All articles

Staying safe

Phishing, and how not to be caught

A message that wants you to act before you think. The shape is always the same, even when the words are perfect.

Phishing is a message pretending to be somebody you trust, designed to get a password, a code or a payment out of you. It arrives by SMS, by WhatsApp, by email and increasingly by phone call.

The shape, which does not change

  1. A reason to hurry. Your account will be closed, your parcel is held, your number will be deactivated today.
  2. A link, or a number to call. Often close to the real one, with a letter changed or an extra word added.
  3. A request for something only you have: a code, a PIN, a password, a payment.

What to do instead, every time

  1. Do not use the link or the number in the message. Go to the app or type the website yourself, the way you normally would.
  2. If it claims to be your bank or your operator, call the number printed on your card or on their official site.
  3. Check the sender properly. A real company does not write from a personal Gmail address.
  4. Treat a code arriving that you did not ask for as an attack in progress: somebody is trying to log in as you right now.
  5. If it is about money and it is urgent, assume it is a scam until you have confirmed it by a route the message did not give you.
On your phone

Making it harder on Android

  1. Messages app, menu, Settings, Spam protection. Turn it on.
  2. Settings, Apps, Default apps, Caller ID and spam app. Pick one, so unknown numbers are flagged before you answer.
  3. Play Protect: open Play Store, tap your picture, Play Protect, and make sure scanning is on.
  4. Never install an app from a link in a message. Only from the Play Store.

Something here out of date, or a question this does not answer? Tell us.