Your phone is now your wallet, mailbox, photo album and workplace — payments, your bank account, your child’s school chat and family conversations all live on one device. That is why scammers focus on it. The good news: you do not need to be a programmer to protect yourself. A few simple habits and a one-time setup are usually enough. Below we cover passwords, two-step verification, Telegram and SMS scams, bank cards, Wi-Fi, app permissions, children and older relatives, and what to do if you are hacked. Set aside 30–40 minutes to go through the settings as you read.
1. A strong password: long and never reused
The most common mistake is one password everywhere. If any website leaks it, scammers will try it on your email, Telegram and other services. The main rule: a separate password for every important account.
Strength comes from length more than from symbols. A phrase of several random words is easy to remember and hard to crack: a phrase like “apple-river-pencil-rain” is far stronger than “Dilnoza1990”.
What to avoid when choosing a password:
- birthdays, phone numbers, the names of your children or spouse;
- popular combinations like “123456”, “qwerty” or “password”;
- “updating” a password by adding a number at the end (password1, password2);
- keeping passwords in phone notes or in a screenshot.
Password managers
Nobody remembers dozens of passwords. A password manager stores them all encrypted, so you only remember one strong master password. Most phones have one built in (in your Google or Apple account), and separate apps exist too. Bonus: it will not autofill your password on a fake website, because the address does not match — extra protection against phishing.
If that feels too complicated for now, at least set three different long passwords for email, Telegram and your banking app. Email matters most: all your other passwords are reset through it.
2. Two-step verification: a second lock
Two-step verification (2FA) is an extra check on top of your password — a second lock on the door. Even with your password, a scammer cannot pass it.
Turn it on here first:
- Telegram: Settings → Privacy and Security → Two-Step Verification. Set an additional password and a recovery email. Telegram accounts are most often stolen by tricking people into sharing their SMS code; this password closes that door.
- Email (Gmail and others): turn on 2-step verification in the security section.
- Social networks and banking apps: look for a “Security” or “Login” section in settings.
Where possible, use an authenticator app instead of SMS — it shows a code that changes every 30 seconds and is more reliable.
Write the backup codes you get when enabling 2FA on paper and keep them safe at home. If you lose your phone, they get your account back.
3. Scams on Telegram and SMS: how to spot them
Scammers trick people, not technology, by making you feel rushed, frightened or excited. Common scenarios:
- Fake prize: “You have won a phone. Follow the link and enter your card details to claim it.”
- Fake bank call: “Bank security here, there is a suspicious payment on your card. Tell us the SMS code to cancel it.”
- Posing as a friend: a hacked account asks for an urgent loan or sends a “vote for me” link.
- Fake job offer: “Easy work from home” — then money or card details are needed to “register”.
- Fake delivery or government service: “Your parcel has been held” or “you have an unpaid fine”, with a link.
- A file attachment: an .apk file sent as “look at these photos”. Installing it can hand control of your phone to a stranger.
Four questions to ask
Whenever a suspicious message arrives, ask yourself:
- Am I being rushed? (“Only 10 minutes left”, “your account will be blocked now”)
- Am I being asked for a code, password or card details?
- Does the link match the official address exactly, letter for letter?
- Was I expecting this message?
A single “yes” is reason enough to stop. A real bank will never force you to decide within minutes.
Example: imagine Gulnora gets a polite call “from the bank”; the caller knows her full name. “To protect your card, an SMS will arrive — please read me the code.” Gulnora hangs up and calls the official number on the back of her card. The bank says nobody called her. Calling back yourself is the most reliable protection there is.
4. Bank cards and SMS codes
The core rule: never tell anyone your SMS code — not a bank employee, an operator, a police officer or a “friend”. A code only arrives for an action you started. If you did nothing and a code arrived, someone is acting in your name.
Checklist for protecting your card:
- never share the CVV/CVC code on the back, and never send photos of both sides of your card;
- to receive money, the card number is enough; anyone asking for a code, expiry date or CVV to “send” you money is a scammer;
- turn on transaction notifications in your banking app;
- use a separate card with a small balance for online shopping;
- find the temporary card-block function in your banking app in advance;
- download your banking app only from the official store (Google Play or the App Store).
If you see a suspicious transaction, first block the card in the app, then call your bank’s official number.
5. Wi-Fi and internet in public places
Open Wi-Fi in a café, station or hotel is convenient, but others may see your data, and scammers sometimes create fake networks with familiar names.
On public Wi-Fi:
- do not open your banking app or make payments — use mobile data instead;
- turn off automatic connection to open networks without a password;
- check that the website address starts with “https” and that the browser shows a padlock icon.
At home: change the router’s default password (often on a sticker underneath), set a long Wi-Fi password and update the router occasionally. Your internet provider can help.
6. App permissions and updates
Apps ask for permissions: camera, microphone, contacts, location, SMS. A flashlight app does not need your contacts. An unnecessary permission is an unnecessary risk.
Set aside 10 minutes once a month to:
- check “Apps” → “Permissions” for access to SMS, contacts and location;
- delete apps you no longer use;
- update your phone and apps — updates often close security holes;
- install apps only from the official store, and keep installation from unknown sources switched off;
- make sure the screen lock (PIN, fingerprint or face) is turned on.
In Telegram, check Settings → Devices and remove any device you do not recognise.
7. Protecting children and older relatives
The weakest links in a family are often the youngest and the oldest. Explaining and setting things up together works better than banning.
For children
- agree on a simple rule with your child: “If a stranger asks for a photo, an address or a code, tell me first”;
- warn them about links in games that promise “free coins” or “gifts”;
- set up parental controls (Google Family Link, or Screen Time on Apple devices);
- do not link your card to your child’s phone, or require a password for purchases;
- make their profiles private and explain why not to post their school or address.
For older relatives
Parents and grandparents are often trusting and uncomfortable arguing with a “bank employee”. Sit down calmly with them:
- write “Never tell anyone the SMS code, not even the bank” on paper next to the phone;
- ask them to hang up on any suspicious call and ring you instead;
- turn on 2FA in Telegram for them yourself and limit calls from unknown numbers;
- warn them about “your relative is in trouble, send money” calls — always call that relative directly first.
8. What to do if you are hacked or scammed
Anyone can make a mistake. Do not feel ashamed and do not lose time — acting quickly reduces the damage.
Steps in order:
- If you shared card details or a code: block the card in your app immediately and call your bank’s official number.
- Change your passwords: email first, then the hacked account, then every other service that used the same password.
- End all sessions: in Telegram, Devices → “Terminate all other sessions”; email and social networks have a similar option.
- Turn on 2FA if it was not already on.
- Warn the people close to you: through another channel, write “If anyone asks for money in my name, do not respond”.
- Remove suspicious apps: delete any unfamiliar .apk or app; if needed, back up and factory-reset the phone.
- Report it: to the service (e.g. Telegram’s report function) and, if needed, to law enforcement; check official sources such as my.gov.uz for the procedure.
Keep the evidence — screenshots, the scammer’s number, the link, transfer history — for your bank and the authorities.
9. Common mistakes
- “What would anyone steal from me?” — your account can be used to trick your contacts.
- Storing passwords in screenshots — your phone gallery may be uploaded to the cloud.
- Blindly trusting a link from someone you know — their account may have been hacked.
- Postponing updates — “later” turns into weeks.
- Hiding that you were scammed — delaying out of embarrassment makes the damage worse.
A quick checklist
Do these today:
- separate long passwords for email, Telegram and your banking app;
- two-step verification on in Telegram and email, backup codes kept somewhere safe;
- the “never share the SMS code” rule explained to the whole family;
- phone and apps updated, unnecessary permissions removed;
- the list of connected devices in Telegram checked;
- the way to block your card quickly located in your banking app.
Conclusion
Online safety is an everyday habit, not a one-off task. A long password, a second lock, refusing to be rushed and “I never share the code” protect you from most scams. Share this with your family — one conversation can prevent serious trouble.
To build your digital skills further — from computer literacy to cybersecurity basics — see our association’s free programmes. Choose the direction that suits you and submit an application.