Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

The message looks familiar. Is the request safe?

Learn to check a suspicious message before sharing information or sending money.

Financial services usersAbout 6 minutes of reading + 3 questions
Start with the example Already clicked or shared information?

What you will learn

  • spot pressure and suspicious requests;
  • verify a message through an independent channel;
  • choose a first step if you have already acted.

Practice example

Which warning signs do you notice in this message?

Account notification
Today, 09:41

Your account will be blocked in 30 minutes. Confirm your card details to keep using the service.

Site shown in the message my-bank.example
Safe simulation: the address is not live and does not represent a real bank.
Show the example explanation
A 30-minute deadline
A short deadline creates pressure to act before checking.
A threat to block access
Fear of losing access can distract you from verifying the sender.
A request for card details
Check the request through the official app or a known bank number, without using the message’s link.
An address that sounds familiar
The words “my” and “bank” sound plausible, but the name does not prove that the site belongs to your bank. Do not open it to investigate; use the official app or a contact you already know.

What is behind the message?

Phishing is an attempt to trick you into sharing information, opening harmful content or sending money by impersonating someone you trust. An attacker may pose as your bank, a delivery service or someone you know.

The example above combines a threat to block your account, a short deadline and a request for card details. Your task is to check the request before acting on it.

A familiar logo, signature or well-written message is not enough to confirm who is contacting you.

Why might the message feel personal?

Some messages reach many people. Others target you or your organisation, using a colleague’s name, a familiar supplier or details about your work. This targeted approach is called spear phishing.

Knowing your name does not make a request authentic. Check what you are being asked to do and whether you expected the request.

Where might you encounter phishing?

  • Email: an unexpected invoice, attachment or invitation to sign in again.
  • Texts and messaging apps: a notice about an account restriction, delivery or refund (smishing).
  • Phone calls: someone posing as a bank or support service asks for confidential information (vishing).
  • QR codes: a code leads to a page whose origin you have not checked (quishing).

Three questions before you act

Am I being rushed?

A short deadline and a threat to remove access are intended to make you skip checks. Urgency is a reason to pause, not evidence that you should trust the message.

What exactly am I being asked to do?

Look for requests for passwords, card details, one-time codes, payments or app installations. Do not share sign-in or transaction approval codes with someone requesting them in a message or call.

Can I check this independently?

An address can resemble a familiar one and a sender’s name can be copied. If you are unsure, do not rely on a link or number in the same message to complete your check.

How to verify the request

  1. Pause the action. Do not open an unexpected attachment or enter information through a suspicious link.
  2. Open the service yourself. Use the official app or a website address you already know. If needed, call the number on your card or the bank’s official website.
  3. Check the actual request. For a work message, contact your colleague through another known channel and follow your internal reporting procedure.

Two-factor authentication reduces the risk from a stolen password, but some methods can still be targeted by phishing. Read our 2FA guide.

If you have already clicked or shared information

If card details, your banking account or money are at risk, contact your bank immediately on its official number. Do not wait to finish the quiz or receive a response to an incident report.

What happened Next step
You only opened the page Close it without entering information or downloading anything. Opening a page alone does not mean your account was taken over; if something downloaded or you notice changes, seek a device assessment.
You entered a password From a device you have no reason to suspect is compromised, change the password through the official service, end other sessions and replace the same password on other accounts.
You entered card details or approved a payment Tell your bank immediately what you entered or approved and follow its protective guidance.
You installed software or allowed device access Disconnect the device from the network and seek technical help. For a work device, notify your IT or security team immediately.

Keep the message, page address and time of the event without reopening suspicious content. In a report, describe what happened and the steps you have taken. Do not send passwords, PINs or one-time codes.

Report an incident to FIN-CSIRT · Account recovery help

Check your knowledge · 3 of 5

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript. Without JavaScript, the full bank of 5 questions is shown.

A text says your account will be blocked and includes a link to “confirm your details”. What do you do first?

Why does this matter? A threat of account suspension creates pressure to act quickly. The link may then lead to a form that sends details to an attacker, so a convincing appearance does not resolve the question of its origin.

  1. Open the link and check whether the page has the bank’s logo.

    A logo can be copied. The page’s appearance is not enough; check the request through the official app or a known number. You are checking a visual detail the sender can easily copy rather than the destination that would receive your information.

  2. Open the official app myself or call the bank on a known number.Correct answer

    This separates your check from a channel the attacker may control. Use contact details found independently of the message. This lets you establish whether an account problem actually exists before disclosing any details.

  3. Reply to the text and ask the sender to confirm their identity.

    The same attacker may reply. Use the official app or independently sourced contact details to verify the request. If the attacker controls the message, they can also write a convincing confirmation, leaving the verification loop unbroken.

A colleague sends an unexpected document. The writing and signature look right. What does that tell you?

Why does this matter? Good spelling and a familiar signature build trust, but do not establish a document’s origin. An unexpected attachment can arrive from a real account that has been taken over, which is why the specific request needs checking.

  1. The document is safe because there are no spelling mistakes.

    Convincing writing does not prove authenticity. An attacker can copy a signature or use a compromised account. Good writing does not establish what the attachment contains or what will happen when you open it.

  2. Replying to the same message to ask whether it is theirs is enough.

    If the account is compromised, the attacker may reply. Call your colleague using a known contact. The same channel may remain under someone else’s control, so another message from it does not confirm your colleague’s intention.

  3. I should still check the unexpected request through another known channel.Correct answer

    You are checking the actual request, not just the message’s appearance. For example, call your colleague using the internal directory. A known separate contact gives the real person a chance to confirm that they sent that particular document.

You entered card details on a page linked from a suspicious message. What is the first step?

Why does this matter? Once entered on a fake page, card details may be outside your control. Closing the page or seeing no new transaction does not mean the possibility of misuse has ended.

  1. Contact my bank immediately on its official number and explain what I entered.Correct answer

    Your bank can assess protective measures for the card and account. Keep the message and time of the event; you can report to FIN-CSIRT afterwards. Describing the exposed details helps the bank assess protection against the actual risk without waiting for another charge.

  2. Wait to see whether an unfamiliar transaction appears.

    Waiting delays the opportunity to protect your card. Notify your bank immediately, even if no unfamiliar transaction is visible yet. This would make new harm a condition for acting, although the exposure already warrants checking.

  3. Finish a FIN-CSIRT report before calling my bank.

    A FIN-CSIRT report does not replace urgent contact with your bank to protect your card and account. Contact the bank first. An incident report helps with handling the event, but does not itself initiate card-protection measures at the bank.

Several sign-in or second-factor prompts arrive that you did not initiate. What do you do?

Why does this matter? Repeated prompts may be an attempt to wear you down into approving somebody else's sign-in.

  1. Approve one so the notifications stop.

    Approval may let an attacker complete the sign-in.

  2. Reject them, open the account independently and secure it if suspicious activity appears.Correct answer

    Rejection and an independent check protect the account without trusting the prompt.

  3. Reply to the last notification with my code.

    A code is an access secret and should not be sent in a reply.

You want to report a suspicious message. What should you preserve?

Why does this matter? Content, sender, time and visible destination help assessment without reopening harmful content.

  1. The message, sender details, time and visible link address without clicking it.Correct answer

    These details preserve the context needed for verification and reporting.

  2. Only a picture of the logo.

    A logo can be copied and does not describe the channel or destination.

  3. The password the page requested.

    Passwords should never be included in a report or shared with others.

No registration. Your answers are not sent; the result is just for you.

Pause. Check. Act.

A familiar-looking message does not prove identity. Open the service yourself and verify the request using a contact you already know.

Next: protect your account with 2FA

References

Sources and further reading

The Serbian National CERT phishing guide describes common message patterns, address checks and rapid response. The FTC phishing guide (United States) supplements independent contact checks; US reporting routes are not part of the lesson. Our account recovery guide provides further account steps. The example message and questions were written for practice.

Content last reviewed