Threat awareness
How to recognise impersonation and phishing attempts
A calm verification habit can protect a family from a convincing impersonation.
Familiarity can be manufactured
A message may refer to a real relative, a recent trip or a known business relationship. Those details can make an unexpected request feel credible. Family phishing uses that familiarity to encourage a disclosure, a payment or a change in account access.
Notice the request, not just the presentation
Pay attention when someone asks for a code, a password, a new payment route or an immediate decision. A polished message is not evidence of legitimacy. Neither is a familiar profile photograph or a message that appears in an existing conversation.
Verify through an independent route
Use a contact method you already know to check an unusual request. Avoid relying on phone numbers or links supplied by the message itself. Agree on a family process in advance so verification feels routine rather than personal or accusatory.
Help everyone respond early
Make it safe for children, relatives and staff to say that they clicked or replied. Preserve the message and relevant details. If account access may have been affected, use the provider’s official recovery and security controls, and seek support appropriate to the situation.
Practise without creating anxiety
Use occasional examples to explain the verification habit. Keep the instructions short and consistent. The most useful defence is one people remember under pressure: pause, verify independently and ask for help. Technical controls support that habit but cannot replace the shared understanding behind it.
Verify the request, not the familiar picture
An account name, profile picture or recognisable writing style is not independent proof of who sent a message. The person may be impersonating someone you know, or using an account that has itself been compromised. Treat the requested action as the important clue: are you being asked to move money, approve a login, reveal a code or open a new link?
Use a known contact method that you already had before the message arrived. For example, call a relative using the number saved in your contacts rather than the new number supplied in the request. A request to keep the matter secret or avoid calling should increase the need to verify, not remove it.
A household example
Imagine a message arrives in a family group from an account using a cousin's photograph. It asks for an urgent transfer because their phone is supposedly damaged. Pause. Contact the cousin or another trusted relative through an established route. Do not let a screenshot of a conversation replace that check.
A similar pattern can appear as a delivery issue, a school notice or a service renewal. Open the organisation's official app or type its known address yourself. Do not use a link in the message as your only route to establish whether the problem is real.
If you already acted
Write down what happened and distinguish opening a message from entering a password, giving a code or installing software. These actions create different risks. If you entered a credential, use the provider's official route from a device you trust to change it and review access. Avoid continuing the conversation with the sender.
If you shared information belonging to someone else, tell the affected person through a trusted channel so they can make their own decisions. Seek help appropriate to the affected account or device. Do not send private evidence to unsolicited recovery services or assume that deleting the original message resolves the incident.
Make verification easy before it is urgent
Families and trusted staff should agree a simple rule for unusual requests: pause, contact the person independently, then act only when the request is understood. Apply the same rule to requests that seem to come from CyberImperials or another adviser. A legitimate relationship should allow room for verification.
Keep reporting calm. Blame makes people delay telling others, which can leave the household with fewer options. Review the event to improve recovery arrangements, contact records and account settings. The useful outcome is a clearer routine, not a promise that every deceptive message can be recognised immediately.
Explore personal cyber security services or request a confidential consultation.