Skip to content

Lab: Spot the Phish & Scam

Every attack-surface map has one pin in common — the human. It is the most reliable way in, because it needs no software flaw at all: just a convincing message and a moment of urgency. This lab trains the instinct that defeats it. No setup, no install — it runs right here.

Read each message, decide scam or legitimate, and check your reasoning against the verdict. Ten messages, India-flavored and real.

However it arrives, fraud reuses the same handful of levers:

  • Urgency & fear — “account suspended today,” “you are under arrest,” “24 hours left.” Panic is designed to stop you thinking.
  • Look-alike domains & numbershdfc-kyc-verify.in is not hdfcbank.com. Read the real domain, not the brand name in the text.
  • Money to receive money — you never enter a UPI PIN or pay a “small fee” to get paid. A collect request pulls money from you.
  • OTPs are yours alone — no bank, no app, no “officer” ever needs your OTP. The scam is never the OTP message itself; it is the person who calls and asks you to read it out.
  • Too-good offers — “₹5,000/day for simple tasks,” “you won ₹25 lakh.” If it’s unsolicited and generous, it’s bait.

If money does leave your account to a fraudster, speed is everything:

  • Call the national cybercrime helpline 1930 and report at cybercrime.gov.in within the “golden hour.” Fast reporting can freeze the funds before they’re withdrawn.
  • Tell your bank to block the card/account immediately.
  • Which message fooled you, and which lever did it pull?
  • This is the human pin that appears on the e-commerce, mobile, car, and IoT maps — the one defenders can’t patch, only train for.
  • Teach one person (a parent, a friend) the “never share an OTP” rule this week. That single habit prevents a large share of real-world losses.