An IT professor from the National University (NU) Manila has developed a Web platform to help users assess suspicious text and chat messages by examining their behavior, links, and transaction context instead of automatically treating common features such as one-time passwords (OTPs) or urgent notices as evidence of fraud.
Called “Scam Ba ’To?”, the independently developed platform allows users to paste suspicious messages and receive Red, Yellow, or Green risk guidance, along with an explanation of the behavior detected and verified official channels when available.
The system is designed to analyze payment notices, account warnings, courier updates, government notices, school messages and other digital communications.
“Hindi dapat matakot ang isang tao dahil lang may OTP o malaking halaga sa text. Ang tanong ay kung ano ang nangyari, ano ang pinapagawa sa iyo, at saan ka dinadala,” said developer and project lead John Clement S. Escobañez.
The platform seeks to distinguish legitimate security messages from scams that imitate them. An OTP, for example, may be legitimate when generated after a user initiates a transaction.
But the risk changes when a message directs the recipient to enter the OTP on an unrelated website, send it to another person, or use it supposedly to cancel an unexpected transaction.
Scam Ba ’To? separates recognition of an organization from authentication of the sender. It evaluates requested actions and transaction context, examines links and domains, applies behavioral scam indicators, and provides verified organization guidance when available.
The platform does not treat recognition of a legitimate company or institution as proof that a message actually came from that organization.
Its Red classification indicates dangerous behavior observed in a message, while Yellow signals that additional verification may be needed. Green represents lower observed risk but is not intended as proof that the sender or message is authentic.
“Catching scam messages is only half the problem. If a system repeatedly scares people about legitimate transactions, it is also failing,” Escobañez said. “Hindi namin gustong sabihing ‘scam’ lang. Gusto naming ipakita kung bakit.”
According to project data, the platform currently has 77 Gold verified entities, 648 recognition entities, 716 organization-intelligence profiles, 186 verified destinations, 211 verified organization facts and 94 source-grounded cases.
Its validation corpus has undergone 48,000 controlled benchmark executions involving 16,447 unique messages and 6,144 behavioral representatives. The developers stressed that the 48,000 executions are validation cases and should not be interpreted as 48,000 separate real-world scam reports.
While Escobañez is affiliated with NU’s College of Computing and Information Technologies, he said the project is independently developed.


