Length beats complexity
A sixteen-character phrase of ordinary words outlasts an eight-character mess of symbols. Attack tools expand P@ssw0rd! instantly; they cannot brute-force four unrelated words.
Stay Secure. Stay Aware. Stay One Step Ahead.
All systems nominal
Nothing protects you on its own. Security works in layers, each one covering what the last one misses. Scroll to assemble the machine — every ring that locks into place is a real control you can switch on today.
A diagram of layered security controls. Six layers assemble as you scroll: attention, identity, encryption, firewall, monitoring, and awareness. Each layer is described in the list that follows.
Nineteen attacks that are actively used against people in Kerala right now. Open any card to see how it works, what it looks like from the inside, and exactly what to do if it reaches you.
19 threats shown
Eight real attack patterns, rebuilt as safe mock-ups. Tap anything that looks wrong. Nothing here is a real link, a real brand or a real form — the messages are inert text, so you can click with complete freedom.
A shell that only teaches. Type a topic and press Enter — or start with help. Nothing is executed and nothing leaves your browser; the prompt is a lesson index wearing a command line.
Type a command and press Enter
Type anything below and watch the vault respond. The meter estimates how long a rented cracking rig would need to guess it — and every character you type stays inside this browser tab.
Vault offline
A sixteen-character phrase of ordinary words outlasts an eight-character mess of symbols. Attack tools expand P@ssw0rd! instantly; they cannot brute-force four unrelated words.
Breaches are traded in bulk. The moment one shopping site leaks your password, attackers replay it against your email and bank — this is called credential stuffing, and it is the single most common way accounts fall.
You cannot memorise sixty unique passwords, and you should not try. A password manager stores them encrypted; you remember one long master phrase. Then switch on two-factor authentication where it is offered.
Security is not a purchase, it is a set of small habits. Tick each one you already do and watch the shield close around you — the list is stored only in this browser, and nothing is sent anywhere.
High smartphone penetration, near-universal UPI and a strongly bilingual population make Kerala a specific target, not a generic one. These are the scripts in local circulation — read them in the language they arrive in.
Every message below is a reconstruction. The numbers, names and links are invented and nothing here is clickable.
Five tracks, five questions each. Pick the one that fits you — every answer comes with the reasoning, so a wrong choice is worth as much as a right one.
Choose a track
Fifty years of attacks, each one changing what came next. Scroll through — the pattern is that every advance in convenience arrived with a matching advance in exploitation.
An experiment on ARPANET that copied itself between machines and printed a message. It was not malicious, and a second program named Reaper was written to remove it — the first antivirus.
Why it still matters
Self-replication was proved possible before anyone thought to defend against it. Security has been catching up with capability ever since.
A graduate student's worm, intended to measure the size of the internet, reinfected machines faster than it should have and disabled a significant share of the network within hours.
Why it still matters
It produced the first computer-crime conviction under US law and led directly to the creation of the first coordinated incident response team.
An email attachment named as a love letter spread to tens of millions of machines in days by mailing itself to every contact in the victim's address book.
Why it still matters
It proved the decisive vulnerability was curiosity, not code. Every phishing email since has been built on that finding.
Malware built specifically to sit inside a browser and alter banking sessions as they happened. It was sold as a toolkit, so the operator no longer needed to be the author.
Why it still matters
It separated skill from crime. Today a person with no technical ability can rent everything needed to run an attack.
Malware that crossed an air gap on removable media and altered the speed of industrial centrifuges while reporting normal readings to their operators.
Why it still matters
The first widely documented case of code causing physical destruction — and the reason an unknown USB device is treated as a weapon.
Strong public-key encryption combined with anonymous payment. Files could be locked with a key the victim could never derive, and the ransom could be collected without a bank account.
Why it still matters
It made extortion scalable, and it is why an offline backup is now the single most valuable thing you can keep.
Two outbreaks used a leaked exploit to spread without any human action, reaching hospitals, ports and factories across more than a hundred countries. A patch had been available for months.
Why it still matters
The clearest demonstration that delayed updates are the vulnerability. Both outbreaks were preventable by a patch already released.
Attackers began inserting malicious code into trusted software before it shipped, so the compromise arrived through a signed, legitimate update installed by careful administrators.
Why it still matters
It broke the assumption that a signed update is safe, and moved the industry towards verifying what software is actually made of.
Bridges and exchanges holding very large balances were drained through flaws in the code that moved assets between networks. There was no clearing house to reverse the transfers.
Why it still matters
It showed what a payment system without reversal really means — the same reason a UPI transfer you authorise yourself is so hard to recover.
Generative tools removed the two things that used to expose a scam: bad language and the impossibility of faking a familiar face or voice. A few seconds of public audio is now enough to clone someone.
Why it still matters
Spotting a scam by its spelling no longer works. Verification has to move to the channel — call back on a number you already had.
A visual model of how a single fraud unfolds and why the first hour decides the outcome. Read it as a diagram, not as a dashboard — every value below is illustrative.
These numbers are illustrativeDemonstration data
This console is not connected to any live feed and does not measure anything. The values are chosen to show the shape of the problem — how sharply recovery falls away with time, and where losses actually begin. For official statistics, consult the National Crime Records Bureau and the I4C reports published by the Ministry of Home Affairs.
Attack patterns currently in circulation, grouped by where they are being seen. These are standing advisories written to stay accurate — not a live news feed and not dated reporting.
Not a live feed — For breaking incidents and official notices, follow CERT-In advisories and the Kerala Police cyber wing. This board covers the patterns that persist between headlines.
Callers posing as police, CBI or customs officers keep victims on a video call for hours, claiming a parcel or a bank account in their name is under investigation, and demand transfers to a 'verification account'.
What to do
There is no lawful process called a digital arrest. Disconnect and call 1930. Tell every older relative this specific sentence.
Late-evening SMS messages claim a utility connection will be cut within the hour over an unpaid bill, and supply a mobile number. The call that follows ends with a remote-access app on the victim's phone.
What to do
Utilities do not send disconnection notices from personal mobile numbers. Check your bill in the official app and never install an app a caller asks for.
Groups offer small payments for simple online tasks, honour the first few withdrawals to establish trust, then require escalating deposits to 'unlock' higher tiers. Withdrawal is blocked behind an unending sequence of fees.
What to do
A job that requires a deposit is not a job. Stop paying at the first fee — further payments never release the balance.
Android install files are circulated in group chats disguised as wedding invitations, delivery receipts or utility bills. Once installed they request SMS and accessibility permissions and can then read OTPs and operate banking apps.
What to do
Never open an .apk received in a chat, even from a known contact. Turn off installation from unknown sources.
Credential lists from breached shopping, gaming and forum sites are traded in bulk and replayed automatically against email and banking providers. The password is already correct somewhere, so nothing is being guessed.
What to do
Give every account its own password and switch on two-factor authentication. Check your addresses on a breach-notification service.
Pirated installers and 'activator' tools ship malware that harvests saved browser passwords, session cookies and cryptocurrency wallets in a single pass. Stolen session cookies let an attacker skip the login entirely.
What to do
Do not run cracked software on a device you also bank on. If you already have, change passwords from a clean device and sign out all sessions.
Printed stickers are pasted over genuine payment codes so that money reaches the attacker instead of the merchant. Neither the customer nor the shopkeeper notices until the takings are reconciled.
What to do
Read the payee name on the confirmation screen before approving. Shopkeepers should check their code daily.
Unregulated apps approve small loans in minutes, then demand repayment at impossible rates. Having taken contact and gallery permissions at install, recovery agents threaten to send morphed images to the borrower's contacts.
What to do
Borrow only from RBI-regulated lenders. If you are being blackmailed, this is a crime against you — report at cybercrime.gov.in and do not keep paying.
A few seconds of audio taken from a public social media video is enough to synthesise a convincing voice. Calls are kept short and the line is made deliberately poor so small imperfections pass unnoticed.
What to do
Agree a family safe-word now, while nothing is wrong. Always hang up and call back on the saved number.
Adversary-in-the-middle kits proxy the real login page in real time, so the code you enter is forwarded and used within seconds — and the session cookie is stolen alongside it, letting the attacker stay logged in.
What to do
Where offered, move to passkeys or a hardware security key. Both are bound to the site's real address and cannot be relayed to a look-alike.
Emails claiming a streaming or cloud-storage subscription failed to renew lead to a convincing payment page. The amount is small and familiar, which is what stops people looking closely at the address.
What to do
Check subscriptions inside the app or your account settings. Never renew through a link in an email.
Leaked identity documents are used to request replacement SIMs. The victim's phone loses service — usually overnight — and every OTP then arrives on the attacker's device instead.
What to do
Treat a sudden lasting loss of network as an emergency. Contact your operator immediately and prefer an authenticator app over SMS codes.
Speed decides how much you get back. Money moves through mule accounts within minutes, and a bank can only freeze what has not yet been withdrawn. Work down this list in order — do not stop to feel foolish, everybody gets caught eventually.
Report an unauthorised transaction to your bank within three working days and your liability is limited under RBI rules. Report it within the first hour and there is a real chance the transfer is still sitting in an account that can be frozen.
Do not pay anyone who promises to recover your money for a fee. Recovery scams target people who have already been scammed once.
Do not delete the messages, the app or the call log. That is the evidence your complaint rests on.
Do not search for a helpline number and call whatever appears first. Fake support numbers are planted exactly where victims look.
Do not wait until morning because you feel ashamed. Every hour lowers the amount that can still be frozen.
Official channels worth bookmarking, and the parts of this site worth returning to. Search in either language, or filter by what you need.
This site offers no downloads on purpose. A page teaching you not to open unexpected files should not be handing you any.
File a financial-fraud complaint directly, without visiting a station. Complaints about content offences against women and children can be filed anonymously.
cybercrime.gov.inDepartment of Telecommunications portal. Check every mobile connection registered against your name, report a lost handset, and flag fraudulent calls and messages.
sancharsaathi.gov.inIndia's national computer emergency response team. Publishes vulnerability notes and security advisories, and is the right channel for organisational incident reporting.
cert-in.org.inState police portal, including the cyber wing and district cyber cells. Useful for local complaints and for verifying that a caller claiming to be an officer is not.
keralapolice.gov.inThe Reserve Bank's public awareness programme. Explains customer liability for unauthorised transactions and how to escalate to the RBI Ombudsman if a bank does not resolve a complaint.
rbikehtahai.rbi.org.inLock your Aadhaar biometrics when you are not using them, generate a masked Aadhaar for sharing, and review the authentication history against your number.
uidai.gov.inA joint law-enforcement and industry project offering free decryption tools for many ransomware families. Check here before even considering a payment.
nomoreransom.orgNineteen attacks with how each one works, what it looks like from the inside, the warning signs, and what to do afterwards.
Jumps to a section of this pageEight safe mock-ups of real attacks. Practise spotting the giveaways with nothing at stake.
Jumps to a section of this pageType a topic and read the lesson. Covers phishing, passwords, OTPs, Wi-Fi, ransomware, privacy and firewalls.
Jumps to a section of this pageEight scripts in local circulation, shown in the Malayalam they actually arrive in, with the giveaway in each.
Jumps to a section of this pageTick what you already do and see what is left exposed. Saved in your browser only.
Jumps to a section of this pageThe seven steps to take after a scam, in order, with every number you will need.
Jumps to a section of this pageTest a password's strength and generate a passphrase. Runs entirely inside your browser.
Jumps to a section of this pageAn open cyber-awareness resource for Kerala, in English and Malayalam. Free to use, free to share, and built to be handed to someone who has just been targeted.
Kerala has near-universal smartphone use and one of the highest rates of digital payment adoption in India. That convenience arrived faster than the awareness needed to use it safely, and the gap is where fraud lives. Most people who lose money are not careless — they are simply meeting a well-rehearsed script for the first time, usually while distracted and under time pressure. Seeing the script once, calmly, in advance, is what changes the outcome.
Not a government website, and not affiliated with any bank, police force or agency. Official channels are listed in the resources section and linked directly.
Not legal or financial advice. If money has been lost, the people who can actually act are your bank, 1930 and the police.
Not a live news or statistics service. The advisory board carries standing patterns, and every figure in the telemetry console is labelled illustrative because it is.
Not a substitute for reporting. Reading this page does not recover anybody's money; calling 1930 within the hour sometimes does.