Familiar appearance is weak evidence
Names, profile photos, logos, and caller information can be copied or misleading. A message arriving from a real account may also be unsafe if that account has been compromised. Treat the requested action as something to assess separately from the displayed identity.
Watch for a changed process
A fictional recruiter asks you to install a remote-control tool before discussing a role. A supposed colleague wants a one-time code to fix an account. Both requests move beyond an ordinary conversation into sensitive access. Urgency and demands for secrecy make independent verification especially important.
Verify through a separate route
Use contact information you already trust, such as an established company directory or official support page. Do not rely on a phone number or link provided in the suspicious message. If the request involves a work account, follow the organization's reporting process.
- Pause before granting remote access.
- Do not relay sign-in or recovery codes.
- Preserve the message for reporting without forwarding it broadly.