LEARN

Learn the habit behind the tool.

The learning system turns real-world situations into plain-language lessons, practical explanations, checklists and practice.

Learn → Understand → Practice → Verify → Act

Cybersecurity is not only about knowing definitions. It is about understanding what is happening well enough to make a safer decision when something unexpected happens.

That is why the VERIFY BEFORE YOU TRUST learning system does more than give short definitions. Each subject should help you understand the meaning of the concept, why it matters, how it appears in real life, what mistakes people commonly make and what verification habit can reduce the risk.

Use these learning topics together with the Knowledge Center, practical tools, simulations, assessments and emergency guidance throughout the platform.

LEARNING CENTER

Choose a topic

Start with the area that is most relevant to the situation you want to understand or improve.

Phishing & malicious links

Understand how attackers use messages, fake websites, urgency, impersonation and malicious links to manipulate people into revealing information or taking unsafe actions.
What will I learn?

Phishing is a form of deception in which someone tries to make you believe that a message, website, email, account notification or request is legitimate when it is not. The objective may be to steal passwords, one-time codes, payment information, identity information or access to an account.

A phishing attempt does not always look obviously fake. Attackers may copy logos, names, language, colours and layouts from banks, technology companies, delivery services, employers or people you know. Some attacks are deliberately designed to create urgency so that you act before checking what you are being asked to do.

The important habit is therefore not simply learning to spot a "strange-looking" message. Learn to verify the sender, destination, request and consequences independently before clicking a link, providing information or approving an action.

Key habit: Never allow urgency, familiarity or a convincing appearance to replace independent verification.

Open →

Payments & POS

Understand how payment fraud happens, why screenshots and verbal confirmations are not proof, and how to verify the final amount, beneficiary and actual transaction.
What will I learn?

Payment security is about verifying what actually happened before you consider a transaction complete. A message saying that a transfer has been made is not the same thing as money actually arriving in the correct account.

Screenshots, SMS messages, receipts and verbal confirmations can be misleading or manipulated. The safest approach is to verify the transaction through the official banking or payment system that actually processed it.

With POS transactions, pay particular attention to the amount shown on the device before authorizing the transaction. Do not approve a transaction merely because someone tells you what amount they entered. Confirm the final amount yourself.

You should also verify who is receiving the money, what the transaction is for and whether the transaction can be reversed if something goes wrong.

Key habit: Verify the actual transaction, not merely the evidence someone presents to you.

Open →

Accounts & identity

Understand passwords, MFA, recovery methods, active sessions, authentication secrets and the steps involved when an account may have been compromised.
What will I learn?

Your online accounts often contain much more than a username and password. Email accounts, financial accounts and social platforms may contain personal information, recovery options, conversations, payment information and connections to other services.

This means account security has several layers. A strong password is important, but it should be supported by appropriate multi-factor authentication, secure recovery methods, protected devices and regular review of active sessions.

Recovery methods deserve particular attention because they can become an alternative route into an account. If an attacker controls a recovery email address, phone number or other recovery mechanism, changing the main password alone may not completely solve the problem.

Key habit: Protect the account, the recovery mechanism and the devices used to access it—not just the password.

Open →

WhatsApp & social engineering

Learn how impersonation, urgency, emotional pressure and trusted relationships can be used to manipulate people into sending money or revealing sensitive information.
What will I learn?

Social engineering attacks target human decision-making rather than relying only on technical weaknesses. An attacker may pretend to be a relative, friend, colleague, customer, bank representative or another trusted person.

A common pattern is urgency: "I need this immediately", "my phone is broken", "send this code", or "please transfer the money now." The pressure is intended to stop you from performing the verification that you would normally perform.

A familiar profile picture, name or telephone number should not be treated as proof of identity. Accounts can be compromised, impersonated or manipulated.

When a request involves money, authentication codes, passwords, account access or other sensitive information, verify the person's identity through a separate trusted channel.

Key habit: Verify the person independently before trusting the request.

Open →

Crypto security

Understand recovery phrases, wallet access, transaction addresses, networks, token visibility and the consequences of irreversible blockchain transactions.
What will I learn?

Cryptocurrency security is different from ordinary account security because control of the wallet may depend on cryptographic keys or a recovery phrase. Whoever obtains the necessary secret may be able to control the associated assets.

A recovery phrase should therefore be treated as a master secret. It should never be entered into a website, sent through a chat or given to someone claiming to be customer support.

Transactions also require careful verification. Before sending an asset, check the destination address, asset, amount and network. Blockchain transactions can be difficult or impossible to reverse once confirmed.

Some wallet problems are not necessarily evidence that funds have disappeared. Incorrect network configuration, unsupported tokens or wallet interface issues can sometimes make assets appear to be missing even though the blockchain record still exists.

Key habit: Verify the secret, address, asset, network and transaction independently before committing an irreversible action.

Open →

Business security

Understand practical controls such as roles, least privilege, payment approvals, backups, account management and secure employee offboarding.
What will I learn?

Business cybersecurity is not only about buying security software. Many incidents occur because organisations have weak processes, excessive access privileges, poor payment controls or accounts that remain active after people leave.

A strong business security system gives people only the access they need to perform their responsibilities. Sensitive actions such as payments, account changes and access to important systems should have appropriate approval and verification processes.

Backups are also important because security incidents can involve data loss, ransomware, accidental deletion or compromised systems. A backup that has never been tested should not automatically be assumed to be reliable.

Employee onboarding and offboarding are equally important. When someone's responsibilities change or their employment ends, their access should be reviewed and removed where appropriate.

Key habit: Build security into the organisation's everyday processes rather than treating it as a separate technical activity.

Open →

Emergency response

Know what to do when something has already gone wrong, including scams, compromised accounts, exposed credentials, lost devices and suspicious transactions.
What will I learn?

When an incident has already happened, the objective is not to solve everything immediately. The first objective is to prevent the situation from becoming worse.

Stop the suspicious activity, preserve useful evidence and secure the affected account, device, payment method or service through its legitimate recovery and security controls.

Be especially careful of secondary scams. Someone may contact you after the original incident and claim that they can recover your money, unlock your account or investigate the attacker. Never assume that someone is legitimate simply because they know details about the original incident.

Key habit: STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE.

Open →

Evidence & lawful reporting

Learn how to preserve useful evidence and report incidents responsibly without hacking, threatening, doxxing or attempting unlawful tracking.
What will I learn?

When something goes wrong, useful evidence can help banks, service providers, platforms, investigators or other appropriate authorities understand what happened.

Depending on the situation, useful information may include transaction references, receipts, messages, email information, usernames, telephone numbers, website addresses, timestamps and screenshots.

Preserve information before deleting conversations, resetting a device or making changes that could remove useful evidence. At the same time, avoid taking matters into your own hands by hacking an account, threatening a suspected scammer, publishing someone's personal information or attempting unlawful tracking.

Key habit: Preserve what you know, document what happened and use legitimate reporting and investigative channels.

Open →
Do not stop at recognition.

Recognizing a suspicious message is useful, but understanding why it is suspicious is more powerful. The more you understand the underlying principle, the easier it becomes to recognize a new variation of the same threat.

For example, a scammer may change the name, logo, telephone number, website or story. The surface details may change, but the underlying manipulation may remain the same: urgency, authority, fear, familiarity, reward or pressure designed to make you act without verification.

Learn the principle rather than memorizing one particular scam. That is how cybersecurity knowledge becomes transferable to new situations.

Make the lesson practical.

After learning a concept, use the relevant simulation or security tool to practice it. When you encounter a real situation, apply the same verification habit before acting.

If you encounter a situation that is not covered by the available lessons, do not guess when the decision could affect your money, identity, account access, device or sensitive information. Use the appropriate guidance or consultancy channel.

VERIFY BEFORE YOU TRUST.