Related on this site: if you suspect your phone itself is already compromised, start with our Android spyware removal guide before working through the tips below — a password change doesn't help if something is still reading your screen. And if your concern is specifically identity misuse rather than device compromise, see How to Check if Your Aadhaar Has Been Misused.
Jump to a section: Passwords · Gmail · WhatsApp · UPI Fraud · QR Scams · AI Scams · New in 2026 · Public Wi-Fi · SIM Swap · Social Media · Backups
Passwords & Account Access
- Move to a dedicated password manager — Bitwarden (free, open-source) or 1Password — instead of your browser's built-in saver, since browser-stored passwords are the first thing infostealer malware scrapes (more on that below).
- Check every email address you've ever used at haveibeenpwned.com to see which past breaches exposed your credentials, and change any password still in active use elsewhere.
- Switch to a passkey wherever a service offers one — passkeys are tied to your device's biometric hardware and can't be phished, guessed, or reused across a data breach the way a text password can.
- Never reuse a password across two important accounts; a leak at one throwaway service becomes a master key to your email, bank, and social accounts the moment reuse is involved.
- Use a passphrase instead of a password for anything you must type by hand — four random unrelated words are harder to crack than "P@ssw0rd123" and easier to remember.
- Turn on login alerts everywhere they're offered, so a new-device sign-in reaches you by email or SMS the moment it happens, not weeks later.
- Audit your account recovery options at least twice a year — an old recovery email you no longer control is a silent backdoor into every account tied to it.
- Avoid security questions with answers that live on your Facebook profile — mother's maiden name, first school, pet's name are publicly guessable for most people.
- Use a hardware security key (YubiKey or Google Titan) as your second factor on your most important accounts, since SIM-swap attacks specifically target SMS-based codes.
- Delete accounts you no longer use rather than letting them sit dormant — an abandoned account with an old, reused password is a live liability with zero benefit to you.
Gmail & Email Security
- Turn on 2-Step Verification at myaccount.google.com/security if you haven't already — this alone blocks the overwhelming majority of automated account takeovers.
- Add a passkey to your Google account under Security > Passkeys and security keys; once added, it bypasses the second authentication step entirely since it already proves device possession.
- If you're a journalist, activist, elected official, or otherwise a plausible target for a targeted attack, enroll in Google's Advanced Protection Program (g.co/advancedprotection), which now accepts a passkey instead of requiring physical security keys.
- Stop creating app passwords unless you're certain you need one — Google itself calls them "unnecessary in most cases" now that OAuth-based "Sign in with Google" covers nearly every modern app.
- Check myaccount.google.com/device-activity monthly for devices signed into your account that you don't recognize, and remove access immediately if you find one.
- Never click "verify your account" links inside an email — go to the service's site directly by typing the URL yourself, since even a hovered link can be spoofed.
- Use Gmail's confidential mode for anything sensitive you're sending, which prevents forwarding, copying, and downloading, and can auto-expire the message.
- Watch for the blue verified checkmark next to a sender's name — it confirms the organization's identity via BIMI and a verified trademark, which most phishing senders can't replicate.
- Review third-party app access under Security > Third-party apps with account access, and revoke anything you no longer use — old app grants are a common quiet leak point, and now a favourite target of OAuth consent phishing (see below).
- Set up a separate, low-value email address for sign-ups and newsletters, keeping your main address reserved for banking, government, and important personal accounts.
WhatsApp Safety
- Turn on WhatsApp's own two-step verification (Settings > Account > Two-step verification) and set a six-digit PIN, so anyone who gets your SIM or OTP still can't register your number on a new device.
- Check Settings > Linked Devices regularly and log out anything you don't recognize; a forgotten linked session can silently mirror every message you send.
- Never share the six-digit SMS verification code WhatsApp sends you — this is all an attacker needs to hijack your account, and "I accidentally sent you my code, forward it" is exactly that scam.
- Set "Who can see my profile photo / last seen / about" to My Contacts or Nobody under Settings > Privacy, since public data feeds directly into social-engineering scripts.
- Be suspicious of any message from a "friend or relative" in urgent financial trouble, especially with slightly off writing style or an unfamiliar number — a common pattern run from cloned numbers.
- Use "View Once" for sensitive photos or documents you must send but don't want stored on the recipient's device indefinitely.
- Report and block unknown business accounts that message you first — legitimate WhatsApp Business accounts show a green verified badge, and its absence on a bank or company account is a red flag.
- Never scan a QR code someone sends you inside WhatsApp to "link your account" or "join a group payment" — a known technique to hijack a WhatsApp Web session.
- Disable auto-download for media from unknown contacts under Settings > Storage and data, since malicious files are sometimes disguised as images or PDFs — including the fake-PDF trick covered below.
- If your account gets hijacked, reinstall WhatsApp with your number immediately to force a re-verification that knocks out the attacker's session, then re-enable two-step verification.
UPI & Digital Payment Fraud
- Save the National Cybercrime Helpline number, 1930, in your phone right now — it operates 24/7 and can trigger a hold on the receiving account if you call within the first critical minutes.
- File any UPI fraud complaint at cybercrime.gov.in as well as calling 1930; the online complaint generates the acknowledgment number your bank will ask for during dispute resolution.
- Remember a UPI PIN is only ever needed to send money, never to receive it — any prompt to enter your PIN for a "refund" or "receive payment" is fraud by definition.
- Never scan a QR code to receive money — QR codes in UPI initiate payments, not receipts, and scanning one that claims to credit you will instead debit your account.
- Refuse any request to install AnyDesk, TeamViewer, or QuickSupport from someone claiming to be bank or UPI support — no legitimate support process requires screen-sharing access, and this remains the single most common vector behind large-value UPI fraud in India.
- Don't trust a customer-care number found via Google search or a sponsored ad — fraudsters actively plant fake "customer care" listings for major banks. Get support numbers only from your bank's official app or physical card.
- Set a daily UPI transaction limit inside your app's settings, which caps your maximum exposure even if your credentials are compromised.
- Enable a separate app-lock (fingerprint or face) specifically on your UPI app, distinct from your general phone lock.
- Verify the payee name on the confirmation screen before completing any transaction — scammers register handles with names one character off from a real business.
- Know the RBI's limited-liability rule: reporting unauthorized fraud to your bank within three working days can reduce your liability to zero — reporting speed has direct financial consequences.
- Enable SMS and app push notifications for every transaction, however small, so an unauthorized debit reaches you within seconds.
- If you've already installed AnyDesk or TeamViewer at someone's request, uninstall it immediately, change your UPI PIN, and call your bank's fraud line — don't wait to see if anything looks wrong first.
QR Code Scams
- Treat every unsolicited QR code — via WhatsApp, SMS, email, or a public sticker — as suspicious until you've verified who sent it and why; "quishing" is now a standalone attack category precisely because people trust QR codes more than links.
- Check what your phone's camera preview shows as the destination URL before scanning; a mismatched or shortened URL is your warning sign.
- Be wary of QR stickers on parking meters, charging stations, or restaurant tables — attackers have repeatedly been caught pasting a fraudulent sticker directly over a legitimate one.
- Never scan a QR code someone hands you claiming it will "process a refund" — refunds happen automatically to your original payment method, never via a QR scan you initiate.
- Use your UPI app's built-in scanner rather than a generic camera or third-party QR reader, since dedicated payment-app scanners are built to flag known-malicious merchant strings.
- Read the merchant name and amount on the confirmation screen out loud before entering your PIN — this single pause catches most QR scams before the money moves.
- Disable QR-code auto-actions in your camera settings if available, so scanning always requires a manual confirmation tap.
- If a QR code leads to an app download rather than a payment or website, don't install it — a common route for sideloading fake banking apps.
AI-Powered Scams
- Agree on a family "safe word" that isn't shared anywhere online, to verify identity during any urgent call or video call asking for money — voice-cloning tools can now convincingly mimic a relative's voice from a few seconds of public audio.
- Treat any urgent call from a "relative in trouble" with heightened suspicion if it pressures you to act within minutes without hanging up and calling back on a saved number.
- Know that AI-generated video calls can now convincingly impersonate a colleague or executive in real time and have been used to authorize fraudulent transfers — verify unusual financial requests through a second channel, not the same call.
- Don't trust caller ID alone; number-spoofing tools let scammers display your bank's real customer-care number on your screen.
- Be skeptical of hyper-personalized phishing messages referencing real details about you — AI tools now let scammers scrape public social posts and craft messages referencing your actual job, city, or recent purchases.
- Assume any investment opportunity promoted through an AI-narrated video using a recognizable public figure's face or voice is fraudulent — the figures shown are rarely aware their likeness is being used.
- Never provide biometric data — a photo, voice recording, or video — to an unfamiliar app or website "for verification," since biometric data can't be changed the way a password can once it leaks.
- Report AI-voice-cloning or deepfake scam attempts to the National Cybercrime Reporting Portal — I4C tracks these as a distinct, rapidly growing fraud category.
New in 2026: The Attacks Older Guides Don't Cover
This is the section most "2026" listicles skip entirely, because these techniques are recent enough that a lot of security content hasn't caught up yet. Every item here reflects an active, currently-documented attack pattern, not a hypothetical.
- Fake CAPTCHA / "ClickFix" attacks: the fastest-growing initial-infection technique of 2026. A page shows a "Verify you are human" box and tells you to press Windows + R, then Ctrl + V, then Enter. What actually happens is a malicious command was silently copied to your clipboard the moment the page loaded, and pasting it into the Run dialog executes it with no download warning at all. No real CAPTCHA has ever asked you to open a Run dialog or terminal — if one does, close the tab immediately.
- Infostealer malware: a category of malware (Lumma, Stealc, and similar families) built purely to harvest saved browser passwords, active login sessions, autofill data, and crypto wallets, then upload everything to the attacker within minutes. It's most often delivered through cracked software, "free" game cheats, or fake AI-tool installers — avoid pirated downloads and never disable Windows Defender or your antivirus "just to install" something.
- Session cookie theft ("pass-the-cookie"): a technique that steals your already-logged-in session token instead of your password, which means it can bypass two-factor authentication entirely since the attacker never needs your second factor. Log out of sensitive accounts on shared devices, and periodically use each service's "sign out of all sessions" option to invalidate stolen tokens.
- OAuth consent phishing ("ConsentFix"): a fake Microsoft/Google sign-in screen that never asks for your password at all — instead it asks you to approve an innocuous-looking permission request from a malicious app. Once approved, the attacker holds a token that survives a password change and keeps working until you manually revoke it under your account's connected-apps settings.
- Malicious browser extensions: extensions requesting the broad "read and change all your data on all websites" permission can inject scripts to steal session cookies and form data invisibly. Open chrome://extensions (or your browser's equivalent) periodically, remove anything you don't actively use, and check the publisher's reputation before installing anything new.
- Fake AI customer-support chat widgets: convincingly natural AI-driven chat boxes embedded on cloned versions of real company websites, capable of holding a normal-feeling conversation while extracting your card number or OTP. Only use support chat launched from a company's verified app or a URL you typed yourself.
- Browser AI assistant manipulation: as AI assistants built into browsers (Chrome's Gemini features, Copilot in Edge, and similar tools) start reading page content and taking actions on your behalf, attackers have begun hiding invisible instructions inside webpage text specifically to manipulate what the assistant does next — a technique known as prompt injection. Review exactly what permissions and autonomous actions you've granted any browser AI assistant, and treat "summarize and act on this page for me" requests on unfamiliar sites with caution.
- Fake PDF download and "document viewer" pages: sites disguised as PDF converters or viewers that serve infected files instead of the document you expected, sometimes paired with a fake "update your PDF reader" prompt. Before opening an unfamiliar PDF or downloaded file, scan it at virustotal.com, a free tool that checks a file or link against dozens of antivirus engines simultaneously.
- NFC / tap-to-pay scams: beyond old-fashioned card skimming, newer scams plant fraudulent "tap here for a refund" NFC tags that silently initiate a payment rather than receiving one — the tap-to-pay equivalent of the fake QR code. Keep NFC switched off when you're not actively paying, and never tap your phone against an unofficial-looking terminal or unattended sticker.
- Fake browser update pop-ups: a full-screen "Your browser is out of date, update now" warning encountered while browsing a site is not from your browser — Chrome, Edge, and Firefox all update themselves automatically in the background and never interrupt your browsing to demand an urgent manual update. Close the tab; never download an executable from a page that shows this prompt.
Public Wi-Fi Safety
- Avoid logging into banking or UPI apps over public Wi-Fi entirely — use mobile data instead, since it's meaningfully harder for someone else on the same network to intercept.
- If you must use public Wi-Fi, connect through a reputable VPN first, encrypting your traffic before it leaves your device.
- Turn off Wi-Fi auto-connect for open networks, so your device doesn't silently join a lookalike hotspot named after a café or airport you're near.
- Check that any site you enter credentials on shows "https://" and a padlock icon, though treat this as a minimum bar, not proof of legitimacy — scam sites can have valid certificates too.
- Turn off file sharing and discovery features while on public networks, and forget the network from your saved Wi-Fi list once you're done, so your phone doesn't silently rejoin it — or a spoofed clone of it — later.
- Be cautious of "free Wi-Fi" networks requiring an app download or unusual permissions to connect — a known technique to get malware installed under the guise of network access.
- Use your phone as a personal mobile hotspot for a laptop instead of public Wi-Fi whenever you're handling anything sensitive.
SIM Swap Fraud
- Check every mobile connection registered against your identity nationwide at tafcop.sancharsaathi.gov.in, using your existing number and an OTP — this reveals SIMs you may not know exist in your name. This is the same tool covered in more depth in our Aadhaar misuse guide, alongside how to check which bank account your identity is actually mapped to for payments.
- Ask your telecom operator to set a SIM-swap PIN or extra verification on your account if offered, adding a manual check before any new SIM can be issued against your number.
- Treat a sudden, unexplained loss of mobile signal — "no service" or "emergency calls only" with no known outage — as a possible sign your SIM has just been swapped, and contact your operator immediately.
- Never share your Aadhaar number, PAN, or other KYC documents with unsolicited callers claiming they need it to "reissue" or "upgrade" your SIM.
- Avoid publicly posting your mobile number or full date of birth on social media, since both are commonly required as verification details for a fraudulent SIM reissue.
- Register for SMS alerts from your operator for any SIM change or number-porting request, so an unauthorized swap attempt reaches you before it completes.
- Move critical account 2FA away from SMS-based OTP wherever an authenticator app or passkey option exists, since SIM swap fraud exists specifically to intercept SMS codes.
- If you suspect a SIM swap has already happened, contact your operator's fraud line immediately to block the number, then separately alert your bank.
Social Media Privacy
- Set every major platform's account to two-factor authentication using an authenticator app, not SMS, for the same SIM-swap-resistance reasoning as email and banking.
- Review "Active Sessions" or "Where you're logged in" periodically on Facebook, Instagram, and X, and log out any device or location you don't recognize.
- Turn off precise location tagging on photos before posting, or strip it entirely — most phone cameras embed exact GPS coordinates by default, which persists even after download.
- Set new posts, stories, and your friends/followers list to private or a restricted audience by default rather than adjusting visibility after something's already public.
- Avoid posting real-time location updates — a "checked in" post tells anyone watching exactly where you are, and just as usefully, exactly where you aren't.
- Limit what's visible on your public profile — full date of birth, workplace, phone number, and home address are precisely the fields used to answer account-recovery security questions elsewhere.
- Be selective about quiz apps and third-party apps requesting account access, and periodically review connected apps under each platform's Settings > Apps and Websites — many exist solely to harvest your friend list, and access often persists long after you stop using the app.
- Avoid posting photos of children with identifying school uniforms, name tags, or location details visible, since this combination is a known input for stalking.
- Search your own name periodically to see what's publicly visible about you, and request removal of anything outdated on people-search and data-broker sites.
Data Backups
- Follow the 3-2-1 backup rule: three copies of anything important, on two different types of storage, with at least one copy off-site, in the cloud, or otherwise not permanently connected to your main device — a single connected backup is not a backup, it's a coincidence.
- Turn on automatic Google Photos or iCloud backup so photos and videos survive a lost, stolen, or factory-reset device.
- Use Google Takeout (takeout.google.com) periodically to download a full local copy of your Gmail, Drive, and Photos, so you're never solely dependent on the cloud provider staying accessible.
- Encrypt any backup drive that leaves your home using built-in tools like BitLocker (Windows) or FileVault (Mac), so a lost or stolen drive doesn't hand over your data with the hardware.
- Test your backups by actually restoring a file from them at least once or twice a year — an untested backup that fails silently is functionally the same as no backup at all, and this is also the moment to confirm your backup automation is still actually running.
- Back up your two-factor authenticator app's recovery codes separately from the phone that runs it — losing your only 2FA device without backup codes can lock you out as effectively as an attacker could.
- Enable end-to-end encrypted backups for WhatsApp under Settings > Chats > Chat backup, so your backup isn't readable even if the cloud storage holding it is ever compromised.
- Keep a printed or offline copy of truly critical information — passport number, insurance policy numbers, emergency contacts — accessible without power or internet.
None of these are complicated on their own — the difficulty is usually just not knowing they exist. Pick five that apply to you right now, act on them today, and treat the rest as a list to revisit rather than a one-time checklist to clear.
Keep reading: How to Remove Spyware from Android | How to Check if Your Aadhaar Has Been Misused





