Cybersecurity advice becomes useful only when it tells you what to do before, during and after an incident. This checklist focuses on common threats facing Indian consumers and small teams: phishing, malicious apps, account takeover, ransomware and payment fraud.
1. Phishing and fake-login pages
What it looks like: an SMS, WhatsApp message, email, ad or search result creates urgency and sends you to a login or payment page.
Prevention: open banking and government services from a saved bookmark or official app, use a password manager so it refuses to autofill on the wrong domain, and enable phishing-resistant MFA where available.
If you entered credentials: change the password from a clean device, revoke active sessions, rotate reused passwords and contact the relevant bank/service if money or identity documents are involved.
2. Malicious Android apps and remote-access scams
Fraudsters may persuade victims to install an APK, screen-sharing tool or “support” app. Treat any unexpected request to install software as high risk. Keep Play Protect enabled, avoid sideloading apps sent over chat, and review Accessibility and Device Admin permissions if you suspect compromise.
3. Account takeover
Attackers often use leaked passwords, SIM-swap attempts or social engineering against account-recovery flows. Use unique passwords, secure your primary email first, add recovery methods you control and save backup codes offline. For high-value accounts, prefer passkeys or FIDO security keys when supported.
4. Ransomware and destructive malware
The defence is not just antivirus. Keep operating systems and applications updated, use standard-user accounts for everyday work, and maintain backups that are not continuously writable from the same device. A backup you have never restored is an assumption, not a tested recovery plan.
5. UPI and payment fraud
Receiving money does not require your UPI PIN. Be suspicious of collect requests, screen-sharing during “refunds”, QR-code pressure and callers who ask you to move funds to a “safe” account. If money has been transferred fraudulently, contact your bank/payment provider and report quickly through 1930 and the National Cyber Crime Reporting Portal.
The 15-minute security baseline
- Update the phone/computer and browser.
- Turn on MFA for your primary email.
- Replace reused passwords on banking, email and social accounts.
- Enable device screen lock and automatic lock.
- Check that important photos/documents exist in a second backup location.
- Save 1930 and your bank’s official fraud contact details.
When to get professional help
If a business device may contain ransomware, customer data may have been exposed, or an attacker still has remote access, disconnect the affected system from the network and get qualified incident-response help. Do not destroy logs or wipe systems before evidence is preserved.
Primary sources
- CERT-In
- National Cyber Crime Reporting Portal
- I4C
- CISA Secure Our World for general security-baseline guidance.
Editorial basis
This guide is written as a defensive, India-focused response guide. It does not claim a personal incident unless that experience is documented, and it does not guarantee recovery after fraud. Official reporting and payment/identity sources take priority over anecdotes.
