Home/Online Safety & Scam Protection
Online Safety & Scam Protection
Accounts, passwords, phishing, scam anatomy, payment safety and recovery — staying safe online as a daily habit.
Passwords, phishing, scam anatomy, payment safety and recovery — the everyday habits that keep accounts and money safe. Government guides, security courses and real BD case material: 41 resources (41 free).
CISA: Manage Application Permissions for Privacy and Security
CISA's free training module on managing application permissions: what apps ask for, why it matters for privacy and security, and how to review and revoke access on phones and computers. Short lessons walk through real permission dialogs and safe defaults. Aimed at everyday users and small-business staff with no security background. Published by the US Cybersecurity and Infrastructure Security Agency as public awareness training.
Define authentication and authorization (Microsoft Learn)
A free self-paced Microsoft Learn training module that teaches identity fundamentals: authentication versus authorization, single sign-on, and how access decisions are enforced. You learn through structured instruction with a short knowledge check at the end, in the vocabulary employers actually use. Aimed at beginners studying for Microsoft's SC-900 security fundamentals exam, and free to anyone. Microsoft Learn is Microsoft's official free training platform.
Introduction to Cybersecurity (Cisco Networking Academy)
Cisco's free self-paced course covering cybersecurity fundamentals: malware types, how devices get infected, safe software sources, updates, and the habits that keep a personal device clean. You learn threat mechanisms and defenses in structured modules with quizzes and a badge on completion. Designed for absolute beginners and career explorers. Offered by Cisco Networking Academy, which has trained millions worldwide.
Bitcoin and Cryptocurrency Technologies (Princeton textbook)
The complete free online edition of Princeton's university textbook on Bitcoin and cryptocurrencies: how Bitcoin works, mining, anonymity, the altcoin landscape, and the community's politics and future. You learn the honest beginner-to-solid map of the space, including why it attracts scams. Suitable for self-study alongside the free Princeton MOOC. Written by Arvind Narayanan and colleagues; the standard university text on the subject.
Authn vs. authz (Cloudflare Learning Center)
Cloudflare's plain-language split of authentication (who you are) from authorization (what you may do), with real scenarios that make the distinction stick. You learn where 401 and 403 responses fit, and why a valid login still cannot open every door. Written for beginners and career switchers. Part of Cloudflare's free Learning Center access-management series.
Avoid Fraud — রুখবো প্রতারক, রাখবো টাকা নিরাপদ (bKash)
bKash's official catalog of real Bangladeshi fraud patterns: fake account-blocked calls, donation and stipend lures, account-update phishing, WhatsApp and IMO impersonation, and fake offers that harvest PINs and verification codes. Each scam is described by what the attacker does, so readers learn to classify new variants by mechanism. It also lists the recovery sequence — call helpline 16247, change your PIN, report the incident. Published in Bangla and English for all bKash users.
Avoid getting locked out of your Google Account
Google's official walkthrough for building an account recovery plan: backup codes printed on paper, a recovery phone and email, and backup options when the primary 2FA device is gone. You learn why recovery codes belong offline and how to rehearse the recovery path before you need it. Aimed at any Google user but the pattern applies to every account you own. Direct from Google's account support academy.
Avoiding Social Engineering and Phishing Attacks (CISA)
CISA's guidance on social engineering — attacks on the human channel rather than the machine. You learn the mechanism behind phishing, pretexting, and baiting: how attackers manufacture trust and urgency, and the habits that neutralise them regardless of the scam's costume. Written for general users and staff awareness training. From the US Cybersecurity and Infrastructure Security Agency.
bKash Security Tips
bKash's official security rules for mobile-money users: never write down or share your PIN, secret code, or security code, and treat every request for them as fraud, because bKash itself will never ask. You learn the standing-secret model in the exact setting Bangladeshi users live in — the PIN that protects the account versus the one-time codes that confirm a transaction. Written for every bKash customer in clear language. Published by Bangladesh's largest mobile financial service.
Cell Phone Fraud (FCC Consumer Guide)
The US Federal Communications Commission's guide to cell phone fraud, with a full breakdown of SIM swapping and number-porting attacks — how a criminal hijacks your phone number to intercept your OTPs and take over bank and wallet accounts. You learn the port-out scam mechanism and the carrier-side protections to demand. Written for consumers, and directly relevant in markets where mobile numbers are identity. From the US telecom regulator.
Getting In and Out of Free Trials, Auto-Renewals, and Negative Option Subscriptions
FTC consumer guide to free trials, auto-renewals and negative-option subscriptions: how 'free' offers hide shipping fees, pre-checked boxes and cancellation traps, and what to do when an unauthorized charge appears. It teaches the reading habits — terms, cancellation path, calendar reminders — that separate a genuinely free tier from a billing trap. Directly applicable to cheap AI tool offers, resold 'unlimited' plans and unknown relay services. From the FTC's consumer advice library.
How To Recognize and Avoid Phishing Scams (FTC)
The US Federal Trade Commission's consumer guide to phishing: how scam email and text messages work, the concrete clues in every phish, and what to do with one. You learn to classify messages by mechanism — fake invoices, account-scare notices, payment requests — instead of memorising brand lists. Written for the general public and used widely in awareness training. The FTC is the US consumer-protection authority.
How To Recover Your Hacked Email or Social Media Account (FTC)
The FTC's step-by-step recovery sequence for a hacked email or social account: contain the damage, change credentials, check recovery settings and forwarding rules, then report. You learn the order of operations that limits loss — the calm checklist to run while panicking. Written for the general public. From the US Federal Trade Commission, the country's consumer-protection agency.
How to shop online safely (ITSAP.00.071) — Canadian Centre for Cyber Security
An official one-page guidance sheet on safe online shopping: how to vet a store before paying, when card-on-delivery beats advance payment, secure payment methods, and how to handle returns and disputes. You learn to separate fake-shop signals from legitimate merchant behaviour. Written for consumers in a printable tip-sheet format. Published by Canada's national cyber security authority.
Introduction to online payments (Stripe Guides)
Stripe's free guide to how online payments actually work: cards versus wallets versus bank transfers, what a payment gateway does, and how authorisation, capture, refunds, and disputes fit together. You learn the payment lifecycle end to end, with receipts and chargebacks explained at each stage. Written for merchants and founders, but the clearest plain-English map of the rails. Produced by Stripe, a major global payments infrastructure company.
Phishing Guidance: Stopping the Attack Cycle at Phase One (CISA)
CISA's deep technical guidance that maps the full phishing attack cycle — reconnaissance, lure crafting, delivery, credential capture — and where defenders can break it. You learn how real phishing operations are built and why certain countermeasures stop whole classes of attacks rather than single messages. Aimed at security practitioners but readable by any motivated learner wanting the mechanism behind the warnings. A free CISA resource with companion PDF.
Scammers use AI to enhance their family emergency schemes (FTC)
The FTC's consumer alert on voice-cloning scams: how a few seconds of audio from social media lets a scammer imitate a grandchild, boss, or relative in a panicked emergency call. It teaches the verification move that defeats the scam, don't trust the voice and call the person back on a number you know, plus the payment tells (wire, crypto, gift cards). Written for families and older adults in the US government's consumer-protection voice. Free public-domain FTC education.
Secure a hacked or compromised Google Account
Google's official incident checklist for a compromised account: regain access, evict attackers' sessions and apps, review recovery and forwarding settings, and check what was exposed. You learn the contain-change-check-report sequence performed on a billion-user account system. Useful to any Google user and transferable to other providers. Direct from Google's account support documentation.
Turn On MFA (CISA Secure Our World)
CISA's practical multi-factor authentication guide: where to switch MFA on, which second factor to prefer, and why it blocks the vast majority of account attacks. You walk through enabling it on email, banking, and social accounts and learn what MFA does and does not protect against. Written for consumers and small organisations. Part of the Secure Our World campaign from the US cyber agency.
Use Strong Passwords (CISA Secure Our World)
CISA's public guidance on creating and handling strong passwords: length over symbols, unique passwords per account, and using a password manager as the default habit. You learn what 'strong' actually means in attacker terms and why memorised password rules fail. Written for general consumers as part of CISA's Secure Our World campaign. CISA is the US Cybersecurity and Infrastructure Security Agency.
What is account takeover? (Cloudflare Learning Center)
An explainer from Cloudflare's free Learning Center on account takeover (ATO): how attackers seize accounts through credential stuffing, phishing, and weak recovery paths, and what takeover actually means for a record held on someone else's server. You learn the attack chain step by step and the defenses that break it, including MFA and breach monitoring. Written for everyday users and IT beginners alike. Cloudflare's Learning Center is one of the most-used free internet-security primers online.
What is HTTPS? (Cloudflare Learning Center)
Cloudflare's explanation of HTTPS and TLS: what encryption in transit actually does to your data, what the padlock icon means, and — crucially — what it does not mean, since an encrypted connection can still belong to a scammer. You learn TLS handshakes and certificate basics in everyday language. Written for website owners and curious users. Part of Cloudflare's free Learning Center SSL series.
What is two-factor authentication? (Cloudflare Learning Center)
Cloudflare's primer on two-factor authentication: why two independent proof channels stop stolen passwords, and how SMS codes, authenticator apps, and hardware keys differ in strength. You learn the mechanism — something you know plus something you have — rather than a checklist. Written for general users and small-business owners. Part of Cloudflare's widely used free Learning Center.
When a Business Offer or Coaching Program Is a Scam
FTC consumer guide to business offers and coaching programs that promise guaranteed income from online storefronts and 'proven systems'. It names the red flags — guaranteed earnings, pressure tactics, upsells, fake testimonials — and the exact questions to ask before paying anyone for a money-making system. The direct template for testing 'make money with AI' schemes, which follow the same playbook with an AI label. Published by the US Federal Trade Commission's consumer education division.
NIST SP 800-63B Digital Identity Guidelines: Authentication
The US government's authoritative rulebook on passwords, PINs, passphrases, and authenticators — the document that killed forced symbol rotation and proved length beats complexity. You learn exactly what makes a secret strong, how PINs differ from passwords, and how recovery codes and 2FA should work. Dense but skimmable, and it is the evidence base behind every modern password recommendation. Free from the National Institute of Standards and Technology.
One-time passwords (OTP) — MDN Web Docs
MDN's reference page explaining what a one-time password actually is: a short-lived token generated for a single transaction, valid once and then worthless. You learn TOTP and HOTP mechanics, why OTPs expire, and why sharing one hands over exactly one transaction. Written for web developers but readable by anyone who wants the mechanism. MDN Web Docs is Mozilla's free, canonical web-technology documentation.
Session hijacking attack (OWASP Foundation)
OWASP's community reference page dissecting session hijacking: the ways an attacker steals or guesses a live session token and acts as you without your password. You learn each hijacking method — sidejacking, XSS token theft, predictable IDs — and the mitigations that close it. Written for developers and security learners. Maintained by the Open Worldwide Application Security Project, the standard body for web security knowledge.
Session management — MDN Web Docs
MDN's deep reference on web sessions: what 'logged in' technically means, how session IDs and cookies carry your login, and how session hijacking and fixation attacks steal them. You learn why 'log out everywhere' works and why banks force re-login after inactivity. Written for web developers but readable by anyone curious about the machinery behind the login. Maintained by Mozilla as free canonical web documentation.
Token types (Google Cloud Authentication docs)
Google Cloud's documentation page that lays out the differences between API keys, access tokens, ID tokens, and refresh tokens — what each proves and how long each lives. You learn why a long-lived API key is effectively a password that never expires, and how credentials should be scoped and rotated. Written for developers, but it is the clearest public map of the token family. Free from Google Cloud's official docs.
Pleasant Green (YouTube)
A YouTube channel where Ben Taylor turns real scam operations into anatomy lessons — fake call centres, romance scams, advance-fee fraud, and the scripts operators read from. You watch scams get dissected in real time, which teaches the urgency-authority-fear-reward pattern better than any list of red flags. Made for general audiences wary of online fraud. Millions of views per video, and widely used by consumer-protection educators.
But how does bitcoin actually work? (3Blue1Brown)
Grant Sanderson's celebrated video lesson that builds Bitcoin from first principles — ledgers, digital signatures, proof of work, and the double-spend problem — with the maths shown, not waved at. You learn what a blockchain actually is and why the design attracts both innovation and scams. Made for curious non-specialists who want the honest mechanism. One of the most-watched explanations of cryptocurrency on the internet.
Institutional roles in issuing and processing credit cards (Khan Academy)
A Khan Academy video lesson explaining the plumbing of card payments: who the issuer, acquirer, card network, and gateway are, and where a transaction actually travels. You learn why a refund or chargeback works the way it does by seeing the money move between institutions. Part of Khan Academy's free core-finance unit on credit cards and interest. Khan Academy is a nonprofit used by millions of learners worldwide.
Video: Malware and ransomware (Get Cyber Safe)
A short official explainer video on malware and ransomware: what malicious code does once it lands, how it arrives through files, USB sticks, and downloads, and how to keep it out. You learn the infection chain in plain language, with device hygiene habits at the end. Aimed at the general public, suitable for classroom use. Published by Get Cyber Safe, the Canadian government's cyber-awareness campaign.
How HTTPS Works
A free illustrated, animated walkthrough of the entire HTTPS story — from a Caesar cipher through symmetric keys, public-key cryptography, certificates, and the TLS handshake. You scroll through the comic-style episodes and watch each concept build on the last. Made for beginners who want the real mechanism without code. A beloved open web explainer used in classrooms and onboarding docs alike.
Spot the Deepfake (University of Washington CIP + Microsoft)
A ten-question interactive quiz from the University of Washington's Center for an Informed Public with Microsoft, Deeptrace, and USA TODAY: you watch real and AI-manipulated videos and decide which is which, then get taught the reasoning. It trains the habits that matter when agents and scammers generate media: checking context and motivation rather than trusting your eyes, and verifying elsewhere before acting. Built for the general public and used in news-literacy teaching. Free, no account.
Consumer Protection in Digital Credit (CGAP)
CGAP's research publication on consumer risks in digital lending: how app-based credit really prices risk, what data access these apps demand, and how over-indebtedness and predatory practices spread. You learn the fine print of digital loans — interest structures, fee stacking, and collection tactics — from evidence gathered across emerging markets. Aimed at policymakers and informed consumers. CGAP is a global partnership housed at the World Bank Group.
Fighting back against harmful voice cloning (FTC Consumer Alert)
An FTC consumer alert explaining AI voice-cloning scams: how a few seconds of audio become a fake family emergency call, and the verification habit that defeats it. You learn why 'sounds like my relative' is no longer evidence and what to demand instead — a callback on a known number. Written for families and caregivers. From the US Federal Trade Commission's consumer-advice desk.
How to spot and avoid task scams
FTC consumer alert on task scams: unexpected messages offering easy money for clicking, rating or 'boosting' tasks through an app, with fake earnings counters that end in a crypto deposit demand. It breaks down the mechanics of the con — small real payouts to build trust, then fees to 'unlock' fake earnings. The clearest public anatomy of the fake-earning schemes that now wear AI branding. Written for anyone receiving work offers over WhatsApp, Telegram or social media.
Principle of least privilege (PoLP) — SailPoint Identity Library
A long-form article defining the principle of least privilege: every account, app, and device gets only the access a task needs and nothing more. You learn how over-privilege turns one stolen login into an incident, and how the same principle maps to personal life — shared family logins, viewer versus owner roles, and guest accounts. Written for a broad identity-security audience in plain language. From SailPoint's free educational Identity Library.
StaySafeOnline: Public Computers and Public Wi-Fi
The National Cybersecurity Alliance's guide to staying safe on public computers and public Wi-Fi: what open networks risk, and practical habits like HTTPS, VPNs, and forgetting networks. Written in plain language with actionable checklists for people on the move. Aimed at everyday internet users, not security professionals. Free consumer guidance from the Stay Safe Online campaign.
The Cost of Convenience: Identifying, Analyzing, and Mitigating Predatory Loan Applications on Android
An academic research paper that dissects predatory loan apps at the code level: the excessive permissions they harvest, the harassment and data-extortion tactics they deploy, and how they evade app-store review. You learn the actual mechanism behind predatory lending apps — contacts, photos, and location taken as collateral — rather than headlines. Written for researchers and advanced learners. Produced by the Boston University Security Lab.