Learning in practice · about 5 minutes
Practice: suspicious messages
Practice the next step in six daily situations. Each answer has an explanation; you can skip the question and come back to it later.
Messages and addresses are fictional. This exercise, not your account security assessment. The result and answers remain only on the open page.
Answers: 0 out of 6.
Situation 1 of 6 · SMS
Additional payment for the consignment
There's a message coming in with the name of the courier company.
Explanation
A small amount and time pressure may reduce alertness. The form can collect card data or login.
Check the package through a channel you know independently of your SMS. Do not use the contact details provided in this message.
HTTPS protects the connection to the displayed host. It does not confirm who sent the message or whether the payment is true.
The amount, sender name and HTTPS shall not replace an independent verification of the request.
How to check suspicious message →See the proposed step and explanation
I will open a well-known application or carrier page.
Check the package through a channel you know independently of your SMS. Do not use the contact details provided in this message.
The amount, sender name and HTTPS shall not replace an independent verification of the request.
How to check suspicious message →Situation 2 of 6 · Phone call
Code for ‘support’
You're not starting any login right now. A person claiming support calls for a code.
Explanation
Do not share caller login codes. Use your own open application or known service contact details.
Knowing the name does not confirm the identity of the caller. The code can allow someone to complete the login.
Do not reveal any part of the secret. This is not a method to confirm the identity of the support.
The code confirms your login operation; it is not information to be given to the contact person.
How to use the second ingredient →See the proposed step and explanation
I won't give you the code, I'll finish the call and check the account through the official channel.
Do not share caller login codes. Use your own open application or known service contact details.
The code confirms your login operation; it is not information to be given to the contact person.
How to use the second ingredient →Situation 3 of 6 · E-mail
New Account Number
A new account number appears in the existing cooperation thread. The message is written correctly.
Explanation
If the sender's account has been taken over, the answer can be sent to the same person who sent the request.
The history of the conversation and the correct language do not guarantee that the new request has been sent by a qualified person.
Use the data you have from previous, verified cooperation. When you pay, apply the approval rules in force in your organization.
A trusted thread can be used for a new, unauthorized request. Confirm unusual changes independently.
Subtitling in conversations and chat →See the proposed step and explanation
I will confirm the change by a previously known number or other independent channel.
Use the data you have from previous, verified cooperation. When you pay, apply the approval rules in force in your organization.
A trusted thread can be used for a new, unauthorized request. Confirm unusual changes independently.
Subtitling in conversations and chat →Situation 4 of 6 · Notification of the application 2FA
Unexpected Confirmation
You're putting the phone down, and there are other requests for login that you don't start.
Explanation
Acceptance may allow foreign login. The number of notifications does not change this risk.
Do not approve login that you do not start. Check the sessions, password and access methods in the settings of the known application.
Removing an application does not remove a foreign session or password disclosed; it may also make it difficult to regain your own access.
An unexpected approval request requires checking your account. Do not approve it for peace of mind.
Response to unexpected notification 2FA →See the proposed step and explanation
I'll turn down the request and review the security of the account myself.
Do not approve login that you do not start. Check the sessions, password and access methods in the settings of the known application.
An unexpected approval request requires checking your account. Do not approve it for peace of mind.
Response to unexpected notification 2FA →Situation 5 of 6 · Link in message
Service name before @
The sender asks you to log in again. In the address shown, you can see a familiar name.
Explanation
The text before @ is part of the user's data in URL, not host.
The position of a familiar name at first does not specify host. In this URL host starts after the @ character.
The host is a session.invalid. Do not open the address to check this out: its ingredients can be read in the local URL inspector.
Read the full host, not just a familiar passage of the text. This is still not a review of the site's reputation.
How to read URL →See the proposed step and explanation
session.invalid
The host is a session.invalid. Do not open the address to check this out: its ingredients can be read in the local URL inspector.
Read the full host, not just a familiar passage of the text. This is still not a review of the site's reputation.
How to read URL →Situation 6 of 6 · E-mail information
Notification after your shift
Just a moment ago you add passkey yourself to the settings of the known application. Now you get information about the change.
Explanation
You can confirm your account balance on your own. You do not have to consider every message a fraud or log in through an email link.
The compatibility of one message with your action does not guarantee the authenticity of any further requests.
The notification does not require the password to be released. Do not share secrets in response to the message.
Evaluate context and request. Confirmation in a known application provides a better basis than the e-mail appearance itself.
Login with passkey in practice →See the proposed step and explanation
I'll check the change in a known application; time and action compatibility is a helpful context.
You can confirm your account balance on your own. You do not have to consider every message a fraud or log in through an email link.
Evaluate context and request. Confirmation in a known application provides a better basis than the e-mail appearance itself.
Login with passkey in practice →Summary of exercises
This result only describes the answers to examples. It does not confirm resistance to phishing or account security.
It's worth practicing.
- Additional shipping: How to check suspicious message
- Code for ‘support’: How to use the second ingredient
- New account number: impersonating in conversations and chat
- Unexpected confirmation: Response to unexpected 2FA notification
- Service name before @: How to read URL
- Notification after your change: Logging in with passkey in practice
In these examples, all the proposed steps have been selected. In the real situation, continue to check the request through an independent channel.
What are the exercises based on?
Examples are original. The rules for checking requests, protecting codes and reading addresses describe the sources below.
- NIST — phishing and independent verification of requests
- FTC — recognition and avoidance of phishing
- OWASP — Restrictions and Attacks on MFA
- WHATWG — URL components
Do you have a real suspicious message now? Go to Action Plan →