Account protection
Security and phishing
Stop and check before entering credentials. Urgency, unexpected addresses and requests for codes are warning signs.
Signs of possible phishing
- The message creates urgency or threatens immediate account suspension.
- The link shows a different domain from the one expected or uses lookalike characters.
- The page asks for a password, one-time code or extra data without a clear reason.
- The sender, tone or attachment is unusual for institutional communications.
- The browser reports an invalid certificate or an insecure connection.
Before entering credentials
- Open the service from the catalogue instead of following an unexpected message link.
- Read the full address in the browser and check HTTPS.
- Make sure the service and requested profile match the task you intend to carry out.
- If in doubt, close the page and use an official support channel.
If you receive a suspicious message
- Do not open attachments or follow links in the message.
- Keep the original message and useful details for investigation.
- Report it through the institutional security or support channel once that channel has been validated for publication.
- Delete the message only after following the guidance from the official channel.
If you have already entered credentials
- Change the password immediately using the official procedure from a trusted device.
- If you reused the same password elsewhere, change it on those accounts too.
- Contact the appropriate institutional channel and state when and where the incident occurred.
- Review account activity and follow any further security instructions.
