Look for pressure, then pause
Messages that claim an account will close, a parcel is stuck, a payment failed, or a prize expires may be legitimate—or may be designed to rush you. Urgency alone does not prove a message is fraudulent. Treat it as a reason to verify independently.
- Be cautious of unexpected requests for passwords, one-time codes, card details, or remote access.
- Check whether the sender address and linked web address match the organization’s real domain. A familiar logo or display name is not proof.
- Watch for unusual payment methods, secrecy, threats, or instructions to move a conversation to another app.
- Don’t open attachments or install apps you weren’t expecting.
Verify using a route you find yourself
Open the organization’s official app, type its known website address yourself, or call a number printed on a card or statement. Ask whether the request is real. Do not rely on a link, number, or contact suggestion supplied by the message.
If you already clicked or replied
- If you entered a password, change it through the official site or app. Change it anywhere else you reused it, and turn on multifactor authentication if available.
- If you shared a payment or banking detail, contact your bank or payment provider promptly using a trusted contact route.
- If you installed something, stop using sensitive accounts on that device and seek help from the device maker or a trusted technician.
- Keep the message and note what happened. Use your local consumer-protection or cybercrime reporting channel to report it.
Don’t feel embarrassed. Scams are built to manipulate normal reactions. Acting quickly to limit further access can help.
More help from official sources
- CISA: Recognize and report phishing (United States cybersecurity agency)
- FTC: How to recognize and avoid phishing scams (United States consumer guidance)
Scambaba is an independent educational project and is not affiliated with these organizations. Guidance may vary by country and service.