Safe online banking is less about finding a “perfect” antivirus and more about controlling the path between you and your bank. Use this checklist for UPI, mobile banking and net banking in India.
Before you log in
- Use the bank’s official app or a bookmark you created from the bank’s verified website. Do not follow a login link from an unexpected SMS, email or WhatsApp message.
- Keep the phone/computer and browser updated. Remove apps you no longer use, especially sideloaded APKs and remote-control tools.
- Use a unique banking password. Do not reuse the same password on shopping, social or email accounts.
- Protect the email account linked to the bank with strong MFA because email is often part of account recovery.
Understand what an OTP and UPI PIN actually do
An OTP, card PIN, CVV and UPI PIN are authorisation secrets. A legitimate bank employee does not need you to read them out on a phone call. For UPI, entering your PIN normally authorises a transaction from your account; you do not need to enter a UPI PIN merely to receive money.
Common scam patterns
“Your KYC will expire today”
The message sends a link or APK. Verify any KYC request from inside the official bank app or by calling the number printed on the bank’s official website/card.
Fake customer-care numbers
Search results, social posts and map listings can be manipulated. Go to the company’s official domain first, then use its listed support route.
Refund or collect-request trick
A scammer claims to send you money but actually sends a collect request. Read the action on screen before entering a PIN.
Remote-access “support”
Do not install AnyDesk, TeamViewer or similar remote-control software because a caller says it is required to fix a banking issue.
If you spot an unauthorised transaction
- Contact the bank through an official fraud channel and ask it to block/freeze the relevant instrument where appropriate.
- For financial cyber fraud, call 1930 quickly and complete the complaint on cybercrime.gov.in.
- Save transaction IDs, screenshots, messages and caller details.
- Change compromised credentials from a trusted device and review active sessions.
A monthly banking-safety check
Review beneficiaries, UPI mandates/autopay instructions, cards, transaction alerts, account recovery email/phone numbers and apps with Accessibility/Device Admin permissions. Remove what you no longer use.
Sources and verification
This is general security information, not financial or legal advice. Bank processes and liability rules can depend on the facts and timing of a specific incident.
Editorial basis
This guide is written as a defensive, India-focused response guide. It does not claim a personal incident unless that experience is documented, and it does not guarantee recovery after fraud. Official reporting and payment/identity sources take priority over anecdotes.
