A Record Number of Threats
The latest threat data from cybersecurity firm Kaspersky has revealed an alarming trend: India recorded 18,187 mobile attack incidents in the first quarter of 2026, the highest volume in the entire Asia-Pacific region. This surge highlights a critical
vulnerability as millions of Indians embrace digital payments, online banking, and e-commerce. While digital adoption is surging, awareness of the risks is lagging, with one report suggesting only 32% of Indians fully recognise the dangers of cybercrime. This gap between digital usage and security knowledge is exactly what fraudsters are exploiting, moving their focus heavily towards mobile devices.
Beyond Simple SMS Scams
Today’s mobile frauds are a far cry from the poorly worded scam emails of the past. Criminals now employ advanced social engineering and technology, including AI, to make their schemes devastatingly effective. One of the most prevalent new threats is the 'digital arrest' scam, where fraudsters impersonate officials from the CBI or police, create fake arrest warrants, and coerce victims into transferring large sums of money for “verification” while on a video call. Another rapidly growing area is malware hidden within fake apps (APKs), often distributed via WhatsApp or SMS. These malicious apps, sometimes disguised as banking or government service updates, can steal your passwords, intercept OTPs, and even hijack your device to mine cryptocurrency without your knowledge.
The Evolution of Phishing and UPI Fraud
Phishing remains a dominant threat, but it has become more convincing. Scammers create pixel-perfect copies of banking websites and use urgent messages about KYC updates or blocked accounts to trick you into entering your credentials. The Unified Payments Interface (UPI) is also a major target. Fraudsters have weaponised the 'collect request' feature, sending payment requests disguised as refunds or lottery winnings. Unsuspecting users who enter their PIN to 'receive' the money end up authorising a payment from their own account. Other sophisticated tactics include AI voice cloning, where a scammer uses a short audio clip from your social media to clone a family member’s voice and create a fake emergency to solicit funds.
Your Digital Self-Defence Guide
While the threats are sophisticated, you can significantly boost your defences with a few key habits. First, treat any unsolicited communication with suspicion. Banks, police, and government agencies will never ask for your OTP, PIN, or password over the phone or via text message. Second, enable two-factor authentication (2FA) on all your financial and email accounts for an essential extra layer of security. Third, only download applications from official sources like the Google Play Store or Apple App Store, and be wary of any app that asks for excessive permissions. Never click on links or download files sent from unknown numbers on WhatsApp or SMS. For financial transactions, always use your mobile data or a trusted private Wi-Fi network, as public Wi-Fi can be easily compromised.
What to Do If You Suspect a Scam
If you receive a suspicious call, hang up immediately. If it purports to be from your bank, call the official customer care number listed on the bank's website to verify the information. Regularly monitor your bank statements for any unauthorised transactions, no matter how small. Should you fall victim to a cybercrime, time is critical. Immediately report the incident to the National Cyber Crime Reporting Portal by dialling the helpline number 1930 or by visiting www.cybercrime.gov.in. Also, inform your bank to block the relevant accounts or cards to prevent further losses.












