I did not think that I would fall for one such attack! But I did and I salvaged the situation in time to come out unscathed!
Sumit has a correction to be made to his PAN card and I have been helping him out. At one stage there is a need for a SMS OTP from Aadhar to verify his identity. We wait for the SMS OTP on his registered mobile number; but does not come in the stipulated 120 seconds. We presume that the Aadhar server is down and repeat this the next day and find that the OTP is elusive. A quick debug shows that his registered mobile number (serviced by MTNL) is out of service. And for some odd reason it stayed that way for the entire day, repeated call to the call center reach the IVR and machine but no human so the problem is not resolved. Curious I scan through Sumit's phone and find an SMS from an unknown number (+91 9883453468) which speaks of his MTNL number not being KYC compliant.
All this seem to add up. The non-functional phone and the SMS! And I jump at the opportunity to _educate_ Sumit that he should keep track of his SMS'es as well, instead of just being on Social Media platform (as a parent you take it upon yourself that you need to educate your adult son! the Indian parent style!).
Without thinking further (Mistake 1: Succumb to Social Engineering) I immediately call +91 9339434679/+91 9883453468 (Clue 1: MTNL might not provide customer service on a personal number) and on the third try the guy at the other end pickup and immediately I hear
This is Mr Somnath from the MTNL head office in New Delhi.
I am surprised and think,
(Clue 2) "When did MTNL people start introducing themselves on a phone"
and without using the Clue 2 I mention about the SMS and about the non-compliant KYC and ask him what is to be done (fall in the trap).
He is patient and assure me
This has happened with lots of old phone connections and there is nothing to worry. It is a simple exercise. Please go to Google Store and download this application.
This is when my dim brain wakes up and I turn smart (self patting!)
Me, "I can not download any application"
He, "Why?"
[Smart Thinking] Me, "I have a bar phone"
He, "What is a bar phone"
Me, "The Nokia one which is very old"
He, "Do you have any other phone?"
Me, "We have only this phone, we can not afford a smart phone"
He, "If that is the case we can not do anything"
Me, "What do I do now?"
He, "Just wait and things will become normal"
Me, "How?"
He hangs up. I try calling him several times but he does not pick the phone. And rightfully before the end of the day Sumit's phone is functional. We go ahead and finish the task which required the registered mobile to receive an OTP via SMS.
I sleepily apologize to Sumit for "should see your SMS" comment. This time I was wrong.
Endnote
Falling into socially engineered trap is real irrespective of how smart you think you are.
Two possibilities
1. It is possible the whole thing was coincidental (MTNL going out of action, the SMS coming in just before this happening) but it added up to the fact that we needed the OTP to come as a SMS.
2. May be MTNL has a scheduled break in services which some people know apriori and then lay the trap of sending out messages to coincide with these break in service and a few people like me (think smart but aren't) fall into this trap.
Comments