Phishing after a breach: recognising scams
After a breach, fraudulent messages multiply and look credible. The warning signs and where to report a fraudulent email or text message.
Data from a breach is mostly used to craft convincing fraudulent messages. The scammer knows your name, the site you were a customer of, sometimes your address or the last digits of your phone number. These accurate details do not prove the message is genuine.
Warning signs
- urgency: account blocked, parcel waiting, fine to pay, refund to claim;
- a request for codes, your password or approval of a transaction you did not start;
- a link to an address that looks like the real site without being identical;
- a call from a supposed bank adviser asking you to "secure" your account.
Your bank will never ask you for a code received by text, nor to approve a transaction in order to "cancel" another one.
Good habits
- Do not click: open the official website or app yourself.
- If a call seems suspicious, hang up and call the organisation's official number.
- If you entered a password, change it immediately. If you gave bank details, call your bank.
Where to report
- A fraudulent email: use the "Report phishing" button of your email service.
- A fraudulent text message: forward it to your operator's spam reporting number (7726 in the UK, 33700 in France).
- If you have lost money: contact your bank immediately and report it to the police or your country's online fraud reporting service.