Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Protect the app, device and every approval

Prepare the phone so a lost device or fraudulent request does not become access to your account.

Mobile banking usersAbout 6 minutes of reading + 3 questions
Start with the example Lost phone or suspicious payment?

What you will learn

  • Prepare a phone for safer mobile banking.
  • Check the payee, amount and purpose before approval.
  • Respond to a lost phone or unexpected authorisation.

Practice example

An approval you did not initiate

Banking app
Today, 09:41

Approve a payment of RSD 48,900. You do not recognise the payee.

Fictional situation for practice.
Show the example explanation
You did not start the action
Reject the request; repetition is not a reason to approve it.
Unknown payee
Do not confirm merely because the request appears in the genuine app.
Prompt response is needed
Use known bank contact details and report the unexpected authorisation.

Prepare the device before the first payment

  • Use a screen lock that is difficult to guess. Enable biometrics if suitable, with a strong fallback code.
  • Install the banking app through the bank’s official website and an authorised app store.
  • Keep the operating system and app updated. Avoid sensitive activity on a device that no longer receives security fixes when a safer option is available.
  • Enable transaction alerts if offered. They help early detection but do not replace reviewing account activity.
  • Do not keep a PIN or password in an unprotected note on the same phone.

Check before every approval

Read the amount, currency, payee and purpose. Approve only an action you initiated. If a caller guides you through “cancelling” a payment or asks for a code, end the call and contact the bank yourself.

Receiving money does not require you to disclose a PIN, card security code, banking password or one-time code to a stranger.

Choose the connection and context

Use mobile data or a network you trust when you cannot verify public Wi-Fi. Encryption helps protect data in transit, but you must still use the genuine app or site and a device you control. Do not bank while an unknown person can view or remotely operate the screen.

If the phone is lost or payment is suspicious

  1. Contact the bank immediately using a verified number. Explain whether the phone was unlocked and whether you saw an unknown payment or approval.
  2. Contact the mobile operator about the SIM and use the device provider’s lost-device controls if already enabled.
  3. From a trusted device, protect the email and other accounts used for recovery. Follow the bank’s instructions before changing banking access.
  4. Preserve transaction details and the time the device was lost. Report theft to the relevant authorities where appropriate.

Follow the locating and locking steps for Android or iPhone without delaying contact with the bank and carrier.

Check your knowledge · 3 of 5

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript. Without JavaScript, the full bank of 5 questions is shown.

A request asks you to approve a payment you did not initiate. What do you do?

Why does this matter? Approval may be the final step of someone else's transaction.

  1. Reject it and check the account through the official app or bank.Correct answer

    Rejection prevents your approval and checking identifies possible compromised access.

  2. Approve it to stop the notifications.

    Approval may authorise the unwanted payment.

  3. Let it expire and check nothing.

    Expiry does not explain the request or protect a compromised account.

Which preparation is best for a mobile-banking phone?

Why does this matter? Protection depends on several layers rather than one setting.

  1. A strong screen lock, updates and the official banking app.Correct answer

    These layers reduce unauthorised access and exposure to known flaws.

  2. Only hiding the app icon.

    A hidden icon does not prevent app access.

  3. Turning off all transaction alerts.

    Alerts can help you notice an unknown transaction sooner.

You lose an unlocked phone with a banking app. What is the priority?

Why does this matter? Access to a financial service may be immediately at risk.

  1. Wait a day in case the phone is returned.

    Waiting delays measures that can limit access and misuse.

  2. Contact the bank and mobile operator immediately through verified channels.Correct answer

    The bank and operator can advise on the specific account, app and SIM.

  3. Publish the number publicly so the finder can call.

    Public disclosure may expose more information and does not protect the account.

The app shows an amount and recipient before approval. What should you check?

Why does this matter? Biometrics or a PIN confirm that you approved the displayed action, not that its transaction details are correct.

  1. Only whether the phone recognises my fingerprint.

    Successful biometrics do not verify the payment details.

  2. The amount, recipient and purpose before every approval.Correct answer

    These details determine what your approval will actually execute.

  3. Nothing if the prompt arrived during a call with 'support'.

    A call does not establish the caller's identity or the request's legitimacy.

A phone has returned from repair. What should you check before using mobile banking?

Why does this matter? Repair, resetting or changed settings may affect device protection and connected accounts.

  1. Updates, screen lock, unfamiliar apps and connected accounts.Correct answer

    This covers the main protection layers before accessing a financial service.

  2. Only the speaker volume.

    Volume says nothing about secure configuration.

  3. Whether the bank icon is in the same place.

    Icon position does not establish the app or device integrity.

No registration. Your answers are not sent; the result is just for you.

Approval is the final check, not a formality

Approve only an action you initiated after reading all its details.

Contact your bank safely

References

Sources and further reading

The handling of security codes follows the National Bank of Serbia warning. App guidance follows the Serbian National CERT’s mobile application publication; network advice is expanded in our public Wi-Fi guide.

Content last reviewed