12 Digital Safety Habits Every Indian Smartphone User Needs in 2026
India has more than 750 million smartphone users, and almost every one of them now carries a bank, an identity card, a wallet and a lifetime of photographs in their pocket. That convenience has a cost. According to the Indian Cybercrime Coordination Centre, Indians lose thousands of crores of rupees every year to digital fraud, and the fastest-growing categories are not sophisticated hacks but simple tricks: a fake delivery SMS, a “digital arrest” video call, a UPI collect request disguised as a refund, a KYC-update link from someone claiming to be from your bank.
The uncomfortable truth is that most of these losses were preventable with a handful of habits that take minutes to set up and seconds to practise. This article lists twelve of them, ordered by how much protection each one buys you for the effort involved. It draws on the priority-ordered security approach that India-focused technology publications such as Techlein have been advocating, where the highest-value action comes first and the rest follow in sequence, rather than an unordered pile of tips that nobody finishes reading.
Why Priority Order Matters
Most security advice fails because it is presented as a list of twenty equal items. Faced with twenty things, people do none of them. In reality, two or three actions eliminate the large majority of risk for an ordinary Indian user, and everything after that is refinement. So work through this list from the top. If you only do the first three, you are already safer than most of the country. If you do all twelve, you are in a very small, very well-protected minority.
1. Lock Your SIM and Your Google or Apple Account First
Your phone number is the master key to your digital life in India. Bank OTPs, UPI PINs resets, Aadhaar-linked services, WhatsApp, and password recovery for almost every account all route through it. That is why SIM swap fraud, where a criminal convinces or bribes a telecom outlet to issue a duplicate SIM for your number, is so devastating: once they hold your number, they hold everything.
Two actions here. First, set a SIM PIN on your phone (Settings, Security, SIM card lock on Android; Settings, Cellular, SIM PIN on iPhone) so that a stolen physical SIM cannot simply be moved to another phone. Second, and more important, secure the account that owns your phone: your Google account on Android or Apple ID on iPhone. Turn on two-step verification, add a recovery email and a backup phone number you control, and generate backup codes and store them somewhere physical. Tech lein’s smartphone security guide describes this as the single highest-value action of all, and that is correct: with a locked Google or Apple account you can remotely locate, lock and erase a lost phone, and an attacker who steals the device gets a brick rather than a bank.
2. Turn On App Lock for Payment and Banking Apps
UPI apps like Google Pay, PhonePe and Paytm already require a PIN to send money, but many people leave the app itself open to anyone holding the phone, which exposes transaction history, linked bank names and balance. Enable the in-app lock (biometric or PIN) on each payment app, on your bank apps, and on your Aadhaar and DigiLocker apps. Most Android manufacturers, including Samsung, Xiaomi, Vivo, Oppo and Realme, also offer a system-level App Lock in Settings that works on any app; iPhones offer Face ID requirement per app from iOS 18 onwards.
Also review the daily UPI transaction limit set by your bank. If you rarely send more than ten thousand rupees at a time, ask your bank to cap it there. A lower cap limits the damage from a single compromised session.
3. Learn the Shape of a Scam, Not Just the Latest Example
Scams in India change every month. Last year it was fake electricity-disconnection SMS; this year it is “digital arrest” video calls from people impersonating CBI or ED officers, and fake “your parcel is held at customs” messages. Memorising individual scams is a losing game. What works is recognising the underlying shape, which never changes: urgency, authority and secrecy. Someone claims to be an official or a bank, tells you something terrible will happen within minutes unless you act, and insists you not tell anyone or hang up.
Every real institution in India, from SBI to the Income Tax Department to the police, will survive you hanging up and calling back on a number you find yourself. No bank asks for your UPI PIN, OTP or card CVV to “verify” or “reverse” a transaction. No government agency arrests people over a video call. Techlein’s security explainer walks through this pattern-recognition approach in detail, and it is worth reading with older family members, who are the primary targets of the digital arrest scam.
4. Never Approve a UPI Collect Request You Did Not Initiate
The most common UPI fraud is embarrassingly simple. A scammer, often posing as a buyer on OLX or a refund agent, sends you a “collect” request and tells you that approving it will credit money to your account. It does the opposite: entering your PIN on a collect request sends money out. The rule is absolute. You never need to enter your UPI PIN to receive money. If anyone asks you to enter your PIN to receive a payment, a refund or a cashback, it is theft.
Similarly, treat QR codes with suspicion when you are the one supposed to be receiving money. Scanning a QR code is for paying. If a “buyer” sends you a QR code to scan, they are not paying you.
5. Install Apps Only from the Play Store or App Store, and Check Before You Update
Sideloaded APKs are the main delivery vehicle for Android banking malware in India. The lure is usually a modded app, a “free premium” version of a paid service, or a fake update sent over WhatsApp. Once installed, these apps request Accessibility and SMS permissions and then silently read OTPs and overlay fake login screens on top of your real banking apps.
Stick to the Play Store, keep Google Play Protect enabled, and be especially wary of APKs for popular apps like YouTube, Telegram or CapCut circulating on Telegram channels and WhatsApp groups. There are legitimate reasons to update outside the Play Store, for instance on phones without Google services, and Tech lein publishes guides on doing exactly that safely through official sources; the key word is official. An APK from a random file-sharing site is never official.
6. Audit Your App Permissions Every Few Months
Go to Settings, Privacy, Permission Manager on Android (or Settings, Privacy & Security on iPhone) and look at which apps have access to SMS, Contacts, Location, Microphone, Camera and Accessibility. Then ask a simple question for each: does this app need this to do its job? A torch app does not need contacts. A wallpaper app does not need SMS. A loan app absolutely does not need your entire contact list, and if it has it, that list is what gets used for harassment when repayment is late.
Accessibility permission deserves special attention because it allows an app to see and control everything on screen. Only screen readers and a few legitimate automation tools should ever have it. Techlein’s guide to Android permissions goes through each permission type with plain-language explanations of what to allow and what to refuse, which is useful if the settings screen feels overwhelming.
7. Use a Password Manager and Stop Reusing Passwords
Indian users are among the most likely in the world to reuse a single password across banking, email, shopping and social media. When any one of those services suffers a breach, and breaches of Indian platforms are announced almost monthly, that password gets tried everywhere else automatically within hours.
A password manager solves this without effort. Google Password Manager is built into Android and Chrome and is free. Apple’s Passwords app is built into iOS. Bitwarden is a free, open-source alternative that works across every platform. Let the manager generate a unique random password for each site and remember it for you; you only need to know one master password. Then go to haveibeenpwned.com and check whether your email has appeared in known breaches, and change any password that has.
8. Set Up Two-Factor Authentication Beyond SMS
SMS-based OTP is better than nothing but it is vulnerable to SIM swap and to malware that reads messages. For your most important accounts, meaning your primary email, your password manager, and any account holding money or crypto, use an authenticator app such as Google Authenticator, Microsoft Authenticator or Aegis, or a hardware key if you are comfortable with one. Email deserves the strongest protection of all, because email is where every other account’s password reset lands.
9. Back Up Your Phone Automatically, Including WhatsApp
Security is not only about attackers. A phone dropped in a Mumbai monsoon drain or stolen on a Delhi metro takes years of photos and every conversation with it. Turn on automatic backup: Google One or Samsung Cloud on Android, iCloud on iPhone. Turn on WhatsApp’s chat backup to Google Drive or iCloud, and enable end-to-end encrypted backups so that the backup itself cannot be read by anyone but you. Photos should sync to Google Photos or iCloud Photos with the “back up and sync” toggle on, not merely sit in the gallery.
Test the backup once. Open Google Photos on a laptop browser and confirm your recent pictures are there. A backup you have never verified is a hope, not a plan.
10. Lock Your Aadhaar Biometrics and Use a Virtual ID
Aadhaar is linked to bank accounts, SIM cards, subsidies and now many private services. UIDAI offers two protections that most people never enable. The first is Biometric Lock in the mAadhaar app or on the UIDAI website: once locked, your fingerprints and iris cannot be used for authentication until you temporarily unlock them, which stops the Aadhaar-enabled payment system (AePS) fraud that has drained accounts in rural India through cloned fingerprints. The second is the Virtual ID, a temporary 16-digit number you can share instead of your real Aadhaar number for verification. Also enable Aadhaar lock if you rarely use it for authentication.
The mAadhaar app has a reputation for being confusing, and a step-by-step guide covering profile setup, biometric lock, Virtual ID, offline eKYC and the secure QR code, such as the one on Techlein, makes the process far less painful than trial and error.
11. Keep Your Phone Updated and Know When It Is No Longer Safe
Security updates fix the exact vulnerabilities that malware exploits. On Android, check Settings, System, System Update monthly and install what is offered; on iPhone, turn on automatic updates. The harder question is what to do when updates stop. Most Android phones sold in India receive two to four years of security patches depending on brand and price tier, after which they remain usable but increasingly exposed.
A phone that has not received a security patch in more than a year should not be your primary banking device. It can still be a media player, a child’s YouTube device or a spare, but move your financial apps to a phone that is still supported. Tech lein has a useful explainer on why phones slow down after two years, which repairs are worth it, and the real signal that it is finally time to upgrade; the end of security updates is that signal, regardless of how fast the phone still feels.
12. Know the First-Hour Response If Something Goes Wrong
Even careful people get hit. What separates a small loss from a ruinous one is speed in the first hour. Memorise these steps or save them somewhere you can reach without your phone.
- If money has left your account: call 1930, the national cybercrime helpline, immediately, and file a complaint at cybercrime.gov.in. Banks and payment platforms can often freeze funds in the receiving account if reported within the first hour or two. Then call your bank’s fraud line and block the card, UPI or net banking as relevant.
- If your phone is lost or stolen: from any browser, go to Find My Device (Android) or iCloud Find My (iPhone), lock the device with a message, and if it is not recoverable, erase it. Then log in to your telecom provider and block the SIM, and report the IMEI on the government’s CEIR portal (ceir.gov.in), which blacklists the phone across all Indian networks. Change the passwords for email and banking from another device.
- If you clicked a suspicious link or installed a suspicious app: disconnect from the internet, uninstall the app, run a Play Protect scan, change the passwords for any account you opened on that phone since the install, and check your bank statements for the next few weeks.
A Simple Monthly Routine
Once the twelve habits are in place, maintenance takes about ten minutes a month. Check for system updates. Glance at the Permission Manager. Confirm your backups are running. Review the last month of bank and UPI transactions for anything you do not recognise. Once a year, rotate the password on your primary email and review the recovery options on your Google or Apple account. That is the whole routine, and it is far less effort than recovering from a single successful scam.
Frequently Asked Questions
Is an antivirus app necessary on Android in India?
Not usually. Google Play Protect, kept enabled, plus the habit of never sideloading unknown APKs, provides most of the benefit. Many “antivirus” and “phone cleaner” apps on the Play Store are themselves ad-laden and request excessive permissions.
Is UPI safe to use?
UPI itself is well designed and secure. The fraud almost always involves tricking the user into entering their PIN on a collect request or into sharing an OTP. The system does not get hacked; the person does. Habits four and three on this list address that directly.
My parents refuse to follow any of this. What is the minimum?
Set up their Google or Apple account security yourself, enable app locks on their bank and UPI apps, lower their UPI transaction limits, lock their Aadhaar biometrics, and teach them exactly one rule: hang up and call you before doing anything anyone on the phone tells them to do with money. That single rule defeats nearly every scam currently running in India.
Where can I read more about protecting my devices?
Publications that focus specifically on Indian conditions are more useful than generic global advice, because the scams, apps, telecom operators and government services are different. Techlein’s security, Aadhaar, DigiLocker and Android permissions guides are written with those specifics in mind.
Final Thoughts
Digital safety in India is not a technical problem for most people. It is a habits problem. The criminals are counting on urgency, confusion and the assumption that security is complicated. Work down this list in order, get the first three done today, and finish the rest over a couple of weekends. You will have removed yourself from the easy-target pool, which is, in practice, most of the battle.