<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Feroze Ashraff</title>
    <description>The latest articles on DEV Community by Feroze Ashraff (@feroze_ashraff_e952c5a67a).</description>
    <link>https://dev.to/feroze_ashraff_e952c5a67a</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4025560%2Fa9bfc1b1-c4a3-4848-967f-9aeaff457009.png</url>
      <title>DEV Community: Feroze Ashraff</title>
      <link>https://dev.to/feroze_ashraff_e952c5a67a</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/feroze_ashraff_e952c5a67a"/>
    <language>en</language>
    <item>
      <title>Deepfake and AI Scams — What's Actually Circulating in NZ Right Now</title>
      <dc:creator>Feroze Ashraff</dc:creator>
      <pubDate>Wed, 12 Aug 2026 16:58:39 +0000</pubDate>
      <link>https://dev.to/feroze_ashraff_e952c5a67a/deepfake-and-ai-scams-whats-actually-circulating-in-nz-right-now-3i2e</link>
      <guid>https://dev.to/feroze_ashraff_e952c5a67a/deepfake-and-ai-scams-whats-actually-circulating-in-nz-right-now-3i2e</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhoarjerx9tk5c7cwho9k.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fhoarjerx9tk5c7cwho9k.png" alt="Article hero" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 Why this matters for schools
&lt;/h2&gt;

&lt;p&gt;Deepfake scams are not just a celebrity or politics problem. For schools, the practical risk is impersonation: a fake voice note from a senior leader, an AI-written email that sounds like a colleague, a synthetic image used to embarrass a student, or a scam message that borrows enough school context to feel real.&lt;/p&gt;

&lt;p&gt;New Zealand's Own Your Online guidance tells people to understand common online risks, including scams and fraud designed to trick people into giving away personal or financial information [1]. AI changes the packaging. The safe response is still familiar: slow down, verify the person, and avoid acting on pressure.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 What counts as a deepfake or AI scam?
&lt;/h2&gt;

&lt;p&gt;A deepfake is synthetic audio, image, or video made or altered to make someone appear to say or do something they did not. In a school context, the risk may look like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a voice message that sounds like a principal, board member, supplier, parent, or colleague&lt;/li&gt;
&lt;li&gt;an AI-written email that imitates a staff member's tone&lt;/li&gt;
&lt;li&gt;a fake screenshot or image of a student or staff member&lt;/li&gt;
&lt;li&gt;a social-media account using generated photos or copied school details&lt;/li&gt;
&lt;li&gt;a phishing page or message that appears after a realistic AI-generated conversation&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Netsafe's deepfake guidance treats manipulated media as a safety and harm issue, especially when the material is used to deceive, harass, or pressure someone [2]. Schools should handle these cases as both digital-safety issues and safeguarding issues, not just as technology curiosities.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 How might this show up in a New Zealand school?
&lt;/h2&gt;

&lt;p&gt;The most likely school scenarios are practical and awkward:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;a finance or office staff member receives a voice note asking for &lt;strong&gt;urgent&lt;/strong&gt; &lt;strong&gt;payment&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;a teacher receives a message that appears to come from school leadership asking for account details&lt;/li&gt;
&lt;li&gt;a student shares an edited image of another student in a group chat&lt;/li&gt;
&lt;li&gt;a parent receives a fake message claiming a school &lt;strong&gt;payment&lt;/strong&gt; or account issue&lt;/li&gt;
&lt;li&gt;a staff member is impersonated in a social-media or email conversation&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Police advice on scams and fraud is clear that scammers try to get money, personal information, or access by making requests look legitimate [3]. Deepfake and AI tools can make that request feel more personal, but the verification steps should not change.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 What warning signs should educators look for?
&lt;/h2&gt;

&lt;p&gt;Do not rely on spotting perfect technical clues. AI-generated material is getting harder to judge by appearance alone. Instead, look at the request and the context.&lt;/p&gt;

&lt;p&gt;Useful warning signs include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;urgency around payments, login details, files, codes, or student information&lt;/li&gt;
&lt;li&gt;a request that bypasses the school's usual process&lt;/li&gt;
&lt;li&gt;a voice note or video that avoids a normal two-way conversation&lt;/li&gt;
&lt;li&gt;unusual wording from a familiar person&lt;/li&gt;
&lt;li&gt;a new phone number, email address, or chat account claiming to be someone known&lt;/li&gt;
&lt;li&gt;pressure not to check with anyone else&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If the message asks for money, access, student information, or secrecy, treat it as high risk even if the voice, image, or writing looks convincing.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 How should a school verify a suspicious voice or video request?
&lt;/h2&gt;

&lt;p&gt;Use a &lt;strong&gt;second channel&lt;/strong&gt; you already trust. Do not reply inside the same thread or call the number supplied in the suspicious message.&lt;/p&gt;

&lt;p&gt;A safer verification process:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;stop the action the message is asking for&lt;/li&gt;
&lt;li&gt;contact the person through a known school number, staff directory, or existing account&lt;/li&gt;
&lt;li&gt;ask a direct question in a live conversation if the request is sensitive&lt;/li&gt;
&lt;li&gt;check whether the request follows the normal approval process&lt;/li&gt;
&lt;li&gt;preserve the original message, link, audio, screenshot, or sender details&lt;/li&gt;
&lt;li&gt;report the concern to the right school contact&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;For account and message-level checks, NZAI's How to Spot Phishing Emails, Scams, and Fake Messages remains the baseline. Deepfake verification builds on those habits rather than replacing them.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 What if students are involved?
&lt;/h2&gt;

&lt;p&gt;Student-facing synthetic media can quickly become bullying, harassment, reputational harm, or a privacy problem. If a student appears in a manipulated image, audio clip, or video, the school should avoid treating it as a harmless prank until the facts are clear.&lt;/p&gt;

&lt;p&gt;Practical first steps:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;preserve evidence without forwarding it around&lt;/li&gt;
&lt;li&gt;support the affected student and limit further sharing&lt;/li&gt;
&lt;li&gt;involve pastoral, safeguarding, or leadership staff early&lt;/li&gt;
&lt;li&gt;consider whether the material includes personal information&lt;/li&gt;
&lt;li&gt;avoid making public claims until the school has checked what happened&lt;/li&gt;
&lt;li&gt;use the school's existing online-safety and behaviour processes&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If personal information has been exposed, misused, or sent to the wrong person, the Office of the Privacy Commissioner's privacy-breach guidance is relevant [4]. The issue may need both student-support and privacy-response handling.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 What should staff be told now?
&lt;/h2&gt;

&lt;p&gt;Keep the staff guidance short. The aim is not to make every educator a media-forensics expert. The aim is to give people a safe default.&lt;/p&gt;

&lt;p&gt;A useful staff message:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;If a message, voice note, video, or image asks you to make a &lt;strong&gt;payment&lt;/strong&gt;, share access, disclose student information, approve a login, or bypass a normal process, verify it through a separate trusted channel first. Do not act just because it sounds or looks like someone you know.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That rule is simple enough to remember under pressure. It also works for ordinary phishing, supplier fraud, social-media impersonation, and AI-generated scams.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 What should schools put in their AI-safety practice?
&lt;/h2&gt;

&lt;p&gt;AI-scam preparation belongs inside ordinary school cyber and digital-safety habits:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;payment&lt;/strong&gt; and bank-detail changes require second-channel verification&lt;/li&gt;
&lt;li&gt;staff know how to report suspicious messages and impersonation attempts&lt;/li&gt;
&lt;li&gt;students know that synthetic images or voice clips can cause real harm&lt;/li&gt;
&lt;li&gt;school leaders avoid asking staff to bypass normal approval processes by informal message&lt;/li&gt;
&lt;li&gt;office and finance staff have a clear escalation path for unusual requests&lt;/li&gt;
&lt;li&gt;privacy-breach assessment is part of the response when student or staff information is involved&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For broader AI use in teaching, use AI Safety for New Zealand Educators. For student guidance, use AI Safety for Students in New Zealand.&lt;/p&gt;

&lt;h2&gt;
  
  
  A quick deepfake-scam checklist for educators
&lt;/h2&gt;

&lt;p&gt;✓Does the message ask for money, access, student information, secrecy, or &lt;strong&gt;urgent&lt;/strong&gt; action?&lt;br&gt;
 ✓Have I verified the request through a separate trusted channel?&lt;br&gt;
 ✓Am I using a known contact method rather than replying to the suspicious message?&lt;br&gt;
 ✓Have I preserved the original evidence without forwarding it unnecessarily?&lt;br&gt;
 ✓If a student is affected, have safeguarding and pastoral staff been involved?&lt;/p&gt;







&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://nzaisecurity.com/insights/deepfake-and-ai-scams-nz-educators-2026/" rel="noopener noreferrer"&gt;nzaisecurity.com&lt;/a&gt;. &lt;a href="https://nzaisecurity.com/insights/deepfake-and-ai-scams-nz-educators-2026/" rel="noopener noreferrer"&gt;Read the full article.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  📚 Sources and references
&lt;/h2&gt;

&lt;h2&gt;
  
  
  Sources and references
&lt;/h2&gt;

</description>
      <category>cybersecurity</category>
      <category>deepfake</category>
      <category>newzealand</category>
    </item>
    <item>
      <title>Passwords, Passphrases, and MFA — What Actually Works in 2026</title>
      <dc:creator>Feroze Ashraff</dc:creator>
      <pubDate>Thu, 30 Jul 2026 09:42:03 +0000</pubDate>
      <link>https://dev.to/feroze_ashraff_e952c5a67a/passwords-passphrases-and-mfa-what-actually-works-in-2026-3kck</link>
      <guid>https://dev.to/feroze_ashraff_e952c5a67a/passwords-passphrases-and-mfa-what-actually-works-in-2026-3kck</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3231rlbjrbkfdrlqivzv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F3231rlbjrbkfdrlqivzv.png" alt="Article hero" width="800" height="533"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Use a unique passphrase for every important account, store them in a password manager, and turn on &lt;strong&gt;MFA&lt;/strong&gt; wherever it is offered. If you only fix three things, fix those three first.&lt;/p&gt;

&lt;p&gt;🚩 Why this matters in a school context&lt;/p&gt;

&lt;p&gt;Your school email account is probably connected to your student records system, your learning platform, your file storage, your communication tools, and sometimes your school's financial or admin systems. If an attacker gets access to that one account, they may be able to reach all of those.&lt;/p&gt;

&lt;p&gt;The same applies to students — a compromised school account can be used to send convincing phishing messages to other students and staff, access personal information, or impersonate the account owner in fraudulent contexts.&lt;/p&gt;

&lt;p&gt;🚩 What makes a password actually strong&lt;/p&gt;

&lt;p&gt;A strong password has three properties: it is long enough that it cannot be cracked by automated attempts, it is unique — not reused across services, and it is not guessable from your personal information.&lt;/p&gt;

&lt;p&gt;The practical solution is a passphrase. Instead of a short complicated password like "Kj8!xQ2", use a longer phrase that is easy for you to remember but hard for anyone else to guess: &lt;strong&gt;"Correct horse battery staple"&lt;/strong&gt; is better than "Tr0ub4dor&amp;amp;3" — longer, easier to remember, and significantly harder to crack.&lt;/p&gt;

&lt;p&gt;🚩 The password manager question&lt;/p&gt;

&lt;p&gt;If you have more than a handful of accounts, remembering unique passwords for all of them is not realistic. A password manager stores your passwords securely in one place, generates strong random passwords for new accounts, and fills in your login details so you do not have to type or remember them.&lt;/p&gt;

&lt;p&gt;⚠️ A password manager only needs one strong password to protect everything else. Make that one password a &lt;strong&gt;passphrase&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Most browsers have a built-in password manager. Dedicated tools like Bitwarden, 1Password, or KeePass offer more cross-device synchronisation and better security features. If your school provides a managed password manager, use it — it is already integrated with your account setup.&lt;/p&gt;

&lt;p&gt;🚩 Multi-factor authentication — what it is and why you should turn it on&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MFA&lt;/strong&gt; means that to log into your account, you need your password and something else — usually a code from your phone or an authenticator app, a fingerprint, or a hardware security key.&lt;/p&gt;

&lt;p&gt;Even if your &lt;strong&gt;password&lt;/strong&gt; is somehow exposed — through a data breach, a phishing page, or a reused password — &lt;strong&gt;MFA&lt;/strong&gt; stops the attacker from getting in without also having your second factor.&lt;/p&gt;

&lt;p&gt;✅ Turn MFA on for any account that offers it, especially:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;your school email or student portal&lt;/li&gt;
&lt;li&gt;any platform that stores personal information about you&lt;/li&gt;
&lt;li&gt;accounts connected to payment or financial information&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;⚠️ For most people, an authenticator app (Google Authenticator, Authy, or similar) is the most practical second factor. The code changes every 30 seconds, so even if someone sees one code, it will not work by the time they try to use it.&lt;/p&gt;

&lt;p&gt;🚩 Safer recovery settings&lt;/p&gt;

&lt;p&gt;When you set up password recovery options — a backup email, a phone number, security questions — treat them with the same care as the password itself:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Use a backup email that is itself secured with a strong password and MFA&lt;/li&gt;
&lt;li&gt;Security questions should have answers that are not guessable from your public profiles — your mother's maiden name and your first pet's name are public information if you share much online&lt;/li&gt;
&lt;li&gt;If a service offers recovery codes, store them somewhere safe — a locked drawer or a password manager entry, not a note on your desk&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;🚩 What to do if your password has been exposed&lt;/p&gt;

&lt;p&gt;If you learn that a service you use has had a data breach and your password may be among the exposed information:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Do not wait&lt;/strong&gt; — change that password immediately on any account where you used it&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Do not reuse the old password&lt;/strong&gt; on any other service&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Turn on MFA&lt;/strong&gt; on the affected account and any other account where you used the same password&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Check the account's recent activity&lt;/strong&gt; — look for logins from unfamiliar locations or devices&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;If the breach involved a school account&lt;/strong&gt;, notify your IT team so they can monitor for related activity&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;HaveIBeenPwned (haveibeenpwned.com) lets you check whether your email has appeared in a known data breach. It is worth checking this periodically.&lt;/p&gt;

&lt;p&gt;🚩 Password habits to build&lt;/p&gt;

&lt;p&gt;These small habits, done regularly, make a meaningful difference:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;When you create a new account, use your password manager to generate a unique password — do not recycle an old one&lt;/li&gt;
&lt;li&gt;If you hear about a data breach for a service you use, change that password within days — do not let it linger&lt;/li&gt;
&lt;li&gt;Do not share passwords with friends, even close ones — they may not handle them as carefully as you do, and friendship changes&lt;/li&gt;
&lt;li&gt;If a device is lost or shared, change the passwords for your most important accounts as a precaution&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://nzaisecurity.com/resource-library/passwords-passphrases-and-mfa-a-simple-guide/" rel="noopener noreferrer"&gt;nzaisecurity.com&lt;/a&gt;. &lt;a href="https://nzaisecurity.com/resource-library/passwords-passphrases-and-mfa-a-simple-guide/" rel="noopener noreferrer"&gt;Read the full article.&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources and references
&lt;/h2&gt;

&lt;p&gt;[1] Google. (2025). &lt;em&gt;Avoid and report phishing emails&lt;/em&gt;. &lt;a href="https://support.google.com/mail/answer/8253" rel="noopener noreferrer"&gt;https://support.google.com/mail/answer/8253&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[2] National Cyber Security Centre UK. (2023). &lt;em&gt;Password managers&lt;/em&gt;. &lt;a href="https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers" rel="noopener noreferrer"&gt;https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/password-managers&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[3] Bitwarden. (2025). &lt;em&gt;Password manager for individuals&lt;/em&gt;. &lt;a href="https://bitwarden.com/products/personal/" rel="noopener noreferrer"&gt;https://bitwarden.com/products/personal/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[4] New Zealand Police. (2024). &lt;em&gt;Internet scams, spam and fraud&lt;/em&gt;. &lt;a href="https://www.police.govt.nz/advice/email-and-internet-safety/internet-scams-spam-and-fraud" rel="noopener noreferrer"&gt;https://www.police.govt.nz/advice/email-and-internet-safety/internet-scams-spam-and-fraud&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[5] HaveIBeenPwned. (2025). &lt;em&gt;Have I been pwned?&lt;/em&gt; &lt;a href="https://haveibeenpwned.com" rel="noopener noreferrer"&gt;https://haveibeenpwned.com&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>passwords</category>
      <category>newzealand</category>
    </item>
    <item>
      <title>How to Spot Phishing Emails — The NZ-Specific Guide for 2026</title>
      <dc:creator>Feroze Ashraff</dc:creator>
      <pubDate>Sun, 12 Jul 2026 04:23:05 +0000</pubDate>
      <link>https://dev.to/feroze_ashraff_e952c5a67a/how-to-spot-phishing-emails-the-nz-specific-guide-for-2026-1e21</link>
      <guid>https://dev.to/feroze_ashraff_e952c5a67a/how-to-spot-phishing-emails-the-nz-specific-guide-for-2026-1e21</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6gt8vovuqyr0tcooe8qm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6gt8vovuqyr0tcooe8qm.png" alt="Phishing guide" width="800" height="533"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Phishing emails are still one of the most common ways attackers get passwords, recovery codes, and access to school or personal accounts. They do not need to look obviously fake to work. Most of the time, they just need to make you feel like you need to act fast before you stop to think [1].&lt;/p&gt;

&lt;p&gt;This guide gives students and educators a way to assess any suspicious message and a clear plan for what to do next.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚩 Why Phishing Still Works
&lt;/h2&gt;

&lt;p&gt;Phishing emails do not win because the writing is clever. They win because they arrive when you are busy or distracted.&lt;/p&gt;

&lt;p&gt;A typical scam message imitates a real notification — something from Google, Microsoft, a courier service, or your school platform. The language creates urgency: account suspension, unusual activity, billing problems, urgent document review.&lt;/p&gt;

&lt;p&gt;Students might encounter fake Google, Microsoft, courier, gaming, or bank messages. Educators might receive account-warning emails, shared-document prompts, or requests that appear to come from a colleague or school leader.&lt;/p&gt;

&lt;p&gt;In both cases, the goal is usually one of:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Getting you to enter your &lt;strong&gt;password&lt;/strong&gt; on a fake login page&lt;/li&gt;
&lt;li&gt;Persuading you to approve a sign-in prompt you did not initiate&lt;/li&gt;
&lt;li&gt;Tricking you into downloading malware or sharing a &lt;strong&gt;recovery code&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  🔍 Warning Signs to Check Before You Click
&lt;/h2&gt;

&lt;p&gt;No single warning sign proves a message is fake, but several together should stop you.&lt;/p&gt;

&lt;h3&gt;
  
  
  Check the &lt;strong&gt;sender address&lt;/strong&gt; carefully
&lt;/h3&gt;

&lt;p&gt;A message can display a familiar name while using a completely different address underneath. Google's Gmail Help advises users to watch for suspicious messages that look real but ask them to share personal information or click a link they were not expecting [1].&lt;/p&gt;

&lt;p&gt;Look past the display name. Check the full &lt;strong&gt;sender address&lt;/strong&gt;. If the email claims to be from Google, Microsoft, your school platform, or a bank, the real &lt;strong&gt;sending domain&lt;/strong&gt; matters — and it will not be a free email service.&lt;/p&gt;

&lt;h3&gt;
  
  
  Watch for &lt;strong&gt;urgency&lt;/strong&gt; before clarity
&lt;/h3&gt;

&lt;p&gt;A lot of phishing works by making you feel behind, exposed, or about to lose access. The language may mention account suspension, unusual activity, billing issues, or urgent document review.&lt;/p&gt;

&lt;p&gt;Urgency alone does not prove a scam. Real services sometimes send urgent alerts. But a legitimate security message should still hold together when you inspect it calmly.&lt;/p&gt;

&lt;h3&gt;
  
  
  Check the &lt;strong&gt;link destination&lt;/strong&gt;
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Hover over the link&lt;/strong&gt; before clicking. On a phone or tablet, use a long press or another safe preview method if your device offers one. If the visible text says one thing but the &lt;strong&gt;destination URL&lt;/strong&gt; says another, treat it as suspicious.&lt;/p&gt;

&lt;p&gt;Google's account-recovery guidance is a good reminder here: when account security is involved, going directly to the service in a new tab is safer than following a message link [2].&lt;/p&gt;

&lt;h3&gt;
  
  
  Never share &lt;strong&gt;passwords&lt;/strong&gt; or &lt;strong&gt;MFA codes&lt;/strong&gt;
&lt;/h3&gt;

&lt;p&gt;Phishing pages often ask for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Your password&lt;/li&gt;
&lt;li&gt;Recovery codes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;One-time passwords (OTP)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Approval of a sign-in request you did not initiate&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No legitimate service will email you asking for your password or MFA code. Any message that does is a phishing attempt, regardless of how official it looks.&lt;/p&gt;

&lt;h3&gt;
  
  
  Watch for unexpected &lt;strong&gt;approval requests&lt;/strong&gt;
&lt;/h3&gt;

&lt;p&gt;Some attacks do not ask for a password — they ask you to approve a &lt;strong&gt;sign-in prompt&lt;/strong&gt; or &lt;strong&gt;OAuth access&lt;/strong&gt;. If you receive a sign-in approval request that you did not initiate, do not approve it. Check your &lt;strong&gt;Google account activity&lt;/strong&gt; directly at myaccount.google.com [3].&lt;/p&gt;

&lt;h2&gt;
  
  
  🛡️ What to Do If You Receive a Suspicious Message
&lt;/h2&gt;

&lt;h3&gt;
  
  
  If you are not sure
&lt;/h3&gt;

&lt;p&gt;⚠️ Do not click, reply, or download anything. Open a new browser tab and navigate directly to the service in question using a known address — go to google.com and sign in from there, rather than from a link in the message.&lt;/p&gt;

&lt;h3&gt;
  
  
  If you already clicked
&lt;/h3&gt;

&lt;p&gt;Change your password from a clean device immediately. Check your &lt;strong&gt;account activity&lt;/strong&gt; for anything unusual. Revoke any third-party access you do not recognise. If you use the same password elsewhere, change it there too — a &lt;strong&gt;password manager&lt;/strong&gt; makes this manageable [4].&lt;/p&gt;

&lt;h3&gt;
  
  
  If you entered financial information
&lt;/h3&gt;

&lt;p&gt;Contact your bank or card provider immediately. Monitor your statements for any unusual transactions. Consider placing a credit freeze with a credit reporting agency if you think your details may have been captured.&lt;/p&gt;

&lt;h3&gt;
  
  
  If you are in a school environment
&lt;/h3&gt;

&lt;p&gt;Report to your IT team or school leadership. If student data may have been involved, the school may have reporting obligations under the &lt;strong&gt;Privacy Act 2020&lt;/strong&gt;. Do not try to manage this alone.&lt;/p&gt;

&lt;h2&gt;
  
  
  ✅ A Quick Decision Framework
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Does the message create urgency? (Pressure to act fast = yellow flag)&lt;/li&gt;
&lt;li&gt;Does the sender address match the brand it claims to be? (Mismatch = red flag)&lt;/li&gt;
&lt;li&gt;Does the link destination match what the message says? (Mismatch = red flag)&lt;/li&gt;
&lt;li&gt;Is the message asking for a password, code, or approval? (Yes = red flag)&lt;/li&gt;
&lt;li&gt;Would this request make sense if you had not just logged in? (No = yellow flag)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;🚨 If you have &lt;strong&gt;yellow flags&lt;/strong&gt;, slow down. If you have &lt;strong&gt;red flags&lt;/strong&gt;, do not click.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://nzaisecurity.com" rel="noopener noreferrer"&gt;nzaisecurity.com&lt;/a&gt;. &lt;a href="https://nzaisecurity.com/resource-library/how-to-spot-phishing-scams-and-fake-messages/" rel="noopener noreferrer"&gt;Read the full article&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  📚 Sources and references
&lt;/h2&gt;

&lt;p&gt;[1] Google. Gmail Help. &lt;em&gt;How to recognise and report phishing emails&lt;/em&gt;. &lt;a href="https://support.google.com/mail/answer/8253" rel="noopener noreferrer"&gt;https://support.google.com/mail/answer/8253&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[2] Google. Account Help. &lt;em&gt;Secure your account with recovery options&lt;/em&gt;. &lt;a href="https://support.google.com/accounts/answer/183723" rel="noopener noreferrer"&gt;https://support.google.com/accounts/answer/183723&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[3] Google. My Account. &lt;em&gt;Check activity and secure your account&lt;/em&gt;. &lt;a href="https://myaccount.google.com/notifications" rel="noopener noreferrer"&gt;https://myaccount.google.com/notifications&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[4] NZ Cyber Security Skills Hub. &lt;em&gt;Password managers explained&lt;/em&gt;. &lt;a href="https://www.ncsc.govt.nz/resources/cyber-security-basics/password-managers/" rel="noopener noreferrer"&gt;https://www.ncsc.govt.nz/resources/cyber-security-basics/password-managers/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>phishing</category>
      <category>newzealand</category>
    </item>
  </channel>
</rss>
