Phishing email कैसे पहचानें: 30 seconds में 4 signals
Phishing email कैसे पहचानें — domain mismatch, urgency, fake links, attachments। Reply-to hijack trap, click के बाद क्या करें, MFA और India report steps।
Phishing अब Nigerian princes जैसी नहीं दिखती
Modern phishing email boring लगती है — "shared Google Doc", "DHL delivery notice", "unusual sign-in from Chennai"। Blend-in ही point है। India में यही emails UPI / bank / OTP scams का पहला दरवाज़ा बनती हैं।
Related: WhatsApp scam India · The UPI Trap · Fake KYC SMS
चार signals — इसी क्रम में देखें
- Sender domain mismatch. Display name "ICICI Bank" हो सकता है, address
secure-update@icici-verify.co। Name नहीं — domain पढ़ें। - Urgency + consequence. "2 hours में account lock।" Real banks email पर ऐसा panic theatre नहीं चलाते।
- Link vs label. Click से पहले hover / long-press। Visible text और underlying URL match न हों तो छोड़ो।
- Unsolicited attachments. खासकर
.zip,.html, और macros enable कराने वाले Office docs।
QR / "customer care" screenshot traps अलग channel पर: UPI QR share · Remote access: AnyDesk refund scam
वह एक trap जो सबको फँसाती है
Reply-to hijacking inside a real thread. Attacker किसी colleague का mailbox compromise करके existing conversation के अंदर reply करता है — सही subject, signature, context। Tell: अचानक pay / forward / click / credentials की माँग।
Rule: existing thread के अंदर भी financial या credential ask → phone-call confirmation। Always.
अगर click हो गया तो क्या करें
- तुरंत Wi-Fi / cellular disconnect करें (जहाँ safe हो)।
- जिस account का email claim कर रहा था, उसका password दूसरे device से change करें।
- MFA on करें — पहले email और bank।
- Work device हो तो IT को घंटे में बताएँ, दिन में नहीं। Early notice close call और breach का फर्क है।
- India में money / OTP / UPI impact हो तो same day 1930 + cybercrime.gov.in। देखें: 1930 FAQ · Report guide · UPI scam 2026
RBI 2027 clocks अलग हैं अगर later compensation framework apply हो: RBI rules
Frequently asked questions
Phishing email कैसे पहचानें सबसे तेज़ तरीके से?
पहले sender domain पढ़ें, फिर urgency language, फिर link URL vs label, फिर unexpected attachment — यही 30-second checklist है।
क्या bank email पर "account lock in 2 hours" भेजता है?
Panic + click-here वाले emails पर भरोसा न करें। Official app / card-back helpline / known website से verify करें — email वाले link से नहीं।
Real thread के अंदर आया request safe है?
जरूरी नहीं। Mailbox compromise से reply-to hijack common है। Money/credentials के लिए out-of-band phone confirm करें।
Click के बाद OTP share हो गया तो?
Passwords + MFA तुरंत rotate करें, bank fraud desk + 1930 / cybercrime.gov.in file करें, evidence save रखें।
Official resources
- National Cyber Crime Reporting Portal · Helpline 1930
- CERT-In
- Reserve Bank of India
- MeitY

