Social Engineering

Social engineers कैसे सोचते हैं: India में trust कैसे तोड़ा जाता है

Mumbai bank call से लेकर Aadhaar pressure तक — social engineering की 4 techniques, क्यों awareness posters काम नहीं करते, और आज से 5 practical steps।

CyberSathi DeskAI-assisted · editorially reviewed
Social engineers कैसे सोचते हैं: India में trust कैसे तोड़ा जाता है

वो phone call जिसने security की सोच बदल दी

Mumbai, 2019। एक आदमी ने bank की internal back-office number पर call किया — customer care नहीं। Number WhatsApp data group से ₹2,000 में मिला था। Account holder का नाम, mother's name, last four digits, city — ये सब ₹50 per record वाले leak से।

उसने system hack नहीं किया। Malware नहीं डाला। सिर्फ कहा: “Main branch से Rajesh बोल रहा हूँ — customer का password reset urgent है, file पर mobile verify कर दो।” Junior desk ने tone इतना casual पाया कि सवाल नहीं पूछा। 16 seconds। 3:15 तक ₹3.2 lakh निकल चुके थे।

यही social engineering है — virus नहीं, zero-day नहीं। बस ये समझना कि दूसरा व्यक्ति कब trust करता है और कब जल्दी करता है।

India में गलती ये रही कि हमने security को सिर्फ technical problem माना — locks, passwords, encryption। दरवाज़ा lock टूटने से नहीं खुलता। घंटी बजने से खुलता है।

Social engineering असल में क्या है

ये कला है किसी से वो चीज़ ले लेना जो आप चाहते हो — उसके डर, इच्छा, और “ये सच होगा” वाली धारणा को पढ़ कर।

नया नहीं है। 1987 में Ahmedabad का एक tailor दुकानदार को call करके बोला बेटा accident में है, ₹50,000 चाहिए। दो घंटे में पैसे चले गए। Accident नहीं हुआ था — सिर्फ ये पता था कि panic में verify भूल जाते हैं।

आज WhatsApp, Aadhaar, NPCI leaks के युग में ये industrial हो गया है। Gurugram call centers phone lists चलाते हैं; हर caller को role सिखाया जाता है — bank manager, telecom, police, tax — और age group के हिसाब से script।

Recording देखने पर झूठ से ज़्यादा इंसानियत चौंकाती है। 60-year-old को धीरे बोलेंगे, नाम दोहराएँगे, माफ़ी माँगेंगे। 35-year-old IT वाले को technical jargon और “आप समझदार हो, अभी act करो”। डर शून्य से नहीं बनाते — आपका पहले से मौजूद डर पढ़ कर map थमा देते हैं।

चार core techniques

Authority

Bank manager, IT officer, police — बचपन से authority पर सवाल न पूछने की training। “Cybercrime से Sergeant Sharma” सुनते ही ज्यादातर callback या complaint number नहीं माँगते।

Bangalore की Priya (नाम बदला) को call आया: Aadhaar suspicious account से link है, ₹25,000 “temporary verification” में भेजो वरना legal action। Software engineer थी; Aadhaar leak जानती थी — फिर भी 20 minutes में transfer हो गया। Authority decision-making का बोझ हटा देती है: सोचना बंद, obey शुरू।

Urgency

“24 घंटे में account block।” “UPI limit freeze।” “School fees fail — tonight तक।” Urgency cortisol/adrenaline है — उस state में card के पीछे number नहीं डायल होता। Calm problem-explain → ticking clock → irreversible action (transfer / link / OTP ज़ोर से)। India में trains, bank hours, government notices की time-sensitivity cultural है — इसलिए artificial urgency असली लगती है।

Likeability

सबसे underestimated। Scammer 10 minutes rapport बनाता है — दिन पूछता है, jokes पर हँसता है, “मैं help करने आया हूँ।” जिसे आप पसंद करते हो, उसको ना कहना मुश्किल। एक recording में telecom agent ने शादी के बारे में पाँच मिनट पूछा; जब “SIM risk verify करो” आया, victim को friend मदद लग रही थी, credential नहीं।

Trust seeding

पैसे से पहले छोटी सच्चाइयाँ confirm करवाते हैं — DOB, last transaction, “ICICI statement आया था?” हर सही जवाब (क्योंकि data पहले से खरीदा/चोरी है) trust बढ़ाता है। तीन सच के बाद चौथा झूठ कमज़ोर पड़ जाता है। कुछ victims ₹90,000 जाने के बाद भी पहले bank error समझते रहे।

Prevention कहाँ टूटती है

हर bank के posters, OTP PSA, SMS warnings — फिर भी CERT-In के अनुसार social engineering reports 2023 में 2022 से ~42% बढ़ीं। Technique जानना ≠ real-time में पकड़ना। 11 AM की call पर “SIM at risk” सुनकर आप intellectual mode में नहीं होते — startled होते हो। Gap यही है: ignorance नहीं, humanity। Engineers, accountants, IT security वाले भी authority+urgency+likeability के आगे गिरे हैं। IQ नहीं — call आने वाली state matter करती है।

आज से पाँच काम

  1. Unsolicited contact को suspicious मानो। उन्होंने दिया number मत डायल करो — statement / official website / fresh search से।
  2. OTP, CVV, password कभी मत दो — phone/WhatsApp/SMS/email। Legitimate institution नहीं माँगती। Hang up → bank main number।
  3. Urgency पर slow down। असली risk bank को खुद call करने के बाद भी रहेगा; scam स्वतंत्र होते ही गायब।
  4. परिवार (खासकर elders) को बताओ: bank कभी पैसे move करने को नहीं कहेगी — security check के नाम पर भी नहीं।
  5. Credit report quarterly चेक करो (CIBIL free annual)। Early catch से नुकसान सस्ता पड़ता है।

Related: Digital arrest guide · 1930 FAQ · WhatsApp scams · Cancellation OTP guide.

याद रखने लायक बात

सालों तक लगा security = बेहतर दीवारें। असल समस्या दरवाज़ा था — और दरवाज़ा अंदर से खुलता है। Social engineering defenses तोड़ना नहीं चाहता; आपको खुद नीचे उतारना चाहता है। Trust कमज़ोरी नहीं — इंसानियत है। Industrial scam के युग में वही हमें तोड़ भी सकता है।

Frequently asked questions

क्या bank कभी OTP phone पर माँगेगी?

नहीं। Hang up करके official number से verify करें।

Internal routing number कैसे लीक होती है?

Data brokers / अंदरूनी leaks — WhatsApp groups पर सस्ते में बिकती हैं।

Educated लोग क्यों फँसते हैं?

IQ नहीं — authority + urgency + likeability वाली emotional state।

कहाँ report करें?

1930 · cybercrime.gov.in · CERT-In

Read next