A convincing phish may use your name, a familiar logo, polished language, or even a compromised conversation thread. Spelling mistakes are therefore a weak test. A stronger habit is to separate the decision from the message: pause, identify the request, then reach the organisation through an app, bookmark, or number you already trust. Easy Guide checked the official guidance below on 7 August 2026; local reporting channels can change.
Stop the response, not the investigation
Do not click just to see what happens, open an attachment, scan a QR code, or reply “stop.” Take a screenshot if you may need to report it, then pause for a minute. You do not need to prove the message is fake; you need to prevent it from controlling the speed and route of your decision.
Extract the story and the ask
State the claim, requested action, and deadline in plain words. Common hooks include a locked account, delivery fee, toll or fine, refund, unfamiliar invoice, executive request, or relative needing a secret transfer. Urgency, fear, reward, and secrecy are not proof by themselves, but they are enough to trigger independent verification.
Inspect identity and destination without interacting
Display names and logos are easy to copy. Expand the full sender address and check the domain character by character; on desktop, hover over a link without clicking. On mobile, avoid a long press if your device automatically previews links. Treat a QR code as a hidden link, and remember that a padlock or https only describes encryption—not who owns the site.
Leave the message and use a route you already know
Close it and open the bank or service app yourself, use a saved bookmark, or call the number on a card or previous statement. For a colleague or relative, call a saved number and ask a question outside the same chat. Do not verify through the message’s link, phone number, or an unverified search advertisement.
Treat approval codes like signatures
Never send a password, PIN, card security code, one-time login code, or approve a sign-in you did not start. Read the code’s wording: if it authorises a login, new device, or payment, it is not a harmless “verification code for the agent.” Do not install remote-control software or share your screen because of an unexpected call.
If you did not interact: report, block, delete
Use the service’s phishing or junk control, alert the impersonated organisation through its real channel, then block and delete. At work, report it through the security process before deletion. Reporting gives providers indicators they can use to disrupt similar campaigns.
If you interacted: respond to what was exposed
For a password, go directly to the real service, change it, sign out other sessions, and change any reused copy. For card details or a transfer, call the bank or issuer immediately to block the instrument and review activity. For an installed file or app, disconnect if compromise is suspected and follow your organisation’s or device provider’s incident steps; preserve the message, URL, time, and receipts first.
Make the next attempt harder
Turn on automatic updates and transaction alerts, use unique passwords or passkeys, and enable the strongest multi-factor option the account supports. Agree on a family verification word for emergency money requests and a second business channel for payment-detail changes. These layers do not replace judgment, but they buy time and make recovery easier.
The rule worth remembering
Do not complete a financial or account decision inside an unexpected message. Leave it, then initiate contact through a separate route you already trust.
Official sources checked
Checked 7 August 2026. Use the current reporting route for your bank, employer, and local authority.
Optional affiliate link
One tool that can add a protective layer
It is not required for this guide. Confirm that your important accounts and devices support FIDO2 or physical security keys, and plan a recovery or spare-key route before buying.
As an Amazon Associate I earn from qualifying purchases.
FIDO2-compatible physical security key
It can provide stronger, more phishing-resistant authentication for services that support it. Match USB or NFC connectivity to your devices and follow each service’s official recovery instructions.
Browse general options on Amazon.sa