The Fake E-Wallet Account Suspension Alert
Attackers impersonate popular Indonesian e-wallet apps to trick users into handing over the PIN or one-time password that protects their balance. This walkthrough describes a generic, fictional e-wallet lure built for training and does not depict any specific provider's actual communications.
The scenario
A text message or in-app-style notification arrives: 'Your e-wallet account has been temporarily suspended due to suspicious activity. Verify your identity within 1 hour or your account will be permanently locked.'
A link is provided that opens a page visually identical to a familiar e-wallet login screen, with the same color scheme, logo placement, and layout the victim recognizes from daily use.
The page asks the user to enter their registered phone number, then their 6-digit PIN, and finally the OTP that arrives by SMS moments later, framed as required steps to 'unlock' or 'restore' the account.
The moment the OTP is entered on the fake page, the attacker (who has simultaneously initiated a real login or transaction attempt on the genuine app) uses that code to authorize a transfer or top-up fraud, often draining the balance within minutes, well before the victim realizes the site was fake.
Red flags to spot
Request to enter your PIN on a page reached via SMS link
Legitimate e-wallet providers never ask you to type your PIN into a web page. The PIN is entered only inside the official app itself.
OTP requested immediately after PIN entry
A real account issue does not require you to hand over an OTP through a link. OTPs exist specifically to confirm actions you initiate, not actions a message tells you to complete.
Countdown of 1 hour or less before permanent lock
Genuine security suspensions give you standard support channels and time to respond; they do not threaten irreversible loss of funds or account within an hour.
Link domain that is not the official app or provider website
Official e-wallet actions happen inside the verified app downloaded from an official app store, not through a browser page reached via SMS or WhatsApp link.
Message arrives with no prior notification history
If you have not received prior alerts about unusual activity from the provider's official in-app notifications, a sudden suspension claim out of nowhere is a strong sign of fraud.
The lesson
Never enter your e-wallet PIN or OTP anywhere except inside the official app itself, and never through a link from SMS, WhatsApp, or email. If you receive a suspension warning, close the message, open the official app directly (not through any link), and check your account status there. If anything seems wrong, contact the provider's official in-app customer support or verified hotline. Remember: your OTP is meant to confirm a transaction you started, never to be given to 'restore' an account someone else claims is at risk.
These are illustrative examples built for training purposes only, not real messages sent by Claro or any actual organization.
Frequently asked questions
The OTP is the final authorization step for transactions. Once an attacker has your phone number, PIN, and OTP, they can complete a transfer or top-up as if they were you, which is why OTP requests deserve the highest suspicion.
Related pages
Fake WhatsApp Verification Code Request
Someone posing as a contact or HR asks you to forward the 6-digit code you just received by SMS, which actually hands over control of your WhatsApp account.
Learn moreMalicious QR Code (Quishing)
A QR code stuck over a parking meter or printed on a fake payment notice leads to a lookalike page that harvests login or card details.
Learn moreThe QRIS 'Refund' Payment Scam
A seller or 'support agent' sends you a QRIS code and tells you to scan it to receive a refund or claim money, but scanning a QRIS code always sends money out, never in.
Learn moreRun these patterns as real simulations
Claro turns each of these lures into a localized, trackable phishing simulation your team can learn from safely.
Request a demo