The core idea
Pause when a message pressures you to reveal a secret, transfer money or surrender device access. Verify through a channel you find independently. If financial cyber fraud occurs, promptly contact the bank or payment provider and report through 1930 or the national cybercrime portal; reporting does not guarantee recovery.
1. Inspect the requested action
Phishing uses an impersonated message or page to obtain something valuable, such as account access or payment approval. The communication may arrive by email, SMS, messaging app, phone call or QR code. The central question is not whether the logo looks professional; it is what the sender wants you to do and why. Urgency narrows attention: “act in ten minutes” discourages checking. Authority claims discourage disagreement, while a reward can make an unexpected request feel welcome. Neither good spelling nor correct personal details prove authenticity; information can be copied or obtained elsewhere. Slow the decision down. Name the action aloud: “This asks me to reveal a code” or “This gives someone control of my screen.” That translation makes the risk easier to evaluate than the surrounding story.
2. Verify through an independent route
A scam message can include a fake helpline that repeats the same story. Calling that supplied number is not independent verification. Instead, open the organisation's known app, use a previously trusted bookmark, or find contact details on its official site. For a message apparently from a teacher or friend, use an already known contact route, because their account may have been misused. Check the full website host and what the page actually requests. A secure connection symbol only describes the connection; a fraudulent site can also use HTTPS. Do not open a suspicious attachment merely to examine whether it is dangerous. If a task is genuine, the organisation should be able to explain it through its normal process. A claim that you must hide the request from family or staff is another reason to stop.
Sources: CERT-In: Digital Safety Compass Handbook ↗ · MDN: What is a URL? ↗
3. Worked scenario: a scholarship processing message
Pooja receives a message claiming that a scholarship is ready but requires a small processing payment and a login code before evening. The sender knows her college name and attaches a logo. She has not verified any award. Her first task is to separate claims from evidence: the logo and college name are easy to reproduce, while the request exposes money and account access. She does not pay, forward the code or install the suggested app. She checks the scholarship portal through a known official route and asks the college office using an existing contact. If no award appears, she treats the message as unverified and reports it through the relevant platform or official reporting route. The lesson is not that every fee is fraudulent; it is that an unsolicited demand needs independent verification before any action.
Slow the request down
- Name the actionA code, payment, download or device permission?
- Stop the supplied routeA message’s own link or helpline is not independent evidence.
- Verify independentlyOpen the known official app or use an existing trusted contact.
- Respond to harmContact the provider and official reporting channels promptly.
Sources: CERT-In: Digital Safety Compass Handbook ↗ · I4C: National Cyber Crime Reporting Portal ↗
4. Worked scenario: selling a used textbook
Imran lists a used textbook for an invented price of ₹450. A supposed buyer says he must scan a code and approve a request to receive payment. Imran opens his own payment app independently and reads the action. A request to pay the buyer is a debit, not incoming sale proceeds. Ordinary receipt of a UPI payment does not require disclosing or entering a UPI PIN to the buyer. A QR code is a carrier of information, not proof of payment or identity. He cancels the request and checks actual transaction history rather than trusting a screenshot supplied by the buyer. A screenshot can be altered or show a different transaction. He releases the book only after independently confirming receipt under the agreed arrangement. Inspecting amount, recipient and direction matters more than the caller's confident explanation.
Sources: RBI: Financial Awareness Messages ↗ · RBI Ombudsman: Be Aware—financial frauds ↗
5. Device control can expose more than one secret
An unsolicited helper may ask for screen sharing, a remote-control app or installation from a message attachment. Those permissions can expose notifications, account pages and the actions you perform. Do not assume an app is harmless because the caller describes it as a refund tool. Read permission requests in relation to the actual task: receiving a payment does not require a stranger to control the phone. If remote access is already active, end it and disconnect the affected device if necessary, then seek help through trusted channels and use another trusted device for account protection. Preserve relevant evidence without continuing the conversation to investigate the scam yourself. Updates and genuine software reduce some technical risks, but they cannot prevent every payment you willingly authorise after being deceived.
6. Respond with facts and prompt reporting
If money has been lost in cyber fraud, contact the bank or payment provider promptly using its official channel and report through 1930 or the National Cyber Crime Reporting Portal. Keep the transaction reference, time, amount, relevant messages and complaint acknowledgement. Follow the reporting instructions you receive; do not assume a phone call completes every required step. Reporting can support intervention and investigation, but neither this lesson nor the helpline can guarantee recovery. If credentials were disclosed, secure the affected accounts through their official recovery processes from a trusted device. Do not post full account numbers, identity documents or private screenshots publicly while asking for help. Avoid blame: embarrassment can delay useful action. A friend can help organise the record without asking to know passwords, PINs or verification codes.
Sources: I4C: National Cyber Crime Reporting Portal ↗ · RBI: Financial Awareness Messages ↗ · Google: Strong passwords and account recovery ↗
PUT IT INTO PRACTICE
Analyse a fictional suspicious request
- Use this invented message: “Your training seat expires today. Pay ₹200 through this link and tell us the code sent to your phone.” Underline each requested action and each pressure tactic.
- Write an independent verification route without opening the link or contacting the supplied number. Explain what evidence would establish a genuine request.
- Imagine payment already occurred. Create a mock incident record with invented time, amount and reference labels. Add official reporting and account-protection steps.
- Solution reasoning: urgency does not prove a deadline, a supplied link is not independent evidence, and a code can authorise account access. Verify through the institution; after loss, report promptly without expecting guaranteed recovery.
Check your understanding
Why can a polished message still be fraudulent?
Appearance, spelling and logos are easy to reproduce. The requested action and independently verified origin matter more than presentation.
Is calling the message’s own helpline an independent check?
No. It may be controlled by the same sender. Use contact details obtained separately from the genuine organisation.
What is wrong with approving a collect request to receive sale money?
Approval may send your money to the requester. Read the payment direction and independently check actual receipt in your own account.
Why is a payment screenshot insufficient?
It can be altered or refer to a different transaction. Your own transaction record provides a better check of whether funds arrived.
Does reporting at 1930 guarantee repayment?
No. Prompt reporting helps the response, but outcomes depend on the circumstances. Keep acknowledgements and follow official instructions.
How can a friend help without learning your secrets?
They can organise times, messages and references, find official reporting channels and support you while you complete private verification yourself.
