Phishing & messages
Phishing emails, SMS, and suspicious links.
- How can I recognise a phishing email?
Check the sender carefully, hover links before clicking, watch for urgent threats or prize pressure, and never enter credentials from an unexpected message.
- How can I check a suspicious link?
Do not tap first. Expand or paste the URL into a trust checker, compare the hostname to the claimed brand, and open only official apps or bookmarks when unsure.
- What should I do after clicking a phishing link?
Disconnect if you entered secrets, change passwords from a clean device, contact your bank if payment data was shared, and report the incident to relevant authorities.
- How can I recognise a fake login page?
Check the hostname carefully, watch for urgency and odd design details, never reuse passwords from unexpected links, and open the real site yourself instead of clicking through.
- How does SMS sender spoofing work?
Attackers can forge the sender name shown on SMS so a message looks like your bank or courier. Treat the displayed name as unreliable and verify through official apps or numbers you already trust.
- How can I analyse a suspicious screenshot or message image?
Look for visible domains, urgency language, brand mismatches, and odd UI details. Image analysis can surface clues but cannot conclusively prove authenticity—always verify independently.