Pathwise

Stay Safe Online · Lesson 4 of 12 · 12 min

Phishing: the message that wants you to hurry

Recognise the recipe behind almost every phishing message, read a link to see who really owns it, and use the one habit that beats even perfect fakes: going around the link.

Phishing

NOUN · SECURITY

A message that pretends to come from someone you trust, to get you to click, log in, pay or share a code. It can arrive by email, SMS, a messaging app or a phone call. The goal is always an action that hands the attacker something: a password, a card number, a code, or a way onto your phone.

An email "from your bank" asking you to confirm your details, an SMS about a parcel waiting for a fee, a DM from a "brand" saying you've won a prize.

THE RECIPE

Trusted name + strong feeling + a quick action

Almost every phishing message mixes three things. A name you trust (your bank, a delivery company, a friend). A strong feeling: fear, urgency, excitement or curiosity. And a quick action: click, log in, pay, send the code. The feeling is the engine. It's there to make you act before you think.

"Your account will be blocked in 2 hours. Verify now." Trusted name: the bank. Feeling: fear plus a deadline. Action: tap and log in. When you notice all three together, slow down.

Check yourself

Sina gets an email: "Your Instagram account will be deleted within 24 hours for copyright violation. If this is a mistake, appeal here." It has the Instagram logo and a neat layout. What is the strongest warning sign?

  1. It's written in English, even though his Instagram is set to Persian
  2. It pushes him to log in through a link before a tight deadline
  3. It includes the Instagram logo in the header
  4. The email has no spelling mistakes
Show the answer

It pushes him to log in through a link before a tight deadline

Right. A deadline plus "log in here" is the recipe. Logos and neat layouts are free to copy, so they prove nothing either way.

READ THE LINK

Who really owns this address?

Look at the part of the address between https:// and the first single /. Read it from the right. The owner is the name just before the ending (.com, .ir, .co.ir and so on). Anything to the left of that name is a label the owner can set to anything, including your bank's name. On a phone, long-press a link to see its address without opening it.

Take a made-up bank, Sepid Bank, at sepidbank.ir. The address sepidbank.ir.secure-login24.com belongs to secure-login24.com. The bank's name on the left is just decoration.

The real site of the made-up Sepid Bank is sepidbank.ir

https://sepidbank.ir/login                  owner: sepidbank.ir
https://ib.sepidbank.ir/accounts            owner: sepidbank.ir
https://sepidbank.ir.secure-login24.com/    owner: secure-login24.com
https://sepidbank-ir.com/login              owner: sepidbank-ir.com
https://sepldbank.ir/login                  owner: sepldbank.ir (l, not i)

Output

Only the first two belong to the bank.

A subdomain like ib. is fine as long as the name right before the ending is the real one.

Check yourself

The real site is sepidbank.ir. Match each link to its true owner

Show the answer
  • https://pay.sepidbank.ir/card → The real bank
  • https://sepidbank.ir.verify-now-account.net/ → verify-now-account.net
  • https://sepidbank-support.com/ → sepidbank-support.com
  • https://sepidbamk.ir/login → A look-alike with m instead of n

THE HABIT

Go around the link

Reading links is useful, but good fakes can be hard to spot on a small screen. So here's the habit that works every time: don't use the link or number in the message. Open the official app, type the address you know, or use a saved bookmark. If there's really a problem with your account, you'll see it there too.

An SMS says your bank card is blocked. Instead of tapping the link, Ava opens her bank app. Everything is normal, so the SMS was fake, and she never had to decide whether the link looked right.

Check yourself

An email addresses Omid by his full name and mentions the exact order number of a phone case he bought last week. It asks him to re-enter his card details because the payment "failed". Since it knows his order number, it must be genuine.

Show the answer

False

False. Order details can come from a leak at the shop, a delivery company or a shared screenshot. The request is what matters: re-entering card details through an email link is exactly what phishing wants. He should check the order in the shop's own app or site.

Signs worth a second look

  • A deadline or threat: blocked, deleted, fined, "within 24 hours".
  • A request for a password, card details, a one-time code or a payment.
  • A link whose owner (the name before the ending) isn't the company it claims to be.
  • An attachment or app file you didn't expect, especially one you're told to install.
  • A prize, refund or offer you never entered for. Note: good fakes may have none of the typos people expect.

Check yourself

Safe to act on as it is, or go around the link?

  • SMS: "Your parcel is held, pay the customs fee here"
  • You typed your bank's address yourself and are logging in
  • Email: "Unusual login, confirm your password here"
  • A reset email arrives just after you tapped "forgot password" yourself
  • DM: "You won a phone! Enter your card to pay shipping"
Show the answer

Go around it: check another way: SMS: "Your parcel is held, pay the customs fee here", Email: "Unusual login, confirm your password here", DM: "You won a phone! Enter your card to pay shipping"

Fine as it is: You typed your bank's address yourself and are logging in, A reset email arrives just after you tapped "forgot password" yourself

Lesson recap

  • Phishing mixes a trusted name, a strong feeling and a quick action.
  • A link's owner is the name just before the ending, right before the first single slash.
  • The habit that always works: go around the link and use the official app or a typed address.
  • Messages that know your details can still be fake; judge them by what they ask for.

Keep it, don't just read it

Pathwise brings each idea back just before you'd forget it, with a quick question. Free on Android and on the web, in English and Persian.

Cafe Bazaar Myket Open the web app

All lessons in this course

  1. How accounts really get taken
  2. Strong passwords you don't have to remember
  3. Two-step login: a stolen password isn't enough
  4. Phishing: the message that wants you to hurry
  5. Fake pages, fake payment gates and fake apps
  6. SMS, call and messenger scams
  7. Pay without handing over your card
  8. Public Wi-Fi and your home network
  9. Share less, on purpose
  10. Stop pressing "later"
  11. Backups: the 3-2-1 rule
  12. If you get hacked: the first hour