Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

Break the pressure, then verify the request

Learn what to do when a caller or text pressures you to disclose a code, share information or send money.

Individuals and financial service usersAbout 5 minutes of reading + 3 questions
Start with the example Have you already acted on the request?

What you will learn

  • Recognise smishing and vishing in everyday situations.
  • Verify identity without using contact details from the suspicious message.
  • Choose the first response if you have already shared information or money.

Practice example

Is this really a message from your bank?

BANK
Today, 09:41

Your card will be blocked today. Confirm your details now: bank-check.example

Fictional message and inactive address for practice.
Show the example explanation
Threat and short deadline
Pressure is meant to reduce the time available for verification.
The sender name looks familiar
A displayed name or number can be spoofed and is not sufficient proof of identity.
The link controls the check
Open the bank app you already use or call a number you found independently.

What are smishing and vishing?

Smishing is phishing by text message; vishing is fraud by phone call. A message may mention a missed delivery, blocked account, prize or debt. A caller may claim to be a bank, police officer, technical support agent or family member.

The pattern matters more than the story: unexpected contact, pressure and a request to disclose a secret, open a link, install an app or send money.

What does not prove identity?

  • the displayed bank name or familiar phone number;
  • personal information that could have been found online;
  • polished language, a logo or placement in an existing message thread;
  • a claim that you must stay on the line to “protect the account”.

Do not give a caller your PIN, password or one-time code. Read the full bank notification and check what action it authorises.

Verify the request

  1. End the call or close the message without opening its link.
  2. Find the contact yourself: use a known app, type the official address, or use the number printed on your card or listed on the official site.
  3. Verify the specific request. If someone claims to be a relative, call a number you already have or contact another family member.
  4. Do not let the caller prevent you from checking separately.

If you have already acted

  • If you shared banking information or a code, or approved a payment, contact your bank immediately through a verified channel.
  • If you disclosed a password, change it from a trusted device and end unknown sessions; replace it anywhere else it was reused.
  • If you installed an app or granted screen access, disconnect the device and follow the suspicious app guide.
  • Preserve the message, number, time, payment details and a short note about the call. Do not delay your first bank contact while gathering every item.

You can also report the incident to FIN-CSIRT. Reporting does not replace contacting the bank to protect the account.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

A caller says a relative urgently needs money. What do you do first?

Why does this matter? Urgency and emotion can make you send money before checking the story.

  1. Send a smaller amount because it is urgent.

    A smaller amount is still a payment to an unverified person.

  2. Hang up and contact the relative using a number I already know.Correct answer

    Independent contact removes the caller from the verification process.

  3. Ask the caller for bank details as proof.

    Payment details do not prove identity or the claimed emergency.

A text appears in the same thread as genuine bank messages. Is it safe?

Why does this matter? Technical abuse can make a fraudulent message appear alongside genuine correspondence.

  1. Yes, the message thread proves the sender.

    Placement in a thread is not independent proof of the sender.

  2. Yes, if there are no spelling mistakes.

    A well-written message can still be fraudulent.

  3. No; I verify the request in a known app or through an official number.Correct answer

    A known channel verifies the request without using the text message link.

You read a one-time code to someone claiming to be your bank. What next?

Why does this matter? The code may already have been used, so no visible transaction is not a reason to wait.

  1. Contact the bank immediately through an official channel and explain what I shared.Correct answer

    The bank can assess the exposed access or payment and recommend protective action.

  2. Wait for the monthly statement.

    Waiting leaves more time for possible misuse.

  3. Call the same displayed number again.

    Calling the same unverified number is not an independent check.

No registration. Your answers are not sent; the result is just for you.

Hang up. Find the number. Verify.

Never share a PIN, password or one-time code with someone who contacts you unexpectedly.

Contact your bank safely

References

Sources and further reading

The patterns and protective steps follow the Serbian National CERT’s guide to smishing and the development of SMS scams and its phishing recognition guidance. Examples are fictional and designed for practice.

Content last reviewed