Phishing, and how not to be caught
A message that wants you to act before you think. The shape is always the same, even when the words are perfect.
Phishing is a message pretending to be somebody you trust, designed to get a password, a code or a payment out of you. It arrives by SMS, by WhatsApp, by email and increasingly by phone call.
The shape, which does not change
- A reason to hurry. Your account will be closed, your parcel is held, your number will be deactivated today.
- A link, or a number to call. Often close to the real one, with a letter changed or an extra word added.
- A request for something only you have: a code, a PIN, a password, a payment.
What to do instead, every time
- Do not use the link or the number in the message. Go to the app or type the website yourself, the way you normally would.
- If it claims to be your bank or your operator, call the number printed on your card or on their official site.
- Check the sender properly. A real company does not write from a personal Gmail address.
- Treat a code arriving that you did not ask for as an attack in progress: somebody is trying to log in as you right now.
- If it is about money and it is urgent, assume it is a scam until you have confirmed it by a route the message did not give you.
On your phone
Making it harder on Android
- Messages app, menu, Settings, Spam protection. Turn it on.
- Settings, Apps, Default apps, Caller ID and spam app. Pick one, so unknown numbers are flagged before you answer.
- Play Protect: open Play Store, tap your picture, Play Protect, and make sure scanning is on.
- Never install an app from a link in a message. Only from the Play Store.