Spot fake messages and sign-in pages
Scammers copy the look of trusted services to trick people into typing passwords or sharing codes. Studies of phishing show that convincing visual details fool many people, so it's safer to check the facts than the look (Dhamija, Tygar & Hearst, 2006).
Real Omxus messages
- Come from noreply@omxus.com.
- Contain a 6-digit code or a short notice, and nothing else.
- Never contain a link to sign in.
- Never ask you to reply with a code, a password or your secret words.
Warning signs
- Someone asks you to read out or forward a code. A real code is only for you to type in yourself.
- A message rushes you: "your account will be deleted today".
- A link leads to an address that isn't the site you meant to visit, or isn't auth.omxus.com.
- A code arrives that you didn't ask for. Ignore it. Someone may have typed your address by mistake, or be trying to get in. They can't without the code.
Check the sign-in page
- Look at the web address. The Omxus sign-in page is always on auth.omxus.com. Sites with the sign-in on their own page show their own address.
- A passkey only works on the real site it was saved for. If your device suddenly doesn't offer your passkey on a page that looks familiar, stop and check the address.
If you already typed something in
Change your password straight away, sign out everywhere else, and check your activity.
Research referred to
- Dhamija, R., Tygar, J. D., & Hearst, M. (2006). Why phishing works. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems. doi.org/10.1145/1124772.1124861
Need more help?
Ask the site you were signing in to about its own service. For your Omxus account, try these next steps.