Financial fraud
Also called: cyber fraud, digital fraud · Topic: Payment Systems and Digital Finance · NCERT: Class 7, Ch 8 "Banks and the Magic of Finance"
Meaning
A financial fraud (also called cyber fraud or digital fraud) is a scam where a fraudster uses fake calls, fake messages or harmful apps to trick a person into sharing bank details, passwords, a UPI PIN or an OTP (one-time password), or into approving a payment, and then empties that person's bank account.
It matters because India's payments are now instant and mobile. Money can be stolen and moved away in minutes, and one trick can reach crores of users. Fighting fraud is now shared work for the RBI, NPCI, the Ministry of Home Affairs (MHA) and the Department of Telecommunications (DoT).
Explanation
How a fraud works
- The usual chain:
- The fraudster sends a fake call or message.
- The victim downloads a harmful app, or shares bank details or an OTP.
- This gives the fraudster access to the victim's phone or computer.
-
The fraudster steals personal data and drains the account.
-
The money then disappears fast:
- Stolen money is sent through mule accounts (bank accounts that are rented, bought or hijacked).
- It passes through many layers within minutes, so it becomes hard to trace.
How fraud changed over time
- Cheque era: mostly physical fraud, such as forged signatures and altered cheques.
- Card and net-banking era: card cloning (copying card data onto a fake card), stolen passwords and fake bank websites.
- UPI era (2016 onwards):
- Payments became instant and mobile.
- So fraud moved to tricking the person (social engineering) instead of breaking the system itself.
Types of fraud today
- Phishing: fake links or emails that look like they come from a bank or company. They open a fake page that steals passwords or card details.
- Vishing ("voice phishing"): the fraudster calls and pretends to be from the bank, the RBI, a courier company or the police.
- SIM swap: the fraudster gets a duplicate SIM of your number, so your OTPs go to their phone.
- QR and collect-request scams:
- The victim is told they will receive money.
- They scan a QR code, or approve a "collect request" by entering their UPI PIN.
- In fact they have paid money.
-
Key fact: you never need a PIN to receive money in UPI.
-
Fake customer-care numbers: fake helplines posted online. Callers are asked to share details or install a screen-sharing app.
- "Digital arrest":
- Fraudsters pretend to be police, CBI, customs or court officials.
- They "arrest" the victim on a video call and demand money to "clear their name".
-
There is no such thing as a digital arrest under Indian law.
-
Fake investment and trading scams: fake apps or WhatsApp and Telegram groups promise very high returns from stocks or crypto. Victims see "profits" on screen but can never withdraw them.
Why OTP helps, and where it fails
- Authentication means proving that you are really you.
- Two-factor authentication = something you know (the PIN) + something you have (the phone that gets the OTP).
- Why it helps: a thief who knows only your PIN still cannot pay without your phone.
- Where it fails: in phishing, vishing and SIM swap, the victim is tricked into giving away the OTP as well. This is why the RBI's 2025 rules move to wider, risk-based authentication.
- Personal safeguards (NCERT Class 7): never share your phone number, account number, address, passwords or OTPs with strangers. Do not click unknown links. Do not store passwords or PINs on your devices.
In India
- Reporting: I4C (MHA)
- Victims report on helpline 1930 (toll-free) or the National Cybercrime Reporting Portal (cybercrime.gov.in). Both are run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs.
- Why speed matters: a quick report → banks freeze the money before it moves on → the frozen money can later go back to the victim.
- More than ₹11,158 crore saved across more than 32.80 lakh complaints (PIB, 2026) [4].
- Suspect Registry (a shared list of fraud-linked identifiers kept by I4C with banks). Up to 30 June 2026:
- I4C blocked more than 3,962 Skype IDs and 83,668 WhatsApp accounts used in digital arrest scams [5].
-
In 2024, I4C warned about illegal payment gateways that transnational cybercriminals built using mule accounts. They offered "money laundering as a service" [6].
-
RBI: customer protection
- Limited liability rule (2017): you pay zero if you report an unauthorised transaction (one you did not make or approve) within three working days. If you report in 4–7 working days, your loss is capped (limited to a set amount). After 7 working days, the bank's board-approved policy decides.
- Worked example: ₹40,000 is stolen from your account by fraud.
- Report on day 2 → you lose ₹0, and the bank credits back ₹40,000.
- Report on day 5 → you bear only up to the cap, and the rest is refunded.
- Report on day 12 → the bank's own policy decides how much you get back.
- Integrated Ombudsman Scheme (2021): "One Nation, One Ombudsman". An ombudsman is an official who settles customer complaints free of cost. One ombudsman now covers banks, NBFCs and payment system operators.
- Fraud-risk management Master Directions (2024): rules on how banks must detect, classify and report frauds.
- MuleHunter.AI: an AI tool built by the Reserve Bank Innovation Hub (RBIH) to find mule accounts inside banks.
-
"bank.in" domains: a web address ending used only by genuine bank websites, so fake sites are easier to spot.
-
RBI (Authentication mechanisms for digital payment transactions) Directions, 2025
- Issued on 25 September 2025. Must be followed from 1 April 2026 [2].
- Every domestic digital payment needs at least two distinct factors of authentication, unless it is exempted [2].
- At least one factor must be dynamic, which means it is created fresh for each transaction and is unique to it [2].
- Issuers may add risk-based checks, such as behaviour patterns and device details [2].
- Other allowed options include behavioural biometrics, location and payment history, digital tokens and in-app notifications [3].
- SMS OTP is not banned. It is still a valid factor [3].
- If a payment goes through without following these rules, the issuer must compensate the customer in full "without demur" (without arguing) [2].
- Card issuers must check non-recurring cross-border Card Not Present (CNP) transactions (online payments made without the physical card) by 1 October 2026 [2][3].
-
System providers must offer an authentication or tokenisation service that works across all apps and channels [2]. Tokenisation means your real card number is replaced by a random code (a "token"), so merchants never store the real number.
-
NPCI: built-in UPI protections [7]
- Device binding: your UPI account is tied to your mobile number and your particular phone.
- Two-factor authentication through the UPI PIN.
- Daily transaction limits.
-
A fraud-monitoring system for all banks that uses AI/ML (artificial intelligence and machine learning) models to flag suspicious payments.
-
DoT
- Sanchar Saathi: block a lost or stolen phone, and check which mobile connections are issued in your name. This helps stop SIM-based fraud.
-
Chakshu (a feature inside Sanchar Saathi): report suspected fraud calls and messages.
-
Data pattern (RBI Annual Report): card and internet frauds lead by number (many small cases). Loan (advances) frauds lead by value (few cases, very large amounts).
Don't confuse with
- Loan (advances) fraud: this is about big corporate borrowers cheating banks. It leads by value. Card and internet fraud hits crores of small users one by one, so it leads by number.
- 1930 / cybercrime.gov.in vs RBI Integrated Ombudsman: 1930 and the portal belong to I4C (MHA). They are for reporting the crime quickly so money can be frozen. The Ombudsman (RBI, 2021) settles complaints against a bank, NBFC or payment operator.
- Sanchar Saathi / Chakshu vs MuleHunter.AI: Sanchar Saathi and Chakshu are DoT tools against misuse of phones and SIMs. MuleHunter.AI is an RBIH tool that finds mule bank accounts.
- Real arrest vs "digital arrest": a real arrest follows legal procedure. A "digital arrest" over a video call has no legal basis in India. It is always a scam.
Prelims Hooks
- 1930 and cybercrime.gov.in are run by I4C under the Ministry of Home Affairs, not the RBI.
- RBI limited liability rule (2017): report within 3 working days → zero liability. Report in 4–7 working days → liability is capped.
- RBI Authentication Directions 2025: at least two factors, and at least one must be dynamic. Compliance from 1 April 2026. SMS OTP is not discontinued [2][3].
- MuleHunter.AI comes from the Reserve Bank Innovation Hub, not NPCI or MeitY. Sanchar Saathi and Chakshu belong to DoT.
- Trap: in UPI, entering a PIN always means paying, never receiving.
- Trap: card and internet frauds are highest by number, but advances (loan) frauds are highest by value.
Mains Points
- Scale versus safety: a layered answer
- UPI made payments instant and cheap. The same speed made fraud fast and wide-scale.
-
The answer works in three layers:
-
Mule accounts are the choke point
- All stolen money has to pass through bank accounts, so finding mule accounts is where fraud can be stopped.
- Examples: MuleHunter.AI, and the Suspect Registry (32.08 lakh Layer 1 mule accounts shared; ₹25,698 crore of transactions declined, up to June 2026) [4][6].
-
This links to weak KYC checks and to financial-inclusion accounts that people rent out.
-
Federalism and liability design
- "Police" is a State subject, but cyber-fraud crosses States and countries. I4C, RBI, NPCI and DoT must work together (GS-II Centre–State relations; GS-III internal security).
- Zero liability and full compensation put the cost on banks, so banks have a reason to invest in fraud detection. But if the customer reports late, the loss shifts back to them. That makes financial literacy a necessary part of consumer protection [2].
Related concepts
Read more
Sources
- 1Class 7, Ch 8 "Banks and the Magic of Finance" (primary)
- 2Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025rbi.org.in · tier 1
- 3RBI Press Release, 25 September 2025 (Authentication Directions; alternative authentication mechanisms)rbidocs.rbi.org.in · tier 1
- 4PIB — National Cybercrime Response Mechanismpib.gov.in · tier 1
- 5PIB — Incidents of Digital Arrestpib.gov.in · tier 1
- 6PIB — I4C, MHA alert against illegal payment gateways created using mule bank accountspib.gov.in · tier 1
- 7PIB — Digital Payment Transactions Surge With Over 18,000 Crore Transactions in 2024-25 (UPI fraud-prevention measures)pib.gov.in · tier 1