UNIVERSAL ANALYSIS · OCR · SOCIAL ENGINEERING
How to detect and analyse an online scam: a practical guide
A scam may start with a text message, continue on WhatsApp or arrive as an altered invoice by email. Threats are not limited to a single channel.
Manual checks have limits when facing such variety. Learn to analyse an online scam with a clear method: understand the request, examine the available evidence and take appropriate precautions before sharing data.
1. Three common foundations of online manipulation
Email, image, QR code or PDF: look beyond the format and ask what you are being pressured to do.
Urgency and time pressure
“Action required within 24 hours”, “your pass will be suspended”: these phrases try to make you act before thinking. Pause and verify the request through an independent channel.
Impersonating a trusted authority
Names, logos and signatures may imitate a public service, bank, regular supplier or your management team. A familiar appearance does not establish the sender’s legitimacy.
Departing from normal procedures
Entering credentials through an external link, secretly changing bank details or enabling macros in an unexpected document: an unusual request calls for verification even when the message looks convincing.
2. How does universal threat analysis work?
When you do not know which tool to choose, a single entry point helps organise online scam analysis into three steps.
Extract text from images and PDFs
Universal analysis can read text in a PDF or use optical character recognition (OCR) on an image or screenshot. Readability, layout and document quality affect extraction: review the recognised elements before continuing.
Identify the elements to check
SecurCheck identifies recognised URLs, email addresses, phone numbers, IBANs, companies or crypto elements and can decode a readable QR code. It suggests suitable modules. A screenshot does not necessarily contain email headers or all the information in the original document.
Compare signals and available sources
Depending on the selected module, checks examine link structure, domain reputation, observable redirects or content inconsistencies. Unavailable sources and report limitations matter when interpreting the result. No reported threat does not prove that an item is safe.
One checking habit across your business channels
Social engineering can target employees through a message, screenshot, invoice or QR code. Existing protections do not cover all these formats in the same way.
SecurCheck Business gives teams a starting point to analyse an online scam and understand detected signals. The report complements internal procedures and helps reporting to support; it guarantees neither a three-second verdict nor the absence of risk.
Explore the offer for your business processes3. What to do when something looks suspicious
Stop the suspicious interaction
Do not reply, open links or attachments, or approve payment or authentication requests. If a suspicious page is already open, close it without further interaction.
Preserve useful evidence
Keep the original message, sender details, timestamps and a screenshot if you can capture it without reopening dangerous content. Do not delete evidence needed by IT or for a report. A screenshot alone does not replace the original message.
Verify through an independent callback
Contact the partner, bank or colleague using an already known number or one from their official website. Do not use contact details in the suspicious message to verify that same message.
Alert IT support
At work, promptly report the context to IT or security: what you received, opened, downloaded or entered. The team can assess the scope and decide on appropriate blocking or account-protection measures.
Centralise checks to make better decisions
Polished presentation does not establish that a document or link is legitimate. Comparing context and technical signals helps detect an online scam and interrupt pressure tactics. Universal analysis makes this habit easier without replacing independent confirmation for sensitive requests.