In short
A text message pretends to be from a trusted service and contains a malicious or deceptive call to action The objective is typically to steal credentials, install malware or cause unauthorized payment.
What it is
The SMS claims a payment, account, KYC, refund or security issue needs attention. The victim is then pushed to click a link, call a number, submit credentials or make a payment.
How it starts
A text message pretends to be from a trusted service and contains a malicious or deceptive call to action.
What they tell you
The SMS claims a payment, account, KYC, refund or security issue needs attention
What they want you to do
Click a link, call a number, submit credentials or make a payment
How you lose money
steal credentials, install malware or cause unauthorized payment
What happens next
After the first successful step, the fraudster may demand more money/information, deepen account or device access, or disappear.
Warning signs
urgency | fear | trust | smishing | phishing link
Where this is documented
India — officially documented by an Indian authority/regulator
How to avoid it
Use only the bank/payment app or official contact details; never share OTP, PIN, password or screen access; verify the payee and transaction purpose before approving.
If it already happened
Contact the bank/payment provider immediately if money moved; report financial cyber fraud promptly via 1930 and cybercrime.gov.in; preserve messages, transaction IDs, phone numbers and URLs.