First-time keyboard guide
Use this short routine before following the Cybersecurity for Screen Reader Users Manual procedures. It explains exactly how the keyboard directions in this manual work.
Press a single key
- Find the named key without pressing it if possible.
- Press and release the key one time. Do not hold it unless the step specifically says to hold it.
- Stop and listen to the full screen-reader announcement before pressing another key.
Press a keyboard combination
- When a command contains a plus sign, such as Ctrl+S, hold down the first key.
- While continuing to hold the first key, press and release the final key once.
- Release the first key. The plus sign is not a key and should not be pressed.
- Listen for the expected result described in the procedure. If nothing changes, verify that the correct application or webpage has focus and try the command once more.
Press a sequence of keys
- When keys are separated by commas or the word “then,” press and release them in order instead of holding them together.
- After each key, listen for a menu, tab, control, or new screen before continuing.
- If the announcement does not match the step, press Escape once to close the current menu or dialog and restart that procedure.
Know which navigation key to try
- Tab and Shift+Tab: move forward and backward among buttons, links, fields, and other controls.
- Arrow keys: move inside menus, lists, groups of choices, text, and many screen-reader reading views.
- Enter: opens the selected item or activates the focused command.
- Space: activates many buttons and checks or clears checkboxes. In a text field, Space types a space.
- Escape: cancels or closes the current menu, list, or dialog without intentionally accepting a change.
Verify before moving on
- Listen for the window, page, or application name so you know where focus is.
- Perform only one numbered step.
- Compare what the screen reader announces with the “What should happen” information in the procedure.
- If the result is wrong, stop. Use the procedure’s recovery directions, Escape to cancel, or Ctrl+Z to undo when that command is supported.
- Continue only after you can identify the result. Save completed work with Ctrl+S whenever the application supports saving.
First complete independent workflow
This rehearsal joins existing procedures into one uninterrupted session without repeating their directions. Follow the linked procedure when a step names it, then return here for the next verification.
Safety check: Confirm the active application, document or project name, and save location before changing content.
- Open Cybersecurity for Screen Reader Users Manual and wait until its name, starting screen, or connected-device status is announced.
- Choose a fictional, public, disposable, or instructor-provided practice item. Do not use private client, student, medical, financial, or account-recovery information.
- Open 3.1 Verify an Email Sender. Read its “What you will learn,” “Before you begin,” keyboard-command, and expected-result information before pressing anything.
- Complete that procedure one numbered action at a time. After each key, stop and identify what changed before continuing.
- State the result aloud or record it in a practice note. If it differs from “What should happen,” use that procedure’s recovery directions before advancing.
- Continue directly to 3.2 Verify a Caller or Text Sender without closing the application or device session. First confirm that focus, account, file, book, conversation, or project context is still correct.
- Complete the second procedure and verify the resulting name, state, location, permission, value, or content. Do not rely only on a success sound.
- Save or synchronize when the product supports it. Wait for the completed state before disconnecting a device, closing a browser, or switching accounts.
- Continue to 4.1 Inspect a Link Without Opening It. Use the exact command listed there; if the command varies by model or version, use Keyboard Help, the product’s shortcut list, or the linked official reference instead of guessing.
- Introduce one harmless recoverable error, such as opening the wrong menu or moving focus away. Press Escape once, identify the active window or device area, and return to the correct step.
- Review the finished practice item from its beginning. Confirm its title or filename, structure, content, destination, sharing state, and saved or synchronized status as applicable.
- Close and reopen the item or return to it from the product’s main screen. The workflow is complete only when you can locate it and verify the same result independently.
Success standard: Complete all three linked tasks, explain the commands used, recover from the practice error, and locate the finished result without another person directing the next key.
Purpose: This manual teaches practical cybersecurity to people who use screen readers, braille displays, keyboard navigation, or speech access. It assumes no technical security background.
Core approach: Security decisions should not depend on seeing color, logos, icons, hover previews, or visual layout. This guide teaches verification methods that work through accessible text, keyboard commands, screen-reader information, known apps, saved bookmarks, typed addresses, and trusted contact methods.
Safety principle: Urgency is not proof. A legitimate bank, employer, government agency, software company, or family member can be contacted independently. Never let a message force you to use only the contact method inside that same message.
How to Use This Manual
Work through the manual in order. The first sections establish habits used everywhere else.
When a message is suspicious, do not click, reply, call the included number, or open the attachment just to investigate.
Use a known app, saved bookmark, typed website address, statement/card phone number, or trusted contact record to verify independently.
Treat passwords, recovery codes, one-time codes, passkeys, security questions, and remote-control access as credentials.
Keep software updated; security updates close known weaknesses.
Use a password manager and unique passwords where passwords are still required.
Turn on MFA; prefer passkeys or other phishing-resistant methods where available.
If something goes wrong, act quickly: disconnect remote access, secure the account, change credentials, turn on MFA, scan/update devices, and contact the legitimate institution.
Part 1 - The Four Core Cybersecurity Habits
CISA's Secure Our World guidance centers on four simple habits. This manual expands them for screen-reader users.
| Situation | Safer action |
|---|---|
| Recognize and report phishing | Do not engage with suspicious messages; verify independently and report/delete them. |
| Use strong, unique passwords | Use a password manager; do not reuse a password across accounts. |
| Turn on MFA | Use the strongest option offered; prefer phishing-resistant methods where available. |
| Install software updates | Apply security updates promptly from official update mechanisms. |
Password length: CISA's current consumer guidance recommends passwords of at least 16 characters, random and unique for each account, with a password manager to create and store them.
Part 2 - What Phishing Is
Phishing is an attempt to make you open a harmful attachment, visit a fake site, reveal information, approve a login, send money, or install software.
Urgency: 'Act in 30 minutes or your account will close.'
Fear: 'Your computer has a virus.'
Authority: 'This is your bank, boss, police, IRS, Microsoft, Apple, Google, or IT department.'
Reward: 'You won a prize/refund.'
Scarcity: 'Only one item left; pay now.'
Secrecy: 'Do not tell anyone.'
Payment pressure: gift cards, cryptocurrency, wire transfer, payment app, or cash.
Credential request: password, verification code, recovery code, PIN, or remote access.
Screen-reader-specific warning: A link's spoken text can say one thing while its real destination is different. A sender display name can also be forged or misleading. Always verify the actual address/domain when the decision matters.
Part 3 - Accessible Sender Verification
3.1 Verify an Email Sender
What you will learn: Check the actual sender address instead of trusting the display name.
Before you begin: Do not reply yet.
Exactly how to do it
- Open the message without activating links or attachments.
- Move to the From/Sender field.
- Use your email program's message-details or sender-details command to read the full email address.
- Spell the domain character by character if necessary.
- Compare the domain with the organization's known official domain.
- If the message asks for action, leave the message and contact the organization using a known app, saved bookmark, statement/card number, or manually typed official website.
What should happen: You know the actual sender address and have verified the request independently.
If that does not happen: If your email client hides the full address, open message details/headers or use a different trusted client/device. Do not treat a display name as proof.
Practice: Inspect three legitimate messages and identify their full sender domains.
3.2 Verify a Caller or Text Sender
What you will learn: Do not trust Caller ID or the number in the message.
Before you begin: A call/text claims to be from an institution or person.
Exactly how to do it
- Do not provide credentials or money.
- End the call or stop replying.
- Find the contact through a trusted source you already possess.
- Call back using the trusted number, not the number supplied by the caller/message.
- For family emergencies, contact the person or another family member through a known number.
What should happen: You verify identity through a separate channel.
If that does not happen: Caller ID and message sender names/numbers can be spoofed.
Practice: Practice finding a bank or utility number from an official statement or app.
Part 4 - Accessible Link Verification
4.1 Inspect a Link Without Opening It
What you will learn: Determine the destination domain first.
Before you begin: Focus the link but do not activate it.
Exactly how to do it
- Listen to the visible link text.
- Use your screen reader's link-information command or the application's context menu where available.
- Press Shift+F10 on Windows to open the link context menu.
- Choose Copy link address when available instead of Open.
- Paste the copied address into a safe text editor such as Notepad.
- Read/spell the domain carefully.
- Cancel/delete the pasted text after inspection if it contains a personal token.
What should happen: You can examine the destination without visiting it.
If that does not happen: Some tracking links are long or obscured. If the message is asking you to sign in, skip the link entirely and reach the service through a known app/bookmark/typed address.
Practice: Inspect several trusted links and identify the domain.
Domain rule: Read the registered domain, not just words anywhere in the address. A name such as bank.example.com.evil-site.test is controlled by evil-site.test, not by 'bank.example.com'.
4.2 Use the Independent-Path Method
What you will learn: Avoid link analysis when a safer route exists.
Before you begin: A message says an account needs attention.
Exactly how to do it
- Close or leave the message.
- Open the institution's official app, your saved trusted bookmark, or type the known address yourself.
- Sign in normally.
- Check the account's alerts/messages/activity from inside the trusted service.
- If there is no matching alert, treat the original message as suspicious.
What should happen: You confirm the issue without trusting the message's link.
If that does not happen: If the organization is unfamiliar, search for its official website carefully and compare multiple trustworthy sources before entering credentials.
Practice: Verify a harmless account notification by independent path.
Part 5 - Suspicious Attachments and Downloads
Do not open unexpected attachments, even from a known contact, until the sender confirms them independently.
Be especially cautious with executable/installable files, macro-enabled documents, archives, disk images, and files that ask you to enable content.
A filename can be misleading; the extension/file type matters.
Do not install an app or browser extension because a website says it is required to continue.
Use built-in download pages to confirm the filename and source before opening.
5.1 Verify an Unexpected Attachment
What you will learn: Confirm purpose before opening.
Before you begin: An attachment arrived unexpectedly.
Exactly how to do it
- Read the sender's actual address.
- Read the attachment filename and file type.
- Do not open it.
- Contact the sender through a known separate method.
- Ask whether they intentionally sent that exact file.
- Open only after verification and only if the file type makes sense.
What should happen: You reduce the risk of opening malware sent from a spoofed or compromised account.
If that does not happen: If the sender cannot confirm it, delete/report the message and do not open the attachment.
Practice: Practice identifying filename extensions on safe files.
Part 6 - Passwords and Password Managers
Use a unique password for every account.
Prefer a password manager to generate and store passwords.
Do not create patterns such as SiteName2026! across many accounts.
Do not store passwords in ordinary notes, email drafts, spreadsheets, or unencrypted documents.
Protect the password manager itself with strong authentication and recovery methods.
6.1 Use a Password Manager Safely
What you will learn: Reduce memorization and password reuse.
Before you begin: Choose a reputable built-in or independent password manager.
Exactly how to do it
- Create or secure the manager account.
- Turn on MFA/passkey protection for the manager if offered.
- Let it generate a long random password for a test account.
- Save the login.
- Return to the site through a trusted path.
- Use autofill only when the password manager recognizes the correct site/domain.
- Review recovery options and store recovery codes securely.
What should happen: You no longer need to type/reuse the site's password manually.
If that does not happen: If autofill does not appear on a site you expect, stop and verify the domain before manually copying the password.
Practice: Create one unique generated password for a noncritical test account.
Useful security signal: A password manager refusing to autofill on a look-alike site can be a warning that the domain does not match the saved login.
Part 7 - MFA, Authenticator Apps, and Security Keys
MFA requires an additional factor beyond a password. Any MFA is generally better than none, but methods differ in resistance to phishing.
| Method | Security note |
|---|---|
| Passkey / FIDO security key | Strong phishing resistance |
| Authenticator app with number matching or domain-aware approval | Strong when used carefully |
| Authenticator time-based code | Useful, but a phishing site can trick you into entering the code |
| SMS/email code | Better than password alone, but weaker than phishing-resistant options |
7.1 Turn On MFA
What you will learn: Protect an account even if its password is stolen.
Before you begin: Sign in through the service's known official app/site.
Exactly how to do it
- Open Account/Security settings.
- Find Two-factor authentication, Two-step verification, MFA, or similar.
- Choose the strongest method you can reliably use.
- Enroll the authenticator, passkey, or security key.
- Complete a test sign-in.
- Generate recovery codes if offered.
- Store recovery codes somewhere secure and separate from the main device.
What should happen: Future sign-ins require the additional factor.
If that does not happen: Do not turn off MFA because a scammer says it blocks a refund or account repair.
Practice: Enable MFA on a low-risk account before your most important accounts.
Part 8 - Passkeys
Passkeys use public-key cryptography and are tied to the real website/app. Microsoft currently describes passkeys as phishing-resistant and as a form of multifactor authentication because the passkey is on a device and is unlocked by a PIN or biometric.
8.1 Use a Passkey
What you will learn: Sign in without typing a reusable password.
Before you begin: Use a service that supports passkeys.
Exactly how to do it
- Reach the service through its official app/site.
- Open Security or Sign-in methods.
- Choose Add/Create passkey.
- Confirm the trusted device/password-manager location where the passkey will be stored.
- Authenticate with your device PIN, fingerprint, face, or other unlock method.
- Sign out and test the passkey sign-in.
What should happen: The service signs you in without exposing a reusable password to the website.
If that does not happen: If the device says no passkey exists for the site, verify you are on the correct domain and signed into the correct password-manager/account ecosystem.
Practice: Create a passkey on a noncritical supported service if you are comfortable doing so.
Why this helps: A passkey created for one registered domain cannot simply be presented to a different look-alike domain, which blocks a common phishing path.
Part 9 - One-Time Codes and MFA Fatigue
Never give a one-time login/security code to someone who contacted you.
If you receive an MFA prompt you did not initiate, deny it.
Repeated unexpected MFA prompts can mean someone knows your password and is trying to make you approve access.
After an unexpected prompt, change the password from a trusted device/path and review account sessions/security activity.
Recovery codes are more sensitive than ordinary one-time codes because they may bypass your normal second factor.
Part 10 - Browser and Website Security Warnings
Do not bypass a browser's red/interstitial security warning merely because a webpage, caller, or email tells you to.
HTTPS means the connection to that domain is encrypted; it does not prove that the domain is honest.
Certificate/security warnings can indicate a wrong site, interception, or configuration problem.
Use Ctrl+L or Alt+D to focus the address bar and have your screen reader read/spell the domain.
Browser Safe Browsing/SmartScreen warnings should be investigated through the vendor's official security controls, not through pop-up phone numbers.
FTC rule: The FTC warns that legitimate security pop-ups do not tell you to call a phone number for support.
Part 11 - Email Safety
11.1 Handle a Suspicious Email
What you will learn: Use a repeatable no-click workflow.
Before you begin: The message asks for urgent action.
Exactly how to do it
- Do not click or reply.
- Read the full sender address.
- Read the subject and request.
- Inspect attachment names without opening.
- Inspect links only if needed; prefer independent path.
- Open the organization's official app/site separately.
- Report the message as phishing/spam if your mail system provides that control.
- Delete/archive according to your organization policy.
What should happen: You investigate without giving the message control over the verification process.
If that does not happen: If the message concerns work/school, use the organization's phishing-report mechanism or IT/security contact.
Practice: Practice on a known spam/phishing sample without opening links.
Part 12 - Text Messages, Calls, and Voicemail Scams
Package-delivery texts often use links to collect payment/card information.
Bank fraud texts may ask you to call a number or reply YES/NO; use the bank's app or known number instead.
Government agencies and utilities can be impersonated.
Voice cloning can imitate relatives or executives; verify through another trusted person/channel.
Do not let a caller keep you on the phone while directing every computer/phone action.
Part 13 - Tech-Support and Remote-Access Scams
FTC guidance is clear: unexpected callers/messages that say your computer has a problem are a classic scam pattern. Legitimate technology companies do not cold-contact you to announce a virus, and real security warnings do not ask you to call a phone number.
13.1 Respond to a Fake Tech-Support Warning
What you will learn: Keep control of your device.
Before you begin: A pop-up or caller says the computer is infected.
Exactly how to do it
- Do not call the phone number in the pop-up.
- Do not install remote-control software.
- Do not give anyone a code from a remote-support app.
- Close the browser tab/window if possible.
- Open Windows Security or your known security software through Start, not through the pop-up.
- Run updates/scan if you have a genuine concern.
- Contact the computer/software company through its official support site if needed.
What should happen: You avoid granting a scammer remote control.
If that does not happen: If the screen is trapped in a browser full-screen page, try Escape, F11, Alt+F4, or Task Manager before following any instructions shown on the page.
Practice: Practice closing a harmless full-screen browser page.
Payment red flag: FTC warns that tech-support scammers commonly demand gift cards, wire/bank transfer, cryptocurrency, or payment apps because reversal is difficult.
Part 14 - Banking, Payment, Gift Card, and Refund Scams
No legitimate business or government agency needs gift card numbers as payment.
Be suspicious of claims that you were accidentally refunded too much and must return money immediately.
Never move money to a 'safe account' because a caller says your current account is compromised.
Verify charges directly in your bank/credit-card app or statement before responding to a renewal/refund notice.
Do not read card numbers, bank credentials, or one-time codes to an unsolicited caller.
Part 15 - Social Media, Dating, and Impersonation Scams
Account takeovers can make messages appear to come from real friends.
Romance/investment scams often build trust over time before asking for money or crypto.
Executive/boss impersonation scams may request gift cards or confidential documents.
New accounts, sudden urgency, secrecy, and payment changes deserve independent verification.
Deepfake audio/video does not replace independent identity checks.
Part 16 - Shopping, Delivery, and Subscription Scams
Too-good-to-be-true prices and urgency are common phishing signals.
Use retailer apps or typed/saved official addresses rather than delivery-message links.
Subscription-renewal scams often claim a large automatic charge and provide a phone number to cancel.
Check the actual bank/card account first; if no charge exists, the renewal message may simply be bait.
Use credit cards or protected payment methods when possible; avoid irreversible payment methods demanded by strangers.
Part 17 - Software Updates and Safe Apps
17.1 Update from the Official Mechanism
What you will learn: Install security fixes without trusting random pop-ups.
Before you begin: The device is online.
Exactly how to do it
- Windows: open Settings > Windows Update.
- iPhone/iPad: open Settings > General > Software Update.
- Android: open Settings > System / Software update as provided by the manufacturer.
- Browsers/apps: use the built-in update command or official app store.
- Install security updates.
- Restart when required.
What should happen: Updates come from the operating system/vendor rather than a message link.
If that does not happen: If a webpage says 'your browser is out of date' and offers a download, leave the page and update through the browser's official menu or operating system.
Practice: Check one device for updates.
CISA guidance: CISA's consumer security guidance emphasizes installing software updates promptly because they patch known weaknesses.
Part 18 - Backups and Ransomware Resilience
Keep important files in a backup system that is not dependent on one device.
Cloud sync is useful but is not always the same as a backup; deletions/encryption can sometimes synchronize.
Use version history/recycle-bin/recovery features where available.
Keep at least one recovery method that is not continuously writable by the main computer when practical.
Test restoring a harmless file before assuming a backup works.
18.1 Test a Backup
What you will learn: Prove that recovery actually works.
Before you begin: Choose a harmless test file.
Exactly how to do it
- Back up or synchronize the test file.
- Rename the local copy.
- Use the backup/version-history service to retrieve or restore the earlier copy.
- Open the restored file.
- Confirm its contents.
What should happen: You know the recovery process before an emergency.
If that does not happen: If you cannot restore a harmless test file, fix the backup process before relying on it for important data.
Practice: Perform one restore test.
Part 19 - Public Wi-Fi, Bluetooth, and Device Privacy
Prefer your phone hotspot or trusted network for sensitive activity when practical.
HTTPS protects traffic to the correct domain, but phishing sites can also use HTTPS.
Turn off automatic connection to unfamiliar Wi-Fi networks.
Do not accept unexpected Bluetooth pairing requests.
Use a screen lock and device encryption when available.
Lock the device before handing it to someone or leaving it unattended.
Part 20 - Screen Reader and Braille Privacy
Assistive technology creates additional ways sensitive information can be exposed. These are not flaws in screen readers; they are privacy channels that deserve deliberate management.
Speech can be overheard. Use headphones for passwords, banking, health, work, or other sensitive tasks in public.
Refreshable braille can display passwords, messages, account numbers, or MFA prompts to anyone physically close enough to read it.
Screen-reader history/clipboard viewers can contain sensitive text.
Braille Terminal connections can expose host-device content on another device.
Screen curtain/black screen hides visuals but does not protect speech, braille, clipboard, network traffic, or malware.
Do not announce passwords character-by-character through speech when another person is nearby if it can be avoided.
20.1 Protect Password Entry in Public
What you will learn: Reduce audible/braille exposure.
Before you begin: You need to sign in around other people.
Exactly how to do it
- Use a passkey/biometric if available.
- Use headphones if speech feedback is required.
- Use password-manager autofill instead of reading/copying the password manually.
- Clear sensitive clipboard contents afterward if you copied anything.
- Lock the device when done.
What should happen: The credential is exposed less than with manual reading/typing.
If that does not happen: If the environment is not private enough, postpone the sensitive task.
Practice: Practice signing into a low-risk account with autofill.
Part 21 - Account Recovery and Security Alerts
Keep recovery email/phone methods current.
Store recovery codes securely and separately.
Review signed-in devices/sessions periodically on major accounts.
Treat unexpected password-reset messages as alerts, not as instructions to click.
Reach the service independently and inspect security activity.
Remove unknown sessions/devices and change credentials when compromise is suspected.
Part 22 - What to Do After a Scam or Account Compromise
22.1 If You Gave Remote Access
What you will learn: Contain the device and accounts.
Before you begin: A scammer controlled your computer or phone.
Exactly how to do it
- End/disconnect the remote-support session and close/uninstall the remote-access app if safe to do so.
- Disconnect from the network if the attacker may still have control.
- From a clean/trusted device, change passwords for important accounts starting with email and financial accounts.
- Turn on or strengthen MFA.
- Update security software/operating system and run a scan.
- Contact your bank/card provider if financial information or payment was involved.
- Review account sessions and remove unfamiliar devices.
- Report the scam to the appropriate institution and FTC/authorities as applicable.
What should happen: You limit continued access and begin recovery.
If that does not happen: FTC guidance recommends updating security software, scanning/removing identified problems, changing passwords, and turning on two-factor authentication after giving a scammer access.
Practice: Write these steps somewhere accessible before an emergency.
22.2 If You Gave Away a Password or Code
What you will learn: Secure the account immediately.
Before you begin: Use a trusted device/path.
Exactly how to do it
- Change the affected password.
- Change any other account that reused that password.
- Turn on MFA/passkey protection.
- Sign out of other sessions/devices.
- Review recovery email/phone and forwarding rules.
- Review recent activity/transactions.
- Report unauthorized activity.
What should happen: The stolen credential stops being useful or becomes much harder to use.
If that does not happen: If the attacker changed recovery information, use the service's official account-recovery process immediately.
Practice: Practice locating security activity on one important account.
Part 23 - Work and School Security
Follow organizational security policy even if a personal shortcut seems easier.
Use the organization's phishing-report button/address when available.
Do not forward suspicious work messages to a personal account just to inspect them.
Verify payment, payroll, banking, gift-card, and credential-change requests through established business procedures.
Do not install remote-control tools, browser extensions, VPNs, or accessibility software on managed devices without authorization.
Report accidental clicks/credential entry promptly; early reporting can reduce damage.
Part 24 - Accessible Security Checklists
24.1 Before Clicking a Link
☐ Do I know the real sender address?
☐ Was I expecting this message?
☐ Is the request urgent, secret, threatening, or unusually rewarding?
☐ Can I reach the service through a known app/bookmark/typed address instead?
☐ Does the actual destination domain match the organization?
☐ Am I being asked for a password, code, money, remote access, or software install?
24.2 Before Sending Money
☐ Have I independently verified the person/organization?
☐ Is the payment method reversible/protected?
☐ Am I being pressured to use gift cards, crypto, wire transfer, or payment app?
☐ Did someone tell me not to speak with family, bank staff, IT, or police?
☐ Did I verify the request using a known number or official app?
24.3 Before Approving MFA
☐ Did I personally just attempt to sign in?
☐ Does the service/account name match?
☐ Does the location/device information make sense?
☐ Is someone on the phone telling me to approve it? If yes, stop.
☐ Am I seeing repeated unexpected prompts? If yes, deny and secure the account.
Part 25 - Practice Scenarios
Scenario 1 - Bank Text
Situation: A text says your debit card is locked and gives a link.
Safer response: Do not use the link. Open the bank's official app or call the number on the card/statement. Check alerts/transactions there.
Scenario 2 - Microsoft Pop-Up
Situation: A browser page says Microsoft found viruses and gives a phone number.
Safer response: Do not call. Close the tab/window. Run Windows Security/update through Start/Settings if concerned.
Scenario 3 - Boss Gift Cards
Situation: An email display name matches your manager and asks for gift cards urgently.
Safer response: Read the full sender address and verify through the manager's known contact method/work process.
Scenario 4 - MFA Prompt
Situation: Your phone asks you to approve a sign-in you did not start.
Safer response: Deny. Change the password through the official site/app and review sessions.
Scenario 5 - Delivery Fee
Situation: A text says a package needs a small redelivery fee.
Safer response: Go directly to the carrier's known official site/app and enter the tracking number independently.
Scenario 6 - Family Emergency
Situation: A caller sounds like a relative and asks for immediate money.
Safer response: End the call and contact the relative/another family member through known numbers.
Scenario 7 - Shared Document
Situation: A colleague sends an unexpected ZIP file.
Safer response: Confirm with the colleague through a separate channel before opening.
Scenario 8 - Refund
Situation: A caller says you were refunded too much and must return money through a payment app.
Safer response: Do not pay. Check the real account/statement and contact the company through its official support channel.
Part 26 - Quick Reference
| Situation | Safer action |
|---|---|
| Unexpected account alert | Open the official app/site independently |
| Suspicious sender | Read full address/domain |
| Suspicious link | Copy/read destination or avoid it entirely |
| Unexpected attachment | Verify sender separately before opening |
| Unexpected MFA prompt | Deny, then secure account |
| Password needed | Use password manager; unique password |
| Passkey available | Prefer it when practical |
| Security pop-up gives phone number | Do not call it |
| Caller requests remote access | Decline unless you independently initiated trusted support |
| Gift card/crypto/wire demanded | Stop and verify; classic scam indicator |
| Browser warning | Do not bypass on someone's instruction |
| Software update | Use official Settings/app-store/vendor mechanism |
| Possible compromise | Change passwords, MFA, sessions, scan/update, contact institutions |
| Need proof of identity | Use a separate trusted channel |
Screen Reader Verification Pattern
1. Read the actual sender. 2. Read/copy the actual destination only if necessary. 3. Leave the message. 4. Open the service independently. 5. Verify the alert/activity inside the trusted service. 6. Report/delete the suspicious message.
Part 27 - Official Security Resources
FTC - What To Do if You Were Scammed
FTC Consumer Advice - Online Privacy and Security
Google - Make your account more secure
Final Independence Checklist
☐ I know the four core cybersecurity habits.
☐ I can identify common phishing pressure tactics.
☐ I can read and verify an actual sender address.
☐ I can inspect or avoid suspicious links without opening them.
☐ I can verify an account alert through an independent trusted path.
☐ I know how to handle unexpected attachments/downloads.
☐ I use unique passwords and understand password managers.
☐ I understand MFA method differences.
☐ I understand why passkeys are phishing-resistant.
☐ I know never to share one-time or recovery codes with an unsolicited caller/message.
☐ I know that HTTPS alone does not prove a site is legitimate.
☐ I can identify tech-support and remote-access scams.
☐ I can identify gift-card, refund, payment, delivery, and impersonation scam patterns.
☐ I know how to update software through official mechanisms.
☐ I understand backups and can test recovery.
☐ I protect screen-reader speech, braille, and clipboard privacy.
☐ I know what to do after giving remote access or credentials to a scammer.
☐ I can use the no-click verification checklist independently.
Most important habit: A suspicious message should never control both the warning and the verification path. Leave the message, reach the real service or person independently, and verify there. That single habit defeats many phishing and impersonation scams.