Skip to content

Learn about security risks such as phishing, spoofing, spyware, and cyberattacks, as well as MEO’s security tips, best practices, and solutions. Stay safe online!

Your safety is MEO's top priority

Learn about the most common attacks and scams, and discover MEO’s solutions to keep you safe

Cyberattacks are on the rise every day

New digital threats can go unnoticed.

One in four cyberattacks recorded in Portugal was related to phishing and other forms of social engineering, according to the ESET Threat Report H2 2025 (1).


15,500 cases of “spoofing” fraud were investigated in Portugal in 2025. Computer fraud, computer forgery, unauthorized access, and extortion are among the most common crimes, according to data from the Judicial Police. (2)


764 reports of online scams have been filed in Portugal. These include fraudulent purchases, fake websites, and scams on social media, according to the Cybercrime Office. (3)


A 36% increase in reported cybersecurity incidents in Portugal. Phishing and smishing were the most commonly reported types of incidents, with a 13% increase compared to the previous year. (4)


Digital security made easy

Learn the basics of staying safe online.

Spoofing, according to Fonseca

"Hey man, spoofing is when someone impersonates you and calls your mom saying, 'Hi, Mom, I lost my mobile phoneIt's a scam—they're just trying to get information out of her."


Spyware, according to Dona Alice

"Look, spyware is a program that spies on you. It sneaks onto mobile phone computer to snoop on your life without you even realizing it."


Phishing, according to Rita

"Phishers are thieves who go around fishing for our stuff on the internet."


Spoofing

Learn more about spoofing from a MEO expert.

Spoofing

Cyberattacks

Learn more about cyberattacks from a MEO expert.

Cyberattacks

Ransomware

Learn more about ransomware from the MEO expert.

Ransomware

Phishing

Learn more about phishing from a MEO expert.

Phishing

The most common attacks that threaten your security

Learn about the most common scams and how to spot the key warning signs.

Phishing
Fake messages (text) that impersonate legitimate organizations. Objective: to steal personal or banking information or gain access to accounts. Typical sign: an urgent request to click on a link and "update your information."



Fake Website: Pages that mimic real stores, banks, or brands. Purpose: to collect data or payments. They arrive via text, email, or fake ads.


Online Shopping Scams
Fake stores, products that never arrive, or credit card theft. Very common during sales, on marketplaces, and on social media.


Account Hijacking (Email / Social Media / WhatsApp)
Unauthorized access to accounts to solicit money, recover other accounts, or steal contacts. Often begins with phishing or shared passwords.


MEO Net Segura is the solution to keep you safe while browsing the internet.

Learn more
Learn about the solution


spoofing The number displayed appears to be legitimate (bank, telecom provider, government agency). Objective: to obtain verification codes, bank details, or to convince the victim to follow instructions.


Wangiri ("one-ring and hang up")
Very brief calls from international numbers. The scam only works if the victim calls back, which results in high charges.


Vishing
"Voice phishing." The scammer calls, creates a sense of urgency, and tries to obtain personal information or codes. Often combined with spoofing.


Robocalls
Mass automated calls with recorded messages. Purpose: spam, scams, or setting up other fraudulent schemes.


Greater security with MEO verified calls.

Learn more
Learn about the solution

Smishingtext
text malicious links designed to steal data or install malware. They impersonate banks, the postal service, the tax authority, telecom providers, etc.


text (Orders / Fines / Fees)
Messages that exploit common situations to appear legitimate. They create a sense of urgency and include payment links.


"Hello Dad / Hello Mom" Scam
A message pretending to be from a family member who needs money urgently. Relying solely on conversation and trust, with no links.


MB WAY Scam via Text Message
The scammer asks you to "accept the request" or "confirm payment." Entering codes is the same as sending money to the scammer.

Learn more

How would you react if you encountered a phishing scam or other type of fraud?

Take the test and find out

Take the test

Best practices for digital security

6 essential tips to help you reduce online risks and threats.

Parental control

Staying informed is the best protection.

Learn more

Passwords

A strong password is your best defense.

Learn more

Two-factor authentication (MFA)

Two keys open just for you.

Learn more

Updates and backups

Updating means protecting.

Learn more

Online privacy

Share less, protect more.

Learn more

Device protection

More barriers, fewer risks.

Learn more

Can you spot a cyberattack?

Learn how to spot signs of fraud and make safer decisions online.

Do you know how to deal with cyber threats?

Test

Stay up to date on the latest fraud alerts

Follow the MEO forum for alerts about phishing, smishing, and text sent in MEO’s name, and stay safe.

View alerts
Report an issue

MEO Security Solutions

Solutions that protect you from digital threats.

Call verification

Verified and more secure calls with MEO Origin. Answer your calls with confidence.

Find out more

MEO Net Segura

Browse safely on mobile networks and your home Wi-Fi. Block suspicious and fraudulent links before they cause problems.

Find out more

MEO Antivirus

It helps protect your devices (PC, tablet smartphone) against viruses and other digital threats.

Find out more

Learn more about Security and Cyberattacks

Check out articles, tips, and much more on digital security.

Podcast: Connected and Safe

In this episode of the “Ligados e Seguros” podcast, we explain in a simple and practical way how to recognize some of the main online threats and what steps you can take to strengthen your digital security.

Listen to a podcast

Safe Digital Vacations

Travel with peace of mind. Protect your digital world, too.

Read the guide

Wangiri: Missed-Call Scam

Did you receive an unknown international call that hung up quickly? It could be a Wangiri scam. Find out how to avoid unexpected charges and protect yourself.

Read more

Fraud and Phishing: what are they and how can you protect yourself?

The internet has brought countless facilities, from online payments to instant communication, but also new risks.

Read more

Social media security: how to protect your privacy online

Social networks are part of our daily lives, allowing us to communicate, share experiences and keep in touch with friends and family. However, they also pose significant risks to privacy and digital security.

Read more

How to protect personal data: good cybersecurity practices

Discover some practical cybersecurity tips to protect your personal data online. Find out how MEO Net Segura can help you surf safely and avoid digital threats.

Read more

5 tips for parents to keep the Internet safe

Discover 5 essential tips to ensure a safe internet for your children. Strong passwords, phishing and adware prevention, cyberbullying and much more!

Read more
5 tips for parents to keep the Internet safe for kids

Navigating safely

Paying bills, searching, storing personal data, sending and receiving messages... nowadays you can do almost everything online. But is it really safe?

Read more
To browse safely on the internet

6 tips for safe online shopping

The possibility of shopping online is available to all of us. Don't let anything happen and brush up on your knowledge of online security in the quiz.

Read more
6 tips for safe online shopping

Computer attacks: protect yourself while surfing the net

The Covid-19 pandemic has led to greater use of the internet and consequently greater concern about security.

Read more
Computer attacks: protect yourself while surfing the net

Do you think you know everything about online security?

Taking advantage of International Safer Internet Day on February 8, we decided to demystify the topic and test our knowledge of the dangers of browsing online through a quiz!

Read more
Do you think you know everything about online security?

Frequently Asked Questions about Security

How can I protect myself online?

Protect your data and access by following these best practices:

  • Always keep your access codes confidential and never share them;
  • Avoid automatic login; enter your login credentials every time you log in;
  • Do not use public or shared computers to access personal data;
  • Always log out at the end of each session;
  • Make sure you are on official MEO websites by checking the address in the browser address bar.

Additional protective measures:

  • Enable additional security with text verification text possible;
  • Do not use digital certificates on shared or untrusted computers;
  • Check your account transactions and activity regularly;
  • Save your login credentials and don't write them down on paper;
  • Change your passwords regularly and avoid obvious combinations (dates, names, sequences such as “123456” or “qwerty”)-;
  • Use different passwords for different services;
  • Keep documents and cards containing sensitive information in a secure location;
  • Never give out personal information or codes over the phone, by email, or via text message.

What precautions should I take when browsing the internet?

Before entering your personal information, please pay special attention to the following points:

  • Avoid accessing sensitive websites via links; always type the address directly into the browser;
  • Make sure the website is legitimate and trustworthy; fake websites may collect your personal information;
  • When making online transactions, check that the address begins with https://;
  • Be wary of websites that don't use secure connections.

Other best practices for browsing the internet:

  • Close your browser or shut down your computer when it is not in use;
  • Avoid making purchases or conducting transactions on public computers;
  • Use up-to-date antivirus software and a firewall to protect against unauthorized access.

What is phishing (and what types are there)?

This is a type of digital fraud that attempts to trick you into revealing personal or financial information by posing as trusted organizations.

This can happen through:

  • Email (phishing) – messages that impersonate banks, companies, or well-known services;
  • text smishing) – text messages containing links, fake payment requests, or fake delivery notifications;
  • Phone calls (vishing) – phone calls asking for urgent information;
  • The goal is always the same: to get you to click on a link, open a file, or provide information;

How can you spot a phishing attempt?

Keep an eye out for a message:

  • It asks for personal information, codes, or passwords.
  • Uses urgent or alarmist language (“Account blocked,” “Last chance,” “Immediate payment”);
  • Promises rewards, refunds, or penalties;
  • Includes suspicious links or files;
  • It does not come from an official MEO domain;
  • It contains grammatical errors or unusual formatting (but note: not all of them have errors).

Important information regarding MEO communications:

  • MEO never asks for sensitive information via email, text phone calls;
  • MEO emails do not send ZIP files;
  • MEO links always lead to official MEO websites.

What should you do if you receive a suspicious message?

If you receive a suspicious email, text phone call:

  • Don't reply, don't click on links, and don't open files;
  • Delete the message after confirming that it is fraudulent;
  • Report the situation to MEO to help protect other customers;

To report phishing using a MEO image:

  • Send the original email (with the technical header) to: csirt@meo.pt;
  • Reports help the MEO block malicious communications and prevent future fraud.

What is Wangiri and how does it work?

Wangiri is a type of telephone scam based on very short calls (i.e., with no actual duration) made from unknown numbers, usually international ones.

It works in a simple way:

  • You receive a call that rings once and then hangs up;
  • The number is recorded as a missed call;
  • When you call back, the call is routed to a premium-rate line or value-added service;
  • The cost of the call is charged to the scammers, with no benefit to you;
  • The goal is to tap into people’s curiosity or their urge to return missed calls;

What should you do if you receive a Wangiri call?

If you receive a suspicious call:

  • Don't return the call, especially if it's from an unknown international number;
  • Search for the number online; many numbers linked to scams are reported by other users;
  • Block mobile phone number that appeared as the caller ID for the suspicious call on your mobile phone to prevent further attempts;
  • Pay special attention to attempts to make very short calls that are out of the usual context;

Rule of thumb: Missed calls from unknown numbers that hang up immediately are a strong indication of fraud.

How can you protect your computer from digital threats?

Viruses and malware are among the main threats to online security and can lead to data loss, theft of personal information, or unauthorized access to your computer.

To protect yourself, follow these essential best practices:

  • Use a reliable antivirus program and keep it up to date.
  • Keep your operating system and browser up to date with the latest versions, with all security updates installed;
  • Scan your computer regularly, as well as any files you download or receive via email;
  • Avoid opening attachments or running programs from unknown or suspicious sources;
  • Install software only from trusted sources and keep all programs up to date.

An up-to-date and secure computer is the foundation for safer browsing.

How can you protect your mobile phone digital threats?

mobile phone can mobile phone be targeted by viruses, malicious apps, and unauthorized access. To browse safely, follow these best practices:

Essential prevention:

  • Install apps only from trusted sources and reputable providers;
  • Do not ignore security alerts from the operating system;
  • Keep your software up to date;
  • Use security solutions that help prevent threats while browsing, such as MEO Net Segura.

Note regarding Bluetooth:

  • Turn on Bluetooth only when necessary;
  • Keep hidden mode enabled by default;
  • Do not accept unexpected or unknown files or connection requests;
  • Always verify the source before accepting any content.

Signs of a possible infection:

  • The battery drains very quickly;
  • The device turns off frequently;
  • Sends messages or makes calls without your input;
  • Synchronization issues or abnormal performance.

If you suspect that your mobile phone infected, you may need to update or reinstall the software with the help of technical support.

How can MEO security services help you?

With MEO Net Segura, threats such as malware are blocked immediately, and you’ll receive an alert message on your device’s screen. You don’t need to install any apps; protection is provided directly on your mobile network and your home Wi-Fi network.

MEO Origin is a service that automatically verifies the origin of calls between customers , enhancing security by displaying a message on the screen confirming that the number has been verified and belongs to the MEO network.

The challenges of safe internet use for younger people

The MEO Foundation, in partnership with the PSP, the GNR, and the Safe Internet Center, has created the "Communicate Safely" section with young people in mind. Here you'll find practical tips and useful examples to help you protect yourself and avoid risks in the digital world.

Find out more

Want to improve your company's security?

Discover MEO Net Segura Escritório and protect your equipment and internet access with a real-time security solution.

Find out more

Security Glossary

Find explanations of key security terms. Stay informed and stay safe.

Cyber Threats

Malicious activities aimed at compromising systems, networks, or data—such as ransomware, phishing, DDoS attacks, or social engineering—can result in financial, operational, or privacy-related losses.


Digital Forensic Analysis

Technical investigation of security incidents that collects and analyzes digital evidence to identify the source of the attack, assess the impact, and support corrective actions.


Anti-malware

Security tools that detect, block, and remove malicious software, protecting devices from known threats and suspicious behavior.


Anti-phishing

Technologies that identify and block fake messages designed to steal personal data, credentials, or banking information.


Anti-spam

Filters that block unsolicited messages, reducing the risk of fraud, phishing, and malware infection.


Antivirus

Security software that detects and removes known viruses, Trojans, and worms, helping to protect computers and mobile devices.


Digital Signatures

A security mechanism that guarantees the authenticity, integrity, and origin of digital documents and files, ensuring that they have not been altered.

Backdoor

A covert method of accessing computer systems that bypasses security mechanisms, enabling unauthorized access.


Immutable Backup

Backups protected against modification or deletion, ensuring data recovery even after attacks such as ransomware.


Botnet

A network of devices that have been infected and are remotely controlled by attackers to carry out attacks, send spam, or commit fraud.


Cyberattack

Malicious activity intended to compromise digital systems, data, or services.


Cyber hygiene

A set of best practices that help users and organizations keep their systems, devices, and accounts more secure.


Cloud

A remote environment where data and applications are stored and processed over the internet, rather than remaining solely on the user's device.


Parental control

Tools and settings that allow you to restrict and monitor children’s internet access, block inappropriate content, and manage screen time.


Cryptography

A set of techniques that protect information by converting it into encrypted data, ensuring confidentiality, integrity, and, in some cases, authenticity.

Sensitive Data

Personal or business information whose disclosure could cause harm, such as bank details, login credentials, or confidential information.


Dark Web

The part of the internet not indexed by search engines, often associated with illegal activities or harmful content.


DDoS (Distributed Denial of Service)

An attack in which multiple devices send large volumes of traffic to a service, causing it to slow down or become unavailable to legitimate users.


Deepfake

Fake content generated using artificial intelligence, such as manipulated videos or audio clips, used in scams or to spread misinformation.

Email Security

Technologies that protect email against phishing, spam, malware, and fraud.


Email Spoofing

Falsifying the sender's address in an email to deceive the recipient and appear to be a legitimate source.


Encryption

The process of applying encryption to convert readable information into an encrypted format.


Social Engineering

Psychological manipulation that exploits people's trust to obtain sensitive information or induce dangerous actions.


Firewall

A security system that monitors network traffic, allowing legitimate communications and blocking unauthorized access.


Footprinting

The process of gathering information about an organization or system, typically from public sources, to identify potential entry points or security vulnerabilities. It is often the first step in a cybersecurity assessment or cyberattack.


Online shopping fraud

Scams when shopping online that can result in financial loss or data theft.

Hacker / Computer Hacker

A person who attempts to access systems or networks without authorization.


Hacktivism

Cyberattacks motivated by political, social, or ideological factors.


Biometric Identification

An authentication method based on physical or behavioral characteristics.


Hardware Inventory

Mapping and monitoring of an organization's physical devices, enabling more secure management.


Incident Investigation

Analysis of security incidents to identify causes and impacts and improve future responses.

Malicious Links

Fraudulent links sent via email or messages that lead to fake websites or install malware.


Malware

Malicious software designed to steal data, cause damage, or compromise systems.


DDoS Mitigation

Processes and technologies that filter out malicious traffic and keep services available during attacks.


Zero Trust Model

A security approach that assumes that no user or device is trustworthy by default.


MFA (Multi-Factor Authentication)

A security method that requires more than one factor, combining a password, mobile phone biometrics.

Phishing

An attack that uses fake messages to obtain personal data or credentials.


Active Prevention

Anticipating threats through continuous monitoring and rapid response.


Active Protection

Automatic blocking of attacks in real time.


Data Protection / GDPR

Rules for the proper and secure handling of personal data.


Quishing (QR Code Phishing)

It involves the use of manipulated QR codes to deceive users by redirecting them to pages controlled by third parties.

Ransomware

A type of malware that encrypts data and demands payment to unlock it.


Active Recovery

The ability to quickly restore systems and data following an attack or failure.


Network Redundancy

Distribution of services across multiple infrastructures to ensure availability.


RobotCalls

Automatic calls used for spam, aggressive advertising, or fraud.


Data Theft

Unauthorized access to or extraction of sensitive information.


Identity Theft

Unauthorized use of personal data to commit fraud or gain access to accounts.

Sandboxing

Analysis of suspicious files in isolated environments to identify threats.


Information Security

Practices that protect information by ensuring confidentiality, integrity, and availability.


Digital Security

Practices and technologies that protect people and devices in the online environment.


Fake Website

A page created to mimic a legitimate website with the aim of deceiving users.


Smishing

Phishing via text messages.


Spear Phishing

Highly targeted and personalized phishing.


Spoofing

Impersonating a legitimate source.


Spyware

It is a type of malicious software that installs itself on a device (mobile phone, computer, tablet) without the user's knowledge to monitor activities and collect personal information.

Threat Hunting

Proactive detection of attack indicators before they cause damage.


Threat Intelligence

Strategic information on threats, techniques, and attackers to strengthen protection.


Vishing

Phishing carried out via phone calls.


Vulnerability

A security vulnerability that can be exploited by attackers.


WAF – Web Application Firewall

Specific protection for web applications against direct attacks.


Wangiri

Telephone fraud involving very short call attempts (i.e., with no actual call duration) made from unknown numbers, usually international ones.
It works simply: you receive a call that rings only once and then hangs up, appearing as a missed call. When you decide to call back, the call is routed to a premium-rate number or value-added service, generating charges that go to the scammers. The goal is to exploit people’s curiosity or impulse to return missed calls.


Worm (Computer Worm)

Malware that automatically spreads between devices.

(1) Source: ESET Threat Report H2 2025

(2) Source: SIC Noticias, based on data from the Judicial Police

(3) Source: Cybercrime Unit of the Public Prosecutor’s Office - Reports of cybercrime complaints

(4) Source: National Cybersecurity Center (CNCS) – Cybersecurity in Portugal: Risks & Conflicts Report, 6th edition, September 2025

Passwords

  • Passwords are like the keys to our digital lives. If they’re weak or reused, it’s like leaving the door ajar for strangers.
  • Create long passwords (at least 12 characters) that combine letters, numbers, and symbols, but that only you can remember.
  • Avoid using birthdates, last names, or the same password on different websites.
  • If you have trouble remembering them, use a program that saves your passwords for you. Password managers help you securely store and fill in your login credentials without having to memorize everything.

Two-factor authentication

  • Two-factor authentication (2FA) provides an extra layer of security beyond your password. When you log in to an account, in addition to your password, you receive a code on mobile phone.
  • Even if someone knows the password, they can't get in without that code. It's like needing two keys.
  • This method is widely used by banks and social media platforms, and it takes just a few seconds to set up—but it makes all the difference in keeping your accounts secure.

Updates and backups

  • Operating system and app updates are designed to fix bugs and make your mobile phone computer more secure.
  • Whenever a notification appears, accept it and refresh the page.
  • You should also back up your photos and documents to an external drive or the cloud. That way, you won’t lose anything important if your device breaks down or is hacked.

Online privacy

  • Think carefully before you share. Your personal information is very valuable, and you don't always know who's seeing it.
  • Before posting a photo, location, or review, ask yourself: "Do I really need to share this publicly?"
  • Avoid sharing your address, schedule, bank information, or documents.
  • Adjust your privacy settings so that only your friends can see what you post. The less you share, the more protected your private life will be.
  • Protecting your digital image means protecting your safety and reputation.

Device protection

Web / Computer

  • Keep your antivirus software up to date
  • Update Windows/macOS and your browser
  • Perform regular scans

Mobile phone

  • Don't install apps from unknown sources
  • Don't ignore security alerts
  • If a virus is detected: an update or repair may be necessary

Bluetooth

  • Only use the phone when necessary
  • Keep hidden mode
  • Do not accept unexpected files

Parental control

Basic rules:

  • Set time limits for internet use and gaming
  • Teach children to keep their profiles private and not to share personal photos
  • Talk about respect and consideration in online conversations

Parental controls (in simple terms):

  • Enable the Parental Controls feature on your mobile phone, tablet console
  • Set time limits and control access to content
  • Keep the lines of communication open—guidance is more effective than prohibition

Discussions about “online friends” and challenges:
Explains that not all profiles are who they claim to be. Encourages young people to ask for help if someone asks personal questions or pressures them. Emphasizes that dangerous online challenges should never be attempted or shared.

Precautions to take and how to prevent it

Phishing

  • Do not click on links or attachments from unknown senders;
  • Avoid accessing bank accounts or making purchases on public networks;
  • If you are a victim of fraud, contact the police.

Fake Website

  • Check the full URL, make sure it includes https:// and the padlock icon, and access the site manually by typing in the address;
  • Be wary of links received via text, email, or social media;
  • Never enter bank details or codes received via text;
  • Never enter codes you receive via text, and never install apps or files.

Online shopping scams

  • Check if the store is well-known and has external reviews;
  • Use payment methods that require additional authentication and keep all purchase receipts.

Account theft

  • Use strong, unique passwords and enable two-factor authentication;
  • Don't share codes or click on unexpected links.

Precautions to take and how to prevent it

Spoofing

  • Never share codes, bank details, or passwords;
  • If in doubt, hang up and contact the organization using an official phone number, and never act under pressure;
  • Report it as fraud.

Wangiri

  • Never return calls from unknown international numbers, and don't call them back;
  • Blocks suspicious numbers and enables alerts for premium-rate calls, when available.

Vishing

  • Never share text codes, bank details, or passwords during the call;
  • Do not follow technical instructions over the phone. If you are unsure, hang up and do not call back;
  • Contact the organization via its official phone number or official app/website;
  • Report this as fraud.

Robocalls

  • Do not respond to or return suspicious calls;
  • Blocks automatic or repetitive numbers.

Precautions to take and how to prevent it

Smishing

  • Never click on links received via text unknown sources, and never reply to them;
  • Always access the site by typing in the official URL, and delete and report text .

If you clicked on a smishing link:

  • Do not enter any data and close the page immediately;
  • Change important passwords and run a security scan on the device.

text

  • Never click on links received via text;
  • Always check official channels, and delete and report text .

"Hello Dad / Hello Mom" Scam

  • Never send money without confirming through another channel, and be wary of urgent requests;
  • Call the family member’s usual number or check with another family member.

MB WAY Fraud via Text Message

  • Never enter MB Way codes at the request of third parties;
  • Receiving money doesn't require any codes, and no one needs your "help" to pay.