The sender address is unfamiliar
An unfamiliar address weakens the identity claim. It is a reason to verify, not proof by itself.
alphaPlan · Facilitator notes
Reference unit: Cybersecurity → Social engineering → Phishing, smishing and vishing
Fictional educational message
Hello,
We detected an unusual sign-in to your account. Access will be suspended today unless you confirm your identity.
Open the link below and enter your password and the one-time code sent to your phone.
hyrje-sigurt.example/konfirmo
Account support team
Fictional educational message. It does not represent a real Albanian institution, address or service.
An unfamiliar address weakens the identity claim. It is a reason to verify, not proof by itself.
Urgency narrows the time available to think. A safe process should still work when someone tries to rush it.
Passwords and one-time codes authorize access. A legitimate helper should not ask you to disclose them.
Using the supplied link keeps verification inside the channel that may be hostile. Open the known service yourself instead.
Unexpected identity checks should be confirmed through a separate route you already trust, not through instructions in the request.
Strong verification example: I will not use the link or share a code. I will open the service from my saved bookmark or call the published number I already know and ask: ‘Was this account warning sent by you?’
Alternative defensible answers: Reporting, asking a trusted colleague or opening the known service directly can all be sound if the learner does not disclose secrets or rely on contact details supplied by the request.
Complication 1
A caller says they are the sender and asks you to read the one-time code aloud.
Complication 2
The message appears to be forwarded by your manager with: ‘Please do this now.’
Complication 3
A second message says the deadline is now ten minutes away.
Extension: Teams rewrite the request into a legitimate safety notice that never asks for secrets and directs people to an independently known channel.
shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.
Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.
DisclaimerFound something unclear, outdated or improvable? Suggest an improvement