Fake messages and calls used to mean one thing: a slightly clumsy email from a stranger asking for money.
That single category has split into six distinct mechanisms now, a text that looks exactly like your bank, a website that looks exactly like your favourite store, a video call with a colleague’s face and voice, except the person on the other end is not actually there.
None of these need to fool you completely. They only need to fool you for the few seconds it takes to click a link, scan a code, or read out an OTP.
This builds on the wider pattern covered in our guide to the most common online scams, since nearly every scam on that list arrives to you through one of the six deceptive channels covered in this section.
This guide walks through phishing and vishing messages, cloned websites, poisoned QR codes, deepfakes, misinformation, and fabricated credentials, what each one actually looks like in practice, and the specific check that exposes it before it costs you anything.

What Do All Six of These Deception Tactics Have in Common?
Every format covered in this section borrows something real, a familiar logo, a genuine face, a real news event, and rebuilds it convincingly enough to survive a quick glance.
None of it requires the person behind it to be a skilled hacker. Templates, cloned domains, and AI voice and video tools are now cheap enough that convincing fakes get produced in minutes rather than days.
What separates a message that fools you from one that doesn’t is rarely intelligence. It is almost always time, whether you had thirty seconds to pause and verify before acting, or whether the message was built specifically to remove that pause.
Phishing attacks overall surged 4,151 percent in the months after ChatGPT’s public launch, according to Adaptive Security’s analysis reported via Barracuda’s 2025 threat research. Cheaper tools do not just mean more fake messages and calls landing in your inbox. They mean sharper ones, harder to catch on sight, arriving in far greater volume than before.
The same pattern shows up constantly in Indian inboxes and WhatsApp groups, a fake courier delivery text here, a cloned bank login page there, each one built on the same underlying trick this section unpacks module by module.
Understanding the mechanism behind each format matters more than memorising a list of warning signs, since the formats keep changing while the underlying trick barely does. A scam that arrived as an email five years ago now just as easily arrives as a QR code sticker or a thirty-second video call.
Treat every unexpected message, call, code, or video as unverified by default, whatever format fake messages and calls happen to be wearing that day, until you have checked it through a channel of your own choosing.
How Do Phishing, Smishing and Vishing Messages Trick You?
Phishing arrives by email, smishing by text message, and vishing by phone call, three delivery methods for the same underlying move: a message designed to look like it came from your bank, a courier service, or someone you trust.
In November 2025, Google filed a lawsuit alleging a China-based network built nearly 200,000 fraudulent websites in just 20 days, impersonating brands including Google and USPS through SMS lures designed to harvest payment card details from anyone who clicked.
Vishing, the voice-call version, surged 442 percent from the first half of 2024 to the second, according to the Anti-Phishing Working Group’s tracking, making it the fastest-growing of the three formats.
Credential harvesting pages sit behind most of these links, cloned login screens built purely to capture a username and password the moment they are typed in, whether the lure arrived by email, text, or a QR code stuck over a genuine one.
The warning signs stay fairly consistent across all three formats: unexpected urgency, a sender address that looks close but not quite right, and a request to click, call back, or read out a code you were never asked for before. Verifying the sender independently, through a number or website you already had rather than one supplied in the message, settles it in under a minute.
Read the full guide: Phishing, Smishing and Vishing: How to Spot Every Type of Fake Message

How Do Fake Websites and Lookalike Stores Steal Your Payment Details?
A cloned website copies a real retailer’s logo, layout, and checkout page closely enough that the fake becomes almost impossible to spot at a glance, right down to matching product photos and a working search bar.
The padlock icon and “https” in the address bar do not help either. 83 percent of phishing sites now use HTTPS encryption too, according to the UK National Cyber Security Centre’s 2025 phishing trends data, which means the lock tells you the connection is encrypted, not that the seller behind it is genuine.
Domain names are the real giveaway most people skip checking, a single swapped letter, an extra word, or a different ending entirely being the only difference between the genuine site and the copy built to steal from you, a trick known as typosquatting.
Lookalike apps carry the same risk on official app stores too, sometimes appearing above the genuine app in search results, using a near-identical icon and a handful of fake five-star reviews to look established.
Three checks catch most of this before you pay: type the retailer’s address directly rather than clicking a link, check the domain letter by letter, and search the app publisher’s name independently before installing anything.
Read the full guide: That Website Looks Real, But It Isn’t. How to Check Before You Buy

Why Is That QR Code on the Wall Not as Safe as It Looks?
A QR code on a parking meter, a restaurant table, or an EV charger feels like part of the furniture, which is exactly why a sticker placed over the real one so rarely gets noticed.
Quishing, QR code phishing, increased 587 percent through 2024 and kept climbing into 2025, with parking payment and package delivery codes among the most common lures, according to the FBI’s Internet Crime Complaint Center.
Codes on public transport and lamppost stickers carry the same risk, since anyone can print and stick a replacement code in seconds, turning an ordinary physical space into a digital attack surface without a single wire touched.
Unlike a phishing email, a QR code is a physical object that can be physically swapped. The code standing on a wall today is not necessarily the one that was there yesterday, and there is rarely any way to tell just by looking.
Scanning safely means checking the code is not a sticker layered over another one, and reading the destination web address before it fully loads rather than trusting the scan blindly.
Read the full guide: QR Code Scams: Why That Code on the Wall Could Be Dangerous

Can You Still Trust What You See or Hear Online?
A finance employee at Arup, a global engineering firm, joined a video call in Hong Kong with what appeared to be the company’s CFO and several colleagues. He transferred HK$200 million, roughly ₹211 crore, across 15 payments. Every person on that call was an AI-generated deepfake.
Deepfake-driven fraud caused 1.65 billion dollars in losses worldwide in 2025, with fake investment videos of celebrities and officials accounting for the largest single share, according to Surfshark’s analysis of AI Incident Database and Resemble AI data.
Cloned voices are used just as often as cloned video, a few seconds of someone’s real voice, pulled from a social media clip, is enough for modern tools to generate a convincing call demanding urgent payment.
Forged documents follow the same logic, a fake PDF invoice or ID document that looks correctly formatted enough to pass a glance, which is precisely why a glance is no longer a sufficient check for anything important.
Verification through a separate channel the caller does not control, phoning the person back on a number you already had rather than one given to you during the call, is no longer optional against fake messages and calls built this convincingly.
Read the full guide: Deepfakes and AI Deception: When You Can’t Trust What You See or Hear

How Do You Tell Real News From Fake News?
Content built to make you feel outrage, fear, or disbelief spreads roughly six times faster than the factual correction that eventually follows it, according to MIT Media Lab research cited in the Reuters Institute’s Digital News Report 2025.
Algorithmically amplified misinformation reached an estimated 1.5 billion people globally across 2024 and 2025, meaning most people encountering false content never see the correction reach them at all.
News, misleading framing of a true event, and pure opinion sit on the same spectrum, and a single sensational headline can slide between all three without a reader noticing the shift.
Evaluating the source behind a claim, rather than judging a single post in isolation, catches most of what a fact-check alone would miss, especially when the same account posts consistently one-sided coverage.
The strongest signal that something might be misleading is often how urgently it makes you want to share it. That urge, more than any single fact-check, is worth pausing on before you forward anything to a family group.
Read the full guide: How to Tell Real News From Fake, A Practical Media Literacy Guide

How Do You Verify Who You’re Really Dealing With Online?
A caller poses as an internal employee, a doctor, or a financial advisor, confident and specific enough that the fabrication is rarely questioned until real money or real medical decisions are already on the line.
Attacks on M&S, Co-op, and Harrods in 2025, attributed to the group known as Scattered Spider, succeeded through exactly this kind of impersonation, callers convincing staff to reset credentials, rather than through any technical hacking at all.
Spoofed caller ID adds another layer, a screen showing a trusted name or a “verified” badge that was never actually checked or issued by anyone with the authority to do so.
A fabricated credential can be built in minutes. A genuine professional can usually be verified in about the same amount of time, through the licensing body or organisation’s own official contact details rather than the number the caller provides.
Read the full guide: Fake Doctors, Lawyers and Experts: How to Verify Who You’re Dealing With

Frequently Asked Questions
How can I tell if a text message is actually a phishing scam?
Check the sender number or address carefully, since it is often close to genuine but not exact. Be wary of any urgent request to click a link, confirm a code, or update payment details, and verify independently through your bank’s official app or number rather than anything in the message itself.
Is it safe to scan any QR code I find in a public place?
Not automatically. Look closely for a sticker layered over another code, and check the web address that appears before it fully loads. If the code sits somewhere a scammer could easily reach, a parking meter or a random flyer, treat it with the same caution as an unexpected link.
How do I know if a video or voice call is a deepfake?
Perfect video and audio quality is no longer proof of anything. If a call involves an urgent request for money or sensitive information, hang up and call the person back on a number you already had, rather than continuing the conversation on the original call.
What Every One of These Deception Tactics Comes Down To
Six formats, one repeating lesson: fake messages and calls survive on speed, not sophistication, and the pause you take before acting is what actually breaks them.
Whether it’s a text, a cloned website, a QR code, a deepfake call, a viral post, or a confident stranger claiming a credential, the same habit protects you every time: stop, verify independently, and never through a channel the other person controls.
Report anything you encounter through India’s National Cyber Crime Reporting Portal or the 1930 helpline, even when nothing was lost, since every report helps build the pattern recognition that gets fraudulent domains and numbers shut down faster.
Start with the module closest to what you’ve actually encountered recently, a suspicious text, an unfamiliar QR code, a call that didn’t sound quite right, and work outward from there.
If this was useful, share it with someone who needs to know.