Phishing messages try to steal a password, push a fake payment, or get you to open something harmful. Many look polished and use familiar logos — slowing down is the main defence.
Common signs
- Urgency or fear — “mailbox deleted today,” “payment failed,” “unusual sign-in.”
- Login links you did not ask for — especially “verify email,” “mailbox full,” or “shared document.”
- Mismatched sender — display name says a bank or “Cid Hosting Support,” but the real address is unrelated.
- Links that do not match the label — hover (or press and hold on a phone) before tapping.
- Sudden new payment details from a supplier or colleague.
- Unexpected attachments or QR codes that ask you to sign in or pay.
About messages that claim to be from Cid Hosting
- We will never ask for your password by email, chat or ticket.
- The client area is https://clients.cidhosting.net. Type it yourself or use a bookmark — do not trust a link inside a suspicious message.
- Unsure whether a message is genuine? Open a ticket from the client area and ask. Checking is always better than guessing.
If you are not sure
- Do not click links, open attachments or reply.
- Confirm with the sender using a phone number or address you already trust — not the ones in the email.
- If it is clearly fake, delete it or mark it as junk/spam.
If you already clicked or entered a password
- Change that mailbox password right away (webmail Password & Security, or cPanel → Email Accounts → Manage). Change it anywhere else you reused it.
- Check for surprise changes — forwarders, filters or autoresponders you did not create. Attackers often add a forwarder to keep a copy of your mail.
- Update the new password on phones, Outlook and other apps.
- Tell your team if the same message may have reached them.
- Open a ticket at clients.cidhosting.net/submitticket.php with the mailbox and approximate time. Full headers help if you can attach them.
If card or bank details were entered, contact your bank as well.
Habits that help
- Different strong passwords for each mailbox, cPanel and the client area.
- Keep devices and browsers updated.
- Pause before acting on urgent mail — most phishing relies on hurry.
