1. BANKING SECURELY ONLINE
-
(a) Use the Virtual Keypad to enter your Login Password and Debit Card
PIN
-
(b) Change your Login Password and Transaction Password on your first
login
-
(c) Change your Password frequently or at least once a month, using
the Change Password option
-
(d) Destroy the Password after memorizing it, do not write it down or
store it anywhere
-
(e) Don't disclose your Password to anyone; it is personal and
confidential
-
(f) Choose Passwords that are difficult for others to guess. Do not
select an easy-to-guess Password, like date of birth, telephone number
or sequential numbers such as 111111, 12356, etc.
-
(g) “Use both letters and numbers and a combination of lower case and
capital letters in your Passwords
-
(h) Always log out of our Net Banking platforms - IndusNet,
IndusDirect, Connect Online, Indus Speed Remit and Indus Collect after
using the service or when you are going to be away from your PC. For
security reasons, your login sessions will be terminated if your
browser is left idle for a while
-
(i) We shall not be responsible for wrong transactions or disclosure
of details by you. Viewing and transacting options online are
different. Please exercise your option diligently
-
(j) Kindly have necessary security related tools (eg.
Anti-Virus/Firewall) in place on your business servers, devices and
associated infrastructure
-
(k) Payment processing using APIs provided by us should be done
through secured and authorized devices, personnel, servers and
associated infrastructure
2. SECURING BANKING ON THE MOVE
-
(a) Download IndusInd Bank’s Mobile Banking App (including IndusDirect
Corporate Mobile Banking App) from Google Play Store/ Apple App Store
only
-
(b) Before downloading, confirm that the app has been developed by
IndusInd Bank Ltd.
-
(c) Avoid installing apps that ask for more permissions than necessary
-
(d) Install and use a reputed AntiVirus as well as a Mobile Protection
App on your mobile
-
(e) Do not root or jail-break the device. It discards all the security
controls on your device
-
(f) Use a screen inactivity lock in conjunction with a pass code /
pattern / fingerprint / face recognition unlock
-
(g) Do not store passwords or any other sensitive information on your
mobile
-
(h) Avoid clicking on the links received via social media, without
verifying the source
3. STAYING AWAY FROM SUSPICIOUS COMMUNICATION
EMAILS
-
(a) Please beware of suspicious emails that invite you into revealing
sensitive information, such as Login ID, Passwords, and other
confidential account information
-
(b) Such emails may also lead you to a fake website that looks very
similar to the Bank's genuine website, or could request you to update
your banking information
-
(c) The Bank does not issue such emails and you are advised to ignore
them, and not respond to any requests for personal information
-
(d) Please report such suspicious emails immediately to
report.phishing@indusind.com
-
(e) Watch out for scam emails. They may invite you into downloading a
virus or clicking through to a fraudulent website in order to elicit
confidential information
-
(f) Make sure that the websites you transact on, have privacy and
security statements and review them carefully
-
(g) Verify that the website address (URL) is www.indusind.com, or type
the URL yourself
-
(h) Do not log into IndusNet, IndusDirect, Connect Online, Indus Speed
Remit and IndusCollect through hyperlinks embedded in the emails or on
third party websites
-
(i) Do not reply to any email that requests your personal information.
Do not disclose your Passwords
-
(j) Do not open an email with an attachment, in case you suspect the
sender
-
(k) Look for the padlock symbol at the bottom right of a web page to
ensure that the site is running in secure mode before you enter
sensitive information
-
(l) Do not keep computers online when not in use. Either shut them off
or physically disconnect them from your internet connection
- (m) Immediately report any irregularities
-
(n) Keep your Personal Computer updated by downloading security
patches and also update your anti-virus & firewall software on a
regular basis
-
(o) Do crosscheck your last login information regularly to monitor
your sessions
PHONE CALLS/SMS
-
(a) Fraudsters may ask for your details through a phone call or a text
message
-
(b) You may also be requested to call a particular number, and to
reveal or key in confidential details on an interactive voice response
system, under the pretext of verifying your Credit Card information.
-
(c) Do not respond to messages asking you for confidential information
-
(d) Do not call any given or unknown numbers, it may be a phishing
-
(e) Contact the Bank immediately in case you receive such messages or
phone calls that look suspicious and fishy
STAY SAFE FROM DOMAIN FRAUD
The first step to avoiding domain fraud is to understand the scam.
Domain fraud is the process of creating and using unethical domain names
of reputed brands to redirect users or businesses to make financial
transactions. Cybercriminals impersonate trusted brand names to launch
some of the following attacks:
- (a) Wire transfer fraud
- (b) Phishing
- (c) Counterfeit good sales
- (d) Session stealing
THINGS WE WILL NEVER ASK FOR
- (a) PIN (Personal Identification Number)
- (b) OTP (One-time Password)
- (c) CVV (Card Verification Value)
- (d) Card Expiry Date
-
(e) Your Net Banking/Mobile Banking Login ID,Transaction Password, OTP
or MPIN (for Mobile Banking)
4. Make Digital Payments Safe and Seamless
DO'S
-
(a) Be alert to fraudulent calls (Vishing) that ask you to download
third-party apps or share confidential information (disconnect such
calls immediately)
-
(b) In case you have already downloaded any remote access app and it
is no longer required, uninstall it immediately
-
(c) Enable app-lock on your payments or mobile banking-related apps
-
(d) Report any suspicious activity at your nearest bank
branch/authorised customer care number only
-
(e) Validate Transaction Type before transacting through UPI, there is
one standard rule – No PIN required for receiving money through UPI
-
(f) Beware of Fraudulent/counterfeit applications while transacting
through UPI, prefer using trusted applications for UPI transactions
- (g) Keep your details updated with your Bank
-
(h) Alert your bank immediately in case you experience any unusual
transaction
DON'TS
-
(a) Never share your UPI PIN, CVV & OTP with anyone over
Call/SMS/Email even if claiming to be from the Bank
- (b) Never store Banking passwords in your mobile handset
-
(c) Be cautious of money requests from unknown senders as accepting an
UPI money request is a debit to your account. Only accept requests
from known senders and verified merchants
-
(d) Do not forward any unsolicited SMS received on a request of the
so-called Bank representative
- (e) Never give permissions/access to unknown apps
-
(f) Never open untrusted SMS/Emails with links redirecting to UPI
payment