Before opening a download link
- Type or compare the full domain, including unexpected extra words or characters.
- Confirm HTTPS is present, while remembering that encryption alone does not prove legitimacy.
- Look for a consistent publisher identity and working policy pages.
- Avoid links received from strangers, pop-ups or unsolicited private messages.
Before installing a file
| Check | Safer sign | Reason to stop |
|---|---|---|
| Publisher | Matches an independently confirmed developer | Unknown or inconsistent developer name |
| Protection scan | No warning from current device protection | Instruction to switch protection off |
| Permissions | Limited to features the app actually needs | SMS, contacts, accessibility or device-admin access without a clear purpose |
| Integrity | Published checksum matches the file | No verifiable version or integrity information |
Never share these with “support”:
Your password, one-time code, recovery phrase, full payment card details or remote-control access to the device.
If something already feels wrong
- Disconnect the suspicious app or page and do not send more information.
- Change the affected password from a clean device; do not reuse the new password elsewhere.
- Review recent transactions and contact the relevant bank or wallet provider through its official channel.
- Remove unfamiliar apps, profiles and device-administrator permissions.
- Run the built-in security scan and update the operating system.
Device-specific guidance
On Android, keep Google Play Protect enabled. On Apple devices, manually installed enterprise apps can require developer trust; confirm the developer before changing management settings. Android also publishes current information about developer verification for apps installed outside official stores.
Useful official sources
- Google: help prevent harmful apps with Play Protect
- Google: Android developer verification
- Apple: manually installed enterprise apps
Last reviewed: 3 September 2026
