Lab: Spot the Phish & Scam
Every attack-surface map has one pin in common — the human. It is the most reliable way in, because it needs no software flaw at all: just a convincing message and a moment of urgency. This lab trains the instinct that defeats it. No setup, no install — it runs right here.
The exercise
Section titled “The exercise”Read each message, decide scam or legitimate, and check your reasoning against the verdict. Ten messages, India-flavored and real.
The patterns that give a scam away
Section titled “The patterns that give a scam away”However it arrives, fraud reuses the same handful of levers:
- Urgency & fear — “account suspended today,” “you are under arrest,” “24 hours left.” Panic is designed to stop you thinking.
- Look-alike domains & numbers —
hdfc-kyc-verify.inis nothdfcbank.com. Read the real domain, not the brand name in the text. - Money to receive money — you never enter a UPI PIN or pay a “small fee” to get paid. A collect request pulls money from you.
- OTPs are yours alone — no bank, no app, no “officer” ever needs your OTP. The scam is never the OTP message itself; it is the person who calls and asks you to read it out.
- Too-good offers — “₹5,000/day for simple tasks,” “you won ₹25 lakh.” If it’s unsolicited and generous, it’s bait.
The one action to remember
Section titled “The one action to remember”If money does leave your account to a fraudster, speed is everything:
- Call the national cybercrime helpline 1930 and report at cybercrime.gov.in within the “golden hour.” Fast reporting can freeze the funds before they’re withdrawn.
- Tell your bank to block the card/account immediately.
Debrief
Section titled “Debrief”- Which message fooled you, and which lever did it pull?
- This is the human pin that appears on the e-commerce, mobile, car, and IoT maps — the one defenders can’t patch, only train for.
- Teach one person (a parent, a friend) the “never share an OTP” rule this week. That single habit prevents a large share of real-world losses.