How can we assess a suspicious message?

Phishing messages can arrive by email, text message or social media. They may look like an account alert, a delivery notification or a payment request. A professional appearance alone does not make a message trustworthy.

1. Is this something you were expecting?

Alerts unrelated to an action you actually initiated deserve extra attention. Even if you are expecting a delivery, check the order through your own account.

2. Where does the link lead?

The text you see and the actual address may be different. Checking the address is useful, but it is not enough on its own. Check your account by typing the service’s address yourself or opening its installed app.

3. What are you being asked to do?

Requests for a password, a verification code, payment information or an unexpected file download are warning signs. When a request creates a sense of urgency, pause to verify it.

4. If you find it suspicious

Report the message through the service’s reporting channel. If you entered account information, change your password on the service’s genuine website and enable multi-factor authentication.

Further reading

CISA · Secure Our World

Similar Posts