Fake pages, fake payment gates and fake apps
Where a scam link actually takes you: a look-alike site, a copy of a payment page or an app that reads your texts. Learn what the padlock does and doesn't mean, how to check a payment page, and which app permissions are red flags.
THE PADLOCK
Encrypted doesn't mean honest
The padlock and https:// mean your connection to that address is encrypted, so nobody in between can read it. They say nothing about who is on the other end. Anyone can get a free certificate for a domain they own, including a scammer's look-alike. So the padlock only matters after you've checked the address itself.
https://sepidbank-ir.com shows a perfect padlock. Your card number travels to it privately and safely, straight into the scammer's hands.
PAYING IN IRAN
Check the payment page's address
In Iran, online card payments go through the Shaparak network, and genuine bank payment pages live on addresses ending in .shaparak.ir. Fake payment pages copy the look exactly, with the amount, the timer and the card form, to collect your card number, CVV2, expiry date and one-time dynamic password. Before typing anything, check that the address really ends in .shaparak.ir and the amount and merchant are what you expect.
Real: an address like sep.shaparak.ir. Fake: shaparak.ir.pay-fast-online.com, which belongs to pay-fast-online.com (lesson 4), or shaparak-pay.ir, which simply isn't shaparak.ir.
Check yourself
Neda follows a link to pay a 180,000-toman phone bill. Which payment page address is the only one she should trust?
- https://shaparak.ir.bill-pay-online.com/card
- https://shaparak-online.ir/payment
- https://sep.shaparak.ir/payment
- https://secure-shaparak.com/ir/pay
Show the answer
https://sep.shaparak.ir/payment
Right. Read from the first single slash backwards: only this one ends in shaparak.ir. The others just use the word shaparak inside someone else's name.
HIDDEN ADDRESSES
Short links and QR codes hide where they go
A shortened link or a QR code shows you nothing about its destination until you open it. That's handy for honest shops and just as handy for scammers. So check after it opens: before you type a password or card number, read the address of the page you've landed on.
A poster in a café offers a discount by QR code. It opens a "login with your bank card" page. Whatever the poster looked like, the address bar is what tells you who you're giving your card to.
FAKE APPS
A file that installs a spy
On Android, an app can be installed from a file (an APK) instead of an app store. Scammers send these through SMS and messengers, dressed up as a court notice, a subsidy form, a wedding album or a delivery tracker. Once installed, some of them quietly read your SMS, including your bank's one-time codes, and forward them to the attacker. The rule: install apps only from the official store you normally use, and never from a link in a message.
"Here are the photos from Saturday, install to view" arrives with a file called album.apk. A real photo is never an app.
Check yourself
Mina lands on a bank-style page with a closed padlock and https:// in the address bar. That's enough to know the page belongs to a real bank.
Show the answer
False
False. The padlock only means the connection is encrypted. A scammer can get one for their own look-alike domain in minutes. Mina still has to read the address itself, or better, open her bank's app directly.
Permissions: fits the job, or a red flag?
Makes sense
A map wants your location. A camera app wants the camera. A messenger wants your contacts. The permission matches what the app obviously does.
Red flag
A viewer, game or "notice" app that wants to read SMS, use Accessibility (which lets it see and tap your screen) or become a device admin. These let an app read codes and control your phone.
Check yourself
Does the permission fit the app?
- A navigation app asks for your location
- A wallpaper app asks to read your SMS
- A "court notice viewer" asks for Accessibility access
- A video-call app asks for the microphone
- A calculator asks to become a device admin
- A photo editor asks for your photos
Show the answer
Fits the job: A navigation app asks for your location, A video-call app asks for the microphone, A photo editor asks for your photos
Red flag: A wallpaper app asks to read your SMS, A "court notice viewer" asks for Accessibility access, A calculator asks to become a device admin
If you already installed something suspicious
- 1 · Cut it off
Turn on airplane mode so the app can't send anything more.
- 2 · Remove it
Uninstall it. If it won't go, look in your security settings for device admin apps, remove its admin rights, then uninstall.
- 3 · Call your bank
If you entered card details or received bank codes while it was installed, call your bank on its official number and block the card.
- 4 · Change passwords from another device
Start with your email, and check your messengers' active sessions.
Check yourself
Hamid installed an app from a messenger link that promised to show a traffic fine. It asked for SMS access, and now it has vanished from his home screen. His bank card is linked to his phone number. What should he do first?
- Wait and see whether any money actually disappears from his account
- Go offline, remove the app and have his bank block the card
- Restart the phone, because a restart removes most hidden apps
- Install a second app from the same link to scan the phone
Show the answer
Go offline, remove the app and have his bank block the card
Yes. An app that reads SMS can forward his bank's one-time codes. Cutting its connection, removing it and blocking the card closes the gap before it's used.
Lesson recap
- A padlock means encrypted, not honest; check the address first.
- Real Iranian bank payment pages end in .shaparak.ir; check the amount and merchant too.
- Short links and QR codes hide their destination, so read the address after they open.
- Install apps only from the official store; an app asking for SMS, Accessibility or device admin without a clear reason is a red flag.