Phishing is a form of online fraud in which criminals impersonate a trusted organisation – a bank, a government portal or a well-known brand – to trick you into revealing sensitive information such as passwords, OTPs, card numbers or UPI PINs. It usually arrives as a fake email, SMS, phone call or website that is designed to look completely genuine.

The word is a play on “fishing”: the attacker casts out bait, in the form of a convincing message, and waits for a victim to bite. Because the trick relies on manipulating human trust rather than breaking through technical defences, phishing remains one of the most common and damaging cyber threats faced by ordinary internet users in India and worldwide.

How does a phishing attack actually work?

A typical phishing attack follows a simple pattern. The fraudster sends a message that appears to come from a legitimate source and creates a sense of urgency – your account will be blocked, a payment has failed, or you have won a prize. The message contains a link to a counterfeit website or a request to call a number.

When the victim clicks the link, they land on a page that closely mimics a real bank, wallet or government site. Any details entered there – login credentials, card numbers, or the one-time password sent by the bank – flow straight to the attacker, who then uses them to drain accounts, make purchases or commit identity theft. In some cases the link silently installs malware instead.

What are the most common types of phishing in India?

Phishing has evolved into several distinct forms. Understanding them helps you recognise an attack whatever channel it uses.

  • Email phishing: mass emails that imitate banks, tax authorities, delivery firms or email providers, asking you to “verify” your account.
  • Smishing: phishing by SMS, often carrying fake KYC-update, electricity-disconnection or parcel-delivery messages with a malicious link.
  • Vishing: voice phishing, where a caller poses as a bank officer, telecom agent or government official to extract OTPs or remote access.
  • Spear phishing: a targeted attack aimed at a specific person or employee, using personal details to appear more convincing.
  • Clone and website phishing: fake third-party websites that copy a genuine bank, e-commerce or search-engine page, a technique the Reserve Bank of India highlights in its customer-awareness material.

What are the warning signs of a phishing message?

Most phishing attempts share tell-tale characteristics. Treat a message with suspicion if it shows any of these signs:

  • It demands urgent action or threatens to block your account or service.
  • It asks for a password, PIN, OTP, CVV or full card number – details no genuine institution requests.
  • It uses a generic greeting such as “Dear Customer” instead of your name.
  • The sender address or website link is slightly misspelt or uses an unusual domain.
  • It contains spelling and grammar errors, or a link hidden behind a shortened URL.
  • It offers a prize, refund or job that seems too good to be true.

Phishing vs vishing vs smishing: what is the difference?

These three terms describe the same fraud delivered through different channels. The table below summarises how they compare.

Feature Phishing (email) Smishing (SMS) Vishing (voice call)
Main channel Email Text message Phone call
Typical bait Account verification, invoices KYC update, parcel or bill link Bank officer, refund, remote support
What is stolen Login details, card data Credentials via a linked page OTP, PIN, device access
Best defence Do not click; verify the sender Do not open links in SMS Never share OTP; hang up and call back

What should you do if you have been phished?

If you suspect you have entered details on a fake page or shared an OTP, act immediately. Contact your bank to block the card or account and freeze suspect transactions. Change the passwords for any affected account, and enable two-factor authentication where available.

Then report the incident. India’s National Cyber Crime Reporting Portal at cybercrime.gov.in, operated by the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs, accepts complaints for financial fraud, phishing and identity theft. For live or recent financial fraud, the 1930 helpline is a free, round-the-clock number, and speed matters because a quickly reported transaction can sometimes be stopped before the money is withdrawn.

How do CERT-In and the government tackle phishing?

The Indian Computer Emergency Response Team (CERT-In), the national nodal agency under the Ministry of Electronics and Information Technology, tracks phishing campaigns, works with service providers and law-enforcement agencies to disable fraudulent websites, and issues public alerts with remedial advice. Suspicious messages and sites can be forwarded to CERT-In at its incident-reporting address.

Alongside this, the Reserve Bank of India’s customer-awareness efforts, including its BE(A)WARE booklet, document the common tactics used by fraudsters and stress a single, powerful rule: never share your passwords, OTPs or card details with anyone, however official they sound. The most reliable protection against phishing is a cautious habit – stop, verify, and reach the organisation through its official app or website rather than through a link someone sent you.

Why is phishing so effective?

Phishing works because it targets people rather than machines. Even the strongest firewall cannot stop a user who willingly types their password into a convincing fake page. Attackers exploit basic human instincts – fear of losing money, respect for authority, curiosity, and the urge to act quickly. A message that appears to come from your bank and warns of an unauthorised transaction is designed to make you panic and click before you think.

Fraudsters also invest heavily in making their bait look authentic. They copy logos, fonts and layouts, register web addresses that differ from the real one by a single character, and time their campaigns around festivals, tax deadlines or salary dates when people expect financial messages. This blend of psychological pressure and visual polish is what makes phishing so hard to resist in the moment.

How is phishing changing over time?

Phishing is not static. As banks and email providers improve their filters, fraudsters adapt. Recent years have seen a rise in phishing through messaging apps and social media, fake customer-care numbers placed on search engines, and QR-code scams in which scanning a code leads to a fraudulent payment or page. Attackers increasingly personalise their messages using details harvested from data leaks, making them harder to distinguish from genuine communication.

The growing use of artificial intelligence to write cleaner, error-free messages means one classic warning sign – poor grammar – is becoming less reliable. This makes the underlying habit of verification more important than ever: rather than judging a message by how polished it looks, treat any unsolicited request for credentials or payment as suspect until you have confirmed it through an official channel.

Can technology stop phishing on its own?

Spam filters, browser warnings and bank fraud-detection systems block a large share of phishing attempts, but none of them is perfect. Because phishing exploits human trust, a convincing message can still slip through. That is why awareness remains the strongest defence. Keeping software and apps updated, using unique passwords, and switching on multi-factor authentication add valuable extra layers, but the decisive moment is almost always the split second before you click a link or read out an OTP. A simple rule protects most people most of the time: never share a password or OTP, and reach any organisation through its official app or website rather than a link someone sent you.