Why it got harder
AI writes flawless messages in any language, copies the style of your bank or courier and personalises them with data from social networks. The old advice “look for bad grammar” no longer protects you — you must check where a message really comes from and what it asks you to do.
The three questions
- Does it want me to act fast? (account blocked, parcel waiting, fine due today)
- Does it want me to click, log in, pay or share a code?
- Did I expect it — and would the real sender ask this way?
Check the real sender and link
Look at the full email address, not just the display name. Hover over a link (or long-press on a phone) and read the domain from right to left: posta.si.secure-login.com belongs to secure-login.com, not to Pošta. When in doubt, don’t click — open the app or type the address yourself.
QR codes and SMS
Fake QR stickers on parking meters and chargers, or QR codes in emails, lead to fake payment pages (quishing). SMS messages about parcels, tolls or tax refunds are a classic. Real institutions don’t ask you to enter card details via a link in an SMS.
Never share these
- One-time codes (SMS or app) — nobody legitimate asks for them
- Card numbers with CVV via a link
- Remote access to your computer (AnyDesk, TeamViewer) for an unknown “technician”
- Your online banking login