Recognise and Report Phishing Scams
What is phishing?
Phishing is an attempt by a fraudster to collect personal and/or financial information over email, phone, text message, or social media channels. These fraudsters typically acquire this information by verbally requesting it over the phone, by posting links or false phone numbers on social media sites, or by sending unsolicited emails or texts messages that direct recipients to enter personal information into fake websites or phone systems posing as real ones.
Learn more about protecting yourself from phishing scams on Square’s blog.
Protect sensitive information
Square will never ask you to provide sensitive information such as your username, password, Square customer code, full bank account details, or payment card information over email, phone, or text message.
If you believe you called a fraudulent number for Square or if you receive a suspicious phone call, do not provide any personal or account information and hang up immediately.
If you receive a suspicious email regarding Square, don’t reply to the message, give out any information, click on any links, or open any attachments. Please forward it to firstname.lastname@example.org to report the incident. Do not include any other information in the email you forward. The appropriate team will investigate and take action if needed.
If you think your information has been compromised due to a phishing scam, please change your email and Square account passwords immediately and report the incident through official channels.
Verify the Phone Number
Square may require your customer code for phone support. To contact support or look up your customer code, visit Square’s contact page and sign in to your account. Keep in mind, if our phone line is unavailable or you are contacting us outside of our business hours, you will not see the option to call, but are able to request a callback or send us an email.
If a third party provides you with contact information for Square, please verify the information through an official Square channel before calling.
Verify the URL
Always be sure that you’re on a secure site before entering your Square login information. To do so, check that the web address in your browser is https://squareup.com/login or that the locked Block, Inc. icon has populated next to this web address.
It is common for phishing emails to contain links that direct recipients to a non-secure page where you may be prompted to enter your username and password (and sometimes additional sensitive information).
Set up two-step verification
2-step verification — frequently known as two-step authentication or 2FA — is a tool that provides an extra layer of security for your Square Account, protecting your account from unauthorised access. All you’ll need is a mobile device and an authentication app like Google Authenticator for iOS or Android, Microsoft Authenticator or Authy. You can set up 2FA from your online Square Dashboard.