Free lesson · Skill · 6 min

Fake bank emails and SMSs

Lesson 3 of 10 in AI Fraud Awareness Foundations

The one idea

Phishing (email) and smishing (SMS) both deliver the same product: a link that takes you somewhere that looks exactly like your bank and asks you to log in. The page can be a perfect clone — colours, layout, even a working password-strength meter. The only thing the scammer cannot clone is the real domain in the address bar.

Compare:

SMS: "FNB: Your card is frozen. Unfreeze: fnb-secure-access.co.za/unlock" — tapped, page looks perfect, logs in.

versus

Same SMS. You do not tap. You open the FNB app you already have. Card is fine. The SMS was the attack.

Why the clone works

The fake page does not need to fool the bank — it only needs your username, password, and the OTP you type into it thirty seconds later. Many fake pages proxy your details straight into the real bank site in real time, so even the OTP timing feels normal. The lesson: the login page is not where you check legitimacy. The route you took to reach it is.

Safe routes: the app already on your phone, a bookmark you made, a URL you typed. Unsafe routes: any link in any message that asked you to log in — no exceptions, even when the message is real, because you cannot reliably tell.

Try it now

Create your safe route now: open your actual banking site by typing the address, and bookmark it. On your phone, check the banking app works. Write one rule where you will see it: "I never log in through a link in a message."

Your win today

Links take you to pages; pages prove nothing. You reach your bank only through routes you created yourself.

Turn the idea into a reflex

Members practice this against a real AI assistant, get feedback on the prompt, then review it before the idea fades.

Practice this lesson free