Oops! Facing network problem. Unable to load this page. Refresh
SPRL

Just a moment...

Hello Guest

logo

FAQs

Help Center

Security & Privacy

Recognizing Phishing Attempts

Identify phishing emails and fraudulent websites.

Overview

Phishing is a type of social engineering attack designed to trick you into revealing sensitive information, visiting a malicious website, downloading harmful content, or performing an action that benefits an attacker.

Phishing attempts can appear through email, SMS, messaging applications, social media, websites, or other communication channels. They may imitate trusted companies, colleagues, administrators, financial institutions, or online services.

Security Reminder:
Never provide your SPRL password, authentication codes, API keys, access tokens, or other confidential credentials in response to an unsolicited request.

What Is Phishing?

Phishing attempts typically rely on deception rather than technical exploitation. An attacker may create a convincing message or website that appears legitimate and attempts to persuade you to take an unsafe action.

Common goals include stealing login credentials, obtaining financial information, accessing business accounts, distributing malware, or redirecting users to fraudulent websites.

Phishing MethodCommon Example
Email PhishingA fraudulent email that asks you to sign in, verify information, or open an attachment.
Message PhishingA suspicious SMS or messaging-app message containing an unexpected link or request.
Fake WebsiteA website designed to look like a legitimate login or service page.
ImpersonationA person pretending to be a company representative, colleague, administrator, or support agent.

Common Signs of a Phishing Attempt

Phishing messages often contain one or more warning signs. A single sign does not necessarily prove that a message is fraudulent, but multiple warning signs should be treated seriously.

  • Unexpected requests for passwords or other sensitive information.
  • Unusual urgency or pressure to act immediately.
  • Suspicious or unfamiliar website addresses.
  • Unexpected account verification requests.
  • Unusual payment or billing requests.
  • Unexpected attachments or downloads.
  • Messages containing spelling, formatting, or grammatical inconsistencies.
  • Requests that bypass normal company procedures.

Check the Website Address

Before entering your SPRL credentials or other sensitive information, carefully check the website address in your browser.

Attackers may create domains or URLs that look similar to legitimate websites. A familiar-looking logo, page design, or company name does not prove that a website is genuine.

CheckWhat to Look For
DomainConfirm that the domain is the expected legitimate domain.
URLReview the complete address rather than relying only on visible page content.
HTTPSConfirm that the connection uses HTTPS, while remembering that HTTPS alone does not prove that a website is legitimate.
Unexpected RedirectBe cautious if you are redirected through unfamiliar or suspicious websites before reaching a login page.
Important:
HTTPS indicates that communication with a website is encrypted, but it does not guarantee that the website itself is trustworthy. Always verify the domain and context of the website.

Be Careful With Urgent Requests

Attackers often create a sense of urgency to prevent users from carefully evaluating a request.

Messages may claim that your account will be suspended, a payment is overdue, a security issue requires immediate action, or an important service will stop unless you act immediately.

  • Do not allow urgency to override normal security checks.
  • Verify unexpected requests independently.
  • Contact the organization using a trusted communication channel.
  • Do not use contact information supplied only in a suspicious message.

Protect Your SPRL Credentials

Your SPRL credentials should remain confidential. Legitimate support or business processes should not require you to disclose your password or authentication codes through an unsolicited request.

  • Never share your SPRL password.
  • Never share authentication codes.
  • Never disclose private API credentials.
  • Do not enter credentials into unfamiliar login pages.
  • Do not send credentials through email or messaging applications.
Never Share:
Passwords, authentication codes, API keys, access tokens, recovery information, and other private credentials should never be disclosed in response to an unsolicited request.

Phishing & API Credentials

Attackers may specifically target developers and technical teams by pretending to be support personnel, service providers, or administrators and requesting API keys or other credentials.

API credentials can provide access to automated workflows and should therefore be treated as highly sensitive information.

  • Never send API keys to an unsolicited contact.
  • Do not place API credentials in public repositories.
  • Do not include private credentials in screenshots.
  • Store API credentials securely.
  • Review credentials immediately if you believe they were exposed.

How to Verify a Suspicious Request

If you receive an unexpected request that appears to come from SPRL or another trusted organization, verify it independently before taking action.

  1. Do not click links immediately.
  2. Review the sender and message carefully.
  3. Check the website address before signing in.
  4. Open the organization's official website directly instead of using the supplied link.
  5. Use a trusted contact method to verify unusual requests.
  6. Do not provide confidential information until the request has been verified.
Good Practice:
When in doubt, navigate to the service directly using a trusted bookmark or manually entered website address instead of following a link contained in an unexpected message.

What to Do If You Clicked a Phishing Link

If you accidentally clicked a suspicious link, do not panic. The appropriate response depends on what happened after the link was opened.

  • Close the suspicious website.
  • Do not enter additional information.
  • If you entered your password, change it immediately.
  • Review your active login sessions.
  • Review your account for unusual activity.
  • If an API credential was exposed, secure or replace it immediately where applicable.
  • Contact SPRL Support if you suspect unauthorized account access.

What to Do If You Submitted Your Password

If you entered your SPRL password into a suspicious website, assume that the password may have been exposed.

  1. Change your SPRL password immediately.
  2. Use a new password that has not been used elsewhere.
  3. Review active login sessions.
  4. Sign out of unfamiliar sessions where possible.
  5. Review your account for suspicious activity.
  6. Review your two-factor authentication settings.
  7. Contact SPRL Support if you suspect unauthorized access.

What to Do If an API Key Was Exposed

If you accidentally provide an SPRL API credential to a suspicious website, person, or application, treat the credential as potentially compromised.

  • Stop using the exposed credential.
  • Replace or deactivate the affected credential where applicable.
  • Review recent API activity.
  • Check your connected application or integration.
  • Investigate unexpected activity.
  • Contact SPRL Support if assistance is required.
Important:
Do not wait to investigate a potentially exposed API credential. Take appropriate steps to secure the integration as soon as possible.

Phishing Protection for Organizations

Organizations should include phishing awareness in their security practices, particularly when multiple employees have access to SPRL or related business systems.

  • Educate users about common phishing techniques.
  • Encourage users to verify unusual requests.
  • Discourage credential sharing.
  • Use two-factor authentication where available.
  • Establish procedures for reporting suspicious messages.
  • Define what information employees should never disclose.

Phishing Warning Signs

Warning SignRecommended Action
Urgent RequestPause and independently verify the request.
Suspicious URLDo not enter credentials until the domain has been verified.
Credential RequestNever provide passwords, API keys, or authentication codes.
Unexpected DownloadDo not download or open unexpected files.
ImpersonationVerify the person's identity through a trusted communication channel.
Unexpected Payment RequestVerify the request independently before making any payment.

Phishing Security Checklist

PracticeStatus
Verify unexpected messages before taking actionRecommended
Check website domains before entering credentialsRequired
Never share passwords or authentication codesRequired
Protect API credentialsRequired if using API
Use two-factor authentication where availableRecommended
Verify unusual requests independentlyRecommended
Report suspected security incidentsRequired if applicable

Frequently Asked Questions

What is phishing?

Phishing is an attempt to deceive users into revealing sensitive information, visiting malicious websites, downloading harmful content, or performing an action that benefits an attacker.

How can I tell if a message is phishing?

Look for unexpected requests, urgent language, suspicious URLs, requests for credentials, unusual payment instructions, unexpected attachments, and other behavior that does not match normal communication.

Does HTTPS mean a website is safe?

No. HTTPS protects communication between your browser and the website, but it does not prove that the website itself is legitimate. Always verify the domain and context.

Will SPRL ask for my password?

You should never disclose your password or authentication codes in response to an unsolicited request.

What should I do if I clicked a suspicious link?

Close the page and avoid entering further information. If you entered credentials, change them immediately and review your account security.

What if I provided an API key to a suspicious website?

Treat the credential as potentially compromised. Secure or replace the credential where applicable, review API activity, and contact SPRL Support if assistance is required.

Where should I report a suspicious SPRL link?

Use the SPRL Abuse Reporting process to submit suspicious or abusive SPRL links for review.


Quick Reference

SituationRecommended Action
Suspicious MessageDo not act immediately. Verify the request independently.
Suspicious WebsiteCheck the domain before entering credentials.
Password ExposedChange the password immediately and review active sessions.
API Key ExposedSecure or replace the affected credential and review API activity.
Unexpected Authentication RequestDo not approve it or provide authentication information.
Suspicious SPRL LinkReport it through the SPRL Abuse Reporting process.
Suspected Account CompromiseSecure the account and contact SPRL Support if required.

Learn More:
Explore the SPRL Help Center for detailed guides on Security Overview, Two-Factor Authentication, Managing Login Sessions, Password Security Best Practices, Data Privacy, API Security, Domain & SSL Security, Reporting Security Issues, and Security FAQs.
Tip: Stop and verify before you click. If a message creates unusual urgency or asks for confidential information, independently verify the request before taking any action.

Need more help?

Our support team is always happy to assist you.

×

We use cookies to improve your experience, analyse traffic, and personalise content. By clicking “Accept”, you consent to the use of cookies as described in our Cookie Policy .

Accept cookies Read our Cookie Policy