Staying safe
Phishing and fake messages
How phishing works on SMS, WhatsApp, and email: the disguises, the fake links and login pages, and the checks that expose them.
Phishing is impersonation with a delivery mechanism: a message dressed as your bank, your mobile operator, your payment app, or a government office, engineered to make you hand over the keys yourself. It succeeds not against careless people but against busy ones — the entire craft is making one dangerous tap feel routine.
The anatomy of the message
- A trusted costume: sender names and message headers can be spoofed or made near-identical — a name you recognise proves nothing about who sent it.
- A plausible emergency: your account is "suspended", a payment "failed", a package is "held", a refund is "waiting". Fear and free money are the two engines; both demand action now.
- A link or a number: the message never wants conversation — it wants you on a page it controls or a call it controls.
- The harvest: a login page that looks perfect and exists to record what you type, or a warm voice walking you through "verification" — passwords, PINs, and the one-time codes arriving on your phone.
The checks that expose it
- Never travel by the message's road. If your bank, operator, or app claims a problem, open the real app yourself or type the address you already know. Genuine problems will be visible there; phantom ones will not.
- Read links before touching them — and treat look-alike spellings, extra words, and unfamiliar endings as the forgeries they are. On a phone, when unsure, simply do not tap: no legitimate process dies because you went through the front door instead.
- Apply the never-asked rule: real institutions do not ask for your PIN, password, or one-time codes by message or call. Kit Pay's version of that promise is written down in what support will never ask, and any message breaking it has identified itself.
- Let urgency itself be the alarm. "Within 24 hours or your account closes" is not how systems talk; it is how scripts talk.
Phishing also arrives as apps — a fake "update" or look-alike download that is the login page in costume, which is why installing only from official stores matters. If a message succeeded before you recognised it, move fast: change the exposed password, and treat it as a live incident — helping someone who was scammed lists the order of operations.
Frequently asked questions
The message came in a thread with real messages from my provider. How?
Sender identity on SMS can be forged, and forged messages can land in the genuine thread. Threading is decoration, not authentication — judge the message by what it asks, not where it sits.
I tapped the link but entered nothing. Am I safe?
Usually the harvest needs your input, so entering nothing is the save. Close the page, do not return to it, and if anything was typed — even partially — change that credential now from the real app or site.