Common Types of Online and Mobile Banking Frauds in India

June 29, 2017

The proliferation of online banking frauds in India represents unauthorized financial diversions executed through digital communication channels, mobile applications, or intercepted banking credentials. Governed under the Information Technology Act, 2000, and regulatory directions issued by the Reserve Bank of India, cyber financial offences target digital payment mechanisms such as Unified Payments Interface (UPI), immediate payment services, and mobile banking portals. In combating online banking frauds India has strengthened regulatory coordination between banks and cyber cells. Victims dealing with online banking frauds in India have defined legal protections and statutory remedies available under Indian law to recover stolen banking funds.

Primary Digital and Mobile Banking Fraud Types

Modern cybercriminals deploy social engineering tactics and technological exploits to compromise user accounts. To investigate complex banking frauds India relies on digital forensics and rapid transaction freeze protocols. Understanding these patterns of online banking frauds in India helps banking consumers and legal practitioners identify systemic vulnerabilities, prevent banking frauds, and pursue appropriate legal relief across India.

Phishing and Vishing Scams

Phishing and vishing scams represent deceptive methods where fraudsters impersonate authorized banking representatives. Phishing typically involves fraudulent electronic mail directing recipients to counterfeit banking websites designed to capture login credentials, transaction passwords, and card details. Vishing utilizes voice telephone calls where scammers create artificial urgency, claiming urgent account suspension or debit card expiry to extract One-Time Passwords (OTPs) and card verification values.

A closely related variation is smishing, where short messaging service (SMS) texts deliver deceptive hyperlinks under the pretext of mandatory KYC updates, electricity bill payment warnings, or lottery prize claims. Once the victim clicks the link, malware is downloaded or sensitive information is entered directly onto a fake banking form.

SIM Swap Banking Fraud

A SIM swap banking fraud occurs when an attacker obtains a duplicate SIM card registered to the victim's mobile number by submitting forged identity documents to telecom service providers. Once the duplicate SIM is activated, the attacker intercepts incoming SMS alerts, authentication prompts, and financial OTPs, locking the legitimate subscriber out of cellular connectivity and initiating fraudulent fund transfers.

Because the victim's original mobile device loses network access, the account holder remains unaware of unauthorized debits until logging into online banking portals in India through alternative devices or reviewing physical banking account statements.

UPI Payment Collect Requests and Malicious QR Codes

The expansion of UPI and online banking transactions has created opportunities for fraudulent collect requests and manipulated quick response (QR) codes that affect online banking in India. Scammers send collect payment links disguised as incoming funds, misleading users into entering their secret UPI personal identification numbers. Because UPI PINs are required strictly for authorizing debits rather than receiving credits, unsuspecting users authorize outward fund transfers to illicit beneficiary banking accounts.

Fraudsters also place counterfeit QR code stickers across commercial merchant locations or send digital QR codes via messaging platforms claiming to process online marketplace payments, tricking sellers into transferring funds to the scammer instead of receiving sales proceeds.

Remote Access Applications and Mobile Trojans

Fraudsters frequently deceive consumers into downloading screen-sharing or remote device administration tools under the pretext of technical support, KYC verification, or reward point redemption. Once installed, these applications transmit live screen data, enabling unauthorized actors to observe credential inputs and capture financial tokens.

In addition, trojan-infected utility apps downloaded from unofficial third-party app repositories can operate covertly in the background, reading incoming notifications, logging keystrokes, and transmitting authentication messages directly to remote command-and-control servers.

Legal Framework Governing Cyber Banking Offences in India

Cyber financial crimes in India are prosecuted under the Information Technology Act, 2000, read alongside traditional penal provisions. Section 43 of the IT Act penalizes unauthorized extraction of data and system access, while Section 66 establishes criminal liability for computer-related offences. When perpetrators assume deceptive identities or misuse digital signatures and credentials, prosecutions invoke Section 66C for identity theft and Section 66D for cheating by personation.

The procedural prosecution of cyber fraud requires strict adherence to digital evidence handling. Electronic records such as server logs, IP access histories, and SMS gateway delivery receipts must satisfy evidentiary standards under The Indian Evidence Act, 1872. Courts emphasize the necessity of preserving digital audit trails during investigation stages, as highlighted in jurisprudence concerning electronic documentation and procedural compliance like Satish Shetty Vs. State of Karnataka [Supreme Court of India, 03-06-2016].

Furthermore, offenders face charges under the Indian Penal Code (and corresponding sections of the Bharatiya Nyaya Sanhita), including Section 419 (cheating by personation), Section 420 (cheating and dishonestly inducing delivery of property), and Section 468 (forgery for purpose of cheating).

RBI Digital Payment Safety Guidelines and Customer Liability

The Reserve Bank of India has established structured customer protection frameworks that limit account holder financial liability in unauthorized electronic banking transactions. The RBI digital payment safety guidelines outline clear liability thresholds based on reporting timelines and fraud origins:

  • Zero Customer Liability: Applicable when unauthorized transactions occur due to established bank negligence, system breaches, or third-party breaches where the customer notifies the financial institution within three working days of receiving the transaction alert.
  • Limited Customer Liability: When third-party fraud reporting is delayed between four and seven working days, customer liability is capped according to account categories, ranging from five thousand to twenty-five thousand rupees.
  • Customer Negligence: If an account holder voluntarily shares sensitive payment credentials such as OTPs or passwords, the customer bears the entire financial loss until the unauthorized transaction is formally reported to the bank.

In India, banking institutions are mandated to provide round-the-clock SMS and email alerts for every financial transaction, alongside direct banking mechanism channels for immediate card blocking and banking account freezing.

Immediate Steps for Reporting Cyber Banking Fraud

Prompt administrative and legal action is critical for asset recovery following a cyber financial security breach. Individuals discovering unauthorized debits must execute the following measures immediately:

  1. Bank Notification: Contact the issuing bank immediately through official customer care helplines or mobile banking portals to freeze the affected bank account and block linked debit or credit cards.
  2. National Cyber Crime Portal Registration: Lodge a formal complaint on the official National Cyber Crime Reporting Portal at cybercrime.gov.in or dial the national financial fraud helpline 1930 to initiate transaction hold requests with beneficiary banks.
  3. Police Complaint: File a formal written complaint with the local Cyber Crime Police Station, attaching complete bank account statements, SMS alert transcripts, and payment transaction references.
  4. Preservation of Digital Records: Preserve original email communications, call records, chat histories, and screenshot evidence to facilitate criminal prosecution and insurance claims.
  5. Banking Ombudsman Escalation: If the concerned financial institution fails to resolve the unauthorized transaction dispute within thirty days, escalate the matter to the RBI Integrated Ombudsman for formal adjudication.

Systematic reporting of online banking frauds in India safeguards consumer legal rights under banking regulations, supports statutory zero-liability claims, and enables law enforcement agencies to freeze illicit banking channels before funds are dispersed across multiple intermediary banking accounts.

Found this helpful?

Share this page with others