Basic Phishing Red Flags for Newcomers
Phishing tries to steal passwords, OTPs, or card details by impersonating banks, delivery firms, universities, or workplaces. Newcomers often focus on “bad grammar” alone — useful sometimes, but modern scams can look polished. Better signals are urgency, unexpected channels, and links that do not match the real domain.
Classic warning signs
- Threats that your account will close in one hour unless you click now.
- Requests for OTP, PIN, or full card number by email or chat.
- Attachments you did not ask for, especially .apk, .exe, or odd archives.
- Sender addresses that mimic a brand with extra words or numbers.
- Links that show one bank name but open a different domain.
Hover or long-press links before opening. Type the official site yourself when money or login is involved. Banks and major platforms almost never ask you to “confirm your password” via a random SMS link.
What to do if you clicked
Disconnect if possible, change the password from a clean device, enable MFA, and check email forwarding rules. Tell your bank quickly if financial details were entered. Warn family in shared chats — recycled bait often hits multiple people the same day.
Build a habit: slow down when a message makes you feel fear or greed. That pause is the cheapest security tool you own. For study and freelancing accounts, unique passwords plus MFA beat cleverness after the fact.
Phishing defense is pattern recognition, not paranoia. Learn the red flags once, then apply them every time something “urgent” lands in your inbox.