Category: Blog

Your blog category

  • WhatsApp Bans 9,400 Accounts Linked to Digital Arrest Scams: Supreme Court Told

    WhatsApp Bans 9,400 Accounts Linked to Digital Arrest Scams: Supreme Court Told

    WhatsApp has banned over 9,400 accounts connected to digital arrest scams in India. The government revealed this in front of the Supreme Court as part of ongoing suo motu proceedings against cyber fraud.

    This is one of the biggest coordinated actions taken against digital arrest scammers in India so far. And if you or someone in your family has ever received a suspicious call from someone claiming to be a CBI officer or a customs official on WhatsApp, this story directly concerns you.

    Here is everything you need to know, based entirely on court submissions and verified news sources.

    What Happened?

    In January 2026, WhatsApp launched a dedicated 12-week investigation specifically targeting digital arrest scams in India. This was done in response to inputs from the Indian Cyber Crime Coordination Centre (I4C), the Ministry of Electronics and Information Technology (MeitY), and the Department of Telecommunications (DoT).

    WhatsApp followed a clear strategy for this investigation: identify seed signals, map the full criminal network, ban the entire network, and then build automated defences to prevent new accounts from doing the same thing.

    The result was 9,400 accounts banned in one targeted operation.

    Critically, WhatsApp went much further than what government agencies had requested. Authorities had flagged around 3,800 scam-related accounts under Section 79 of the IT Act. Of those, only 17 were directly tied to digital arrest scams. But WhatsApp treated each government input as a starting point to map and disrupt entire criminal networks, which led to the much larger ban.

    As WhatsApp stated in its submission: “WhatsApp does not treat signals from investigation agencies and Government of India as isolated, one-off reports. Each signal is treated as a seed to map and disrupt the entire criminal network.”

    Source: Bar and Bench

    Why Is the Supreme Court Involved?

    This case began in October 2025 when a senior citizen couple from India wrote directly to the Supreme Court after losing Rs 1.5 crore in just 16 days. Between September 1 and 16, 2025, scammers had called them pretending to be CBI officers, Intelligence Bureau officials and judicial authorities. They showed forged Supreme Court orders on WhatsApp video calls and threatened the couple with arrest unless they paid immediately.

    The Supreme Court took suo motu cognizance of the matter. This means the Court registered the case on its own without anyone filing a formal petition. It directed the CBI to investigate the digital arrest scam network and called for coordinated action across all central government agencies.

    In December 2025 the Court went further and ordered a full CBI probe specifically into digital arrest scams across India. The agency was also given authority to investigate bankers linked to mule accounts being used to route cyber fraud money.

    The update shared in court today was submitted by Attorney General R. Venkataramani on behalf of I4C. It was a formal status report covering all actions taken since the Supreme Court’s last directions on February 9, 2026.

    Key Numbers from the Court Submissions

    These figures come directly from the government’s status report filed before the Supreme Court today:

    • 9,400 WhatsApp accounts banned linked to digital arrest scams
    • 2,41,000+ complaints related to digital arrest scams recorded in India
    • Rs 30,000 crore in total losses reported by victims across the country
    • Rs 22.92 crore lost by a single victim in one Delhi case
    • Rs 1.5 crore lost by the senior citizen couple whose letter triggered the Supreme Court case
    • 3 major cases re-registered by CBI, each involving losses above Rs 10 crore (two from Gujarat, one from Delhi)

    Where Are These Scammers Operating From?

    According to WhatsApp’s own investigation findings submitted to the court, most accounts targeting Indian users were being run from organised scam centres in Southeast Asia, particularly Cambodia.

    These are not individuals acting alone. They are professional criminal operations running coordinated call centres with scripts, fake uniforms, fake government office setups, and teams working around the clock to target Indian phone numbers.

    WhatsApp found that fraudsters were using display names like “Delhi Police,” “Mumbai HQ,” “CBI,” and “ATS Department,” along with official-looking logos as profile pictures to appear credible to victims.

    This is also why this problem cannot be solved by Indian law enforcement alone. As WhatsApp noted in its submission, “many scams involve off-platform payment, coercion, and criminal infrastructure. WhatsApp can disrupt the accounts and networks; dismantling the underlying criminal operations requires coordinated multi-jurisdictional law enforcement action.”

    Also Read: WhatsApp Wedding Invite Scam: One Tap Can Empty Your Bank

    What New Technology Is WhatsApp Deploying?

    Beyond just banning accounts, WhatsApp has also built new systems to detect and prevent such scams going forward. These include:

    • A logo-matching system to detect accounts impersonating police or government bodies
    • Logging of account display names to track scam patterns
    • A large language model trained specifically to identify evolving digital arrest scam tactics
    • A database of known scam assets to enable faster detection of repeat offenders

    WhatsApp is also rolling out user-facing protections, including:

    • Warnings for suspicious first-time messages from unknown numbers
    • Visibility of account age for unknown contacts
    • Suppression of profile photos in high-risk interactions
    • Enhanced caller information display for unknown numbers

    WhatsApp says these combined measures are expected to create a “material and observable decline” in such scams on the platform.

    What Other Agencies Are Doing

    The status report also covered steps being taken by other government departments:

    • Department of Telecommunications: The proposed Biometric Identity Verification System for real-time SIM verification is currently at proof-of-concept stage. Full implementation is not expected before December 2026.
    • Telecom operators have been directed to reduce SIM blocking time for suspicious numbers to 2 to 3 hours, since most fraudulent calls happen within the first few hours of a new SIM being activated.
    • Reserve Bank of India: RBI has issued draft directions proposing that victims losing up to Rs 50,000 in fraudulent digital transactions may be compensated up to 85 per cent of the net loss or Rs 25,000, whichever is lower. This compensation would be available once per customer’s lifetime.
    • Department of Revenue: No rules have yet been framed under Section 12AA of the Prevention of Money Laundering Act, 2002, which would allow banks to temporarily freeze suspicious transactions. The Department indicated that framing these rules may take 30 to 45 days.
    • CBI: Three major digital arrest cases have been re-registered for deeper investigation. The Delhi case involves a single victim who lost Rs 22.92 crore.

    Check: LPG Cylinder Scam on WhatsApp

    What Is a Digital Arrest Scam?

    If this is your first time hearing this term, here is what it means.

    Scammers call you on WhatsApp video, dressed in fake police uniforms or sitting in front of what looks like a government office background. They tell you that your Aadhaar card, phone number or bank account has been linked to a serious crime like drug trafficking or money laundering.

    Then they tell you that you are under digital arrest. You cannot hang up, cannot contact anyone, and will be physically arrested if you disconnect. They keep you on that call for hours, sometimes days, wearing you down until you transfer money just to make it stop.

    Here is the most important thing to understand about digital arrest in India. It does not exist. There is no such thing in Indian law. No police officer, no CBI agent, no court official in India will ever call you on WhatsApp to threaten you with arrest or demand money over a video call.

    If you receive a call like this, hang up immediately. It is a scam, every single time.

    How to Protect Yourself

    You do not need to wait for the government or WhatsApp to protect you. Here is what you can do right now:

    • If you receive a WhatsApp video call from an unknown number claiming to be a police officer, CBI agent or any government official, hang up immediately. Do not engage, do not explain yourself, just hang up
    • Never share your OTP, Aadhaar number, bank details or UPI PIN during any call, no matter how official the person sounds or looks
    • Do not transfer money to anyone who identifies themselves as a law enforcement officer over a call. Real officers do not work this way
    • Enable two-step verification on WhatsApp right now. Go to Settings, then Account, then Two-Step Verification. Takes two minutes and makes your account significantly harder to misuse
    • Save 1930 in your phone contacts today. This is India’s National Cyber Crime Helpline and the first number you should call if something like this happens to you or anyone in your family.

    If you receive a suspicious link on WhatsApp, do not click it. Paste it into ScamDekho’s free URL Checker to find out instantly whether it is safe or a scam.

    If You Have Already Lost Money

    Act immediately. Every hour matters.

    1. Call 1930 right now. This is the National Cyber Crime Helpline and the fastest way to get the right people alerted
    2. File a complaint at cybercrime.gov.in with all the details you have, screenshots, transaction records, the scammer’s number, everything
    3. Call your bank immediately and ask them to freeze or reverse the transfer before the money moves further
    4. Save everything. The scammer’s number, their account details, any screenshots from the call or chat

    The Supreme Court has specifically pushed for faster response times from banks in digital arrest cases. The sooner you report, the better your chances of getting something back..

    Why This News Matters

    Two things stand out from today’s court proceedings.

    First, the scale of the problem is enormous. Over 2.41 lakh complaints. Rs 30,000 crore in losses. A single victim in Delhi losing Rs 22.92 crore. These are not isolated incidents. This is a national crisis that is actively growing.

    Second, the response is finally becoming coordinated. For the first time, WhatsApp, the CBI, RBI, DoT, MeitY, and I4C are all working together under Supreme Court supervision. That kind of multi-agency coordination has not happened before on this issue.

    But even with all of this, scammers create new accounts every single day. No government action replaces personal awareness. Knowing how this scam works is the single most effective protection you have.

    Share this article with your family today, especially parents and elderly relatives. One conversation could stop someone from losing everything.

  • How to Verify a Company Before Joining or Paying in India (2026)

    How to Verify a Company Before Joining or Paying in India (2026)

    You got a job offer. Or maybe someone is asking you to pay before your first day. It looks real. The logo is there. The letter has your name on it.

    But is the company actually real?

    Every day in India, people lose money or personal data to companies that exist only on paper or not at all. The scary part is that most victims trusted the offer because it “looked legitimate.”

    This guide will show you exactly how to verify any company in India before you join, sign anything, or send a single rupee.

    Why Does This Matter?

    Fake company scams are not just about job offers. People get scammed when:

    • A “company” sends a job offer and asks for a security deposit
    • Someone sells a product or service in a company’s name that does not exist
    • A recruiter collects your Aadhaar and PAN “for onboarding” and disappears
    • A vendor asks for advance payment and ghosts you

    The damage is not just financial. Once your documents are out, they can be used for identity fraud.

    If someone is asking you to trust a company, verify it first. It takes less than 10 minutes.

    Step 1: Check the Company on MCA Portal (Free and Official)

    The Ministry of Corporate Affairs (MCA) maintains a public database of every registered company and LLP in India. This is your first and most important check.

    Here is how to do it:

    1. Go to mca.gov.in
    2. Click on MCA Services in the top menu
    3. Select View Company/LLP Master Data
    4. Enter company name or its CIN (Corporate Identification Number)
    5. Click Submit

    You will see the company’s registration status, date of incorporation, registered address, director names and filing history. No account needed, no payment, nothing.

    What you are looking for:

    • Status should be Active. If it says “Strike Off” or “Under Process of Striking Off,” stop immediately. Do not pay, do not share documents, do not join.
    • The registered address should roughly match what the company told you.
    • There should be recent annual filings (MGT-7 and AOC-4). A company with no filings for years is a red flag.

    Important note: This only works for Private Limited companies, Public Limited companies, and LLPs. Sole proprietorships and general partnerships are not registered on MCA. If a company claims to be a “Private Limited” but has no MCA record, that is a major warning sign.

    Step 2: Verify the GST Number

    Any business in India with a turnover above a certain threshold must register for GST. Most genuine businesses will have a GSTIN.

    To verify:

    • Go to gst.gov.in
    • Click on Search Taxpayer
    • Enter the GSTIN shared by the company

    This will show the legal name, registration status and business type. If the details do not match what the company told you, something is off.

    If a company is claiming to be a large business but has no GST registration, ask them to explain. Most genuine companies will have one.

    Step 3: Check the Email Domain

    This one is simple but it catches a lot of fakes.

    Real companies use their own domain for email. That is just how businesses work.

    If someone is contacting you from a Gmail, Yahoo or Outlook address while claiming to represent a company, stop and think before you respond. It does not always mean it is a scam but it means something is worth checking.

    Google the company name, find their actual website and see if the email domain matches. Takes two minutes.

    Also watch out for domains that look almost right but are not. Scammers register things like tata-careers.com or infosys-hr.com specifically because they look convincing at a quick glance. Read the domain carefully every single time.al. Always check the actual official website domain.

    Step 4: Look Them Up on LinkedIn

    Go to LinkedIn and search for the company by name. A genuine business of any size will have a LinkedIn page with employees, a description, and some activity.

    Check:

    • Does the company profile exist and look active?
    • Can you find the person who contacted you on LinkedIn?
    • Do their work history and company connection look real?

    If the “HR manager” who sent you an offer has a LinkedIn profile with no connections, a blank history, and was created last month, that is suspicious.

    You can also search the name of the company on Google News to see if they have any press coverage, announcements, or complaints.

    Step 5: Call the Company’s Official Number

    Find the company’s phone number yourself. Go to their official website and get it from there, not from the offer letter and not from the recruiter’s message.

    Then call and ask two simple questions:

    • Is this person actually employed here?
    • Do you have an opening for this role?

    Five minutes. That is all it takes. And it catches fake offers almost every single time.immediately. Scammers cannot control calls to the real company.

    Step 6: Check Glassdoor and Ambitionbox

    These platforms have real employee reviews. Search the company name and see what past and current employees are saying.

    Look for:

    • Reviews mentioning salary not being paid
    • Complaints about fake promises at the time of joining
    • Warnings from other candidates who had similar experiences

    No reviews at all for a company that claims to have 500 employees is itself a red flag.

    You can also check platforms like Trustpilot or simply Google the company name with words like “fraud,” “fake,” or “complaint” to see if others have already flagged it.

    Also Read: Matrimonial Scam in India: Fake Profiles, NRI Fraud and How to Stay Safe

    Red Flags That Should Stop You Immediately

    Before you verify anything else, these signs should make you stop and investigate:

    • They are asking for money before you join. No genuine company in India charges candidates for joining, training, a laptop deposit, a security deposit, or anything else. This is the single biggest red flag. If money is being asked before your first working day, walk away.
    • The offer came out of nowhere. You never applied. They somehow found you and are very eager to hire you. Real companies that are interested in you will always have a traceable hiring process.
    • There is urgency. “Pay within 24 hours or the offer will be cancelled.” Real HR teams do not operate with this kind of pressure. This is a manipulation tactic.
    • The salary is unusually high. A fresher being offered 80,000 per month for basic data entry work. Scammers use unrealistic salaries to attract attention.
    • They want your documents early. Asking for Aadhaar, PAN, or bank details before you have even confirmed the job or met anyone in person is suspicious. Your documents are valuable. Share them only when you are sure the company is real.

    What If You Already Paid or Shared Details?

    If you already sent money:

    • Call 1930 immediately. The faster you call the better the chance of freezing the transaction before it is withdrawn
    • File a complaint at cybercrime.gov.in
    • Call your bank and ask them to raise a dispute

    If you already shared documents like Aadhaar or PAN:

    • Keep a close eye on your bank accounts and credit report for anything unusual
    • Lock your Aadhaar biometric temporarily on the UIDAI website
    • Report the incident at cybercrime.gov.in

    Read our guide on how to recover money lost in an online scam in India for detailed steps.

    Quick Summary: Company Verification Checklist

    Before you join or pay, check this:

    • Search the company on the MCA portal. The status must show Active
    • Verify their GSTIN on gst.gov.in
    • Check that the recruiter’s email matches the company’s official domain
    • Find the person on LinkedIn and make sure their profile looks real
    • Call the company’s official number yourself and confirm the offer exists
    • Look up reviews on Glassdoor or Ambitionbox
    • If anyone asks for money at any point, stop everything and report it

    One Rule That Never Fails

    Employment is based on your skills, not your money. No real company charges you to work for them. No legitimate HR team asks for a security deposit before your joining date. No genuine recruiter needs you to pay for a background check, a training kit or an ID card.

    If anyone at any point during a hiring process asks you to transfer money, pause everything. It does not matter how professional the offer letter looks, how many rounds of interviews you went through or how badly you need the job. The moment money is involved on your end, something is wrong.

    Verify before you get excited. Check the company on the MCA portal. Confirm the email domain. Call the official number. Look up the recruiter on LinkedIn. Five minutes of checking can save you months of regret.

    And if something feels off, trust that feeling. Not every red flag is obvious. Sometimes it is just a gut sense that something does not quite add up. Do not talk yourself out of it. Check first, join later.

  • Matrimonial Scam in India: Fake Profiles, NRI Fraud and How to Stay Safe

    Matrimonial Scam in India: Fake Profiles, NRI Fraud and How to Stay Safe

    A woman from Mumbai was talking to a man named Michael Williams on BharatMatrimony. He said he was from the UK. They talked every single day. He was sweet, he listened, he remembered things. After weeks of calls she genuinely felt something for him.

    He told her he was coming to India to meet her.

    On the day he was supposed to land her phone rang. He was panicking. Airport customs had stopped him. Too much foreign currency. He just needed her to send some money for a certificate, something called an anti-terrorist certificate, and he would be out within hours.

    She sent it.

    He never called again.

     ₹ 2.93 lakh. And a person she thought was real, both gone the same day. When she reached out to BharatMatrimony they told her his profile was already gone and that it had always been her responsibility to check who she was talking to.

    She is not alone in this. Not even close. Someone in India is going through this exact thing right now, on some app, trusting someone who does not exist.

    India lost  ₹ 22,845 crore to cyber fraud in 2024, a number the Ministry of Home Affairs shared in Parliament. Matrimonial fraud alone has shot up 206% in a year. Romance scams drain over Rs 500 crore annually. More than 12,000 complaints were filed in this one category in 2024. And that is only the people who actually told someone. Most never do because losing money hurts but telling people you fell for someone who was never real hurts differently.

    If someone in your family is on BharatMatrimony, Shaadi.com, Jeevansathi or any matrimonial app, please read this carefuly.

    What Is a Matrimonial Scam?

    Matrimonial scams are planned. The person who made that fake profile was not confused or lonely. They knew exactly who they were looking for. Someone genuine. Someone hoping to find a life partner.

    That person then spends weeks, sometimes months, just building trust. Daily messages, emotional conversations, small details that make everything feel real. The victim is not being careless. They are just responding to what feels like a real connection.

    By the time money is asked for, the emotional damage is already done. Walking away at that point feels like losing a person, not avoiding a scam.

    This is what makes matrimonial fraud so serious. The scammer did not exploit a mistake. They exploited sincerity. And that is a very different thing.

    Who Gets Targeted?

    Anyone on a matrimonial platform can be targeted, but fraudsters specifically look for:

    • Women in their late 20s to 40s under family pressure to get married
    • Widows or divorcees who may be emotionally vulnerable
    • People from smaller cities who are less experienced with online fraud
    • Families with good financial backgrounds who mention assets or property in profiles
    • Men and women searching for NRI matches who may be impressed by foreign lifestyles

    Delhi, Mumbai, and Bengaluru top the list of most affected cities. But Tier 2 and Tier 3 cities are increasingly targeted because awareness is lower and victims are less likely to report.

    Common Types of Matrimonial Scams in India

    1. The Fake NRI Groom or Bride Scam

    This is the most reported type of matrimonial fraud in India. The scammer shows up as a successful NRI, based in the US, UK, Canada, or Australia. The profile looks convincing. Good English, a professional photo, a clean backstory. Doctor, engineer, businessman. Someone any family would approve of.

    Weeks of conversation follow. Sometimes months. Then comes the plan to visit India, meet the family, make things official. And then something goes wrong. A medical emergency. A customs issue. A visa problem. Money is needed urgently. The victim transfers it. The scammer is gone.

    In June 2025, Pune Cyber Police arrested Abhishek Shukla an Australian citizen from Lucknow, at Mumbai International Airport. He had been using the name Dr. Rohit Oberoi on Shaadi.com. His target was a 40-year-old divorced woman living in Pune’s Kharadi area. Over time, she transferred Rs. 3.6 crore across four bank accounts, including one in Citibank Singapore. She believed they were going to get married and build a business together.

    When police investigated, they found Shukla had reached out to over 3,000 women using fake matrimonial profiles.

    One man. Three thousand targets. One got caught.

    Source: NDTV

    2. The Fake Army Officer Scam

    Scammers impersonate Indian Army, Navy, or Air Force officers using fake ID cards and official-looking documents. The military profession creates immediate trust. Parents feel reassured. The victim feels proud.

    After building trust, the fraudster claims they need money for a transfer fee, a no-objection certificate to marry, or an urgent personal emergency. By the time the victim realizes the person was never in the military, large amounts have been transferred.

    In one case uncovered by police, a family was looking for a groom for their daughter and matched with someone claiming to be an IAS officer. They even verified his profile photo. But when they searched the DoPT (Department of Personnel and Training) database, his name did not exist. He had already collected their daughter’s photographs.

    3. Fake Dowry and Wedding Expense Scam

    Some fraudsters go further. They actually agree to an engagement or marriage. They meet the family in person or on video call. Everything seems real.

    Then they start asking for money. Venue bookings. Travel costs for relatives from abroad. Dowry discussions. “Just transfer the amount and we will settle everything after the wedding.”

    Once the money is transferred, they vanish. Sometimes the entire “family” they introduced was also part of the scam.

    4. The Sob Story and Emergency Scam

    After weeks of emotional bonding, the scammer hits a crisis. Medical emergency. Business loss. Passport stolen. The ask is always urgent and the reason always sounds temporary. Just until we meet. Just until after the wedding.

    The victim is not being foolish at this point. They are being caring. They have invested real emotion into this relationship and sending money feels like the natural thing to do for someone you love.

    And it does not stop at one transfer. The crisis comes back. A new problem surfaces. Each time the victim gives, it becomes harder to accept that none of it was real. So they keep going.

    In 2025, more than 10 women in Visakhapatnam lost a combined Rs. 20 lakh to NRI scammers using this exact pattern. Most of them never filed a complaint. Not because they did not know they were cheated. But because they were ashamed.

    That shame is also part of the trap.

    5. Fake Matrimonial Websites

    In 2025, Chhattisgarh police busted a gang that had built six fake matrimonial websites from scratch. One of them was even called Indian Royal Matrimony. These were not rough, obviously fake pages. They looked legitimate enough for people to pay membership fees and hand over personal information without suspecting anything.

    Behind the sites was a full call center operation. Real people calling victims, building conversations, creating relationships. The fraud was not automated. It was run like a business.

    By the time the gang was arrested, over 500 people had already been cheated.

    6. Document and Identity Theft

    Some scammers are not after your money directly. They ask for documents instead. Aadhaar, PAN, passport copies, bank statements. The reason always sounds legitimate. Marriage paperwork. Visa formalities. Legal requirements from their side.

    Once they have those documents, the damage goes far beyond the relationship. Your identity can be used to open fake bank accounts, take loans, or your information gets sold on the dark web to people you will never trace.

    The financial loss from a scam can sometimes be recovered. Identity theft is a much longer and harder problem to fix.

    Never share scanned copies of your personal documents with someone you have only spoken to online. No matter how long you have been talking. No matter how real it feels. Until you have met them in person and verified who they actually are, those documents stay with you.

    7. Sextortion Through Matrimonial Platforms

    Some scammers are not after money from day one. First comes the relationship. The trust. The late night conversations. And once that is established, things slowly shift toward personal photos or private video calls.

    Then comes the threat. Send money or this goes to your family. Your office. Your contacts.

    At that point the victim is not just dealing with financial loss. They are dealing with fear. Real, daily fear about their own life being used against them.

    Most people in India never report this. Not because they do not know it is wrong. But because coming forward feels more dangerous than staying silent. That is exactly what the scammer wants.

    If this has happened to you, understand one thing clearly. You did nothing wrong. Trusting someone is not a crime. What they did is. Call 1930 immediately and report it. The sooner you do, the better your chances of stopping them.

    Warning Signs of a Matrimonial Scam

    Watch for these red flags before it is too late:

    • The profile looks too perfect: highly educated, great job, handsome or beautiful, living abroad
    • They fall in love or get serious very quickly, within days or a week or two
    • They avoid video calls or make excuses like bad internet or camera not working
    • They ask about your financial situation, property, savings, or investments early on
    • They always have an emergency that requires money
    • They say they are coming to India but always face some problem at the last minute
    • They pressure you to keep the relationship secret from family members
    • Their English or communication style suddenly changes between messages
    • Reverse image search on their photo shows it belongs to someone else

    Also Read: Online Gaming Scams in India: Free Fire, BGMI and Roblox Frauds

    How to Verify a Matrimonial Profile Before Going Further

    Step 1: Do a Reverse Image Search

    Save their profile photo and upload it to Google Images or TinEye. If that same photo shows up with a different name or on a stock photo site, you have your answer. This one step alone can save you from months of emotional damage.

    Step 2: Video Call First

    Before you get emotionally involved, ask for a live video call. Scammers will delay, make excuses, or simply refuse. If someone says they love you but cannot spare five minutes on camera, something is wrong.

    Step 3: Verify Their Employer or Business

    They say they are a doctor in London or an engineer in Canada. Search the company. Search their name on LinkedIn. Ask them to show their work ID on a call. Takes five minutes. A genuine person will not mind.

    Step 4: Check Suspicious Links They Send

    Some scammers send links to fake investment platforms, fake booking sites, or fake emergency payment portals. Before clicking any link they share, use ScamDekho’s URL Checker to verify if the link is safe.

    Step 5: Check Messages for Scam Signs

    If they send you messages that feel scripted, too emotional too fast, or contain requests for money or documents, check the message using ScamDekho’s Scam Message Checker before responding.

    Step 6: Meet in Person With Family Present

    Before any money, documents, or serious commitment, meet them in person. Take a family member along. Anyone with real intentions will understand this. Anyone who refuses should tell you everything.

    Step 7: Never Transfer Money

    No matter how long you have been talking or how real it feels, do not transfer money to someone you have not met in person. A genuine partner will never put you in that position.

    What to Do If You Have Already Been Scammed

    Do not feel ashamed. These people do this for a living. You were targeted, not stupid.

    Here is what you need to do right now.

    • Block them everywhere: Do not reply to anything, not even to confront them. Every response you give is another opportunity for them to manipulate you.
    • Do not send more money: They will come back with a worse story or a direct threat. That is part of the plan. Do not give in.
    • Call 1930: This is the national cyber crime helpline. Tell them everything. Transaction IDs, numbers, screenshots, whatever you have.
    • Go to cybercrime.gov.in and file a written complaint: This creates a legal record and matters if the case goes further.
    • Visit your local police station and file an FIR: Carry every proof you have. Under Bharatiya Nyaya Sanhita 2023, cheating through impersonation can lead to 7 years in prison.
    • Report the profile on the platform: There is a Report Abuse option on every matrimonial site. Use it so the next person does not go through what you did.
    • Call your bank: If money moved through UPI or a bank transfer, raise a fraud dispute immediately. The sooner you call, the better the chance of getting it back.

    You can also read our full guide on how to recover money lost in an online scam in India for a complete step-by-step recovery process.

    What Laws Apply to Matrimonial Fraud in India?

    Victims have strong legal protection under Indian law:

    Bharatiya Nyaya Sanhita 2023 (BNS): Cheating and impersonation through electronic means carries imprisonment of up to 7 years and heavy fines. Organized crime syndicates face enhanced penalties.

    IT Act 2000, Section 66C and 66D: Identity theft and impersonation using computer resources. Up to 3 years imprisonment and Rs. 1 lakh fine.

    IT Act 2000, Section 66E: Publishing private images without consent (used in sextortion cases). Up to 3 years and Rs. 2 lakh fine.

    Aadhaar Act 2016: If your Aadhaar was obtained and misused through the matrimonial scam, additional charges under the Aadhaar Act apply.

    How to Use Matrimonial Platforms Safely

    Follow these rules every time:

    • Never put your phone number or financial details in your public profile. That information does not belong there.
    • Use the platform’s internal messaging system until you are genuinely confident about the person. Moving to WhatsApp too early gives them direct access to you outside any platform oversight.
    • Do not share personal photos beyond what is already on your profile. Not until you have met them in person.
    • Never share scanned copies of Aadhaar, PAN, passport, or bank statements with anyone you have only spoken to online. No matter how far the conversation has gone.
    • Always involve a trusted family member before any major decision. A second pair of eyes catches what emotions sometimes miss.
    • Trust your instincts. If something feels slightly off, do not ignore it. That feeling exists for a reason.
    • Report suspicious profiles immediately even if you are not completely sure. You do not need proof to report. Let the platform investigate and decide.
  • Online Gaming Scams in India: Free Fire, BGMI and Roblox Frauds

    Online Gaming Scams in India: Free Fire, BGMI and Roblox Frauds

    Akshay Kumar recently revealed that his own daughter was targeted by scammers while playing an online game. If it can happen to a celebrity’s child, it can happen to yours too.

    A 14-year-old boy from Panchkula was extorted for Rs. 4 lakh by people he met while playing an online game. A family in Ajmer lost Rs. 10.85 lakh after their child made a “friend” on Free Fire. And in Lucknow, a gang of teenagers ran a fake gaming operation that cheated over 2.5 lakh people out of Rs. 500 crore.

    Online gaming scams targeting kids and teens in India are rising faster than most parents realize. Gaming frauds have gone up by 300% since 2023 according to I4C data. And 65% of Indian kids between the ages of 8 and 15 play online games daily.

    This guide covers every scam type, real cases, and exactly what parents and kids need to do to stay safe.

    Why Are Kids Being Targeted?

    Scammers do not randomly pick victims. They specifically go after young gamers because:

    • Kids are trusting by nature and less likely to question an offer
    • They want to win badly and will take shortcuts for free diamonds or UC
    • They have access to their parents phones, UPI apps and bank accounts
    • They feel embarrassed to tell parents if something goes wrong
    • They do not fully understand what sharing an OTP or password means

    Most scams happen not because kids are careless, but because the traps are designed specifically for them.ss, but because the traps are designed specifically for them.

    Most Common Gaming Scams Targeting

    Indian Kids in 2026

    1. Free Diamonds and Free UC Generator Scams

    This is the most common trap. Your child is playing Free Fire or BGMI and comes across a YouTube comment, a WhatsApp forward, or an Instagram link that says something like:

    “Get 10,000 Free Diamonds instantly! No survey! 100% working!”

    They click it, type in their game ID, sometimes even their password. The site looks real enough. What they do not know is that it was built to steal exactly what they just typed in. Some of these sites go further and ask for an OTP to verify the diamond transfer. The moment your child shares that OTP, whoever is on the other end has access to the UPI app or bank account on that phone.

    Krafton, the company behind BGMI, ran an awareness campaign in 2025 specifically because thousands of players had fallen for fake UC generator sites designed to look identical to Codashop.

    2. Fake Codashop and Top-Up Sites

    Codashop is a legitimate platform where players buy BGMI UC and Free Fire diamonds. Scammers build copies of it that look almost identical.

    A kid searches for cheap UC India or Free Fire diamonds discount and lands on one of these fake pages. They pay via UPI. The money leaves their account and nothing arrives. Some of these sites also quietly save the UPI details and card numbers entered, and use them weeks later for transactions the family never notices until it is too late.

    3. The Fake Friend Scam

    This one does not happen overnight. A stranger sends a friend request on the game, on Discord, or on Instagram. They play together for days, sometimes weeks. They seem genuinely friendly. Then slowly things shift:

    • They mention a special method to get free UC or diamonds
    • They ask for the game account login to transfer the rewards themselves
    • They ask for an OTP claiming it is needed for verification
    • They start asking for small amounts of money, saying they are in trouble

    In the Ajmer case from December 2025, this is exactly how it started. A friendship on Free Fire. Weeks of playing together. Then access to the family’s phone and bank account. Rs 10.85 lakh gone.

    4. Fake Game Customer Support Scams

    The message comes on WhatsApp or Instagram and sounds urgent:

    “Your account has been flagged for suspicious activity. Share your login details within 24 hours or your account will be permanently banned.”

    A kid who has spent months building their account reads that and panics. They share what is asked. The scammer gets in, takes over the account, and in many cases comes back demanding money to return it or threatening to report the account themselves.

    No game company, whether it is Free Fire, BGMI or Roblox, will ever contact a player through WhatsApp or Instagram. Every real communication from these companies happens through the official app or the registered email address. Nothing else.

    5. Fake Mod, Skin, and Cheat Download Scams

    Kids searching for “Free Fire mod apk” or “BGMI unlimited UC hack download” end up downloading malicious files. These files infect the phone with malware that:

    • Steals saved passwords
    • Monitors banking apps
    • Sends all OTPs to the scammer without the user knowing
    • Accesses the camera and microphone

    Kaspersky research shows that over 3 million attack attempts were made on young gamers through malicious mod downloads in just one year.

    6. Gaming Tournament and Prize Scams

    Fake tournament announcements are sent through WhatsApp groups or Instagram pages. They promise cash prizes of Rs. 50,000 or more for winning a Free Fire or BGMI tournament.

    To register, kids are asked to pay a small “entry fee” of Rs. 100 to Rs. 500 via UPI. Once paid, the scammer disappears. There is no tournament. This scam runs on volume. If 1,000 kids each pay Rs. 200, the scammer makes Rs. 2 lakh in a day.

    7. Roblox Robux Generator Scams

    Roblox is extremely popular among kids below 14 in India. Scammers set up fake “Robux generator” sites promising free Roblox currency. These sites ask for the child’s Roblox username and password to “credit the Robux.”

    Once the scammer has the login details, they take over the account and steal any Robux or rare items the child has collected. In some cases, they access the email linked to the account and use it for further fraud.

    Warning Signs Your Child May Be Getting Scammed

    Watch out for these red flags:

    • Your child has become secretive about what they are doing on their phone
    • You notice UPI transactions or bank debits you never authorized
    • Your child seems anxious, scared or unusually emotional after gaming
    • They keep asking for money for game items more than usual
    • Their game account suddenly loses all progress or gets locked out of nowhere
    • They are receiving calls or messages from unknown numbers related to gaming
    • You find unfamiliar apps downloaded on your phone or theirs that nobody can explain

    How to Protect Your Child: A Step-by-Step Guide for Parents

    Step 1: Have an Open Conversation First

    Before you set any rules or take away any devices, just talk to your child. Ask them what games they play, who they talk to online, and what kind of rewards they are chasing. Kids who feel safe talking to their parents are the ones who come to them when something feels wrong. That conversation is worth more than any parental control app.

    Step 2: Disable In-App Purchases

    This one is simple and takes two minutes. On Android, open Google Play Store, go to Settings and turn on purchase authentication so every transaction needs a password. On iPhone, go to Screen Time and block in-app purchases from there. Do this today before you forget.

    Step 3: Never Link Your Main Bank Account to a Gaming App

    If your child wants to make a legitimate purchase, set up a separate prepaid card or wallet with a small fixed amount. Your primary salary account or main UPI ID should never be anywhere near a gaming app.

    Step 4: Teach Kids These Rules

    Sit down with your child and go through these one by one:

    • Free diamonds, free UC and free Robux do not exist. Every single site claiming otherwise is trying to steal something
    • Never share your game password with anyone online, even someone you have been playing with for months
    • Never share an OTP with anyone claiming to be from game support
    • Real game support never reaches out on WhatsApp or Instagram. Ever
    • Never download mod APKs or cheat tools from outside the official app store
    • If anything feels uncomfortable or wrong, come and tell us. No scolding, no lecture, just tell us

    Step 5: Check Suspicious Links Before Clicking

    Your child gets a link promising free rewards or entry into a tournament. Before anyone clicks it, run it through ScamDekho’s website Checker free. Takes five seconds and could save a lot of trouble.

    Step 6: Check Suspicious Messages

    Someone claiming to be from BGMI or Free Fire support slides into your child’s WhatsApp or Instagram. Before your child replies or clicks anything, put that message through ScamDekho’s Scam Message Checker first.

    Step 7: Enable Google Play Family Library and Parental Controls

    Google Play lets you set up a family group where every purchase your child tries to make needs your approval first. Set this up on every device they use for gaming and you will never get a surprise transaction again.

    What to Do If Your Child Has Already Been Scammed

    Act fast. Here is exactly what to do:

    Immediately:

    • Call your bank or open your banking app and block the UPI ID or card that was used
    • Change the passwords of every account your child may have shared, their game account, email and Google account
    • Check for any apps downloaded recently and uninstall them right away

    Within a few hours:

    • Call 1930, India’s national cyber crime helpline. The sooner you call the better the chance of freezing the transaction before the money is withdrawn
    • File a complaint on cybercrime.gov.in

    Within 24 hours:

    One last thing. Do not blame your child and do not let them feel ashamed. These scams are built to fool adults too. What happened is not their fault. What matters right now is moving fast.

    You can also read our complete guide on how to recover money lost in an online scam in India for a detailed recovery process.

    Safe Ways to Buy In-Game Currency in India

    If your child wants to buy diamonds, UC or Robux, here are the only safe ways to do it:

    • Free Fire Diamonds: Only through the official Free Fire app or Garena’s official website
    • BGMI UC: Only through the in-game store or the official Codashop website at codashop.com
    • Roblox Robux: Only through roblox.com or through the app on Google Play or the App Store
    • Google Play Gift Cards: Only from authorized retailers like Amazon, Flipkart or a physical store you trust

    Never buy from individual sellers on Instagram, no matter how cheap the price looks or how many positive comments their post has. That is where most of these scams begin.

    A Note for Parents

    Your child is not stupid for falling for these scams. These traps are designed by adults who spend hours studying what kids want and how they think. The 14-year-old in Panchkula, the child in Ajmer, and Akshay Kumar’s daughter were all targeted by professionals at manipulation.

    The best protection is not restrictions alone. It is trust. A child who knows they can come to you without being shouted at will come to you when something feels wrong. That conversation can save your family from serious financial and emotional damage.

    Frequently Asked Questions

    Q: Are free diamond generators for Free Fire real?

    Nope, never. They are all fake. Not a single one works. Only official game events give free stuff, nothing else.

    Q: How do scammers get into my child’s game account?

    Three ways mostly. Fake websites that look like the game login. Mod APKs with hidden malware. Or someone your child thinks is a friend slowly gains trust and asks for the password directly.

    Q: Can my child’s phone get hacked by just clicking a link?

    Yes. Some links start downloading malware without even asking. That malware sits quietly and reads OTPs, opens banking apps, tracks everything. Do not click random gaming links without checking first.

    Q: Where should I buy BGMI UC from?

    Only from Codashop.com. That is it. Any other website selling UC at a lower price is fake, period.

    Q: My child spent from my account without telling me. What now?

    UPI payment? Call your bank right now and raise a dispute. Google Play or App Store? Go to their refund page and apply today. Every hour you wait makes it harder.

    Q: My child is 10. Should I let them play online games?

    Most games allow 13 and above. Below that, stay away from online multiplayer. Even at 13, keep checking who they talk to and what they share in-game chats.

    Q: What if someone in a game asks my child for money?

    Block immediately. Report inside the game. And tell you. That is the only right answer. Anyone asking a child for money online is not a friend, they are a scammer.

  • Identity Theft in India: What It Is, How It Happens and What to Do

    Identity Theft in India: What It Is, How It Happens and What to Do

    A 34 year old man from Rajasthan woke up one morning to find police at his door. It was not a one time thing. Over the next six years, law enforcement teams from 33 different states showed up at his home. FIRs worth crores of rupees in cyber fraud had been filed against him from across the country.

    He had never committed a single crime.

    Years earlier his email had been hacked. Inside that email were scanned copies of his Aadhaar card, PAN card and voter ID. Fraudsters used those documents to open bank accounts, register fake businesses and cheat hundreds of people across India. Everything was done in his name, with his documents, while he had no idea any of it was happening.

    Six years of police visits, legal battles and a ruined reputation. All because of files sitting in a hacked email inbox.

    This is what identity theft in India actually looks like. Not just financial loss. A completely innocent person’s life turned upside down while the real criminals are never found. And it can happen to anyone who has ever scanned and shared their documents online.

    What Is Identity Theft?

    Most people think identity theft means someone hacks into your bank account and transfers money out. That is one version of it. But honestly, it can get much worse than that.

    When someone gets hold of your Aadhaar number, PAN card, phone number or date of birth, they do not need all of it. Two or three of these details together is enough for a fraudster to open a bank account in your name, apply for a loan you never asked for, or run a fake business using your identity. You find out months or years later when a recovery agent shows up at your door or an FIR gets filed against you for something you never did.

    That is the part nobody talks about. The damage is not always financial. Sometimes it follows you around for years.

    How Common Is Identity Theft in India?

    More common than most people realize.

    According to a 2025 report by U.S. cybersecurity firm Entrust, India’s PAN card is now the most-forged identity document globally, appearing in over 27% of all identity and tax document fraud cases worldwide.

    In April 2025, Indian authorities uncovered a fraud ring that had exploited loopholes in UIDAI’s enrollment software to illegally update the personal and biometric data of over 1,500 Aadhaar card holders. Fraudsters changed names, birthdates, and linked phone numbers using tools like cloned iris scans and silicone fingerprints.

    And it is not just targeted attacks. In one of India’s largest alleged data breaches, a hacking group claimed to have stolen records of 815 million Indian residents, including Aadhaar details, passport information, names, phone numbers, and addresses, reportedly sourced from ICMR’s Covid-19 testing database.

    Your data may already be out there. The question is whether you know how to protect yourself.

    How Do Fraudsters Steal Your Identity?

    There is no single method. Scammers use whatever works.

    1. Phishing messages and fake websites You get a message saying your KYC is expiring. The link looks real, the website looks real, and you enter your details without a second thought. That is it. The fraudster has your information and you have no idea it happened.

    2. Hacked email accounts Open your sent folder right now. There is a good chance you have emailed scanned documents to a bank, an employer or an insurance company at some point. If someone gets into your email, they do not need to do anything else. Everything is already sitting there waiting for them.

    3. SIM swap fraud The fraudster calls your telecom provider pretending to be you and gets a new SIM issued on your number. Your phone goes silent. They start receiving your OTPs. By the time you figure out what happened, your bank account has already been accessed.

    4. Data breaches You signed up for an app or filled a form somewhere. That company got hacked. Your Aadhaar number, phone number and date of birth are now being sold on the dark web for less than the cost of a meal.

    5. Fake KYC calls A calm, professional sounding person calls from what seems like your bank or UIDAI. They just need your Aadhaar number and a quick OTP for verification. They are not from your bank. They never were.

    If you receive a suspicious message asking for personal details, run it through our Scam Message Checker before doing anything.

    What Can Fraudsters Do With Your Identity?

    Once someone has your details, here is what they can misuse:

    • Open bank accounts or take loans in your name
    • Apply for credit cards using your PAN and Aadhaar
    • File fake GST returns or income tax refunds using your PAN
    • Activate SIM cards in your name (used for scam calls)
    • Create fake social media profiles to scam your contacts
    • Commit crimes and leave your documents as the trail

    In the Rajasthan case, investigators discovered that the victim’s documents had been used to open fraudulent bank accounts across multiple states. These accounts were used for GST-linked transactions worth crores of rupees. When victims of those scams filed complaints, the trail kept pointing back to this one innocent man’s documents.

    Clearing your name after this kind of theft can take years.

    Warning Signs That Your Identity Has Been Stolen

    Most people find out too late. Watch out for these red flags:

    • You get a loan rejection despite a clean credit history
    • Unknown loans or credit card entries appear on your CIBIL report
    • You receive OTPs for transactions you never initiated
    • A bank account you never opened shows up linked to your Aadhaar
    • Police or legal notices arrive at your address for crimes you did not commit
    • Friends receive messages or calls from “you” asking for money

    Check: Fake Aadhaar and PAN Update Scam: How It Works

    What to Do If Your Identity Is Stolen: Step by Step

    Step 1: Freeze Your Bank Accounts and Aadhaar

    Call your bank first. Tell them what happened and ask for a temporary hold on all transactions.

    Do not wait until you have more information. While you are at it, open the mAadhaar app and lock your biometrics. This means nobody can use your fingerprints or iris scan to authenticate anything until you unlock it yourself. You can also do this on uidai.gov.in if you do not have the app.

    Step 2: Check Your Credit Report

    Go to cibil.com, experian.in, equifax.in or crif.in and download your credit report. Go through it carefully and look for loans, credit cards or enquiries you never made.

    Even one unfamiliar entry is worth investigating. Raise a dispute on the bureau’s website and they have to respond within 30 days by law.

    Step 3: File a Complaint on cybercrime.gov.in

    Go to cybercrime.gov.in and file under Other Cyber Crimes. Write down what happened as clearly as you can, attach whatever evidence you have and submit. You will get a tracking number within 48 hours and your complaint gets sent to the local cyber cell automatically.

    Step 4: File an FIR at Your Local Police Station

    Do not stop at the online complaint. Go to your nearest police station and file a physical FIR. Section 66C of the IT Act covers identity theft and the punishment goes up to three years in prison.

    If the police say it is not their jurisdiction, tell them about Section 154 of CrPC. Any station can register a Zero FIR regardless of where the crime happened.

    Step 5: Report to UIDAI and Your Telecom Provider

    Aadhaar misused? Email help@uidai.gov.in or call 1947.

    SIM swapped? Go to your telecom store with your ID and ask them to block the fake SIM and restore your original number on the spot.

    Step 6: Inform Your Contacts

    If someone created a fake profile in your name, report it to the platform. Facebook, Instagram and LinkedIn all have impersonation reporting tools. Also tell your close contacts directly so nobody sends money to someone pretending to be you.

    What Laws Protect You in India?

    India has clear laws that cover identity theft. Here is what you should know.

    • IT Act 2000, Section 66C Someone used your Aadhaar to open a fake account? That falls under this section. Three years in prison and a Rs 1 lakh fine for whoever did it.
    • IT Act 2000, Section 66D This one covers impersonation through a phone or computer. Think fake profiles, fake customer care calls, someone pretending to be you online. Most identity theft cases end up with both 66C and 66D applied together.
    • Aadhaar Act 2016 Touch someone’s Aadhaar without permission and the law comes down hard. Misusing biometric data carries three years in prison. Breaking into UIDAI’s central system carries ten. These are not small penalties.
    • Digital Personal Data Protection Act 2023 Here is the part most people miss. If a company lost your data because they did not protect it properly, and that data was then used to steal your identity, that company is legally responsible. You can go to the Data Protection Board and claim compensation from them directly. The burden is not yours alone to carry.

    How to Protect Yourself Before It Happens

    Prevention is always better than trying to fix the damage later. Here are practical steps you can take today:

    • Lock your Aadhaar biometrics on the mAadhaar app when not in use. Most people do not even know this feature exists. Use it
    • Never share your OTP with anyone calling you. It does not matter how official they sound. The moment someone asks for your OTP on a call, hang up
    • Pull your CIBIL report every three months and look for loans you never took. Catching something early is the difference between fixing it and fighting it for years
    • Stop sending scanned Aadhaar and PAN copies over WhatsApp to people you barely know. Once that image leaves your phone you have zero control over it
    • Your email inbox is probably full of sensitive documents you forgot you sent. Put a strong password on it and turn on two factor authentication today
    • Any message asking you to update your KYC or Aadhaar through a link is a scam. Close it and go to the official website yourself if you think something needs updating
    • Before you open any link claiming to be from your bank or a government portal, paste it into our URL Checker first

    Last thing. Go to your social media profiles right now and check what is publicly visible. Your date of birth, phone number and home address sitting open on your profile is all a fraudster needs to start building a case against you.er together are enough for a fraudster to start building a fake identity using your name.

    Also read: How Smart People Lose Money to Scams in India

    Real Case: A Six-Year Identity Theft Nightmare

    A man from Rajasthan had his email hacked. Inside that inbox were scanned copies of his Aadhaar, PAN and other identity documents. The hackers used those documents to open bank accounts and run fraud operations across multiple states. All of it in his name, without him knowing any of it was happening.

    Then the police started showing up at his door. FIRs from different states kept getting linked to his name. Officers who had no reason to doubt the paperwork treated him as a suspect in crimes he had never heard of, let alone committed. This went on for years.

    He eventually managed to get an FIR registered that acknowledged his identity had been misused. But getting his name removed from multiple records across different states is still an ongoing process.

    This is what identity theft can actually cost a person. Not just money. Years of your life spent proving you are not a criminal for something someone else did using your name.

    Source: The420

    Frequently Asked Questions

    Can someone misuse my Aadhaar just by knowing the number?

    Not easily. Just the number on its own is not enough. To actually authenticate anything, they would also need your OTP, biometrics or linked phone number. That said, your Aadhaar number combined with your PAN and date of birth can be enough to get through verification on platforms that do not check as carefully as they should.

    How do I check if my Aadhaar has been used somewhere without my knowledge?

    Go to myaadhaar.uidai.gov.in and look for the Aadhaar Authentication History section. It shows the last 50 times your Aadhaar was authenticated, where and for what purpose. Worth checking every few months.

    What if a loan is taken in my name without my knowledge?

    Go to the lending institution directly with a copy of your FIR and tell them what happened. At the same time raise a dispute on the credit bureau’s website. RBI rules require banks to investigate fraud loan complaints within 90 days.

    Can I get compensation if a company’s data breach exposed my details?

    Yes. Under the Digital Personal Data Protection Act 2023 you can file a complaint with the Data Protection Board of India if a company’s negligence caused your data to be exposed. The company is not off the hook just because it was a hack.

    Is identity theft only a financial crime?

    Not at all. Someone can create a criminal record in your name, build fake social media profiles, use your health insurance for medical fraud or file taxes using your PAN. The financial damage is just one part of it.

  • How Law Enforcement Investigates Cyber Scams in India: The Complete Process

    How Law Enforcement Investigates Cyber Scams in India: The Complete Process

    You filed a complaint. The police took your details. And then… silence.

    Most scam victims have no idea what happens after they report a cybercrime. Does anyone actually look into it? Are the police tracing the fraudster? Will they ever catch him?

    The short answer is: yes, investigations do happen. But the process is nothing like what you see in movies. This guide breaks down exactly how Indian law enforcement investigates cyber scams, step by step, in plain language.

    Understanding this process helps you know what to expect, how to help your own case, and why fast reporting matters so much.

    Step 1: Your Complaint Triggers an Immediate Bank Alert

    When you call 1930 or file a complaint on cybercrime.gov.in, your report does not just sit in a queue somewhere.

    The moment your complaint goes in, the operator contacts the banks and payment platforms involved in the transaction. This happens through a system called CFCFRMS which directly connects over 85 banks, UPI platforms and digital wallets to the cyber crime backend. Think of it as a direct hotline between the helpline and your bank.

    The only goal at this point is to freeze the money before the scammer gets to it. Call within the first hour and there is a real chance the funds in the fraudster’s account get locked before they can touch it. Wait longer and that window starts closing fast.

    Speed is everything here. The sooner you report, the better your chances. And this is also where the official investigation begins.

    Step 2: The FIR Is Filed and a Case Is Assigned

    Once your online complaint is verified, it goes straight to the nodal officer of your state cyber crime cell.

    If your loss is above Rs 10 lakh, something important happens automatically. As of May 2025, complaints above this amount trigger a Zero FIR with the e-Crime Police Station of Delhi. This is a new initiative by the Ministry of Home Affairs under I4C and it means your case gets registered immediately without any back and forth about which police station has jurisdiction.

    This matters because cyber crimes do not follow state boundaries. The scammer could be sitting in a different state or a different country entirely. A Zero FIR cuts through all of that and gets the case moving right away.

    After this an Investigating Officer gets assigned to your case. This is the person who takes charge of the investigation from here.

    Step 3: Tracing the Digital Trail

    This is where the actual detective work begins. Once an Investigating Officer is assigned to your case, they start tracing the scammer through multiple digital channels at the same time.

    • Bank account trail Your UTR number is the starting point. Police use it to request the full transaction history from the bank. They can see exactly which accounts the money passed through and where it ended up. Banks have to share this by law.
    • Mobile number trace Police request the call records for the phone number the scammer used. The telecom company has to provide this under Section 91 of CrPC. Those records show every call made, every tower the phone connected to, and the time of each activity. Location starts becoming clear from here.
    • IP address analysis Every fake website or phishing link runs on a server that has an IP address. Police contact the internet service provider associated with that IP and request the name and address registered to it at the time of the fraud.
    • Device fingerprinting Every phone has a unique IMEI number that does not change even when the SIM card is replaced. If police can identify the device used in the scam, they can keep tracking it regardless of how many numbers the scammer switches to.
    • UPI handle and wallet data Every UPI account on PhonePe, Google Pay or Paytm is linked to a KYC verified identity. Police send a legal notice to the platform and within days they have the real name and details behind that UPI handle.

    Step 4: Mule Account Investigation

    Here is something most people do not know.

    Scammers rarely use their own bank accounts. They use what are called “mule accounts.” These are accounts opened by innocent people who were either tricked or paid to lend their account details. The money lands in these accounts first, then gets moved quickly to other accounts or converted to cash.

    When police trace the first account, they often find it belongs to a person who had no idea their account was being misused. This person then becomes a witness, not the main accused, and helps investigators trace the actual scammer.

    This is why it sometimes takes weeks before you hear news of an arrest. Police are following a chain of accounts, sometimes across 5 to 10 different states.

    You can read more about how mule accounts work in our blog on mule account scams in India.

    Step 5: Digital Forensics at the Cyber Lab

    If a device gets seized during the investigation, it is sent to a cyber forensic lab. India has a National Cyber Forensic Laboratory in New Delhi that has already assisted state police in over 12,000 cases.

    At the lab, forensic experts do the following:

    • Recover deleted messages, call logs and files from the seized device that the scammer thought were permanently gone
    • Pull out transaction records and app data to build a clear picture of what happened
    • Read the metadata hidden inside images and documents, which reveals the exact location and time a photo was taken
    • Go through WhatsApp, Telegram and other chat histories through legal data requests to the platforms
    • Check whether any screenshots or payment proofs submitted as evidence were digitally edited or manipulated

    If you ever suspect someone sent you a fake payment screenshot, our Fake Payment Screenshot Checker can help you verify it before you take any action.

    The forensic report prepared at this stage becomes the primary technical evidence used in court. This is not just a formality. Under Section 63 of the Bharatiya Sakshya Adhiniyam 2023, which replaced Section 65B of the Indian Evidence Act, digital records are only accepted as valid evidence in court if they come with a proper certificate from a certified forensic expert. Without that certificate, even genuine digital evidence can be challenged and thrown out entirely.

    Step 6: Surveillance and the Pratibimb Tool

    India’s I4C has developed an analytics tool called Pratibimb that gives investigators a live map of criminal activity across the entire country. It shows where fraud is happening, where the people behind it are located, and how different scam operations are connected to each other.

    Using Pratibimb, investigators can spot clusters of fraud activity, link multiple complaints back to a single criminal network, and coordinate arrests across different states at the same time without waiting for paperwork to travel between jurisdictions.

    Since its launch the tool has led to over 12,987 arrests and uncovered more than 1.5 lakh criminal linkages across India according to the Ministry of Home Affairs.

    When Pratibimb data is combined with CCTV footage and cell tower records, investigators can often narrow down the exact location of a scam operation, even if it is running out of a compound in a completely different state from where the victim is.

    Step 7: Arrest and Cross-State Operations

    Cyber crime rarely happens in one place. A scammer sitting in Rajasthan might be targeting someone in Mumbai using a phone number registered in UP and a bank account opened in West Bengal. The pieces are deliberately scattered to make investigations harder.

    Indian cyber crime units now coordinate regularly through I4C’s Cyber Crime Coordination Centres. Special Task Forces are put together for larger cases. In 2025 alone, the UP Cyber Crime police froze Rs 325 crore across thousands of complaints. Recovery rates have also improved, going from 11% in 2024 to 24% in 2025, which shows the system is getting better at acting fast.

    When a fraudster is identified, a team is physically sent to arrest them. For cases connected to international scam networks like digital arrest scams that trace back to Cambodia or Myanmar, Indian agencies coordinate with Interpol and partner agencies in those countries.

    But international cases are genuinely difficult. Once the money crosses the border or IP addresses point to servers in another country, the trail usually goes cold. A real case covered by Bloomberg in 2025 showed exactly this. A major digital arrest scam was traced back to Cambodia but the person running it was never caught. The investigation hit a wall the moment it crossed international borders.

    What Are the Realistic Chances of Recovery?

    Between April 2021 and September 2025, only 6.7% of total cyber fraud money was recovered across India. That number is hard to read but it is the reality. However for people who reported within the first hour, the recovery rate was significantly better, reaching up to 24% in 2025.

    Your chances depend on a few specific factors:

    • How fast you reported. Within the first hour gives you the best shot. Every hour after that reduces your chances considerably
    • Whether the money stayed in India. Domestic transfers can still be traced and frozen. Once the money leaves the country, recovery becomes extremely difficult
    • How many accounts the money passed through. A single transfer to one account is much easier to freeze than money that has hopped through five different accounts across three states
    • What the fraudster did with the money at the end. If they withdrew cash or converted it to cryptocurrency, getting it back becomes nearly impossible. These two methods are specifically used by scammers because they know how hard they are to reverse

    Why Do So Few Cases Result in Arrests?

    In 2025, India recorded 28.15 lakh cyber crime complaints. But only 55,484 FIRs were filed. That means most complaints never became formal police cases.

    There are real reasons for this:

    • Volume: Police are overwhelmed. Small-value cases (below Rs. 50,000) often get logged but do not receive dedicated investigation resources.
    • Jurisdiction complexity: Crime in one state, money in another, fraudster in a third. Coordinating between three state police forces takes time.
    • VPNs and anonymization: Fraudsters increasingly use VPNs, encrypted messaging apps, and anonymous SIM cards, making IP tracing difficult.
    • Mule accounts: By the time police trace the full chain of mule accounts, the actual perpetrator may have disappeared.

    This does not mean you should not report. Serial fraudsters are eventually caught through the pattern of cumulative complaints. Your single complaint contributes to a larger picture that helps police dismantle entire networks.

    How You Can Help Your Own Investigation

    The police can only work with what you give them. Here is what you should do immediately after a scam:

    • Do not delete any messages, calls, or screenshots from the fraudster
    • Note down the exact time of every transaction
    • Save the UTR number and transaction ID from your banking app
    • Take screenshots of any URLs, WhatsApp messages, or emails
    • If you clicked a suspicious link, use our URL Checker and report the link to police
    • Write down everything that happened in order, before memory fades

    Also, if you received suspicious messages or calls, check them using our Scam Message Checker before taking action.

    Real Case: Digital Arrest Scam in India

    A Noida based woman received a call from someone claiming to be a Delhi Police official. Nothing about the call felt suspicious at first. The person spoke like an authority figure, used the right language and made the situation sound extremely serious.

    She was told her Aadhaar number had shown up in a money laundering case and that she needed to cooperate immediately or face arrest. Then came the video call. The scammers kept her on a continuous WhatsApp call and told her she was under digital arrest. She could not hang up. She could not talk to her family. She could not leave the room.

    For the next several days she was pressured into transferring money to different bank accounts, each one described as a safe account or a verification account. The calls never stopped. The threats never stopped. She had no space to think, no moment to step back and question what was happening.

    By the time it was over she had transferred more than Rs 11 crore.

    What makes this case important to understand is how little the victim did wrong. She did not click a suspicious link. She did not ignore obvious warning signs. She was systematically isolated, threatened and controlled until she had nothing left to transfer. That is what digital arrest scams actually look like. Not a obvious fraud but a carefully constructed situation designed to make a normal person feel like they have no choice.

    Source: NDTV

    Frequently Asked Questions

    How long does a cyber crime investigation take in India?

    Simple financial fraud cases can result in account freezing within hours. Full investigations leading to arrest can take weeks to months, depending on how many states and accounts are involved.

    Can police recover money after a UPI scam?

    If reported within the first hour, there is a chance of freezing the funds before withdrawal. After that, recovery depends on whether the money is still in a traceable Indian bank account.

    What law is used to prosecute cyber scammers in India?

    Cases are filed under the Information Technology Act 2000, the Bharatiya Nyaya Sanhita 2023 (which replaced IPC), and relevant banking fraud provisions. Digital evidence must comply with Section 63 of the Bharatiya Sakshya Adhiniyam 2023.

    Do police investigate small fraud cases below Rs. 10,000?

    These cases are logged and contribute to pattern analysis, but dedicated investigation is less likely. Filing a complaint still matters because serial fraudsters are often identified through cumulative reports.

    What is a Zero FIR in cyber crime cases?

    A Zero FIR can be filed at any police station regardless of where the crime occurred. For financial cyber fraud above Rs. 10 lakh, this is now automatic under the e-Zero FIR initiative launched in May 2025.

  • Cyber Crime Helpline Number India: Call 1930 to Report Online Fraud

    Cyber Crime Helpline Number India: Call 1930 to Report Online Fraud

    Got scammed online? Call 1930 immediately. Seriously, do not wait even five minutes. This is India’s official cyber crime helpline and the moment you call, there is a real chance the authorities can freeze the transaction before that money is completely gone.

    Every second matters here. Scammers move fast and once the money leaves your account, getting it back becomes extremely difficult. One phone call can make all the difference.

    In this guide you will find out exactly how to call 1930, what to say, what documents to keep ready, and what happens after your complaint goes in. No confusing terms, no wasted time. Just the stuff that actually helps you get your money back.

    What Is the Cyber Crime Helpline Number in India?

    1930 is India’s national cyber crime helpline number, and it exists for one simple reason. When someone scams you online, you need to report it fast and you need to reach the right people. This is that number.

    The Ministry of Home Affairs set it up through the Indian Cyber Crime Coordination Centre and it stays open all day, all night, every single day of the year. Whether someone tricked you through a fake UPI request, a job offer that turned out to be fraud, or straight up stole money from your bank account, this is the number you call.

    Before 2021 things were honestly quite confusing. Each state had its own cyber crime number. So if you got scammed you had to first figure out which number belongs to your state, then hope it actually worked. Most people just gave up. The government saw this problem and replaced all those different numbers with one single helpline for the entire country. Simple, clean, no confusion.

    One small thing before we move forward. Save 1930 in your phone right now. Seriously, just do it. Because when you actually need this number you will be stressed and panicking and the last thing you want to do is search for it online.

    When Should You Call 1930?

    Call 1930 if any of these have happened to you:

    • Money was transferred from your bank account or UPI without your permission
    • You paid someone online and got cheated (fake product, fake job, fake investment)
    • You received a fake call from someone pretending to be a bank, police officer, or government official
    • Your OTP was stolen and your account was accessed
    • You clicked a suspicious link and your money was debited
    • You fell for a digital arrest scam or a parcel fraud call

    The golden window is the first 30 to 60 minutes after a fraud. If you call within this time, the cyber crime team can alert the receiving bank and put a hold on the money before the scammer withdraws it.

    What Happens When You Call 1930?

    Here is what happens once you dial 1930:

    Step 1: You call 1930 Someone picks up and asks you three basic things. Your name, your mobile number, and what happened. Do not panic, do not ramble. Just tell them clearly that you got scammed, how much money was taken, and through which app or platform.

    Step 2: They log your complaint They put your details into the system and hand you a reference number. Please write this down on paper, not just a mental note. This little number is the only proof that your complaint exists and you will need it more than once going forward.

    Step 3: They alert the bank This is where things move quickly. The operator gets in touch with the bank or the payment app where your money landed, PhonePe, Google Pay, Paytm, wherever it went. They flag the transaction right there on the call.

    Step 4: Bank puts a hold If the scammer has not already moved the money out, the bank can freeze their account immediately. This is honestly the most important step in the entire process and the only reason it works is because you called fast enough.

    Step 5: You file an online complaint The call gets the ball rolling but it does not close the case. After hanging up you need to go to cybercrime.gov.in and submit a full written complaint using that reference number. The phone call stops the bleeding. The online complaint is what actually builds your case.

    What to Keep Ready Before You Call

    Do not panic and call empty-handed. Have these things ready:

    • Your bank account number or UPI ID The one from which the money was sent. This is the first thing they will ask you.
    • The fraudster’s details Whatever you have. Their UPI ID, bank account number, or phone number. Even one of these is enough to get things moving.
    • Transaction ID or UTR number Open your banking app or payment app and find the transaction. That reference number is proof the payment actually happened.
    • The exact amount and time Do not guess. Check your app and note down the exact figure and the timestamp of the transaction.
    • Screenshots Any messages, fake links, suspicious calls, or chats related to the fraud. Take screenshots of everything before you call.
    • Your Aadhaar or PAN number Just for identity verification. They need to confirm who is filing the complaint.

    Now here is the thing. If you do not have all of this right now, do not let that stop you from calling. The operator will guide you through whatever you are missing. Having everything ready just speeds things up and increases your chances of freezing the transaction in time. Call first, gather more details later if needed information ready will make the process much faster.

    How to File an Online Complaint on cybercrime.gov.in

    Calling 1930 is your first step. But you also need to file a written complaint online. Here is how:

    1. Go to cybercrime.gov.in
    2. Click on “File a Complaint”
    3. Select “Financial Fraud” as the category
    4. Fill in your personal details and the complaint details
    5. Upload screenshots and any evidence you have
    6. Submit and save your complaint number

    You can also track your complaint status on the same website using your registered mobile number.

    If you are unsure whether a message or payment screenshot is fake, use ScamDekho’s Scam Message Checker or Fake Payment Screenshot Checker before you call.

    State-Wise Cyber Crime Helpline Numbers (Backup Options)

    While 1930 works across India, some states also have their own cyber cells. These can be useful if your local case needs follow-up:

    All numbers are sourced from the National Cyber Crime Reporting Portal (cybercrime.gov.in). For the latest updates, visit cybercrime.gov.in directly.

    #State / UTGrievance Phone NumberHow to Report
    1National (All India)1930Call 1930 or visit cybercrime.gov.in
    2Andaman & Nicobar03192-232334Contact DIGP (Intl.)
    3Andhra Pradesh8331043255SP Cyber Crimes, CID
    4Arunachal Pradesh9436040703IGP Crime
    5Assam0361-2521618IGP CID
    6Bihar0612-2238098SSP Cyber Cell
    7Chandigarh0172-2700056IGP-UT
    8Chhattisgarh0771-2511989DIG Technical Services
    9Dadra & Nagar Haveli / Daman & Diu0260-2220140DIGP
    10Delhi011-20892633JT. CP, IFSO Special Cell
    11Goa0832-2420883DIGP
    12Gujarat079-23250798IGP, CID
    13Haryana0172-2524058DIG SCB
    14Himachal Pradesh0177-2620331DIGP/Crime
    15Jammu & Kashmir0191-2582292ADGP CID
    16Jharkhand0651-2220060SP Cyber Crime, CID
    17Karnataka080-22942475DIG Cyber Crimes, CID
    18Kerala0471-2300042ADGP Cyber Operations
    19Ladakh9541902324AIG CIV PHQ
    20Lakshadweep04896-262258SP L&O
    21Madhya Pradesh0755-2770248ADG State Cyber Police
    22Maharashtra022-22160080SP, Cyber Crime Branch
    23Manipur0385-2444888DIGP (Intl.)
    24Meghalaya9402519391SP Cyber, PHQ
    25Mizoram0389-2334682DGP
    26Nagaland6009308003ADGP L&O
    27Odisha0674-2913100ADGP CID CB
    28Puducherry0413-2231313IGP
    29Punjab0172-2226258ADGP Cyber Crime
    30Rajasthan0141-2821741Inspector General of Police
    31Sikkim8695622134Police Inspector CID
    32Tamil Nadu044-29580300SP, Cyber Crimes Division
    33Telangana040-27852000Director, TSCSB
    34Tripura0381-2415501ADGP/IGP Crime
    35Uttar Pradesh0522-2304954ADGP Cyber Crime
    36Uttarakhand0135-2655900IGP/DIG Crime
    37West Bengal033-22143000ADGP CID

    For national financial fraud, always start with 1930 first. The state numbers are for cases that need local police follow-up.

    Real Case: How 1930 Saved Someone’s Money

    Here is a real example shared by a Mumbai resident on a consumer forum:

    It started with a phone call. Someone claiming to be from TRAI told this person that their number was about to be blocked because it was linked to illegal activity. That one line was enough to make them freeze.

    Before they could even process what was happening, they were transferred to a WhatsApp video call. On the other end was a man in uniform, introducing himself as a CBI officer. He was aggressive, authoritative, and gave them no room to think. Pay Rs 2.8 lakh right now or face arrest. So they paid.

    The moment the money left their account, something felt wrong. They started putting the pieces together and realised they had just been played. No TRAI. No CBI. Just scammers who knew exactly how to make a person panic and act without thinking.

    What they did next is the reason this story does not end terribly. They called 1930 within 40 minutes. The team flagged the receiving account and managed to freeze it before everything was gone. Three weeks later Rs 1.9 lakh came back to them out of the Rs 2.8 lakh they had lost.

    Not a full recovery. But nearly 70 percent returned because they picked up the phone and called in time.

    Common Mistakes People Make After Getting Scammed

    Most people do not lose their money because of the scam alone. They lose it because of what they do in the hour after it happens.

    • Waiting too long to call People sit with it. They feel embarrassed, they second guess themselves, they hope maybe the payment will reverse on its own. It will not. And while you are sitting there the fraudster is at an ATM. Once that cash is out, no helpline in the world can bring it back.
    • Not saving the transaction details You are going to be flustered when you call. That is completely normal. But before you dial, open your payment app and screenshot that transaction. The UTR number on it is the one thing that tells the operator exactly which payment to freeze. Without it the complaint still gets filed but it moves much slower.
    • Calling the wrong number Fake helpline numbers travel fast on WhatsApp. Some of them are run by the exact same people who scammed you, waiting for a second bite. 1930 is the only number that is real. Any other number you see floating around on social media or forwarded messages, ignore it completely unless you have confirmed it on cybercrime.gov.in yourself.
    • Forgetting what actually happened Panic does strange things to memory. Before you call, take sixty seconds and write down the basics. How much, which app, what time, what the person said to you. You do not need to have everything figured out but a clear two minute explanation on the call makes a real difference.
    • Trusting someone who calls you back to help This happens more than you think. A scammer calls you pretending to be a cyber crime official, says they saw your case, and offers to help recover your money. Then they ask for an OTP or tell you to download an app. That is the second scam. Genuine 1930 operators do not call you back out of nowhere and they will never ask for your OTP or any kind of remote access Ever

    Is 1930 Available 24 Hours?

    Yes. The 1930 helpline operates 24 hours a day, 7 days a week, including weekends and public holidays. You can call at any time.

    However, response time may vary. If the line is busy, keep trying. Do not wait and give up.

    What If Your Money Is Not Recovered?

    This is the hard truth. Not every case leads to a recovery. But here is what else you can do:

    • File an FIR at your nearest police station A phone call to 1930 starts the process but an FIR makes it official. It creates a legal record of what happened and without it you cannot move forward with insurance claims or bank disputes. It feels like a lot of effort when you are already exhausted but it is worth doing.
    • Contact RBI’s SACHET portal If the fraud involved a bank or any kind of financial company regulated by RBI, head to sachet.rbi.org.in and file a complaint there. It is a separate channel and it applies pressure from a different direction.
    • Call the National Consumer Helpline at 1915 Got scammed through an e-commerce website or an online shopping platform? This is the number for that. It does not replace 1930 but it is the right place to escalate if a platform was involved.
    • Go back to your bank and ask for a chargeback If the payment went through a credit or debit card, your bank is legally required to investigate it. Walk in, raise a chargeback request, and follow up. They have 90 days to look into it and a surprising number of these do get resolved in the customer’s favour.

    Also check our guide on how to recover money lost in an online scam for a full step-by-step breakdown.

    How to Protect Yourself from Cyber Fraud in the Future

    Reporting is important. Prevention is better. A few habits that actually help:

    • Never share OTP, PIN, or Aadhaar details on a call, even if the caller sounds official
    • Always verify a UPI QR code before paying. Use ScamDekho’s UPI QR Checker when in doubt
    • Do not click links sent via WhatsApp, SMS, or email from unknown contacts
    • If you receive a job offer, verify the offer letter before paying any fees. Use our Fake Offer Letter Checker
    • Turn on transaction alerts for your bank account so you know immediately if something unexpected happens

    Summary: What You Need to Know

    • The cyber crime helpline number in India is 1930
    • Call immediately after any online fraud, the first hour is critical
    • Keep your transaction ID, bank details, and screenshots ready before calling
    • After calling, file a written complaint at cybercrime.gov.in
    • Real operators will never ask for your OTP or ask you to install apps
    • Recovery is possible, especially if you act fast

    Frequently Asked Questions

    What is the cyber crime helpline number in India?

    1930. Save it right now. Seriously, stop reading for two seconds and save it. Because when you actually need this number you are going to be panicking and searching for it is the last thing you want to be doing.

    Can 1930 recover my money?

    If you call quickly and the fraudster has not touched the money yet, there is a real chance. Some people get most of it back. Others get nothing despite doing everything right. What I can tell you is that every single person who got even a rupee back made that call fast.

    Is there a time limit to file a cyber crime complaint?

    There is no strict legal deadline, but the sooner you report, the better. Within 24 hours is ideal for financial frauds.

    What if my state police does not take action?

    You can escalate on the national cyber crime portal at cybercrime.gov.in or contact the National Cyber Crime Reporting Portal directly.

    What is the difference between calling 1930 and filing online?

    Calling 1930 triggers immediate bank-level action to freeze accounts. Filing online creates a formal legal complaint. You should do both.

  • Screen Sharing Scam in India: AnyDesk Fraud That Can Empty Your Bank Account

    Screen Sharing Scam in India: AnyDesk Fraud That Can Empty Your Bank Account

    A senior citizen in Mumbai lost ₹9.26 lakh in a single phone call. The caller said he was from a telecom company. He asked the man’s father to download a “small app” for verification. That app was a screen sharing tool. Within minutes, every rupee was gone.

    A businessman in Karnataka lost over ₹50,000 after downloading a screen sharing app called Rust Desk, just because he wanted help operating his PhonePe account.

    A Hyderabad-based doctor lost ₹1.41 lakh while sharing her Google Pay screen with a stranger who promised to send “advance payment” for a medical checkup.

    These are not rare cases. Screen sharing scam is one of the fastest-growing cyber frauds in India right now. The Reserve Bank of India (RBI), NPCI, and police departments across multiple states have all issued warnings against it.

    If someone on a phone call is asking you to download AnyDesk, TeamViewer, QuickSupport, or Rust Desk, stop right there. That person is a scammer.

    This guide explains exactly how this scam works, who gets targeted, and what you should do if you’ve already fallen for it.

    What Is a Screen Sharing Scam?

    A screen sharing scam is a type of cyber fraud where a scammer tricks you into downloading a remote access app on your phone or computer. Once installed, the scammer can see everything on your screen in real-time, including your OTPs, UPI PIN, banking apps, passwords, and personal messages.

    The most commonly misused apps in these scams are:

    • AnyDesk
    • TeamViewer
    • QuickSupport
    • Rust Desk
    • Google Meet screen share

    These are legitimate apps used by IT professionals for remote support. But in the hands of a scammer, they become tools to drain your bank account.

    The RBI issued its first public advisory about AnyDesk fraud back in February 2019. NPCI followed with its own warning. Since then, police departments in Kerala, Meghalaya, Gurugram, Hyderabad, and many other cities have issued similar alerts, but the scam is still growing because most people have never heard of it.

    How Does the Screen Sharing Scam Work? (Step-by-Step)

    Here is the exact playbook scammers follow. Every step is designed to build trust and create urgency.

    Step 1: The Fake Call

    You receive a phone call. The caller claims to be from:

    • Your bank (SBI, HDFC, ICICI, etc.)
    • A telecom company (Airtel, Jio, Vi)
    • A payment app (PhonePe, Google Pay, Paytm)
    • Amazon, Flipkart, or any e-commerce platform
    • The “Electricity Board” or “Insurance Company”

    They sound professional. They may already know your name, phone number, or even partial account details (collected from data leaks or social media).

    Step 2: Creating Panic or Excitement

    The scammer creates urgency using one of these stories, and if you receive such messages, you can verify them using a scam message checker:

    • “Your KYC is expired. Your account will be blocked in 2 hours.”
    • “A suspicious transaction of ₹48,000 has been detected on your account.”
    • “You are eligible for a refund of ₹3,500. Let me help you process it.”
    • “Your credit card application is approved. Let me complete the verification.”
    • “Your electricity bill is overdue. Pay now or your connection will be cut.”

    The goal is to make you act fast without thinking.

    Step 3: “Download This Small App”

    Once you’re worried (or excited), the scammer says:

    “Don’t worry, I will help you fix this. Just download a small app from Play Store. Search for AnyDesk (or TeamViewer or QuickSupport).”

    You download the app. It generates a 9-digit code on your screen.

    Step 4: Sharing the Code

    The scammer asks you to share this code. You share it, after all, it is just a number, right?

    Wrong. That 9-digit code gives the scammer complete remote access to your phone or computer.

    Step 5: Granting Permissions

    The app asks for certain permissions like display over other apps and accessibility access. The scammer guides you through all of them, saying things like “just tap Allow, it’s a routine security check.”

    Step 6: Your Money Disappears

    Now the scammer can see everything on your screen. They can:

    • Watch your OTPs as they arrive via SMS
    • See your UPI PIN as you type it
    • Open your banking app and initiate transfers
    • Install a UPI app on their own device using your phone number and the OTP visible on your screen
    • Copy your saved passwords and card details

    In the Hyderabad doctor case, the scammer installed a UPI app on their own device using the victim’s phone number. The activation OTP appeared on her shared screen. The scammer typed it in on their end and started making transactions from her ICICI Bank account without her even knowing.

    All of this can happen within 5 to 10 minutes.

    Real Cases of Screen Sharing Scam in India

    Case 1: Mumbai Senior Citizen, ₹9.26 Lakh Lost

    A Colaba-based senior citizen received a call from someone pretending to be a telecom company representative. The caller asked him to download a screen sharing app. Once access was granted, the scammer transferred ₹9.26 lakh from his account. An FIR was registered under IPC and IT Act, but no arrests were made at the time of reporting.

    Case 2: Karnataka Businessman, ₹50,000+ Lost

    A village-based businessman in Karnataka was having trouble with his PhonePe app. He searched Google for customer care numbers and called one. The person asked him to install Rust Desk, a screen sharing app. After he shared access, the scammer scanned his credit cards through the phone camera and made transactions worth ₹57,801 from two different credit cards. FIR was registered on July 31.

    Case 3: Hyderabad Doctor, ₹1.41 Lakh Lost

    A 49-year-old doctor received a WhatsApp message from a man claiming to be an army officer. He said he wanted to send 90 women cadets for medical examination and would pay in advance. During the payment process, he asked her to share her Google Pay screen. While her screen was shared, the scammer installed a UPI app using her mobile number and made unauthorized transactions of ₹1,40,972 from her ICICI account.

    Case 4: Pune Resident, ₹3.2 Lakh Lost

    A man in Pune received a call from someone claiming to be a bank officer. The caller said his KYC was expiring and asked him to install AnyDesk for quick verification. Within 10 minutes of sharing his access code, ₹3.2 lakh was transferred out of his account.

    Case 5: Delhi Woman, ₹85,000 Lost (Amazon Refund Scam)

    A woman in Delhi received a call from a supposed Amazon refund team. She was told to install AnyDesk to process her refund. Instead, ₹85,000 was transferred from her account while she was still on the call with the scammer.

    Who Gets Targeted the Most?

    Screen sharing scams do not discriminate, but some groups are targeted more frequently:

    • Senior citizens, Less familiar with app permissions and remote access concepts
    • Small shopkeepers and businessmen, Often search Google for customer care numbers when facing issues
    • First-time smartphone users, Trust anyone who sounds professional on the phone
    • People searching for help online, Google is full of fake customer care numbers posted by scammers
    • Salaried professionals, Targeted with credit card upgrade or insurance renewal scams

    If your parents or grandparents use smartphones, please share this article with them. Most victims never realize what went wrong until their bank balance shows zero.

    Warning Signs: How to Spot a Screen Sharing Scam

    Ask yourself these questions. If the answer to even one is “yes”, it is a scam.

    1. Did someone call YOU first?

    Real banks and companies rarely call customers. They send emails, app notifications, or SMS. An unsolicited call asking you to verify or update something is almost always fake.

    2. Are they asking you to download an app?

    No bank, no payment company, and no government agency will ever ask you to download AnyDesk, TeamViewer, QuickSupport, or any screen sharing app. Period.

    3. Are they asking for a code from your screen?

    That 9-digit code is the key to your entire device. Sharing it is like handing over the keys to your house.

    4. Are they creating urgency or fear?

    “Your account will be blocked in 1 hour.” “A fraud transaction has been detected.” “Act now or lose your refund.” These are pressure tactics. Real companies give you time.

    5. Did you find their number on Google?

    Many customer care numbers on Google are fake, and before trusting any link or website, you should always verify it using a URL checker. Scammers pay for Google Ads or post numbers on websites that look official. Always get the customer care number from the official app or website.

    What Should You Do If Someone Asks You to Share Your Screen?

    Immediately hang up the call.

    Then follow these steps:

    1. Do NOT download any app they mentioned. If you already downloaded it, uninstall it immediately.

    2. If you shared the code but no money was taken yet:

    • Uninstall the screen sharing app right away
    • Change your UPI PIN immediately
    • Change your internet banking password
    • Call your bank and ask them to temporarily block transactions

    3. If money has already been taken:

    • Call the national cybercrime helpline 1930 within the first hour (this is the golden hour, your chances of recovery are highest if you act within 1 to 3 hours)
    • File a complaint at cybercrime.gov.in
    • Call your bank’s fraud helpline and request an account freeze on the recipient’s account
    • Visit your nearest police station and file an FIR
    • Save all evidence like call recordings, screenshots, transaction IDs, and the scammer’s phone number

    Final Words

    Screen sharing scams work because they exploit trust. You trust the person on the phone because they sound professional. You trust the app because it is on Google Play Store. You trust the process because it seems simple.

    But here is the truth. No real bank, company, or government agency will ever ask you to share your screen or download a remote access app over a phone call.

    If you remember just one thing from this entire article, let it be this:

    Phone pe koi app download karne bole → Scam hai. Phone kaat do.

    Share this article with your family, especially your parents and grandparents. One share can save someone’s life savings.

  • Fake Customer Care Scam in India: One Google Search Can Cost You Lakhs

    Fake Customer Care Scam in India: One Google Search Can Cost You Lakhs

    Your UPI payment just failed. Your flight got rescheduled. Your new washing machine stopped working two days after delivery. What do most of us do? We pull out our phone, open Google, and type something like “XYZ customer care number.” A number pops up right at the top. Looks legit. We call it. That one call ends up costing us lakhs.

    The fake customer care number scam plays out thousands of times every month across India. And it does not target careless people. It targets frustrated people who trust Google. This guide breaks down exactly how it works, shares real cases, and gives you a clear action plan so you never fall for it.

    How Does the Fake Customer Care Number Scam Work?

    The scam runs like a well-oiled machine. Here is the typical playbook, step by step.

    • Step 1: Plant the number. Scammers create fake helpline numbers for SBI, HDFC, PhonePe, Paytm, Airtel, Uber, and Swiggy. These get pushed through Facebook pages, blog posts, Google Ads, and increasingly through Google AI Overviews.
    • Step 2: You Google and call. You search “PhonePe customer care number.” The fake number appears at the top, sometimes sitting right above the real one. You tap and call without thinking twice.
    • Step 3: A trained agent answers. They know the company’s terminology, product lineup, and refund procedures. They sound more helpful than most real agents. Then the trap begins.
    • Step 4: Your money vanishes. Once they have screen access or your credentials, funds are siphoned through UPI, wallets, or card transactions within minutes. The money bounces through multiple mule accounts and becomes nearly impossible to recover.

    What Tricks Do Fake Agents Use?

    • Ask you to download AnyDesk, TeamViewer, or Rust Desk for “remote help”
    • Send a UPI collect request disguised as a “refund verification step”
    • Request your OTP, card number, or CVV for “account verification”
    • Ask you to make a small “test transaction” to confirm your account is active

    The Numbers Behind the Scam: What CloudSEK Found

    Bengaluru-based cybersecurity firm CloudSEK ran a deep investigation using their XVigil platform. The findings are genuinely alarming.

    FindingData
    Total fake numbers detected31,179
    Indian numbers (% of total)56% (17,285 numbers)
    Still active when discovered80% of Indian numbers
    Primary distribution channelFacebook (88%)
    Most impersonated sectorBanking and Finance (59.4%)
    Top scam hub stateWest Bengal (23%)
    Biggest single victim lossRs 16 lakh

    Why Is 2025 and 2026 Especially Dangerous?

    Scammers have cracked a new channel: Google AI Overviews. These AI-generated summaries at the top of search results sometimes pull phone numbers from scammer-controlled websites without verifying whether the number is legitimate. That is a massive vulnerability, and fraudsters are exploiting it aggressively right now.

    Real Cases: How Ordinary People Lost Lakhs Over One Call

    Case 1: Rs 100 Uber Overcharge Turned Into a Rs 5 Lakh Nightmare

    Delhi resident Pradeep Chowdhary was charged Rs 318 for a ride that should have cost Rs 205. He Googled “Uber customer care number,” called the top result, and was asked to download the Rust Desk app. Within minutes, Rs 83,760 was transferred out. Four more transactions followed. Total loss: over Rs 5 lakh. Delhi Police filed an FIR under Section 420 IPC and Section 66D of the IT Act.

    Think about that for a second. The man was trying to recover Rs 100 and ended up losing Rs 5 lakh.

    Case 2: Defective Flour Machine Led to Rs 1.29 Lakh Gone

    A Panchsheel Park resident searched for a manufacturer’s helpline after his flour machine stopped working. Scammers extracted his bank details and Rs 1,29,000 disappeared from his account. Delhi Cyber Cell traced the funds to Patna and made three arrests, with links uncovered to the Jamtara cybercrime network.

    Case 3: The Swiggy Scam That Should Never Have Been Possible

    A user searched for “Swiggy customer care number” after a missing Instamart order. The number that appeared, reportedly through Google AI Overviews, was fake. The scammer asked the victim to share their screen and approve a UPI collect request.

    Here is the thing: Swiggy Instamart has no phone-based customer support at all. They only offer in-app chat. So if you are calling a Swiggy phone number, it is automatically a scam. Full stop.

    The Indian Cyber Crime Coordination Centre (I4C) removed 4,200 fake customer care pages from Google in Q2 2026 alone. That is just what they caught.

    Why Smart People Still Fall for the Fake Customer Care Number Scam

    • We over-trust Google. If a number appears near the top of search results, most people assume it is real. That assumption is the single biggest vulnerability scammers exploit.
    • The callers are trained professionals. They know company terminology, refund timelines, and complaint procedures. They often sound more helpful than real customer care agents, which is both ironic and terrifying.
    • They manufacture urgency. You will hear things like “your account will be suspended in 10 minutes” or “this refund link expires today.” Panic shuts down critical thinking.
    • Screen sharing is brutal. The moment you install AnyDesk or TeamViewer, the scammer can see your entire phone screen in real time. Every OTP that pops up, every banking app you open, everything becomes visible to them.

    Check: WhatsApp Wedding Invite Scam: One Tap Can Empty Your Bank

    How to Spot a Fake Customer Care Number Before You Call

    Before you call any helpline number, go through this checklist.

    • Go to the official website or app directly. Type the company URL yourself. Do not use a number from search results, Facebook posts, or blog articles.
    • Check if the company even offers phone support. Swiggy, Zomato, and many fintech apps only offer in-app chat. A phone number for these companies is automatically suspicious.
    • If they ask you to download any app, hang up immediately. No legitimate customer support team will ever ask you to install AnyDesk, TeamViewer, Quick Support, or Rust Desk.
    • No real agent will ask for your OTP, UPI PIN, CVV, or card number. If someone claiming to be from customer care asks for these, it is a scam. Period.
    • Run suspicious messages through a verification tool before acting on any helpline number sent via WhatsApp or SMS.
    • Never trust a number from Google AI Overviews. Documented cases show fake numbers appearing for Swiggy, Royal Caribbean, and British Airways. Always verify on the company’s official website.

    Already Got Scammed? Here Is Your Exact Action Plan

    The Golden Hour: First 60 Minutes

    • Call 1930 immediately. This is the national cyber fraud helpline run by the Ministry of Home Affairs. It is toll-free, available 24/7, and operators can freeze suspicious transactions in real time. The faster you call, the better your chances.
    • Block your bank account and cards through your bank’s official app or by calling your branch directly.
    • Do not delete anything. Keep all call logs, SMS messages, WhatsApp chats, and transaction notifications. These are your evidence.

    Within 24 Hours

    • File a detailed complaint on cybercrime.gov.in with screenshots, transaction IDs, and any recordings.
    • Visit your nearest police station and file an FIR. Under the Bharatiya Nyaya Sanhita (BNS), cyber fraud is a cognizable offense, which means police are legally required to register it.
    • Send a written complaint to your bank about the unauthorized transaction. Under the RBI’s zero-liability policy, reporting within 3 working days may qualify you for a complete refund.

    If the scammer sent you any link during the call, do not click it. Paste it into a URL checker tool first. This can prevent further damage.

    How Big Is This Problem in 2026?

    • Online scams caused losses of roughly Rs 7,000 crore ($789 million) in just the first five months of 2025, according to the Ministry of Home Affairs.
    • India’s National Cyber Crime Reporting Portal logged 22.68 lakh incident reports in 2024. That is nearly five times the 2021 figure.
    • The RBI’s 2024 to 2025 Annual Report flagged a 34% year-on-year jump in digital payment fraud cases.
    • Cybersecurity firm Aurascape found that scammers are now injecting fake numbers into Google AI Overviews and Perplexity, not just traditional search results.

    Who Runs These Fake Customer Care Operations?

    These are not lone wolves working from a bedroom. Investigations by Delhi Cyber Cell and state police units have exposed organized fraud rings operating from specific hubs:

    • Jamtara, Jharkhand has earned the nickname “India’s phishing capital” and even inspired a Netflix series.
    • Patna and Bihar districts are known for mule bank accounts that are bought and sold openly.
    • West Bengal accounts for 23% of all fake customer care numbers registered, according to CloudSEK data.
    • Delhi and Uttar Pradesh each account for 9.3% and serve as both operational and money laundering hubs.

    These operations are structured like small businesses. One team creates and distributes fake listings online. Another handles calls using rehearsed scripts. A third manages money movement through chains of mule accounts.

    The Google AI Overviews Problem Nobody Talks About Enough

    When Google rolled out AI Overviews in 2024, the idea was simple: put an AI-generated summary at the top of search results so users get quick answers. Great concept. Terrible execution when it comes to phone numbers.

    Here is what happens. Scammers create cheap websites filled with content that mentions well-known brands alongside fake phone numbers. Google’s AI scrapes these pages, treats the number as a valid answer, and displays it prominently at the very top of search results. The user sees a clean, Google-branded box with a phone number in it and naturally assumes it is reliable.

    Android Authority, Digital Trends, and the Washington Post all documented multiple cases of this happening. One widely reported incident involved Alex Rivlin, a real estate developer who searched for Royal Caribbean’s customer service number. The number shown in Google’s AI Overview was fraudulent. He shared his credit card information with the scammer before realising the mistake.

    Google has said they are aware of the problem and working on fixes. Until those fixes are fully in place, the rule is simple: never trust a phone number from any search engine result or AI summary. Open the company’s official website or app and find the number there yourself.

    Final Thoughts

    This scam is not going away anytime soon. As long as millions of people rely on Google to find phone numbers instead of going directly to official company websites and apps, scammers will keep exploiting that habit. The technology changes, the delivery channels evolve, but the core trick stays the same: plant a fake number where people are searching for help and wait for the calls to come in.

    The single most powerful thing you can do right now is share this information. Forward this article to your parents, your grandparents, your friends who are not very tech-savvy. Teach them one rule and make sure it sticks: never search for a customer care number on Google. Go to the company’s official website or app. Every single time.

    And if something feels wrong during a call, if they ask you to download software, share your OTP, or approve a payment request, just hang up. No real company will ever ask for those things. Trust that instinct.

    FAQ: Fake Customer Care Number Scam in India

    Q1: How do scammers get their fake numbers to show up on Google?

    They flood the internet with low-quality websites, blog posts, and social media pages that mention popular brand names alongside fake phone numbers. Google’s search algorithm and AI Overview feature sometimes pick these up and present them as legitimate. Scammers also run paid Google Ads and Facebook Ads pointing to fake helpline pages, which gives them even more visibility.

    Q2: Can Google AI Overviews actually show a scam phone number?

    Yes, and it has happened multiple times. Documented cases from 2025 and 2026 show Google AI Overviews displaying fake numbers for companies like Swiggy, Royal Caribbean, Southwest Airlines, and British Airways. Aurascape published detailed research explaining how scammers manipulate AI-generated results to surface fraudulent contact details.

    Q3: What should I do if I already shared my OTP or UPI PIN with a fake agent?

    Call 1930 immediately. Block your bank account through your bank’s official app. File a complaint on cybercrime.gov.in. Change your UPI PIN and all banking passwords from a completely different device. If you report within 3 working days, you may be covered under the RBI zero-liability policy for unauthorized transactions.

    Q4: Which brands do scammers impersonate the most in India?

    CloudSEK’s data shows banking and finance companies are the top targets at 59.4%, followed by healthcare at 19.2% and telecom at 10.5%. In terms of specific brands, SBI, HDFC, PhonePe, Paytm, Airtel, Uber, and Swiggy are among the most frequently impersonated names in India.

    Q5: Is the 1930 cyber fraud helpline available round the clock?

    Yes. The 1930 helpline, operated under the Ministry of Home Affairs, is toll-free and runs 24 hours a day, 7 days a week. It is connected to major banks and payment platforms, which allows operators to initiate transaction freezes in real time. The faster you call after a fraud, the higher the chances of recovering your money.

    Disclaimer: This blog is published for informational and educational purposes only. Nothing here should be treated as legal, financial, or professional advice. If you have been a victim of cyber fraud, please reach out to law enforcement and a qualified legal professional for guidance specific to your situation. Always report cyber crimes immediately through the official channels mentioned above.

  • WhatsApp Wedding Invite Scam: One Tap Can Empty Your Bank

    WhatsApp Wedding Invite Scam: One Tap Can Empty Your Bank

    It is peak wedding season in India, and your WhatsApp is flooded with shaadi cards from relatives, old college friends, and distant cousins. One morning, a new message pops up from an unknown number with a familiar tagline: “Welcome. Shaadi mein zarur aana. 30/04/2026. Love is the master key to happiness.” Attached is a neat little file that looks like a PDF invite. You tap it once, the screen flickers for a second, and nothing happens. You think it is broken and move on.

    Twelve hours later, your bank account is empty. This is not a hypothetical situation. It is exactly how a Maharashtra government employee lost ₹1.9 lakh and how Rajasthan Police recently warned the entire state. Welcome to the fake wedding invitation APK scam, one of the sneakiest cyber frauds spreading across India right now. This guide breaks down how the scam works, the red flags, and the exact steps to take if you or someone in your family has already tapped that file.

    What Is the Fake Wedding Invitation APK Scam?

    The fake wedding invitation scam is a malware-based cyber fraud where scammers send a file on WhatsApp that looks like a wedding card but is actually an APK (Android installer file).

    When you tap it, a hidden app gets installed on your phone. This app then:

    • Reads your SMS inbox (including banking OTPs)
    • Accesses your UPI and banking apps
    • Copies your contact list to send the same scam to your friends
    • Can take screenshots or record your screen in the background

    This scam is also known as:

    • Shaadi card scam
    • Wedding card APK fraud
    • WhatsApp malware scam
    • Fake e-invite scam

    How Big Is the Problem? (Data You Should Know)

    This is not a one-off scam. State police departments across India have officially flagged it as a wedding-season epidemic.

    State / AuthorityWarning IssuedReported Incident
    Rajasthan PoliceOfficial X (Twitter) advisory, November 2024₹4.5 lakh lost by single victim
    Himachal Pradesh CIDPublic warning by DIG Mohit ChawlaMultiple family accounts drained
    Gujarat PoliceState-wide social media advisoryFake cards auto-install malware
    Telangana Cyber BureauOfficial warning via XBank accounts compromised
    Maharashtra (Hingoli Dist.)FIR filedGovt employee lost ₹1.9 lakh
    HDFC BankCustomer advisory issuedWarned users against APK files

    According to cybersecurity firm EY, these attacks are significantly more common on Android devices compared to iPhones because Android permits installation of apps from outside the Play Store. The scam peaks between October and February, which coincides with India’s wedding season when 4.8+ million weddings take place annually.

    How the Scam Actually Works Step by Step

    Here is the exact chain of events scammers follow, reconstructed from police FIRs and cybersecurity advisories.

    Step 1: The Unknown Number

    You receive a WhatsApp message from a number not saved in your contacts. The profile picture often shows a smiling couple or a floral wedding design to lower your guard.

    Step 2: The Sweet Message

    The message looks emotionally warm and urgent, usually in Hindi or English:

    “Namaste 🙏 Shaadi mein aapka swagat hai. Please open the card and bless the couple. 30/04/2026”

    Sometimes the sender even uses a name similar to a known relative, making you assume it is a cousin or distant family member.

    Step 3: The Disguised File

    Attached is a file named:

    • Wedding_Invite.apk
    • Shaadi_Card.apk
    • Invitation_30-04-2026.apk
    • Rahul_weds_Priya.pdf.apk (double extension trick)

    On some Android phones, WhatsApp hides the .apk extension, making the file look like a normal PDF.

    Step 4: The Silent Install

    The moment you tap the file and press “Install” (even once), the malware:

    • Installs a hidden app with no visible icon
    • Requests permissions for SMS, contacts, and accessibility
    • Starts forwarding every OTP to the scammer’s server

    Step 5: The Drain

    Within hours, the scammer:

    • Initiates a UPI or bank transfer from your account
    • Intercepts the OTP silently
    • Transfers money to mule accounts before you notice
    • Uses your WhatsApp to forward the same fake card to your 100+ contacts

    Real Case Studies

    Case 1: Rajasthan Victim Loses ₹4.5 Lakh (2024) A Rajasthan resident received a WhatsApp message with a file named as a wedding invitation. After opening the file, malware accessed their bank account and drained ₹4,50,000 within hours. Rajasthan Police issued an official public warning afterwards.

    Case 2: Maharashtra Govt Employee, Hingoli District (2025) A government employee in Hingoli received a wedding invite from an unknown WhatsApp number with the message “Welcome. Shaadi mein zarur aye. 30/08/2025.” The attached file was an APK disguised as a PDF. Once installed, the malware gave scammers access to his bank account. Loss: ₹1,90,000. An FIR was registered at Hingoli Cyber Cell. Source: NDTV.

    Case 3: Kerala Family Loss (2024) Four members of a single family in Kerala received similar wedding APK files and each lost money. Police traced the malware to a remote-access tool based in a different state.

    8 Red Flags to Identify a Fake Wedding Invitation APK

    If any ONE of these appears, do not open the file.

    1. The sender is an unknown number not saved in your contacts.
    2. The file extension is .apk (or looks like .pdf.apk).
    3. The file size is bigger than 3 MB (real PDF invites are usually under 2 MB).
    4. The message has urgency: “Please open immediately” or “Just one day left”.
    5. The sender uses a familiar-sounding name but the phone number is new.
    6. The profile photo is a generic wedding couple image, often stock photo style.
    7. The message is forwarded, and shows the “Forwarded” tag on WhatsApp.
    8. After opening, your phone asks to “Allow installation from unknown sources”.

    Important: No legitimate wedding invitation in 2026 is shared as an APK file. Real invites come as PDF, JPG, PNG, or links to Canva/Google Drive/WedMeGood.

    Why Android Users Are More at Risk

    APK (Android Package) files only run on Android phones, which is why iPhone users are largely safe from this specific scam.

    Android allows app installations from outside the Play Store through a feature called “Install from Unknown Sources”. Scammers exploit this feature by:

    • Telling users to approve the permission “just this once”
    • Using Android’s trust in familiar file icons
    • Hiding the .apk extension behind .pdf naming

    If you want to check whether any suspicious link or file source you received is safe before tapping it, you can quickly verify it through our URL Checker tool. It cross-checks against databases of known malware and phishing domains.

    What to Do If You Already Opened the File

    Speed matters more than anything. If you realise you opened a suspicious APK, follow this immediately.

    Within 0 to 2 minutes

    1. Turn on airplane mode immediately. This cuts off the malware’s ability to transmit data or OTPs.
    2. Remove the SIM card from your phone.
    3. Do not use internet banking or UPI on this phone.

    Within 30 minutes

    1. Go to Settings → Apps, find any unfamiliar app, and uninstall it.
    2. If you cannot find the app, factory reset your phone. This is the only guaranteed way to remove all traces.
    3. Call your bank’s 24/7 helpline and freeze your accounts and cards temporarily.
    4. Change all banking, UPI, and email passwords from a different device.

    If Money Has Already Been Transferred

    1. Call 1930, the National Cyber Helpline, within the first 60 minutes (Golden Hour).
    2. File a detailed complaint at cybercrime.gov.in with all transaction IDs.
    3. Visit your bank branch with a written complaint to dispute the fraudulent transaction.
    4. File an FIR under IT Act Sections 66C, 66D, and IPC Section 420. For a full recovery walkthrough, read our step-by-step money recovery guide.

    Disclaimer: This information is for awareness only. For legal action, specific recovery procedures, or financial advice, consult a qualified cybercrime lawyer or certified professional. Recovery of funds is not guaranteed and depends on how quickly you act.

    Real Wedding Invite vs Fake APK Invite: Quick Comparison

    FactorFake APK InviteGenuine Wedding Invite
    File Type.apk (or hidden .pdf.apk).pdf, .jpg, .png, or link
    File Size3 MB to 15 MBUsually under 2 MB
    SenderUnknown number, often +92/+84Saved contact or close family
    Message ToneUrgent, generic, forwardedPersonal, often includes voice note
    Asks for permissionsYes, “Install from unknown sources”Never
    DesignerNone, basic iconMade on Canva, WedMeGood, or designer cards
    LinkNo link, direct fileOften a Google Drive / Canva link

    How to Check a Suspicious Message Before Opening

    If you are ever unsure whether a WhatsApp message is safe, there are three quick safety checks you can do before tapping the file.

    1. Ask the sender directly by calling them. Never reply on WhatsApp itself, as that account may already be compromised.
    2. Cross-verify the mobile number with known family members. Most weddings have a single contact person for invites.
    3. Paste the message text into our scam message checker. It analyses wording patterns, known fraud templates, and urgency markers used in such scams.

    Who Is Most at Risk?

    Based on police reports and cybersecurity advisories:

    • Working professionals (25 to 45 years) receiving genuine wedding invites daily, making fakes harder to spot
    • Homemakers and senior citizens less familiar with APK vs PDF difference
    • Job seekers and freshers who frequently download files on Android (also covered in our guide on spotting fake offer letters)
    • Small business owners whose WhatsApp doubles as a customer channel

    This scam specifically targets the emotional trust built around Indian weddings. Nobody wants to offend a distant relative by ignoring their shaadi card, and scammers weaponise exactly this instinct.

    Internal Safety Checklist (Print or Save This)

    • Never open files ending in .apk on WhatsApp
    • Check the file size before opening any invite
    • Disable “Install from unknown sources” in Android settings
    • Never tap “Allow” when an app requests SMS or Accessibility permissions
    • Keep Google Play Protect turned ON at all times
    • Never share OTPs, even with people who claim to be from your bank
    • Back up your phone regularly so factory reset is not painful
    • Teach elderly family members this single rule: if it ends in .apk, do not tap

    Final Word

    The fake wedding invitation APK scam works because it hijacks the purest part of Indian culture, community, celebration, and shaadi invitations. Scammers know that no Indian wants to be rude to a distant cousin’s wedding invite, and they exploit that social pressure perfectly.

    The good news is that this scam has exactly one fatal weakness. It only works if you tap that file. The moment you see an .apk extension on WhatsApp, the entire scheme collapses.

    One simple rule to remember: real wedding invitations are never app files. If the filename ends in .apk, it is not a wedding card, it is a thief at your door.

    Share this guide with your family WhatsApp group today, especially with parents and older relatives who receive the most wedding invites. That one forward could save someone lakhs.

    This article is for educational and awareness purposes only. It does not constitute legal or financial advice. If you are a scam victim, please consult a qualified cybercrime lawyer and your bank immediately.