27. Social Engineering Awareness
27.3 How to Spot a Phishing Message
Ek phishing email/SMS olakhayche step-by-step:
- Sender address – hover/expand it.
sbi-alerts@secure-sbi-verify.xyzis not SBI. Real domains are short and official. - Urgency and threats – "act now or lose access" is a red flag.
- Links – hover (do not click); does the real URL match the text? Look for lookalikes (
paytm-kyc.com,arnazon.in). - Attachments – unexpected
.zip,.exe, or a document asking you to "enable macros". - Generic greeting – "Dear Customer" instead of your name (though spear phishing uses your name).
- Spelling and grammar – many (not all) have odd language.
- Request for secrets – any ask for OTP, password, PIN, card number = fraud.
- Too good to be true – prizes, refunds, lottery.
Safe habit: NEVER click a link in a message to log in.
Instead, open the bank/company site yourself by typing the address or using your saved bookmark.
Ravindra Bagale's Tip
Sarvat sopa ani strong niyam: "link var click karun login karu naka." Bank cha kaam asel tar app ughda kiwa browser madhe swatahha address type kara. Ha ek savay 90% phishing thambavto. Students la ha ekach niyam pakka shikavla tari khup.
Lab
Find two real suspicious messages in your own SMS/email (do not click anything). For each, go through the 8-point checklist above and write which points flagged it. Then show how you would verify by opening the official app/site directly.