Phishing uses fake messages and websites that imitate your financial institution. A text or email warns that your account is blocked and links to a login page that looks real, but everything you type goes straight to the scammer, who then logs into the genuine service as you.
A message arrives claiming a problem: 'your account is suspended, verify now'.
The link opens a near-perfect copy of the real login page.
You enter your username, password, or card number; some pages also ask for the OTP that arrives moments later.
The scammer replays those details on the real site and empties the account.
Messages that create panic and include a link.
Web addresses that are slightly wrong: extra words, odd domains, misspellings.
Login pages reached from a message rather than typed by you.
Requests for full card numbers, PINs, or OTPs on a web form.
Never log in through a link in a message. Type your institution's address yourself or use the official app.
Check the web address carefully before entering anything.
Treat every 'verify now or lose your account' message as a scam until proven otherwise.
If you entered details on a suspicious page, contact your institution immediately and change your passwords.