free
Phishing & fake messages
Phishing: the fake message that looks real
Emails, texts and DMs pretending to be your bank, a courier or a government office. How to spot them in 30 seconds.
HOW IT WORKS
A scammer sends a message that looks like it comes from a company you trust: your bank, a delivery service, an online shop, even the police. The message creates urgency — “your account is blocked”, “your parcel is waiting”, “unusual login detected” — and asks you to click a link, open an attachment, or reply with personal details.
The link usually leads to a convincing fake login page. The moment you type your password or card details, they are captured and used within minutes.
RED FLAGS
- Urgency or fear: “act within 24 hours or your account is closed”. Real companies never pressure you like this.
- A link that does not match the sender: hover over it without clicking — the real address is shown.
- Grammar mistakes, odd greetings (“Dear Customer”), or a sender address that ends in @gmail.com while claiming to be your bank.
- Attachments you did not ask for. Do not open them.
- Requests for a password, a PIN, or a one-time SMS code. No legitimate company ever asks for these.
WHAT TO DO
- Do not click. Do not reply.
- Contact the company directly using the phone number or app you already know — never the one in the message.
- Report the message to your bank if it impersonates them, and to the platform that sent it (Report Junk / Report Spam).
- Forward phishing emails to your country's anti-phishing reporting address where one exists (e.g. [email protected] in the UK).
REMEMBER
If someone asks for your password, your PIN or a login code, it is a scammer — even if the logo looks perfect. No institution needs your code; they generate their own.