Phishing messages imitate trusted organisations to steal passwords, payment details and authentication codes. They may appear to come from your hosting provider, bank, email service, courier company or government agency.

A phishing email often claims that your account has been suspended, a payment has failed or urgent verification is required. Its link then opens a convincing copy of a genuine login page.

How to recognise phishing

Look carefully for:

  • An unfamiliar or misspelled sender address

  • Links that do not lead to the organisation’s real domain

  • Unexpected attachments

  • Threats of immediate account suspension

  • Requests for passwords or authentication codes

  • Poor spelling, unusual formatting or generic greetings

  • Login prompts you were not expecting

Never approve an unexpected MFA request

Multi-factor authentication provides valuable protection, but it should not be approved automatically.

If you receive a login notification or approval request that you did not initiate, reject it. An attacker may already have your password and be waiting for you to approve their login.

Never tell another person the security code displayed by your authentication app or sent to your telephone.

Safer ways to access your account

Instead of following a link in an unexpected message:

  1. Close the message.

  2. Open a fresh browser window.

  3. Type the organisation’s address yourself or use a trusted bookmark.

  4. Sign in and check for notifications inside the account.

Use a password manager to create a different password for each service. Where supported, passkeys provide additional protection against fake login pages.

If you entered your password on a suspicious page

Change the affected password immediately from a trusted device. Sign out other active sessions and inspect the account’s recovery details, forwarding rules and authorised applications.

If the same password was used elsewhere, change those accounts as well. Contact your bank immediately if financial information was entered.

Cyber incidents can be reported through ReportCyber, while suspicious messages and scams can be reported to Scamwatch.

If a MediaRack service may be affected, submit an urgent support ticket through the client area. MediaRack will never ask you to provide your password in a support ticket or email.

 



Mandag, Maj 11, 2026





« Tilbage