Lock anything you mentioned and warn your bank

    Cancel the relevant card, change the relevant password, and assume any code you read aloud is burned.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    There's a clear pattern: identify which account was exposed by the conversation, then act on that account first. Don't rely on 'they didn't sound that smart' — assume professional fraud.

    If they asked you to install something

    Important

    Apps installed via SMS links almost always include remote-access or banking-trojan capability. Don't open the banking app on that device until it's been wiped or scanned by a trusted security tool.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Communications Security