Skip to main content
Cyber awareness command center

CyberShield Keralam

Stay Secure. Stay Aware. Stay One Step Ahead.

All systems nominal

Scroll to power up the engine
0x01~/engine

Anatomy of a defence engine

Nothing protects you on its own. Security works in layers, each one covering what the last one misses. Scroll to assemble the machine — every ring that locks into place is a real control you can switch on today.

Standby01 / 06

Spin up

Attention

0%

Assembly

A diagram of layered security controls. Six layers assemble as you scroll: attention, identity, encryption, firewall, monitoring, and awareness. Each layer is described in the list that follows.

  1. 01

    Attention

    Spin up

    Every attack starts with a message you did not expect. Slowing down for three seconds before you tap is the cheapest control there is.

  2. 02

    Identity

    Tumblers engaged

    A long unique password on every account, plus two-factor authentication. Even a stolen password stops being useful the moment a second factor is required.

  3. 03

    Encryption

    Key exchange

    Look for the lock and the correct spelling of the domain before you type anything. Encrypt your backups and your phone, so a lost device is an inconvenience and not a breach.

  4. 04

    Firewall and updates

    Barrier closed

    Keep the built-in firewall on and install updates the week they arrive. Most successful attacks use a hole that was patched months earlier.

  5. 05

    Monitoring

    Traces live

    Turn on transaction alerts and actually read them. Fraud is survivable when it is caught in minutes; it is expensive when it is caught in a monthly statement.

  6. 06

    Awareness

    Core sealed

    The innermost layer is you. Tools stop the automated attacks; only a person who knows the pattern stops the one written specifically for them.

0x02~/threats

Cyber Threat Encyclopedia

Nineteen attacks that are actively used against people in Kerala right now. Open any card to see how it works, what it looks like from the inside, and exactly what to do if it reaches you.

19 threats shown

0x03~/simulator

Scam simulator

Eight real attack patterns, rebuilt as safe mock-ups. Tap anything that looks wrong. Nothing here is a real link, a real brand or a real form — the messages are inert text, so you can click with complete freedom.

Inbox
Safe simulation

The KYC expiry email

An email says your bank account will be frozen tonight unless you re-verify. Three things give it away.

Tap every part that looks suspicious

Found
0 / 3
Wrong taps
0
01 / 08
0x04~/learn

Terminal learning mode

A shell that only teaches. Type a topic and press Enter — or start with help. Nothing is executed and nothing leaves your browser; the prompt is a lesson index wearing a command line.

guest@cybershield

CyberShield Keralam — training shell v1.0. No commands are executed.

Type help to list the lessons.

Try

Type a command and press Enter

0x05~/password

Build a password worth the lock

Type anything below and watch the vault respond. The meter estimates how long a rented cracking rig would need to guess it — and every character you type stays inside this browser tab.

Vault offline

StrengthWaiting for input
Time to crack

Assuming an offline attack at 100 billion guesses a second against a fast hash.

Entropy
0 bits

Every extra bit doubles the work an attacker has to do.

Character pool
0

How many different characters your password draws from.

Character classes

  • Lowercase
  • Uppercase
  • Numbers
  • Symbols
  • Non-English

How to improve it

The vault is waiting. Type a password — or generate one — to bring it online.

Four random words are easier to remember than one mangled word — and far harder to crack.

This never leaves your device

There is no network request, no storage and no logging behind this field. The check runs as ordinary JavaScript on your own machine. Even so — never type a password you actually use into any website that asks for it, including this one.

Length beats complexity

A sixteen-character phrase of ordinary words outlasts an eight-character mess of symbols. Attack tools expand P@ssw0rd! instantly; they cannot brute-force four unrelated words.

Never reuse one twice

Breaches are traded in bulk. The moment one shopping site leaks your password, attackers replay it against your email and bank — this is called credential stuffing, and it is the single most common way accounts fall.

Let a manager remember them

You cannot memorise sixty unique passwords, and you should not try. A password manager stores them encrypted; you remember one long master phrase. Then switch on two-factor authentication where it is offered.

0x06~/hygiene

Ten habits, one shield

Security is not a purchase, it is a set of small habits. Tick each one you already do and watch the shield close around you — the list is stored only in this browser, and nothing is sent anywhere.

Shield integrity

Exposed — nothing between you and the next attempt

0 layers active

0x07~/kerala

Kerala on the front line

High smartphone penetration, near-universal UPI and a strongly bilingual population make Kerala a specific target, not a generic one. These are the scripts in local circulation — read them in the language they arrive in.

Every message below is a reconstruction. The numbers, names and links are invented and nothing here is clickable.

  • UPI 'wrong transfer' refund

    01

    A stranger claims to have sent money to your number by mistake and pleads for it back. Often a small real amount does arrive first — from an account that was itself stolen, which later makes you a link in the fraud chain.

    As it arrivesമലയാളം

    ചേട്ടാ ക്ഷമിക്കണം, ഞാൻ അബദ്ധത്തിൽ 8,500 രൂപ നിങ്ങളുടെ നമ്പറിലേക്ക് അയച്ചുപോയി. എന്റെ മോളുടെ ഫീസ് അടയ്ക്കാനുള്ളതാ. ദയവായി ഈ നമ്പറിലേക്ക് തിരിച്ചയക്കണേ 🙏

    What it says

    "Sorry brother, I accidentally sent ₹8,500 to your number. It was for my daughter's fees. Please send it back to this number."

    The giveaway

    A genuine wrong transfer is reversed by the bank, not by you. Refer them to their bank and do not send anything from your own account.

  • KSEB disconnection notice

    02

    A late-evening SMS threatens to cut your power over an unpaid bill and supplies a mobile number for an 'officer'. The call ends with a remote-access app installed on your phone.

    As it arrivesമലയാളം

    പ്രിയ ഉപഭോക്താവേ, നിങ്ങളുടെ വൈദ്യുതി കണക്ഷൻ ഇന്ന് രാത്രി 9.30-ന് വിച്ഛേദിക്കപ്പെടും. കഴിഞ്ഞ മാസത്തെ ബിൽ അപ്ഡേറ്റ് ആയിട്ടില്ല. ഉടൻ ബന്ധപ്പെടുക: 8x9xxxxxx4 -KSEB

    What it says

    "Dear consumer, your electricity connection will be disconnected tonight at 9:30. Last month's bill has not been updated. Contact immediately: 8x9xxxxxx4 -KSEB"

    The giveaway

    KSEB does not send disconnection notices from a personal ten-digit mobile number, and never at night. Check your bill in the official app instead.

  • Police and 'digital arrest'

    03

    Someone in uniform on a video call says a case has been registered in your name and that you must remain on the call and transfer your balance for verification. The uniform, the desk and the file are all staging.

    As it arrivesമലയാളം

    നിങ്ങളുടെ ആധാർ ഉപയോഗിച്ച് മുംബൈയിൽ ഒരു പാർസൽ പിടിച്ചെടുത്തിട്ടുണ്ട്. CBI കേസ് നമ്പർ 4471/2025. ഈ കോൾ കട്ട് ചെയ്യരുത്, ആരോടും പറയരുത്. വെരിഫിക്കേഷനായി പണം അയക്കുക.

    What it says

    "A parcel using your Aadhaar has been seized in Mumbai. CBI case number 4471/2025. Do not disconnect this call, do not tell anyone. Send money for verification."

    The giveaway

    There is no such thing as a digital arrest. No police force in India investigates by video call or takes money to establish innocence. Hang up and call 1930.

  • The customs-duty parcel

    04

    A message says a parcel addressed to you is held for a small customs fee. The fee is trivial by design — it exists to capture your card details on the payment page that follows.

    As it arrivesമലയാളം

    നിങ്ങളുടെ പാർസൽ കസ്റ്റംസിൽ തടഞ്ഞുവച്ചിരിക്കുന്നു. 48 രൂപ ഡ്യൂട്ടി അടച്ച് ഡെലിവറി ഉറപ്പാക്കുക: kerala-parcel-pay.in/track

    What it says

    "Your parcel is held at customs. Pay ₹48 duty to confirm delivery: kerala-parcel-pay.in/track"

    The giveaway

    The amount is too small to be worth a scam — which is exactly the trick. You are paying with your card number, not with ₹48.

  • Gulf job and visa fees

    05

    An agent offers a confirmed overseas job and asks for staged payments — registration, medical, visa stamping. Each stage is real-sounding and each payment is final.

    As it arrivesമലയാളം

    സൂപ്പർമാർക്കറ്റ് സ്റ്റാഫ് വേക്കൻസി - ദുബായ്. ശമ്പളം 2500 ദിർഹം + താമസം. വിസ ഉറപ്പ്. രജിസ്ട്രേഷൻ ഫീസ് 15,000 രൂപ ഇന്ന് അടച്ചാൽ സീറ്റ് ഉറപ്പിക്കാം. ഇന്റർവ്യൂ ഇല്ല.

    What it says

    "Supermarket staff vacancy – Dubai. Salary 2500 dirhams + accommodation. Visa guaranteed. Pay ₹15,000 registration today to confirm your seat. No interview."

    The giveaway

    A guaranteed visa with no interview does not exist. Check the recruiter against the eMigrate registry, and never pay before a verified offer letter.

  • The hijacked family account

    06

    A message from a relative's real account asks for urgent money. The account was taken over by tricking them into forwarding a six-digit registration code, so the name and photo are genuine.

    As it arrivesമലയാളം

    മോനേ അത്യാവശ്യമായി 20,000 രൂപ വേണം. എന്റെ ഫോൺ പ്രശ്നത്തിലാണ്, വിളിക്കാൻ പറ്റില്ല. ഈ നമ്പറിലേക്ക് ഗൂഗിൾ പേ ചെയ്യൂ, നാളെ തിരിച്ചുതരാം.

    What it says

    "Son, I urgently need ₹20,000. My phone is having trouble, I cannot call. Google Pay it to this number, I will return it tomorrow."

    The giveaway

    The excuse for not talking is the scam. Call the person on their saved number — if the account is genuinely theirs, they will answer.

  • Instant loan apps

    07

    An app approves a small loan in minutes, then demands repayment at impossible interest. Having taken your contacts and gallery at install time, it threatens to send morphed images to everyone you know.

    As it arrivesമലയാളം

    അഭിനന്ദനങ്ങൾ! നിങ്ങൾക്ക് 25,000 രൂപ വരെ വായ്പ അനുവദിച്ചിരിക്കുന്നു. രേഖകൾ വേണ്ട, CIBIL നോക്കില്ല. 5 മിനിറ്റിൽ അക്കൗണ്ടിൽ. ആപ്പ് ഡൗൺലോഡ് ചെയ്യൂ ↓

    What it says

    "Congratulations! A loan of up to ₹25,000 has been approved. No documents, no CIBIL check. In your account in 5 minutes. Download the app ↓"

    The giveaway

    No documents and no credit check means the lender is not regulated. Check the RBI register, and never grant a loan app access to contacts or photos.

  • Lottery and KYC combined

    08

    A message congratulates you on a prize and then requires a processing fee and 'KYC verification' to release it. The prize is imaginary; the fee and the documents are real.

    As it arrivesമലയാളം

    അഭിനന്ദനങ്ങൾ! നിങ്ങളുടെ നമ്പർ 10 ലക്ഷം രൂപയുടെ ബമ്പർ സമ്മാനത്തിന് അർഹമായി. തുക ലഭിക്കാൻ ആധാർ, ബാങ്ക് വിവരങ്ങൾ, 4,999 രൂപ പ്രോസസിംഗ് ഫീസ് എന്നിവ അയക്കുക.

    What it says

    "Congratulations! Your number has won a bumper prize of ₹10 lakh. To receive it, send your Aadhaar, bank details and a processing fee of ₹4,999."

    The giveaway

    You cannot win a lottery you never entered, and a genuine prize is never released against an advance fee. This one harvests your identity as well as your money.

0x08~/quiz

Prove it

Five tracks, five questions each. Pick the one that fits you — every answer comes with the reasoning, so a wrong choice is worth as much as a right one.

Choose a track

0x09~/timeline

How we got here

Fifty years of attacks, each one changing what came next. Scroll through — the pattern is that every advance in convenience arrived with a matching advance in exploitation.

  1. 1971First self-replicating program

    Creeper

    An experiment on ARPANET that copied itself between machines and printed a message. It was not malicious, and a second program named Reaper was written to remove it — the first antivirus.

    Why it still matters

    Self-replication was proved possible before anyone thought to defend against it. Security has been catching up with capability ever since.

  2. 1988First internet-scale incident

    The Morris Worm

    A graduate student's worm, intended to measure the size of the internet, reinfected machines faster than it should have and disabled a significant share of the network within hours.

    Why it still matters

    It produced the first computer-crime conviction under US law and led directly to the creation of the first coordinated incident response team.

  3. 2000Social engineering at scale

    ILOVEYOU

    An email attachment named as a love letter spread to tens of millions of machines in days by mailing itself to every contact in the victim's address book.

    Why it still matters

    It proved the decisive vulnerability was curiosity, not code. Every phishing email since has been built on that finding.

  4. 2007Crime becomes an industry

    Zeus and banking trojans

    Malware built specifically to sit inside a browser and alter banking sessions as they happened. It was sold as a toolkit, so the operator no longer needed to be the author.

    Why it still matters

    It separated skill from crime. Today a person with no technical ability can rent everything needed to run an attack.

  5. 2010Software damages hardware

    Stuxnet

    Malware that crossed an air gap on removable media and altered the speed of industrial centrifuges while reporting normal readings to their operators.

    Why it still matters

    The first widely documented case of code causing physical destruction — and the reason an unknown USB device is treated as a weapon.

  6. 2013Ransomware finds its business model

    CryptoLocker

    Strong public-key encryption combined with anonymous payment. Files could be locked with a key the victim could never derive, and the ransom could be collected without a bank account.

    Why it still matters

    It made extortion scalable, and it is why an offline backup is now the single most valuable thing you can keep.

  7. 2017Unpatched systems, worldwide

    WannaCry & NotPetya

    Two outbreaks used a leaked exploit to spread without any human action, reaching hospitals, ports and factories across more than a hundred countries. A patch had been available for months.

    Why it still matters

    The clearest demonstration that delayed updates are the vulnerability. Both outbreaks were preventable by a patch already released.

  8. 2020Attacking the update itself

    Supply-chain compromise

    Attackers began inserting malicious code into trusted software before it shipped, so the compromise arrived through a signed, legitimate update installed by careful administrators.

    Why it still matters

    It broke the assumption that a signed update is safe, and moved the industry towards verifying what software is actually made of.

  9. 2022Theft becomes irreversible

    Cross-chain and exchange thefts

    Bridges and exchanges holding very large balances were drained through flaws in the code that moved assets between networks. There was no clearing house to reverse the transfers.

    Why it still matters

    It showed what a payment system without reversal really means — the same reason a UPI transfer you authorise yourself is so hard to recover.

  10. 2023→Forgery without skill

    AI-assisted fraud and deepfakes

    Generative tools removed the two things that used to expose a scam: bad language and the impossibility of faking a familiar face or voice. A few seconds of public audio is now enough to clone someone.

    Why it still matters

    Spotting a scam by its spelling no longer works. Verification has to move to the channel — call back on a number you already had.

0x0A~/telemetry

Fraud response console

A visual model of how a single fraud unfolds and why the first hour decides the outcome. Read it as a diagram, not as a dashboard — every value below is illustrative.

These numbers are illustrativeDemonstration data

This console is not connected to any live feed and does not measure anything. The values are chosen to show the shape of the problem — how sharply recovery falls away with time, and where losses actually begin. For official statistics, consult the National Crime Records Bureau and the I4C reports published by the Ministry of Home Affairs.

The recovery window

How much of a transferred amount can still be frozen, by the time you report it.

Within 1 hour

0%

still recoverable

Within 6 hours

0%

still recoverable

Within 24 hours

0%

still recoverable

After 3 days

0%

still recoverable

Where it starts

Almost nothing begins with a technical exploit. It begins with a message.

  • Messages and calls41%
  • Payment requests27%
  • Fake apps and sites18%
  • Malware on the device9%
  • Technical exploits5%

of reported cases · Demonstration data

Why layers compound

Each control removes a share of what the previous one let through.

  • No controls100% still getting through
  • + Strong unique password62% still getting through
  • + Two-factor authentication29% still getting through
  • + Updates installed14% still getting through
  • + A person who checks3% still getting through

Control status

The five settings that decide most outcomes. Switch them on today.

  • critical

    Two-factor authentication

  • critical

    Automatic updates

  • high

    Offline backup

  • high

    Daily UPI limit

  • medium

    Transaction alerts

0x0B~/news

Advisory board

Attack patterns currently in circulation, grouped by where they are being seen. These are standing advisories written to stay accurate — not a live news feed and not dated reporting.

Not a live feedFor breaking incidents and official notices, follow CERT-In advisories and the Kerala Police cyber wing. This board covers the patterns that persist between headlines.

12 advisories
  • SevereKerala

    'Digital arrest' calls targeting older residents

    Callers posing as police, CBI or customs officers keep victims on a video call for hours, claiming a parcel or a bank account in their name is under investigation, and demand transfers to a 'verification account'.

    What to do

    There is no lawful process called a digital arrest. Disconnect and call 1930. Tell every older relative this specific sentence.

  • ElevatedKerala

    Electricity and water disconnection texts

    Late-evening SMS messages claim a utility connection will be cut within the hour over an unpaid bill, and supply a mobile number. The call that follows ends with a remote-access app on the victim's phone.

    What to do

    Utilities do not send disconnection notices from personal mobile numbers. Check your bill in the official app and never install an app a caller asks for.

  • SevereIndia

    Task-based investment scams on messaging apps

    Groups offer small payments for simple online tasks, honour the first few withdrawals to establish trust, then require escalating deposits to 'unlock' higher tiers. Withdrawal is blocked behind an unending sequence of fees.

    What to do

    A job that requires a deposit is not a job. Stop paying at the first fee — further payments never release the balance.

  • SevereIndia

    APK files shared as invitations and receipts

    Android install files are circulated in group chats disguised as wedding invitations, delivery receipts or utility bills. Once installed they request SMS and accessibility permissions and can then read OTPs and operate banking apps.

    What to do

    Never open an .apk received in a chat, even from a known contact. Turn off installation from unknown sources.

  • ElevatedBreaches

    Reused passwords replayed after unrelated breaches

    Credential lists from breached shopping, gaming and forum sites are traded in bulk and replayed automatically against email and banking providers. The password is already correct somewhere, so nothing is being guessed.

    What to do

    Give every account its own password and switch on two-factor authentication. Check your addresses on a breach-notification service.

  • ElevatedGlobal

    Info-stealers bundled with cracked software

    Pirated installers and 'activator' tools ship malware that harvests saved browser passwords, session cookies and cryptocurrency wallets in a single pass. Stolen session cookies let an attacker skip the login entirely.

    What to do

    Do not run cracked software on a device you also bank on. If you already have, change passwords from a clean device and sign out all sessions.

  • WatchScam alerts

    Tampered QR codes on shop counters and parking meters

    Printed stickers are pasted over genuine payment codes so that money reaches the attacker instead of the merchant. Neither the customer nor the shopkeeper notices until the takings are reconciled.

    What to do

    Read the payee name on the confirmation screen before approving. Shopkeepers should check their code daily.

  • SevereScam alerts

    Predatory instant-loan apps and blackmail

    Unregulated apps approve small loans in minutes, then demand repayment at impossible rates. Having taken contact and gallery permissions at install, recovery agents threaten to send morphed images to the borrower's contacts.

    What to do

    Borrow only from RBI-regulated lenders. If you are being blackmailed, this is a crime against you — report at cybercrime.gov.in and do not keep paying.

  • ElevatedEmerging

    Voice cloning in family emergency calls

    A few seconds of audio taken from a public social media video is enough to synthesise a convincing voice. Calls are kept short and the line is made deliberately poor so small imperfections pass unnoticed.

    What to do

    Agree a family safe-word now, while nothing is wrong. Always hang up and call back on the saved number.

  • ElevatedEmerging

    Phishing kits that defeat SMS and app codes

    Adversary-in-the-middle kits proxy the real login page in real time, so the code you enter is forwarded and used within seconds — and the session cookie is stolen alongside it, letting the attacker stay logged in.

    What to do

    Where offered, move to passkeys or a hardware security key. Both are bound to the site's real address and cannot be relayed to a look-alike.

  • WatchGlobal

    Fake subscription renewal notices

    Emails claiming a streaming or cloud-storage subscription failed to renew lead to a convincing payment page. The amount is small and familiar, which is what stops people looking closely at the address.

    What to do

    Check subscriptions inside the app or your account settings. Never renew through a link in an email.

  • SevereBreaches

    SIM swaps following data leaks

    Leaked identity documents are used to request replacement SIMs. The victim's phone loses service — usually overnight — and every OTP then arrives on the attacker's device instead.

    What to do

    Treat a sudden lasting loss of network as an emergency. Contact your operator immediately and prefer an authenticator app over SMS codes.

0x0C~/emergency

You have been scammed. Do this now.

Speed decides how much you get back. Money moves through mule accounts within minutes, and a bank can only freeze what has not yet been withdrawn. Work down this list in order — do not stop to feel foolish, everybody gets caught eventually.

The first hour matters most

Report an unauthorised transaction to your bank within three working days and your liability is limited under RBI rules. Report it within the first hour and there is a real chance the transfer is still sitting in an account that can be frozen.

1930Call now

Response sequence

  1. 01

    Call 1930 immediately

    The national cyber-fraud helpline runs 24 hours and can trigger a freeze on the receiving account. Call before you do anything else — before you check your balance, before you tell anyone.

  2. 02

    Tell your bank in writing

    Phone the number printed on your card, then follow up by email or the in-app complaint form so there is a timestamp. Ask them to block the card, stop the beneficiary and register a dispute. Note the complaint reference.

  3. 03

    File at cybercrime.gov.in

    The National Cyber Crime Reporting Portal takes financial-fraud complaints directly and routes them to the right police unit. You can file without visiting a station. Keep the acknowledgement number safe.

  4. 04

    Preserve every scrap of evidence

    Screenshot the messages, the transaction page, the caller ID and the UPI reference before anything auto-deletes. Do not delete the conversation, however much you want to. Export the chat if you can.

  5. 05

    Cut the attacker's access

    Uninstall any app they asked you to install, put the phone in aeroplane mode and restart it. If you granted screen sharing or accessibility permission, assume everything on that device was seen.

  6. 06

    Change passwords from a clean device

    Start with email, because every other reset runs through it. Then banking, then anything sharing that password. Switch on two-factor authentication as you go, and sign out all other sessions.

  7. 07

    Warn the people around you

    Scammers reuse a working script on your contacts, and a compromised account is used to vouch for the next message. Tell your family and your workplace what happened — plainly, without embarrassment.

Official channels

  • Cyber Crime Helpline

    1930

    National, toll free, 24x7. Financial fraud goes here first.

    Call now
  • National Cyber Crime Reporting Portal

    cybercrime.gov.in

    File the formal complaint here, including anonymously for content offences.

    Open the site
  • Kerala Police

    112

    Emergency response number for any immediate threat to safety.

    Call now
  • Women & child helpline

    1098 / 181

    For online harassment, blackmail or image-based abuse.

    Call now

Do not do these

  • Do not pay anyone who promises to recover your money for a fee. Recovery scams target people who have already been scammed once.

  • Do not delete the messages, the app or the call log. That is the evidence your complaint rests on.

  • Do not search for a helpline number and call whatever appears first. Fake support numbers are planted exactly where victims look.

  • Do not wait until morning because you feel ashamed. Every hour lowers the amount that can still be frozen.

0x0D~/resources

Resources

Official channels worth bookmarking, and the parts of this site worth returning to. Search in either language, or filter by what you need.

This site offers no downloads on purpose. A page teaching you not to open unexpected files should not be handing you any.

Common questions

0x0E~/about

What this is

An open cyber-awareness resource for Kerala, in English and Malayalam. Free to use, free to share, and built to be handed to someone who has just been targeted.

Why it exists

Kerala has near-universal smartphone use and one of the highest rates of digital payment adoption in India. That convenience arrived faster than the awareness needed to use it safely, and the gap is where fraud lives. Most people who lose money are not careless — they are simply meeting a well-rehearsed script for the first time, usually while distracted and under time pressure. Seeing the script once, calmly, in advance, is what changes the outcome.

Who it is for

  • Schools and colleges running awareness sessions
  • Police and local-body outreach programmes
  • Workplaces briefing staff on fraud and phishing
  • Anyone explaining this to a parent or grandparent

How it is built

  • Bilingual by construction

    Every visible string exists as an English–Malayalam pair in the source. There is no separate translation file to fall behind, and the project will not compile if either half is missing.

  • Accessible on purpose

    Reduced motion, high contrast and sound are real settings, not decoration. Zoom is never blocked, every animation has a text equivalent, and the whole site works by keyboard.

  • Nothing is collected

    No analytics, no tracking, no accounts, no cookies for measurement. The password checker and the hygiene checklist run entirely in your browser, and neither sends anything anywhere.

  • Every simulation is inert

    The scam mock-ups contain no real links, no real brands and no working forms. The terminal executes nothing. There are no downloads anywhere on this site, deliberately.

What this is not

  • Not a government website, and not affiliated with any bank, police force or agency. Official channels are listed in the resources section and linked directly.

  • Not legal or financial advice. If money has been lost, the people who can actually act are your bank, 1930 and the police.

  • Not a live news or statistics service. The advisory board carries standing patterns, and every figure in the telemetry console is labelled illustrative because it is.

  • Not a substitute for reporting. Reading this page does not recover anybody's money; calling 1930 within the hour sometimes does.

Use it freely

Project it in a classroom, walk a relative through the simulator, or send someone straight to the emergency section. No permission needed and no attribution required — if it stops one transfer, it has paid for itself.