Phishing is the front door for most attacks: a fake bank login, a “your parcel is waiting” SMS, or an accounting email that looks urgent. The goal is to harvest a password or an OTP, or to get a malicious file executed.

The Kalkhan approach rests on one principle: never let the connection happen. That is what CTI-driven web blocking and, on mobile, fake URL checking are there for. This article is not a lab percentage; it collects the warning signs any user or small business can act on every day.

If it looks off, do not click. Read the address bar; a brand logo proves nothing.

Common traps

  • Look-alike domains (typosquatting) and fake panels served over HTTPS
  • Urgency language: “your account will be locked”, “this invoice is unpaid”
  • An unexpected attachment or an “enable macros” prompt
  • Shortened links in SMS and instant messages
  • Fake payment pages reached through a QR code

What should you do?

Reach known sites from a bookmark or the official app. On Windows the Anti-Virus web blocker helps; on Android, Mobile Security and Kalkhan Browser do the same job. If something looks suspicious, head to the support center or contact us.

Related: the mobile security article · the full Threat Watch.