The scams going around right now — fake “digital arrest” calls, KYC-expiry links,
UPI collect requests, courier and e-challan tricks — with the red flags to look for and exactly what to do.
Share an alert with anyone likely to get that call or SMS.
Last updated
· 17 active alerts
☎
Money already gone? Call 1930, India’s national cyber-fraud helpline,
straight away — the first hour matters most — and report it on
cybercrime.gov.in.
Then call your bank on the number printed on your card.
NewHigh riskWhatsAppPunjab, Haryana, Kerala, Gujarat, Tamil Nadu
Fake overseas job, study-visa and Gulf recruitment agents
Agents on WhatsApp, Instagram and in local offices promise a Canada, Europe, Gulf or Australia job or study visa for an upfront 'processing', 'medical' or 'embassy' fee running into lakhs. Some victims are trafficked into scam compounds in South-East Asia and forced to run online frauds.
How it works
Genuine-looking offer letters, visa stamps and video 'interviews' are faked. Payments are staged - registration, then medical, then ticket - and the agent vanishes or the visa turns out to be a tourist visa with no job at the other end.
Red flags
A job that needs no interview, no skills test and money before a contract
An agent who is not a registered recruiting agent (check emigrate.gov.in) and payment to a personal account
Offers for 'data entry' or 'customer service' in Thailand, Cambodia, Myanmar or Laos with flights paid by the employer
Pressure to hand over your passport
What to do
Check the recruiting agent's registration on emigrate.gov.in before paying anything; use only registered agents for Gulf and other ECR-country jobs.
Verify a foreign employer directly through its official website and the embassy - not through the agent's contacts.
Keep your passport; never pay for a 'job' before a signed contract you can verify.
Report on cybercrime.gov.in or to the local police; if someone is stuck abroad, contact the nearest Indian embassy and the MEA helpline.
Share this alert
NewMedium riskWebsiteUttarakhand, Himachal Pradesh, Jammu & Kashmir, Goa, Kerala
Fake helicopter, hotel and houseboat booking websites for pilgrim and tourist spots
Look-alike websites and Facebook pages take advance UPI payments for Kedarnath / Char Dham helicopter seats, Vaishno Devi hotels, Goa and Kerala resorts, Manali stays and Dal Lake houseboats. The booking does not exist and the site disappears after the season.
How it works
The pages copy real photos and names, rank through paid ads, and insist on full payment by UPI or bank transfer to a personal account. There is no refund route because there was never a booking.
Red flags
Helicopter tickets sold anywhere other than the official IRCTC Heli Yatra portal for Char Dham
Payment to a personal UPI ID or individual's bank account instead of a card gateway
Prices far below the season rate and 'only 2 seats left' pressure
A website registered weeks ago with no landline, GST number or physical address
What to do
Book Char Dham helicopter seats only on heliyatra.irctc.co.in; book hotels through known platforms or by calling the property on a number from its own verified listing.
Pay by card or a platform's gateway so a chargeback is possible; avoid advance transfers to personal accounts.
Run the site through Aegix Scam Checker - it flags newly registered and look-alike domains.
Report on cybercrime.gov.in and to the state tourism department.
Share this alert
NewHigh riskPhone callAll India
"Digital arrest" video calls from fake police, CBI or customs
A caller claiming to be from the police, CBI, ED, TRAI or customs says your Aadhaar, phone number or a parcel in your name is linked to money laundering or drugs. They move you to a video call, show fake ID cards and a fake police station backdrop, and keep you on the line for hours while you transfer money to a 'safe account' to avoid arrest.
How it works
Fear and isolation. You are told you are under 'digital arrest' and must not hang up or tell anyone. There is no such thing as a digital arrest under Indian law. The 'verification' ends with you moving your savings to an account the caller controls, sometimes in several instalments over days.
Red flags
A police, court or government agency contacting you over WhatsApp or a video call
Being told to stay on the call and not speak to family, a lawyer or your bank
Any demand to transfer money to a 'safe', 'RBI' or 'verification' account
Pressure to act within minutes and threats of an arrest warrant
What to do
Hang up. No agency arrests anyone over a video call or asks for money to avoid arrest.
Do not transfer anything. Call a family member and your bank on their official numbers.
Report the number on cybercrime.gov.in or call 1930 (the national cyber-fraud helpline).
If money already left your account, call 1930 immediately - the first hour matters most.
Part-time 'task' jobs: like videos, review hotels, earn Rs 5,000 a day
A WhatsApp message offers easy work from home - liking YouTube videos, rating hotels or OYO listings, or reviewing products. Small payouts arrive at first; then 'prepaid tasks' require you to deposit money to unlock bigger commissions, and the deposits are never returned.
How it works
The first Rs 150-500 is paid to build trust and to move you to a Telegram group full of fake 'members' posting profits. Deposits escalate from Rs 1,000 to lakhs, always one 'final task' away from withdrawal. The group vanishes once you stop paying.
Red flags
A job offer you never applied for, from an unknown number, with a company logo but no real interview
Being moved to Telegram and given a 'receptionist' or 'mentor'
Any deposit, registration or 'prepaid task' before you can withdraw
Earnings shown on a website dashboard that will not let you withdraw
What to do
No real employer pays you to like videos or asks you to deposit money to work.
Stop paying the moment a deposit is requested - there is no 'final task'.
Screenshot the chats and report on cybercrime.gov.in or 1930; report the group inside Telegram/WhatsApp too.
Warn family members who are looking for work from home.
A caller claiming to be from Jio, Airtel, Vi or BSNL offers a free 5G or eSIM upgrade, or warns that your SIM will be blocked under a 'TRAI/DoT order'. You are asked to forward an SMS, share an OTP or enter a code - which moves your number to the scammer's SIM, and every bank OTP with it.
How it works
The eSIM activation code is sent to your phone; the scammer needs you to read it out or forward it. Once your number is theirs, your phone loses signal and they reset banking and UPI passwords using the OTPs.
Red flags
Any request to forward a message, share an OTP or dial a code to 'upgrade' your SIM
'TRAI' or 'DoT' calling you personally about your number being blocked - they do not
Your phone suddenly shows no network after such a call
An eSIM activation SMS you did not request
What to do
Hang up. Upgrade a SIM only inside the operator's official app or at a store.
If your signal disappears unexpectedly, call the operator from another phone at once and tell your bank.
Check which numbers are registered on your name at sancharsaathi.gov.in (TAFCOP) and report suspected fraud there (Chakshu).
Fake courier or customs call about a parcel with drugs or passports
A recorded or live call says a FedEx, DHL, Blue Dart or India Post parcel in your name has been stopped by customs with drugs, fake passports or cash inside. 'Press 1 to speak to customs' hands you to a fake officer, and the call often turns into a digital-arrest scam.
How it works
The scammer needs only your name and number. Claiming a parcel is in your name creates instant panic; a 'police case number' and a 'Mumbai/Delhi cyber cell' transfer make it feel real. The end goal is money moved to a 'verification' account or a remote-access app installed on your phone.
Red flags
You were not expecting any parcel, or it is 'addressed to you' from a city you have no link to
An automated voice asking you to press a key to reach customs or police
The courier company 'transfers' you to the police on the same call
Requests to install AnyDesk, TeamViewer or a 'verification' app
What to do
Hang up and check any real shipment on the courier's official app or website using your own tracking number.
Courier companies do not connect calls to the police; customs does not phone individuals about seized parcels.
Never install an app or share an OTP because a caller told you to.
Stock-tip and trading WhatsApp groups run by a fake 'SEBI-registered' expert
You are added to a WhatsApp or Telegram group where a 'guru' from a well-known broker or fund posts daily profits and members share screenshots. You are asked to install a special trading app or join an 'institutional account' for IPO allotments; the app shows fake gains and blocks every withdrawal.
How it works
Everyone in the group except you is part of the scam. The 'app' is a website or APK controlled by the operator - the profits are numbers on a screen. Withdrawals require 'tax', 'unlock' or 'compliance' payments, which are the actual theft.
Red flags
Guaranteed or 'assured' returns, 'block trades', 'IPO quota' or profit promises of 2-3x
Trading through an app or website not listed on a registered broker's site
Being asked to move money to a personal or company account rather than your own demat-linked bank account
A withdrawal that needs a fee first
What to do
Trade only through a SEBI-registered broker's own app; check the registration on sebi.gov.in.
Leave the group and block the admin. Never install a trading app from a chat link.
Report on cybercrime.gov.in or 1930 with screenshots of the group and payment details.
Warn relatives - these groups target retirees and salaried savers most.
"Your electricity will be disconnected tonight" SMS and WhatsApp messages
A message in the name of your discom (Mahavitaran, BSES, Tata Power, UPPCL, TANGEDCO, BESCOM, Torrent and others) says last month's bill was not updated and power will be cut at 9:30 PM tonight unless you call an 'electricity officer' or update via a link.
How it works
The number given is a scammer's personal mobile. On the call you are asked to pay a small 'update fee' of Rs 10 through a link or app, which either captures your card and UPI details or installs a screen-sharing app that empties the account.
Red flags
A bill message from a personal 10-digit mobile number instead of the discom's sender ID
Threat of disconnection 'tonight' with a phone number to call
Spelling mistakes, 'Dear consumer' with no consumer number or amount
A request to pay Rs 5-10 to 'update' or 'reconnect'
What to do
Check your bill only inside the discom's official app or website, or on the number printed on your paper bill.
Discoms send disconnection notices with your consumer number and a due date, never a 'tonight' deadline over WhatsApp.
Do not call the number in the message and never install an app to pay a bill.
Forward the message to your discom's official WhatsApp or helpline and report it on cybercrime.gov.in.
Share this alert
High riskWhatsAppAll India
Wedding invitation, PDF or 'photo' APKs sent on WhatsApp
A contact - or an unknown number - shares a wedding card, an exam admit card, a bank 'statement' or a photo that is actually an .apk file. Installing it puts malware on the phone that reads SMS OTPs, forwards your chats and sends itself to your contacts.
How it works
The file name and icon look like a document, but Android will ask to 'install' it - that is the tell. Once installed it hides its icon, asks for SMS and accessibility access and quietly forwards bank OTPs; some variants take over WhatsApp to spread further.
Red flags
A file ending in .apk pretending to be a card, PDF or photo
Android asking to install something when you only wanted to view a file
A new app asking for SMS, accessibility or 'display over other apps' access
Friends receiving the same file from your number
What to do
Never open an .apk sent in a chat, even from a friend - their phone may already be infected.
If you installed one: flight mode, uninstall it, run Aegix Scan, then change banking passwords from another device.
Ask the sender by call whether they really sent it.
KYC-expiry links in the name of your bank, wallet or telecom operator
An SMS or email says your SBI, HDFC, ICICI, Paytm, PhonePe or SIM KYC has expired and the account will be blocked today. The link opens a look-alike login page that collects your net-banking password, card details and OTP, or downloads a fake bank APK.
How it works
The page is a copy of the real login screen on a domain that only resembles the bank's. Whatever you type goes to the scammer, who logs in on their side and uses the OTP you 'confirm' to move money. The APK variant reads your incoming SMS so future OTPs are stolen silently.
Red flags
A link to update KYC - banks update KYC only in their own app, at the branch or via video KYC you start yourself
The address is not the bank's real domain (for example sbi.co.in, hdfcbank.com, icicibank.com)
Urgent 'blocked today' language and a shortened link (bit.ly, tinyurl, cutt.ly)
A download of an .apk file
What to do
Do not tap the link. Open your bank's official app instead and see if a KYC notice really exists.
Check the sender: real bank messages come from a registered sender ID such as SBIINB or HDFCBK, not a mobile number.
Run the link through Aegix Scam Checker before opening anything you are unsure about.
If you typed anything on such a page, change the password in the official app and call the bank at once.
Medium riskWhatsAppMaharashtra, Madhya Pradesh, Karnataka
Fake 'Ladki Bahin', 'Ladli Behna' and 'Gruha Lakshmi' registration links
WhatsApp forwards and Facebook ads offer registration or a 'pending instalment' for Maharashtra's Mukhyamantri Majhi Ladki Bahin Yojana, Madhya Pradesh's Ladli Behna Yojana or Karnataka's Gruha Lakshmi scheme through a link or app. They collect Aadhaar, bank details and OTPs, or charge a 'form fee'.
How it works
Popular state cash-transfer schemes have millions of applicants, so a message about a stuck instalment gets attention. The fake form is a phishing page; some variants push an APK that reads SMS.
Red flags
A link that is not on the state's official portal (for example ladakibahin.maharashtra.gov.in, cmladlibahna.mp.gov.in, sevasindhugs.karnataka.gov.in)
A fee to apply or to 'release' an instalment
Aadhaar, bank account and OTP asked together in a chat or on one page
A message from a personal number claiming to be the state government
What to do
Apply and check status only on the official state portal, the official app on Google Play, or at an Anganwadi / Seva Kendra / CSC.
Never pay a fee - these schemes are free to apply for.
Do not share an OTP with anyone offering to 'help' with registration.
Report on cybercrime.gov.in.
Share this alert
Medium riskWhatsAppAll India
Fake traffic e-challan link or 'Vahan Parivahan' APK
An SMS or WhatsApp message says a challan is pending on your vehicle and offers a link to pay - or a file named like 'Vahan Parivahan.apk' or 'e-Challan.apk'. The link is a phishing page; the APK is malware that reads your OTP messages and can drain accounts.
How it works
Real challans are paid only on echallan.parivahan.gov.in or the state traffic police portal. The fake page collects card details; the APK asks for SMS and accessibility permissions, hides its icon and forwards your bank OTPs to the scammer.
Red flags
A challan message with an .apk attachment or a link not on parivahan.gov.in
No vehicle number, challan number or offence details in the message
The 'app' asks to read SMS or to be set as the default SMS app
A discount if you pay 'today'
What to do
Check challans yourself on echallan.parivahan.gov.in by entering your vehicle number.
Never install an APK from a chat. Government apps are only on Google Play.
If you installed one, switch on flight mode, uninstall it, run Aegix Scan and change your banking passwords from another device.
"Sent by mistake, please return" and UPI collect requests
A stranger messages or calls saying they sent money to your UPI by mistake and asks you to return it. Either no money ever arrived, the 'credit' is a fake screenshot, or a UPI collect request appears on your phone that would pull money OUT when you enter your PIN.
How it works
UPI PIN is needed only to send money, never to receive it. A collect request dressed up as a 'refund' or 'cashback' still takes your PIN and debits you. Variants use a fake payment screenshot or a chargeback the scammer's bank later reverses, leaving you out of pocket.
Red flags
Anyone asking you to enter your UPI PIN to 'receive' money
A collect request or QR code you are told to approve or scan to get a refund
A payment screenshot instead of a credit in your own bank or UPI app
Pressure to 'return it now' with emotional stories
What to do
Decline every collect request you did not initiate.
Check your own bank statement or UPI app history before believing any credit.
If a real mistaken credit exists, tell your bank - a refund goes through the bank, not by you sending money back.
Report the UPI ID on your UPI app and on cybercrime.gov.in.
Share this alert
Medium riskWhatsAppAll India
PM-Kisan, Ayushman and other government-scheme links and APKs
Messages promise a pending PM-Kisan instalment, an Ayushman card, a free ration card, a 'PM Yojana' loan or scheme registration through a link or an APK named after the scheme. The page or app collects Aadhaar, bank and OTP details, or installs SMS-stealing malware.
How it works
Scheme names are trusted and rural users are the target. The fake app asks for SMS permission 'to verify your mobile' and then forwards every OTP; the phishing page harvests Aadhaar and bank details for later fraud.
Red flags
A scheme link that is not on a gov.in domain, or an .apk file
A request for Aadhaar number, bank account and OTP together
A 'registration fee' or 'processing fee' for a free government scheme
Promises of a payout 'today' if you act now
What to do
Check PM-Kisan status only on pmkisan.gov.in or the PM-Kisan app from Google Play; check other schemes on their official gov.in portals or at the CSC.
Government schemes never charge a fee over a link and never need an APK from WhatsApp.
If you installed such an app, uninstall it and run Aegix Scan.
Instant loan apps that read your contacts and then harass you
Apps promising a loan in minutes with no documents ask for contacts, photos and SMS access at install. They credit far less than promised, charge huge 'processing fees', and when the short repayment window passes they threaten and message your contacts, sometimes with morphed photos.
How it works
The app is the weapon: contacts and gallery access are all the lender needs to blackmail. Many such apps are not registered with the RBI at all; some are sideloaded from links rather than from Play.
Red flags
A loan app asking for contacts, gallery or SMS access
No mention of a bank or an RBI-registered NBFC partner
Loan tenure of 7-14 days with fees deducted upfront
Installed from a link or APK, not from Google Play
What to do
Borrow only from RBI-regulated banks and NBFCs; check the lender on the RBI website before installing anything.
Deny contacts, gallery and SMS permissions - a genuine lender does not need them.
If you are being harassed, do not pay extra. Keep the messages and file a complaint on cybercrime.gov.in and with the RBI Sachet portal.
Use Aegix Scan to find apps that can read your SMS or contacts and uninstall the ones you do not trust.
A caller posing as an Amazon, Flipkart, Swiggy or courier delivery agent says a parcel could not be delivered and asks you to confirm an OTP that has 'just been sent', or to pay a small re-delivery fee. The OTP is for your bank, e-commerce account or SIM, not for any parcel.
How it works
The scammer triggers a real OTP (a password reset, a card transaction, a SIM-swap request) at the same moment they call. Because a delivery OTP is normal in India, reading it out feels harmless. A re-delivery 'fee' link captures card details instead.
Red flags
An OTP request for a parcel you did not order or that you have not been tracking
The OTP message itself says it is for a bank, a login or a SIM change, not a delivery
A fee to re-attempt delivery or to 'update the address'
The caller is not the delivery partner shown in the shopping app
What to do
Read the OTP message fully before sharing anything - it names what it is for.
Delivery OTPs are shown inside the shopping app and are given only to the agent at your door.
Do not pay re-delivery fees over a link; genuine partners never charge this way.
Report the number in the shopping app and on cybercrime.gov.in.
Share this alert
Medium riskWebsiteAll India
Fake customer-care numbers in search results and social posts
Searching for a bank, airline, IRCTC, courier or app helpline turns up a scammer's number in an ad, a Google Maps listing, a Twitter/X reply or a Facebook page. The 'agent' takes your card number, sends a 'refund form' link or asks you to install a screen-sharing app.
How it works
Scammers plant numbers wherever people look for help and reply to public complaints within minutes. Once on the call they resolve a fake refund by asking for your card details and OTP, or watch your screen through AnyDesk while you log in.
Red flags
A helpline number from an ad, a comment, a Maps pin or a random website instead of the company's own app
An 'agent' asking for card number, CVV, UPI PIN or OTP to process a refund
A request to install AnyDesk, TeamViewer, QuickSupport or any 'support' app
A refund that needs you to pay first
What to do
Take helpline numbers only from the company's official app, the back of your card or a bill.
Real support never asks for a PIN, CVV or OTP, and never asks you to install a screen-sharing app.
Post complaints on social media without your phone number; real companies reply from verified handles.
Report fake listings to the platform and on cybercrime.gov.in.
Share this alert
Protect your parents — send them Aegix
Scam SMS aim hardest at the people least likely to spot a fake KYC link. Send them the app in one tap: the message explains what it does, links this page and the Play listing. Install it on their phone and switch on scam-SMS warnings — the warnings show on their phone.
Get these warnings on the phone itself
Aegix is a free Android app from CryoSim. Switch on scam-SMS warnings and it flags a new SMS that pairs a link
with typical scam wording (KYC expired, OTP, SIM block, e-challan…). Its Scam Checker reads any message,
link or UPI ID you paste in, and Scam Radar brings this list into the app, filtered to your state.