Anglický text článku
It was a Tuesday evening, and I was making dinner when a new email landed in my inbox. The email came from my bank, or at least that is what the sender's name said. It said that my account had been blocked and that I had twenty-four hours to confirm my details.
For about ten seconds, I believed every word of it, and that is what still bothers me. My heart was beating faster, my cursor was already moving towards the link, and I was not thinking at all. That is exactly how phishing works: it does not attack your computer, but the person sitting in front of the screen.
Then I stopped and read the message properly, and three small details gave the scam away. The sender's name looked right, but the real address behind it ended in a domain I had never seen before. The message began with “Dear Customer”, although my bank always uses my name. And when I moved the mouse over the button, the web address at the bottom of the screen had nothing to do with my bank.
I did not click on anything. Instead, I closed the email, opened my banking app myself and checked my account there. Everything was fine, and there was no hurry, so the next morning I reported the message to my bank and deleted it.
If an email tells you that you must act immediately, that pressure is part of the attack. A real bank will never ask you to confirm your password or your full card number in an email, so you should never send them. Take ten seconds and look at the sender before you do anything else. And if you are not sure, close the message and go to the website yourself.