Home/Legal Resources/Legal Glossary/Phishing

LEGAL GLOSSARY · CONSUMER & CYBER

What Is Phishing?

Impersonation attacks that harvest your trust before your money — recognising the patterns, and the recovery clock if you already bit.

Gyanendra Singh·Advocate·High Court of Madhya Pradesh, Jabalpur

DEFINITION

What Does Phishing Mean?

Phishing is a fraud technique in which attackers impersonate trusted entities — banks, government portals, employers, marketplaces — through deceptive messages that trick victims into revealing credentials, OTPs or payments. The attack targets human psychology rather than software vulnerabilities, which is why awareness outperforms any single technical fix.

Legally, successful phishing constitutes cheating and impersonation offences under criminal law alongside information-technology offences — prosecution and money-recovery tracks run together.

One Fraud, Many Channels

  • Email phishing: mass deceptive mails with credential-harvesting links.
  • Smishing: SMS and messaging-app versions — courier updates, KYC expiries, tax refunds.
  • Vishing: voice calls from 'bank officers' extracting OTPs under urgency scripts.
  • Spear phishing: researched, targeted strikes against specific individuals or companies — the engine behind large business-email-compromise losses.
  • Fake apps and sites: lookalike login pages and store applications capturing everything typed into them.

Red Flags That Never Change

  • Urgency paired with consequence — 'account closing today', 'parcel held, pay now'.
  • Senders whose domains differ subtly from genuine ones; shortened or obfuscated links.
  • Any request for OTPs, PINs, card details or screen-sharing — no legitimate institution ever asks.
  • Offers arriving unsolicited: refunds you never sought, prizes never entered.
RESPONSE

If You Already Clicked or Paid

  • Disconnect and change passwords from a different device, starting with email — it resets everything else.
  • If money moved: freeze accounts via your bank, call 1930, and file on the national cybercrime portal within hours — see our UPI-fraud explainer for the liability windows.
  • Report the phishing message through your email or platform's report function to protect others.
  • Preserve every artefact — screenshots, numbers, transaction IDs — before anything self-deletes.
Verification habit: never authenticate a message using its own links or numbers. Close the message, then independently reach the institution through saved contacts — ten seconds of separation defeats nearly every phish.
FAQ

Phishing: Common Questions

1. I entered my password on a fake site but no money moved. Anything to do?

Treat it as compromised immediately: change that password everywhere it was reused, enable app-based two-factor authentication, and check account activity for unfamiliar sessions or forwarding rules attackers add quietly.

2. Can banks refuse refunds because I was careless?

The regulatory liability framework focuses on reporting speed and transaction authorisation character rather than victim-blaming — deception-induced debits reported promptly sit within zero-liability logic. Escalate refusals formally.

3. My company lost money to a spoofed CEO email. Any recourse?

Business-email-compromise losses are actionable — freeze attempts through banking channels, cyber-cell complaints, and civil recovery against identifiable recipients all run in parallel. Internal controls evidence shapes outcomes too.

4. Are SMSes safer than emails since they come from 'bank names'?

No — sender-ID masking lets fraudsters appear as institutions on SMS headers too. Treat message content, not header names, as the verification surface.

5. Where do I report a phishing site so others are protected?

Report through the national cybercrime reporting channels and the browser or email provider's own abuse functions — reports feed blocking systems that protect the wider public automatically.

6. Can phishing victims recover damages beyond refunded money?

Identified offenders face compensation orders alongside prosecution where cases mature; realistically, rapid-freeze recovery dominates outcomes, making speed the decisive variable once more.

Clicked Something You Regret — or Fighting Refusal After Loss?

Hours matter more than arguments here. Get the response sequence moving correctly right now.

Contact Gyanendra Singh →

Disclaimer: This explanation covers phishing in general terms and is not legal advice. Recovery depends on facts and timing; consult a qualified advocate about your matter.