How to spot 'legitimately scary' phishing scams, according to a chartered accountant – Moneycontrol

My Account
Follow us on:
 
Find & Invest in bonds issued by top corporates, PSU Banks, NBFCs, and much more. Invest as low as 10,000 and earn better returns than FD
Invest Now
Powered By
Find safe & high-yielding bonds for your buck. Discover the right bonds meeting your investment amount & investment horizon
Invest Now
Gamechangers
AMBAREESH BALIGA
Fundamental, Stock Ideas, Multibaggers & Insights
Subscribe
CK NARAYAN
Stock & Index F&O Trading Calls & Market Analysis
Subscribe
SUDARSHAN SUKHANI
Technical Call, Trading Calls & Insights
Subscribe
T GNANASEKAR
Commodity Trading Calls & Market Analysis
Subscribe
MECKLAI FINANCIALS
Currency Derivatives Trading Calls & Insights
Subscribe
SHUBHAM AGARWAL
Options Trading Advice and Market Analysis
Subscribe
MARKET SMITH INDIA
Model portfolios, Investment Ideas, Guru Screens and Much More
Subscribe
TraderSmith
Proprietary system driven Rule Based Trading calls
Subscribe
Moneycontrol  PRO
Moneycontrol  PRO
Curated markets data, exclusive trading recommendations, Independent equity analysis & actionable investment ideas
Subscribe
Curated markets data, exclusive trading recommendations, Independent equity analysis & actionable investment ideas
Explore
STOCK REPORTS BY THOMSON REUTERS
Details stock report and investment recommendation
Subscribe
POWER YOUR TRADE
Technical and Commodity Calls
Subscribe
INVESTMENT WATCH
Set price, volume and news alerts
Subscribe
STOCKAXIS EMERGING MARKET LEADERS
15-20 High Growth Stocks primed for price jumps
Subscribe
When Lavanya Mohan received a text message from “HDFC Bank”, asking her to click on a link, she immediately knew something was off.
The finance writer and chartered accountant was told her net banking services would be suspended if she didn’t update her PAN Card.
First, she was aware no bank sends its customers links. “Everything they want you to do will either be app-led or bank relationship manager led,” she wrote in a Twitter thread.
Second, she looked closely at the language of the message. Mohan said it did not begin with the usual “dear customer” greeting and had an awkward sentence formation. Also, the text came from a mobile number.
The warning of service suspension was another red flag. “No bank can suspend ANYTHING of yours unless some govt authorities demand it and even that involves a due process,” Mohan added.
 


But she decided to click on the link in the message to see how far the scammers would go. On the landing page, titled “Log in to PAN KYC”, there were fields asking for the customers’ user ID, password and mobile number.
To make it seem legitimate, a “Norton secured” badge had been added to the page.
Mohan admitted that the landing page was “excellent” and anyone could have fallen for it.
She said that on a closer look, she noticed the page had “HDFC KYC” and not “HDFC Bank” in its URL.
“The tells are so minor — any one of us can fall for this given how distracted we are in our daily lives,” she wrote. “And the smallest actions can have serious repercussions.”
Her advice to bank customers was to speak to their relationship managers before taking any action and insist on doing all processes in person, in case someone calls, claiming to be from their bank.
Below her Twitter thread, more users shared their experience with fraudsters. At least two received the same message as Mohan.
One user was told their bank account would be closed if they didn’t update their PAN Card by clicking on a link.
Another person said he received a call from someone claiming to be an ICICI Bank representative, telling him he had to do a KYC process online or their account will be suspended.
“They were so kind in the way they spoke, I almost fell for it (they even used the ‘Dear Customer’ bait in text),” he wrote. “The tell for me was the .apk file. Never download a .apk file.”
Copyright © e-Eighteen.com Ltd. All rights reserved. Reproduction of news articles, photos, videos or any other content in whole or in part in any form or medium without express writtern permission of moneycontrol.com is prohibited.
You are already a Moneycontrol Pro user.

source

Leave a Comment

Your email address will not be published. Required fields are marked *