The Golden Rule: Never Share Your Secrets
The most fundamental rule of financial safety is that some information should never be shared with anyone. Your bank, a legitimate merchant, or a payment app will never ask for your most sensitive credentials. These include your Personal Identification
Number (PIN), One-Time Passwords (OTPs), net banking passwords, or the three-digit CVV number on the back of your card. Think of these details as the keys to your vault. An OTP, for instance, is used to authorise a payment you are making. If someone asks for an OTP to send you money, it is a scam. You never need to enter a PIN or share an OTP to receive funds. Fraudsters often create a sense of urgency or fear, pretending to be from your bank or a government agency, to trick you into revealing this information. Always remember that legitimate organisations will not ask for these details over a call, SMS, or email.
Navigating Online and In-App Payments
When paying online, you will be asked for your card number, your name as it appears on the card, the expiry date, and the CVV. These are necessary to process the transaction. However, always ensure the website is secure by looking for "https://" and a padlock symbol in the address bar before entering any details. Avoid saving your card details on multiple websites; while convenient, it increases your risk if that site suffers a data breach. For UPI transactions, which have revolutionised payments in India, the process is different. To pay someone, you only need their UPI ID or linked mobile number. You then enter your secret UPI PIN on your own device to authorise the payment. Never share this PIN with anyone, including the person you are paying. Be wary of unsolicited payment requests; fraudsters send these hoping you will approve them by mistake. Always double-check the recipient's name on the screen before you confirm the transaction.
Staying Safe with Physical Transactions
The threat of fraud isn't limited to the digital world. When using your card at an ATM or a point-of-sale (POS) machine in a shop, always shield the keypad with your hand as you enter your PIN. This simple action prevents both prying eyes and hidden cameras from capturing your secret code. Be aware of your surroundings and look for any unusual devices attached to ATM slots or card readers, as these could be skimming devices designed to copy your card's data. Whenever possible, use ATMs located inside or directly outside a bank branch, as they are generally more secure. In restaurants or shops, try to keep your card in your sight at all times. Don't let a server or cashier take it to a back room to process a payment, as this provides an opportunity for your card details to be illicitly copied.
Recognising Phishing and Vishing Scams
Phishing and vishing (voice phishing) are common tactics where fraudsters impersonate trusted entities to steal your information. You might receive an SMS or email that appears to be from your bank, urging you to click a link to update your KYC details, claim a tax refund, or unlock your account. These links lead to fake websites designed to harvest your login credentials or card information. A recent report highlighted a 146% increase in text-message-based scams in India, showing how prevalent this threat has become. Vishing involves receiving a phone call from someone pretending to be a bank employee or official. They might sound professional and convincing, but their goal is to trick you into revealing your PIN, OTP, or passwords. The Reserve Bank of India (RBI) and other banks have repeatedly clarified that they will never call or email you to ask for these confidential details. If you receive such a communication, do not respond and report it immediately.
Proactive Steps for Financial Hygiene
Beyond being cautious during transactions, good financial hygiene can significantly reduce your risk. Regularly review your bank and card statements for any unauthorised transactions and report discrepancies immediately. Enable SMS and email alerts for all transactions, so you are notified the moment a payment is made. Use strong, unique passwords for your net banking and mobile banking apps, and enable two-factor authentication (2FA) wherever possible. This adds an extra layer of security, requiring both your password and a dynamic code (like an OTP) to log in. Avoid using public or open Wi-Fi networks for financial transactions, as these can be insecure. If your bank allows, consider setting daily transaction limits on your UPI and card usage to minimise potential losses in case of a compromise.














