Author: Himanshu Mishra

  • Cloud Storage Scam Emails Australia 2026: Fake Google and iCloud Alerts

    Cloud Storage Scam Emails Australia 2026: Fake Google and iCloud Alerts

    If you have received an email saying your Google Drive, iCloud or OneDrive storage is full and you need to act immediately, stop right there. Chances are, it is a scam. Thousands of Australians are receiving these fake cloud storage emails every week in 2026, and many are losing their personal data and money because of them.

    A cloud storage scam email is a fake message pretending to be from Google, Apple or Microsoft. It warns you that your storage is full and pushes you to click a link. That link leads to a fake website designed to steal your login credentials or payment information. In 2026, these phishing emails are targeting Australians at record rates.

    This guide will help you identify these scam emails, understand how they work and know exactly what to do if you receive one.

    What Are Cloud Storage Scam Emails?

    Cloud storage scam emails are phishing messages designed to look like official notifications from Google, Apple or Microsoft. They tell you that your storage is almost full or has been compromised, and they push you to click a link to “upgrade” or “fix” the issue.

    The link takes you to a fake website that looks identical to the real login page. Once you enter your email and password, scammers steal your credentials. In some cases, they also ask for credit card details to process a fake storage upgrade payment.

    These emails are not new, but in 2026 they have become far more convincing because scammers are now using AI tools to write cleaner, more professional looking emails that are harder to distinguish from the real thing.

    Why Are Australians Being Targeted?

    Australia has one of the highest rates of cloud service adoption in the Asia Pacific region. Most Australians use at least one cloud platform for personal photos, work documents or backups. Scammers know this and they exploit it.

    According to ScamWatch, Australians reported over 74,000 phishing incidents in 2023, making it one of the most reported scam types in the country. Cloud storage phishing has emerged as one of the fastest growing variants of this threat in 2026.

    The timing also matters. Scammers often send these emails during busy periods like tax season (July to October) or the holiday shopping season when people are more likely to click without thinking.

    A Real Example from Australia

    In early 2026, a Melbourne woman lost complete access to her iCloud account after clicking a fake storage warning email. The scammers locked her out and accessed over 10 years of family photos, personal documents and saved passwords. They then demanded payment to restore access. By the time she contacted Apple support, the damage was already done. Her case was reported through IDCARE and is now part of an ongoing investigation.

    Stories like hers are becoming more common across Australia every month.

    What Do These Scam Emails Look Like?

    Here are real examples of subject lines being used in 2026.

    1. Fake Google Email: “Your Google Drive storage is 98% full. Upgrade now to avoid losing your files.”
    2. Fake Apple Email: “Your iCloud storage is full. Photos and backups will stop syncing. Tap here to manage your plan.”
    3. Fake Microsoft Email: “OneDrive Alert: Your storage has exceeded the free limit. Verify your account to continue.”

    These emails typically include official looking logos, proper formatting and even fake footer links to privacy policies and help centres. At first glance, they look completely real.

    How This Scam Actually Works

    Understanding the step by step process helps you spot it before any damage is done.

    Step 1: You receive an email that appears to be from Google, Apple or Microsoft.

    Step 2: The email warns you about a storage problem and creates urgency. Words like “immediate action required” or “your files will be deleted” are common.

    Step 3: You click the link and land on a website that looks exactly like the real login page.

    Step 4: You enter your email address and password thinking you are signing into your real account.

    Step 5: Scammers now have your login credentials. They can access your emails, photos, documents and contacts.

    Step 6: In many cases, the fake site also asks for payment details to process an “upgrade.” If you enter your card details, unauthorised charges will follow.

    Also Check: Depop Social Media Scams in Australia 

    Red Flags to Identify Fake Cloud Storage Emails

    Before you click anything, check for these warning signs.

    The sender email address does not match the official domain. Google emails come from @google.com, not @google-storage-alert.com.

    The email creates extreme urgency with phrases like “act within 24 hours or lose all data.”

    The link URL does not match the official website. Hover over the button without clicking to see where it actually leads.

    The email asks you to enter your password or payment details through a link. Google, Apple and Microsoft will never ask for this via email.

    There is no personalisation. The email says “Dear User” instead of your actual name.

    The email arrived in your spam or junk folder. Your email provider has already flagged it as suspicious.

    Real vs Fake Cloud Storage Emails

    FeatureReal EmailScam Email
    Sender Address@google.com or @apple.comRandom or misspelled domain
    PersonalisationUses your full nameSays “Dear User” or “Dear Customer”
    LinksLead to official websiteLead to unknown domain
    UrgencyGentle reminderThreatening language
    Payment RequestDirects to app settingsAsks for card details via link
    GrammarProfessional Australian EnglishMay have subtle errors
    Unsubscribe OptionWorking official linkMissing or fake

    Also Read: AI Powered Bank Scams in Australia 2026

    What to Do If You Clicked the Link

    If you have already clicked a link or entered your details, take these steps immediately.

    • Change your password right now. Go directly to the official website and update your password for the affected account. Do not use the link from the email.
    • Enable two factor authentication. This adds an extra layer of security so that even if scammers have your password, they cannot access your account without a verification code.
    • Check your account activity. Google, Apple and Microsoft all allow you to review recent sign in activity. Look for any logins from unfamiliar locations or devices.
    • Contact your bank. If you entered credit card or payment details, call your bank immediately. Request a card block and dispute any unauthorised transactions.
    • Scan your device. Run a full antivirus scan on your phone or computer to check for any malware that may have been installed.
    • Report the scam. Report the email to the relevant authorities and delete it from your inbox.

    How to Report Cloud Storage Scam Emails in Australia

    Reporting helps authorities track and shut down these operations. Here is where to report.

    • ScamWatch (ACCC): Visit scamwatch.gov.au to lodge a report about the scam email you received.
    • ReportCyber: Visit cyber.gov.au/report to report the phishing attempt to the Australian Cyber Security Centre.
    • Google: Open the suspicious email in Gmail, click the three dot menu next to the reply button and select “Report Phishing.” This sends the email directly to Google’s security team for review.
    • Apple: Forward suspicious iCloud emails to reportphishing@apple.com. This is the official email address confirmed by Apple Support.
    • Microsoft: If you use Outlook, select the suspicious email, click “Report” in the toolbar and then select “Report Phishing.” If you are a Microsoft 365 business user, you can also forward the email to phish@office365.microsoft.com for investigation.
    • IDCARE: If your personal information has been compromised, contact idcare.org for free identity and cyber security support. IDCARE is Australia and New Zealand’s national identity protection service.

    How to Protect Yourself Going Forward

    1. Never click links in storage warning emails. Instead, open your browser and go directly to drive.google.com, icloud.com or onedrive.com to check your actual storage status.
    2. Use a password manager to create unique passwords for every account. If one password gets stolen, your other accounts stay safe.
    3. Turn on two factor authentication on all cloud accounts. This is the single most effective way to prevent unauthorised access.
    4. Keep your operating system and apps updated. Security patches fix vulnerabilities that scammers try to exploit.
    5. If you want to verify whether a suspicious link is safe before clicking, you can use our free URL Checker Tool to analyse it instantly.
    6. Received a suspicious message that does not look right? Run it through our Scam Message Checker to find out if it is legitimate or a phishing attempt.

    Frequently Asked Questions

    Does Google actually send emails about storage being full?

    Yes, Google does send legitimate storage notifications. But Google will never ask you to click a link to enter your password or payment details directly. You can always check your real storage status at one.google.com.

    Can scammers access my photos if I fall for this scam?

    Yes. If scammers get your cloud login credentials, they can access everything stored in your account including photos, documents, emails and contacts. In some cases they may also lock you out of your own account.

    What if I only clicked the link but did not enter any details?

    If you only visited the page without entering any information, your risk is lower. However, run an antivirus scan on your device as some phishing pages can install tracking software automatically when the page loads.

    Are these scams only targeting Gmail users?

    No. These scams target users of Google Drive, Apple iCloud, Microsoft OneDrive and even Dropbox. Anyone using cloud storage services can be a target regardless of which platform they use.

    How can I tell if a storage email is real or fake?

    Always check the sender email address, hover over any links without clicking to see the real URL, and verify your storage directly through the official app or website. Real companies will never ask you to enter passwords or payment details through an email link.

  • Depop Social Media Scams in Australia: Spot Fake Sellers Before Paying

    Depop Social Media Scams in Australia: Spot Fake Sellers Before Paying

    If you are buying or selling on Depop Australia, there is something you need to know. Scammers are everywhere on this platform, and they are getting smarter every single day.

    I have spent weeks researching depop scams, going through real complaints from Australian users, checking Reddit threads, and analysing how scammers on depop actually operate. What I found was honestly alarming.

    Whether you are a buyer looking for vintage finds or a seller trying to make some extra cash, this guide will help you identify depop social media scams, protect your bank account, and know exactly what to do if you get scammed on depop.

    Is Depop Legit or Just Another Dodgy Platform?

    Let me clear this up straight away. Depop itself is a legitimate marketplace. It is owned by Etsy, has millions of users worldwide, and does depop work in Australia? Yes, absolutely. Australian users can buy, sell, and ship items within the country and internationally.

    But here is the catch.

    While the platform is legit, not every person on it is. Depop is a peer to peer marketplace, which means anyone can create an account and start selling. And that is exactly where the problem begins.

    Think of it like Gumtree or Facebook Marketplace. The platform is real, but the people using it can be dodgy. So when someone asks “is depop legit,” the honest answer is yes, the app is legit, but you still need to be careful about who you are dealing with.

    Depop reviews from Australian users are mixed. Some people love it for finding unique second hand fashion. Others have shared nightmare stories about getting scammed on depop and never seeing their money again.

    Common Depop Scams in Australia You Need to Know

    Based on real complaints from Australian buyers and sellers, here are the most common scams on depop right now in 2026.

    1. The “Pay Outside the App” Scam

    This is the biggest one. A seller or buyer asks you to pay through PayPal Friends and Family, direct bank transfer, or some random payment link instead of using Depop payments.

    Why is this dangerous? Because Depop buyer protection only covers transactions made through the app. The moment you pay outside, you lose all protection. If the item never arrives or turns out to be fake, Depop cannot help you.

    Australian users fall for this more than you would think because the scammer usually offers a “discount” for paying directly. Do not fall for it. Ever.

    2. Fake Designer Items

    Depop is massive for vintage and designer fashion. Scammers know this. They list fake designer bags, shoes, and clothing with stolen photos from legitimate sellers or brand websites.

    You pay full price thinking you are getting an authentic Gucci bag. What arrives is a $15 knockoff from overseas, if anything arrives at all.

    How to spot this:

    • Ask for tagged photos with the seller’s username written on paper
    • Request close up shots of labels, stitching, and hardware
    • Check if the same photos appear on other accounts or websites
    • If the price seems too good for a designer item, it probably is

    3. The “Item Not as Described” Trick

    This one is sneaky. The seller posts photos of a perfect item. What you receive is stained, damaged, or completely different from what was shown. When you complain, they block you or stop responding.

    Some scammers on depop even use photos from other listings or older seasons to make their items look better than they actually are.

    4. Fake Tracking Number Scam

    You buy something. The seller marks it as shipped and uploads a tracking number. But when you check the tracking, it either shows delivered to a completely different address or the tracking number belongs to someone else’s parcel entirely.

    This is a clever way for depop scammers to make it look like they have fulfilled the order while never actually sending your item. By the time you figure it out, the dispute window might have closed.

    5. The Refund Reversal Scam (For Sellers)

    If you are selling on Depop Australia, watch out for this one. A buyer purchases your item, receives it, and then files a dispute claiming it never arrived or was “not as described.” They get a refund through Depop or PayPal while keeping your item.

    This scam has hit Australian sellers hard, especially those selling higher value items. Some sellers have reported losing hundreds of dollars this way.

    Also Read: AI Powered Bank Scams Australia 2026: How Aussies Are Being Targeted

    Is Depop Safe for Your Bank Account?

    This is one of the most searched questions by Australian users, and rightfully so. You are linking your bank account or card to an app where strangers buy and sell. It makes sense to be worried.

    Here is what you need to know about depop payments in Australia.

    Depop uses its own payment system powered by Stripe. When you make a purchase through the app, your payment details are processed securely through Stripe, not shared directly with the seller. This is actually safer than paying through direct bank transfer.

    Your bank account is safe as long as you:

    • Only pay through the Depop app, never outside it
    • Never share your banking details in messages
    • Do not click on links sent by other users claiming to be “Depop support”
    • Enable two factor authentication on your account

    The real danger to your bank account is not Depop itself. It is phishing scams where someone pretends to be Depop and tricks you into entering your details on a fake website. Always check the URL before logging in.

    What to Do If You Get Scammed on Depop

    If you have already been scammed, do not panic. Here is exactly what you need to do, step by step.

    Step 1: Screenshot everything. Save the listing, messages, payment confirmation, and tracking details. Do not let the scammer delete evidence by blocking you first.

    Step 2: Open a dispute through Depop. Go to the transaction, tap “I have a problem,” and describe what happened. Depop refunds are possible if you paid through the app and can prove the item was not received or not as described.

    Step 3: If you paid through PayPal, open a dispute there as well. PayPal has its own buyer protection program that covers you for up to 180 days.

    Step 4: Contact your bank. If you paid by card, you can request a chargeback. Australian banks are generally quite helpful with fraud disputes, especially if you have evidence.

    Step 5: Report the account to Depop. The more reports a scammer gets, the faster Depop suspends them. You can also report to the ACCC (Australian Competition and Consumer Commission) if the amount is significant.

    Step 6: If you need direct help, reach out through the Depop helpline or their in app support. There is no public depop customer service number for Australia, but their in app support and email support do respond, usually within 48 to 72 hours.

    Depop Australia Reviews: What Real Users Are Saying in 2026

    I went through dozens of depop reviews from Australian users on Reddit, Trustpilot, and Product Review AU. Here is the honest picture.

    What people love:

    • Great for finding unique vintage and second hand clothing
    • Easy to list items and start selling
    • Depop shipping cost in Australia is reasonable for smaller items
    • The community feel and aesthetic of the platform

    What people hate:

    • Customer support is slow and sometimes unhelpful
    • Scammers are not removed fast enough
    • Depop account suspended sometimes happens to legitimate sellers without clear explanation
    • Depop payment methods are limited compared to other platforms
    • Seller fees eat into profits

    The overall sentiment? Depop is a solid platform if you know how to protect yourself. But if you go in blindly trusting every seller, you are setting yourself up for a bad experience.

    7 Rules to Stay Safe on Depop in Australia

    1. Always pay through the app. No exceptions. No “special discounts” for direct transfer.
    2. Check the seller’s history. Look at their reviews, how long they have been active, and how many sales they have made. New accounts with no reviews selling expensive items are a red flag.
    3. Reverse search product photos. Right click on the image and search Google. If the same photos appear on multiple accounts, it is likely a scam.
    4. Never share personal details in chat. Your address is shared securely through the transaction. You do not need to send it in messages.
    5. Use Depop’s built in shipping labels when selling. This gives both parties tracking and proof of delivery.
    6. Be suspicious of urgency. “Buy now before someone else does” or “I can only hold this for an hour” are classic pressure tactics used by scammers on depop.
    7. Trust your gut. If something feels off about a listing or a conversation, walk away. There will always be another deal.

    Final Thoughts

    Depop social media scams in Australia are real, and they are not slowing down. Scammers are getting more creative, their fake listings look more convincing, and they know exactly how to exploit the platform’s gaps.

    But here is the good news. Now you know exactly how they operate. You know what depop scams look like, how to check if depop is safe for your situation, and what to do if you get scammed on depop.

    The platform itself is not the problem. It is the people who misuse it. Stay sharp, follow the safety rules in this guide, and you will be able to enjoy everything Depop Australia has to offer without losing a single dollar.

    If this guide helped you, share it with someone who shops on Depop. One share could save someone from getting scammed.

  • Online Shopping Scams in India: Spot Fake Sites Before Paying Online

    Online Shopping Scams in India: Spot Fake Sites Before Paying Online

    Every day, thousands of Indians lose their hard earned money to online shopping scams. From fake shopping sites offering “90% off” deals to pyramid schemes like Safe Shop, digital scams are growing faster than ever in India.

    If you have ever wondered what is online fraud and how it actually works, you are in the right place. In this guide, I will break down real online shopping fraud cases, show you how to identify fake shopping websites, and give you practical steps to protect yourself in 2026.

    Let me be honest. I have personally come across multiple fake shopping sites while researching for this blog. Some of them looked so real that even I had to double check. That is exactly why this guide exists.

    What is Internet Fraud and Why Should You Care?

    Internet fraud is any illegal activity where someone uses the internet to steal money, personal data, or both. When we talk specifically about what is online fraud in the context of shopping, it means scammers creating fake platforms or offers to trick you into paying for products that never arrive.

    India reported over 11 lakh cyber crime complaints in 2024 alone, according to the National Cyber Crime Reporting Portal. And a large chunk of these were related to online shopping scams in India.

    The problem? Most people do not even report these scams because the amount lost feels “too small.” But when you add it all up, we are talking about thousands of crores every year.

    How Do Online Shopping Scams Actually Work?

    Before I list the types, let me explain the basic pattern that most digital scams follow. Understanding this pattern will help you spot any new scam, even the ones that do not exist yet.

    The usual flow looks like this:

    1. You see an unbelievable deal on social media or WhatsApp
    2. You click and land on a website that looks professional
    3. You place an order and make the payment
    4. Either the product never arrives, or you get a cheap knockoff
    5. When you try to contact customer support, the number is dead

    Simple. Effective. And thousands of Indians fall for it every single week.

    Types of Online Shopping Fraud in India (2026)

    1. Fake Shopping Sites with Huge Discounts

    These are standalone websites that copy the design of popular brands. They run Instagram and Facebook ads showing branded products at 70 to 90 percent off.

    Red flags to watch for:

    • Domain registered only a few weeks ago
    • No physical address or GSTIN mentioned
    • Only prepaid payment options, no cash on delivery
    • Too good to be true pricing
    • Poor grammar and blurry product images

    Quick tip: Before buying from any new website, check its domain age on Whois. If it was registered less than 6 months ago, stay away.

    2. Fake Seller Accounts on Legitimate Platforms

    Even on trusted platforms like Amazon, Flipkart, and Meesho, some sellers create fake accounts. They list products at low prices, collect orders, and either send empty boxes or never ship at all.

    How to protect yourself:

    • Always check seller ratings and reviews
    • Look for “Fulfilled by Amazon” or “Flipkart Assured” tags
    • Avoid sellers with zero reviews or brand new accounts

    3. Social Media Shopping Scams

    This is probably the fastest growing category of online scams in India right now. Scammers run paid ads on Instagram and Facebook with stolen product photos. They create urgency with phrases like “Only 2 left” or “Sale ends tonight.”

    I personally tracked one such Instagram page last month. It had 50,000 followers, all bought. The comments were full of bots saying “Received my order, quality is amazing.” But when I reverse searched their product photos, they were stolen from AliExpress listings.

    4. WhatsApp and Telegram Shopping Scams

    You get added to a group. Someone shares a Google Form or a direct UPI link for discounted electronics or branded clothes. You pay. Product never comes. And you get removed from the group.

    This is extremely common in tier 2 and tier 3 cities where people trust WhatsApp forwards more than official websites.

    Safe Shop Scams: India’s Biggest MLM Shopping Fraud

    Let me talk about this in detail because Safe Shop frauds have affected lakhs of Indians, mostly in smaller towns and rural areas.

    Safe Shop, also known as Safe Shop India, presented itself as a direct selling or network marketing company. They sold overpriced products like tablets, health supplements, and educational courses. But the real “business” was not about selling products. It was about recruiting new members.

    Here is how the Safe Shop scam worked:

    • You paid a joining fee, usually between Rs 3,000 to Rs 12,000
    • You received a low quality product that was worth a fraction of what you paid
    • To earn money, you had to recruit more people under you
    • The people at the top made money while those at the bottom lost everything

    The FTC and even Indian consumer courts have flagged such models as pyramid schemes. Multiple complaints were filed on consumer forums and the National Consumer Helpline against Safe Shop.

    Why did so many people fall for it?

    Because the pitch was emotional. Recruiters showed fake income proof, rented luxury cars for seminars, and promised “financial freedom.” In states like Bihar, Jharkhand, UP, and Rajasthan, thousands of students, unemployed youth, and small town workers invested their savings.

    If someone is pitching you a “business opportunity” where the income depends more on recruitment than actual product sales, it is almost certainly a scam. Walk away.

    How to Identify Fake Shopping Websites in 2026

    Here is a quick checklist you can use every time you shop on a new website:

    Check ThisWhat to Look For
    URLShould start with https, look for misspellings
    Contact InfoReal phone number, email, and physical address
    GSTINLegitimate Indian businesses display this
    Payment OptionsCOD available or only prepaid?
    Return PolicyClearly mentioned or hidden?
    Domain AgeUse Whois lookup, avoid sites less than 6 months old
    ReviewsSearch “[website name] + review” or “+ scam” on Google

    Pro tip : Use the Government of India’s Sanchar Saathi portal to verify suspicious numbers. Also, check the DPIIT recognition page if a website claims to be a registered startup also you can check website on scamdekho

    What to Do If You Have Been Scammed

    If you have already lost money to an online shopping fraud, do not panic. Take these steps immediately:

    Step 1: Take screenshots of everything. The website, payment confirmation, WhatsApp chats, ads, everything.

    Step 2: Report on the National Cyber Crime Portal at cybercrime.gov.in. You can also call 1930, which is the cyber crime helpline.

    Step 3: File a complaint with your bank or UPI app (Google Pay, PhonePe, Paytm) to initiate a chargeback or reversal.

    Step 4: Report the website or social media page. On Instagram, use the “Report” option. For websites, report to Google Safe Browsing.

    Step 5: If the amount is significant, file an FIR at your local police station under the IT Act.

    The faster you act, the higher your chances of getting your money back.

    5 Simple Rules to Stay Safe While Shopping Online

    1. If the deal feels too good, it probably is. No one sells an iPhone for Rs 5,000.
    2. Never share OTP with anyone. No legitimate company will ever ask for it.
    3. Use credit cards instead of debit cards for online shopping. Credit cards offer better fraud protection.
    4. Avoid clicking on links from unknown WhatsApp messages or SMS. Type the URL manually.
    5. Keep your apps and browser updated. Security patches fix vulnerabilities that scammers exploit.
    6. Never trust payment screenshots as proof. Scammers use fake payment screenshot generators to show you fabricated UPI or bank transfer confirmations. Always verify the payment directly in your bank app or UPI app before handing over any product or service.

    Final Thoughts

    Online shopping scams in India are not going away anytime soon. If anything, they are getting smarter. From fake shopping websites that look identical to real brands, to pyramid schemes like Safe Shop that prey on people’s dreams, the threats are real and evolving.

    Your best defence is awareness. Bookmark this guide, share it with your family and friends, and always verify before you pay. A two minute check can save you from losing thousands.

    Stay alert. Shop smart. And if something feels off, trust your gut.

    FAQ: Online Shopping Scams in India

    Q: What are some common online shopping scams examples in India?
    Fake discount websites, duplicate product listings on marketplaces, WhatsApp group scams, Instagram page frauds, and MLM schemes like Safe Shop are the most common examples in 2026.

    Q: How do I report online shopping fraud in India?
    Visit cybercrime.gov.in or call 1930. You can also file a complaint on the National Consumer Helpline at 1800-11-4000.

    Q: Are all direct selling companies scams?
    No. Legitimate direct selling companies follow the Consumer Protection (Direct Selling) Rules, 2021. The difference is that real companies focus on product sales, not recruitment.

    Q: Can I get my money back after being scammed?
    Yes, if you act fast. Contact your bank, file a complaint on the cyber crime portal, and request a chargeback through your payment app.

  • AI Powered Bank Scams Australia 2026: How Aussies Are Being Targeted

    AI Powered Bank Scams Australia 2026: How Aussies Are Being Targeted

    Australians lost $2.18 billion to scams in 2026. And the scariest part? The scams hitting hardest right now are not your old-school “Nigerian prince” emails. They look real. They sound real. They feel real.

    That is because they are built with AI.

    If you bank online in Australia, this directly affects you. Here is everything you need to know.

    What Are AI Powered Bank Scams?

    AI powered bank scams use artificial intelligence to make fraud attempts look and sound far more convincing than before. Scammers are no longer sending poorly written emails full of typos. They are creating:

    • Deepfake videos of celebrities promoting fake investments
    • Voice clones of your family members asking for urgent money transfers
    • Personalised phishing emails that reference your real name, bank, and recent activity
    • Fake investment ads polished to look like legitimate financial products

    ASIC Commissioner Alan Kirkland put it plainly in April 2026: scammers are using AI to make fake investment ads look more polished, more convincing, and harder to spot.

    The result? Investment scams alone cost Australians $837.7 million in 2026.

    How Scammers Are Using AI Against Australians Right Now

    1. Deepfake Celebrity Investment Ads

    This is one of the fastest-growing AI scam types in Australia. Scammers clone the faces and voices of well-known Australians, such as business figures and TV personalities, and use them in fake investment videos shared on Facebook, Instagram, and YouTube.

    The video looks completely legitimate. The “celebrity” explains why they invest in a particular platform and urges viewers to sign up fast.

    Once you deposit money, it disappears.

    ASIC removed more than 1,100 investment scam ads from social media in 2025 and took down 11,964 scam websites in the same period, which is a 90% jump compared to the year before.

    Source: ASIC

    2. AI Voice Cloning and the “Hi Mum” Scam

    You get a call. It is your daughter’s voice. She is crying. She says she is in trouble and needs you to transfer money immediately.

    Except it is not your daughter. It is an AI voice clone built from a few seconds of audio scraped from her social media.

    Westpac’s Head of Fraud Prevention, Ben Young, warned in April 2026 that scammers are moving well beyond generic phishing into highly targeted attacks that feel intensely personal.

    3. AI Powered Phishing Emails and Texts

    Old phishing emails were easy to spot because of the grammar mistakes and generic greetings. Not anymore.

    Today’s AI generated phishing messages use your correct name, mention your bank by name, and sometimes even reference a recent transaction. They mimic the exact tone and design of official bank communications.

    One click on the wrong link can hand over your internet banking login.

    4. AI Used for Property and Loan Fraud

    This one is bigger than most Australians realise. In early 2026, Commonwealth Bank alerted authorities after identifying a suspected $1 billion loan fraud racket where AI was allegedly used to generate fake financial documents. Fraudsters used artificial documents to obtain home loans for shell companies and luxury properties.

    This shows AI bank scams are not just targeting everyday Australians at home. They are attacking the financial system at scale.

    Fake SMS and Scam Call Examples

    Scammers are getting smarter, and honestly, it’s getting harder to keep up. They’re now using AI-generated messages and cloned voices to pull off banking scams that look and sound like the real deal. Plenty of Aussies have already been caught out by fake SMS alerts pretending to be from CommBank, NAB, ANZ, and Westpac.

    Here are some examples that have actually been sent to real people:

    “Your CommBank account has been temporarily locked due to suspicious activity. Verify now to avoid account suspension.”

    “NAB Security Alert: A payment attempt was detected on your account. Confirm immediately.”

    “Hi Mum, I lost my phone and can’t access my bank account. Please transfer money urgently.”

    These messages are written to make you panic on the spot. Before you’ve even had a chance to think it through, you’re already clicking a dodgy link or transferring money to someone you’ve never met.

    Signs an AI Bank Scam Call Is Fake

    AI-powered scam calls have gotten scarily good, but if you know what to look for, the cracks start to show pretty quickly. Here are some things that should immediately get your guard up:

    • The caller is pushing you to act right now, no time to think
    • They’re asking for your OTP, PIN, or internet banking password
    • The message has a link that just doesn’t look right
    • You’re being told to transfer money on the spot
    • They want you to download software so they can access your device remotely
    • The voice on the other end sounds a bit off, almost too smooth or robotic
    • They’re telling you not to call your bank directly, which is a massive red flag

    Here’s something worth remembering. Your bank will never ask for your internet banking password, PIN, or any verification codes over the phone or by SMS. Ever. If someone is asking for that stuff, it is not your bank.

    Most Targeted Australian Banks in AI Scams

    Scammers aren’t picking banks at random. They go after the big names because people are more likely to trust them without questioning. In 2026, customers of these four banks are being hit the hardest:

    • Commonwealth Bank (CommBank)
    • NAB (National Australia Bank)
    • ANZ
    • Westpac

    The fake messages, cloned support calls and phishing emails being sent out are frighteningly close to the real thing. If something feels a bit suss, skip the link or number they’ve given you and head straight to your bank’s official app or website to check.

    Real vs Fake Bank Messages

    Real Bank MessageScam Message
    Uses official bank domainsContains suspicious or shortened links
    Does not create panicUses urgent or threatening language
    Never asks for OTPs or passwordsRequests verification codes or passwords
    Encourages contact through official supportPressures you to act immediately
    Appears inside official banking appsSent through random numbers or emails

    How Good Are Australians at Spotting AI Scams?

    Not as good as they think.

    CommBank research from January 2026 found that 89% of Australians are confident they can spot an AI-generated scam. But when tested, they could only correctly identify real versus AI-generated images 42% of the time. That is actually worse than a random guess.

    Even Australians aged over 65 were only 6% less accurate than younger people. AI scams fool everyone.

    The gap between confidence and reality is exactly what scammers are exploiting.

    How Australian Banks Are Fighting Back

    The good news is that Australian banks are not sitting still.

    CommBank has deployed an advanced AI agent that monitors over 20 million payments per day and sends more than 40,000 proactive scam alerts daily through the CommBank app. The system helped reduce customer fraud losses by over 20% in the first half of the 2026 financial year.

    CommBank also partnered with Apate.ai, an Australian AI company, deploying 10,000 AI voice bots and 25,500 messaging bots that engage with scammers in real time, waste their time, and collect intelligence on how they operate.

    Westpac launched SaferPay, an AI-powered system that detects high-risk payments and stops suspicious transactions before they go through. Since launch, Westpac has saved customers over $400 million from being lost to scammers.

    Despite all this, no bank system is foolproof. Your own awareness remains the strongest line of defence.

    How to Protect Yourself from AI Bank Scams in Australia

    These steps are recommended by ASIC, CommBank, Westpac, and the Australian Banking Association:

    • Stop before you act. If anything creates urgency or pressure, that is your signal to pause. Scammers rely on panic to make you act before you think.
    • Verify through a separate channel. If you get a call from someone claiming to be your bank or a family member, hang up and call them back on a number you already know. Do not use the number from the message.
    • Set up a family safe word. This is something Australians rarely do but absolutely should. Only 1 in 5 Australians have a family safe word to confirm identity, despite 74% agreeing it is a good idea. Pick a word only your family knows and use it to verify urgent calls.
    • Use CommBank CallerCheck or Westpac push notifications. These tools let you verify in the app whether someone claiming to be from your bank is genuinely calling from there.
    • Check investment opportunities on ASIC’s register. Before putting any money into an investment you found on social media, search the company at asic.gov.au. Always verify they hold an Australian Financial Services Licence.
    • Report scams immediately. If you think you have been targeted, contact your bank straight away and report to Scamwatch at scamwatch.gov.au.

    What to Do If You Have Already Been Scammed

    If you have already transferred money or shared your banking details:

    1. Call your bank immediately using the number on the back of your card
    2. Report the scam to Scamwatch (scamwatch.gov.au)
    3. Lodge a report with the Australian Cyber Security Centre (cyber.gov.au)
    4. If identity theft is involved, contact IDCARE (idcare.org)

    Acting fast is critical. The sooner your bank knows, the better the chance of stopping or recovering the transfer.

    The Bottom Line

    AI powered bank scams in Australia are not a future threat. They are happening right now, at scale, and they are designed to fool even careful, tech-savvy people.

    The technology scammers are using is becoming cheaper and more accessible every month. But the core defence has not changed. Slow down. Verify independently. Never act under pressure.

    And if something does not feel right, it probably is not.

  • Geek Squad Renewal Scam: How It Works and How to Protect Yourself

    Geek Squad Renewal Scam: How It Works and How to Protect Yourself

    Got an email saying your Geek Squad subscription just renewed for $349.99 or $399.99? Before you panic and call that number in the email, stop. You are likely looking at a Geek Squad renewal scam, and thousands of people across the US and UK fall for it every year.

    This guide will show you exactly how the scam works, what the fake emails look like, and what to do if you already clicked something you should not have.

    So What Is the Geek Squad Auto Renewal Scam, Exactly?

    Here is the short version: criminals send you a fake invoice pretending to be Best Buy’s Geek Squad tech support. The email looks like a real billing notification, complete with logos, a fake order number, and a charge somewhere between $299 and $499.99.

    The whole point is to get you scared enough to either call a number or click a link. The moment you do either of those things, they have you.

    This is not a small-time operation either. The FTC received close to 52,000 reports of people being scammed by fake Geek Squad and Best Buy impersonators in 2023 alone, more reports than Amazon and PayPal scams combined. And heading into 2026, those numbers have not dropped.

    How the Geek Squad Auto Renew Scam Actually Works

    Here is what happens step by step:

    Step 1: You get the email out of nowhere

    Subject line says something like “Invoice Attached, $399.99 Charged” or “Your Geek Squad Membership Has Been Renewed.” The email looks clean and professional. There is a Geek Squad logo, a fake invoice table, an order number, the whole thing.

    Step 2: Then comes the pressure

    Buried somewhere in the email is a line that says you only have 24 hours to cancel and get a refund. That clock ticking is not an accident. It is designed to stop you from thinking clearly and push you into acting fast.

    Step 3: You call the number or click the link

    The email makes this feel like the only logical next step. If you call, someone picks up sounding completely calm and professional, pretending to be a Geek Squad agent. They will ask for your banking information to “process your refund.” Or they will tell you your computer has a virus and ask to connect remotely to fix it.

    Step 4: That is when the real damage happens.

    Remote access means they can see everything on your device. Banking credentials, saved passwords, personal files, everything is on the table. Some victims have had their accounts drained. Others have had their identities stolen months later.

    Also Read: Evri Scam Text 2026: Spot Fake Texts, Red Flags & What To Do

    What Does a Fake Geek Squad Renewal Email Actually Look Like?

    A real Geek Squad automatic renewal scam email will usually have most of these:

    • A sender address that is not @bestbuy.com or @geeksquad.com. Think something like [email protected] or a random Gmail address
    • A generic opener like “Dear Sir/Madam” or “Dear Customer” instead of your actual name
    • A fake invoice showing a charge for something like “Geek Squad Best Buy Service, One Year Subscription”
    • An amount that feels plausible, usually between $349.99 and $499.99
    • A hard deadline, typically 24 hours, to cancel and get a refund
    • A phone number to call that goes straight to the scammer

    If you have gotten an email that checks more than two or three of these boxes, you are looking at a geek squad renewal email scam. Close it. Do not reply, do not call, do not click anything inside it.

    Is the Geek Squad Renewal Email a Scam? Here Is How to Know for Sure

    Yes, in almost every case it is. But if you want to be completely certain, here is the one thing to do: open your browser, type BestBuy.com yourself, log in, and check your account under Subscriptions or Protection Plans.

    If there is no active Geek Squad subscription sitting there, that email is fake. End of story.

    Real Geek Squad renewal emails come from official @bestbuy.com addresses. They never give you a 24-hour panic window. And they never ask you to call a random number to dispute a charge.

    The Different Types of Geek Squad Subscription Renewal Scams Running in 2026

    The basic scam has a few variations. All of them are designed to hit different pressure points.

    The Classic Fake Invoice Email

    This is the most common one. You get a geek squad auto renewal scam email claiming you have been billed $300 to $500 for a membership you never signed up for. The only way to cancel, the email says, is to call their number. That number is not Best Buy. It is a scammer sitting somewhere waiting for you to hand over your bank details.

    The Overpayment Refund Trick

    In this version, the scammer claims they accidentally refunded you too much money and now needs you to send some back. They might even show you a fake bank screen to “prove” it. They want the money sent through gift cards or wire transfer because those are nearly impossible to trace or recover.

    The Remote Access Play

    You get told your device has been infected with malware. They urgently ask you to download software so their “technician” can clean it up. Once they have remote access to your computer, they have access to everything on it.

    The Best Buy Geek Squad Renewal Scam via Phone

    Not every geek squad membership renewal scam starts with an email. Some people get a cold call from someone claiming to be a Geek Squad agent. Same script, same urgency, same goal. If you did not initiate the call, hang up.

    How to Cancel Geek Squad Auto Renewal the Right Way

    If you actually do have a Geek Squad subscription and want to cancel it, here is how to do it without getting tricked:

    1. Open your browser and type BestBuy.com yourself. Never use a link from an email.
    2. Sign in to your account.
    3. Head to Account Settings and look for Subscriptions or Protection Plans.
    4. Find your plan and cancel from there.
    5. Or call Geek Squad directly at (888) 237-8289, which is their official number.

    That is it. No third-party links, no emailed phone numbers, just your account and the official site.

    Already Fell for It? Here Is What to Do Right Now

    This happens to smart people every day. These scams are built by professionals. If you already made a move, here is how to limit the damage:

    Gave them your credit card or bank info?

    Call your bank immediately. Ask them to freeze the card and flag any recent transactions as potentially fraudulent. Request a chargeback if any money has already moved.

    Let them into your computer?

    Disconnect from the internet right now. Run a full scan with a trusted antivirus program. Then change every important password, starting with your email and banking accounts.

    Handed over your Social Security number?

    Place a fraud alert or credit freeze with Experian, Equifax, and TransUnion. File an identity theft report at IdentityTheft.gov. This creates an official record and helps you dispute anything fraudulent that pops up later.

    Sent money through gift cards?

    This is the hardest situation to recover from because gift card payments are almost untraceable. Report it to the FTC immediately and contact the gift card company directly. Some issuers can put a hold on unused card balances if you catch it fast enough.

    Where to Report a Geek Squad Membership Renewal Scam

    Reporting matters because it helps the FTC and FBI track these operations and warn other people. Here is where to go:

    • Your email provider: Hit “Report Phishing” inside Gmail or Outlook so they can filter similar messages in the future
    • FTC: reportfraud.ftc.gov
    • Best Buy fraud team: Forward the scam email to abuse@bestbuy.com
    • FBI Internet Crime Complaint Center: ic3.gov

    Also Check: How to Report PayPal Scam Emails: A Complete Guide

    Red Flags to Spot a Geek Squad Phishing Email

    Bookmark these. They will save you one day:

    • Sender email is not from @bestbuy.com or @geeksquad.com
    • Email addresses you as “Dear Sir/Madam” or “Dear Customer”
    • There is a charge for a subscription you never signed up for
    • You are given 24 hours or less to respond
    • The email asks you to call a number to cancel
    • Any mention of gift cards as a way to send or receive money
    • Grammar feels slightly off or sentence structure seems automated

    Final Thoughts

    The Geek Squad renewal scam is not going anywhere in 2026. It works too well for scammers to give up on it. It creates instant fear, uses a name people recognize and trust, and gives victims just enough time to react without thinking.

    The single best thing you can do is slow down. If you get an unexpected billing email from Geek Squad, do not call the number. Do not click the link. Open a browser tab, go to BestBuy.com yourself, and check your account. That 30-second step is the difference between staying safe and handing a scammer your financial information.

    If you found this helpful, share it with someone who shops at Best Buy regularly. Older adults are particularly targeted by this scam and are less likely to have seen a warning like this before.

    FAQs About the Geek Squad Renewal Scam

    Is Geek Squad a scam?

    No. Geek Squad is a legitimate tech support service owned by Best Buy. Scammers are impersonating the brand. If you contact Geek Squad through the official Best Buy website or phone number, you are talking to real people.

    How do I cancel my Geek Squad auto renewal without getting scammed?

    Go directly to BestBuy.com, sign in, and manage your plan from your account. Never use a cancellation link from an unsolicited email.

    What amounts do the fake Geek Squad renewal emails claim in 2026?

    Most geek squad automatic renewal scam emails in 2026 claim charges of $349.99, $359.99, $399.99, or $499.99. These amounts are chosen to feel believable for an annual tech subscription.

    Can I get my money back?

    It depends on how you paid. Credit card payments have the best shot at recovery through a bank chargeback. Wire transfers and gift card payments are very difficult to recover. The faster you act, the better your chances.

    How do I know if a Geek Squad renewal email is real?

    Log into your Best Buy account directly and check your active subscriptions. If nothing is there, the email is fake. Also verify the sender address ends in @bestbuy.com.

  • Evri Scam Text 2026: Spot Fake Texts, Red Flags & What To Do

    Evri Scam Text 2026: Spot Fake Texts, Red Flags & What To Do

    Got a text from “Evri” saying your parcel couldn’t be delivered? Maybe it’s asking you to pay 79p or update your address?

    Stop. Don’t click that link.

    There’s a very good chance it’s a scam and thousands of people across the UK are falling for it every single week. We’ve been tracking Evri scam texts throughout 2025 and 2026, and the patterns are getting more sophisticated. In this guide, we break down exactly how these scams work, what real examples look like, and what you should do right now if you’ve already clicked.

    What Is the Evri Scam Text?

    The Evri scam text is a type of smishing attack (SMS phishing) where fraudsters impersonate Evri, one of the UK’s largest parcel delivery companies (formerly Hermes).

    These fake text messages typically claim that:

    • Your parcel couldn’t be delivered
    • You need to pay a small redelivery fee (usually 79p or £1.99)
    • Your address is “incomplete” and needs updating
    • You must reschedule delivery by clicking a link

    The goal? Steal your bank details, personal information, or both.

    According to Action Fraud UK, parcel delivery scams increased by over 35% between 2024 and 2025, with Evri being one of the most impersonated brands. The National Cyber Security Centre (NCSC) has also issued multiple warnings about these fraudulent messages.

    Here’s the thing these texts look genuinely convincing. The scammers have gotten really good at copying Evri’s branding, tone, and even their tracking page layout.

    Real Evri Scam Text Examples (2026 Latest)

    We’ve collected the most common Evri scam text formats currently circulating across the UK. Here’s what they look like:

    Example 1: The “79p Redelivery Fee” Scam

    “Evri: We attempted to deliver your parcel today but no one was available. Please pay £0.79 redelivery fee to reschedule: [suspicious-link.com]”

    Why it works: The small amount (79p) makes people think “what’s the harm?” but the linked page captures your full card details.

    Example 2: The “Incomplete Address” Scam

    “Evri: Your parcel is on hold due to an incomplete address. Please update your delivery details here: [evri-address-update.com]”

    Why it works: If you’ve recently ordered something online, this feels completely believable.

    Example 3: The “Driver David” Scam

    “Evri: Our driver David attempted to deliver your package today, but was unsuccessful. To arrange a redelivery, please visit: [fake-link.com]”

    Why it works: Adding a driver’s name makes it feel personal and authentic. This version went viral on Reddit’s r/Scams and r/AskUK communities.

    Example 4: The WhatsApp Version

    A WhatsApp message from an unknown number with Evri’s logo as the profile picture, asking you to “confirm your delivery slot.”

    Why it works: People trust WhatsApp messages more than random SMS texts.

    Example 5: The Email Version (donotreply@evri)

    Subject: “Your Evri delivery requires action”
    Body: “We were unable to deliver your parcel. Customs charges of £1.45 must be paid before redelivery. Click here to pay.”

    Why it works: The “donotreply” sender name mimics legitimate corporate emails.

    Example 6: The “Reschedule Delivery” Text

    “EVRI: Your delivery is scheduled for today. We need you to confirm your time slot. Reschedule here: [evri-reschedule.com]”

    Why it works: Creates urgency, you think you’ll miss your parcel if you don’t act fast.

    How to Spot a Fake Evri Text: 9 Red Flags

    Not sure whether that Evri text message is real or fake? Look for these red flags:

    1. It Asks for Payment

    Evri never charges for redelivery. This is confirmed directly on Evri’s official website. If any text asks for 79p, £1.99, or any amount, it’s fake. Period.

    2. Suspicious Links

    Real Evri links only come from evri.com. Scam links often look like:

    • evri-redelivery.com
    • evri-address.com
    • evr.i-c26829gb.com
    • evri.psocy.com

    Pro tip: Hover over (or long-press on mobile) any link to see the actual URL before clicking.

    Run the link through a URL checker first

    3. Sent from a Mobile Number

    Genuine Evri messages come from a verified sender ID that shows as “Evri” not from a random mobile number like 07xxx.

    4. Urgency and Pressure

    Phrases like “act within 24 hours” or “your parcel will be returned” are classic pressure tactics. Real delivery companies don’t threaten you.

    5. Spelling and Grammar Mistakes

    While scammers are getting better, many texts still contain awkward phrasing, random capitalisation, or spelling errors.

    6. No Personal Greeting

    A real Evri notification typically includes your name or tracking reference. Scam texts are generic they don’t know your name.

    7. Asks for Card Details

    No legitimate delivery company will ever ask for your full card details via a text message link.

    8. Comes Via Email from a Personal Address

    If you get an Evri email from a Hotmail, Gmail, or Yahoo address that’s obviously not Evri. Their emails come from official @evri.com domains.

    9. You Weren’t Expecting a Parcel

    This seems obvious, but it works. If you haven’t ordered anything, why would Evri text you? Scammers play the numbers game they send millions of texts hoping some people are actually waiting for a delivery.

    Real Evri Text vs Scam Text: Side-by-Side Comparison

    Here’s how to tell the difference at a glance:

    FeatureReal Evri TextScam Evri Text
    SenderShows as “Evri”Random mobile number
    Linkevri.com onlyevri-redelivery.com, evr.i-xxx.com
    Payment requestNever asks for moneyAsks for 79p, £1.99 etc.
    Tracking numberIncludedUsually missing
    Personal detailsMay include your nameGeneric “Dear Customer”
    GrammarProfessionalOften has errors
    UrgencyCalm tone“Act now or lose your parcel!”

    Does Evri Send Text Messages? How Does Evri Actually Contact You?

    Yes, Evri does send legitimate text messages, which is exactly why these scams are so effective. Here’s how the real Evri contacts customers:

    Legitimate Evri communications include:

    • SMS updates with your tracking number
    • Emails from @evri.com addresses
    • Notifications through the Evri app
    • A card left at your door if delivery was attempted

    Evri will NEVER:

    • Ask you to pay a redelivery fee
    • Request your bank or card details via text
    • Send messages from personal email addresses (Hotmail, Gmail)
    • Ask you to click a link to “verify your address” with payment

    This is confirmed on Evri’s official FAQ page about genuine communications.

    Clicked the Evri Scam Link? Do This RIGHT NOW

    Already clicked the link or worse entered your details? Don’t panic, but act fast. Here’s your step-by-step action plan:

    Step 1: Disconnect from the Internet

    If you clicked on your phone, switch to Aeroplane Mode immediately. This can prevent any malware from sending your data.

    Step 2: Contact Your Bank (Immediately)

    If you entered any card or banking details:

    • Call your bank’s fraud department (number is on the back of your card)
    • Ask them to freeze your card and block any pending transactions
    • Request a new card to be issued

    Most UK banks have 24/7 fraud lines. Don’t wait until morning.

    Step 3: Change Your Passwords

    If you entered any login credentials, change passwords immediately especially for:

    • Email accounts
    • Banking apps
    • Any account using the same password

    Step 4: Report to Action Fraud

    File a report at actionfraud.police.uk or call 0300 123 2040. This helps UK authorities track and shut down scam operations.

    Step 5: Forward the Text to 7726

    Forward the scam text message to 7726 this is the UK’s free spam reporting service run by Ofcom. Your network provider will investigate.

    Step 6: Report to the NCSC

    Forward suspicious emails to report@phishing.gov.uk the National Cyber Security Centre actively takes down scam websites based on these reports.

    Step 7: Run an Antivirus Scan

    If you clicked a link on your phone, run a full scan using a trusted antivirus app. Some scam links install malware that monitors your keystrokes.

    Step 8: Monitor Your Accounts

    For the next 30-90 days, keep a close eye on:

    • Bank statements for unusual transactions
    • Credit report (use free services like ClearScore or Experian)
    • Email for password reset notifications you didn’t request

    Can You Get Your Money Back?

    If scammers have already taken money from your account, here’s what we know:

    Through your bank:

    • Under the Contingent Reimbursement Model (CRM) Code, many UK banks will refund victims of Authorised Push Payment (APP) fraud
    • Contact your bank’s fraud team and request a chargeback or Section 75 claim (for credit card payments)
    • From October 2024, the PSR (Payment Systems Regulator) requires banks to reimburse APP fraud victims in most cases

    Success rate: According to UK Finance data, approximately 62% of APP fraud cases received full or partial reimbursement in 2024.

    Important: The sooner you report, the higher your chances of getting money back.

    Why Are Evri Scam Texts So Common?

    You might wonder why Evri specifically? Why not Royal Mail or DPD?

    A few reasons:

    1. Evri handles millions of parcels daily – so the chances of someone actually expecting an Evri delivery when they receive the scam text are high
    2. Evri’s reputation – let’s be honest, Evri already has a mixed reputation for missed deliveries, so a “failed delivery” text feels believable
    3. Low-cost shipping – many online retailers use Evri as their default courier, so most UK online shoppers have dealt with them
    4. Easy to impersonate – Evri’s simple branding and short company name makes it easy to fake convincingly

    How to Report an Evri Scam Text (Complete Guide)

    Here’s every way you can report these fraudulent messages:

    MethodDetails
    Forward SMSSend the text to 7726 (free)
    Action Fraudactionfraud.police.uk or call 0300 123 2040
    NCSC EmailForward to report@phishing.gov.uk
    Evri directlyReport at evri.com/digital-security
    Your networkContact your mobile provider to block the sender

    Every report helps. The NCSC has taken down over 235,000 scam URLs since 2020 based on public reports (source: NCSC Annual Review 2024).

    The Bottom Line

    Evri scam texts aren’t going away anytime soon. Scammers know that millions of people across the UK use Evri regularly, and they exploit that familiarity. The best defence is simple never click links in unexpected delivery texts, and remember that Evri never charges for redelivery.

    If something feels off about a text or email, trust your instinct. Check directly on the official Evri website. And if you’ve already fallen victim, act fast, contact your bank, report the scam, and monitor your accounts.

    Stay safe out there.

    For more scam alerts and verification guides, explore ScamDekho.in we help you spot scams before they spot you.

    Frequently Asked Questions

    Are texts from Evri a scam?

    Not all texts from Evri are scams. Evri does send legitimate delivery notifications. However, any text asking for payment, card details, or directing you to a non-evri.com website is almost certainly a scam. Always verify by checking your tracking number directly on the official Evri website or app.

    Does Evri charge for redelivery?

    No. Evri does not charge any fee for redelivery. They attempt delivery up to 3 times free of charge. Any text asking for 79p, £1.45, or £1.99 for redelivery is a scam no exceptions.

    What does a real Evri text look like?

    A genuine Evri text will come from a verified “Evri” sender ID (not a mobile number), contain your tracking reference number, and will never ask for payment or card details. Real texts simply provide delivery updates or estimated delivery windows.

    What happens if you click an Evri scam link?

    If you only clicked the link but didn’t enter any details, the risk is lower but you should still run an antivirus scan on your device. If you entered personal or banking information, contact your bank immediately to freeze your card and report the incident to Action Fraud.

    How do you verify if an Evri text is genuine?

    Copy the tracking number from the text and enter it directly on evri.com/track-a-parcel. If the tracking number doesn’t exist on their official site, the message is fake. You can also contact Evri directly through their app or website chat.

    What is the donotreply Evri email scam?

    This is a phishing email that appears to come from “donotreply@evri.com” but actually uses a spoofed or slightly altered email address. These emails typically claim you need to pay customs charges or update delivery information. Always check the actual sender address carefully.

    Is evri.psocy.com a real Evri website?

    No. Any website that isn’t evri.com is not affiliated with Evri. Domains like evri.psocy.com, evr.i-c26829gb.com, and evri-redelivery.com are all scam websites designed to steal your information.

  • How to Report PayPal Scam Emails: A Complete Guide(2026)

    How to Report PayPal Scam Emails: A Complete Guide(2026)

    I’ll be honest with you. I’ve received my fair share of sketchy PayPal emails over the years. That moment when you see “Your account has been limited” or “Unusual activity detected” in your inbox? Your heart skips a beat, right?

    Here’s the thing: you’re definitely not alone. Scammers send out millions of fake PayPal emails every single day, and they’re getting scarily good at it. But there’s good news too. Reporting these scam emails is actually pretty straightforward, and it makes a real difference.

    Why Should You Report PayPal Scam Emails?

    Your first instinct might be to just delete the email and move on. And yeah, that’s better than clicking anything suspicious. But reporting matters. Here’s why:

    • You help shut down scam operations before they trick someone else, maybe your mom, your friend, or someone less tech-savvy
    • PayPal tracks patterns and enough reports about one scam means they can find the fake websites and shut them down fast
    • Spam filters improve because your report helps block similar emails automatically for everyone
    • You put up a warning sign that protects the next person

    How Do I Know If It’s Actually a Scam?

    Before hitting report, make sure you’re actually looking at a scam. Here’s what to check:

    Red FlagWhat to Look For
    Generic greeting“Dear User” or “Dear PayPal Customer” instead of your real name
    Urgent language“Your account closes in 24 hours!” PayPal doesn’t operate like that
    Suspicious sender addressLook for tricks like “paypa1@randomsite.xyz” (number 1 instead of letter l)
    Strange link URLsHover without clicking. If it doesn’t end in paypal.com, it’s a scam
    Grammar mistakesProfessional companies have editors. Scammers don’t.

    Golden Rule: When in doubt, open a new browser tab, type paypal.com directly, log in, and check your notifications there. If there’s really a problem, you’ll see it.

    How to Report PayPal Scam Email: Step by Step

    Method 1: Forward the Email (Easiest, Takes 30 Seconds)

    This is hands-down the easiest method:

    1. Don’t click anything in the suspicious email, no links, no buttons
    2. Hit Forward in your email client
    3. Enter phishing@paypal.com as the recipient
    4. Send it as-is and don’t add comments or change the subject line
    5. Delete the original and empty your trash

    PayPal’s security team needs the email exactly as you received it. Headers, links, everything. That’s how they track the scammers.

    Note: You may see older articles mention spoof@paypal.com. That still works, but phishing@paypal.com is the current recommended address.

    Method 2: Report Through Your PayPal Account

    1. Go to PayPal.com (type it yourself, don’t Google it)
    2. Log into your account
    3. Click Help at the top
    4. Select Contact Us
    5. Find “Report a security issue or unauthorized activity”
    6. Describe what happened and submit

    Takes a bit longer but feels more official if you prefer that.

    Method 3: Using the PayPal Mobile App

    1. Tap your profile picture
    2. Go to Help & Contact
    3. Select Report a Problem
    4. Choose Security
    5. Follow the prompts

    Method 4: Report to Additional Authorities

    Want to go the extra mile? Also report to:

    Check out our PayPal Email Checker if you want a quick way to verify whether an email is legit.

    Where to Report PayPal Scam Email: All Official Channels

    ChannelWhere
    Primary reportingphishing@paypal.com
    Account-based reportingPayPal Resolution Center (after logging in)
    Help CenterDesktop or mobile app
    US incidentsreportfraud.ftc.gov
    Global phishing databasereportphishing@apwg.org

    Honestly? Just forwarding to phishing@paypal.com covers 90% of what you need.

    What Happens After You Report?

    Don’t expect a personal thank-you. PayPal handles thousands of reports daily. But your report doesn’t disappear:

    • Automated scanning pulls out all links and checks where they lead
    • Fake websites get shut down usually within a few hours
    • Spam filters get smarter with every report they receive
    • If you actually clicked something and entered info, you’ll hear back within 24 to 48 hours and they’ll help secure your account

    Common Questions

    I already clicked the link. What do I do?

    Did you enter your password or personal info?

    • If no: you’re probably fine
    • If yes: change your PayPal password immediately at PayPal.com, enable two-factor authentication, contact PayPal support, and run a virus scan

    I don’t have a PayPal account. Can I still report?

    Yes. Forward to phishing@paypal.com anyway. Scammers blast these to millions of addresses. Your report still helps protect real users.

    Will PayPal ever email me about account issues?

    Yes, but they’ll never ask you to click a link to fix anything. Real PayPal emails tell you to log in directly. Never “click here to verify.”

    I keep getting the same scam email. Report every time?

    Once is enough for the identical email. But different versions or new scam types? Yes, report those separately.

    How long before PayPal responds?

    • Phishing reports to phishing@paypal.com: typically no personal response
    • Unauthorized transaction reports via Resolution Center: 24 to 48 hours

    PayPal Scam Email Examples to Watch For (2026)

    These are the ones making the rounds right now:

    1. Fake Invoice Scam You receive a PayPal invoice for something expensive like Norton antivirus or random electronics. It actually comes through PayPal’s system so it looks real. The scam is a fake phone number to “call if you didn’t authorize this” and that number connects you to scammers.

    2. Cryptocurrency Payment Scam Claims you bought Bitcoin through PayPal with a large charge listed. Designed to make you panic and call a fake support number.

    3. DocuSign Combination Scam Looks like it’s from both PayPal and DocuSign asking you to sign a document. Extremely professional-looking and has fooled a lot of people.

    4. Receipt Scam A fake PayPal receipt for a purchase you never made, complete with fake transaction IDs. Looks identical to real receipts.

    5. Account Limitation Scam Claims your account is limited due to “suspicious activity.” Classic fear tactic that’s still very effective.

    What NOT to Do When You Get a Scam Email

    • Don’t reply because it confirms your email is active and invites more scams
    • Don’t click any links, even out of curiosity. Phishing sites can install malware just by visiting
    • Don’t download attachments as they often contain keyloggers or ransomware
    • Don’t call phone numbers in the email because those connect directly to scammers
    • Don’t enter your password anywhere except PayPal.com, even if the page looks identical

    How to Protect Yourself Going Forward

    • Enable two-factor authentication Use an authenticator app like Google Authenticator or Authy. It’s more secure than SMS and takes only 10 extra seconds to log in. Worth every second.
    • Check your account regularly Glance at your PayPal transactions once a week. Takes 30 seconds and you’ll catch anything weird immediately.
    • Use a unique password If you’re reusing your PayPal password anywhere else, stop. Get a password manager.
    • Use a separate email for financial accounts One email just for banking and PayPal gets far fewer scam attempts than a general-use email.
    • Review linked accounts periodically Every few months, check what bank accounts, cards, and apps are connected. Remove anything you don’t use.

    How to Reduce the Number of Scam Emails You Get

    • Turn on your email provider’s spam filters because Gmail, Outlook, and Yahoo all have them built in
    • Mark scams as spam before deleting to train the filter
    • Don’t post your email publicly since bots scrape addresses from forums and social media
    • Report and block senders when possible

    Final Thoughts

    Reporting a PayPal scam email takes maybe 60 seconds. That minute could save someone from losing their hard-earned money.

    The process is simple: see a scam, forward to phishing@paypal.com, delete, and move on.

    Share this with anyone who might not be familiar with these scams. The people most at risk are the ones who trust every email in their inbox.

    Stay safe. When something feels fishy about a PayPal email, it usually is.

  • PayPal DocuSign Phishing Scam: How to Identify Fake Emails Before It’s Too Late

    PayPal DocuSign Phishing Scam: How to Identify Fake Emails Before It’s Too Late

    You open your inbox and see an email from DocuSign. It looks completely normal. The DocuSign logo is right there, the formatting is clean, and it says PayPal needs you to review a document about an unauthorized transaction on your account. Your stomach drops a little. $755 charged to Coinbase? You never made that purchase.

    So you click.

    And that is exactly what the scammers want.

    The PayPal DocuSign phishing scam is one of the most convincing fraud techniques circulating in 2025, and it has already fooled thousands of people including business owners, finance teams, and everyday PayPal users. What makes it so dangerous is simple: the email is not fake. It actually comes from DocuSign’s real servers.

    Let’s break down how this works, what to look for, and how to protect yourself.

    What Exactly Is the PayPal DocuSign Phishing Scam?

    Most phishing emails are easy to spot if you know what to look for. Misspelled words, weird sender addresses, links to strange domains. But this scam is built differently.

    Here is what cybercriminals actually do. They sign up for a real DocuSign account. Then they use DocuSign’s own API and templates to create a document that looks like a PayPal invoice. Inside that document, there is a fake transaction alert, usually for a few hundred dollars, along with a phone number or link for “dispute resolution.” They then send this through DocuSign’s actual email system to thousands of targets.

    Because the email originates from DocuSign’s legitimate infrastructure, it bypasses spam filters that would normally catch phishing attempts. Your inbox receives it as a trusted message. DocuSign itself has confirmed this, noting an increase in sophisticated phishing scams that use the platform in combination with communication outside their system, with fake PayPal invoices being a common tactic.

    This is not your typical email scam. It weaponizes two brands that people genuinely trust.

    How the Scam Actually Plays Out

    Understanding the full sequence helps you recognize it faster. Here is how the PayPal DocuSign email scam typically works from start to finish.

    Step 1: You receive the email

    The subject line is usually something like “Action Required: PayPal Payment Authorization” or “Unauthorized Transaction Detected on Your Account.” Sometimes the attacker’s DocuSign account name is set to “PayPal Billing” or “PayPal Accounting,” and the email body uses the standard DocuSign notification template. Nothing looks off because nothing is technically off. It is a real DocuSign email.

    Step 2: You open the document

    Inside the DocuSign interface, you see what looks like a PayPal invoice. It has the PayPal logo, a fake transaction ID, an alarming dollar amount, and either a phone number or a link to contact “PayPal’s Fraud Prevention Team.”

    Step 3: You take the bait

    If you call the phone number, a live operator walks you through “verifying” your identity, which really means handing over your PayPal login, banking details, or even granting remote access to your device. If you click a link instead, you land on a fake webpage designed to steal your credentials, or worse, silently download malware onto your computer.

    6 Red Flags in a PayPal DocuSign Email

    Even though these emails are genuinely hard to spot, there are clear warning signs once you know where to look.

    1. You did not initiate anything

    This is the most important signal. PayPal does not randomly send you a DocuSign document out of nowhere. You will generally only receive a legitimate DocuSign email after coming to a prior agreement with the sender. If you did not buy anything, request anything, or sign up for anything, treat that email with serious suspicion.

    2. PayPal does not use DocuSign for transaction alerts

    This is a fact most people simply do not know. PayPal has its own transaction notification system and would not use DocuSign. There is also no mention of actually signing a document in these scam emails, which is what DocuSign is genuinely used for. A real payment alert from PayPal arrives directly from PayPal, not through a third-party document signing platform.

    3. The sender address does not add up

    Look closely at the “From” and “Reply-To” fields. A common sign of a PayPal DocuSign scam is that the customer care email inside the document ends with gmail.com, not paypal.com. No legitimate PayPal team uses a Gmail address.

    4. Your name and account details are missing

    Legitimate emails from a company you do business with will include your name and the last four digits of your account. If the email greets you with “Dear Customer” or a generic phrase, that is a red flag worth pausing on.

    5. There is a phone number inside the document itself

    Real PayPal transaction alerts do not include random customer service phone numbers inside DocuSign documents. Scammers include that number because they want you to call, so they can socially engineer you into giving up your information directly.

    6. No actual signature is required

    DocuSign exists for one core purpose: getting documents signed. If the document you are being asked to “review” has no actual signature requirement and is just an invoice or alert, someone is using DocuSign purely as a delivery vehicle to make the email look real.

    The Quick Verification Test

    Got an email from DocuSign mentioning PayPal and not sure if it is real? Do not click anything inside the email. Here is a simple way to check.

    Go directly to DocuSign.com, click “Access Documents” in the upper right corner, and enter the security code shown in the email. If you get an error message, that means the document was removed or never existed at all. That is confirmation it is a scam.

    At the same time, open a new browser tab and log into your PayPal account directly at paypal.com by typing it yourself. If there was genuinely a suspicious transaction or any account issue, it will be visible inside your PayPal dashboard. You do not need a DocuSign email to tell you about your own PayPal activity.

    “If someone sends you a PayPal payment screenshot as proof, verify any payment screenshot instantly before trusting it.”

    What to Do If You Already Clicked

    If you clicked a link or called the number in one of these emails, here is what to do right away.

    • Check your PayPal account: Log in directly and look at recent transactions. Anything suspicious should be reported immediately through the PayPal Resolution Center as fraud.
    • Change your passwords without delay: Update your PayPal password, your email password, and any other account that uses the same credentials. Enable two-factor authentication while you are at it.
    • Run a full antivirus scan: If you clicked any link in the email, there is a real possibility malware was downloaded onto your device. Run a complete scan before doing anything else online.
    • Contact your bank: If your PayPal account is connected to a bank account or card, let your bank know what happened so they can monitor for suspicious activity.
    • Report it to both platforms: Forward the phishing email to phishing@paypal.com. For the DocuSign abuse, use DocuSign’s Report Abuse feature on their website. Their team investigates suspicious accounts within 24 hours and closes them once confirmed.
    • File a complaint with the FTC: Visit reportfraud.ftc.gov to make an official report. This helps authorities track these campaigns and protect more people.

    Does PayPal Actually Send DocuSign Emails?

    This is the most common question people ask, and the answer in almost every real-world scenario is no.

    DocuSign is built for electronic document signing. PayPal is a payment processor with its own fully functioning notification system. There is no legitimate reason for PayPal to route a transaction alert, refund notice, or fraud warning through DocuSign.

    Some attackers invest in paid DocuSign accounts to access professional templates and send documents through official servers specifically to bypass email security filters. This is precisely why the email from PayPal via DocuSign looks so convincing: the delivery mechanism is technically real. The malicious content lives inside the document itself.

    If you ever receive an email titled “PayPal Customer Care via DocuSign,” treat it as a scam unless you have a very specific, pre-existing reason to expect that exact document.

    How to Stay Protected Going Forward

    You do not need to be a cybersecurity expert to stay safe from these attacks. A few consistent habits make a big difference.

    • Never click links in unexpected financial emails. If something involves your money or account security, go directly to the official website by typing the URL yourself. Do not follow email links, even if the email looks completely legitimate.
    • Recognize manufactured urgency. Scammers intentionally create panic to make you act before you think. An email claiming hundreds of dollars were just charged to your account is designed to bypass your rational thinking. Slow down. Check directly through the official app or website.
    • Turn on two-factor authentication for your PayPal account and email. Even if a scammer gets your password, they cannot access your account without the second verification step.
    • Keep your antivirus software current. Many modern tools now flag known phishing domains in real time, even when the originating email looks completely legitimate at a glance.
    • Be cautious of emails that demand immediate action, use generic greetings, or contain even minor misspellings or awkward phrasing. These are signals that something is off, even when the overall email looks polished.

    “Not sure if a link is safe? Check any suspicious URL here before clicking.”

    The Bottom Line

    The PayPal DocuSign phishing scam succeeds because it targets something completely reasonable: the habit of trusting familiar brands. When you see the DocuSign interface alongside a PayPal logo, your brain reads it as safe. That mental shortcut is the exact vulnerability being exploited.

    Once you understand how the docusign paypal scam works, the signals become obvious. The email arrived without any prior context. PayPal does not use DocuSign for transaction alerts. There is a random phone number inside the document. No actual signature is being requested.

    Any one of those signals should be enough to make you stop and verify before taking any action. Pass this along to someone you know who uses PayPal regularly. Awareness is genuinely the most effective defense against this kind of scam.

  • Mahadev App Scam: The ₹6,000 Crore Betting Scam That Is Still Not Over

    Mahadev App Scam: The ₹6,000 Crore Betting Scam That Is Still Not Over

    Two friends from a small city in Chhattisgarh built a betting app from Dubai. That app made ₹200 crore every single day. It pulled in Bollywood stars, a former Chief Minister, and top agencies like ED and CBI.

    And even after arrests, raids, and court orders, the app came back during IPL 2026.

    This is the full story of the Mahadev App scam. Everything in one place, no confusion.

    What Is the Mahadev App Scam?

    Mahadev App was an illegal betting platform. People used it to place bets on cricket, tennis, card games, poker, and even elections.

    It was run by two people: Saurabh Chandrakar and Ravi Uppal. Both from Bhilai, Chhattisgarh. Both operating from Dubai.

    But here is what made this different from a regular gambling website.

    They did not run it alone. They created over 3,200 “panels.” Think of each panel like a franchise. A local operator would get a panel, find users in their area, collect money, and send it up the chain. The app kept 70% of all profits. The operator kept 30%.

    This is how ₹200 crore was flowing in every single day.

    The numbers:

    • Total scam size: over ₹6,000 crore
    • Panels active across India: 3,200+
    • Assets attached by ED so far: over ₹2,600 crore
    • Daily earnings at peak: ₹200 crore

    All this money was hidden through fake bank accounts, hawala, shell companies, and crypto.

    Also Read: What Information Is Safe to Share Online? A Real Guide for Indian Users

    ₹508 Crore or ₹6,000 Crore? What Is the Real Number?

    You will see different numbers in different news articles. Here is what each one means:

    • ₹508 crore is what ED attached or froze in the early part of the investigation. It was just the beginning.
    • ₹6,000 crore is the total estimated size of the whole scam. This includes all betting money, laundered funds, and assets.
    • ₹2,600 crore is the total value of properties and assets ED has attached so far across India and Dubai.

    So no number is wrong. They are just measuring different things. The scam itself is ₹6,000 crore.

    The Full Timeline: 2022 to 2026

    1. 2022: Mahadev App quietly starts. The network grows fast in Chhattisgarh and then spreads across India.
    2. February 2023: Saurabh Chandrakar gets married in Ras Al-Khaimah, UAE. The wedding reportedly costs ₹200 crore. Bollywood artists are flown in. This wedding is what first caught the attention of ED.
    3. 2023: The ED begins investigation. An Interpol Red Corner Notice is issued against Chandrakar.
    4. Late 2023: Ravi Uppal is briefly detained in Dubai but is later released. He does not remain in custody.
    5. 2024: CBI and ED both run investigations at the same time. Raids happen across 29 locations in five districts of Chhattisgarh. The name of former Chief Minister Bhupesh Baghel comes up in the probe.
    6. October 10, 2024: Saurabh Chandrakar is formally arrested by UAE authorities. Indian officials are officially informed on this date. Extradition proceedings begin.
    7. March 26, 2025: CBI conducts searches at around 60 locations including Bhupesh Baghel’s homes in Raipur and Bhilai.
    8. March 2025: ED attaches ₹1,700 crore worth of properties in Dubai and New Delhi.
    9. November 2025: Ravi Uppal flees the UAE. The Supreme Court of India directs ED to trace him and calls out how the main accused keep escaping the legal system.
    10. April 2026: Mahadev App is active again during IPL season. Despite everything, the betting network is still running.

    Scammers often send fake payment screenshots, you can detect fake payment proof here.

    Who Are Saurabh Chandrakar and Ravi Uppal?

    • Saurabh Chandrakar grew up in Bhilai. He moved to Dubai and built the Mahadev App with his childhood friend Ravi Uppal.

      His February 2023 wedding in Ras Al-Khaimah is what really blew the cover off this scam. When investigators asked how a person could spend ₹200 crore on one wedding, the trail led straight to the app.

      He was formally arrested on October 10, 2024 by UAE authorities. Extradition to India is still ongoing.
    • Ravi Uppal was the co-founder. He was briefly detained in Dubai in late 2023 but was released. After that he stayed mostly off the radar. In November 2025, he fled the UAE completely. He is now officially a fugitive. The Supreme Court has ordered ED to find him.

      His escape is a big problem for investigators. Because as long as the people who built this network are free, the operation can always start again somewhere.

    Check: Fake UPI Payment Screenshot Scam: Complete Guide for Indian Shopkeepers

    How Did They Hide ₹6,000 Crore?

    This is the part that made ED and CBI both take this case so seriously. The money did not just sit in one bank account. It went through many layers on purpose.

    Step 1: Fake bank accounts Real people’s KYC documents were stolen and used to open thousands of fake accounts. Betting money came in through these first.

    Step 2: Shell companies The money then moved into fake companies that existed only on paper. This made the money look like business income.

    Step 3: Hawala Hawala moved money across borders with zero paper trail. No bank. No record.

    Step 4: Crypto Some money was converted to cryptocurrency. This made it almost impossible to track using normal banking systems.

    Step 5: Real estate Finally, the cleaned money was used to buy properties in Dubai and India. This is why ED has been able to attach ₹2,600 crore worth of assets.

    Every rupee passed through several of these steps. That is why untangling this has taken years.

    The Bollywood and Baghel Connection

    The Ras Al-Khaimah wedding is connected to both parts of this story.

    Several Bollywood celebrities attended or performed at Chandrakar’s wedding. ED called many of them in for questioning. The main question was whether they were paid in cash and whether they knew where the money was coming from. As of now, no celebrity has been formally charged.

    Bhupesh Baghel is a more serious name in this case. He was the Chief Minister of Chhattisgarh when the app was growing fast. His name came up in ED’s probe. On March 26, 2025, CBI searched around 60 locations including his homes in Raipur and Bhilai.

    Baghel publicly called the raids politically motivated and said they were timed to serve political purposes. His role in the case is still being investigated.

    The political angle makes this more than just a money laundering case. It is also a story about how illegal networks can grow when the right people look the other way.

    Where Does the Case Stand in 2026?

    Here is the current status of everything:

    • Saurabh Chandrakar arrested in UAE in October 2024, extradition pending
    • Ravi Uppal is a fugitive, Supreme Court has ordered ED to trace him
    • ₹2,600 crore in assets attached across India and Dubai
    • Bhupesh Baghel under investigation, CBI raids done in March 2025
    • EaseMyTrip CEO Nishant Pitti has also been probed by ED
    • The app came back during IPL 2026, showing the network is still alive

    Why Did Mahadev App Come Back During IPL 2026?

    This is the part that should worry everyone.

    In April 2026, reports confirmed that Mahadev App was running again during IPL season. Bans, arrests, raids, Supreme Court orders, nothing stopped it fully.

    The reason is how the network was designed. With 3,200 panels spread across India, the platform was never dependent on just two people at the top. When one operator gets caught, another picks up from where they left off. The whole thing was built to survive exactly this kind of pressure.

    This is also why Ravi Uppal still being free matters so much. The architects of this system have not been fully brought to justice. And until they are, the Mahadev betting scam will keep finding ways to come back.

    What This Case Is Really About

    The Mahadev app case is not just about two guys running a gambling website. It is about a much bigger problem:

    • Online gambling rules in India are still weak and easy to work around
    • Thousands of fake KYC accounts were created without anyone catching it for years
    • Hawala and crypto together make money almost untraceable
    • When powerful people are involved, investigations slow down
    • IPL season is peak time for illegal betting in India every single year

    The case is still going on. Until Ravi Uppal is caught and extradition for Chandrakar is completed, the final chapter of this scam has not been written.

    Sources: The Hindu, Moneycontrol, Times of India, Indian Express, ANI News, Tribune India, New Indian ExpressShare

    FAQs

    Why was the Mahadev app banned in India?

    It was running illegal betting without any license and washing thousands of crores through fake accounts and hawala networks. Authorities blocked it but the operation never fully stopped.

    What is the Mahadev app scam in simple words?

    An illegal betting app pulling in Rs 200 crore every single day through 3,200 local operators spread across India. The money was hidden through fake accounts, hawala and crypto. Total estimated scam size is over Rs 6,000 crore.

    Who is Saurabh Chandrakar and where is he now?

    One of the two co-founders, originally from Bhilai in Chhattisgarh. UAE authorities arrested him on October 10, 2024. He is currently in UAE custody and extradition to India is still pending.

    Is Ravi Uppal caught yet?

    No. He slipped out of the UAE in November 2025 and has been on the run since. The Supreme Court has directed ED to track him down. As of May 2026 he is still a fugitive.

    What is the connection between Mahadev app and Bhupesh Baghel?

    Baghel is the former Chief Minister of Chhattisgarh. His name surfaced during the ED investigation. CBI raided his properties in Raipur and Bhilai on March 26, 2025. His exact role is still being investigated.

    How did Mahadev app launder money?

    Through stolen KYC accounts, shell companies, hawala transfers, crypto conversions and finally into real estate in Dubai and India. ED has attached over Rs 2,600 crore in assets so far.

    Is Mahadev app still active in 2026?

    Yes. It was openly running during IPL 2026. The app works through 3,200 local panels across India, which means even with the founders behind bars, local operators keep the whole thing going.

  • What Information Is Safe to Share Online? A Real Guide for Indian Users

    What Information Is Safe to Share Online? A Real Guide for Indian Users

    Let me be honest with you. Most of us never really think about what we share online until something goes wrong. A scam call that knew your full name. A stranger who somehow had your address. A bank account drained overnight.

    That moment of “how did they get this?” is what this guide is trying to prevent.

    India Has a Very Specific Problem

    We are not talking about hacking in the Hollywood sense. No one is sitting in a dark room cracking codes to get into your accounts.

    What is actually happening is much simpler and honestly scarier. People are freely giving away information that criminals piece together like a puzzle. Your name from Instagram. Your workplace from LinkedIn. Your phone number from a WhatsApp group. Your home locality from a food delivery review you left two years ago.

    Put it all together and someone has enough to impersonate you, take a loan in your name, or clean out your UPI account.

    This is the reality for Indian internet users today. And most people have no idea it is happening.

    Start Here Before Anything Else

    Before getting into specifics, remember just one thing.

    Anything you share online can end up anywhere.

    Private Instagram. Closed WhatsApp group. Snapchat with disappearing messages. Does not matter. One screenshot and it lives forever. So before posting anything, ask yourself: would I be okay if this reached a complete stranger?

    If the answer is no, do not post it.

    So What Information Is Safe to Share Online?

    There is plenty you can put out there without any real risk. Your first name. The city you live in. Your opinions on films, cricket, food, or travel. Your professional wins on LinkedIn. Photos from a trip you already came back from. A restaurant review. A product recommendation.

    None of that, on its own, can hurt you.

    The problem is when you start combining things. Your first name is harmless. Your first name plus your employer plus your city plus your daily gym timing is enough for someone to find you in real life knowing exactly who you are.

    So when people ask which one of these is safe to share online, the honest answer is: it depends on what else you are sharing alongside it. A single piece of information is rarely the problem. The combination is.

    What Personal Information Should You Never Share Online

    This is the section that actually matters. Save it. Send it to your parents. Pin it somewhere.

    • Your Aadhaar number. This one gets misused more than anything else in India. With your Aadhaar, someone can get a new SIM issued in your name. With that SIM, they can reset your bank passwords and take over your accounts. You see how fast it goes.
    • OTPs. Any OTP. From any service. Ever. No bank, no government office, no legitimate company will ever call you and ask for an OTP. The second someone asks for it over call or chat, you are being scammed. Hang up immediately.
    • Your PAN number. Used in loan fraud and fake tax filings more than most people realize.
    • Real-time location. Posting “off to Shimla for a week!” tells every person following you that your house is sitting empty. Post the holiday photos when you are back home safe.
    • Your children’s details. Not their school name. Not their schedule. Not clear photos of their faces in public posts. This is non-negotiable.
    • Intimate photos. Even to someone you completely trust. Relationships end. Phones get stolen. Accounts get hacked. Draw this line firmly and do not move it.
    • Your full date of birth combined with your full name. Individually they seem fine. Together they are used to answer security questions and verify identity with banks and telecom providers.
    • Your mother’s maiden name. This one surprises people. It is one of the most common security questions used by banks. Once someone has it, they have a key.

    Is Sharing Aadhaar Card Number Online Safe?

    Short answer: No. Not even close.

    People share it in WhatsApp groups for housing societies, office onboarding, school admissions, and all sorts of everyday situations without thinking twice. It feels normal because everyone is doing it.

    But is sharing your Aadhaar card number online safe? Absolutely not. Your 12-digit Aadhaar number is linked to your mobile number, your bank account, and your entire financial identity. In the wrong hands, it can be used to get a SIM card issued in your name, which then becomes the key to everything else.

    If someone genuinely needs to verify your identity, use a masked Aadhaar instead. The UIDAI website lets you download a version that hides the first 8 digits. That is what you share, not the full card.

    And if someone is asking for your Aadhaar number over WhatsApp or email for a reason that feels even slightly off, trust that feeling.

    Also Read: Deepfake Scam in India: How AI Is Being Used to Cheat You

    The 5 Things Indians Specifically Keep Getting Wrong

    • Sending Aadhaar photos in group chats. Housing societies, office groups, school parent chats. It happens every single day and it is one of the riskiest habits on this list.
    • Trusting closed groups. A Facebook group with 300 members is not a private conversation. It is a room full of people, many of whom you have never actually met. Treat it like a semi-public space.
    • Filling every field in every online form. A food delivery app does not need your blood group. A loyalty card does not need your anniversary. If a field is optional, leave it blank.
    • Posting travel plans before leaving. Already said it above but worth repeating because it is that common and that easy to avoid.
    • Using the same photo on every platform. When your LinkedIn, Instagram, WhatsApp, and Gmail all use the same profile picture, it becomes easy to connect your identities across every platform you are on. Small change, real difference.

    Platform by Platform, Quickly

    • WhatsApp: Set your profile photo to contacts only. Turn off Last Seen for everyone outside your contacts. Never join groups from unknown invite links.
    • Instagram: If your account has photos of your home, your kids, or your daily routine, keep it private. Avoid location tagging posts taken at or near your house.
    • Facebook: Go through your friend list once a year. Remove people you would not recognize if you ran into them. Check your privacy settings every few months because they tend to reset quietly after updates.
    • LinkedIn: Do not put your personal phone number on your public profile. It will be scraped by bots and sold to spammers faster than you think.

    Check: WhatsApp Bans 9,400 Accounts Linked to Digital Arrest Scams: Supreme Court Told

    What the Law Says, Simply Put

    India’s Digital Personal Data Protection Act gives you the right to ask any company what data they hold on you and the right to ask them to delete it. Companies that leak your data now face serious penalties.

    On the flip side, sharing someone else’s private information, photos, or messages without their permission is a punishable offense under the IT Act. Forwarding an intimate image of someone, even if they once sent it to you willingly, is a criminal offense under Section 67A.

    Your data is protected by law. But so is your responsibility with someone else’s.

    If Something Has Already Gone Wrong

    First, do not panic. Then move quickly.

    Delete whatever you can still delete. Change passwords on every account connected to the information that got out. If money is involved, call your bank right now and ask them to freeze transactions while you investigate.

    File a complaint at cybercrime.gov.in or call 1930. That is India’s national cyber fraud helpline and it is the right first call to make.

    If your Aadhaar was compromised, go to uidai.gov.in and lock your biometrics immediately. It takes two minutes and can prevent a lot of damage.

    Conclusion

    Being careful online does not mean being paranoid or suspicious of everyone. It just means pausing for two seconds before you share something.

    Most privacy violations and scams targeting Indians do not happen through sophisticated attacks. They happen because someone shared the wrong detail with the wrong person at the wrong time, usually without even realizing it.

    You now know what that looks like. That already puts you ahead of most people.

    Frequently Asked Questions

    Q1: Which one of these is safe to share online?

    Your first name, a secondary email address, general interests, professional profile, and UPI ID for receiving payments are all relatively safe. OTP, Aadhaar number, PAN card, CVV, UPI PIN, and any banking credentials should never be shared with anyone under any circumstances.

    Q2: What information is safe to share online?

    Non-sensitive details like your first name, general location (city only), hobbies, secondary email, and professional work are safe to share. What is not safe: government IDs like Aadhaar and PAN, financial details like CVV and UPI PIN, one-time passwords, and your exact home address.

    Q3: What personal information should you never share online?

    Your full Aadhaar number, PAN card combined with date of birth, OTP, CVV, UPI PIN, net banking password, ATM PIN, passport scan, home address, and bank statements. No legitimate service in India will ever ask for these over a call, message, or email.

    Q4: Which information is risky to share online?

    OTP, full Aadhaar number, PAN combined with date of birth, CVV, UPI PIN, bank passwords, home address, and passport scans. These individually or in combination give scammers everything they need to commit fraud in your name.

    Q5: What are the top 3 data privacy risks in India?

    Identity theft using Aadhaar and PAN details, financial fraud through OTP and UPI PIN scams, and social engineering where scammers use your personal information to build trust before stealing from you.

    Q6: Is sharing your Aadhaar card number online safe?

    No. Sharing your full 12-digit Aadhaar number can lead to identity theft and SIM swap fraud. Use UIDAI’s Masked Aadhaar or Virtual ID instead. Only share on verified government portals with HTTPS.

    Q7: Is sharing passport details online safe?

    Never share a passport scan or photo on WhatsApp, email, or social media. Only upload it on verified visa processing or official government portals. Passport combined with date of birth is one of the most dangerous combinations for identity theft.

    Q8: Can someone misuse your PAN card details?

    Yes. PAN combined with date of birth can be used to file fake tax returns, open fraudulent bank accounts, or take loans in your name. Only share PAN on verified income tax or banking portals.

    Q9: Can someone misuse your phone number?

    By itself, a phone number is limited. But combined with other data, it enables SIM swap attacks where a scammer gets a new SIM issued on your number and then intercepts all your OTPs. Never confirm personal details to unsolicited callers.

    Q10: Is it safe to share photos online?

    Photos are generally fine as long as they do not reveal your home address, school or workplace name, car number plate, location tags, or any documents visible in the background. Always turn off geotagging before sharing.