password.
Man-in-the-Middle Attack
An interception method where an attacker secretly sits between two communicating parties — for example, between your browser and a banking website — to read or alter the exchanged data.
Quishing
Phishing that uses QR codes instead of traditional links. Scanning a fraudulent QR code — on a flyer, parking meter, or email — can direct you to a credential-harvesting site.
Account Takeover (ATO)
When a fraudster gains access to and takes control of someone's online account — email, bank, social media — typically using stolen or guessed credentials. Once inside, they may lock out the real owner and exploit the account.
Key Concepts Behind Online Scams
Most online scams — regardless of the specific tactic — rely on a small set of psychological mechanisms. Understanding these patterns helps you stay skeptical at the right moments.
| Most common scam contact method | Email (FTC Consumer Sentinel Network, 2023) |
| Americans who reported losing money to fraud | More than 2.6 million (FTC Consumer Sentinel Network, 2023) |
| Reported fraud losses in the U.S. | $10 billion+ (FTC Consumer Sentinel Network, 2023) |
| Top scam category by reports | Impersonator scams (FTC Consumer Sentinel Network, 2023) |
| Where to report online scams (U.S.) | ReportFraud.ftc.gov and IC3.gov |
Impersonation and Spoofing
Scammers rarely announce themselves. Instead, they disguise emails, phone numbers, or websites to look like trusted institutions — your bank, the IRS, or a well-known retailer. This is called spoofing. A spoofed email address might swap one letter or add a hyphen that's easy to miss at a glance.
Urgency and Pressure
Legitimate organizations almost never demand immediate action under threat of arrest, account suspension, or penalty. If a message pushes you to act right now, treat that pressure itself as a warning sign — it's a core feature of social engineering, not a reason to comply.
Unfamiliar Delivery Channels
Scammers adapt to wherever people spend time: email, SMS, phone calls, social media DMs, and even QR codes in physical spaces. The tactic changes; the underlying goal — getting you to hand over credentials, money, or personal data — does not.
Glossaries like this one serve the same purpose as plain-language references in other high-stakes domains. Just as homebuyers benefit from knowing terms like escrow and contingency (see the homebuying vocabulary reference), internet users benefit from knowing what separates a legitimate login page from a credential-harvesting fake.
Putting the Glossary to Work
Knowing definitions is the first step; applying them in real time is what counts. Here's a practical frame for using this vocabulary:
- Pause before clicking. Hover over links to see the real destination URL. Mismatched domains are a telltale sign of spoofing.
- Verify through a separate channel. If a message claims to be from your bank, call the number on the back of your card — not any number provided in the message.
- Report what you see. The FTC's ReportFraud.ftc.gov and the FBI's IC3.gov both accept online scam reports. Your report helps investigators track emerging tactics.
No Single Term Covers Every Scam
Scam tactics overlap and evolve rapidly. A single attack may combine spoofing, social engineering, and credential harvesting at once. Treat this glossary as a foundation, not an exhaustive list. When in doubt about a communication, independently verify through an official channel before taking any action.
Staying informed also means keeping your devices and accounts in good shape. For practical steps on protecting your connection and data at home, explore our Internet & Connectivity hub.
