Protect

How to Spot Phishing Scams

A perfect logo does not make a message real. You check the sender and the URL, not the artwork.

What Is a Phishing Scam?

Phishing means sending a fake email or SMS that impersonates a well-known company, bank, or delivery service to lure you to a fake website, then stealing your ID, password, or credit card number. The word is said to blend "fish" (fishing for victims) and "sophisticated" (because the fakes are polished). Like a fish taking bait, people are drawn to pages that look identical to the real thing. Teens are targeted because they use games, social media, and online shopping.

How a Typical Attack Unfolds

Real Phishing SMS vs. Genuine Notification — What's Different? Classic examples impersonating delivery, shopping, and banking services that teens often receive × Fake SMS (Phishing) +1 555-0143 2026/05/04 14:23 [Yamato Transport] We attempted to deliver your package but you were not home. ▶ http://kuronekoyama- to.duckdns.org/jp *Please confirm within 24 hours Red flags ▶ International number (+1 or +86) ▶ URL is NOT the real delivery company ▶ Unfamiliar domain like "duckdns.org" ▶ Urgent tone designed to panic you ○ Genuine Notification Kuroneko Members App 2026/05/04 14:23 Kuroneko Members Your delivery is scheduled for this afternoon. To change time or location, use the app. ▶ Check in the app (No link included — delivered via app push notification) Genuine traits ▶ Delivered through the official app ▶ SMS usually does not contain a URL ▶ Not urgent; offers multiple ways to verify ▶ Never asks for login credentials
Fig. 1: Phishing SMS vs. genuine notification. If you habitually open things through the official app, link-based scams are almost entirely preventable.

Watch out for one particularly sneaky trick: right after you enter your credentials the fake site displays "Login failed. Redirecting to the real site" — and bounces you to the real page. The victim thinks they just mistyped, and has no idea their ID and password were just stolen.

5 Checkpoints for Spotting Fakes

Spotting Phishing by URL (Services Commonly Targeted for Teen Accounts) Read the domain just before the final "/". Memorize the suspicious patterns and you'll catch them instantly. Service ○ Real URL (memorize these) × Common Phishing URLs Amazon Major e-commerce amazon.co.jp www.amazon.co.jp amazon-jp.com amaz0n.co.jp (0=zero) Apple ID iPhone / Mac shared appleid.apple.com id.apple.com apple-id.support appleid-jp.com LINE Popular with teens line.me Mainly via official app line-jp.net line-account.tk Yamato Transport Fake missed-delivery SMS kuronekoyamato.co.jp Use official app recommended kuroneko-yamato.duckdns.org yamato-jp.cn Banks / Cards SMBC, Rakuten, etc. smbc.co.jp / rakuten.co.jp Official with https:// smbc-card.security.com rakuten-cards.cn ▶ Common fake domain tricks · Append "-jp", "-account", "-security" with a hyphen · Change ".co.jp" to ".com", ".net", or ".cn" · Swap letters for lookalikes ("amaz0n", "amazom") · Use free subdomains (duckdns.org, .tk)
Fig. 2: Real vs. fake URL comparison. Memorizing the real domain lets you spot fakes in SMS and emails at a glance.

① Checking the URL is essential. Fakes use look-alike characters like replacing the letter "l" with the number "1." On a small phone screen the URL is easy to miss — build the habit of reading it to the end. ② Check the sender's email domain too. ③ "Within 24 hours" and "Account suspended" urgency is a classic phishing pattern. ④ Natural-sounding language does not mean an email is safe. ⑤ Never follow a link in an email — open your bookmarks or the official app directly instead.

Patterns That Target Teens Specifically

Teens are commonly targeted through: missed-delivery SMS notifications, game "account suspended" notices, and SNS "terms of service violation" messages. DM-based attacks like "check out this link," "vote for me," or "verify your account" are also common. Natural, well-written phishing messages have become more frequent, so "I can spot bad Japanese" is no longer a reliable defense.

When in doubt, pause before tapping any link. Open the official app yourself, show it to a family member or teacher, or search "[service name] phishing scam" — following those steps in order makes it much easier to avoid being scammed. The more urgently the message tries to rush you, the more important it is to slow down and not enter anything right away.

Common Pitfalls

Mistakes people make with phishing
  • Opening a link "just to check" if the login works. The moment you enter your ID, it can be stolen.
  • Believing an SMS that appears to come from a family member ("new number, please contact me here"). Verify through a separate channel.
  • Entering credit card details and then entering an SMS verification code. That sequence also defeats two-factor authentication.

How Does This Help Your Future?

As an adult, your work email will receive fraudulent messages disguised as invoices or contracts. One careless click can expose confidential company data or customers' personal information. The ability to recognize phishing is a skill that will be genuinely valued in any workplace.

What You Can Do Today

Today: point at the URL
  1. Pick one ordinary message
  2. Do not tap. Read the domain with a finger
  3. Agree to forward anything odd to a parent

Summary

Phishing is a scam that uses fake sites to steal IDs and card numbers. Check the URL, sender, urgency language, and how you opened the link — and never follow links inside emails; use the official app or bookmarks instead. Even messages in natural, fluent language can be scams, so judge by "how did I get here," not by how it looks.

Check When you doubt a fake mail, look at?