9:41
Bharat Suraksha Bank
VM-BHRTBK
Today, 9:38 AM
Dear Customer, your Bharat Suraksha Bank account will be BLOCKED in 24 hrs due to incomplete KYC. To avoid suspension, please re-verify your details immediately: http://bharatbank-kyc-verify.secure-login-in.com/verify
bharatbank-kyc-verify.secure-login-in.com/verify
RBI mandate: complete your pending KYC verification before 24 hrs to keep net-banking active.

Banking that keeps you secure, always.

Verify your KYC online in under two minutes. Your session is protected by 256-bit encryption.

No branch visit required
Instant account re-activation
Secured by Bharat Suraksha SafePay
© Bharat Suraksha Bank Ltd. · Regd. Office: Nariman Point, Mumbai 400021 · CIN U65191MH1994PLC | Member RBI · DICGC Insured · IBA Registered
Privacy Policy · Terms of Use · Report Fraud · Toll-Free 1800-XXX-XXXX
attacker_console - incoming_victim_data.log
CREDENTIALS CAPTURED
Victim: small-business owner · Bharat Suraksha Bank net-banking
Customer ID
Login Password
OTP
Card Number
ATM PIN
In real life this data is now on a criminal's server in seconds. With your password, OTP, card and PIN, they can drain your account, take loans in your name, and lock you out - all before your next chai.
authify·cyber suraksha

What just happened

Threat 01 - Phishing: a fake message that tricks you into handing over secrets

1 What this attack looked like

  • A text arrived appearing to come from "Bharat Suraksha Bank", warning your account would be blocked in 24 hours over incomplete KYC.
  • The message carried a tappable link. Tapping it opened a website that copied the bank's real design - logo, colours, padlock and trust seals.
  • The page asked for everything at once: Customer ID, password, OTP, debit card number and ATM PIN.
  • The instant you pressed "Verify", those details appeared on the attacker's screen. The page never belonged to any bank.

2 Red flags - how to spot it

  • Fear & urgency. A countdown ("blocked in 24 hrs") rushes you so you skip thinking.
  • Lookalike web address. The real owner is the part just before .com - here secure-login-in.com, a stranger's site. "bharatbank" is only a decoy word at the front.
  • The padlock means nothing. It only shows the page is encrypted (private), not honest. Scammers get padlocks too.
  • Over-asking. Password + OTP + card number + PIN on one screen. No real bank ever does this.
  • Unsolicited link in an SMS/WhatsApp; generic "Dear Customer"; subtle spelling tricks in the address.

3 Best practices - prevent it

  • Never tap links in messages. Open the bank's official app, or type the address yourself.
  • Banks never ask for OTP, PIN, CVV or full password - by SMS, call or site. Anyone who does is a fraud.
  • Check the exact domain - read the word just before .com, slowly.
  • Turn on transaction alerts and set low daily limits for cards and UPI.
  • Use a password manager with a unique password per site (it also won't autofill on fake domains).
  • Enable your UPI / banking-app PIN, biometric lock and a strong device screen lock.
  • Slow down. When unsure, call the number on the back of your card - never a number from the message.

4 If you have already been hit

  • Act in the "golden hour" - the sooner you report, the higher the chance of recovering money.
  • Call your bank now to block the card and freeze / pause the account.
  • Change passwords for net-banking and your linked email from a clean device.
  • Report to 1930 and file at cybercrime.gov.in within 24 hours.
  • Watch your statements, dispute unknown transactions, and keep the complaint reference number.
  • Turn on 2FA everywhere and re-check that no new payee/loan was added.
#3
India is the world's 3rd-largest target for phishing. Small businesses are hit hardest - a single tap can cost lakhs.
Press I to hide / reopen this debrief.