Breaches & Passwords

How to Spot and Avoid Phishing After a Breach

By the RedactZero Team · August 21, 2026 · 8 min read

The short version

A breach does not just leak your data. It hands scammers the raw material for messages that sound like they really come from your bank, your carrier, or a shop you used last week. Phishing and spoofing was the most-reported crime to the FBI's Internet Crime Complaint Center in 2025, with 191,561 complaints. The defense is a habit, not a sharper eye: never act on a link inside a message. Open the app or type the address yourself, put two-factor authentication on your email first, and report what you get.

Why a breach makes phishing more dangerous

Before a breach, a scammer is guessing. After one, they know something true about you. A leaked record commonly pairs your email address with your real name, your phone number, and the name of the company you held the account with. That single detail is what turns a message you would have deleted into one you pause over.

This is the difference between spam and phishing that is aimed at you. Generic spam says "your package could not be delivered." A message built from breach data says your name, names the retailer you actually shop with, and references an order number format that looks right. Nothing about it needs to be sophisticated. It only needs to be specific enough that checking feels unnecessary.

If you have just learned your data was exposed, our guide on what to do right after a data breach covers the ordered checklist. This post covers the part that arrives afterwards and keeps arriving: the messages.

What phishing actually costs right now

The honest headline is that phishing reports have flattened while the money lost to them has climbed sharply. The FBI's IC3 logged 191,561 phishing and spoofing complaints in 2025, more than double the next most-reported category, extortion, at 89,129. But the loss figure is where the change shows.

YearPhishing / spoofing complaintsReported losses in that category
2023298,878$18,728,550
2024193,407$70,013,036
2025191,561$215,843,126

FBI Internet Crime Complaint Center, 2025 IC3 Annual Report, three-year complaint count and complaint loss comparison tables.

Reports fell by about a third from 2023 to 2025 while reported losses grew roughly elevenfold. Fewer people are reporting, and the ones who do are losing much more. Fewer, better-aimed messages is exactly the pattern you would expect when attackers have better data to work from.

That $215.8 million is also only what IC3 filed under phishing itself. Each complaint is categorized under a single crime type, so the money lost after a phish succeeds often surfaces elsewhere in the same report: tech and customer support fraud accounted for $2.13 billion in 2025, and business email compromise for $3.05 billion. Across all crime types, IC3 recorded 1,008,597 complaints and $20.877 billion in losses, a 26 percent rise in losses over 2024.

The lures to expect in the weeks after a breach

Breach-driven phishing tends to arrive in a predictable order, and it leans on urgency about the breach itself. The most expensive version is a fake alert. The FTC states plainly that some of the costliest impersonation scams start with a fake security alert, often from a bank, after which people are convinced to move money to "protect" it.

Watch for these in particular:

The FTC also reports that people lost $3.5 billion to imposter scams in 2025, with nearly one in three fraud reports falling into that category. Losses to business impersonators reached nearly $1 billion, with the highest reported losses going to bank impersonators.

Seven signs a message is a phish

No single sign is proof, but any one of them should stop you from clicking. The FTC's guidance is built around the same pattern: an unexpected message that tells a story designed to make you act quickly, from a company you recognise, with a link that does the acting for you.

  1. It arrived unexpectedly and concerns an account you did not just touch.
  2. It creates a deadline. Account on hold, delivery failing, refund expiring in 24 hours.
  3. It wants payment details updated via a link. As the FTC puts it, legitimate companies will not email or text you a link to update your payment information.
  4. The greeting is generic where a real one would use your name, or uses your name where that company never does.
  5. The reply address does not match the brand, even when the display name and logo do.
  6. It asks you to confirm information the company already has, like a Social Security number or full card number.
  7. It pushes you off-channel: call this number, reply with a code, install this app, move money to a "safe" account.

That last one is the reliable tell. Real organisations resolve problems inside their own systems. Scammers need you somewhere they control.

Why "it looks real" stopped being a defense

Spelling mistakes and clumsy grammar used to be the giveaway. They are not any more. IC3 received 22,364 complaints in 2025 that referenced artificial intelligence, with adjusted losses over $893 million, and its report notes that AI-enabled synthetic content is becoming increasingly difficult to detect and easier to make.

What that means for you is simple and slightly uncomfortable: appearance is no longer evidence. A well-written message, a clean logo, a working web page, and a confident voice on the phone can all be produced cheaply. IC3 specifically flags voice cloning used to request payments and to mimic a relative in distress.

So stop grading messages on how convincing they look. Grade them on how you verified them.

How to verify a message without touching the link

This is the one habit that does most of the work, and it costs about thirty seconds. Treat every message as unverified until you have reached the company through a route you chose yourself. The FTC's version of the test: if you do have an account with the sender, contact the company using a phone number or website you know is real, not the details in the message.

In practice:

If the alert exists in both places, it is real. If it only exists in the message, you just avoided a scam without having to judge whether the email looked convincing.

The defenses that hold even when you slip

Assume that eventually, tired and distracted, you will click something. The goal is to make that moment survivable rather than catastrophic. The FTC's four core protections are automatic security updates on your computer, automatic updates on your phone, multi-factor authentication on your accounts, and backups of your data.

Two additions matter most after a breach. First, unique passwords, which stop one leaked credential from opening every other account you own. Second, two-factor authentication on your email before anything else, because email is the reset route for everything else. Our password manager and 2FA guide walks through both.

Prefer an authenticator app or a hardware key over codes sent by text. Texted codes can be intercepted by a SIM-swap attack, and a convincing fake login page can simply ask you for the code as you type it. A freeze on your credit file is the other durable layer, since it blocks new accounts being opened in your name regardless of what a scammer learns about you.

What to do in the first hour if you clicked

Move in order, and start with the account that controls the others. Speed matters more than thoroughness here, because most of the damage from a stolen credential happens in the first hours while the scammer is still testing what it opens.

  1. Change the password on the affected account, then on your email if it shares that password.
  2. Sign out all other sessions from the account's security settings.
  3. Turn on two-factor authentication if it was not already on.
  4. Change the password anywhere you reused it. This is how credential stuffing spreads one leak across your accounts.
  5. Update your device and run your security software if you opened an attachment or downloaded anything.
  6. Call your bank directly if you entered card or account details.

If you handed over a Social Security number, bank account number, or card number, the FTC directs you to IdentityTheft.gov, which gives steps specific to the exact information that was exposed. It is free and it is the government's own tool.

Where to report a phishing message

Reporting takes under a minute and it is the input regulators and carriers actually use. The FTC gives three destinations, and you can use all three for the same message. None of them require an account and none of them ask you to identify yourself.

Then delete the message. Reporting is worth doing even when you spotted the scam instantly, because the aggregate data is what drives enforcement and carrier-level blocking.

Cut off the data that makes phishing personal

Everything above is defense. The offense is reducing how much fresh, accurate detail about you is sitting in public. Breach dumps age and go stale. Data-broker profiles do not, because people-search sites keep refreshing your address, phone number, relatives, and past addresses from public records.

That is the material that makes a scam call convincing. A caller who names your street, your previous city, and your sister is not guessing. Removing yourself from the major people-search sites raises the effort required to build that script. Every big broker has a free opt-out, and our step-by-step opt-out guides cover the process site by site.

It is also worth knowing what actually leaked, rather than assuming. Checking your address against the known-breach record tells you which accounts to prioritise, which is what our post on checking whether your email was in a breach explains.

Find out what a scammer would find

Run a free exposure scan to see which breaches list your email and which data brokers are likely publishing your details - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

Why did I start getting more scam messages after a data breach?

Because the breach gave scammers material to work with. A leaked record often pairs your email or phone number with your real name and the name of the company you had an account with. That lets a scammer send a message that names a service you actually use, which is far more convincing than generic spam.

How can I tell if a suspicious login alert is real?

Do not use the message to find out. Close it, open the company's app or type its web address yourself, and check the account activity or security page there. A real alert will still be waiting for you inside the account. The FTC notes that some of the costliest impersonation scams start with a fake security alert, often from a bank.

Is it dangerous to just open a phishing email?

Opening the message itself is low risk on a modern, updated mail app. The risk is in what you do next: clicking a link, opening an attachment, calling the phone number in the message, or replying with information. Read it, do not act on it, then report and delete it.

What should I do if I clicked a phishing link but did not type anything?

Do not panic, but do close the page without entering anything. Then update your device and browser, run a scan with your security software, and watch that account for unusual activity. The FTC advises updating your security software and running a scan if you think you clicked a link or opened an attachment that downloaded harmful software.

What if I already gave a phishing site my password?

Change that password immediately, starting with your email account, and change it anywhere else you reused it. Turn on two-factor authentication and sign out all other sessions. If you handed over a Social Security, bank account, or card number, the FTC directs you to IdentityTheft.gov for steps specific to what was exposed.

Does two-factor authentication stop phishing?

It stops the common version, where a stolen password alone is enough to get in. The FTC lists multi-factor authentication as one of four core protections against phishing. It is not absolute, because a convincing fake login page can ask for the code too, so an app or hardware key beats a texted code.

How do I report a phishing text or email?

The FTC says to forward a phishing email to the Anti-Phishing Working Group at reportphishing@apwg.org, forward a phishing text message to SPAM (7726), and report the attempt to the FTC at ReportFraud.ftc.gov. Reporting takes seconds and feeds the data that regulators use to act.

Can I stop phishing messages entirely?

No. Once your email address and phone number are circulating, you cannot recall them, and spam filters will never catch everything. What you can control is the amount of fresh personal detail available to make the next message convincing, and whether a single successful message can actually cost you anything.

Sources: FBI Internet Crime Complaint Center, 2025 IC3 Annual Report (complaint counts, loss figures, three-year comparison tables, and the section on AI used in cybercrime); Federal Trade Commission press release, June 15, 2026, "FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025"; FTC Consumer Advice, "How To Recognize and Avoid Phishing Scams" (warning signs, the four protections, and reporting destinations). More in breaches and passwords, or see what hackers actually do with leaked data.