Phishing Vishing Smishing Frauds: IIBF Cyber Crime Guide

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 22 June 2026 · Updated 12 Sep 2026 · 12 min read · 66 views
Phishing Vishing Smishing Frauds: IIBF Cyber Crime Guide

Phishing, vishing and smishing frauds are the single most common way money leaves a bank customer's account in India today, and they are also among the most heavily weighted topics in the IIBF Prevention of Cyber Crime certification. The reason is simple: these attacks do not break encryption or defeat firewalls. They defeat people. A fraudster only needs one panicked customer to read out an OTP, and a lifetime of savings can vanish in seconds.

For a banker, mastering this trio is not an academic exercise. The same knowledge that earns you marks in the exam is what protects the person standing across the counter from you. This guide explains exactly what each fraud is, the IT Act 2000 sections that punish them, the CERT-In reporting clock, and the RBI customer-protection rules every frontline officer must know cold.

Phishing vishing and smishing banking fraud guide for IIBF cyber crime exam
Phishing, vishing and smishing are the three faces of social-engineering fraud in banking

Key Takeaways

  • Same goal, different channel: phishing uses email or fake websites, vishing uses phone calls, and smishing uses SMS — all to steal credentials, OTPs or money.
  • Core IT Act sections: 66D (cheating by personation using a computer resource) is the headline provision; 66C covers identity theft.
  • CERT-In 6-hour rule: covered cyber incidents must be reported to CERT-In within 6 hours of being noticed; logs must be retained for 180 days in India.
  • Customer protection: report within 3 working days for zero liability under the RBI 2017 framework.
  • Golden hour: calling the 1930 helpline immediately can freeze funds before they are withdrawn.

What Phishing, Vishing and Smishing Frauds Actually Are

All three belong to a family called social engineering — deception that manipulates a victim into surrendering something valuable of their own free will. No malware is strictly required; the human being is the vulnerability being exploited. The only thing that separates the three is the delivery channel of the lure, and the exam expects you to distinguish them precisely.

  • Phishing arrives by fraudulent email or through cloned websites that impersonate a bank, payment app, tax department or other trusted body. The victim clicks a link to a fake login page, and their username, password and card details are quietly harvested.
  • Vishing (voice phishing) is carried out over a phone call. The fraudster poses as a bank officer, a KYC verification team or even an RBI official, then pressures the victim into reading out an OTP, CVV or PIN — or into installing a remote-access app such as AnyDesk that hands over control of the device.
  • Smishing (SMS phishing) uses text messages carrying malicious links: a fake KYC-update alert, a bogus reward redemption, or a fake parcel-delivery notice that routes the victim to a credential-stealing page.

The common thread across all three is a manufactured sense of urgency and fear. "Your account will be blocked." "Your card is suspended." "Claim your refund within two hours." That pressure is designed to switch off rational judgement. The single most powerful counter-message a banker can repeat to customers is this: a genuine bank will never ask for an OTP, full card number, PIN or net-banking password through any channel, at any time, for any reason.

Comparison of phishing vishing and smishing cyber fraud attack channels
Each fraud type uses a different channel but chases the same stolen credentials

Quick Comparison: How the Three Frauds Differ

When a question asks you to match a scenario to the correct fraud type, the channel is your clue. Keep this table in mind — it is the fastest way to lock in the distinction before the exam.

Feature Phishing Vishing Smishing
Channel Email / fake website Voice phone call SMS / text message
Typical lure Cloned login page Fake KYC / RBI call Malicious link in text
Target stolen Passwords, card data OTP, CVV, PIN Credentials via fake page
Emotional trigger Account warning Authority + pressure Reward / urgency

You can test how well you can tell these apart on the practice cyber-crime mock tests, which mirror the scenario-style questions the certification favours.

The Legal Framework: IT Act 2000 and the BNS

Phishing, vishing and smishing frauds are prosecuted under a combination of the Information Technology Act, 2000 and the general penal code. Examiners love these section numbers because they are precise and unambiguous, so commit them to memory rather than skimming.

  • Section 66 covers computer-related offences, picking up the dishonest or fraudulent acts described in Section 43. It is punishable with imprisonment up to three years or a fine up to Rs 5 lakh.
  • Section 66C deals with identity theft — the fraudulent use of another person's electronic signature, password or other unique identification feature. This squarely covers the credential theft at the heart of phishing.
  • Section 66D is the principal provision for vishing and phishing: cheating by personation using a computer resource. It applies when a fraudster impersonates a bank or official to deceive a victim, and carries imprisonment up to three years and a fine up to Rs 1 lakh.
  • Section 43 provides for civil liability and compensation where there is unauthorised access, downloading or damage to a computer system.

A detail worth remembering is that the IT Act was substantially amended in 2008, and it was this amendment that introduced Sections 66C and 66D. Alongside the IT Act, the cheating and forgery provisions of the Bharatiya Nyaya Sanhita (BNS), which has replaced the Indian Penal Code, apply to the underlying fraud. For the deeper legal background, our companion guide on the IT Act 2000 cyber crime sections every IIBF aspirant needs walks through each provision with worked examples, and the types of cyber crime in banking explainer places these frauds in the wider offence map.

CERT-In Directions and the 6-Hour Reporting Rule

The Indian Computer Emergency Response Team (CERT-In), constituted under Section 70B of the IT Act, is the national nodal agency for cyber-security incidents. Its directions issued in April 2022 remain the operative compliance baseline for banks and intermediaries, and they generate some of the most frequently tested numbers in the syllabus.

  • 6-hour reporting: any covered cyber incident — including phishing campaigns targeting a bank's customers, data breaches and unauthorised access — must be reported to CERT-In within six hours of being noticed. This tight window is a perennial favourite in the exam.
  • 180-day log retention: service providers and intermediaries must enable and securely maintain system logs for a rolling period of 180 days within Indian jurisdiction.
  • Clock synchronisation: all ICT systems must synchronise their clocks to the NTP servers of NIC or NPL (or traceable equivalents) so that incident timelines line up.
  • KYC by intermediaries: data centres, virtual private server, cloud and VPN providers must maintain validated subscriber records.

For a bank, these directions sit on top of the RBI's own cyber-security framework and incident-reporting expectations. A phishing site spoofing a bank's domain is therefore never just a customer's problem — it starts a mandatory regulatory clock the moment it is detected. Drill the 6-hour CERT-In window and the 180-day figure until they are reflexes, and reinforce them with the rapid-recall cyber-crime matching games.

Cyber fraud incident response and reporting flow to 1930 helpline and cybercrime portal
Reporting flow: branch action, the 1930 helpline and the national cybercrime portal

Customer Protection, Zero Liability and the 1930 Helpline

The RBI circular on "Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions" (2017) decides who bears the loss after a phishing, vishing or smishing fraud. This is essential frontline knowledge, because the timeline of the customer's report directly determines the financial outcome.

  • Zero liability applies where the loss is due to bank negligence or a third-party breach, and the customer reports the unauthorised transaction within 3 working days.
  • Limited liability, capped and tiered by account type, applies where the customer reports within 4 to 7 working days.
  • Shadow reversal: the bank must credit the disputed amount within 10 working days of notification, so the customer is not left out of pocket while the dispute is investigated.

Tip for the counter: The two channels every customer must know are the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the 1930 helpline — the toll-free number that feeds the Citizen Financial Cyber Fraud Reporting and Management System. A call to 1930 inside the golden hour can interdict the transaction and freeze funds before they are withdrawn or layered into mule accounts.

Counsel customers to do three things at once: call 1930 immediately, file a complaint on the portal, and inform the branch the same day. For the customer-facing red flags and defensive scripts, our guide on phishing and vishing attacks on banks: red flags and defence is a useful companion, while the broader cyber crime in banking — IT Act and RBI framework overview ties the regulatory pieces together.

How to Study This Topic for the Exam

This is a high-yield, fact-dense topic, so a structured approach pays off. Work through it in layers rather than trying to memorise everything at once.

  1. Lock the definitions first. Be able to map any scenario to phishing, vishing or smishing in one read. The channel is always the giveaway.
  2. Memorise the section numbers. Pair 66C with identity theft and 66D with cheating by personation. These two carry the most marks.
  3. Drill the numbers. The 6-hour CERT-In window, 180-day logs, 3-day zero-liability rule and the 1930 helpline are pure recall — perfect for flashcards and matching games.
  4. Practise application questions. The exam rarely asks "what is phishing"; it asks what a banker should do next. Solve full-length sets on the mock tests to build that reflex.
  5. Revise in the syllabus context. Anchor your study in the official outline using the Prevention of Cyber Crimes and Fraud Management syllabus so nothing is missed.

You can browse the full set of exam guides for this paper on the cyber crime blog hub, and study the structured chapters inside the Prevention of Cyber Crime subject within the Prevention of Cyber Crime course.

Common Mistakes Candidates Make

  • Confusing 66C and 66D. Identity theft is 66C; cheating by personation is 66D. Many candidates flip them under exam pressure — fix the pairing early.
  • Misremembering the CERT-In window. It is six hours, not 24 or 72. The shorter figure is the one that gets tested.
  • Mixing up reporting timelines. The 3-working-day zero-liability rule (RBI) is different from the 6-hour CERT-In rule (incident reporting). Keep customer protection and incident reporting in separate mental boxes.
  • Treating the three frauds as identical. They share a goal but differ by channel; a scenario question hinges on that channel.
  • Forgetting the golden hour. Speed of the 1930 call is what makes fund recovery possible — examiners reward candidates who recognise this.

Frequently Asked Questions on Phishing Vishing Smishing Frauds

What is the difference between phishing, vishing and smishing?

All three are social-engineering frauds that differ only by the channel of attack. Phishing uses fraudulent emails or cloned websites, vishing uses phone calls in which the fraudster impersonates a bank or RBI official, and smishing uses SMS messages carrying malicious links. Each one aims to steal credentials, OTPs, card details or money from the victim.

Which IT Act section covers cheating by impersonation in vishing?

Section 66D of the Information Technology Act, 2000 covers cheating by personation using a computer resource, and it is the principal provision for both vishing and phishing. It carries imprisonment of up to three years and a fine of up to Rs 1 lakh. Section 66C, which covers identity theft, also applies where passwords or other credentials are stolen.

What is the CERT-In reporting timeline for cyber incidents?

Under the CERT-In April 2022 Directions, organisations must report covered cyber incidents — including phishing attacks, data breaches and unauthorised access — within six hours of noticing them. They must also retain system logs for 180 days within India and synchronise system clocks to the NTP servers of NIC or NPL. Always confirm the current directions, as compliance baselines can be updated.

How quickly must a customer report a fraud for zero liability?

Under the RBI 2017 limited-liability framework, a customer enjoys zero liability when the loss results from bank negligence or a third-party breach and the unauthorised transaction is reported within three working days. Reporting within four to seven working days attracts limited, capped liability instead. Customers should also call the 1930 helpline immediately to improve the chances of freezing the funds.

What is the 1930 helpline and the golden hour?

1930 is the national toll-free helpline that feeds the Citizen Financial Cyber Fraud Reporting and Management System, used to report financial cyber fraud. The "golden hour" refers to reporting the fraud as soon as possible after it occurs, so that the transaction can be interdicted and the money frozen before it is withdrawn. A banker should always counsel customers to call 1930 first, then file on cybercrime.gov.in.

Are phishing and smishing punished differently under law?

No — the punishment depends on the offence committed, not the channel used to commit it. Whether the lure arrives by email (phishing) or SMS (smishing), the same IT Act provisions such as Sections 66C and 66D apply, along with the cheating provisions of the Bharatiya Nyaya Sanhita. The channel matters for detection and customer advice, while the legal sections turn on the act of identity theft or personation.

Conclusion: Master Cyber Crime Prevention and Pass with Confidence

Phishing, vishing and smishing frauds sit exactly where human psychology, banking operations and cyber law meet — which is precisely why they dominate the IIBF Prevention of Cyber Crime certification. Lock down the IT Act sections (66C and 66D), the CERT-In six-hour rule, the 180-day log retention, and the RBI zero-liability and 1930-helpline timelines, and you will handle the overwhelming majority of exam questions and real customer incidents with calm authority. Treat each fact as a customer you might one day protect, and the learning will stick. For the official position on banking certifications, you can always refer to the Indian Institute of Banking and Finance.

Related Guides

📚 Free Learning Sessions resources — connect & crack your exam

💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.

📱 Study on the go — get our iOS & Android app at iibf.store/app.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading