← Back to Knowledge Center
KNOWLEDGE CENTER

Phishing Messages: How to Recognize a Message Designed to Trick You

Phishing & Scamsen-NG
BEFORE YOU BEGIN

Understand the issue before you decide what to do.

This lesson is designed to explain the subject in practical terms so that you can understand not only what the risk is, but why it matters, how it can appear in real situations and what you can do to reduce your exposure.

Read the explanation carefully before acting on a suspicious message, request, transaction, account notification or other security-related situation.

FULL LESSON

Understanding the subject

Take your time with this explanation. The goal is not simply to recognise a warning sign, but to understand what is happening and make a safer decision when you encounter it.

PHISHING: HOW TO RECOGNISE, AVOID AND RESPOND TO DECEPTIVE MESSAGES

Phishing is a social-engineering attack in which someone tries to manipulate you into revealing information, giving access, sending money, installing something, approving an action or visiting a harmful destination.

Phishing is not limited to email. It can arrive through SMS, WhatsApp, social media, phone calls, websites, messaging apps, fake customer-support conversations, QR codes and even messages from accounts that appear to belong to people you know.

The central principle is simple:

A FAMILIAR NAME, LOGO, PHONE NUMBER OR PROFILE DOES NOT PROVE THAT A REQUEST IS GENUINE.

Phishing works by attacking trust and decision-making. The attacker wants you to act before you stop to verify.

1. WHAT PHISHING IS REALLY TRYING TO DO

A phishing message is usually designed to make you take an action that benefits the attacker.

That action might be:

  • Entering a username and password.
  • Giving away an OTP, PIN or recovery code.
  • Sending money.
  • Changing bank or payment details.
  • Approving a login or authentication request.
  • Installing an application or allowing remote access.
  • Opening a malicious attachment.
  • Connecting a cryptocurrency wallet.
  • Signing a transaction or approving an asset permission.
  • Revealing personal or business information.

The message itself is only the delivery mechanism. The real target is the action the attacker wants you to take.

2. HOW PHISHING WORKS

A typical phishing attack can be understood as a sequence:

CREATE TRUST → CREATE PRESSURE → PRESENT A REQUEST → REDUCE YOUR TIME TO THINK → CAPTURE THE ACTION

For example, an attacker may send:

“Your bank account has been restricted. Verify your account within 30 minutes or your account will be suspended.”

The attacker has combined three psychological triggers:

  • Fear: something is supposedly wrong.
  • Urgency: you have very little time.
  • Authority: the message claims to come from your bank.

The link then leads to a fake page designed to collect your credentials or other information.

The important lesson is that phishing is often a manipulation process before it becomes a technical attack.

3. THE PHISHING CHAIN

A useful way to understand phishing is to follow the chain from beginning to end.

STEP 1 — THE ATTACKER CHOOSES A TARGET

The target may be an individual, employee, business owner, finance officer, administrator or anyone who controls valuable information or money.

STEP 2 — THE ATTACKER CREATES A STORY

The attacker creates a believable reason for contacting you.

Examples include:

  • “Your account needs verification.”
  • “Your delivery could not be completed.”
  • “Your payment failed.”
  • “Your package is waiting.”
  • “Your account will be closed.”
  • “I need this payment urgently.”
  • “Your wallet needs to be synchronised.”

STEP 3 — THE ATTACKER CREATES A CHANNEL

The story may arrive through email, SMS, WhatsApp, social media, a fake website, a QR code or a phone call.

STEP 4 — THE ATTACKER CREATES PRESSURE

The attacker wants you to react rather than investigate.

STEP 5 — THE ATTACKER PRESENTS THE REQUEST

The request may be to click, log in, pay, download, approve or disclose information.

STEP 6 — THE VICTIM TAKES THE ACTION

This is the point at which the attacker gains the intended benefit.

Understanding this chain makes it easier to interrupt the attack before the final action.

4. THE SIX QUESTIONS TO ASK BEFORE ACTING

When an unexpected message arrives, pause and ask:

  1. WHO is contacting me?
  2. WHY are they contacting me?
  3. WHAT exactly are they asking me to do?
  4. WHAT happens if I do it?
  5. HOW can I verify the request independently?
  6. WHERE will this action take me?

If the request involves money, passwords, authentication codes, recovery information, sensitive documents, device access or cryptocurrency, raise your level of caution.

5. THE MOST IMPORTANT PHISHING WARNING SIGNS

No single warning sign proves that a message is phishing. Several signals together are much more meaningful.

Watch for:

  • Unexpected contact.
  • Urgent deadlines.
  • Threats of account closure or penalties.
  • Requests for passwords or OTPs.
  • Requests for recovery codes or private information.
  • Unexpected payment instructions.
  • Bank-detail changes.
  • Links to unfamiliar domains.
  • Attachments you were not expecting.
  • Requests to install software.
  • Requests for remote access to your device.
  • Poorly written or unusual messages.
  • A sender address that does not match the claimed organization.
  • A message that asks you to bypass normal procedures.
  • A request that is unusually secret or confidential.
  • A familiar person suddenly asking for something unusual.
KEY TAKEAWAYprofessional spelling does not prove legitimacy, and poor spelling does not automatically prove fraud. Verify the request itself.

6. LOOK AT THE REQUEST BEFORE LOOKING AT THE BRANDING

Attackers can copy logos, colours, signatures, names and other visual details.

Instead of asking:

“Does this look like my bank?”

Ask:

“Why is my bank asking me to do this, and can I verify the request independently?”

A convincing appearance is not authentication.

7. URGENCY IS A SIGNAL TO SLOW DOWN

Phishing messages frequently create artificial deadlines.

Examples:

“Act now.”

“Your account will be closed today.”

“Payment must be made immediately.”

“Your parcel will be returned within one hour.”

“Do not tell anyone.”

Urgency does not prove that a message is fraudulent. But urgency combined with a high-impact request should cause you to slow down.

A legitimate request can normally survive independent verification.

A scam often depends on preventing you from verifying it.

8. CHECK THE SENDER CAREFULLY

Look beyond the display name.

A message may display:

“Your Bank”

while the actual email address belongs to an unrelated domain.

A contact may also use a familiar person's name while the underlying phone number or account is different.

Ask:

  • Do I recognise the actual sender address or number?
  • Does it match the organization I am being told it represents?
  • Was I expecting this communication?
  • Does the sender normally contact me in this way?

A familiar display name is not proof of identity.

9. CHECK THE LINK BEFORE YOU TRUST IT

A link can hide its real destination behind words such as:

“Verify account”

“Secure your account”

“Claim reward”

“Track package”

Do not assume that the visible words tell you where the link goes.

If a message contains an unexpected link to an important account, the safer approach is often to ignore the link and open the official application or type the known website address yourself.

10. UNDERSTAND DOMAINS

The important part of a web address is the actual registered domain, not merely words appearing somewhere in the address.

For example, an attacker might create a domain containing the name of a legitimate company while using a completely different registered domain.

Be cautious with:

  • Misspelled brand names.
  • Extra words inserted into domains.
  • Unusual domain endings.
  • Lookalike characters.
  • Long addresses designed to hide the important part.
  • Links that redirect through unfamiliar services.

Do not decide that a site is genuine simply because the address contains the name of a company.

When an important account is involved, opening the official app or using a website address you already know is safer than trusting an unexpected link.

11. PHISHING THROUGH EMAIL

Email phishing remains common because email is used for banking, work, shopping, account recovery and business communication.

EXAMPLE

“Dear customer, unusual activity has been detected on your account. Click below to confirm your identity.”

Before clicking, ask:

  • Did I expect this?
  • Does the sender match the organization?
  • What is the actual destination of the link?
  • Can I check the account directly through the official app?

If the answer to the last question is yes, that is usually the better route.

12. PHISHING THROUGH SMS

SMS phishing is sometimes called smishing.

Examples include fake:

  • Bank alerts.
  • Delivery notifications.
  • Mobile-network messages.
  • Government notices.
  • Job offers.
  • Loan offers.
  • Account-verification messages.

A message saying “your package is held, pay a small fee here” may look harmless because the requested amount is small.

But the real objective may be to capture your card details, credentials or other information.

Do not judge risk only by the amount requested.

13. PHISHING THROUGH WHATSAPP AND SOCIAL MEDIA

Attackers may impersonate:

  • Friends.
  • Family members.
  • Business owners.
  • Managers.
  • Customer-support representatives.
  • Sellers.
  • Public figures.
EXAMPLE

“Please help me urgently. I cannot access my bank app. Send this money to this account and I will refund you.”

The safest response is to verify the person's identity through another channel you already trust.

Do not rely on the fact that the profile photo, name or conversation history looks familiar.

Accounts can be compromised or impersonated.

14. BUSINESS EMAIL AND PAYMENT PHISHING

Businesses face a particularly dangerous form of phishing in which criminals manipulate payment instructions.

EXAMPLE

A supplier normally receives payments into Account A.

An email arrives saying:

“We have changed our bank account. Please use Account B for all future payments.”

The message may contain a genuine invoice and familiar branding.

The correct response is not to reply to the same email and ask whether the change is genuine.

Verify the change through a trusted contact method that was already known before the message arrived.

This principle is especially important for:

  • Bank-detail changes.
  • Large transfers.
  • Payroll changes.
  • Supplier payments.
  • Executive payment requests.
  • Requests to bypass normal approval procedures.

15. PHISHING AND FAKE CUSTOMER SUPPORT

Attackers may pretend to be support staff after seeing someone publicly complain about a service.

EXAMPLE

“I saw your complaint. I am from support. Send me your verification code so I can fix the issue.”

This is dangerous because the attacker may use the code to authenticate as you.

Never surrender passwords, OTPs, recovery codes, PINs or private keys to an unsolicited person claiming to be support.

If you need support, find the official support channel yourself.

16. PHISHING AND QR CODES

QR codes can also lead to phishing pages.

A QR code does not become trustworthy merely because it is convenient to scan.

A malicious QR code may lead to a fake login page, payment page or application download.

Before using a QR code for an important action, consider where it came from and what action it is asking you to perform.

For sensitive accounts, use the official application or known website rather than an unexpected QR code.

17. PHISHING AND ATTACHMENTS

Some phishing messages contain attachments instead of links.

Possible examples include:

  • Fake invoices.
  • Fake receipts.
  • Delivery documents.
  • Job applications.
  • Account statements.
  • Password-protected archives.
  • Documents claiming to contain important information.

An attachment can be dangerous even when the message looks professional.

If you were not expecting the attachment, verify it before opening it.

Do not enable unusual document features or install software merely because an attachment tells you that it is necessary.

18. PHISHING AND FAKE LOGIN PAGES

One of the most common objectives of phishing is credential theft.

The attacker creates a page that resembles a legitimate login page.

You enter:

Username → Password → OTP

The attacker may receive the information and attempt to use it against the real service.

This is why MFA does not mean you can safely enter your credentials into any page that asks for them.

The authentication page itself must be verified.

19. MFA CAN HELP, BUT MFA DOES NOT MAKE PHISHING IMPOSSIBLE

MFA can make account takeover more difficult when a password is stolen.

However, attackers may try to manipulate the MFA process itself.

For example, an attacker may:

  • Ask you to read an OTP aloud.
  • Send repeated approval requests.
  • Create a fake login page that asks for your MFA code.
  • Pretend to be support and request authentication information.

If you receive an authentication request you did not initiate, do not approve it.

If someone asks you to provide an authentication code, do not give it to them.

20. MFA FATIGUE AND APPROVAL TRICKS

An attacker who knows your password may repeatedly trigger login prompts.

The attacker hopes that you eventually press “Approve” simply to stop the notifications.

This is commonly called MFA fatigue or push-bombing.

The correct response to an unexpected approval request is:

STOP → DENY → INVESTIGATE

Do not assume the request is harmless because it appears inside your normal authentication application.

21. PHISHING AND CRYPTOCURRENCY

Cryptocurrency users face additional phishing risks because transactions can be difficult or impossible to reverse.

Common examples include:

  • Fake wallet-support messages.
  • Fake token-claim pages.
  • Fake airdrops.
  • Fake exchange alerts.
  • Fake wallet synchronisation requests.
  • Malicious websites asking you to connect a wallet.
  • Requests for recovery phrases or private keys.
  • Fake transaction-verification messages.

A legitimate person should never need your wallet recovery phrase or private key in order to “verify,” “synchronise,” “unlock” or “recover” your wallet.

If a website asks for your recovery phrase, stop.

22. CRYPTO WALLET CONNECTIONS AND PHISHING

A crypto phishing attack does not always ask for your password.

It may ask you to connect your wallet and approve a signature, permission or transaction.

Before approving a wallet request, verify:

  • The website address.
  • The official project or service.
  • The network.
  • The asset involved.
  • The requested permission or transaction.
  • Whether the action makes sense.

A professional-looking website is not proof of legitimacy.

Do not approve an unfamiliar transaction simply because a message says it is required to receive a reward or fix a wallet problem.

23. PHISHING CAN HAPPEN WITHOUT A LINK

Some phishing attacks simply ask you to provide information in a conversation.

EXAMPLE

“Send me your account number, OTP and PIN so I can confirm your identity.”

No link is required.

The attack is still phishing because the attacker is manipulating you into revealing information that they should not receive.

This is why focusing only on suspicious links is not enough.

Look at the request itself.

24. THE “FRIEND OR FAMILY” TEST

If a message appears to come from someone you know but asks for money, sensitive information or an unusual action, verify the person independently.

Call their known number.

Speak to them directly.

Use another communication channel you already trust.

Do not use contact information supplied by the suspicious message as the only method of verification.

25. THE “BANK” TEST

If a message claims to be from your bank and asks you to click a link, do not let the message decide how you access your bank.

Open the official banking application yourself or use a known official website address.

Check whether the claimed problem actually exists.

If necessary, contact the bank through an official number or channel you obtained independently.

26. THE “DELIVERY” TEST

Suppose you receive:

“Your parcel could not be delivered. Pay ₦1,500 to reschedule.”

Before paying, ask:

  • Am I expecting a parcel?
  • Which company is delivering it?
  • Did I receive a legitimate tracking number through a known channel?
  • Can I check the delivery through the company's official website or application?

Do not allow a small payment request to lower your guard.

27. THE “JOB OFFER” TEST

Phishing can target job seekers with messages promising employment.

Warning signs can include:

  • Requests for payment before employment.
  • Requests for sensitive identity documents through an unexpected channel.
  • Requests to install unfamiliar software.
  • Requests to deposit or transfer money.
  • Unrealistic urgency.
  • Instructions to bypass normal recruitment procedures.

Verify the employer independently before providing sensitive information or money.

28. THE “INVESTMENT OR CRYPTO OPPORTUNITY” TEST

Scammers may use social media, messaging groups or fake investment platforms to create urgency around an opportunity.

Examples:

“Deposit now before the opportunity closes.”

“Connect your wallet to receive your allocation.”

“Send a small verification fee before withdrawal.”

Do not treat urgency, screenshots of profits or testimonials as proof.

Verify the platform independently and understand exactly what you are being asked to authorise.

29. HOW TO VERIFY A MESSAGE INDEPENDENTLY

Independent verification means using a method that does not depend on the suspicious message itself.

EXAMPLE

SUSPICIOUS MESSAGE → DO NOT USE ITS LINK → OPEN OFFICIAL APP → CHECK ACCOUNT → CONTACT KNOWN OFFICIAL CHANNEL IF NECESSARY

For a payment request:

NEW PAYMENT INSTRUCTION → DO NOT REPLY ONLY TO THE REQUEST → CONTACT KNOWN SUPPLIER CONTACT → CONFIRM DETAILS → FOLLOW APPROVAL PROCESS

For a family or friend request:

UNUSUAL REQUEST → CALL KNOWN NUMBER → CONFIRM IDENTITY → THEN ACT IF GENUINE

30. WHAT NOT TO DO WHEN YOU SUSPECT PHISHING

Do not:

  • Rush because the message says you have little time.
  • Reply with sensitive information.
  • Share passwords or OTPs.
  • Share recovery codes.
  • Share wallet recovery phrases or private keys.
  • Click repeatedly to “see what happens.”
  • Download unexpected attachments.
  • Install remote-access software because a stranger told you to.
  • Send money simply to stop a threat.
  • Use the suspicious message itself as your only verification channel.
  • Assume that a familiar logo proves legitimacy.

31. WHAT TO DO WHEN YOU RECEIVE A SUSPICIOUS MESSAGE

Use this simple process:

STOP → INSPECT → VERIFY → ACT

STOP

Do not click, reply, pay or approve anything immediately.

INSPECT

Look at the sender, request, urgency, link, attachment and context.

VERIFY

Use the official application, known website or trusted independent contact.

ACT

Only after verification should you take the requested action. If it cannot be verified, do not proceed.

32. WHAT IF YOU ALREADY CLICKED THE LINK?

Do not panic. The appropriate response depends on what happened next.

If you clicked but did not enter information, download anything or approve an action, close the page and continue to monitor the account. Consider whether anything was downloaded or whether the page requested additional permissions.

If you entered a password, change that password through the legitimate service immediately, preferably from a trusted device. If you reused the password elsewhere, change it there too.

If you entered an OTP or approved an unexpected MFA request, secure the account immediately and review active sessions and security settings.

If you provided financial information, contact the relevant financial institution through an official channel as soon as possible.

If you authorised a cryptocurrency transaction or permission, act according to the wallet, exchange or blockchain service's legitimate security procedures and preserve the transaction details.

33. WHAT IF YOU SENT MONEY?

Contact the relevant bank, payment provider or financial institution through its official channel immediately.

Provide accurate information about what happened, including the time, amount, beneficiary details and transaction reference where available.

Do not pay another person who claims they can recover the money for a fee unless you have independently verified that the service is legitimate.

Recovery scams often target people who have already lost money.

34. WHAT IF YOU GAVE AWAY YOUR PASSWORD?

Use the legitimate service immediately.

  1. Change the compromised password.
  2. Change it anywhere else you reused it.
  3. Review MFA.
  4. Review recovery methods.
  5. Review active sessions and devices.
  6. Review connected applications.
  7. Check security notifications and important account activity.
  8. Look for unauthorised changes.

Changing the password is important, but it should not be the only step after suspected compromise.

35. WHAT IF YOU GAVE AWAY YOUR RECOVERY PHRASE?

For a cryptocurrency wallet, treat a compromised recovery phrase as a serious security event.

Do not continue treating the wallet as secure simply because the assets are still visible.

Follow the legitimate wallet's security guidance and, where appropriate, move assets to a newly secured wallet using a new recovery phrase.

Never give the new recovery phrase to anyone offering assistance.

36. HOW ATTACKERS MAKE PHISHING LOOK REAL

Attackers may use:

  • Copied logos.
  • Similar colours and layouts.
  • Real company names.
  • Information gathered from social media.
  • Compromised accounts.
  • Lookalike domains.
  • Professional-looking documents.
  • Correct personal details.
  • Real invoices combined with fake payment instructions.

This is why “it looks real” is not a sufficient security test.

The correct question is:

CAN I VERIFY THE REQUEST THROUGH A TRUSTED CHANNEL?

37. SOCIAL ENGINEERING: THE HUMAN SIDE OF PHISHING

Phishing is often successful because it exploits normal human behaviour.

Attackers may exploit:

  • Trust.
  • Fear.
  • Curiosity.
  • Respect for authority.
  • Desire to help.
  • Greed or promised rewards.
  • Embarrassment.
  • Urgency.
  • Familiarity.

Recognising these emotional triggers helps you notice when someone is trying to control your decision rather than simply communicate information.

38. WHY SMART PEOPLE STILL FALL FOR PHISHING

Phishing does not require someone to be careless or unintelligent.

A person may be busy, distracted, tired, worried about losing money or responding to what appears to be an urgent work request.

Security therefore should not depend on perfect attention every second.

Good habits create friction before high-impact actions.

Pause. Verify. Then act.

39. A PRACTICAL PHISHING DECISION TREE

MESSAGE ARRIVES

Was it expected?

NO → Slow down and inspect it.
YES → Continue checking because expected messages can also be compromised.

Does it request money, credentials, codes, sensitive information, access or an unusual action?

YES → Treat as high-impact and verify independently.
NO → Continue normal caution.

Does it contain a link or attachment you did not expect?

YES → Do not open it until independently verified.

Can you complete the task through the official application or known website?

YES → Use that route instead.

Can the request be independently verified?

NO → Do not act.
YES → Verify before acting.

40. PHISHING EXAMPLE: FAKE BANK ALERT

MESSAGE:

“Your account has been restricted. Click here within 20 minutes to restore access.”

Warning signals:

  • Unexpected alert.
  • Urgency.
  • Account threat.
  • Link to an unknown destination.

Safe response:

Do not click the link.

Open the official banking application yourself.

Check whether there is actually a restriction.

If necessary, contact the bank through its official support channel.

41. PHISHING EXAMPLE: FAKE FRIEND REQUEST

MESSAGE:

“Please send me ₦50,000 urgently. I lost my phone and this is my new number.”

Safe response:

Do not send money based solely on the message.

Call the person's known number or verify through another trusted channel.

If the identity cannot be independently confirmed, do not send the money.

42. PHISHING EXAMPLE: FAKE COMPANY EXECUTIVE

MESSAGE TO AN EMPLOYEE:

“I am in a meeting. Make this supplier payment immediately and do not delay.”

Safe response:

Follow the organization's normal approval and verification procedure.

Do not bypass controls because the message appears to come from a senior person.

An unusual request from a trusted authority is still an unusual request.

43. PHISHING EXAMPLE: FAKE CRYPTO SUPPORT

MESSAGE:

“Your wallet has a synchronisation problem. Send your recovery phrase so we can restore your assets.”

This is a critical warning sign.

Never send a wallet recovery phrase to someone claiming it is needed for support, verification, synchronisation or recovery.

Use the wallet provider's official support process instead.

44. PHISHING EXAMPLE: FAKE DELIVERY PAYMENT

MESSAGE:

“Your package is waiting. Pay ₦1,200 to complete delivery.”

Safe response:

Check whether you are expecting a package.

Find the delivery company's official website or application yourself.

Enter the tracking information there rather than trusting the message link.

45. PHISHING EXAMPLE: FAKE JOB OFFER

MESSAGE:

“Congratulations. You have been selected. Pay a registration fee today to secure your position.”

Warning signals:

  • Unexpected offer.
  • Urgency.
  • Upfront payment.
  • Request to act outside normal recruitment procedures.

Verify the employer independently before providing money or sensitive documents.

46. PHISHING EXAMPLE: FAKE ACCOUNT RECOVERY

MESSAGE:

“We detected suspicious activity. Send the recovery code you just received so we can confirm you own the account.”

Do not send the code.

The attacker may have triggered the code themselves and is attempting to use you as part of the authentication process.

Secure the account through the official service instead.

47. REPORTING PHISHING

Reporting suspicious messages can help protect you and others.

Where appropriate:

  • Use the service's official report-phishing feature.
  • Report suspicious business messages to the responsible security or IT contact.
  • Notify the relevant financial institution if a financial scam is involved.
  • Preserve useful evidence when an incident may need investigation.

Do not forward dangerous links to others simply to warn them if doing so could cause them to click the link accidentally. Use safe reporting mechanisms where available.

48. BUILD A PERSONAL PHISHING HABIT

A useful habit is:

UNEXPECTED + URGENT + HIGH IMPACT = STOP AND VERIFY

High-impact actions include:

  • Sending money.
  • Changing payment details.
  • Entering credentials.
  • Sharing authentication codes.
  • Changing recovery information.
  • Installing software.
  • Granting remote access.
  • Connecting a wallet.
  • Approving a transaction.
  • Sharing sensitive documents.

The more serious the consequence, the stronger your verification should be.

49. YOUR PHISHING CHECKLIST

Before acting on an unexpected message, ask:

□ Do I know who actually sent this? □ Was I expecting it? □ What exactly is it asking me to do? □ Is there pressure or urgency? □ Does it involve money or sensitive information? □ Does it ask for a password, OTP, PIN or recovery code? □ Is the link going where I expect? □ Can I use the official application instead? □ Can I verify the request independently? □ Would I make the same decision if the message were not creating pressure?

If you cannot verify a high-impact request, do not act on it.

50. THE GOLDEN RULE

Phishing is not defeated by becoming suspicious of every message.

It is defeated by learning when to pause and verify.

A genuine request should be able to survive independent verification.

A familiar name can be copied. A logo can be copied. A phone number can be spoofed or changed. An account can be compromised. A website can look genuine. A message can contain real information and still lead to a fraudulent action.

Therefore:

DO NOT VERIFY THE APPEARANCE. VERIFY THE REQUEST.

When money, credentials, access, recovery information or sensitive data is involved, slow down.

Open the official service yourself. Use a known contact channel. Confirm the request independently. Then act.

VERIFY BEFORE YOU TRUST.

APPLY WHAT YOU LEARNED

Turn understanding into a security habit.

Knowing the definition is only the beginning. The real value of cybersecurity education is being able to recognise the situation and make a safer decision when it happens to you.

How should you use what you learned?

Understanding a cybersecurity concept is useful only when it changes how you make decisions. When you encounter a similar situation in real life, slow down and identify what is being requested before you respond.

Ask yourself who is making the request, what they are asking you to do, what information or access is involved, and whether the request can be independently verified.

Do not allow urgency, fear, authority, familiarity or the promise of a reward to replace independent verification.

What if I still do not understand something?

Cybersecurity concepts can sometimes involve technical terms or situations that are difficult to interpret from a single lesson. If something is unclear, do not guess when the decision could affect your money, identity, account access, device or sensitive information.

You can seek further guidance through the consultancy channel. Explain the situation clearly, but never include passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A convincing message, familiar name, professional appearance or urgent request is not proof of legitimacy. Verify the important facts independently before taking an action that could be difficult to reverse.