21/09/2026
"Suspicious login detected. Confirm your password here to secure your account."
If a text like this lands from your "bank," the right response is the one in the screenshot. π
Jokes aside, this is one of the most effective phishing scams in circulation β and it works on a simple psychological trick: manufactured urgency. "Your account is at risk" bypasses careful thinking and pushes people to act fast. That's the whole design.
The defence is one clear rule, worth sharing with your whole team and family: a legitimate bank will never ask you to confirm or enter your password via a message or link. Neither will the ATO, Microsoft, or any real institution. The request itself is the red flag β the content doesn't matter.
So the habit to build is channel discipline: never act on the message in front of you. Go to the source independently β the official app, or the number on the back of the card. It defeats every variation, because it doesn't rely on spotting a convincing fake.
For businesses, this matters twice over: the same trick that targets personal banking is used to harvest the credentials that lead to business breaches. One panicked click by one team member is often all it takes.
What's the most convincing phishing attempt you've seen lately? π