Before you click a service message, check the route it wants you to take

A message can use a familiar logo and still direct you to an unfamiliar destination. The US Federal Trade Commission warns that phishing messages may impersonate organizations to obtain personal information. A useful first response is to verify the request independently, especially when it introduces pressure or an unexpected payment.
Leave the message and use a known channel
Open the organization’s official app or type a website address you already know. Use contact information from an established statement or account record rather than the message itself. Check whether the same request appears there. Do not share a one-time code with someone who contacted you, and avoid treating the displayed caller name as proof of identity.
Keep a short record if something went wrong
If you entered information or sent money, contact the relevant institution promptly through its verified channel and follow its incident process. Preserve useful details without forwarding sensitive information to a public group. Reporting routes depend on location and the type of incident; the linked FTC resource is US guidance. No single visual clue proves that a message is safe, so verification matters more than polished formatting.
Try this, one step at a time
- Verify through an independently opened official channel.
- Keep one-time codes private.
- Use the relevant institution’s incident process if you responded.
US FTC: Recognizing Phishing ↗
Checked September 7, 2026. This guide distinguishes attributed information from our practical suggestions. Local rules and services may differ.