27. Social Engineering Awareness
27.3 How to Spot a Phishing Message
Ek phishing email/SMS olakhayche step-by-step:
- Sender address – hover/expand it.
sbi-alerts@secure-sbi-verify.xyzis not SBI. Real domains are short and official. - Urgency and threats – "act now or lose access" is a red flag.
- Links – hover (do not click); does the real URL match the text? Look for lookalikes (
paytm-kyc.com,arnazon.in). - Attachments – unexpected
.zip,.exe, or a document asking you to "enable macros". - Generic greeting – "Dear Customer" instead of your name (though spear phishing uses your name).
- Spelling and grammar – many (not all) have odd language.
- Request for secrets – any ask for OTP, password, PIN, card number = fraud.
- Too good to be true – prizes, refunds, lottery.
Safe habit: NEVER click a link in a message to log in.
Instead, open the bank/company site yourself by typing the address or using your saved bookmark.
Ravindra Bagale's Tip
The simplest and strongest rule: "Don't log in by clicking a link." For anything bank-related, open the app or type the address into the browser yourself. This one habit stops 90% of phishing. Even if you only teach students this one rule firmly, it is a lot.
Ravindra Bagale's Tip – मराठी
सर्वात सोपा आणि strong नियम: "link वर click करून login करू नका." Bank चे काम असेल तर app उघडा किंवा browser मध्ये स्वतः address type करा. ही एक सवय 90% phishing थांबवते. Students ना हा एकच नियम पक्का शिकवला तरी खूप.
Ravindra Bagale's Tip – हिंदी
सबसे आसान और strong नियम: "link पर click करके login मत करो." Bank का काम हो तो app खोलो या browser में खुद address type करो. यह एक आदत 90% phishing रोकती है. Students को यह एक ही नियम पक्का सिखा दिया तो भी बहुत है.
Lab
Find two real suspicious messages in your own SMS/email (do not click anything). For each, go through the 8-point checklist above and write which points flagged it. Then show how you would verify by opening the official app/site directly.