Sharaxaad
1) Maxay tahay phishing?
“Phishing” waa khiyaano dadka lagu qaldo si ay u bixiyaan eray-sir, koodh mobile-money, ama xog xasaasi ah. Tuugadu waxay isu ekaysiiyaan hay’ad la aamino (bangi, shirkad isgaarsiineed, wasaarad, ama NGO) iyagoo adeegsanaya email, SMS, WhatsApp/Telegram, wicitaan, ama bogag been abuur ah.
2) Sida ay u shaqeyso
Qancin/degdeg: “Lacag ayaa kugu xayiran”, “Abaalmarin ayaad ku guuleysatay”, iwm.
Isu-ekaysiin: Waxaa isku dhigaya hay’ad magaca leh.
Qabsasho xog: Kuu diraya link ama fayl; kugu dalbaya password/OTP/koodh.
Isticmaal xun: Koontada ayay galaan, lacag/xog bay qaataan, ama saaxiibbadaada ayay u sii diraan.
3) Tusaalooyin caadi ka ah Soomaaliya
Koodh EVC/ZAAD: “Si qalad ah ayaan kuugu dirnay—soo dir koodhka si loo celiyo.”
Xisaab baraha bulshada: “Boggaagu wuxuu jebiyay qaanuun—halkan ku xaqiiji 24 saac gudahood.”
Shaqo/NGO been abuur: “Waad u soo baxday—faylka fur ama bixi khidmad si aad u xaqiijiso.”
WhatsApp/Telegram takeover: “Is-xaqiiji oo 6-digit code-ka ii soo dir.”
Canshuur/adeeg: “Hanti ama adeeg ayaa la jarayaa haddii aadan bixin subaxda.”
4) Calaamadaha digniinta
Farriin degdeg ah ama cabsi gelin; ballanqaad abaalmarin.
Cinwaan-email/number shaki leh; domains khaldan.
Links aan ku habboonayn hay’adda ay sheeganayaan.
Codsi password/OTP/koodh lacag—hay’ad dhab ah marna ma weydiisato.
Lifaaqyo lama filaan ah (gaar ahaan .html/.exe ama macro-Office).
5) Haddii aad hesho farriin shakisan
Ha furin link, hana ka jawaabin.
Xaqiiji waddo kale: wac lambarka saxda ah ee websaytka rasmiga ah.
Eeg link-ga ka hor intaadan furin: desktop (hover), mobile (long-press).
Ku wargeli oo tirtir (fiiri Qaybta 8).
6) Haddii aad horay u furtay ama la wadaagtay koodh/eray-sir
Isbeddel password isla markiiba; ha isku mid noqon koontada kale.
Daar laba-tallaabo (2FA); ka fogow SMS haddii ay suurtagal tahay.
Ka bax kulammada oo dhan (log out all sessions).
La xiriir bangiga/telecom-kaaga si loo xannibo ama loo baaro macaamillada.
Kasoo celi qalabka adigoo antivirus isticmaalaya; ku cusboonaysii nidaamka.
7) Ka-hortag (shakhsi & hay’ad)
Adeegso password manager iyo eray-sirar kala duwan.
Daar 2FA dhamaan koontada muhiimka ah.
Cusboonaysii qalabka iyo barnaamijyada si joogto ah.
Baro sida loo aqoonsado cinwaanada iyo link-yada.
Hay’adaha: samee tababarro/imtixaano phishing saddex-biloodle iyo kanaal warbixin fudud (tusaale security@yourorg.so).
8) Sida loo wargeliyo
Baraha bulshada: isticmaal “Report” gudaha app-ka.
Telecom/Bangiga: la xiriir taageerada rasmiga ah si degdeg ah.
Hay’addaada: u sheeg IT/security-ga isla markiiba.
Booliiska/ciidanka la dagaalanka dambiyada elektarooniga (meesha ay ku habboon tahay).
9) Qoraallo wacyigelin kooban
SMS/WhatsApp (Somali):Waligaa la ha wadaagin OTP/eray-sir—bangi, telecom, ama NGO ma weydiinayaan. Xaqiiji adigoo wacaya lambarka rasmiga ah ee websaytka.
Banner (Somali):Ka fiirso ka hor intaadan gujin: hubi link-ga dhabta ah oo ku soo sheeg security@yourorg.so.
10) Siyaasad-yare hay’adaha
2FA qasab u dhig email-ka iyo koontada maamulka.
Dhaqan geli SPF, DKIM, DMARC si loo yareeyo email-spoofing.
Ilaalinta qalabka iyo maareynta cusboonaysiinta.
Hayso buug-falcelin (cidda lala xiriiro, tallaabooyinka xakameynta, ogeysiisyada).