Financial frauds and cyber safety
Payment Systems and Digital Finance · section 10 of 10
In this note
Detail
1. What a financial fraud is
- A financial fraud is a scam that uses fake calls, fake messages or harmful apps to steal bank details or OTPs and then empty a person's bank account.
- How it works, step by step:
- The fraudster sends a fake call or message.
- The victim downloads a harmful app, or shares bank details or an OTP.
- This "gives them access to the user's mobile or computer".
-
The fraudster steals personal data and drains the bank account.
-
How fraud changed over time:
- Cheque era: frauds were mostly physical, such as forged signatures and altered cheques.
- Card and net-banking era: card cloning (copying card data onto a fake card), stolen passwords and fake bank websites became common.
- UPI era (2016 onwards): payments are now instant and mobile. So fraud became mostly about tricking the person (social engineering) rather than breaking the system itself.
2. Newer fraud patterns
- Phishing: fake links or emails that look like they come from a bank or company. They lead to a fake page that steals passwords or card details.
- Vishing: "voice phishing". The fraudster calls and pretends to be from the bank, the RBI, a courier company or the police.
- SIM swap: the fraudster gets a duplicate SIM of your mobile number. Your OTPs then go to their phone, not yours.
- QR and collect-request scams:
- The victim is told they will receive money.
- They scan a QR code, or approve a "collect request" by entering their UPI PIN.
- In fact they have paid money.
-
Key fact: you never need to enter a PIN to receive money in UPI.
-
Fake customer-care numbers: fraudsters post fake helpline numbers online. Victims who call them are asked to share details or install a screen-sharing app.
- Mule accounts: bank accounts that are rented, bought or hijacked and used to move stolen money quickly through many layers. This makes the money hard to trace.
-
I4C (MHA) issued an alert about illegal payment gateways that transnational cybercriminals built using mule bank accounts. They offered "money laundering as a service" (2024) [6].
-
"Digital arrest":
- Fraudsters pretend to be police, CBI, customs or court officials.
- Over a video call, they "arrest" the victim and threaten them.
- They demand money to "clear their name".
- There is no such thing as a digital arrest under Indian law.
-
I4C has found and blocked more than 3,962 Skype IDs and 83,668 WhatsApp accounts used for digital arrest scams [5].
-
Fake investment and trading scams: fake apps or WhatsApp and Telegram groups promise very high returns from stocks or crypto. Victims can see "profits" on screen but can never withdraw them.
3. Personal safeguards (Class 7, Fig. 8.23)
- Never share your phone number, account number, home address, passwords or OTPs with strangers.
- Avoid clicking unknown links or videos received in messages.
- Do not store account passwords, debit card PINs and similar details on your devices.
- One-Time Password (OTP): a unique, temporary code of letters or numbers. It is used to verify who you are or to approve a transaction.
- It is a one-time second factor of authentication.
- Authentication means proving that you are really you.
- Two-factor authentication = something you know (the PIN) + something you have (the phone that receives the OTP).
- Why it helps: a thief who knows only your PIN still cannot pay without your phone.
-
Where it fails: in phishing, vishing and SIM swap, the victim is tricked into handing over the OTP too. That is why the RBI is moving beyond SMS OTP (see §5).
-
Built-in UPI protections [7]:
- Device binding: your UPI account is tied to your mobile number and your particular phone.
- Two-factor authentication through the UPI PIN.
- Daily transaction limits.
- NPCI fraud-monitoring solution for all banks, which uses AI/ML (artificial intelligence and machine learning) models to raise alerts about suspicious payments.
4. How to report a fraud
- Helpline 1930 (toll-free), or the National Cybercrime Reporting Portal (cybercrime.gov.in).
- Both are run by MHA's Indian Cyber Crime Coordination Centre (I4C).
- Why speed matters:
- Stolen money moves through mule accounts within minutes.
- A quick report lets banks freeze the money before it moves further.
-
Frozen money can later be returned to the victim.
-
Results: more than ₹11,158 crore saved across more than 32.80 lakh complaints (PIB, 2026) [4].
- Suspect Registry (a shared list of fraud-linked identifiers kept by I4C with banks):
- Up to 30 June 2026, more than 30.48 lakh suspect identifiers had been received from banks [4].
- 32.08 lakh "Layer 1" mule accounts (accounts where stolen money lands first) had been shared with participating entities [4].
- Transactions worth ₹25,698 crore were declined as a result [4].
5. RBI customer protection
- Limited liability rule (2017):
- Zero customer liability if an unauthorised transaction (one the customer did not make or approve) is reported within three working days.
- Reported in 4–7 working days → the customer's loss is capped (limited to a set amount).
- Reported after 7 working days → the bank's board-approved policy decides.
-
Worked example: ₹40,000 is taken from your account by fraud.
- Report on day 2 → you lose ₹0, and the bank credits back ₹40,000.
- Report on day 5 → you bear only up to the cap. The rest is refunded.
- Report on day 12 → the bank's own policy decides how much you get back.
-
RBI Integrated Ombudsman Scheme (2021):
- An ombudsman is an official who settles customer complaints free of cost.
-
This scheme gives one ombudsman for banks, NBFCs and payment system operators ("One Nation, One Ombudsman").
-
Fraud-risk management Master Directions (2024): rules for how banks must detect, classify and report frauds.
- MuleHunter.AI: an AI tool built by the Reserve Bank Innovation Hub (RBIH) to find mule accounts inside banks.
- "bank.in" domains: a web address ending only for genuine bank websites. Customers can spot fake sites more easily.
- New authentication rules: RBI (Authentication mechanisms for digital payment transactions) Directions, 2025
- Issued 25 September 2025. Must be followed from 1 April 2026 [2].
- All domestic digital payments need at least two distinct factors of authentication, unless exempted [2].
- At least one factor must be dynamic, meaning it is created fresh for each transaction and is unique to it [2].
- Issuers may add risk-based checks beyond the two-factor minimum, for example behaviour patterns and device details [2].
- Other options that can be used include behavioural biometrics, location and payment history, digital tokens and in-app notifications [3].
- SMS OTP is not banned. It remains a valid factor [3]. (NCERT scaffold: "move beyond SMS OTP", marked "verify current". This is the current position.)
- If a payment goes through without following these rules, the issuer must compensate the customer in full "without demur" (without arguing) [2].
- Cross-border card payments: card issuers must check non-recurring cross-border Card Not Present (CNP) transactions (online payments made without the physical card) by 1 October 2026 [2][3].
- System providers must offer an authentication or tokenisation service that works across all apps and channels [2].
- Tokenisation: your real card number is replaced by a random code (a "token"). A merchant never stores your actual card number.
6. Department of Telecommunications (DoT)
- Sanchar Saathi: a portal to block lost or stolen phones and to check which mobile connections are issued in your name. This helps stop SIM-based fraud.
- Chakshu (a feature inside Sanchar Saathi): report suspected fraud calls and messages.
7. Fraud data pattern
- RBI Annual Report:
- Card and internet frauds lead by number. There are many small cases.
-
Loan (advances) frauds lead by value. There are few cases, but they involve very large amounts.
-
Why: digital frauds hit crores of small users one by one. Loan frauds involve big corporate borrowers.
- Bank-fraud and NPA details are covered in banking-regulation-npas.
8. The balance (Class 7, question 8)
- The question: how can we keep the convenience of digital payments while limiting the risk of cyber fraud?
- Technology: tokenisation, device binding, dynamic authentication factors, and AI monitoring (NPCI's fraud models, MuleHunter.AI) [2][7].
- Regulation: zero or limited liability, the issuer's duty to compensate in full, the Integrated Ombudsman, and the Suspect Registry [2][4].
- Financial literacy: knowing that you never need a PIN to receive money, that "digital arrest" does not exist, and that you should report on 1930 fast.
Prelims Hooks
- 1930 is the national cyber-fraud helpline. It and cybercrime.gov.in are run by I4C under the Ministry of Home Affairs, not the RBI.
- Customer reports an unauthorised transaction within 3 working days → zero liability. In 4–7 days → liability is capped (RBI, 2017).
- MuleHunter.AI was developed by the Reserve Bank Innovation Hub. It is not an NPCI or MeitY tool.
- Sanchar Saathi and Chakshu belong to the Department of Telecommunications, not the RBI or MHA.
- RBI Authentication Directions 2025: at least two factors, of which at least one must be dynamic. Compliance from 1 April 2026. SMS OTP is not discontinued [2][3].
- Integrated Ombudsman Scheme (2021) covers banks, NBFCs and payment system operators together.
- Trap: in UPI, entering a PIN always means paying, never receiving.
- Trap: card and internet frauds are highest by number, but advances (loan) frauds are highest by value.
- "Digital arrest" has no legal basis. Blocked accounts include 3,962 Skype IDs and 83,668 WhatsApp accounts [5].
Mains Points
- Scale versus safety: India's instant, low-cost payments such as UPI made fraud fast and wide-scale. The answer is layered: device binding and dynamic authentication (technology), full compensation when issuers fail (regulation), and reporting to 1930 within the "golden hour" (citizen action) [2][4][7].
- Mule accounts are the choke point:
- Stolen money has to pass through bank accounts.
- So finding mules is where fraud can be stopped: MuleHunter.AI, the Suspect Registry (32.08 lakh Layer 1 mule accounts; ₹25,698 crore of transactions declined, up to June 2026).
-
This connects to weak KYC checks and to financial inclusion accounts that are rented out [4][6].
-
Cooperative federalism problem:
- "Police" is a State subject, but cyber-fraud crosses States and countries.
- I4C (MHA), the RBI, NPCI and DoT all play a role, so coordination between them matters most.
-
Link to GS-II (Centre–State relations) and GS-III (internal security and cybersecurity).
-
Liability design as an incentive:
- Zero customer liability, and full compensation when authentication rules are not followed, push the cost onto banks.
- Banks then have a reason to invest in fraud detection.
- But a delay in reporting shifts the risk back to the customer. So financial literacy is a necessary part of consumer protection [2].
Sources
- 1Class 7, Ch 8 "Banks and the Magic of Finance"; Class 7, Ch 11 "From Barter to Money"; Class 12, Ch 3 "Money and Banking"; Class 10, Ch 3 "Money and Credit" (primary)
- 2Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025rbi.org.in · tier 1
- 3RBI Press Release, 25 September 2025 (Authentication Directions; alternative authentication mechanisms)rbidocs.rbi.org.in · tier 1
- 4PIB — National Cybercrime Response Mechanismpib.gov.in · tier 1
- 5PIB — Incidents of Digital Arrestpib.gov.in · tier 1
- 6PIB — I4C, MHA alert against illegal payment gateways created using mule bank accountspib.gov.in · tier 1
- 7PIB — Digital Payment Transactions Surge With Over 18,000 Crore Transactions in 2024-25 (UPI fraud-prevention measures)pib.gov.in · tier 1