Skip to content

Online Security - Phishing | MEO

Protect yourself, your family, and your friends. Learn tips and advice for browsing safely.

Browsing the Internet Safely

Protect yourself, your family, and your friends. Learn tips and advice for staying safe online.

Browsing the Internet Safely
Fraud Alerts
Best Practices
Phishing
Wangiri
Protect Your Computer
Protect Your mobile phone

What is it?

It is a form of cyber fraud designed to deceive victims in order to steal personal information. Various methods can be used to achieve this goal: emails (phishing), text messages (smishing), and phone calls (vishing).

Phishing involves an attempt to mimic the content of a website, leading the recipient to believe they are interacting with a specific, trusted entity. It can take the form of a simple “pop-up” or an “email.”

The goal is to trick the recipient into clicking on malicious links or providing personal information such as passwords, credit card numbers, or other sensitive data.

Example: A user receives an email that appears to be from their bank, stating that there is a problem with their account and that they need to click a link and enter their credentials to resolve the issue. The link redirects to a fake website that collects the information entered.

Smishing is similar to phishing, but it is carried out via text messages text. The term “smishing” is a combination of “text ” and “phishing.” Criminals send text messages that appear to come from trusted sources, encouraging victims to click on links, download malware, or provide personal information.

Example 1: A user receives a text message purporting to be from a delivery company, stating that a bundle could not be delivered and that the user must click a link to reschedule the delivery. The link may lead to a malicious website containing software that is harmful to the device customer (commonly known as “malware”) and/or where personal or financial information is requested.

Example 2: A user receives a text message purporting to be from a telecommunications carrier or other service provider, stating that they owe money to the company in question due to overdue bills and directing them to make a payment at an ATM that is actually unrelated to that company (e.g., 21423, 21800, 11893, 45761, 12101, 12167, among others).

Vishing is a form of phishing that uses phone calls instead of emails or text. The term “vishing” is a combination of “voice” and “phishing.” Criminals call victims, often using fake caller IDs to make it appear as though the call is from a legitimate entity, and try to persuade them to provide personal or financial information.

Example: A person receives a call from someone posing as a representative of their bank, claiming that their bank account has been compromised and that they need to confirm their personal information and account number to resolve the situation. During the call, the victim is tricked into providing sensitive information.

How can you avoid it?

You should follow safe practices:

  • Do not click on attachments or links in emails, in “pop-up” windows (additional browser windows that open automatically) such as “Click Here,” or on suspicious web text s; If you receive a suspicious email, delete it and contact the company whose email the message is attempting to impersonate;
  • When contacted, verify the authenticity of the sender's email address, profile, or phone number;
  • Always assess the appropriateness of the content of emails, instant messages, text , or phone calls;
  • Do not share personal data or follow instructions without verifying the authenticity of the request with other sources—for example, with your bank account manager or a supervisor;
  • Be wary of messages that contain formal language errors, but also don't trust all messages just because they don't contain formal language errors;
  • Do not share sensitive data on social media, as this practice can provide information to potential attackers who want to carry out spear phishing (phishing targeted at a specific person);
  • Be vigilant and do not allow yourself to be persuaded without careful consideration by authoritative demands, promises, or urgent requests.

How to Detect Phishing and Smishing Attacks Using the MEO Image?

When you receive an email or text , pay close attention to the tone and content. These types of messages usually contain serious grammatical errors and ask you to visit a website or open files that do not belong to or are not hosted on MEO’s websites. Be especially on the lookout for emails in your SPAM/Junk folder.
Please note that:

  • Personal information (such as passwords, personal details, access codes, account numbers, phone numbers, etc.) is typically requested;
  • It creates a sense of urgency to prompt a response. A user under pressure is more likely to respond to this type of communication. Phrases such as “Urgent,” “Your account will be canceled,” “Last chance by xx:xx today,” etc., are used;
  • Most of the messages are alarmist (“losing service,” “receiving a prize,” among others) and require you to provide information or click on a link;
  • The messages do not originate from MEO, and the links do not lead to MEO domains either;
  • Never reply, click on links, or download unknown files;
  • MEO emails do not contain ZIP files. The only attachments we send are PDF files, such as the email containing the electronic invoice, which also includes a digital certificate;
  • If our emails or text contain links, they will always direct you to our websites.

How should you handle suspicious emails, text , and other messages?

If you receive an email, text , or MMS from a sender claiming to be MEO that asks you to enter your login credentials for customer or your personal information, please be aware that this is not an email from MEO.
If you have any questions about the authenticity of an email you receive from a sender claiming to be MEO, please contact us immediately. See the next section for instructions on how to report a possible case of fraud.
If you receive a suspicious email, here’s what you should do:

  • Avoid opening files or programmes attached to email messages without first checking them with an up-to-date antivirus, even if the message is from someone you trust. These messages are often used to spread viruses;
  • Avoid opening emails from unknown senders and err on the side of caution even with emails that appear to have been written and sent by people you know;
  • Always be wary of missed calls from unknown or suspicious numbers, especially international ones. If you have any doubts, do not call back.

Other preventive measures:
Be wary of emails written in other languages, containing typos or spelling errors, from unknown senders or with a forged “From:” field, or with subject lines that are unusual or repetitive;
Disable the “Preview Pane” option in your email client to prevent a message containing a virus (usually in HTML) from being processed automatically. If you wish to keep this option enabled, we recommend that you set your email client to receive all messages in text format;
Before subscribing to a value-added service (VAS), carefully read its subscription terms and conditions. Sometimes subscription to these services is disguised as seemingly harmless survey emails.
If you receive an email, text , or MMS stating that you have won a prize, you should question its credibility and contact the entity that sent the message.

How do I report phishing attempts using the MEO image?

To report a phishing incident, create a new email message and paste the “Internet Header” of the email you received into the body of the message, then send it to csirt@telecom.pt.

How do I retrieve the message's "Internet Header" (adapted for Microsoft Outlook)?

In the Outlook message list (main screen), right-click on the ORIGINAL message (it won't work if it's a forwarded message—it has to be the original one) and select the “Message/Options” option (the last option in the list);

In the window that appears, go to the "Internet Headers" box;

Select all the content in the "Internet Headers" box and click Copy.

After reporting the situation, you should immediately delete the email or contact text.

Upon receiving these reports, CSIRT MEO takes the necessary steps to ensure that malicious emails and/or text are not delivered.

These types of attacks are not caused by vulnerabilities or flaws in the infrastructure of MEO SGPS, S.A.

For more information, visit: http://www.antiphishing.org/