Staying Safe Online: Scams, Passwords and 2FA Phishing: Spotting the Fake
1 / 5
Next
Phishing: Spotting the Fake ~14min

The shape of every phishing message

  1. Urgency. "your account will be closed today"
  2. A link to a page that looks exactly right
  3. A request for something, password, PIN, OTP, card number

Urgency exists to stop you thinking. Once you notice that, most of these fall apart.

Check the actual address

Hover a link before clicking; the real destination appears at the bottom of the browser. Read it right to left. The domain is what sits immediately before the first single slash.

  • safaricom.co.ke.login-secure.tk. The real domain is login-secure.tk
  • merikagency.com.verify.xyz. The real domain is verify.xyz

The absolute rule

No bank, no mobile money service and no legitimate company will EVER ask for your PIN or OTP. Not by SMS, not by call, not by email. Anyone who asks is stealing from you, including someone who says they are from customer care and knows your name.

Fake payment confirmations

An SMS saying money was sent is text; anyone can craft it. Confirm the balance in the app or by USSD before releasing goods. This is one of the most common scams in Kenyan trade.

When unsure, go the other way

Do not use the link. Type the address yourself, or call the number printed on your card. That single habit defeats nearly every phishing attempt.

Tasks
Preview