Quick answer
Phishing is a scam where criminals pose as a trusted company or person to steal your passwords, OTPs, bank or card details. Watch for urgency, unexpected links, odd sender addresses, requests for OTPs or PINs, and offers that seem too good to be true. When in doubt, do not click; contact the company through its official app or website.
Phishing arrives by email, SMS (often called smishing), WhatsApp and even phone calls (vishing). Scammers copy logos and language from banks, delivery firms, electricity boards and government departments to look real.
9 red flags of a phishing message
1. It creates urgency or fear
“Your account will be blocked today”, “Your electricity will be cut tonight” or “KYC expired” are classic pressure tactics meant to stop you from thinking.
2. It asks for an OTP, PIN or password
No genuine bank, app or government office will ask you to share an OTP, UPI PIN, CVV or password over a message or call.
3. The sender does not match
Look closely at the sender’s email address or number. Scammers use addresses with small spelling changes or free email accounts.
4. The link looks wrong
Press and hold (on a phone) or hover (on a computer) to see the real web address. Look out for misspellings, extra words or unfamiliar domain endings.
5. It offers something too good to be true
Lottery wins, refunds you did not ask for, easy part-time jobs that pay per “like”, and huge discounts are common bait.
6. It has an unexpected attachment
Invoices, “delivery notes” or APK files you did not expect can install malware. Never install apps from links in messages.
7. The greeting is generic
“Dear customer” instead of your name is a warning sign, though some scams do use personal details.
8. Spelling and grammar are off
Many phishing messages contain errors, odd formatting or a mix of languages, though better-written scams are increasingly common.
9. It asks you to move to another app or call a number
Scammers often push you to WhatsApp, Telegram or a phone call where they can pressure you in real time.
What to do if you clicked a phishing link
- Do not enter any more details. Close the page.
- If you shared bank or card details, call your bank immediately to block the card or account.
- Change passwords for any account you entered, starting with email and banking, and turn on two-factor authentication.
- In India, report financial fraud on the National Cyber Crime Helpline 1930 or at cybercrime.gov.in as soon as possible.
- Report suspicious calls and messages through the Chakshu facility on the Sanchar Saathi portal.
Habits that keep you safe
- Open banking and shopping sites by typing the address or using the official app.
- Turn on two-factor authentication for email, social media and banking.
- Keep your phone and apps updated.
- Talk to older family members about common scams. They are frequent targets.
Frequently asked questions
What is smishing?
Smishing is phishing through SMS. Scammers send text messages with fake links or requests to steal your details.
Will my bank ever ask for my OTP?
No. Banks never ask customers to share an OTP, UPI PIN, CVV or password by call, SMS or email.
Where do I report online fraud in India?
Call the National Cyber Crime Helpline on 1930 or file a complaint at cybercrime.gov.in, and inform your bank immediately.
Sources and further reading
Featured image: Photo: Mohamed Hassan / Wikimedia Commons (CC0)










