The Digital Big Brother

Home  /  Stay safe

Twenty minutes now, or a bad week later

None of this is technical and none of it is optional-sounding advice about being careful. These are specific settings and habits. Set them once and most of what follows stops being possible.
Start here

Your phone, set up properly

Your phone holds your money, your identity and your OTPs. It deserves fifteen minutes of attention.
Turn on two-factor authentication for your email first. Whoever controls your email can reset everything else.
Set a screen lock that isn’t your date of birth, and turn off message previews on the lock screen so OTPs are not readable without unlocking.
Install apps only from the Play Store or App Store. Never install an APK someone sends you, whatever they say it does.
Review app permissions and remove SMS, call log and accessibility access from anything that has no business needing it.
Turn on automatic updates. Most phone compromises use holes that were patched months ago.
Never allow screen sharing or remote access with someone who called you. Real support does not need to watch your screen.
Keep your recovery phone number and email current, so you can actually get back in if you lose access.
Money

Payment habits worth building

Most losses come down to one of three moments: an OTP shared, a PIN entered, or a request approved.
Your UPI PIN only ever sends money out. If a screen asks for it, money is leaving. Read the amount before you type.
To receive money you share your UPI ID or show your QR code. Nothing else, ever.
Never share an OTP with anyone, including someone who says they are from your bank. There is no legitimate reason for that call to exist.
Turn on SMS and email alerts for every transaction, so a debit is visible in seconds rather than at month end.
Set a daily transaction limit in your banking app that matches how you actually spend. It caps the damage.
Keep the bulk of your money in an account that isn’t linked to UPI, and a small balance in the one that is.
Save your bank’s real fraud helpline in your contacts now, so you don’t have to search for it while panicking.
Social media

What you’re giving away for free

Scammers research before they message. Everything they use to sound convincing came from a public profile.
Set your accounts to private, and hide your followers and following lists — this is what sextortion threats rely on.
Restrict who can send you direct messages and who can add you to groups.
Don’t post your phone number, college ID, admission letter, boarding pass or exam hall ticket. They contain more than you think.
Turn off location tagging on posts, especially anything from your hostel or home.
Be sceptical of new accounts that follow and message quickly. Check when the account was created.
Assume anything on a video call can be recorded. That is not paranoia, it is just how cameras work.
The skill

Spotting a fake before it costs you

Three checks that cover almost everything.
01

Read the address, not the page

Find the first single slash. The two parts just before it are the real owner. Government sites end in .gov.in and nothing else.
02

Go the other way round

Never use the link or number they sent. Find the organisation yourself and contact them through their own channel.
03

Follow the money question

Ask what payment is required and when. Genuine jobs, scholarships and refunds never need money from you first.
Questions we get

Straight answers

Including a few things almost everyone has slightly wrong.
Yes. Your UPI ID works like an email address for payments — someone can send money to it, but they cannot take money out with it. What is never safe to share is your UPI PIN. And to repeat the rule that matters most: you never need a PIN to receive money.
No. A mobile number or UPI ID on its own is not enough. Money leaves an account when someone gets an OTP, a PIN, a password or card details out of you — or when you approve a payment request yourself. Every scam on this site exists to obtain one of those things, which is also why protecting them covers most of your risk.
Answering cannot by itself compromise your phone or your money. The risk lives in the conversation. The genuinely dangerous actions are sharing an OTP, installing an app someone asks you to install, allowing screen sharing or remote access, and transferring money. If a call moves towards any of those, hang up.
Yes, and sooner than feels comfortable. Nearly every case that gets worse does so during the days someone spent hiding it. Report the fraud first — call 1930 and file at cybercrime.gov.in — then tell them. Their reaction is almost always smaller than the one you have been imagining.
Fine for browsing and streaming. Avoid net banking, payments and logging into important accounts on a network you do not control. If you have to, use mobile data instead — it is considerably harder to intercept than an open Wi-Fi network.
Read the address, not the design — copying a design takes an afternoon. Find the first single slash and read the two parts immediately before it; that is the owner. Government sites in India end in .gov.in and nothing else. And note that a padlock only means the connection is encrypted; it does not mean the site is honest.
No, and paying reliably makes it worse — it identifies you as someone who pays, and the demands increase. This is extortion, which is a crime committed against you. Save your evidence, stop replying, tell one person you trust, and report it on 1930 or at cybercrime.gov.in.

Send this to one person

Most people read a page like this after something has already gone wrong. Forwarding it to one friend before that happens is genuinely the highest-value thing you can do today.
Scroll to Top