Phishing, Smishing and Vishing: Spot Them and What to Do If You Clicked
Independently fact-checked against primary sources (last audited October 3, 2026). · 36 primary sources cited on this page. How we verify our legal content

Phishing is a scam message that pretends to come from a company or agency you trust so you will hand over a password, account number, Social Security number or payment. It is called phishing when it arrives by email, smishing when it arrives by text message, and vishing when it arrives as a phone call or voicemail. The tell is almost always the same: an urgent problem (a suspicious login, an unpaid toll, a package that cannot be delivered) and a link, number or code request that lets you "fix" it.
If you already clicked or answered, what to do next depends on what you gave away. If you only clicked, the FTC's fix is a security scan. A password, a one-time code, a card number, bank login or Social Security number each has its own fix, and if a thief has already used your login or code to move money out of your account, federal rules treat that as an unauthorized transfer you can dispute with your bank. Call your bank or card issuer first, using the number on your card or statement, then work through the steps below.
Information last verified on October 2, 2026. This article has not been reviewed by a licensed lawyer.
Jurisdiction scope: This guide covers United States federal law and federal agency guidance on phishing, smishing and vishing: the federal criminal statutes on wire fraud, identity fraud and computer fraud, the FTC's Impersonation Rule, Regulation E's protections for unauthorized bank transfers, and the free federal credit-freeze right. It notes California's Anti-Phishing Act and anti-phishing statutes in Texas and Virginia. It does not survey every state's law, and it does not cover phishing aimed at businesses (such as business email compromise).
What is phishing, smishing and vishing?
All three are the same trick sent through a different channel. The scammer pretends to be someone you trust, such as your bank, a toll agency, the Postal Service, Amazon, the IRS or your boss, and pushes you to act before you think.
Phishing: The FTC describes it this way: "Scammers use email or text messages to try to steal your passwords, account numbers, or Social Security numbers. If they get that information, they could get access to your email, bank, or other accounts. Or they could sell your information to other scammers."
| Type | How it reaches you | What it usually wants |
|---|---|---|
| Phishing | You click a link to a fake login page, open an attachment, or "confirm" account details | |
| Smishing | Text message | You tap a link to pay a small fee (toll, redelivery) or log in, which hands over card details or a password |
| Vishing | Phone call or voicemail, sometimes with an AI-generated voice | You read out a verification code, give account details, or move money "to keep it safe" |
The Cybersecurity and Infrastructure Security Agency (CISA) defines smishing as "Phishing via text messages to get the victim to click on a link, download files and applications, or begin a conversation" and vishing as "Phishing via voice communication to entice the victim to engage in conversation and build trust." The FBI describes smishing as an attack using fake texts "to trick people into downloading malware, sharing sensitive information, or sending money to cybercriminals."
Vishing now includes cloned voices. In a May 15, 2025 public service announcement about a campaign impersonating senior US officials, the FBI's Internet Crime Complaint Center (IC3) warned that vishing "may incorporate AI-generated voices" and that criminals "are more frequently exploiting AI-generated audio to impersonate well-known, public figures or personal relations to increase the believability of their schemes." Our guide to AI voice scam calls covers that variant in detail.
How to spot a phishing email, text or call
The FTC lists the stories scammers tell most often. The message might say someone noticed suspicious activity or login attempts on your account, claim there's a problem with your account or payment information, ask you to confirm personal or financial details, include an invoice you don't recognize, or promise a government refund or a free coupon. None of those are real.
Three rules from federal agencies catch most of these messages:
- Real companies don't ask for payment details by link. The FTC says "legitimate companies won't email or text with a link to update your payment information," and "Legitimate companies won't ask for information about your account by text."
- Nobody legitimate asks for your verification code. The FTC says "Anyone who asks you for your account verification code is a scammer," and that no caller from your bank's fraud department "will ever ask for the verification code. That's always a scam."
- Nobody legitimate tells you to move money to protect it. In the FTC's words: "Someone who says you have to move your money to protect it is a scammer. Period."
Do not rely on spelling mistakes. CISA's consumer guidance says poor grammar used to be a common sign, "although in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling, so look out for the other signs."
When you are unsure, the FTC suggests one question: "Do I have an account with the company or know the person who contacted me?" If the answer is yes, contact the company using a phone number or website you know is real, not the link, number or reply option in the message. CISA adds that you should not click any link in a suspicious message, including an "unsubscribe" link.
The scam texts and calls people report most
The FTC's analysis of 2024 text-scam reports found that five scripts made up about half of all text-scam reports: fake package-delivery problems (the most reported), phony job offers, fake fraud alerts, unpaid tolls, and "wrong number" texts that start a conversation.

Toll text scams (E-ZPass, SunPass, FasTrak, Peach Pass)
The unpaid-toll text is a smishing script that the FBI has tracked since 2024. On April 12, 2024, the IC3 issued an alert titled "Smishing Scam Regarding Debt for Road Toll Services," reporting that since early March 2024 it had "received over 2,000 complaints reporting smishing texts representing road toll collection service from at least three states." The FBI quoted a typical message: "(State Toll Service Name): We've noticed an outstanding toll amount of $12.51 on your record. To avoid a late fee of $50.00, visit https://myturnpiketollservices.com to settle your balance."
The FBI explained that the link "is created to impersonate the state's toll service name, and phone numbers appear to change between states." Its advice: check your account on the toll service's legitimate website, call the toll service's real customer service number, and delete the text. If you clicked or entered information, the FBI says to "take efforts to secure your personal information and financial accounts" and "Dispute any unfamiliar charges."
The E-ZPass Group issued its own warning in an April 26, 2024 media advisory, stating that "The toll account information provided in these texts is neither valid nor accurate." It told customers to delete the texts without clicking, and said "Customers who have clicked the link and completed the form should immediately contact their financial institution and notify E-ZPass of any erroneous information posted to their accounts."
The wave did not stop. On March 12, 2025, the FBI's Atlanta field office reported that complaints about fake texts from Georgia's Peach Pass system had "jumped dramatically": 1,573 complaints in the first part of March 2025, compared with 1,720 over the 14 months from January 1, 2024 to February 28, 2025. In its April 2025 review of 2024 text scams, the FTC said these toll texts imitate programs "all over the country, from SunPass in Florida to FasTrak in San Francisco," and that "these scammers are really after credit card and even Social Security numbers."
USPS and package-delivery text scams
The FTC found that package-delivery messages, "usually from someone pretending to be from the U.S. Postal Service, were the most reported text scam" in 2024, and that "Many people reported paying a small 'redelivery fee' that turned out to be a trick to get their credit card or even Social Security number."
The U.S. Postal Inspection Service (USPIS) is direct about how real USPS texts work: "USPS will not send customers text messages or e-mails without a customer first requesting the service with a tracking number, and it will NOT contain a link." If you already interacted with the link, USPIS says to notify your financial institution "even if you did not click 'submit'."
Fake bank fraud alerts and verification-code calls
This is the script that drains bank accounts. The FTC describes texts that "often look like they're from a bank or Amazon" and either give a number to call or ask you to reply YES or NO to verify a large transaction. "People who reply are connected to the (fake) fraud department," the FTC says, and the scammers then "pressure people into moving money out of their accounts to supposedly keep it safe, but it really goes to the scammers."
A related version asks for the one-time code your bank just texted you. The FTC warns: "If you give them the code, they can log into your account and transfer all the money out of your savings or investment accounts." If you get a call like this, hang up and call your real bank using "the number you find on your statement," as the FTC puts it, "never the number the caller gave you."
IRS and government look-alikes
The IRS says "We don't send text messages without your permission." Messages claiming to be from a government agency are also covered by the FTC rule against government impersonation, discussed below. For tax-related identity theft after a phishing attack, see our guide to tax identity theft.
I clicked on a phishing link: what to do now, by what you gave away
Work out what actually left your hands, then use the matching fix. If more than one applies, do all of them, starting with anything that touches money.
| What you did or gave | First move | Free follow-up |
|---|---|---|
| Clicked only, entered nothing | Close the page; update and run your security software | Watch your accounts |
| Entered a password | Change it, and everywhere you reused it | Turn on two-factor authentication |
| Gave a one-time verification code | Call your bank or the account's company using a number you know is real | Change the password; check for transfers |
| Gave a credit card number | Call the issuer using the number on the back of the card | Review the statement; dispute charges in writing |
| Gave a debit card number or bank login | Call your bank's fraud line using the number on your card or statement | Report any transfer as unauthorized |
| Gave your Social Security number | Go to IdentityTheft.gov | Free credit freeze at all three bureaus |
| Installed an app or allowed remote access | Disconnect, update security software, run a scan | Change passwords from a clean device; call your bank |
You clicked the link but didn't enter anything
The FTC's advice if you think you clicked a link or opened an attachment that downloaded harmful software: "update your computer's security software. Then run a scan and remove anything it identifies as a problem." Keep an eye on your accounts afterward. If the link was a fake USPS page, remember the Postal Inspection Service's warning that interacting with the page can matter even if you never pressed submit, so tell your bank if you typed anything at all.
You entered a password
The FTC says that if you gave a scammer the username and password to one of your accounts and you can still log in, "Create a new, strong password for the account that was compromised. (If you use the same password on another account, change it there, too.)" Then turn on two-factor authentication. The FTC explains that multi-factor authentication "makes it harder for scammers to log in to your accounts if they do get your username and password."
If the scammer has already changed your password and locked you out, use the account provider's official recovery process (the FTC's guide "How To Get Back Into Your Hacked Account" links to recovery pages for popular services).
You gave a one-time code (verification code)
A one-time code lets the scammer finish logging in as you. Call the company the code came from right away, using the number on your card, statement or the company's real website, and tell them the code was stolen. Change the account password and turn on stronger authentication. Then check the account for transfers, new payees and changed contact details.
If the code was for your bank and money has already moved, that matters legally: the CFPB treats a transfer made by a fake bank representative who tricked you into giving a "texted account confirmation code" as an unauthorized transfer (see the section below on money taken from your bank account).
You gave a credit card number
The FTC says to report it "to the credit card issuer immediately. Use the number on the back of your card or log in to your account online or through their app," and ask for a refund.
Federal credit card rules are strong here. Under Regulation Z, your liability for unauthorized use of a credit card "shall not exceed the lesser of $50 or the amount" obtained before you notify the issuer (12 C.F.R. § 1026.12(b)(1)(ii)), and the official commentary says unauthorized use includes a transaction initiated by someone who obtained the card "through fraud or robbery." To use the billing-error dispute process, your written notice must reach the issuer within 60 days after it sent the first statement showing the charge (12 C.F.R. § 1026.13(b)). Our guide to getting money back after a scam walks through both.
You gave a debit card number or your bank login
Call your bank or credit union's fraud line now, using the number on your card or statement, and tell them the card number or login was stolen in a scam. Ask them to block the card, reset your online banking credentials and check for transfers. The FTC says "Federal law protects you from unauthorized use of your debit card." If money has already left, report each transfer as unauthorized (next section).
You gave your Social Security number
The FTC's steps depend on whether the number has been used:
- If the scammer used it: "Go to IdentityTheft.gov to report it. Get a customized recovery plan based on your situation."
- If the scammer didn't use it or you aren't sure: "Go to IdentityTheft.gov/databreach" and follow the steps to protect yourself.
Then freeze your credit. A credit freeze stops new accounts from being opened in your name, and federal law makes it free: under 15 U.S.C. § 1681c-1(i), each credit bureau "shall, free of charge, place the security freeze" within 1 business day of a phone or online request (3 business days by mail). The FTC says "There's no cost to place or lift a credit freeze, and it doesn't affect your credit score," that "A credit freeze lasts until you lift it," and that you must contact all three bureaus: Equifax, Experian and TransUnion. A one-year initial fraud alert is a lighter option; you contact one bureau and it "must tell the other two." Our guide to credit freezes vs. fraud alerts compares them, and our guide on how to report identity theft covers the IdentityTheft.gov report. Spanish speakers can report at RobodeIdentidad.gov.
You installed something or let someone into your computer
If the message or caller got you to install an app or allow remote access, the FTC says to update your security software, "Run a scan and delete anything it identifies as a problem," and "Change your passwords and turn on two-factor authentication to protect your accounts." If you logged into your bank while the scammer was connected, call the bank: the CFPB lists a third party "using phishing or other methods to gain access to a consumer's computer and observe the consumer entering account login information" as a situation that produces unauthorized transfers. Our guide to tech support and fake invoice scams covers remote-access scams in depth.
Did the scam take money from your bank account?
It depends on who pressed send. If the thief moved the money using your login, card number or code, federal rules treat it as an unauthorized transfer, and your bank has to investigate. If you moved the money yourself because the scammer convinced you to, those protections are written for a different situation.

Regulation E, the federal rule for debit cards, ATM, online and app transfers out of consumer bank accounts, defines the term this way:
"'Unauthorized electronic fund transfer' means an electronic fund transfer from a consumer's account initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit." (12 C.F.R. § 1005.2(m))
The Consumer Financial Protection Bureau has answered the phishing question directly in its official Regulation E FAQ. When "a consumer is fraudulently induced into sharing account access information with a third party, and a third party uses that information to make an EFT from the consumer's account, the transfer is an unauthorized EFT under Regulation E." The CFPB gives two examples:
"(1) a third-party calling the consumer and pretending to be a representative from the consumer's financial institution and then tricking the consumer into providing their account login information, texted account confirmation code, debit card number, or other information that could be used to initiate an EFT out of the consumer's account, and (2) a third party using phishing or other methods to gain access to a consumer's computer and observe the consumer entering account login information."
Two more points from the same FAQ help phishing victims. Your bank cannot raise your liability because you were careless: Regulation E's commentary "expressly states that negligence by the consumer cannot be used as the basis for imposing greater liability than is permissible under Regulation E." And for payment-network transfers such as person-to-person payments, private network rules that call a transfer "final and irrevocable" do "not reduce consumer protections against liability for unauthorized EFTs." Our guide to Zelle and payment app scams covers those apps.
The clock: report fast
Speed protects you in two ways: the bank may be able to stop the money, and Regulation E's limits on your liability depend on when you report.
- Within two business days of learning that your card, code or other access device was lost or stolen, your liability is capped at "the lesser of $50 or the amount of unauthorized transfers that occur before notice" (12 C.F.R. § 1005.6(b)(1)). Later notice can raise the cap to $500 (§ 1005.6(b)(2)). These two tiers are written for a lost or stolen access device, and neither the regulation nor the CFPB's FAQ says whether a code or login you were tricked into sharing starts that two-day clock, so report within two business days of discovering the scam to be safe. If a transfer was made without an access device at all, the $50 and $500 tiers do not apply and only the 60-day rule below does (Official Interpretation, comment 6(b)(3)-2).
- Within 60 days after the bank sends the statement that first shows the unauthorized transfer, you must report it "to avoid liability for subsequent transfers" (§ 1005.6(b)(3)), and the bank's formal error-resolution duties apply to a notice received within that window (§ 1005.11(b)(1)(i)). The bank must extend these times to a reasonable period if your delay was due to "extenuating circumstances" (§ 1005.6(b)(4)).
- You can report by phone. The bank may ask for written confirmation within 10 business days of your call (§ 1005.11(b)(2)), and it must tell you so when you call.
Once you report, the bank generally has 10 business days to decide whether an error occurred. It may take up to 45 days (90 days for some transfers, such as point-of-sale debit card transactions) only if it provisionally credits your account within 10 business days (12 C.F.R. § 1005.11(c)). The full timeline, and what to do if the bank says no, is in our guide to getting money back after a scam.
If you sent the money yourself
In the fake-fraud-alert script the FTC describes, the scammer does not touch your account at all. A fake bank employee pressures you into moving the money yourself, supposedly to keep it safe. The Regulation E definition covers transfers "initiated by a person other than the consumer," so a payment you initiated yourself generally falls outside that definition as written, and banks and payment apps often treat such payments as authorized. The FTC is blunt: "If you are scammed into moving your money out of your account, you won't be protected. And you probably won't get that money back."
That does not mean you should not try. The FTC still tells people who paid a scammer by Zelle or bank transfer to "Report it to your bank or credit union immediately" and "Ask them to reverse the payment and refund your money." Any refund in that situation usually depends on the bank's or app's own policy rather than a legal requirement.
Where to report phishing, smishing and vishing
Reporting will not usually get your money back, but it helps carriers block numbers and helps law enforcement build cases. Report to your bank first if money or account access is involved, then to the channels that match the message.
| What you received | Where to report it |
|---|---|
| Scam text message | Forward it to 7726 (SPAM). The FTC says this "helps your wireless provider spot and block similar messages in the future." You can also use your messaging app's report-junk option. |
| Phishing email | Forward it to the Anti-Phishing Working Group at reportphishing@apwg.org |
| Any phishing, smishing or vishing attempt | The FTC at ReportFraud.ftc.gov (also available in Spanish) |
| Toll smishing texts | The FBI's IC3 at ic3.gov, including "The phone number from where the text originated" and "The website listed within the text" |
| Fake USPS texts | spam@uspis.gov, and forward the text to 7726 |
| Fake IRS or Treasury texts | phishing@irs.gov with the subject line "Text," including the sender's phone number and message, your phone number, and the date, time and time zone received, then delete the text |
| Fake IRS or Treasury emails | phishing@irs.gov, following the IRS's reporting instructions for email |
| Stolen identity | IdentityTheft.gov (RobodeIdentidad.gov in Spanish) |
For a fuller list by type of scam, see where to report a scam.
Is phishing illegal? The federal and state laws
Yes. Federal prosecutors reach phishing through several general criminal statutes, each covering a different stage of the scheme, and an FTC rule targets the impersonation itself. These are laws the government enforces. Reporting is how a victim sets them in motion.
Federal criminal law
- Wire fraud, 18 U.S.C. § 1343. The statute reaches anyone who, having devised a "scheme or artifice to defraud," transmits a wire, radio or television communication in interstate or foreign commerce "for the purpose of executing" it. A phishing email, text or call sent as part of such a scheme fits that description. The maximum is 20 years in prison; when the violation affects a financial institution, it rises to a fine of up to $1,000,000, up to 30 years in prison, or both.
- Identity fraud, 18 U.S.C. § 1028(a)(7). It is a federal crime to knowingly transfer, possess or use, "without lawful authority, a means of identification of another person" in connection with a federal crime or a state felony. That covers what phishers do with stolen Social Security numbers and account details.
- Aggravated identity theft, 18 U.S.C. § 1028A. Using another person's means of identification during certain listed felonies, which include wire fraud, adds a mandatory 2-year prison term "in addition to the punishment provided for such felony."
- Computer fraud, 18 U.S.C. § 1030(a)(4). Logging into your account with stolen credentials is a separate crime: knowingly and with intent to defraud accessing "a protected computer without authorization" to further the fraud and obtain anything of value.
The FTC Impersonation Rule
Since April 1, 2024, the FTC's Impersonation Rule (16 C.F.R. Part 461) makes it an unfair or deceptive practice to "materially and falsely pose as, directly or by implication," a government entity or officer (§ 461.2) or a business or business officer (§ 461.3). "Materially" means likely to affect a person's choice of, or conduct regarding, goods or services. A message falsely posing as a bank, toll agency, the Postal Service or the IRS is the kind of conduct the rule describes. The FTC enforces the rule, so a report to ReportFraud.ftc.gov is how a victim puts it to work.
CAN-SPAM and email headers
The federal CAN-SPAM Act makes it unlawful to send a commercial email that "contains, or is accompanied by, header information that is materially false or materially misleading" (15 U.S.C. § 7704(a)(1)). The Act defines an electronic mail message by reference to a mailbox and an Internet domain, so it is aimed at email rather than text messages. Robotext rules for phones are covered in our TCPA guide.
State anti-phishing laws
Some states have their own anti-phishing statutes. Three examples:
- California. The Anti-Phishing Act of 2005 (Cal. Bus. & Prof. Code §§ 22948 to 22948.3, effective January 1, 2006) makes it unlawful to use a web page, email or the Internet to induce someone to provide identifying information "by representing itself to be a business without the authority or approval of the business" (§ 22948.2). Identifying information includes a Social Security number, bank account number, card number, PIN and account password. California lets the victim sue: "An individual who is adversely affected" may sue the person who directly committed the violation for an injunction and "the greater of three times the amount of actual damages or five thousand dollars ($5,000) per violation" (§ 22948.3(a)(2)), and the court may award a prevailing plaintiff costs and reasonable attorney's fees. Adversely affected Internet access providers and web page or trademark owners can recover the greater of actual damages or $500,000 (for their suits, multiple violations arising from a single action or conduct count as one violation), and the Attorney General or a district attorney can seek civil penalties of up to $2,500 per violation.
- Texas. A 2005 law (House Bill 1098) created the Texas Anti-Phishing Act, originally enacted as Business and Commerce Code chapter 48 (we could not confirm its current chapter number on the official Texas statutes site), covering fake web pages and email fraud. As enacted, it let internet access providers, adversely affected web page or trademark owners, and the attorney general sue, not individual victims. We have not verified later amendments to the current text.
- Virginia. Va. Code § 18.2-152.5:1 makes it a Class 6 felony to use a computer to obtain identifying information "through the use of material artifice, trickery or deception," and a Class 5 felony to sell or distribute that information.
A lawsuit is only useful against someone you can identify, and a phishing victim often cannot identify the sender. For most victims, the bank or card dispute process described above is the practical route to getting money back.
Do phone carriers have to block scam texts?
Partly. Since May 11, 2023, an FCC rule (FCC 23-21) requires mobile wireless providers "to block--at the network level--texts purporting to be from North American Numbering Plan (NANP) numbers on a reasonable Do-Not-Originate (DNO) list," which covers invalid, unallocated or unused numbers and numbers whose owners say they never send texts. A scam text from a valid-looking number is not covered by that mandatory block, which is one reason forwarding scam texts to 7726 still matters.
How big is the problem?
- Text scams: "In 2024, people reported $470 million in losses to these scams, more than five times the 2020 number," according to the FTC's April 2025 data review. The FTC adds that because most frauds are never reported, the figure "likely reflects only a fraction of the actual harm." The share of text-scam reports involving a money loss rose from 5% in 2020 to 11% in 2024.
- How scammers reached people in 2025: Ranked by fraud reports with a loss, the FTC's April 2026 data showed website or app (31%), social media (28%), phone call (11%), email (10%) and text (7%). The FTC notes it did not collect reports during the 2025 government shutdown.
- FBI complaints: The IC3's 2024 annual report listed phishing and spoofing as the most-reported crime type, with 193,407 complaints and $70,013,036 in reported losses. Its 2025 report put phishing and spoofing losses at $215,843,126.
These counts are self-reported complaints, and the FTC and FBI figures come from different datasets, so they should not be added together.
Related guides
- Scams and fraud laws: the complete guide
- How to get your money back after a scam
- Where to report a scam
- Zelle and payment app scams
- Tech support and fake invoice scams
- Identity theft laws
- Phone scams targeting Spanish speakers
- How to Tell if Something Is a Scam
Last updated: October 2, 2026.
Disclaimer: This article provides general legal information about United States federal law and the state laws named above, verified as of October 2, 2026. It is not legal advice. For your specific situation, contact your bank, card issuer or payment company, the agency named above, or a lawyer licensed in your state.
Frequently Asked Questions
What is the difference between phishing, smishing and vishing?
They are the same scam through different channels: phishing usually means email, smishing means text messages, and vishing means phone calls or voicemail. CISA defines smishing as phishing via text messages and vishing as phishing via voice communication.
I clicked on a phishing link but didn't enter anything. Am I okay?
The FTC says to update your security software, run a scan and remove anything it flags. If it was a fake USPS page, the Postal Inspection Service says to tell your bank if you interacted with it even without pressing submit.
What should I do if I entered my password on a phishing site?
Change the password right away, change it anywhere else you used it, and turn on two-factor authentication, as the FTC advises. If you are locked out, use the provider's official account-recovery process.
Is the toll text I got a scam?
Very likely. The FBI warned on April 12, 2024 about texts claiming unpaid tolls with links that impersonate state toll services, and E-ZPass said the account information in those texts is neither valid nor accurate. Check your balance on the toll agency's real website instead of tapping the link.
Does USPS send texts about package delivery?
Only if you asked. The Postal Inspection Service says USPS will not text or email you without your first requesting it with a tracking number, and the message will not contain a link. Report fake ones to spam@uspis.gov and forward them to 7726.
Will my bank refund money a scammer took after I gave them a code?
If the scammer used the code or login to make the transfer, the CFPB says it is an unauthorized transfer under Regulation E, so the bank must investigate and limit your liability. Report it quickly and within 60 days after the statement that first shows it.
What if a fake bank employee talked me into sending the money myself?
Regulation E's definition covers transfers initiated by someone other than you, so a payment you sent yourself is generally treated as authorized, and the FTC warns you probably won't get it back. Still report it to your bank immediately and ask them to reverse it.
Where do I forward a phishing email or text?
Forward scam texts to 7726 (SPAM) and phishing emails to reportphishing@apwg.org, then report to the FTC at ReportFraud.ftc.gov. Fake IRS messages go to phishing@irs.gov.
Is phishing a crime?
Yes. Federal prosecutors can charge it as wire fraud under 18 U.S.C. 1343 (up to 20 years), identity fraud under 18 U.S.C. 1028, aggravated identity theft under 1028A, and computer fraud under 18 U.S.C. 1030. The FTC's Impersonation Rule also bans posing as a government agency or business.
Can I sue a phisher?
California's Anti-Phishing Act lets an adversely affected individual sue the person who directly violated it for three times actual damages or $5,000 per violation, whichever is greater. A lawsuit needs an identifiable defendant, so for most victims the bank or card dispute process is the practical route.
Updates
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
United States Code Title 18
§ 1343Fraud by wire, radio, or televisionIn forcecited in 18 of our articles
Whoever, having devised or intending to devise any scheme or artifice to defraud, or for obtaining money or property by means of false or fraudulent pretenses, representations, or promises, transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme or artifice, shall be fined under this title or imprisoned not more than 20 years, or both. If the violation occurs in relation to, or involving any benefit authorized, transported, transmitted, transferred, disbursed, or paid in connection with, a presidentially declared major disaster or emergency (as those terms are defined in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5122)), or affects a financial institution, such person shall be fined not more than $1,000,000 or imprisoned not more than 30 years, or both.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 7,198 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts read § 1343 as requiring a scheme to defraud plus use of interstate wires to further it. In United States v. Allen (2007), the Fourth Circuit affirmed wire fraud convictions and said intent to repay eventually is irrelevant; in United States v. Barrington (2011), lost tuition from hacked grade changes counted as money or property.
Opinions citing this section in our collection:
- Morrison v. National Australia Bank Ltd. (Supreme Court of the United States 2010, 561 U.S. 247)“…11 In that case we concluded that the wire-fraud statute, 18 U. S. C. § 1343 (2000 ed., Supp. II), was violated by…”
- Rubin v. United States (Supreme Court of the United States 1981, 449 U.S. 424)“…k loan application), 18 U. S. C. §1341 (mail fraud), and 18 U. S. C. § 1343 (wire fraud), as well as § 17 (a) (sec…”
- Bacchus Industries, Inc. v. Arvin Industries, Inc. (Court of Appeals for the Tenth Circuit 1991, 939 F.2d 887)“…to include mail fraud ( 18 U.S.C. § 1341 ) and wire fraud ( 18 U.S.C. § 1343 ). 18 U.S.C. § 1961 (1). These acts of…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Where to Report a Scam: Which Agency, and Can You Get Money Back?, Tech Support Scams and Fake Invoices: Geek Squad, McAfee, PayPal, I Got Scammed: What to Do, How to Get Money Back, Where to Report
§ 1028Fraud and related activity in connection with identification documents, authentication features, and informationIn forcecited in 22 of our articles
Whoever, in a circumstance described in subsection (c) of this section— knowingly and without lawful authority produces an identification document, authentication feature, or a false identification document; knowingly transfers an identification document, authentication feature, or a false identification document knowing that such document or feature was stolen or produced without lawful authority; knowingly possesses with intent to use unlawfully or transfer unlawfully five or more identification documents (other than those issued lawfully for the use of the possessor), authentication features, or false identification documents; knowingly possesses an identification document (other than one issued lawfully for the use of the possessor), authentication feature, or a false identification document, with the intent such document or feature be used to defraud the United States; knowingly produces, transfers, or possesses a document-making implement or authentication feature with the intent such document-making implement or authentication feature will be used in the production of a false identification document or another document-making implement or authentication feature which will…
Official text (excerpt) · last checked 2026-09-16 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 1,360 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):United States v. Christensen (2016) affirmed Section 1028(a)(7) identity-theft convictions after the CFAA predicates were set aside, holding intent to violate California Penal Code 502 was a valid alternative predicate. United States v. Campa (2008) upheld a 1028(a)(3) conviction on constructive possession of counterfeit documents.
Opinions citing this section in our collection:
- Flores-Figueroa v. United States (Supreme Court of the United States 2009, 556 U.S. 646)“…tion documents, authentica tion features, and information.” 18 U. S. C. §1028. The title of another provision (the pro…”
- United States v. George Lloyd Pregent (Court of Appeals for the Fourth Circuit 1999, 190 F.3d 279)“…zed United States identification documents in violation of 18 U.S.C.A. § 1028 (a)(1) (West Supp.1999), knowingly prod…”
- United States v. Lesmarge Valnor (Court of Appeals for the Eleventh Circuit 2006, 451 F.3d 744)✓Valnor charged $400 to $500 a head to have a Florida DMV examiner issue fraudulent driver's licenses; the Eleventh Circuit affirmed a sentence above the advisory range for his Section 1028(f) conspiracy, noting it fell far below Section 1028(b)(1)(A)'s 15-year maximum.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Identity Theft Laws: Federal Rules and State Penalties, Indiana Identity Theft Laws, Alabama Identity Theft Laws: Statute, Reporting, and Your Rights
§ 1028AAggravated identity theftIn forcecited in 4 of our articles
Whoever, during and in relation to any felony violation enumerated in subsection (c), knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person shall, in addition to the punishment provided for such felony, be sentenced to a term of imprisonment of 2 years. Whoever, during and in relation to any felony violation enumerated in section 2332b(g)(5)(B), knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person or a false identification document shall, in addition to the punishment provided for such felony, be sentenced to a term of imprisonment of 5 years.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 1,768 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Flores-Figueroa v. United States (Supreme Court of the United States 2009, 556 U.S. 646)“…ul authority, a means of identification of another person.” 18 U. S. C. §1028A(a)(1) (emphasis added). After petitione…”
- United States v. Barrington (Court of Appeals for the Eleventh Circuit 2011, 648 F.3d 1178)“…d three counts of aggravated identity theft in violation of 18 U.S.C. §§ 1028A and 2. Jacquette and Secrease pleaded g…”
- United States v. Junaidu Savage (Court of Appeals for the Fourth Circuit 2018, 885 F.3d 212)“…Count One), and aggravated identity theft, in violation of 18 U.S.C. § 1028A (Counts Two and Three). In March 2016,…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Are AI Voice Scam Calls Illegal? Federal and State Law (2026), Deepfake Fraud and Impersonation Laws: Federal and State (2026)
§ 1030Fraud and related activity in connection with computersIn forcecited in 4 of our articles
Whoever— having knowingly accessed a computer without authorization or exceeding authorized access, and by means of such conduct having obtained information that has been determined by the United States Government pursuant to an Executive order or statute to require protection against unauthorized disclosure for reasons of national defense or foreign relations, or any restricted data, as defined in paragraph y. of section 11 of the Atomic Energy Act of 1954, with reason to believe that such information so obtained could be used to the injury of the United States, or to the advantage of any foreign nation willfully communicates, delivers, transmits, or causes to be communicated, delivered, or transmitted, or attempts to communicate, deliver, transmit or cause to be communicated, delivered, or transmitted the same to any person not entitled to receive it, or willfully retains the same and fails to deliver it to the officer or employee of the United States entitled to receive it; intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains— information contained in a financial record of a financial institution, or of a card issuer as…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 1,820 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Leon Modrowski v. John Pigatto (Court of Appeals for the Seventh Circuit 2013, 712 F.3d 1166)“…t (18 U.S.C. § 2511), and the Computer Fraud and Abuse Act (18 U.S.C. § 1030). His complaint also asserts a handful…”
- register.com, Inc. v. Verio, Inc. (Court of Appeals for the Second Circuit 2004, 356 F.3d 393)“…rization, a violation of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030 ; and, (c) trespassing on Register’s ch…”
- United States v. Barrington (Court of Appeals for the Eleventh Circuit 2011, 648 F.3d 1178)“…and 1349; fraud using a protected computer in violation of 18 U.S.C. §§1030(a)(4) and (c)(3)(A) and 2; and three c…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Missouri Voyeurism Laws: Hidden Cameras, Penalties, and Privacy Protections, Wisconsin Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Code of Federal Regulations Title 12
§ 1005.2Definitions.In forcecited in 9 of our articles
Except as otherwise provided in subpart B, for purposes of this part, the following definitions apply: (a)(1) “Access device” means a card, code, or other means of access to a consumer's account, or any combination thereof, that may be used by the consumer to initiate electronic fund transfers. (2) An access device becomes an “accepted access device” when the consumer: (i) Requests and receives, or signs, or uses (or authorizes another to use) the access device to transfer money between accounts or to obtain money, property, or services; (ii) Requests validation of an access device issued on an unsolicited basis; or (iii) Receives an access device in renewal of, or in substitution for, an accepted access device from either the financial institution that initially issued the device or a successor. (b)(1) “Account” means a demand deposit (checking), savings, or other consumer asset account (other than an occasional or incidental credit balance in a credit plan) held directly or indirectly by a financial institution and established primarily for personal, family, or household purposes.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 25 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts apply the § 1005.2 definitions to decide whether an account falls under the EFTA. In Yagoub Mohamed v. Bank of America (2024), the Fourth Circuit held pandemic benefits on a bank-issued prepaid card sat in a government benefit account; Brown v. Stored Value Cards (2020) found 'account' plausibly reached a jail release card.
Opinions citing this section in our collection:
- Danica Brown v. Stored Value Cards, Inc. (Court of Appeals for the Ninth Circuit 2020, 953 F.3d 567)“…ndants note that the regulation implementing section 1693i, 12 C.F.R. § 1005.2, was amended recently to state that “[t…”
- Yagoub Mohamed v. Bank of America, N.A. (Court of Appeals for the Fourth Circuit 2024, 93 F.4th 205)“…tions” further defining “account” are published at 12 C.F.R. § 1005.2(b)(1). Those provisions are contained i…”
- Warner v. Tinder Inc. (District Court, C.D. California 2015, 105 F. Supp. 3d 1083)“…d in advance to recur at substantially regular intervals.” 12 C.F.R. § 1005.2 (k). “Written authorization” from the c…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to Get Money Back After a Scam: Your Rights by Payment Method, Zelle, Venmo, Cash App and PayPal Scams: Can You Get Money Back?, A Scammer Has My Information: What They Can Do and How to Fix It
§ 1005.6Liability of consumer for unauthorized transfers.In forcecited in 6 of our articles
(a) Conditions for liability. A consumer may be held liable, within the limitations described in paragraph (b) of this section, for an unauthorized electronic fund transfer involving the consumer's account only if the financial institution has provided the disclosures required by § 1005.7(b)(1), (2), and (3). If the unauthorized transfer involved an access device, it must be an accepted access device and the financial institution must have provided a means to identify the consumer to whom it was issued. (b) Limitations on amount of liability. A consumer's liability for an unauthorized electronic fund transfer or a series of related unauthorized transfers shall be determined as follows: (1) Timely notice given. If the consumer notifies the financial institution within two business days after learning of the loss or theft of the access device, the consumer's liability shall not exceed the lesser of $50 or the amount of unauthorized transfers that occur before notice to the financial institution. (2) Timely notice not given.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 7 court opinions in our collectionLatest citing opinion in our collection: 2024
In the courts (editorial summary, independently checked):In Widjaja v. JPMorgan Chase Bank (2021), the Ninth Circuit applied the 60-day rule reflected in § 1005.6(b)(3): late reporters owe later transfers only if the bank shows the delay caused them, but a suing consumer must plead facts they would have occurred anyway. Trang v. JPMorgan Chase Bank (2023) dismissed such claims on that basis.
Opinions citing this section in our collection:
- Margaretha Widjaja v. Jpmorgan Chase Bank, N.A. (Court of Appeals for the Ninth Circuit 2021, 21 F.4th 579)“…A ordinarily requires. See 15 U.S.C. §§ 1693f(a), 1693g(a); 12 C.F.R. § 1005.6(b)(3). 1 In June 2019, Widjaja fil…”
- Nelipa v. TD Bank, N.A. (District Court, E.D. New York 2024)“…ed electronic fund transfer[s].” 15 U.S.C. § 1693f(f)(1); 12 C.F.R. § 1005.6. The term “unauthorized electronic fund…”
- Trang v. JPMorgan Chase Bank, N.A. (District Court, D. Oregon 2023)“…rs occurring outside the 60-day period.” Id. at 583 (citing 12 C.F.R. § 1005.6(b)(3); 12 C.F.R. pt. 1005, Supp. I, 6(b…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Bank Refused Your Scam Refund? How to Challenge a Fraud Claim Denial
§ 1005.11Procedures for resolving errors.In forcecited in 9 of our articles
(a) Definition of error —(1) Types of transfers or inquiries covered. The term “error” means: (i) An unauthorized electronic fund transfer; (ii) An incorrect electronic fund transfer to or from the consumer's account; (iii) The omission of an electronic fund transfer from a periodic statement; (iv) A computational or bookkeeping error made by the financial institution relating to an electronic fund transfer; (v) The consumer's receipt of an incorrect amount of money from an electronic terminal; (vi) An electronic fund transfer not identified in accordance with § 1005.9 or § 1005.10(a); or (vii) The consumer's request for documentation required by § 1005.9 or § 1005.10(a) or for additional information or clarification concerning an electronic fund transfer, including a request the consumer makes to determine whether an error exists under paragraphs (a)(1)(i) through (vi) of this section. (2) Types of inquiries not covered. The term “error” does not include: (i) A routine inquiry about the consumer's account balance; (ii) A request for information for tax or other recordkeeping purposes; or (iii) A request for duplicate copies of documentation.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 23 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Machinski (District Court, D. Utah 2026)“…entified by the financial institution or the consumer. See 12 C.F.R. § 1005.11. Regulation E provides a closed list of…”
- Sundahl (District Court, S.D. California 2026)“…notice requirements.” Id.; see 15 U.S.C. 20 § 1693f(a); 12 C.F.R. § 1005.11(b).…”
- Hubbard v. Chime Financial, Inc. (District Court, S.D. Ohio 2025)“…had failed to allege “which investigatory obligation under 12 C.F.R. § 1005.11(c) Huntington violated.” Lumbus, 2025 W…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Can I Sue a Scammer? When a Lawyer Actually Helps After a Scam
§ 1026.12Special credit card provisions.In forcecited in 6 of our articles
(a) Issuance of credit cards. Regardless of the purpose for which a credit card is to be used, including business, commercial, or agricultural use, no credit card shall be issued to any person except: (1) In response to an oral or written request or application for the card; or (2) As a renewal of, or substitute for, an accepted credit card. (b) Liability of cardholder for unauthorized use —(1)(i) Definition of unauthorized use. For purposes of this section, the term “unauthorized use” means the use of a credit card by a person, other than the cardholder, who does not have actual, implied, or apparent authority for such use, and from which the cardholder receives no benefit. (ii) Limitation on amount. The liability of a cardholder for unauthorized use of a credit card shall not exceed the lesser of $50 or the amount of money, property, labor, or services obtained by the unauthorized use before notification to the card issuer under paragraph (b)(3) of this section. (2) Conditions of liability.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 12 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Strubel v. Comenity Bank (Court of Appeals for the Second Circuit 2016, 842 F.3d 181)“…extension of credit.” The official staff interpretation of 12 C.F.R. § 1026.12(c)(1), the portion of Regulation Z impl…”
- William Krieger v. Bank of America NA (Court of Appeals for the Third Circuit 2018, 890 F.3d 429)“…he cardholder previously the “maximum potential liability,” 12 C.F.R. § 1026.12(b)(2)(ii), and a means by which the car…”
- William Lyons v. PNC Bank, N.A. (Court of Appeals for the Fourth Circuit 2024)“…e cardholder held on deposit with the card issuer. 12 C.F.R. § 1026.12(d)(1). 2 In January 200…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 1026.13Billing error resolution.In forcecited in 5 of our articles
(a) Definition of billing error. For purposes of this section, the term billing error means: (1) A reflection on or with a periodic statement of an extension of credit that is not made to the consumer or to a person who has actual, implied, or apparent authority to use the consumer's credit card or open-end credit plan. (2) A reflection on or with a periodic statement of an extension of credit that is not identified in accordance with the requirements of §§ 1026.7(a)(2) or (b)(2), as applicable, and 1026.8. (3) A reflection on or with a periodic statement of an extension of credit for property or services not accepted by the consumer or the consumer's designee, or not delivered to the consumer or the consumer's designee as agreed. (4) A reflection on a periodic statement of the creditor's failure to credit properly a payment or other credit issued to the consumer's account. (5) A reflection on a periodic statement of a computational or similar error of an accounting nature that is made by the creditor. (6) A reflection on a periodic statement of an extension of credit for which the consumer requests additional clarification, including documentary evidence.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 21 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- William Krieger v. Bank of America NA (Court of Appeals for the Third Circuit 2018, 890 F.3d 429)“…on of Regulation Z as promulgated by the CFPB is located at 12 C.F.R. § 1026.13, a materially identical regulation, to…”
- Strubel v. Comenity Bank (Court of Appeals for the Second Circuit 2016, 842 F.3d 181)“…three business days before the scheduled payment date. See 12 C.F.R. § 1026.13(d)(1). Thus, disclosure of this righ…”
- Williams v. Capital One Bank, N.A. (District Court, District of Columbia 2025)“…deral law. Compare Compl. at 47, with 15 U.S.C. § 1666 and 12 C.F.R. § 1026.13 (requiring creditors to investigate and…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of Federal Regulations Title 16
§ 461.3Impersonation of businesses prohibited.In forcecited in 4 of our articles
It is a violation of this part, and an unfair or deceptive act or practice to: (a) materially and falsely pose as, directly or by implication, a business or officer thereof, in or affecting commerce as commerce is defined in the Federal Trade Commission Act (15 U.S.C. 44); or (b) materially misrepresent, directly or by implication, affiliation with, including endorsement or sponsorship by, a business or officer thereof, in or affecting commerce as commerce is defined in the Federal Trade Commission Act (15 U.S.C. 44).
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Also relied on in: Government Impersonation Scams: IRS, Social Security, Jury Duty, Police, Utility Scams: Shutoff Threats, Fake Workers and What to Do
§ 461.2Impersonation of government prohibited.In forcecited in 7 of our articles
It is a violation of this part, and an unfair or deceptive act or practice to: (a) materially and falsely pose as, directly or by implication, a government entity or officer thereof, in or affecting commerce as commerce is defined in the Federal Trade Commission Act (15 U.S.C. 44); or (b) materially misrepresent, directly or by implication, affiliation with, including endorsement or sponsorship by, a government entity or officer thereof, in or affecting commerce as commerce is defined in the Federal Trade Commission Act (15 U.S.C. 44).
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Also relied on in: Phone Scams Targeting Spanish Speakers in the U.S.: How to Spot Them, Medicare and Health Insurance Scams: Warning Signs and Reporting
United States Code Title 15
§ 7704Other protections for users of commercial electronic mailIn force
It is unlawful for any person to initiate the transmission, to a protected computer, of a commercial electronic mail message, or a transactional or relationship message, that contains, or is accompanied by, header information that is materially false or materially misleading. For purposes of this paragraph— header information that is technically accurate but includes an originating electronic mail address, domain name, or Internet Protocol address the access to which for purposes of initiating the message was obtained by means of false or fraudulent pretenses or representations shall be considered materially misleading; a “from” line (the line identifying or purporting to identify a person initiating the message) that accurately identifies any person who initiated the message shall not be considered materially false or materially misleading; and header information shall be considered materially misleading if it fails to identify accurately a protected computer used to initiate the message because the person initiating the message knowingly uses another protected computer to relay or retransmit the message for purposes of disguising its origin.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 43 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Gordon v. Virtumundo, Inc. (Court of Appeals for the Ninth Circuit 2009, 575 F.3d 1040)“…that is materially false or materially misleading.” See 15 U.S.C. § 7704 (a)(1), (2). The Act also imposes requi…”
- Omega World Travel, Inc. v. Mummagraphics, Inc. (Court of Appeals for the Fourth Circuit 2006, 469 F.3d 348)“…rmation that is materially false or materially misleading." 15 U.S.C. § 7704(a)(1) (emphasis added). While "the head…”
- Aitken v. Communications Workers of America (District Court, E.D. Virginia 2007, 496 F. Supp. 2d 653)“…following seven claims: (i) violation of the CAN-SPAM Act, 15 U.S.C. § 7704 , (ii) false endorsement, in violation…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
California Business and Professions Code
§ 22948.2In forcecited in 2 of our articles
It shall be unlawful for any person, by means of a Web page, electronic mail message, or otherwise through use of the Internet, to solicit, request, or take any action to induce another person to provide identifying information by representing itself to be a business without the authority or approval of the business.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2021
Opinions citing this section in our collection:
- Yahoo! Inc. v. XYZ Companies (District Court, S.D. New York 2011, 872 F. Supp. 2d 300)“…and 10) violation of California’s Anti-Phishing Statute, Cal. Bus. & Prof. Code § 22948.2 . 1 Trademark Counterfeiting and I…”
- Gonzalez v. Bryant (District Court, E.D. California 2021)“…thout the authority or 13 approval of that business. Cf. Cal. Bus. & Prof. Code § 22948.2. As this Court has 14 already held,…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Scam and Fraud Laws: Where to Report, Your Right to Sue (2026)
§ 22948.3In force
(a) The following persons may bring an action against a person who violates or is in violation of Section 22948.2: (1) A person who (A) is engaged in the business of providing Internet access service to the public, owns a Web page, or owns a trademark, and (B) is adversely affected by a violation of Section 22948.2. An action brought under this paragraph may seek to recover the greater of actual damages or five hundred thousand dollars ($500,000). (2) An individual who is adversely affected by a violation of Section 22948.2 may bring an action, but only against a person who has directly violated Section 22948.2. An action brought under this paragraph may seek to enjoin further violations of Section 22948.2 and to recover the greater of three times the amount of actual damages or five thousand dollars ($5,000) per violation. (b) The Attorney General or a district attorney may bring an action against a person who violates or is in violation of Section 22948.2 to enjoin further violations of Section 22948.2 and to recover a civil penalty of up to two thousand five hundred dollars ($2,500) per violation.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Code of Virginia, Title 18.2: Crimes and Offenses Generally
§ 18.2-152.5:1Using a computer to gather identifying information; penaltiesIn forcecited in 2 of our articles
A. It is unlawful for any person, other than a law-enforcement officer, as defined in § 9.1-101, and acting in the performance of his official duties, to use a computer to obtain, access, or record, through the use of material artifice, trickery or deception, any identifying information, as defined in clauses (iii) through (xiii) of subsection C of § 18.2-186.3. Any person who violates this section is guilty of a Class 6 felony. B. Any person who violates this section and sells or distributes such information to another is guilty of a Class 5 felony. C. Any person who violates this section and uses such information in the commission of another crime is guilty of a Class 5 felony.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at law.lis.virginia.gov
Also relied on in: Virginia Scam and Fraud Laws: Where to Report, Your Right to Sue (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- FTC, How To Recognize and Avoid Phishing Scams (September 2022)(consumer.ftc.gov).gov
- CISA, Update to Phishing General Security Postcard (January 2024)(cisa.gov).gov
- FBI Atlanta, FBI Atlanta Warns of Smishing Scam Regarding Peach Pass (March 12, 2025)(fbi.gov).gov
- FBI IC3, Public Service Announcement I-051525-PSA (May 15, 2025)(ic3.gov).gov
- FTC, What's a verification code and why would someone ask me for it? (March 7, 2024)(consumer.ftc.gov).gov
- FTC, Got a call about fraud activity on your bank account? It could be a scammer (2024)(consumer.ftc.gov).gov
- FTC, Never move your money to 'protect it.' That's a scam (March 5, 2024)(consumer.ftc.gov).gov
- FTC, How to Recognize and Report Spam Text Messages (July 2022)(consumer.ftc.gov).gov
- CISA, Recognize and Report Phishing (archived consumer guidance)(cisa.gov).gov
- FTC Data Spotlight, Top text scams of 2024 (April 14, 2025)(ftc.gov).gov
- FBI IC3, Smishing Scam Regarding Debt for Road Toll Services, I-041224-PSA (April 12, 2024)(ic3.gov).gov
- E-ZPass Group media advisory on smishing texts (April 26, 2024), via Georgia State Road and Tollway Authority(srta.ga.gov).gov
- U.S. Postal Inspection Service, Smishing: Package Tracking Text Scams(uspis.gov).gov
- IRS, Report fake IRS, Treasury or tax-related emails and messages(irs.gov).gov
- FTC, What To Do if You Were Scammed (June 2026)(consumer.ftc.gov).gov
- 12 C.F.R. § 1026.12 (Regulation Z, unauthorized use of credit cards), eCFR(ecfr.gov).gov
- 12 C.F.R. § 1026.13 (Regulation Z, billing error resolution), eCFR(ecfr.gov).gov
- 15 U.S.C. § 1681c-1 (security freezes and fraud alerts)(law.cornell.edu)
- FTC, What To Know About Credit Freezes and Fraud Alerts(consumer.ftc.gov).gov
- FTC, What To Know About Identity Theft (September 2024)(consumer.ftc.gov).gov
- 12 C.F.R. § 1005.2 (Regulation E definitions), eCFR(ecfr.gov).gov
- CFPB, Electronic Fund Transfers FAQs: Error Resolution, Unauthorized EFTs(consumerfinance.gov).gov
- 12 C.F.R. § 1005.6 (Regulation E, liability for unauthorized transfers), eCFR(ecfr.gov).gov
- 12 C.F.R. § 1005.11 (Regulation E, procedures for resolving errors), eCFR(ecfr.gov).gov
- ReportFraud.ftc.gov (FTC reporting site)(reportfraud.ftc.gov).gov
- IdentityTheft.gov (FTC identity theft reporting and recovery)(identitytheft.gov).gov
- 18 U.S.C. § 1343 (wire fraud)(law.cornell.edu)
- 18 U.S.C. § 1028 (fraud in connection with identification documents and information)(law.cornell.edu)
- 18 U.S.C. § 1028A (aggravated identity theft)(law.cornell.edu)
- 18 U.S.C. § 1030 (Computer Fraud and Abuse Act)(law.cornell.edu)
- Federal Register, FTC Impersonation Rule final rule, 89 FR 15030 (March 1, 2024)(govinfo.gov).gov
- 16 C.F.R. Part 461 (FTC Impersonation Rule), eCFR(ecfr.gov).gov
- 15 U.S.C. § 7704 (CAN-SPAM Act)(law.cornell.edu)
- Cal. Bus. & Prof. Code § 22948.2 (Anti-Phishing Act of 2005)(leginfo.legislature.ca.gov).gov
- Cal. Bus. & Prof. Code § 22948.3 (Anti-Phishing Act remedies)(leginfo.legislature.ca.gov).gov
- Texas H.B. 1098 (79th Legislature, 2005), enrolled text creating the Anti-Phishing Act(capitol.texas.gov).gov
- Va. Code § 18.2-152.5:1(law.lis.virginia.gov).gov
- FCC Report and Order FCC 23-21 (adopted March 16, 2023)(docs.fcc.gov).gov
- Federal Register, FCC text-blocking rule, effective May 11, 2023 (April 11, 2023)(govinfo.gov).gov
- FTC Data Spotlight on social media scams (April 2026), 2025 contact-method data(ftc.gov).gov
- FBI IC3, 2024 Internet Crime Report(ic3.gov).gov
- FBI IC3, 2025 Internet Crime Report(ic3.gov).gov