The New Battlefield: Your Inbox and Chats
Cybercrime in India has shifted from complex hacks to widespread social engineering. Instead of breaking into systems, fraudsters now manipulate people into giving away money and data willingly. They use familiar platforms like SMS, WhatsApp, and UPI,
making their attacks feel personal and urgent. These attackers leverage a deep understanding of daily life, impersonating banks, delivery companies, and even government bodies to create a sense of legitimacy and urgency. With over a billion smartphone users in India, the scale of this threat is massive, making it a lucrative target for both local and international cybercriminals. They no longer need sophisticated tools when a simple, convincing message can trick someone into compromising their own security.
Smishing and Vishing: The Message and Call Scams
Smishing (SMS phishing) and vishing (voice phishing) are two of the most common attack methods. Scammers send text messages about pending electricity bills, required KYC updates for bank accounts, or package delivery issues. These messages contain malicious links that lead to fake websites designed to steal your login credentials or financial information. Vishing involves a fraudster calling you, often pretending to be a bank official or customer service representative, to trick you into sharing your PIN, OTP, or other sensitive details. A recent scam even saw fraudsters impersonating a company's Managing Director on WhatsApp to have an employee transfer nearly ₹2 crore.
UPI and QR Code Traps
The Unified Payments Interface (UPI) has revolutionized payments, but it has also created new avenues for fraud. A common trick is the 'collect request' scam. A fraudster sends you a payment request on a UPI app, often disguised as a refund or cashback offer. If you approve the request by entering your PIN, money is debited from your account instead of being credited. Similarly, scammers share malicious QR codes. They might promise you'll receive money after scanning it, but scanning a QR code is only ever for making a payment, not receiving one. Once scanned, these codes can authorize an instant transfer from your account to the fraudster's. Always remember: you never need to enter a PIN or scan a QR code to receive money.
Malicious Apps and Remote Access
Attackers are also tricking users into installing malicious applications (APKs) outside of official app stores. A scam might begin with a WhatsApp message from a fake customer care executive who instructs you to download a special app to resolve an issue. These apps can contain malware that steals your personal information, records your keystrokes to capture passwords, or even gives the scammer remote access to your device. Once they have control, they can access your banking apps, intercept OTPs, and empty your accounts. India's Computer Emergency Response Team (CERT-In) has repeatedly warned users about these fake apps and the dangers of granting remote access.
Your Practical Defence Strategy
Protecting yourself relies on vigilance and a healthy dose of scepticism. First, never click on unsolicited links or download attachments from unknown sources in SMS, email, or WhatsApp. No legitimate bank or company will ask for your PIN, CVV, or full password. Second, always verify payment requests. If a friend or family member asks for money via message, call them on their known number to confirm. For UPI transactions, double-check the recipient's name before entering your PIN and decline all unknown 'collect' requests. Third, stick to official sources. Only download apps from the Google Play Store or Apple App Store, and visit bank websites by typing the address directly, not through links. Finally, enable two-factor authentication (2FA) on all your accounts and regularly monitor your bank statements for any suspicious activity.











