10 Nov 2025 · Vytautė Karpytė
How to Protect Yourself from Scammers?


Fraudsters’ most common tools for obtaining money and data are phishing emails, SMS messages, phone calls, and social media. Markus Ilmar Münzer, CEO of cybersecurity training company RiskSight, and Tauno Tamm, content director, remind us of some simple tips on how to protect yourself from scammers.
“If you receive a message or email that raises even the slightest doubts, it’s worth taking seven seconds to pause and analyze. Think about whether you have any reason to receive such a message and whether what it contains is true,” says Tauno.
According to Markus, the biggest mistake is well-meaning trust. “Often people click on the sent link and, in the worst case, even enter information. Usually nothing happens just from clicking the link, but if you’ve entered data, you should change your password and definitely notify CERT-EE and, in the case of a work device, the IT department.”
If there’s suspicion that fraudsters have obtained bank login credentials, you should immediately contact your bank.
There are some tips for recognizing fraud
Understanding the logic of URL or link structure helps determine whether the link in a phishing email is genuine. Fraud pages look quite authentic at first glance, as they often mimic well-known companies or brands quite convincingly.
A URL consists of a root domain (for example, www.selver.ee) and a subdomain (subpage address, for example, https://www.selver.ee/uudised). “The root domain shows which site you’re on. Often in fraud cases, the positions of the root domain and subdomain are swapped. Because the URL contains familiar keywords, it’s easy to fall victim to the attack,” explains Tauno.
“I recommend avoiding the use of HTTP pages because the page is unencrypted and someone could steal data in transit. HTTPS pages are more secure, but that doesn’t rule out that it could be a fraudulent page,” he adds.
Tauno explains that both on computers and phones, it’s possible to check whether it’s the correct link before clicking. “A link in an email may appear correct because it’s hidden under text or another link. To check the link’s destination, move the mouse cursor over the link without clicking it. The actual destination will be displayed above the link and can also be seen in the bottom left corner of the screen. On a phone, you need to hold your finger on the link to open a page preview.”
All computers and phones that have any access to systems within the organization are potential attack points.
“There are cases where a company CEO’s face and voice are presented. In the call, supposedly the CEO asks for money to be transferred in connection with an important project. People have also been sent fraud emails saying that you’ve failed a phishing test and click here. Unfortunately, reverse psychology also works quite successfully,” he adds.

A strong password is supported by a password manager
A secure password is at least 12 characters long and contains uppercase and lowercase letters, numbers, and symbols. The password shouldn’t contain information related to you. “Children’s names or loved ones’ birthdays can be researched about you,” says Tauno.
“When having different accounts, people sometimes start using variations derived from previous passwords. This isn’t secure because it’s essentially the same password. You also shouldn’t use number patterns, for example 123, because they’re easily guessable,” he adds.
A password manager can be used to remember passwords, where all passwords can be stored. This can be accessed with one master password, face recognition, or fingerprint authentication.
It’s also important to enable two-factor authentication to ensure account security in case of a data breach. “For example, you can use a one-time code sent to a phone app. This prevents someone from accessing your account,” says Tauno.
Social media is a digital copy of real life
Fake accounts are common on social media, through which access to your personal data can be gained. Fraudulent raffles promising big prizes also spread there.
Markus adds that as a first step, cybercriminals look at what you’ve posted about yourself on social media. “On LinkedIn, they check who else works in the same organization as you and in what positions. They’ll probably also get an overview of your family. When traveling, you shouldn’t share photos and destinations. Every little detail on the internet can help put together a complete profile.”

Text: Angela Rääk