They then exploit the victim's bank accounts. Numerous cases of this fraudulent conduct have recently emerged.
According to a Reserve Bank of India (RBI) study, India experienced bank frauds totaling more than Rs 30,000 crore in FY23. Over the last decade, Indian banks have reported 65,017 fraud instances, resulting in a total loss of Rs 4.69 trillion.
To deceive naive people, cybercriminals use a variety of strategies, such as UPI, credit card, OTP, job, and delivery scams. Digital house arrest is a new popular scamming strategy.
Digital house arrest occurs when cybercriminals trap victims in their homes to trick them. Perpetrators instill terror by making calls, frequently impersonating law enforcement officers via AI-generated voice or video calls.
They fraudulently accuse victims of misconduct involving their Aadhaar or phone number, creating a sense of imminent arrest and pushing them to send money.
Hackers usually contact victims and claim they shipped or received boxes carrying illegal substances such as narcotics or false passports. They may even fraudulently alert the target's relatives or acquaintances about their involvement in a crime, instilling a sense of urgency.
Criminals pose as law enforcement officers, and demand money from victims as compensation for covering the case. Victims are pressured to remain visible on video conferencing services until their requests are granted.
Hackers use strategies such as setting up fake police stations or government offices and dressing in uniforms mimicking those of law enforcement authorities.
Uttar Pradesh Police launched an investigation into the first recorded case of 'digital arrest' in December of last year after receiving a complaint from a Noida resident.
The victim fell victim to the fraud, losing more than Rs 11 lakh and facing a day-long 'digital arrest'. Perpetrators posed as police officers, impersonating an IPS officer from the CBI and the founder of a bankrupt airline, and implicated the victim in a manufactured money-laundering case.
The Indian Cyber Crime Coordination Centre (I4C) and the Department of Telecommunications (DoT) are collaborating to combat the influx of spoof calls coming from abroad. These callers falsely claim to be from law enforcement authorities such as the Narcotics Control Bureau or the Central Bureau of Investigation, among others, and claim 'digital arrests'.
In addition, I4C has partnered with Microsoft to fight the abuse of law enforcement emblems. These logos are regularly used by scammers abroad to take money from Indian nationals.
To raise awareness, I4C has released infographics and videos on its social media platform Cyberdost and its X (Twitter), Facebook, and Instagram pages. The Ministry has asked citizens to remain vigilant and raise awareness about cybercrime.
If you get a similar call or message, contact the authorities. The government of India has launched the Chakshu portal on the Sanchar Saathi website to combat cyber and online fraud. Individuals can also report similar incidents using the cybercrime helpline 1930 or online http://www.cybercrime.gov.in.
The National Payments Corporation of India (NPCI) and RBI regulations advise not using Indian payment systems for banned or blacklisted website categories such as porn sites, gambling, Chinese laundering/loan apps, Forex trading sites, or other shadowy websites.
To escape this restriction, scammers use Mule accounts to receive money through Indian payment ways like bank accounts, credit cards, UPI, debit cards, and VPA.
A Mule account is a famous term in cybercrime that looks for any account used for moving money illegally received through illegal activities. These accounts mostly belong to those who, intentionally or unintentionally, have been tricked into playing the illegal money laundering act.
Not aware of being part of a bigger scam, these individuals or “money Mules” are tricked into letting unknown scammers use their accounts to hide the source of laundered money. Scammers make these payments look legit through sly schemes and baits, hiding the money’s shadowy inheritance before it goes to the final destination.
“We detect 18 to 20 thousand cases every single day for a National Bank. These mule accounts are usually owned by regular people who are either tricked into opening them or knowingly use them at the behest of some monetary payments. We advise people not to share their account details or give access to anyone. Fraudsters can use your credentials for such illegal activity” said Amit Relan, Co-founder and CEO of mFilterit.
Money Mules fall into two categories: willing participants and duped participants. The scammers approach the Mule account customer online via emails, social media, websites, etc. Customers are fooled into believing they will get money in their bank account through commissions or incentives. After that, the scammer transfers laundered money into the Mule account.
Scammers attack vulnerable and naive individuals, using lucrative job scams or fake online relationships to scam people. The victims are fooled through false promises of easy money for not-so-harmful activities like transferring goods or money. If an online job opening seems too good to be true or needs managing money or services, it is most likely a Mule recruitment scam.
“Fraudsters might pose as authentic organizations like banks or government agencies to deceive victims into divulging personal or financial details. Phishing emails frequently include hyperlinks or attachments that, once clicked or opened, can deploy malware or direct users to fake websites crafted to steal sensitive information” said Dhiren. V. Dhedia, Head- Enterprise Solutions, CrossFraud.
Be cautious, if someone else controls your bank account, you are risking your savings and facing possible criminal charges. You should stay updated and informed to not fall for the mule scam.
Sharing your personal banking details with people you don’t trust is a big no, even if they have a believable story or offer.
Phishing emails are scams where the actors try to befool the user by sending emails that may concern the user. Generally, these emails are received in the name of a bank or some trusted company, that asks for your personal information. The entire process appears to be legitimate but it's designed to trick the user into extracting their personals information.
The Central Bank of Russia informed banks that fraudsters use the voice menu to get information about the status of customers' accounts, using only the last four digits of the card.
It all started with the fact that one of the credit organizations reported a sharp increase in the number of calls to customers from fraudsters, and the attackers knew the exact amount on the accounts.
It turned out that the scammers made phone calls to the IVR system (Interactive Voice Response), replacing customer numbers. When calling from a client's number, they requested information about the remaining funds by entering the last four digits of the Bank card.
After that, the scammers called potential victims and introduced themselves as Bank employees. As proof of authenticity, they provided customers with information about their account balances. After that, they successfully used social engineering methods to steal money.
The phone numbers of customers and their Bank cards were compromised and spread on the Internet. The Central Bank believes that fraudsters could get them from the Joom client base, which was in the public domain. Then, representatives of the online store and banks assured that there is no danger for customers, since the data that fell into the hands of fraudsters is not enough to debit money from their accounts.
It turns out that the last four digits of the card may be enough to get confidential information from Bank customers. But this information is not officially classified as secret and is printed on any check.
According to Sergey Golovanov, a leading expert at Kaspersky Lab, the use of biometrics can simplify the identification process for the user and make this process more secure. At the same time, the expert believes that the use of biometrics would increase its cost for the Bank. Thus, despite the recommendations of the Central Bank, banks will continue to minimize their costs in this area, risking making their customers victims of fraud.