Phishing scam

Tom receives an email that appears to have been sent from his bank Onedirect. The email urges to click on the link in the email. When Tom does so, he is taken to “a secure page on the bank’s website”. Tom believes the web page to be authentic and he enters his username, password and other information. In reality, the website is a fake and Tom’s personal information is stolen and misused. His bank account is cleaned out. What could Tom do? What could the government do?

Related Background Materials