Everything else in this curriculum is about making good decisions. None of it survives someone else having access to your account — and the methods used are mundane rather than sophisticated. Nobody is breaking encryption; they are getting you to help.
The four common attacks
| Method | How it works | The defence |
|---|---|---|
| SIM swap | A duplicate SIM is issued on your number, so OTPs go to them | App-based authenticator instead of SMS; act instantly if the network drops |
| Fake support number | A search result shows a fraudulent "broker helpline" | Only ever use the number in the official app or on the broker's site |
| Screen sharing | You are asked to install a remote-access app to "fix" something | No legitimate broker or bank will ever ask for this |
| Phishing link | A convincing login page harvests your credentials | Type the address yourself; never log in from a link |
Almost no theft involves picking a lock. Someone rings the bell, says they are from the electricity board, and is let in. The lock was never the weak point.
Account fraud works identically. Nobody breaks the security — they call you, sound official, create urgency, and you provide access yourself.
What to actually set up
- 1App-based two-factor, not SMS
An authenticator app generates codes on the device and cannot be intercepted by a SIM swap. Enable it wherever your broker supports it.
- 2A unique password for financial accounts
Reused passwords mean one unrelated breach exposes your broker. A password manager solves this properly.
- 3Turn on depository alerts
NSDL and CDSL send SMS and email on every debit from your demat. This is an independent channel — it works even if the broker app is compromised.
- 4Review the pledges and mandates
Check what is pledged and which mandates are active. Revoke anything you do not recognise or no longer use.
What no legitimate institution will ever ask
- Your OTP, by anyone, for any reason
- Your password or PIN
- A remote access or screen-sharing app
- A transfer to a "verification" account
- KYC documents through the official app or portal
- Confirming a trade you actually placed
- Re-authenticating in the app itself
- A signed physical form for specific changes
Your phone suddenly loses network with no outage in your area, and shortly after you receive password reset emails. What is happening?
Chori mein aksar taala nahi tootta — koi ghanti bajata hai, bolta hai "bijli wibhag se aaya hoon", aur andar aa jaata hai. Account fraud bilkul wahi hai. Aur sabse bada ishaara ek hi hai: jaldi. "Aaj hi karo, ek ghante mein account band ho jaayega" — koi asli bank aisa kabhi nahi bolta.
- The attacks are mundane — SIM swap, fake helplines, screen sharing, phishing.
- A sudden loss of network with no outage is the SIM swap symptom; act immediately.
- Use app-based two-factor rather than SMS wherever possible.
- Depository alerts are an independent channel that works even if the broker app is compromised.
- Urgency is the red flag. Hang up and call the number in your official app.
Mark it done to track your progress through the curriculum.
Common questions
Short, direct answers to what people ask about this topic.
- sim swap fraud meaning
- A SIM swap is when a fraudster gets a duplicate SIM issued on your mobile number, so every OTP and password-reset message reaches their handset instead of yours. Nothing about the broker or bank is broken — the number that all OTP protection quietly depends on has simply moved. The characteristic symptom is your own phone losing network and staying without it while there is no outage in your area.
- my phone lost network and I am getting password reset emails what should I do
- Treat it as a suspected SIM swap and act from another phone: call your mobile operator to check whether a duplicate SIM has been issued, then call your bank and broker on the numbers shown inside their official apps and ask for the accounts to be secured. India’s cybercrime helpline is 1930 and a complaint can be filed at cybercrime.gov.in. Speed matters more than certainty here, because the window between a duplicate SIM activating and money moving is short.
- will my broker ever ask for my OTP
- No. No broker, depository, bank, exchange or regulator will ask for your OTP, password, PIN or for a screen-sharing app to be installed, under any circumstance — no legitimate process needs them. Anyone who asks is running a fraud, however official the caller ID, the email signature or the deadline sounds. The reliable tell is urgency, because urgency exists to stop you checking.
- how do I turn on SMS alerts for my demat account
- Register for them through your depository participant — your broker — or directly on the NSDL or CDSL website, using the mobile number and email held against your demat account. Their value is that they come from the depository rather than from the broker, so they are an independent channel that still reaches you if the broking login or app has been compromised. Every debit of shares from the account triggers one.
- DDPI meaning in demat account
- DDPI stands for Demat Debit and Pledge Instruction — a narrow authorisation that lets your broker debit shares from your demat account only for a defined list of purposes, chiefly settling the delivery obligations of trades you have placed and pledging securities for margin. SEBI introduced it as a limited replacement for the broad power of attorney brokers previously took, which granted far wider authority over the account. Signing it is optional: without it, each delivery sale is approved by you with a depository PIN and OTP.