Learn about common fraud types and warning signs to protect yourself
Online users should follow basic security tips to protect themselves from falling victims to online frauds.
HDFC Bank has been one of the pioneers in extending internet banking services to cater to anytime, anywhere banking needs of its customers by leveraging on to its state-of-the-art technology platforms. Internet Banking has also been exploited by hackers and fraudsters to deceive the bank's customer and commit frauds. While the bank has best-of-the-breed solutions, processes and people deployed to extend secure banking to its customers, it is important for our customers to know that "SecUrity is incomplete without U". Customers need to follow secure computing guidelines to avert any frauds or security breaches to their accounts, as keys to the internet banking accounts are held by respective account owners in the form of Customer IDs and Internet Banking passwords (IPIN).
1. Keep your Customer ID and IPIN confidential and do not disclose it to anybody.
2. Change your IPIN as soon as you receive it by logging into your NetBanking account. Memorise your IPIN, do not write it down anywhere.
3. Refer "Protect your computer accounts with strong passwords" section under computer security tips.
4. Avoid accessing internet banking from shared computer networks such as cyber cafes.
5. Do not click on links in the emails or sites other than https://www.hdfc.bank.in/ to access your NetBanking webpage.
6. Always visit the HDFC Bank's NetBanking site through HDFC Bank's home page by typing the bank's website address (https://www.hdfc.bank.in/) on to the browser's address bar. Users are encouraged to add the bank's URL to Favorites or Bookmark in the user computer browser.
7. Always verify the authenticity of the Bank's NetBanking webpage by checking its URL as "https://netbanking.hdfcbank.com" and the PAD Lock symbol at the bottom corner of the browser before putting in your Customer ID and IPIN.
8. If your Customer ID and IPIN appear automatically on the login page of NetBanking webpage, you should disable "Auto Complete" feature on your browser. To disable auto complete feature:
1. Open Internet Explorer, Click on Tools=> Internet Options=> Content.
2. Click on "Auto Complete", under "Personal Information"
3. Uncheck "User names and passwords on forms", click on "Clear Passwords"
4. Click "OK"
9. Use virtual keyboard feature while logging into your internet banking account.
10. Do cross check your last login information available in NetBanking upon every login to ascertain your last login and monitor any unauthorised logins.
11. Always type your confidential account information. Do not copy paste it.
12. Monitor your transactions regularly.
13. Use HDFC Bank's "InstaAlerts" service.
14. Always logout when you exit NetBanking. Do not directly close the browser.
15. In addition to the above stated points please refer Computer Security Tips.
1. Watch your click:
You must observe click discipline while browsing through different websites. You may land up clicking on to malicious link that could download malicious code / software or virus on to your computer.
2. Do not download software from nontrustworthy sites:
Downloading software from non-trustworthy sites may lead to infecting your computer with virus. Users should particularly be careful of downloading freeware which may have Trojans installed that would transmit your confidential information to a hacker or fraudster without your knowledge.
3. Read privacy policy of the website:
Make sure that you read the privacy policy of the website before parting with any personal information such as name, email id, contact number, etc and be aware of how your information would be used by the website owner.
Internet Banking System Security:
Login Security:
Access to customer's NetBanking account is granted using a Customer ID and IPIN (internet banking password) that is privy to the customer. Without a valid IPIN corresponding to the customer ID, access to customer account cannot be gained by anyone.
IPIN Security:
Session Security:
Access to the customers are provided through a secure webpage that encrypts the session between the customer's computer and the webpage using 128-bit encryption so that the communication between the customer's computers and the webpage cannot be intercepted by anyone over the internet.
HDFC Bank systems time out the customer's login sessions to his NetBanking account upon prolonged inactivity for protection against misuse.
Digital Certificate:
The webpage of the HDFC Bank's internet banking server is identified by means of a digital certificate provided by Verisign to ensure its customer that they are on the correct site and protect themselves from revealing their confidential account information on some fake website.
Taking internet security to a new level and to prevent frauds, HDFC Bank has enhanced its NetBanking security by obtaining the Extended Validation Secure Sockets Layer Certificate (hereby referred to as “the EVSSL certificate” or “the certificate”).
The EV SSL Certificate provides clear visual indicators in the form of green address bar so that customers can easily identify a genuine website. This implies that it belongs to the organization it claims to be from. In this case it is HDFC Bank. As soon as the bar (URL address bar) turns green, customers can be assured it is the genuine website. Alternatively, if the bar turns red, it means that the web page they are accessing might be unsafe and customers are advised to stop accessing the web page immediately. For further verification you can also click on the green address bar to check for the details of the organization (Simultaneously you can also be on a lookout for padlock* in the bar and the Norton Secured Seal**).
Some of the other benefits of having the EVSSL certificate also includes that the online shoppers can recognize the green address bar as an easy and reliable way to verify the site identity and security.
The customers should be informed that the certificate works on all the major browsers like Internet Explorer 7, Mozilla Firefox 3, Opera 9.5, Google Chrome and Safari 3.2 and the higher versions of these. In case customers are using an older browser, they will not get a green color notification in the address bar, even though the website is EV SSL authenticated. It is highly recommended that they upgrade their browser to a version that is compatible with EV SSL certificates.
The next time you log in to the NetBanking page, watch out for the green address bar as below:
Virtual keyboard:
Customer can use the feature of Virtual Keyboard while logging into his NetBanking account. This protects the users IPIN from being compromised by keylogger software installed on untrusted/shared computers e.g cyber cafes.
Insta Alert:
The Bank has InstaAlert service to send SMS/ Email alert to the customer upon registration for defined transaction denominations and while adding beneficiary/ies for carrying out Third Party Transfer transactions.
Security Solutions:
All banking systems are secured using state-of-the-art security solutions acknowledged world wide viz, firewalls, intrusion detection systems, intrusion prevention systems, anti-malware systems to extend secure banking services to our customers.
Security Teams:
The Bank has robust processes, skilled people and competent service providers who monitor the security of our systems round the clock.
HDFC Bank has the best security solutions backed with robust processes in place to extend secure Banking services to its customers.
Access to customer's NetBanking account is granted using a Customer ID and IPIN (internet banking password) that is privy to the customer. Without a valid IPIN corresponding to the customer ID, access to customer account cannot be gained by anyone.
Access to the customers are provided through a secure webpage that encrypts the session between the customer's computer and the webpage using 128-bit encryption so that the communication between the customer's computers and the webpage cannot be intercepted by anyone over the internet.
HDFC Bank systems time out the customer's login sessions to his NetBanking account upon prolonged inactivity for protection against misuse.
The webpage of the HDFC Bank's internet banking server is identified by means of a digital certificate provided by Verisign to ensure its customer that they are on the correct site and protect themselves from revealing their confidential account information on some fake website.
Taking internet security to a new level and to prevent frauds, HDFC Bank has enhanced its NetBanking security by obtaining the Extended Validation Secure Sockets Layer Certificate (hereby referred to as “the EVSSL certificate” or “the certificate”).
The EV SSL Certificate provides clear visual indicators in the form of green address bar so that customers can easily identify a genuine website. This implies that it belongs to the organization it claims to be from. In this case it is HDFC Bank. As soon as the bar (URL address bar) turns green, customers can be assured it is the genuine website. Alternatively, if the bar turns red, it means that the web page they are accessing might be unsafe and customers are advised to stop accessing the web page immediately. For further verification you can also click on the green address bar to check for the details of the organization (Simultaneously you can also be on a lookout for padlock* in the bar and the Norton Secured Seal**).
Some of the other benefits of having the EVSSL certificate also includes that the online shoppers can recognize the green address bar as an easy and reliable way to verify the site identity and security.
The customers should be informed that the certificate works on all the major browsers like Internet Explorer 7, Mozilla Firefox 3, Opera 9.5, Google Chrome and Safari 3.2 and the higher versions of these. In case customers are using an older browser, they will not get a green color notification in the address bar, even though the website is EV SSL authenticated. It is highly recommended that they upgrade their browser to a version that is compatible with EV SSL certificates.
The next time you log in to the NetBanking page, watch out for the green address bar as below:
Customer can use the feature of Virtual Keyboard while logging into his NetBanking account. This protects the users IPIN from being compromised by keylogger software installed on untrusted/shared computers e.g cyber cafes.
The Bank has InstaAlert service to send SMS/ Email alert to the customer upon registration for defined transaction denominations and while adding beneficiary/ies for carrying out Third Party Transfer transactions.
All banking systems are secured using state-of-the-art security solutions acknowledged world wide viz, firewalls, intrusion detection systems, intrusion prevention systems, anti-malware systems to extend secure banking services to our customers.
The Bank has robust processes, skilled people and competent service providers who monitor the security of our systems round the clock.