Skip to main content

How to Spot and Prevent Phishing Attacks

What is phishing?

Phishing is when a scammer pretends to be a trusted company (like RedotPay) to trick you into sharing sensitive information like your password, card details, or recovery phrases. They often use high-pressure language, such as claiming your account is "locked" or "at risk."

How to spot a phishing attempt

Scammers use various channels to reach you. Look out for these common red flags:

  • Suspicious Emails: Messages that look official but come from a fake domain (anything other than @redotpay.com).

  • Fake Websites: Links that take you to a site that looks like RedotPay but has a slightly misspelled URL.

  • Urgent SMS or Calls: Scammers pretending to be "support agents" asking for your 2FA code or card PIN. RedotPay will never ask for these.

  • Social Media DMs: "Agents" reaching out on Telegram, X , or WhatsApp.

Your Security Checklist

Stay ahead of scammers with these three essential steps:

1. Set up an anti-phishing code: This is your most effective defense. Once enabled, every official email from us will include a code chosen by you.


For more details, see our Help Center article on How to Set Up the Anti-Phishing Code.

2. Turn on Two-Factor Authentication (2FA): Even if a scammer gets your password, 2FA prevents them from accessing your account. Ensure this is active in your security settings.


3. Check the URL & sender: Before entering card details anywhere, double-check the website address. Never click links in unexpected emails; instead, type redotpay.com directly into your browser.

What to do if you’ve been targeted

If you accidentally clicked a link or shared your details:

  1. Freeze your card immediately in the RedotPay app.

  2. Change your password and update your 2FA.

  3. Contact us via the official in-app chat so we can secure your account.

Did this answer your question?