Phishing लोगों के compromise होने का नंबर एक तरीका है – sophisticated hacks नहीं, बल्कि एक नकली email जो जल्दबाज़ी में किसी को धोखा देने लायक असली लगे। अच्छी खबर: हर phish सुराग छोड़ता है। उन्हें पहचानने का तरीका यहाँ है।

Phishing क्या है

Phishing आपके भरोसे का नाटक करके आपका password, पैसा या personal data लेना है। यह email, text (smishing), phone (vishing) या नकली websites से आता है। Attacker urgency बनाता है, एक plausible कहानी देता है और एक लापरवाह click का इंतज़ार करता है।

7 red flags

अगर किसी message में इनमें से कोई भी हो, तो उसे शक से देखें:

1. Urgency या डर

"Your account has been locked!"
"Action required within 24 hours!"
"Your payment failed – verify now or you'll lose access!"

Legitimate कंपनियाँ आपको तेज़ी से काम करने के लिए धमकाती नहीं हैं। Urgency phishers का #1 हथियार है – यह आपकी judgment को short-circuit कर देता है। जब कुछ आप पर दबाव डाले, तो धीमे हो जाएँ।

2. संदिग्ध sender address

असली email address देखें, display name नहीं। Display name कुछ भी कह सकता है; address ही सच है।

❌ "[email protected]"
❌ "[email protected]"      (not amazon.com)
✅ "[email protected]"
✅ "[email protected]"

Links पर hover करें (click न करें) और असली URL देखें। Text में "paypal.com" लिखा हो सकता है जबकि link paypal.verify-account.net पर जाता है।

3. Generic greetings

असली कंपनियाँ आमतौर पर आपका नाम इस्तेमाल करती हैं। "Dear valued customer" या "Hello user" mass-sent phishing की निशानी है – sender नहीं जानता आप कौन हैं।

4. Grammar और typos

एक typo का मतलब phishing नहीं, पर खराब grammar, अजीब phrasing या odd formatting scams में आम है। Official mail आमतौर पर clean होती है।

5. जानकारी के लिए अनुरोध

कोई भी legitimate service आपसे email या message में कभी आपका password, PIN या OTP code नहीं माँगेगी। जो भी माँगे वह scammer है, चाहे वह कुछ भी दावा करे।

6. अनपेक्षित attachments

Invoice, "receipt", "report" जो आपने माँगा ही नहीं – attachments malware के आने का तरीका हैं। अगर आप किसी फ़ाइल की उम्मीद नहीं कर रहे, तो उसे न खोलें।

7. सच होने से ज़्यादा अच्छा

"आपने gift card जीता!", "unexpected tax refund", "अपना free crypto claim करें"। अगर कुछ सच होने से ज़्यादा अच्छा लगे, तो वह hook है।

एक वास्तविक उदाहरण, annotated

Subject: URGENT - Your Netflix account has been suspended
─────────────────────────────────────────────────────
[🔴] Urgency: "URGENT", "suspended"
Dear customer,                                      [🔴] generic greeting
We have noticed unusual activity on your account.    [🔴] fear + vague
Click below to verify your billing information       [🔴] "verify" = give data
within 24 hours or your account will be cancelled.   [🔴] deadline pressure
Veriy your account now:                              [🔴] typo "Veriy"
  [ http://netflix.account-update.ru ]               [🔴] not netflix.com
─────────────────────────────────────────────────────
Sincerely, Netflix Billing                            [🔴] no name

एक ही message में सात red flags। असली Netflix mail में आपका नाम होता है, कोई धमकी नहीं, और links netflix.com पर जाते हैं।

जब आप पहचान लें तो क्या करें

  1. कुछ भी click न करें – कोई links, कोई attachments, कोई "unsubscribe" नहीं (वह बस confirm करता है कि आपका address काम करता है)।
  2. Reply न करें।
  3. अगर वह किसी service का claim कर रहा है जिसे आप इस्तेमाल करते हैं, तो सीधे service पर जाएँ – नई tab खोलें, असली address type करें और वहाँ अपना account check करें।
  4. Report करें। ज़्यादातर email providers में "Report phishing" button होता है। Gmail, Outlook और Apple Mail सब में है।
  5. अगर आपने click किया या data डाल दिया, तो तेज़ी से action लें: password बदलें, 2FA चालू करें और असली कंपनी के support से contact करें।

Extra protection layers

मानसिक आदत

आपको हर red flag याद रखने की ज़रूरत नहीं। एक नियम याद रखें:

जब कोई message आपको rushed या scared महसूस कराए और click या reply करने को कहे – रुक जाएँ। पहले अलग, known-good channel से verify करें।

Phishing emotion पर काम करता है, logic पर नहीं। धीमे हो जाएँ, और यह हर बार fail हो जाता है।