Free lesson · Skill · 6 min
Fake bank emails and SMSs
Lesson 3 of 10 in AI Fraud Awareness Foundations
The one idea
Phishing (email) and smishing (SMS) both deliver the same product: a link that takes you somewhere that looks exactly like your bank and asks you to log in. The page can be a perfect clone — colours, layout, even a working password-strength meter. The only thing the scammer cannot clone is the real domain in the address bar.
Compare:
SMS: "FNB: Your card is frozen. Unfreeze: fnb-secure-access.co.za/unlock" — tapped, page looks perfect, logs in.
versus
Same SMS. You do not tap. You open the FNB app you already have. Card is fine. The SMS was the attack.
Why the clone works
The fake page does not need to fool the bank — it only needs your username, password, and the OTP you type into it thirty seconds later. Many fake pages proxy your details straight into the real bank site in real time, so even the OTP timing feels normal. The lesson: the login page is not where you check legitimacy. The route you took to reach it is.
Safe routes: the app already on your phone, a bookmark you made, a URL you typed. Unsafe routes: any link in any message that asked you to log in — no exceptions, even when the message is real, because you cannot reliably tell.
Try it now
Create your safe route now: open your actual banking site by typing the address, and bookmark it. On your phone, check the banking app works. Write one rule where you will see it: "I never log in through a link in a message."
Your win today
Links take you to pages; pages prove nothing. You reach your bank only through routes you created yourself.