In this guide
Tech 7 steps 15 min Easy

How to protect yourself from online scams before it's too late

The step-by-step to recognize the most common scams (phishing, pyramid schemes, fake stores, social engineering), verify the source, distrust urgency, protect your accounts, and act fast if you've been scammed.

Updated
Person typing on a laptop while holding a card, with suspicious message alerts and padlocks on the screen
Time 15 min
Difficulty Easy
You'll need Phone or computer with an up-to-date browser · Your bank's official app installed · A password manager · Two-factor authentication (2FA) on
7 steps

Most online scams don’t break into your computer; they break into your head. That’s why they work so well: the victim is talked into doing the wrong thing on their own — usually clicking a link, typing a password, sending a code, or transferring money.

The good news is that the scammer’s playbook is small and it repeats. Learn to recognize the pattern and you’ll stay ahead of almost every trap on the internet.

The common thread in every scam is urgency combined with pressure and fake authority. If a message makes you act now to avoid losing something, it wants to skip your judgment. That’s the alarm — whenever it appears, stop.

Recognize the scams you’re most likely to see

Almost everything circulating out there falls into four families. Naming each one already helps you spot when you’re the target.

  • Phishing: a message or email that imitates a real company (your bank, a delivery service, the tax office) or someone you trust, to steal a login, password, or code. It usually arrives with a link or a “confirm” button.
  • Pyramid scheme and “easy money”: the promise of high, guaranteed returns, often with little effort, which only held up if you recruit more people. If you must pay to start or to “unlock” the earnings, it’s a scam.
  • Fake purchases: a store or seller that doesn’t exist. You pay (instant transfer or bank transfer) and the product never arrives. Also in this family: the deal that’s too good, off the charts, that demands payment up front and then vanishes.
  • Social engineering: a scammer builds a trusted relationship and uses emotion — love, pity, fear, hurry — to ask for money, a code, or access. Think the fake relative, the fake bank call center, or the “intermediary” who asks you to receive money in your own account.

Verify the source before you trust

Golden rule: you go to the institution; the institution doesn’t come to you. If a message says it’s from “your bank,” it’s more likely a scam than the truth.

  • Don’t click the link in the message. Type the official address in your browser or open the official app.
  • Look closely at the sender’s domain and the link. Scammers swap similar-looking letters (g00gle, bannk, an extra “r”) that are easy to miss on a phone.
  • If it’s a company, call the official number that’s on the app, the website, or the back of your card — never the number that came in the message.
  • Be suspicious of any confirmation you didn’t ask for: “your package is held,” “your account was locked,” “you’ve won.”
  • Before buying, check the store’s reputation on independent sources. A legitimate business doesn’t disappear.

Distrust urgency

Urgency is the trademark of the scam. A legitimate bank never tells you “do it in five minutes or you’ll be blocked.” A held package doesn’t require paying a fee through a link in a text. And no prize asks for an advance payment to be released.

When a message arrives in a hurry, do the opposite of what it asks: stop, close the tab, and treat the information as false until you confirm it yourself through the official channels. A scammer rushes you precisely so you don’t have time to check.

Never hand over a password, code, or sensitive data

No bank, company, or government asks for a password, two-factor code, full card number, or security code by message, call, or email. Whoever does is a scammer.

  • A two-factor code is the key to your safe: nobody can receive it, not even someone who claims to be from support.
  • Type your password only on the official site you opened, never on a link that arrived by message.
  • Don’t confirm card or bank details in forms sent by third parties.
  • Your email password is gold: it’s how every other account gets recovered. Protect it like a master key.

Protect your accounts

The best defense is not leaving the door unlocked. Before that message ever lands in your inbox, it’s worth a few minutes to lock down the accounts that matter.

  • Turn on two-factor authentication for everything important: email, bank, social media, payment apps.
  • Use a password manager so each account has a unique, strong password. A repeated password means one breach opens every account.
  • Keep your recovery email and phone number up to date. They’re the path back into everything.
  • Always open your bank through the official app, not a link. Check your balance and transactions regularly.
  • Be wary of apps that are “so convenient” they want broad access to your bank for no real need.

Check before you pay

Buying online is safe when you pay the right way. A scam usually redirects the payment to a person or a third-party account.

  • Research the store first: grammar, broken dates, contact details, reviews on independent sources. A ghost store has an address and phone number that don’t exist.
  • Prefer paying by card, which you can dispute, over an instant or bank transfer to a stranger.
  • Be suspicious of a price that’s too good, a short-running “sale that ends today,” and a seller who avoids working inside the platform.
  • Never agree to “receive money from a stranger into your account and pass it on.” That’s a money-laundering / mule setup and can make you part of it — even without bad intent.

What to do if you’ve been scammed

Falling for a scam isn’t the end. What sets the damage is how fast you respond. Here’s the order of action that raises your chances of turning it around.

  • Stop paying. Don’t make another transfer to “unblock” or “recover” the money. That’s a scam on top of a scam.
  • Dispute it with the bank now. Call the bank or card issuer, tell them what happened, and dispute the transaction. For instant transfers, request the special return mechanism — the faster, the better the chance of a reversal.
  • Change the passwords. Change the password on the affected account, your email, and your bank, and rotate your two-factor codes.
  • Save the evidence. Messages, phone numbers, a screenshot of the chat, the transaction receipt, and the transfer ID. That’s what the police, the bank, and the platform act on.
  • File a report. Many places let you report online. Keep the case number. It’s not shameful: it’s the first step to investigation and to protecting other people.
  • Tell whoever needs to know. Report the store or page on the site itself, warn friends and family who could receive the same scam, and watch your statements over the next few days.

Common mistakes

  • Clicking the link that arrived in the message. Always type the address or use the official app.
  • Believing the fake bank call center was real. Banks don’t call asking for codes; hang up and call the official number yourself.
  • Trusting “guaranteed returns” and “easy money.” High return with no risk doesn’t exist; whoever pays to start is funding the scam.
  • Agreeing to be a stranger’s intermediary. Receiving third-party money into your account to pass it on is a scam and can compromise you.
  • Using the same password everywhere. One breach opens all your accounts; use a unique password per service.
  • Sharing your two-factor code. That code is the lock on the safe only you can use.
  • Feeling ashamed of reporting. Plenty of smart people get scammed. Reporting and disputing faster reduces the damage and can help others.

Frequently asked questions

How do I know if a message is a scam?

A scam almost always relies on one of three triggers (urgency, pressure, or fake authority). "Do it now or it will be blocked," "pay a small fee to unlock your prize," or "I'm from your bank's support and I need your code." If a message rushes you to act to avoid losing something, that's the alarm signal.

Do banks or companies ask for passwords and codes by phone or WhatsApp?

Never. No legitimate institution asks for a password, two-factor code, or full card number by message, phone call, or email. If you gave your code or password to someone, change the password right away and notify your bank.

I got scammed. What do I do now?

Don't panic, and don't make another payment to "reverse" it. Contact your bank or card issuer immediately to dispute the transaction, and request the special return mechanism for instant transfers. Then change passwords, save the evidence, and file a report. The faster you act, the better the chance of getting the money back.

How do I check if a link is safe?

Don't click it from the message. Type the official address in your browser or open the official app. If it's a domain, read the name closely — scammers swap similar-looking letters (g00gle, bannk). If the message leads to a site, check its reputation on independent sources before entering anything.

#security#scam#phishing#password#money

Informational content. For risky situations or technical, legal or medical doubts, talk to a professional.

Keep going

Wi-Fi router on a high shelf in a bright living room with its antennas raised Tech

How to improve your home Wi-Fi signal

Improve Wi-Fi coverage with practical changes to router placement, frequency bands, channels, security, firmware, and carefully chosen extra equipment.

30 min Easy