Scams in Sri Lanka have moved from bad-English emails to convincing SMS in Sinhala, WhatsApp messages with real company logos, and phone calls from people who know your name. The technology got better; the underlying tricks did not. Here is how to recognise them.

The five scams I see most right now

  1. "Your parcel is held — pay Rs. 150 customs/redelivery fee." SMS with a link to a page that looks like the post office or a courier. The Rs. 150 is bait; the page harvests your card number. Real couriers do not collect fees through a link in an SMS.
  2. "Your bank account / CEB / SLT account will be suspended — verify now." The link leads to a copy of the bank's login page. Banks in Sri Lanka will never send a login link by SMS. Type the bank's address yourself or use the app.
  3. "You have been selected for a part-time job — earn Rs. 5,000 a day liking videos." Starts with small real payments to build trust, then asks you to "invest" to unlock bigger tasks. Every rupee invested is gone.
  4. Fake buyer / fake Fiverr-style client — "I want to order but please chat on Telegram" or "I'll pay via this link". Anyone moving you off the platform to pay is stealing from you.
  5. The "bank officer" call — knows your name and last four card digits (leaked from some breach), says there is a suspicious transaction, and asks for the OTP "to cancel it". The OTP authorises the transaction. No bank employee ever needs your OTP.

The 10-second checks

  • Press and hold the link (do not tap). Look at the real address. slt-bill-pay.xyz is not SLT. combank-secure.info is not Commercial Bank. Real Sri Lankan institutions use .lk or their well-known .com.
  • Urgency is the tell. "Within 24 hours", "immediately", "account will be closed" — legitimate organisations do not threaten you by SMS.
  • Check the sender. Bank SMS come from a named sender ID (e.g., a bank's name), not a random 07x number. Emails: look at the actual address, not the display name.
  • Never share an OTP. Not with a caller, not in a form, not with "customer support" on WhatsApp. The only place an OTP goes is the app or website that you opened yourself.
  • Money moving off-platform = scam. Marketplace buyers, freelance clients, rental deposits — the moment they insist on a "different way to pay", walk away.

If you already clicked or paid

  1. Card details entered: call the bank's hotline (the number on the back of the card) and block the card immediately. Minutes matter.
  2. Password entered on a fake page: change that password everywhere you used it, and turn on two-factor authentication.
  3. Installed an APK from a link: uninstall it, then change your banking password from a different device. Some fake apps read your SMS to capture OTPs.
  4. Report it: Sri Lanka CERT (cert.gov.lk) and the bank's fraud line. Reports help take the pages down before the next person clicks.

Protect the older people in your family

Most losses I hear about are parents and grandparents. Set their phones up with: SMS spam filtering on, Google Play Protect on, "install from unknown sources" off, and one rule they can remember — "If it asks for money or an OTP, call me first." That single rule prevents almost everything above.