Phishing
Phishing is a method in which an attacker behaves like a trusted institution or person in order to persuade you to hand over data such as passwords and card details yourself. It targets human trust rather than a technical hole.
| In brief | Phishing is a fraud in which someone poses as a trusted institution or person in order to persuade you to share data such as passwords and card details. |
|---|---|
| How it works |
|
| Warning signs |
|
| How to protect yourself |
|
| If it happens to you |
|
Why does it still work?
Phishing messages make skilful use of two feelings: haste and fear. Messages such as 'your account will be closed', 'a suspicious sign-in has been detected' or 'your payment will be refunded' aim to produce a tap before there is time to think. Because the messages imitate genuine institutional templates and can be decorated with personal details such as your name or a recent purchase, appearance has stopped being a measure of trustworthiness.
The soundest habit
A single habit renders the great majority of phishing attempts ineffective: signing in by opening the application or the site yourself rather than by tapping a link in a message. If your bank really does want to reach you, you will see the message in the application's own notification area as well. Following this route with every message that hurries you reduces the whole burden of decision to one rule.
What institutions ask for, and what they never ask for
No bank or official body asks you by message or by telephone for your password, all the details of your card, or the approval code sent to your phone. Being asked for that information is proof enough about who you are dealing with. In cases of doubt you can verify by calling the institution's official call centre yourself; the Account Takeover record complements this with safe account habits.
Related terms: Fake Text Messages, Account Takeover, Malware