Identity and accounts · ImmediateBusiness account takeover
Unknown sign-in, password change or messages sent without your action.
First action: Use a trusted device to revoke sessions, change access and enable multi-factor authentication; alert the IT team.
Preserve: Times, sign-in alerts, available logs and sent messages.
Escalate: If other accounts or data may be affected, activate the incident process and assess notification duties.
Check an entity →
Identity and accounts · PromptImpersonating profile
A profile copies a name, photo or role to contact third parties.
First action: Warn exposed contacts through a known channel and report the profile to the platform without engaging the apparent operator.
Preserve: Exact URL, handle, dated captures and messages received by contacts.
Escalate: For fraud, threats or harm, contact the appropriate services and record each report.
Check an entity →
Identity and accounts · PromptExecutive spoofing message
An urgent request for payment or documents uses a leader's name.
First action: Pause the request and call the person using a previously known number outside the received thread.
Preserve: Full message with headers, sending address and payment instructions.
Escalate: If a transfer was made, contact the bank and internal response team immediately.
Check an entity →
Identity and accounts · PromptLost business device
A device with access to accounts or files is no longer under control.
First action: Report the loss, revoke sessions and apply authorised remote management actions.
Preserve: Last known location, time, model and accessible accounts.
Escalate: Assess sensitive data exposure and required next steps with the responsible teams.
Check an entity →
Fraud and payment · PromptSuspicious link opened
Someone followed an unexpected sign-in or delivery link.
First action: Return to the service through its official address; if credentials were entered, change them and revoke sessions.
Preserve: Received URL, original message, time and actions after opening.
Escalate: If a file ran or business access was used, alert the IT team.
Check a message →
Fraud and payment · ImmediateSuspicious bank transfer made
A payment went to an unverified or changed beneficiary.
First action: Contact the bank immediately through its official channel to request recall or blocking steps.
Preserve: Transfer order, references, exchanges, invoice and approval timeline.
Escalate: Alert relevant owners and make reports appropriate to the case.
Check a message →
Fraud and payment · PromptInvoice bank details changed
An email announces a new account number or beneficiary.
First action: Hold payment and confirm the change with a previously verified supplier contact.
Preserve: Old and new invoices, full emails and approval records.
Escalate: If payment was made, follow the suspicious transfer procedure.
Check a message →
Fraud and payment · VerifyQuestionable recruiter or job offer
A listing quickly asks for identity documents, bank details, fees or software installation.
First action: Find the role on the employer's official site and contact recruitment through an independent channel.
Preserve: Listing, recruiter profile, email domain and requests made.
Escalate: If data was already shared, assess its nature and protect affected accounts.
Check a message →
Fraud and payment · PromptDomain mimicking an organisation
A site copies a brand under a slightly different address.
First action: Do not enter information; alert the brand owner and domain owners.
Preserve: Full URL, dated captures, redirects and messages distributing the link.
Escalate: If the site actively collects credentials or payments, accelerate reports and warnings to affected people.
Check a message →
Data and exposure · PromptSensitive file publicly accessible
An internal document appears in a search result or at an open URL.
First action: Restrict access with the service owner without spreading the URL; assess the exposure scope.
Preserve: URL, date, server response, data type and minimal proof of visibility.
Escalate: Have the appropriate owners assess duties tied to the affected data.
Audit exposure →
Data and exposure · ImmediateCredential or secret disclosed
A password, token or key appears in an accessible source.
First action: Revoke the secret, rotate dependent access and review abnormal use.
Preserve: Location, discovery time, secret type and usage logs without copying the secret into notes.
Escalate: Treat as an incident if unauthorised use is possible or observed.
Audit exposure →
Data and exposure · PromptData export shared in error
A file containing personal data was sent or published to the wrong recipient.
First action: Stop sharing, request removal through the proper channel and identify recipients and data precisely.
Preserve: Original file, recipient list, timestamps and removal actions.
Escalate: Promptly assess notification duties and impact on individuals.
Audit exposure →
Data and exposure · ImmediatePrivate details published with a threat
Address, phone number or other private details are posted with a targeted threat.
First action: Prioritise the person's safety and contact emergency services for immediate danger; request platform removal.
Preserve: Links, dated captures and threat context without republishing the details.
Escalate: Involve security owners and relevant authorities according to severity.
Audit exposure →
Reputation and content · VerifyUnusual wave of negative reviews
Several similar reviews appear over a short period.
First action: Document the timeline, check verifiable facts and respond only once the context is understood.
Preserve: URL, date and content of each review and any real transaction link.
Escalate: Report reviews breaching platform rules with factual evidence.
Assess a claim →
Reputation and content · PromptPotentially manipulated audio or video
Media attributes disputed words or acts to a person.
First action: Pause distribution and seek the original version, surrounding frames and independent corroboration.
Preserve: Original file, URL, publication date, apparent author and repost chain.
Escalate: If it drives fraud or threats, coordinate protection and reporting.
Assess a claim →
Reputation and content · VerifyOnline rumour spreading
A claim spreads without a clear primary source.
First action: Identify the earliest traceable post and separate reposts from independent confirmation.
Preserve: URLs, dates, versions of the claim and supporting or contradicting evidence.
Escalate: Choose a response proportionate to actual reach and verified harm.
Assess a claim →
Identity and accounts · ImmediateUnexpected repeated MFA prompts
Sign-in approvals appear when nobody is trying to sign in.
First action: Deny the prompts, use a trusted device to change the password and revoke sessions; alert the IT team.
Preserve: Times, affected service, notifications and sign-in logs.
Escalate: Check successful sign-ins and newly added MFA methods.
Check an entity →
Identity and accounts · PromptAccount recovery channel changed
An account backup phone or email changed unexpectedly.
First action: Open the service through its official address, regain control and revoke sessions from a trusted device.
Preserve: Change notices, previous settings and sign-in times.
Escalate: If access remains lost or the service is sensitive, contact official support and internal owners.
Check an entity →
Identity and accounts · ImmediateMobile line lost alongside account alerts
Service disappears unexpectedly while several accounts show sign-in codes or warnings.
First action: Contact the carrier through its official channel and protect accounts tied to the number from a trusted device.
Preserve: Time service was lost, carrier messages and account alerts.
Escalate: Promptly assess payments, work access and recovery methods tied to the line.
Check an entity →
Identity and accounts · PromptOfficial social account locked out
A team loses access to a public account used to speak for the organisation.
First action: Check other accounts and channels, start official recovery and alert communications owners.
Preserve: Account URL, last known access, recent posts and change notices.
Escalate: Warn followers through an authenticated channel if unauthorised messages may have appeared.
Check an entity →
Fraud and payment · ImmediateFake support gained remote access
A caller obtained control of a device while claiming to resolve a warning.
First action: End the unverified session with IT help; use another device to protect accounts and payments.
Preserve: Approach number or URL, installed tool, times, observed actions and any receipts.
Escalate: Have the device and accounts assessed before normal use; contact the bank if payment occurred.
Check a message →
Fraud and payment · PromptPayment QR code replaced
A code on an invoice, poster or page leads to an unexpected recipient.
First action: Pause payment and obtain details from the supplier or organiser through an independent channel.
Preserve: Code-bearing material, destination URL, displayed beneficiary and scan time.
Escalate: If payment was sent, contact the payment provider and document where the code appeared.
Check a message →
Fraud and payment · PromptMarketplace payment moved off-platform
A buyer or seller asks to leave the marketplace to pay, receive or confirm delivery.
First action: Check the platform rules and payment system without opening the received link.
Preserve: Listing, profile, messages, external URL and proposed terms.
Escalate: If details or money were shared, contact the payment provider and report the account to the platform.
Check a message →
Data and exposure · ImmediateUnknown mail forwarding rule
An account has forwarding or deletion rules the owner did not create.
First action: Revoke sessions, protect the account from a trusted device and review rules and delegated access.
Preserve: Rule settings, creation date if available, sign-ins and affected messages.
Escalate: Assess exported data and exposed correspondents with the responsible team.
Audit exposure →
Data and exposure · PromptCloud share link circulated too widely
A link gives unintended people access to a shared folder.
First action: Restrict the link with the folder owner and check nested permissions without redistributing the URL.
Preserve: Share settings, date, file types and available access logs.
Escalate: Assess actual access and any duties tied to the data involved.
Audit exposure →
Data and exposure · PromptFormer staff access still active
An account or delegation remains active after someone has left.
First action: Have service owners revoke sessions, access and delegated rights; check shared accounts.
Preserve: Rights list, departure and deactivation dates, available usage logs.
Escalate: If unusual activity appears, activate incident response and assess affected data.
Audit exposure →
Reputation and content · PromptForged public statement
A document or post announces a decision with no trace on official channels.
First action: Check with communications owners and preserve the circulated version before responding publicly.
Preserve: URL, file, date, relay accounts and comparable official version.
Escalate: If it drives fraud or concrete harm, coordinate a clarification and appropriate reports.
Assess a claim →
Reputation and content · PromptAd impersonating a brand
A sponsored ad uses a brand to lead to an unrecognised offer or domain.
First action: Check the campaign with the brand owner and avoid the ad link.
Preserve: Ad capture, visible ad identifier, final URL and observation date.
Escalate: Report the ad to the platform and warn exposed audiences if it collects payments or credentials.
Assess a claim →
No scenario matches these filters.