Skip to content

Resources

Tools to Spot the Tell

Practical, plain-language guides to help you check what's real, stay safer online, and know what to do if something goes wrong.

Awareness toolkit

Our Toolkits to keep you safe online

Report an incident

Been targeted? Here's exactly who to contact and what to keep.

The guides

01

Spot the Deepfake

Spot & Verify

Intro

Deepfakes use AI to fake images, video, and even voices, sometimes convincingly. You don't need to be a tech expert to stay safe. You just need a habit of checking before you act.

Key things to know

AI can now copy a face, clone a voice, or forge a document. It's used to impersonate people you know, create fake "proof," or push you into acting quickly. Seeing or hearing something is no longer enough on its own.

What to look for

  • Video that looks slightly off: odd lighting, strange edges around the face, unnatural blinking or movement.
  • Audio that sounds flat, clipped, or a little robotic.
  • An urgent or unusual request that appears to come from someone you know.
  • Content you can only find in one place, with no other source to back it up.

What you can do

Don't act on the content alone. Confirm it through a separate, trusted channel. For example, call the person back on a number you already have. For a suspicious call or voice note, ask something only the real person would know. It also helps to check whether the same content appears on the organisation's official channels. If something can't be confirmed anywhere else, treat it as fake until you know otherwise.

Want to see what DESC did about it?
02

Before You Click

Spot & Verify

Intro

Fake websites and links are built to look real. A few seconds of checking protects your money, your passwords, and your accounts.

Key things to know

Scam links arrive by email, SMS, chat, ads, and QR codes. They often copy a real brand and add a sense of urgency so you click before you think.

What to look for

  • Web addresses that are misspelled or slightly different from the real one.
  • A link that doesn't match who it claims to be from.
  • A login page you reached from a message you weren't expecting.
  • Requests for a password, a payment, or a one-time code.

What you can do

Don't open links from unexpected messages. Reach the website yourself: type the address, or use an app you already trust. On a computer, you can hover over a link to see its real address before clicking. Remember that a padlock and "https" mean the connection is private, not that the site is genuine. If you're unsure about a link, check it first with RZAM. When in doubt, don't enter anything.

Want to see what DESC did about it?
03

Think Before You Trust

Spot & Verify

Intro

Most scams reach us through a message that seems to come from someone we trust, like a bank, a company, a boss, or a family member.

Key things to know

Scammers copy names, logos, and phone numbers. The message is often urgent, emotional, or about money, designed to get a reaction before you check.

What to look for

  • Pressure to act immediately.
  • Requests for payment, gift cards, or a one-time code.
  • A "known" contact reaching you from a new number or account.
  • A sender name that looks right, but a full email address that doesn't.
  • Attachments you weren't expecting.
  • Anything that discourages you from stopping to check.

What you can do

Slow down. Verify the request through a channel you already know. Call the person or organisation directly using a number you have, not the one in the message. A real request will still be there after you check.

04

Use AI Safely

Use AI Safely

Intro

AI tools are genuinely useful, but what you type into them, and what you trust back from them, both matter.

Key things to know

Anything you enter into a public AI tool may be stored or used to improve the system. AI can also be confidently wrong, and it can generate fake images, audio, and "facts" that look real.

Be careful sharing

  • Passwords, ID numbers, or card and account details.
  • Confidential work documents.
  • Other people's personal information.
  • Anything you wouldn't be comfortable posting publicly.

What you can do

Keep sensitive and confidential information out of public AI tools. Double-check important answers against a trusted source. And treat AI-generated images, audio, and claims as unverified until you've confirmed them. Three things to keep in mind: don't assume it's private, don't assume it's accurate, and don't assume AI-made images or audio are real.

05

Clicked Something Suspicious?

What To Do Next

Intro

It happens to everyone, and acting fast makes all the difference. If you've clicked a link, opened a file, or shared information you're now unsure about, don't panic. Most harm can be limited if you move quickly and calmly. Here's exactly what to do.

Key things to know

Act in this order: stop, protect, check, report, monitor.

What to do now

  1. 1
    StopClose the page, message, or file. Don't enter anything more, don't tap more links, and don't reply. If you can, disconnect from Wi-Fi or data for a moment.
  2. 2
    ProtectChange the password for any account you may have exposed, and any other account using the same one. Turn on two-factor authentication. If it's a work account, reset it from a different, trusted device. If you shared card or bank details, contact your bank straight away.
  3. 3
    CheckLook for anything you didn't do: unexpected logins, messages sent from your account, new apps or downloads, or changed settings. Run a security scan on your device. On a work device, tell your IT or security team immediately.
  4. 4
    ReportReport it. In Dubai, you can report cybercrime and online scams. Reporting protects you and helps stop the same scam reaching someone else. Report through Alameen
  5. 5
    MonitorKeep an eye on your accounts, messages, and statements over the next few days. If anything looks off, act on it early.
  6. 6
    Browse fearlesslyRZAM is a web browser plugin that constantly checks each webpage for malicious content. Download it to stay safe
06

Protect Your Digital Life

Protect Yourself

Intro

A few simple habits make your accounts and devices much harder to break into. You don't need to do everything at once. Start with your email and your bank.

Key things to know

Most everyday attacks rely on weak passwords, reused passwords, and out-of-date software. Small fixes close most of the gaps.

12 things you can do today

  • Use a long, unique password for your important accounts.
  • Turn on two-factor authentication wherever it's offered.
  • Use passkeys or "sign in without a password" where it's offered.
  • Use a password manager so you don't have to remember them all.
  • Keep your phone, computer, and apps updated.
  • Lock your devices with a PIN, fingerprint, or face.
  • Be careful on public Wi-Fi: avoid logging into sensitive accounts.
  • Review app permissions and remove what you don't use.
  • Check your privacy settings on social media.
  • Set a recovery email or phone number for your key accounts.
  • Back up important photos and files.
  • Never reuse the same password across accounts.

Help others

Your Family Becomes the Firewall

Share a guide

Send a resource to someone who'd find it useful: a parent, a friend, a colleague.

Set it up together

Sit down with a family member and switch on two-factor authentication together.

Make checking normal

Agree as a family: when something feels urgent or off, you check with each other first.