10 Tips to Stay Safe from Phishing Attacks

Phishing attacks involve deceptive techniques used by hackers to acquire confidential information, including passwords and personal data. By masquerading as trusted sources, these cybercriminals…

Madhurendra SachanBy Madhurendra Sachan
January 25, 2021
6 min read
Updated October 4, 2026
Feature image for phishing bait

The best protection against phishing is a few firm habits: never share an OTP or password because a message asked, reach websites through your own bookmarks or apps, check the real sender domain, and turn on two-step verification everywhere. Add a reporting habit and, for organisations, email authentication, and most phishing attempts fail before they cost anything.

Phishing is a technique criminals use to steal confidential information such as passwords, card numbers and personal data by posing as a trusted source. It used to arrive mostly by email. Today it comes just as often through text messages, WhatsApp, social media, phone calls and fake ads. The ten tips below are the ones that make the biggest difference, in rough order of impact.

10 tips to prevent phishing attacks

1. Never share an OTP, PIN or password

No real bank, wallet, courier or government office needs your one-time password to “verify” or “refund” anything. An OTP is the final key to a transaction or a login. Anyone asking for it, by phone, chat or email, is trying to use it. Hang up, and call back on a number you already trust.

Type the address, use a bookmark or open the official app. Links in emails and texts are the main way people end up on fake login pages. This one habit defeats most credential phishing, however convincing the message looks.

3. Check the real sender, not the display name

The name shown in your inbox can be anything. Look at the actual email address and the domain after the @. “Accounts Team <billing@yourbank-support.co>” is not your bank. In texts, a message from an ordinary mobile number claiming to be a company is a warning sign.

4. Turn on two-step verification, ideally phishing-resistant

Two-step verification means a stolen password alone isn’t enough. Passkeys and hardware security keys go further, because they only work on the genuine website and can’t be typed into a fake one. Use an authenticator app over SMS codes where you have the choice.

5. Don’t trust the padlock alone

A padlock and https:// mean the connection is encrypted. They don’t mean the site is honest. Free certificates are available to anyone, scammers included. Check the domain name in the address bar instead. Our guide on how to identify a phishing website shows what to look for.

6. Slow down when a message is urgent

“Your account will be blocked today.” “Pay within one hour to avoid legal action.” Urgency is the most common pressure tactic in phishing because it stops you from checking. The more a message hurries you, the more time you should take.

7. Use a password manager

A password manager creates a different password for every site, so one stolen password doesn’t open everything. It also refuses to autofill on a lookalike domain. If your manager doesn’t offer your password, ask why before typing it in.

8. Check your accounts and statements regularly

Look at bank and card transactions, and the list of devices signed into your email and social accounts. Fraud caught on day one is far easier to stop than fraud found at the end of the month.

9. Remember phishing isn’t only about banks, and it speaks every language

Criminals impersonate marketplaces, social networks, delivery firms, tax departments, streaming services and your own employer. Messages can be in any language and are no longer reliably full of mistakes, since AI tools write fluent text. Judge the request, not the spelling.

10. If in doubt, report it and delete it

Use the “report phishing” button in your mail app. In India, report suspicious calls and messages through Chakshu on the Sanchar Saathi portal, and if money has left your account, call 1930 or file a complaint on cybercrime.gov.in immediately.

Why reporting fast matters for your money

Speed affects who pays for a fraud. Under the Reserve Bank of India’s 2017 circular on limiting customer liability in unauthorised electronic banking transactions, a customer whose loss comes from negligence, such as sharing payment credentials, bears the entire loss until the transaction is reported to the bank. Report at once and the bank is responsible for what happens after that. Waiting can be the most expensive mistake.

Tips for organisations

The habits above protect individuals. Companies need a few controls on top:

  • Publish DMARC. Domain-based Message Authentication, Reporting and Conformance, together with SPF and DKIM, stops criminals sending email that uses your exact domain once your policy is set to reject. Start with our explainer on what DMARC is and how it works.
  • Make reporting one click. Staff who report quickly are your best detection system. Thank them and act on reports fast.
  • Run realistic phishing simulations based on the lures your sector actually sees.
  • Watch for lookalike domains and fake pages using your brand, and get them taken down. DMARC can’t stop a domain someone else registered.
  • Agree a verification rule for payments. Any change to bank details is confirmed by phone on a known number, every time.

For a closer look at the warning signs inside a message, read how to identify a phishing email.

FAQ

What is the single most effective tip against phishing?

Never act on a link or request inside an unexpected message. Instead, open the app or type the website address yourself, and call back on a number you already trust. This one habit defeats fake login pages, fake payment requests and most phone scams, because it takes the attacker’s link and phone number out of the conversation.

Do banks ever ask for an OTP over the phone?

You should treat any request for your OTP, PIN, CVV or password as fraud, whoever the caller says they are. A real bank already has what it needs to identify you and won’t ask you to read out a code sent to your phone. If someone asks, hang up and call the number on your card.

Close the page and don’t enter anything else. If you typed a password, change it immediately from a trusted device, along with any account that shares it. If you shared card details or an OTP, call your bank at once to block the card. In India, call 1930 if money has been taken.

Want to learn more about protecting your organization?

Talk to a TIKAJ security expert and discover how our platform can help secure your digital ecosystem.

Get in Touch