التصيد والروابط المشبوهة | Phishing & Suspicious Links
تعلّم ببساطة، خطوة بخطوة
Learn simply, step by step
معلومة واضحة، ثم خطوة جديدة.
Clear knowledge, one step at a time.
التصيد والروابط المشبوهة Phishing & Suspicious Links
ما هو التصيد الاحتيالي؟
يُعد التصيد والروابط المشبوهة من أكثر الأساليب المستخدمة لخداع المستخدمين على الإنترنت. يحاول المحتال أن يجعلك تعتقد أن الرسالة أو الموقع تابع لجهة موثوقة، ثم يدفعك إلى الضغط على رابط أو إدخال معلومات حساسة.
قد تصل محاولة التصيد عبر البريد الإلكتروني أو الرسائل النصية أو تطبيقات التواصل الاجتماعي، وقد تنتحل اسم بنك أو منصة تداول أو متجر أو خدمة تستخدمها بالفعل.
كيف تتعرف على رسالة تصيد؟
لا توجد علامة واحدة تكشف جميع محاولات التصيد، لكن اجتماع بعض العلامات التالية يستدعي الحذر:
- الاستعجال: رسالة تخبرك أن حسابك سيُغلق أو أموالك في خطر إذا لم تتصرف فورًا.
- طلب معلومات حساسة: مثل كلمة المرور أو رمز التحقق أو عبارة الاسترداد.
- رابط غير معتاد: عنوان يشبه الموقع الأصلي لكنه يحتوي على اختلافات أو حروف إضافية.
- عرض غير متوقع: جائزة أو استثمار أو مكافأة تبدو أفضل من أن تكون حقيقية.
- مرسل غير معروف: أو عنوان إرسال لا يتطابق مع الجهة التي يدّعي تمثيلها.
ماذا تفعل قبل الضغط على رابط؟
لا تعتمد على شكل الرسالة أو الشعار وحدهما. تحقق من عنوان الموقع والمرسل، وإذا كانت الرسالة تدّعي وجود مشكلة في حسابك، فمن الأفضل فتح الموقع أو التطبيق الرسمي بنفسك بدل الدخول إليه من الرابط الموجود في الرسالة.
ويمكنك أيضًا استخدام
فاحص الروابط المشبوهة من TheCrypTechAI
كخطوة مساعدة لفحص الرابط قبل فتحه.
لا تشارك بيانات الدخول أو عبارة الاسترداد
لا ترسل كلمة المرور أو رموز المصادقة الثنائية إلى شخص يطلبها منك عبر رسالة. وإذا كنت تستخدم محفظة عملات رقمية، فلا تشارك المفتاح الخاص أو عبارة الاسترداد مع أي شخص.
حتى لو بدا الموقع حقيقيًا، تحقق من عنوانه قبل إدخال بياناتك. بعض صفحات التصيد تُصمم لتشبه صفحة تسجيل الدخول الأصلية بدرجة كبيرة.
ماذا لو ضغطت على رابط مشبوه؟
مجرد الضغط على رابط لا يعني دائمًا أن حسابك تم اختراقه، لكن لا تدخل أي معلومات إذا لاحظت شيئًا مريبًا. وإذا أدخلت كلمة مرور أو بيانات حساسة، غيّر بيانات الدخول من الموقع الرسمي وراجع نشاط الحساب وفعّل وسائل الحماية المتاحة.
وللمزيد من أدلة وأدوات الحماية يمكنك زيارة
مركز الأمان في TheCrypTechAI.
كما يمكنك الاطلاع على
إرشادات CISA للتعرف على التصيد والإبلاغ عنه.
الخلاصة
الحماية من التصيد والروابط المشبوهة تبدأ بعدم الاستعجال. افحص المرسل والرابط، ولا تدخل بياناتك من خلال رسالة غير متوقعة، ولا تشارك كلمات المرور أو رموز التحقق أو عبارة الاسترداد. وعند الشك، ادخل إلى الخدمة من موقعها أو تطبيقها الرسمي بنفسك.
What Is Phishing?
Phishing and suspicious links are common methods used to trick people online. A scammer may try to make a message or website look like it comes from a trusted organization, then encourage you to click a link or enter sensitive information.
Phishing attempts can arrive through email, text messages, or social media, and they may impersonate a bank, crypto exchange, online store, or another service you already use.
How Can You Recognize a Phishing Message?
There is no single sign that identifies every phishing attempt, but you should be cautious when you notice one or more of these warning signs:
- Urgency: A message claims your account will be closed or your money is at risk unless you act immediately.
- Requests for sensitive information: Such as your password, verification code, or recovery phrase.
- Unusual links: A web address looks similar to the official website but contains extra or different characters.
- Unexpected offers: A prize, investment, or reward that seems too good to be true.
- Unknown sender: The sender's address does not match the organization they claim to represent.
What Should You Do Before Clicking a Link?
Do not trust a message simply because it contains a familiar logo or design. Check the sender and website address carefully. If a message claims there is a problem with your account, open the official website or app yourself instead of using the link in the message.
You can also use the
TheCrypTechAI Suspicious Link Checker
as an additional step to check an unfamiliar link before opening it.
Never Share Login Details or Recovery Phrases
Never send your password or two-factor authentication codes to someone who requests them through a message. If you use a cryptocurrency wallet, never share your private key or recovery phrase with anyone.
Even when a website looks genuine, check its address before entering your information. Phishing pages can be designed to closely imitate a real login page.
What If You Clicked a Suspicious Link?
Clicking a suspicious link does not always mean your account has been compromised, but avoid entering any information if something looks unusual. If you entered a password or sensitive information, change your login credentials through the official service, review your account activity, and enable available security protections.
For more security guides and tools, visit the
TheCrypTechAI Security Center.
You can also read
CISA's guidance on recognizing and reporting phishing.
Key Takeaway
Protecting yourself from phishing and suspicious links starts by slowing down and checking before you act. Verify the sender and link, avoid entering information through unexpected messages, and never share passwords, verification codes, or recovery phrases. When in doubt, access the service directly through its official website or app.
اختبر فهمك
Check Your Understanding
سؤالان سريعان لتثبيت أهم ما تعلمته.
Two quick questions to reinforce the key ideas.