Privacy guide

How to spot a phishing message before you click.

How to recognise phishing SMS, email and WhatsApp scams in India: the warning signs, what they want, and what to do if you already clicked.

The simple answer

Phishing messages try to rush you into clicking a link or sharing an OTP, password or payment detail. They often pretend to be your bank, a delivery service, a reward or a government notice.

The common signs are urgency, an unfamiliar link, small spelling mistakes and a request for something no real service would ask by message. When in doubt, do not click; go to the official app or site directly.

What to check

1
Be suspicious of urgency and threats.

If this is unclear, treat it as a signal to ask the company for a plain-English explanation.

2
Check the sender and the real link before tapping.

If this is unclear, treat it as a signal to ask the company for a plain-English explanation.

3
Never share OTPs, passwords or full card details.

If this is unclear, treat it as a signal to ask the company for a plain-English explanation.

4
Open the official app instead of message links.

If this is unclear, treat it as a signal to ask the company for a plain-English explanation.

From our investigation

Scams use your leaked details.

State of Privacy connects data exposure to scams because leaked names and numbers make phishing more convincing. The less data out there, the weaker the bait.

What to do next

1
Verify through official apps, not message links.

Keep it practical: take one action, save proof, and avoid giving more data than the task needs.

2
Report and delete suspicious messages.

Keep it practical: take one action, save proof, and avoid giving more data than the task needs.

3
If you clicked, change passwords and alert your bank.

Keep it practical: take one action, save proof, and avoid giving more data than the task needs.

People also ask

How do I know a message is phishing?

Watch for urgency, odd links, spelling errors and requests for OTPs, passwords or payment details.

What if I clicked a phishing link?

Do not enter details, change affected passwords, enable two-factor authentication and contact your bank if money is involved.

Why do scammers know my details?

Leaked or shared data can make scams more personalised and convincing, which is why limiting exposure helps.

If you are a company
Check your own website.

How many trackers run on your pages? Does your privacy policy name them? Can you answer a data-rights email? If you don't know, we can help you find out.

Talk to Meridian Bridge Strategy →
Your right under Indian law
Mera data mera hai.

Your personal data belongs to you. Under DPDP, every company must tell you what they have and delete it if you ask. One email is all it takes.

Get the template email →
Read the full investigation.

We investigated 107 Indian company websites. The public report shows what we found.

Read the reportTry the experience