The Scale of the Mobile Threat
India is grappling with an unprecedented wave of mobile-centric cybercrime. In the first part of 2026 alone, the country recorded over 18,000 mobile cyberattacks, the highest in the Asia-Pacific region. This isn't a distant, corporate problem; it's a direct
threat to millions of ordinary citizens. The sheer volume of attacks is staggering, with some reports indicating that Indian devices face over 500 cyber threat attempts every minute. This surge is primarily powered by two intertwined tactics: highly convincing phishing campaigns and the widespread distribution of malicious applications designed to look and feel like the real thing. Fraudsters are no longer just sending suspicious emails. They are using every tool at their disposal, from instant messaging apps to fake advertisements, to trick users into compromising their own security. The financial stakes are enormous, with losses from online fraud reported on the National Cyber Crime Reporting Portal running into thousands of crores.
The Two-Pronged Attack: Phishing and Fake Apps
The modern cyberattack in India often begins with a simple message. Scammers use social engineering tactics, sending messages via WhatsApp or Telegram that impersonate banks, government services, or utility companies. These messages create a sense of urgency, prompting you to click a link or download a file. This is where the attack splits. The link might lead to a phishing website, a perfect replica of your bank's login page, designed to steal your credentials. Alternatively, you might be persuaded to install a malicious app (an APK file) that looks official but is actually a banking trojan. Once installed, these apps can be devastating. They can intercept SMS messages to steal one-time passwords (OTPs), record your keystrokes to capture PINs, and even use your device's processing power to mine cryptocurrency in the background. Cybercriminals have become adept at using assets from official banking websites to make their fakes nearly indistinguishable from legitimate apps.
Real Money, Real Targets
The primary goal of these attacks is financial gain, and the methods are becoming more direct. One of the most common scams involves abusing the UPI Collect Request feature. A fraudster will call with a convincing story about a refund or account verification and send a payment request, which many users approve without realising they are authorising a payment, not receiving one. Attackers also create fake investment platforms, luring victims through social media groups and convincing them to make repeated UPI payments into what they believe are profitable ventures. The banking and financial services sector is the prime target. Recent campaigns have impersonated major Indian banks like SBI, Axis Bank, and ICICI Bank, tricking customers into giving up sensitive data. Even government schemes are not immune, with fake PM-KISAN websites used to distribute malware. The sophistication of these attacks is evolving, with some criminals now using AI to generate hyper-personalised phishing messages in regional languages, making them even more difficult to spot.
Your First Line of Defense
While the threats are sophisticated, strong digital hygiene can significantly reduce your risk. First and foremost, never download applications from sources other than the official Google Play Store or Apple's App Store. Be wary of links sent via SMS, WhatsApp, or other messengers, even if they appear to be from a trusted source. Banks and legitimate companies will never ask for your PIN, OTP, or password. Always scrutinise UPI payment requests; if you are not expecting to pay someone, decline the request. Regularly review the permissions granted to your apps and uninstall any you don't recognise or use. Keep your phone's operating system and all your apps updated to ensure you have the latest security patches. If you receive a suspicious call or message, the safest action is to ignore it and contact your bank or the relevant service provider directly through their official website or customer service number. Despite high awareness of fraud, studies show that even educated users can fall victim to psychological manipulation, making vigilance a crucial habit for everyone.













