The network, connection and website are different
On a public network, you may not know who runs the equipment. However, public Wi-Fi does not automatically mean other users can see all your information: HTTPS encrypts the connection between the browser and website.
HTTPS does not establish that a website is honest. A fraudulent site can have an encrypted connection too. Check the address and whether the request makes sense, as well as the connection’s protection; our domain-checking guide provides detailed steps.
Before entering information
- Check the exact network name with staff. A similar or familiar name alone does not establish who runs it.
- For banking, use the official app or known bank address. If you cannot verify the network, switch to mobile data or postpone the sensitive task.
- Do not bypass browser certificate warnings. Do not install unfamiliar programs or profiles to get Wi-Fi access.
- Disable unnecessary file sharing and keep the system, apps and browser updated.
What a VPN and 2FA can add
A VPN encrypts traffic between your device and the VPN service. It does not make a fake website trustworthy or stop its operator reading information you submit. For a work device, follow your organisation’s network and VPN requirements.
Two-factor authentication adds protection for account access. It does not protect card details you enter on a fake site.
If you have already shared information
Stop using the suspicious page. From a trusted device and connection, change an exposed password and check the account using the recovery guide. If you entered banking information or approved a suspicious payment, call your bank immediately on an official number.
If you installed unfamiliar software or allowed device access, follow device recovery steps. Record the time, network name and page address without reopening suspicious content.