Q.An online retail company received several customer complaints about unauthorised transactions on their accounts after customers received e-mails, appearing to be from the company, asking them to "verify" their card details by clicking a link. Investigation revealed the e-mails were not genuinely sent by the company.
You're viewing a preview — the full solution, concept, methods & PYQ mapping are locked.
Start your 14-day free trial to unlock the full solution →- Identifying the risk: The scenario describes fraudulent e-mails that impersonate the genuine company and trick customers into revealing sensitive card details by clicking a link — this is precisely the definition of Phishing, a form of e-business fraud where a criminal impersonates a trusted party to extract confidential information from a victim.
- Suggested safeguards:
-
Customer awareness — the company should clearly and repeatedly communicate to customers that it will never ask them to "verify" card details or send an OTP through an e-mail link, and should train customers to check the sender's actual e-mail address and avoid clicking links in unsolicited messages asking for sensitive information.
-
Strong (OTP-based) authentication — requiring a One-Time Password sent directly to the customer's registered mobile number for any transaction adds a second layer of security, so that even if a phishing attempt captures a card number, the transaction cannot be completed without the OTP, which a phishing e-mail alone cannot obtain. …
Unlock everything free for 14 days
- Full step-by-step solutions
- Concept-first explanations
- Methods, shortcuts & mistakes
- PYQ mapping + timed mock tests
Full access for 14 days. No credit card required.