Staying safe

Phishing and fake messages

How phishing works on SMS, WhatsApp, and email: the disguises, the fake links and login pages, and the checks that expose them.

Phishing is impersonation with a delivery mechanism: a message dressed as your bank, your mobile operator, your payment app, or a government office, engineered to make you hand over the keys yourself. It succeeds not against careless people but against busy ones — the entire craft is making one dangerous tap feel routine.

The anatomy of the message

  • A trusted costume: sender names and message headers can be spoofed or made near-identical — a name you recognise proves nothing about who sent it.
  • A plausible emergency: your account is "suspended", a payment "failed", a package is "held", a refund is "waiting". Fear and free money are the two engines; both demand action now.
  • A link or a number: the message never wants conversation — it wants you on a page it controls or a call it controls.
  • The harvest: a login page that looks perfect and exists to record what you type, or a warm voice walking you through "verification" — passwords, PINs, and the one-time codes arriving on your phone.

The checks that expose it

  1. Never travel by the message's road. If your bank, operator, or app claims a problem, open the real app yourself or type the address you already know. Genuine problems will be visible there; phantom ones will not.
  2. Read links before touching them — and treat look-alike spellings, extra words, and unfamiliar endings as the forgeries they are. On a phone, when unsure, simply do not tap: no legitimate process dies because you went through the front door instead.
  3. Apply the never-asked rule: real institutions do not ask for your PIN, password, or one-time codes by message or call. Kit Pay's version of that promise is written down in what support will never ask, and any message breaking it has identified itself.
  4. Let urgency itself be the alarm. "Within 24 hours or your account closes" is not how systems talk; it is how scripts talk.

Phishing also arrives as apps — a fake "update" or look-alike download that is the login page in costume, which is why installing only from official stores matters. If a message succeeded before you recognised it, move fast: change the exposed password, and treat it as a live incident — helping someone who was scammed lists the order of operations.

Frequently asked questions

The message came in a thread with real messages from my provider. How?

Sender identity on SMS can be forged, and forged messages can land in the genuine thread. Threading is decoration, not authentication — judge the message by what it asks, not where it sits.

I tapped the link but entered nothing. Am I safe?

Usually the harvest needs your input, so entering nothing is the save. Close the page, do not return to it, and if anything was typed — even partially — change that credential now from the real app or site.