Monday, July 27


MUMBAI: India’s cyber-fraud landscape is undergoing a decisive shift, with fraudsters moving away from remote takeover of devices to real-time social engineering, where victims themselves execute transactions under live phone instruction, even as a sprawling network of mule accounts enables the laundering of proceeds.According to the July 2026 report by Biocatch (a company that assists global banks on fraud prevention) on digital banking fraud trends, total attempted fraud sessions declined 12% between H2 2025-H1 2026 and the corresponding previous period, the value of attempted fraud payments rose 35%, signalling a pivot towards fewer but higher-value attacks.

Total attempted fraud sessions declined 12% between H2 2025 and H1 2026

This change is being driven by a move away from technology-heavy methods such as Remote Access Trojans to more direct psychological manipulation.

CJP Jantar Mantar Protest Updates

Detection of such malware fell from 2.5% to 1.7% of fraudulent sessions.At the centre of this shift is the rise of “active call guidance” frauds, where scammers remain on a phone call with victims and guide them step by step through fund transfers. The share of fraudulent sessions occurring during such calls rose from 3.9% to 4.5%.This new model is being amplified by a surge in mobile-led fraud. Mobile banking fraud sessions jumped 67%, driven by an 86% rise on iOS and 35% on Android, while web-based fraud fell 10%. Text messages have emerged as the primary entry point, with SMS-based scams rising 146%, typically used to lure victims into calls where social engineering takes over.Once engaged, victims are often instructed to enter credentials themselves, reflected in a rise in autofill usage for usernames and passwords, reducing the need for direct system compromise.Behind these front-end scams lies a critical but less visible layer: mule accounts, which form the backbone of the fraud economy.The CBI in 2025 identified more than 8.5 lakh mule accounts across more than 700 bank branches. Overall, 26.5 lakh mule cases were logged nationally, linked to cyber-fraud complaints amounting to Rs 22,496 crore, of which Rs 9,055 crore was blocked or declined through intervention mechanisms. Authorities froze more than 4.5 lakh mule accounts in a year.Money mules (individuals) are recruited through fake job advertisements, social media, or messaging platforms, often without full awareness of the criminal intent.These accounts are either newly opened with legitimate KYC or rented from existing account holders. Once activated, they are used for rapid “layering” of funds, moving money across multiple beneficiaries at high speed using instant payment systems such as UPI, before eventual dispersal into cash, cryptocurrency, or international channels.The “mule-as-a-service” model decentralises operations, allowing fraudsters to bypass banking controls and later consolidate funds, often converting them into cryptocurrency before transferring them abroad.



Source link

Share.
Leave A Reply

Exit mobile version