September 16, 2026 · Credit, Investment, Savings, Security

10 Warning Signs of Dangerous Email Scams

Man with close-cropped hair, beard and moustache wearing black glasses and medium blue short-sleeved polo shirt looking at computer monitor.

Email scams can look like ordinary messages from companies, government agencies, retailers, delivery services, financial institutions or even people you know. But behind a suspicious email may be a criminal who’s trying to steal your personal information, access your accounts, install malicious software or take your money.

One of the most common types of email scams is phishing. Phishing occurs when scammers send fake emails, text messages or social media messages designed to lure someone into clicking a harmful link, visiting a bogus website or downloading a dangerous attachment to a computer, tablet or cell phone.

If you click a phishing link or open a malicious file, you may accidentally give cybercriminals access to your device, personal information, financial accounts or money. But with a little caution—and knowing what warning signs to look for—you can reduce your chances of getting caught by an email scam.

Warning signs of a phishing email

A suspicious email may include one or more of the warning signs below.

1. It offers something that seems too good to be true. Be cautious if the email says you won a prize, qualified for an unbelievable discount or were selected for an offer you never requested. If you have not entered a contest, that “winner” email may be a scam. In many legitimate contests, a person generally must intentionally enter before they have the chance to win.

2. It comes from a company you do not recognize at all. Does the message appear to come from a store, service provider or financial company that you are aware of, but don’t have an account? If you rarely—or never—do business with the company, treat the message carefully.

3. It includes an unexpected attachment. Attachments can be dangerous even when they look harmless. A scam email may include a file that appears to be a document, spreadsheet, image or software program. Be especially cautious with files ending in .exe, which usually is an executable file that when clicked can become active and may try to infect and install on your device. Remember that many distinct types of attachments may have viruses, spyware or other malware.

4. It uses threatening or alarming language about you, your device or your accounts to panic you into taking immediate action. The message may say you must log in, verify information, fix a security problem or call a number to avoid legal or governmental penalties.

5. It has unusual grammar, spelling errors or poor-quality formatting. So, look for misspellings, awkward grammar, unusual sentence structure or wording that does not sound like it came from a professional company. Also examine the design. Is the logo blurry? Are the colors slightly wrong? Does the message look like a rushed imitation of a real company’s email? But—sophisticated scammers can also produce very polished messages, so even a professional-looking email can still be fraudulent.

6. It asks for personal or financial information. Be cautious if an email asks you to provide or confirm:

  • Social Security Number
  • Account number
  • ATM, debit or credit card number
  • Digital Banking credentials (log-in and/or password)
  • Personal Identification Number (PIN)
  • One-time passcode
  • Street address
  • Telephone number
  • Other sensitive information

7. Be cautious with abrupt or unusual requests, such as a job offer from a company where you never applied, an invoice you do not recognize, or a request to change payment information.

8. Carefully review the sender’s email address. Scammers may use slight misspellings or lookalike names to imitate a real company or have what look like personal email addresses that do not represent the company purportedly associated with the email. For example, a fake email address may look similar to a familiar brand name, but one or two letters may be changed. If an email claims to be from a major company but comes from a personal email address, that is a stern warning sign. Reputable companies generally do not use personal email accounts for official customer communications.

9. Check all the links before clicking on any of them. On a computer, you should be able to hover your cursor over a link to preview where it leads before clicking it. If a link does not match the company’s official website, do not click it.

10. Be careful with any email that claims to be from a government agency, threatens you and demands immediate payment, personal information or account access. Government-related scams often use fear and urgency. If you are unsure whether a message is legitimate, go directly to the agency’s official website or use a verified phone number instead of clicking links in the email.

Here are a few actions that may help protect you from fraudulent emails

Once you recognize that an email may be fake, the safest response is usually to avoid interacting with it.

  • Do not click any links in a suspected phishing email, including an “unsubscribe” link.
  • Do not reply to the email.
  • Do not open or download attachments.
  • Do not call phone numbers listed in the suspicious message.
  • Do not provide personal, financial or account information.
  • If you need to report the message, save basic details or screenshots first.
  • Report the message to your email service provider if that option is available.
  • Delete the email after you have determined it is fraudulent.
  • Block the sender from your email account.

Blocking a sender may not stop every future scam message, since criminals can use different email addresses. But it can help reduce unwanted messages and make your inbox safer and less cluttered.

What if you already clicked a link in a suspect email?

If you have clicked a suspicious link, opened an attachment or provided personal information— act quickly. Consider taking these steps:

  • Change the password for the affected account.
  • If you use the same password elsewhere, change it on those accounts too.
  • Run an antivirus or security scan on the device.
  • Monitor your financial accounts for unfamiliar activity.
  • Contact your financial institution if account information may have been exposed.

Where to report fraudulent email

Report suspected identity theft or fraud to the proper authorities:

  • The U.S. government agency the Federal Trade Commission (FTC) at 877-FTC-HELP, 1-877-ID-THEFT, or online at ReportFraud.ftc.gov.
  • Besides the FTC, internet-related crime may be reported to the U.S. Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3).
  • Identity theft can also be reported to state and local government authorities such as your local police department.
  • For some states, fraudulent activities are often reported to the state’s attorney general’s office.

The faster you respond to being harmed by a fraudster, the better chance you may have of limiting the damage you have experienced.

What if you think your Delta Community account was targeted?

If you believe one of your Delta Community accounts may have been compromised or targeted by a scammer, please contact us right away. Call the Delta Community Member Care Center at 800-544-3328 and provide as many details as you can, including:

  • Dates
  • Dollar amounts
  • Email addresses
  • Phone numbers
  • Text messages
  • Email messages
  • Names used by the suspected scammer

Please remember that Delta Community will never call, text or email you to ask for your checking, savings or investment account numbers, ATM card number, debit or credit card number, password, telephone access PIN or one-time passcode.

The Credit Union will also never ask members to send money electronically as a test or share one-time passcodes received by email or text.

If someone claiming to be from Delta Community asks for this kind of information, hang up or stop responding at once. Then call the Member Care Center directly at 800-544-3328.