A Sharply Escalating Threat
The numbers paint a concerning picture of the mobile security landscape in India. According to a recent report from fraud detection firm BioCatch, text-message-based scams shot up by 146% between late 2025 and mid-2026. During the same period, overall
mobile fraud sessions increased by 67%, signalling a clear shift by criminals away from web browsers and directly onto the devices in our pockets. This isn't just about an increase in volume; the attacks are becoming more costly. The total value of attempted fraudulent payments has risen by 35%, even as the time scammers spend per victim has decreased. This efficiency indicates that criminal tactics are becoming more refined and automated. Data from the National Cyber Crime Reporting Portal further highlights the scale of the problem, with cumulative financial loss claims from 2021 to mid-2026 exceeding ₹55,050 crore.
The Scammer's New Toolkit
Forget poorly worded emails and obvious fake links. Today's fraudsters are using a far more deceptive and technologically advanced playbook. One of the most alarming new trends is the use of Artificial Intelligence to create hyper-personalised phishing messages and even deepfake audio that can clone the voice of a trusted person. Scammers are also weaponizing the Unified Payments Interface (UPI) ecosystem in novel ways. A highly sophisticated QR code scam has emerged where scanning a malicious code with an Android phone's camera can link your bank account to a scammer's device without your consent. Unlike typical QR scams that trick you into authorising a payment, this method involves a technical exploit that forces your phone to send a hidden UPI registration token, effectively giving the fraudster control. Another widespread tactic is the 'digital arrest,' where criminals impersonate law enforcement officials from agencies like the CBI or ED, using video calls to create a high-pressure situation and coerce victims into transferring large sums for "verification".
The Psychology of Deception
These new scams are effective because they exploit basic human psychology: trust, urgency, and fear. A text message appearing to be from a bank or a delivery service hijacks a trusted communication channel, prompting an immediate reaction rather than careful thought. QR code scams prey on our comfort with the technology; we scan them daily at shops and restaurants, lowering our guard. Fraudsters often create a sense of urgency, claiming an account will be blocked or a parcel is being held, to prevent the victim from stopping to think or verify the information. The 'digital arrest' scam leverages fear and respect for authority to an extreme degree, isolating victims on camera for hours to break down their resistance. The fundamental rule that scammers exploit is the simple fact that you never need to scan a QR code or enter a PIN to receive money—only to send it.
How to Build Your Defences
While the threats are evolving, your core defence strategy remains rooted in vigilance and basic digital hygiene. The Indian Computer Emergency Response Team (CERT-In) regularly issues warnings and advises all users to keep their device's operating system and applications updated with the latest security patches. Be extremely cautious of unsolicited messages, especially those containing links or urging immediate action. A critical rule for UPI users is to always verify the recipient's name on the payment screen before entering your PIN. Never scan a QR code sent by a stranger via WhatsApp or SMS. If you are selling something online, a legitimate buyer never needs you to scan a code to pay you. For added security, the RBI has suggested new measures like enabling a 'switch on/off' facility for different payment modes within your banking app. If you suspect you've been scammed, immediately call the national cybercrime helpline at 1930 to report the incident and block the fraudulent accounts.













