Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What should users do when a text message…
Cyber Security

What should users do when a text message appears to come from a public authority during a crisis?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Cyber Security

Users should ignore the embedded link, avoid replying with sensitive information, and navigate directly to the authority’s official website or app. They should also report suspicious messages to their mobile provider or internal security team when possible. That simple habit reduces exposure to phishing kits, identity theft, and malware that often ride on crisis-related messaging.

Why crisis text messages from public authorities deserve suspicion

Crises create urgency, and urgency is exactly what impersonation campaigns exploit. A message that appears to come from a public authority can still be a phishing lure, a malware delivery path, or a request to capture personal data under pressure. The safest assumption is that the message may be fake until the source is verified through an independent channel.

The key problem is not just the message content, it is the trust shortcut it tries to create. Attackers often borrow the language, logos, and timing of real authorities to make recipients act before they think. That means the security failure happens at the point of trust, not only after a malicious link is clicked or a reply is sent.

Do not use the link, phone number, or reply path inside the text message. Open a browser manually and go to the authority’s known official website, use its published app, or call a number from a trusted source such as a prior statement, government directory, or the organisation’s official contact page. If the message is genuine, the same instructions should be visible there.

This approach matters because it breaks the attacker’s control over the next step. A fake link can lead to a credential-harvesting page, a payment trap, or a site that installs malicious content or captures form data. Independent navigation also helps users spot small inconsistencies, such as odd domains, shortened URLs, spelling errors, or requests that do not fit the crisis context.

If the message asks for account details, bank information, identity documents, one-time codes, or payment, treat that as a strong warning sign. Public authorities rarely need sensitive data by text in an urgent ad hoc exchange, especially during fast-moving events. If the same request is not present on the official site or app, assume the text is fraudulent.

What to do when the message looks urgent or threatening

Pause before acting, even if the message claims there is a deadline, fine, safety issue, or access restriction. Crisis-themed lures are designed to compress decision time. The right response is to slow the process down, verify from the outside, and avoid sharing anything that could help an attacker pivot into another account or device.

Reporting the message is also part of the defensive response. Where possible, forward it to the mobile provider’s spam or abuse channel, or escalate it to an internal security team if it reached a managed device. That creates visibility for broader filtering, warning, or incident handling, especially when the same lure is circulating widely.

If you already tapped the link or entered information, change any relevant passwords immediately through the official service, watch for account activity, and notify support or security staff if payment, identity data, or multifactor codes were exposed. The earlier the response, the easier it is to limit follow-on abuse.

Risk and Threat Considerations

Crisis impersonation messages are attractive because they combine authority, urgency, and fear. That combination increases the chance of credential theft, identity abuse, device compromise, and fraudulent payment or enrolment activity, especially when recipients are distracted or seeking help quickly.

Failure mechanism: The attacker relies on a trusted-looking message to push the user onto an attacker-controlled site or into a reply that discloses sensitive information, then uses the captured data or malicious payload to extend access.

Impact: The result can include account takeover, malware infection, loss of personal data, and secondary fraud against the user or their organisation, especially if the same credentials or device are reused elsewhere.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingCrisis texts use deceptive lures to induce user action and credential disclosure.
Recommendation — Map suspicious crisis texts to phishing and train users to verify outside the message path.
CIS Controls v8CIS-17 — Incident Response ManagementSuspicious texts should be reported so security teams can triage and contain abuse.
Recommendation — Define a reporting path for suspicious messages and route them into incident handling.
NIST CSF 2.0PR.AT-01 — Awareness and TrainingThe answer depends on users recognising and resisting impersonation under urgency.
RS.CO-02 — Incident ReportingUsers need a clear route to report suspicious messages to providers or security teams.
Recommendation — Teach users to distrust embedded links and verify authority messages independently. Provide a simple channel for reporting suspected phishing texts quickly.
NIST SP 800-53 Rev 5AT-2 — Awareness TrainingUsers need training on impersonation, urgency cues, and safe verification habits.
Recommendation — Train personnel to verify official communications through trusted channels only.

Practitioner Guidance

What to verify: Users should verify the destination independently before any click or reply. The practical test is simple: if the message is important, the same instruction should be reachable from the authority’s official site or app without following the texted link.

Common mistake: People often trust crisis messages because they look timely and official. The safer habit is to treat urgency as a reason to verify more, not less, because urgency is the attacker’s main advantage.

Escalation / exception: If a message asks for credentials, payment, codes, or identity documents, treat it as high risk and escalate quickly if the message reached a managed environment. That is true even if the text appears to reference a real event.

Practitioner takeaway: The right control is behavioural, not technical, first, stop, verify through an independent path, and report the lure so that one crisis message does not become an account compromise or malware incident.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org