Skip to content
Case Problems · Q9

Q.An online retail company received several customer complaints about unauthorised transactions on their accounts after customers received e-mails, appearing to be from the company, asking them to "verify" their card details by clicking a link. Investigation revealed the e-mails were not genuinely sent by the company.

(a) Identify the e-business risk described here.
(b) Suggest two safeguards the company and its customers could use to prevent this in future.
Maharashtra MsbshseTextbookSubjectiveImportance★★★★★
27% · 10/37 Questions
🔒 Locked · start free trial →

You're viewing a preview — the full solution, concept, methods & PYQ mapping are locked.

Start your 14-day free trial to unlock the full solution →
  1. Identifying the risk: The scenario describes fraudulent e-mails that impersonate the genuine company and trick customers into revealing sensitive card details by clicking a link — this is precisely the definition of Phishing, a form of e-business fraud where a criminal impersonates a trusted party to extract confidential information from a victim.
  2. Suggested safeguards:
  1. Customer awareness — the company should clearly and repeatedly communicate to customers that it will never ask them to "verify" card details or send an OTP through an e-mail link, and should train customers to check the sender's actual e-mail address and avoid clicking links in unsolicited messages asking for sensitive information.

  2. Strong (OTP-based) authentication — requiring a One-Time Password sent directly to the customer's registered mobile number for any transaction adds a second layer of security, so that even if a phishing attempt captures a card number, the transaction cannot be completed without the OTP, which a phishing e-mail alone cannot obtain. …

Unlock everything free for 14 days

  • Full step-by-step solutions
  • Concept-first explanations
  • Methods, shortcuts & mistakes
  • PYQ mapping + timed mock tests

Full access for 14 days. No credit card required.