Safe browsing and phishing awareness
Slow down high-pressure messages and use trusted routes before sharing information or taking action.
How phishing works#
Phishing messages imitate a trusted person or service and pressure the recipient to click, sign in, pay, download, or disclose information. They may arrive by email, text, social media, phone, or collaboration tools.
Warning signs#
Look for unexpected urgency, threats, rewards, payment-detail changes, requests for passwords or codes, unfamiliar attachments, and a destination domain that differs from the claimed organization.
Good spelling does not prove legitimacy, and poor spelling is not required for a scam.
Verify separately#
Do not use the suspicious message's contact details to verify itself. Open the known official app or type a trusted address, call a number already on record, or ask the person through an established channel.
If you interacted#
Stop, record useful details, report the message, and use a known-safe route to secure affected accounts. Change reused credentials, review sessions, and seek qualified support. Avoid continuing to engage with the sender.
Common mistakes#
Hover previews can help but are not a complete guarantee. HTTPS secures a connection to the displayed site; it does not prove the site is honest.
Main habit#
Treat urgent changes involving identity, money, credentials, or confidential data as decisions that require independent confirmation.
Key points
- Phishing uses deceptive communication to trigger unsafe action.
- Urgency, unusual payment changes, credential requests, and mismatched domains are warning signs.
- Verification should use a separate trusted channel.
- Report suspicious messages through the relevant service or organization.