Phishing Vishing and Smishing: Bank Fraud Defences (IIBF Cyber Crime)
Every fraud case you will see in the Prevention of Cyber Crime paper eventually reduces to one question: did the customer or the branch spot the deception in time? Phishing vishing and smishing are the three channels criminals use most often to trigger unauthorised transactions against Indian bank accounts — email, voice call, and SMS respectively. Each relies on the same trick: impersonate a trusted source, create urgency, and extract a credential, OTP, or card detail before the victim can verify the request. This article maps the attack anatomy, the red flags your bank's controls are built to catch, and what RBI expects both banks and customers to do.
🎣 How Phishing, Vishing and Smishing Attacks Unfold
Phishing is the email-borne version: a message that looks like it comes from your bank, warns of a blocked account or pending KYC update, and pushes you toward a lookalike login page. Vishing swaps the email for a phone call — often from a spoofed number that displays your bank's actual name — where the caller poses as a bank officer, RBI official, or even a "fraud prevention" agent. Smishing does the same job through SMS or WhatsApp, usually with a shortened link and a manufactured deadline ("your account will be frozen in 2 hours").
Despite the different channel, the underlying anatomy is identical across all three: a plausible lure, an urgent ask, and a narrow window to comply before the victim can think it through. Recognising this shared structure is more useful for exam purposes than memorising channel-specific examples, because IIBF questions frequently test whether you can classify a scenario correctly. For a deeper breakdown of how these methods fit into the wider taxonomy, revisit the Cyber Crime Methods chapter alongside Introduction To Cyber Crimes, which frame phishing, vishing and smishing as social-engineering variants rather than technical hacks.

🚩 Red Flags That Expose a Fake Message or Call
The single most reliable red flag across phishing, vishing and smishing is a request for something a bank never asks for by phone, SMS, or email: your OTP, CVV, full card number, PIN, or net-banking password. Genuine banks authenticate you through channels you initiated, not the reverse. A second flag is artificial urgency — "act in 10 minutes" or "your account will be blocked today" — designed to short-circuit verification.
Domain and number mismatches are the third tell. A phishing email from "support@sbi-verify.net" or a smishing link with a random shortened URL rarely matches the bank's registered domain. Caller-ID spoofing makes vishing harder to spot on number alone, which is why banks train staff and customers to verify through a callback to the number printed on the passbook or card, never the number the caller supplies. Poor grammar, generic greetings ("Dear Customer" instead of your name), and requests to install a remote-access app are additional signals worth flagging at the branch level. The Computer Fraud Protection chapter covers these detection heuristics in more depth, and the sibling note on card skimming fraud detection is worth pairing with this one since both hinge on spotting manufactured urgency before money moves.
| Attack Type | Primary Channel | Typical Lure | ✅ Do | ❌ Don't |
|---|---|---|---|---|
| Phishing | Email with a spoofed sender/link | Fake KYC update or account-block warning | Verify the sender domain; log in only via the bank's saved bookmark | Click embedded links or open unexpected attachments |
| Vishing | Phone call, often with a spoofed bank number | Caller poses as a bank/RBI official citing a "security issue" | Hang up and call back the number printed on your card or passbook | Share OTP, CVV, PIN, or install a remote-access app on request |
| Smishing | SMS or WhatsApp with a short link | Fake reward, refund, or account-freeze alert | Check the URL domain before tapping; use the bank's app instead | Tap shortened links or reply with account details |

⚠️ Common Mistake: Candidates often assume vishing requires a "hacked" phone line. It doesn't — caller-ID spoofing alone is enough to display a genuine-looking bank number, which is why RBI recommends verifying through a callback rather than trusting the display.
🏦 Bank-Side Controls Under the RBI Framework
Banks build layered defences against phishing vishing and smishing rather than relying on any single control. Two-factor authentication (password plus OTP) limits how much damage a stolen password alone can cause. Real-time transaction alerts via SMS and app push notifications give customers a chance to catch an unauthorised debit within minutes. Velocity checks and anomaly-detection rules flag transactions that deviate from a customer's usual pattern — an unusually large transfer, a new payee added minutes before a big-value transaction, or a login from an unfamiliar device or location.
On the liability side, RBI's circular on customer protection for unauthorised electronic banking transactions sets out a graded framework: liability depends on how quickly the customer reports the incident and whether the breach originated from the bank's systems, a third party, or the customer's own negligence. Prompt reporting — within the prescribed working-day window from the date of the alert — materially reduces what a customer bears, which is one reason branch staff are trained to push customers toward immediate reporting rather than waiting to "confirm" the fraud themselves. You can read RBI's official guidance and updates directly at rbi.org.in. For how these frauds interact with plastic-card channels specifically, see Electronic Card Frauds, and for the statutory backbone behind these controls, the sibling article on IT Act 2000 sections for cyber crime is a useful companion read.

💡 Exam Tip: When a question describes a scenario, first classify the channel (email/call/SMS) to name the attack, then check whether the facts test detection (red flags) or liability (RBI's reporting-window framework) — these are usually asked as separate sub-questions.
🛡️ Customer Awareness, Reporting and Recovery
Customer-facing awareness is the last line of defence, and it is also the one IIBF weights heavily because branch staff are expected to guide customers, not just process transactions. The core message to reinforce with every customer: no bank employee will ever ask for an OTP, CVV, PIN, or full card number over a call, SMS, or email, and no legitimate deadline requires acting within minutes.
If a customer suspects they have been targeted by phishing, vishing or smishing, the sequence matters. First, they should stop the interaction — hang up, don't click, don't reply. Second, they should call the bank's official helpline (from the number on their card, not one dialled from the suspicious message) to block the account, card, or UPI handle. Third, they must file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in or call the 1930 helpline, since fast reporting through these official channels also improves the odds of transaction reversal under the banking system's fraud-response protocols. Related controls around device and channel security are covered in COMPUTER INSECURITY, and since these frauds often exploit weak authentication design, it's worth cross-referencing the IT Security note on digital signature and PKI in banking to see how stronger authentication reduces exposure in the first place.
📌 Remember: Reporting speed changes the liability outcome. A customer who reports within the prescribed working-day window is treated very differently under RBI's framework than one who reports weeks later.
🎯 Conclusion: Turning Awareness Into Exam-Ready Recall
Phishing vishing and smishing are tested less as technical trivia and more as applied judgement — can you classify the channel, spot the red flag, and apply the correct liability and reporting rule to a given scenario? Anchor your revision around the three-channel structure, the shared red flags (OTP requests, urgency, domain mismatch), and RBI's graded liability framework, and most scenario-based questions become straightforward. Build broader recall across the Channels Of Cyber Crimes chapter, and pair it with the sibling guide on channels of cyber crime in banking for the full taxonomy before you sit the paper. For the complete set of notes on this subject, browse every Prevention of Cyber Crime article published on the blog.
🧠 Practice MCQs: Phishing, Vishing and Smishing
Q1. Which of the following best describes 'vishing'? (a) Fraud conducted purely via SMS links (b) Fraud conducted via voice calls impersonating a trusted entity (c) Malware installed through email attachments (d) Card cloning at ATM skimmers
Answer: (b) — Vishing is voice phishing: the fraudster calls, often spoofing a bank or RBI number, to extract confidential details.
Q2. Under RBI's framework on customer liability for unauthorised electronic transactions, a customer who reports the fraud promptly within the prescribed working-day window and is not at fault typically bears: (a) Zero liability (b) Full liability (c) A fixed penalty regardless of timing (d) Liability decided solely by the police
Answer: (a) — Prompt reporting where the breach is not due to customer negligence attracts zero liability under RBI's graded framework; liability rises as reporting is delayed.
Q3. Which of these is a genuine red flag of a smishing attempt? (a) A message from a saved bank contact with no link (b) A shortened, obscure link demanding you "update KYC immediately" (c) An SMS OTP you requested for your own transaction (d) A statement email from the bank's registered domain
Answer: (b) — Unsolicited shortened links paired with urgent KYC or account-freeze threats are a classic smishing pattern.
Q4. A caller claiming to be a bank official asks you to share your OTP to "reverse a wrongful debit." What is the correct action? (a) Share the OTP since it is meant for a reversal (b) Ask for the caller's employee ID and then share the OTP (c) Disconnect and call the bank's official number printed on your card or passbook (d) Share the OTP only if the caller knows your account number
Answer: (c) — No bank ever needs your OTP over a call; verify independently through the number on your card before taking any action.
Q5. Where should a customer in India report a suspected phishing, vishing or smishing fraud immediately? (a) Only the branch manager, after a week (b) The National Cyber Crime Reporting Portal (cybercrime.gov.in) or helpline 1930 (c) Directly to IIBF (d) The bank's social media handle only
Answer: (b) — Immediate reporting via cybercrime.gov.in or the 1930 helpline, alongside informing the bank, is the correct first response.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
What is the difference between phishing, vishing and smishing?
They differ only in the channel used — phishing uses email, vishing uses voice calls, and smishing uses SMS or messaging apps — but all three impersonate a trusted party to extract credentials, OTPs, or card details.
Can a bank ever ask for my OTP or CVV over a phone call?
No. Banks and RBI have repeatedly clarified that OTP, CVV, PIN, and full card number are never requested over a call, SMS, or email; any such request is fraudulent regardless of how legitimate the caller sounds.
What is RBI's limited liability rule for unauthorised transactions?
Under RBI's framework on customer protection for unauthorised electronic banking transactions, a customer's liability depends on how quickly the transaction is reported and whether the breach originated with the bank, a third party, or the customer's own negligence, ranging from zero liability to full liability.
Where can I report a phishing, vishing or smishing incident in India?
File a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in or call the 1930 helpline immediately, and simultaneously inform your bank so the account, card, or UPI handle can be blocked.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.