Staying safe online
Whether it’s email, online banking, online shopping or working from home: our daily lives are becoming increasingly digital. However, where there are significant benefits, there are usually risks as well. By following basic security rules, you protect not only your data, but also your assets and your identity.
We communicate by email, conduct banking transactions on our smartphones, shop online and access company data while working from home. This digital connectivity brings convenience and efficiency, but at the same time creates new attack vectors for cybercriminals. Often, all it takes to install malware or compromise sensitive data is a single careless click on a link or opening a tampered document.
Staying safe with emails and text messages
Emails and text messages are the most common entry point for phishing and various types of fraud, as well as for malware. Attackers try to trick their targets into doing something they wouldn’t normally do, such as clicking on a link, opening a document or entering personal details. Be especially cautious with messages that demand immediate action or create a sense of urgency. These tactics are collectively known as social engineering. The aim here is to exploit emotions such as fear, curiosity or a willingness to help.
As a rule of thumb: Never enter sensitive information such as passwords or credit card details on websites that you’ve accessed via a link in an email or text message.
Other points to bear in mind:
- Do not click on links in unexpected emails.
- Do not open attachments from unknown senders.
- Always keep your email program up to date.
- Even messages from known senders can be dangerous if their account has been compromised.
Buying and selling online
The internet offers a wide selection of goods and services. At the same time, however, there are also risks posed by fraudulent sellers or offers. Therefore, carefully check unfamiliar online stores before using them. To help you assess them, the NCSC recommends reading other people’s reviews. If an online store or company has no reviews, this usually indicates that it is a new business. Extra caution is advised in such cases. For experienced users, the NCSC recommends checking the domain’s "Whois information". This can reveal, among other things, the age of a domain. The newer the domain, the higher the risk of fraud is generally considered to be. Since positive reviews can often be purchased or fabricated, it’s especially important to carefully read the critical reviews as well.
Scammers are also active on classifieds platforms. One of the most commonly reported cybercrimes to the police is classified ad scam. Here, too, it’s important to read other users’ reviews beforehand. After a sale, do not enter any confidential information – such as bank login credentials or credit card details – on purported shipping portals.
The NCSC recommends the following:
- Check whether a seller has a legal notice. Verify that it is complete and plausible. For example, does the seller have a plausible contact address, a correct telephone number or email address and a valid commercial registry number?
- Use a different password for each online service.
- Choose payment on account rather than advance payment where possible.
- Check the information regarding the right of cancellation and returns, as well as shipping costs.
- Avoid providing credit card numbers unless it is absolutely necessary. If this isn’t possible, make sure you only do so on an encrypted website (look for "https://" with a lock or key icon in the browser’s address bar).
- Check your credit card statements carefully and report any discrepancies to your card issuer.
- Examine reviews critically, as even reviews can be fake.
When selling, follow this rule: Do not ship the merchandise until payment has been received, and do not rely on payment confirmations sent by email.
Further information
Phishing emails target first-time sellers on classifieds platforms
Secure online banking
More and more banking transactions are being conducted online or via mobile apps. Financial institutions are investing heavily in security. As a result, attacks are not directed at the bank itself, but rather at customers’ devices. You should therefore only use online banking on secure and up-to-date devices. Install updates for your operating system and software regularly. Use up-to-date antivirus software and keep your firewall enabled. Avoid using public computers or open Wi-Fi networks for banking transactions.
Attacks generally only succeed if you grant the fraudsters access to your computer via remote access software, or if you reveal both your password and the second security factor (e.g. a one-time password) on a website or over the phone. Therefore, be sure to follow these rules:
- Always enter your financial institution’s address manually into the browser.
- Never enter your banking information on a page you’ve opened via a link.
- Financial institutions never ask for your password or one-time password (OTP) via email or phone – not even to stop an alleged fraudulent payment. End such calls immediately.
- Actively end each session using the logout button.
The NCSC also recommends always using your financial institution’s official mobile banking app. Mobile banking apps are generally considered more secure than accessing banking services via a web browser, as browsers offer more attack vectors because they can have many extensions, plugins, and potential interfaces. Official apps, on the other hand, usually feature additional security mechanisms such as device binding or built-in protection functions.
Using artificial intelligence safely
AI applications such as chatbots and image and video generators are now widely available and are being used more and more frequently in everyday life. They assist with writing texts, translations, answering questions, and creating new content. These tools offer a wide range of functions and often give the impression of being all-knowing.
However, using AI applications carelessly carries risks, particularly when personal, sensitive or confidential information is entered. Many AI applications store user input or use it to further develop their systems. As a result, data may be unintentionally processed further or stored long-term.
To minimise risks, the following protective measures should be observed:
- Do not enter personal data, such as names, addresses, passwords, bank details or health information into AI applications.
- Do not share confidential business, customer or internal company data with AI applications.
- Use only reputable and well-known AI services, and read the privacy policy and terms of use carefully.
- Critically evaluate the responses provided by AI applications, as they may be incorrect, incomplete or misleading.
- Download AI applications only from official app stores or trusted providers to avoid counterfeit or tampered apps.
QR codes: Uses and risks
QR codes make it easier to access websites, payment information or apps. Their advantage lies in their ease of use. A single scan is all it takes to trigger the desired action. The problem, however, is that the content of a QR code is not visible before it is scanned. As a result, a QR code could conceal a malicious website or a suspicious download. Fraudsters can then cover existing QR codes with fake ones or place new codes in their place. A common scam involves covering QR codes on parking meters. Since users in these situations want to pay their parking fees as quickly as possible, they pay less attention to the URL of the page that opens.
Follow these protective measures:
- Use a trusted scanning app or your device’s built-in camera function.
- Never enter credentials on a website you accessed via a QR code.
- Only scan a QR code after examining it closely or even touching it ensure it is not a sticker that has been placed over the original.
- If you realise you have scanned a QR code with a malicious link, immediately notify the person in charge at the location where you discovered the QR code.
Further information
Beware when scanning QR codes!
Parking fee phishing with fake QR codes
Social media
Social media makes it easy to connect with friends, family and business partners. At the same time, a great deal of personal information is published there that can be misused by cybercriminals. Public profiles, posts, comments and even photos contain valuable details that can be used for fraud or identity theft. It is therefore particularly important to handle personal data with care.
Follow these protective measures:
- Regularly check the privacy settings of your profiles.
- Only post information that you don’t mind others seeing or using.
- Be cautious with direct messages containing links or attachments.
- Use strong passwords and enable two-factor authentication.
Once something has been shared on social media, it is nearly impossible to remove it completely. A mindful and cautious approach helps to prevent unwanted consequences and enhances digital security.
Travelling abroad
When travelling abroad, exercise particular caution when using mobile devices. Before departure, familiarise yourself with country-specific regulations and avoid using public computers and public Wi-Fi networks for sensitive activities such as online banking or accessing confidential data.
Take only the devices you absolutely need with you, and take every precaution to protect them from loss or theft. Hotel safes do not offer complete protection. In some countries, authorities are also authorised to inspect electronic devices or access data storage media. Therefore, whenever possible, do not take sensitive data with you, or encrypt it thoroughly. Disclose as little travel information as possible – for example, on social media. Avoid using public USB charging stations and use your own chargers or a power bank instead. If possible, use the internet via the cellular network and check in advance for any roaming charges. Keep electronic devices in your hand luggage and do not leave it unattended.
Further information
Holiday time: what to watch out for when you return home
Federal Department of Foreign Affairs FDFA : Travel advice in brief
