← Back to Knowledge Center
KNOWLEDGE CENTER

What Not to Share: Information Attackers Can Use Against You

Privacy & Personal Informationen-NG
BEFORE YOU BEGIN

Understand the issue before you decide what to do.

This lesson is designed to explain the subject in practical terms so that you can understand not only what the risk is, but why it matters, how it can appear in real situations and what you can do to reduce your exposure.

Read the explanation carefully before acting on a suspicious message, request, transaction, account notification or other security-related situation.

FULL LESSON

Understanding the subject

Take your time with this explanation. The goal is not simply to recognise a warning sign, but to understand what is happening and make a safer decision when you encounter it.

WHAT NOT TO SHARE: INFORMATION ATTACKERS CAN USE AGAINST YOU

Attackers often begin by collecting information rather than immediately attempting to break into an account. They may use small pieces of information to support impersonation, account takeover, fraud or targeted social engineering.

THE CORE PRINCIPLE

A REQUEST FOR INFORMATION SHOULD BE VERIFIED BEFORE YOU TREAT IT AS LEGITIMATE.

01 · NEVER CASUALLY SHARE AUTHENTICATION SECRETS

Be extremely careful with passwords, PINs, one-time authentication codes, recovery codes, recovery phrases and other information that can provide access to an account or wallet.

02 · PROTECT FINANCIAL INFORMATION

Be cautious with payment-card details, banking information, transaction information and other financial data. Use legitimate official channels when financial information genuinely needs to be submitted.

03 · PROTECT IDENTIFICATION DOCUMENTS

Identity documents can contain multiple identifiers in a single image. Verify who needs the document, why it is needed and how it will be handled before sending it.

04 · PROTECT SECURITY QUESTIONS AND RECOVERY INFORMATION

Information used to recover an account can be as important as the password itself. Do not provide answers or recovery details simply because someone claims to be support staff.

05 · BE CAREFUL WITH UNEXPECTED REQUESTS

A caller, message or social-media contact may ask for information while creating urgency or claiming authority. The request itself should be verified independently.

06 · USE OFFICIAL SUBMISSION CHANNELS

When sensitive information genuinely needs to be submitted, use the organization's official website, application or established process rather than an unexpected link or message.

EXAMPLE

A caller claims to be from a service provider and says they need your one-time code to “confirm ownership.” The correct response is not to provide the code. End the interaction and contact the provider through its known official channel.

WHAT TO DO

  • Treat passwords, PINs, OTPs and recovery information as secrets.
  • Verify requests for financial or identity information.
  • Do not let urgency override verification.
  • Use official channels for legitimate sensitive-data submissions.
  • If you already disclosed a secret, take protective action promptly.

WHY THIS MATTERS

Attackers can combine several ordinary pieces of information to create a convincing attack. Protecting information is therefore part of protecting your accounts and identity.

VERIFY BEFORE YOU TRUST.

APPLY WHAT YOU LEARNED

Turn understanding into a security habit.

Knowing the definition is only the beginning. The real value of cybersecurity education is being able to recognise the situation and make a safer decision when it happens to you.

How should you use what you learned?

Understanding a cybersecurity concept is useful only when it changes how you make decisions. When you encounter a similar situation in real life, slow down and identify what is being requested before you respond.

Ask yourself who is making the request, what they are asking you to do, what information or access is involved, and whether the request can be independently verified.

Do not allow urgency, fear, authority, familiarity or the promise of a reward to replace independent verification.

What if I still do not understand something?

Cybersecurity concepts can sometimes involve technical terms or situations that are difficult to interpret from a single lesson. If something is unclear, do not guess when the decision could affect your money, identity, account access, device or sensitive information.

You can seek further guidance through the consultancy channel. Explain the situation clearly, but never include passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A convincing message, familiar name, professional appearance or urgent request is not proof of legitimacy. Verify the important facts independently before taking an action that could be difficult to reverse.