About this tool
Takes a fake bank OTP SMS apart line by line and scans any message you paste for the same weighted scam markers and lookalike links.
This explainer dissects the fake bank OTP message — the "your account is suspended, share the OTP to reactivate" SMS — one line at a time, naming the tell in each sentence and why it works. A built-in scanner scores any message you paste against 13 weighted markers of the same scam family, from OTP and CVV requests to APK downloads, and separately inspects every link: the registrable domain, punycode, userinfo tricks, shorteners and bare IP hosts. It is for anyone who wants to recognise the next one on sight rather than memorise a blocklist.
Open Bank OTP Phishing Anatomy Explainer on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Each marker carries a weight, so an OTP request scores 14 points and a generic greeting scores 5 — the verdict reflects what actually separates a scam from a real alert.
The scanner reads the registrable domain, handles two-level suffixes like co.in, and refangs bad[.]top and hxxp:// so a safely pasted link is still analysed.
The rules run in your browser, so a message you are unsure about is never uploaded anywhere.
No. No bank and no bank employee is permitted to ask for an OTP, PIN, CVV or password — by SMS, email or phone. Genuine bank alerts carry the opposite instruction, and any request to share a code is a scam regardless of who the caller claims to be.
Read the registrable domain — the last two labels immediately before the first single slash. In sbi-secure-verify.top/login the site is sbi-secure-verify.top, not State Bank; the brand word can appear anywhere in a hostname because the owner of that domain chose it.
Call 1930, the national cyber-crime helpline, immediately and file a complaint at cybercrime.gov.in — reporting within the first hours gives the best chance of the receiving account being frozen. Also call your bank on the number printed on your card and ask for the card and net banking access to be blocked.
A sideloaded banking APK requests SMS and accessibility permissions, which lets it read the OTPs arriving on your phone and operate the screen on its own. That is the step that converts a phishing page into a completed transfer, and no bank distributes its app outside the Play Store or App Store.