Can we talk about how I almost gave my bank login to a fake site last month?
I got a text saying my card was locked and the link looked just like my bank's real site, only the URL had an extra hyphen in it. Now I always type the address myself instead of clicking, and I set up a password manager so it won't even fill in on a fake page. What's the one thing you check first before entering your login anywhere?