KYCKART
KYCKART Guide · August 2026Guide

Bank Fraud: Warning Signs, Common Types, and How to Prevent It

Bank fraud in India spans phishing, digital arrest scams, UPI fraud, and money mules. The warning signs, how to report fraud fast, and what RBI requires of banks.

calendar_monthAugust 2026
schedule13 min read
library_books38 Cited Sources
personBhanujeet Choudhary, Head of Compliance

Bank fraud is any act of deception used to illegally obtain money, property, or sensitive account information from a bank or its customers. Indian law prosecutes it as cheating under Section 318(4) of the Bharatiya Nyaya Sanhita (BNS), 2023, which replaced Section 420 of the Indian Penal Code on 1 July 2024, carries up to seven years’ imprisonment and a fine, and applies to digital fraud (online scams, app-based fraud, cryptocurrency cheating) as much as it does to a forged cheque[1]. The offence is cognisable and non-bailable, which is why police can arrest without a warrant and bail isn’t automatic at the station[38].

This piece covers two things: the warning signs an individual account holder needs to recognize, and what banks and NBFCs are required to do once fraud is reported. This is general awareness content, not legal or compliance advice for a specific situation.

01

Common Types of Bank Fraud in India Right Now

Phishing and smishing

The Indian Computer Emergency Response Team (CERT-In) has issued periodic advisories warning bank customers about phishing campaigns that use fake SMS links, in some cases abusing legitimate platforms like ngrok, to host pages that impersonate a bank’s internet-banking portal and harvest login credentials, mobile numbers, and OTPs[23]. CERT-In has separately warned about smishing specifically: once a victim clicks the link in a text message, their personal details risk being sold on the dark web or used to alter e-filing and account records[24]. CERT-In directs the public to report phishing sites and suspicious messages to incident@cert-in.org.in as well as to their bank[24].

Digital arrest scams

In this scam, fraudsters impersonate law enforcement or government officials over video or voice calls and pressure victims into transferring money out of fear of arrest[16]. Cases rose 103% year-on-year in India in 2024, to 1,23,672, and reported losses jumped 465% to roughly ₹1,918-1,935 crore, according to data the Minister of State for Home Affairs presented to Parliament[16]. That’s a steep climb from ₹91 crore in losses across 39,925 cases in 2022 and 60,676 cases in 2023[16]. The Ministry of Home Affairs later reported that digital arrest cases fell 86% and losses fell 66.4% in 2025, attributing part of the drop to public awareness campaigns[16].

AI voice cloning and deepfake scams

One 2025 analysis estimated that 47% of Indian adults had either been a victim of, or knew someone who had been a victim of, an AI voice-cloning or deepfake scam, nearly double a cited global average of 25%[28]. In one widely reported 2025 case, a 54-year-old woman in Bengaluru lost more than ₹33 lakh after trusting a deepfake video that appeared to show Union Finance Minister Nirmala Sitharaman endorsing a fraudulent trading platform on Facebook[29]. The RBI has publicly stated that deepfake videos of its own officials promoting fraudulent investment schemes are fake and has urged the public not to trust or act on such content[27]. India’s Ministry of Electronics and Information Technology (MeitY) notified amendments to the IT Rules in 2026 that formally define “synthetic media” for the first time and require large social media platforms to remove flagged deepfake content within 3 hours[30].

UPI fraud

UPI-related fraud in India totalled ₹981 crore across 12.64 lakh reported cases in FY2024-25, down slightly from ₹1,087 crore across 13.42 lakh incidents the year before, with both total value and average loss per case falling year-on-year[10]. A LocalCircles survey found that roughly one in five families with a UPI user had experienced UPI-related fraud at least once in the past three years, and that 51% of victims never reported it[11].

Cheque fraud

Common cheque fraud in India takes three forms: forged signatures, altered cheque details, and entirely counterfeit cheques[13]. The RBI introduced the Positive Pay System (PPS) on 1 January 2021 specifically to combat tampering and alteration[12]. For cheques above a bank-set threshold, commonly ₹50,000, with several banks mandating it above ₹5 lakh, the issuer must pre-register the payee, amount, date, and cheque number through mobile or internet banking, and the paying bank cross-checks those details against the physical cheque before honouring it, flagging any mismatch as potentially fraudulent[12][13].

ATM and card skimming

RBI data cited by Moneyview showed nearly 24,000 fraud cases related to credit cards, debit cards, and internet banking registered in India between April and December of a recent reporting year[14]. Skimming remains an active, low-tech threat: Mumbai police broke up a card-cloning racket in which waiters at bars and restaurants used skimming devices to steal card data from roughly 1,000 customers over two years, and Kolkata police separately arrested three people found with skimming devices, a laptop, and pinhole cameras used to capture PINs at ATMs[15].

Money mule recruitment

A money mule account is a bank account used to receive and quickly move or launder money obtained through fraud[17]. Some account holders are recruited and paid to lend their account; others don’t know their account is being used this way[17]. India’s Indian Cyber Crime Coordination Centre (I4C) had flagged more than 2.47 million “Layer-1” mule accounts as of early 2026[17]. The scale shows up locally too: mule accounts were a common thread in 9,437 reported cybercrime cases in Hyderabad alone, linked to roughly ₹400 crore in annual losses; Delhi police uncovered a mule-account syndicate active for three to four years that moved more than ₹70 crore through the network, with a bank manager among ten people arrested; and Bengaluru police recovered more than 357 bank accounts that had been rented out to cybercriminals[18].

At a Glance: Comparing the Seven Fraud Types

Fraud TypeHow It WorksScale or Loss FigureWhere to Report
Phishing & smishingFake SMS links (sometimes abusing platforms like ngrok) impersonate a bank’s internet-banking portal to harvest logins and OTPs[23][24]Not quantified in sourced dataCERT-In (incident@cert-in.org.in) and your bank[24]
Digital arrest scamsFraudsters posing as police or officials pressure victims by video/voice call into transferring money[16]1,23,672 cases and ~₹1,918-1,935 crore in losses in 2024, then an 86% drop in cases in 2025[16]1930, India’s national cybercrime helpline[31]
AI deepfake & voice cloningAI-generated video or audio impersonates officials or public figures to promote fraudulent schemes[27][29]47% of Indian adults victimized or know a victim[28]; one Bengaluru case cost over ₹33 lakh[29]1930[31]
UPI fraudFraudulent transactions on India’s UPI payment rail[10]₹981 crore across 12.64 lakh cases in FY2024-25[10]1930[31]
Cheque fraudForged signatures, altered details, or entirely counterfeit cheques[13]RBI’s Positive Pay System requires pre-registration for cheques above ₹50,000 (₹5 lakh at some banks)[12][13]Your bank
ATM & card skimmingSkimming devices and pinhole cameras capture card data and PINs at ATMs, bars, and restaurants[15]~24,000 card/internet-banking fraud cases registered Apr-Dec of a recent year[14]; one Mumbai racket affected ~1,000 customers over two years[15]Your bank
Money mule accountsAccounts used, knowingly or not, to receive and quickly move fraud proceeds[17]2.47 million+ “Layer-1” mule accounts flagged by I4C as of early 2026[17]1930[31]
02

Warning Signs to Watch For

RBI and Indian banks’ public guidance is direct on this point: bank employees will never ask for confidential details such as OTPs, PINs, CVV numbers, or passwords over phone, SMS, or email, and any such request should be treated as fraud[25]. RBI’s own consumer awareness campaign, which also covers grievance redressal and the RBI Ombudsman Scheme, boils down to a short list[26]:

  • Don’t share your login ID, password, PIN, or OTP with anyone, including someone claiming to call from your bank.[26]
  • Don’t download apps from unknown or unverified sources.[26]
  • Treat any call or video call from someone claiming to be a police officer, government official, or bank representative, demanding urgent money transfer under threat of arrest, as a probable digital arrest scam.[16]
  • Be skeptical of investment endorsements from public officials or celebrities in video clips, especially on social media. RBI has said scammers are using deepfakes of its own officials for exactly this purpose.[27]
  • Watch for links in unsolicited SMS messages, even ones that appear to come from your bank, and verify directly with the bank rather than clicking through.[24]
  • If someone offers payment in exchange for using your bank account to receive or transfer funds, decline. That’s mule-account recruitment.[17]
03

If You Suspect Fraud, Report It Fast

India’s national cybercrime helpline, 1930, is a 24/7 toll-free number operated by I4C under the Ministry of Home Affairs, specifically for reporting financial cyber fraud[31]. It replaced an earlier number, 155260, in 2021, and connects to the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), which links police, banks, payment gateways, and wallets to freeze suspect accounts[31].

Speed matters here. Responders call the window right after a fraud occurs the “golden hour”: early reporting can trigger a temporary lien or freeze on a fraudster’s beneficiary account within minutes, before funds move across multiple mule accounts[32]. Officials describe the difference as recovering funds quickly versus a multi-year recovery process through the courts[32]. Mumbai’s 1930 cyber helpline blocked or recovered nearly ₹202 crore for fraud victims in 2025 through this mechanism, according to Mumbai police data reported by The420.in[33]. Nationally, I4C reported saving more than ₹11,158 crore across over 32.80 lakh cyber financial fraud complaints as of 30 June 2026[34].

Separately, data presented to Parliament put total Indian losses to cyber fraud, across all types, not limited to banking, at approximately ₹22,845 crore in 2024, with cybercrime complaint volumes reaching 22.68 lakh, a 42.08% rise over the prior year[35].

04

How Much Bank Fraud Actually Costs India

Per RBI’s Annual Report for FY2024-25, the total value of frauds reported by banks rose 194%, from ₹12,230 crore in FY2023-24 to ₹36,014 crore in FY2024-25, even as the number of reported fraud cases fell from 36,060 to 23,953 over the same period[6]. Fewer incidents, far more money lost per incident[6].

Public sector banks bore most of that increase: ₹25,667 crore in fraud value, up from ₹9,254 crore the prior year, across 6,935 cases, compared with 14,233 cases at private banks that were generally lower in value individually[7].

Credit and loan-related fraud was the largest category by value, surging more than 229% to ₹33,148 crore[8]. RBI attributed a significant part of that spike to the reclassification of 122 legacy, high-value loan fraud cases worth ₹18,674 crore, following a Supreme Court directive[8]. By contrast, card and internet-related fraud declined in value, from ₹1,457 crore to ₹520 crore year-on-year, even though digital-fraud cases (13,516) still accounted for 56.5% of all reported banking fraud cases that year[9]. Most reported fraud cases involve digital channels, but the rupee value is concentrated in large legacy loan fraud instead[8][9].

05

What Banks and NBFCs Are Required to Do

The RBI regulates fraud classification and reporting for Indian banks under its Master Directions on Fraud Risk Management, revised 15 July 2024, covering commercial banks, Regional Rural Banks, and All India Financial Institutions[2]. These directions classify frauds into standardised categories, including misappropriation of funds, criminal breach of trust, and fraudulent encashment, so reporting is consistent across institutions[2].

Classification isn’t unilateral anymore. Following the Supreme Court’s 2023 judgment in State Bank of India v. Rajesh Agarwal, regulated entities must follow principles of natural justice, meaning they give the person or entity a chance to respond, before formally classifying an account or person as fraud[3]. RBI’s framework also requires banks to maintain an Early Warning Signals (EWS) and Red Flagging of Accounts system, and mandates a Data Analytics and Market Intelligence Unit to strengthen fraud risk management[4]. On the payments side, banks must report disputed, suspected, or attempted fraudulent transactions to the Central Payments Fraud Information Registry (CPFIR), which RBI maintains[5].

Underneath fraud reporting sits India’s separate anti-money-laundering framework. The Prevention of Money Laundering Act (PMLA), 2002, in force since 1 July 2005, requires regulated entities to carry out KYC verification and Customer Due Diligence, maintain records, and report suspicious transactions promptly to the Financial Intelligence Unit - India (FIU-IND)[20]. Money laundering itself is commonly described, including in Indian legal and UPSC-exam reference material, as happening in three stages: placement (getting illicit funds into the formal financial system), layering (moving funds through multiple transactions or accounts to obscure their origin), and integration (reintroducing the cleaned funds into the legitimate economy)[21]. India’s PMLA-based framework is designed to align with the recommendations of the Financial Action Task Force (FATF), the international AML/CFT standard-setting body established by the G7 in 1989[22].

Mule accounts are pushing this framework further. India’s Supreme Court has directed RBI to develop a nationwide Standard Operating Procedure for banks to deal with mule accounts used in cyber fraud[19], and the Indian Banks’ Association has pushed for RBI to be given explicit statutory power to freeze mule accounts more quickly[39].

Internal fraud is a meaningful part of the picture in Indian banking as well. Research from KPMG India’s “Global Profiles of the Fraudster - India Outlook” (looking at corporate occupational fraud broadly, not banking specifically) found the typical Indian fraud perpetrator is male, aged 26-45, with more than six years’ service, most often in middle management or executive-level roles, and that formal whistleblowing channels were the top detection method, ahead of management reviews or informal tip-offs[36]. The research describes corporate fraud in India as mostly internal and low-tech, exploiting operational and procurement loopholes rather than sophisticated cyberattacks[36].

info

PMLA’s KYC and reporting obligations are well established. The IBA’s push for statutory power to freeze mule accounts faster hasn’t been legislated yet, leaving banks to work within the SOP that RBI is still developing under the Supreme Court’s direction, not a standing freeze authority of their own[19][39].

06

What the Volume-Versus-Value Gap Means for BFSI Fraud Programs

Two of the figures above point in different directions, and reading them together says more than either does alone. Card and internet fraud accounted for 56.5% of all reported banking fraud cases in FY2024-25, yet the ₹520 crore in card/internet fraud value works out to roughly 1.4% of the ₹36,014 crore banks reported in total[6][9]. Credit and loan-related fraud sits at the opposite end: a comparatively small share of cases, but about 92% of the value (₹33,148 crore of ₹36,014 crore), and RBI itself attributed a large part of that surge to the reclassification of 122 legacy loan cases rather than a wave of newly committed fraud[6][8].

That split points to two different problems sharing one budget line. Digital fraud is high in volume and comparatively low in per-case value, which is the problem the “golden hour” mechanics behind the 1930 helpline and CFCFRMS freezes are built to interrupt by catching the transaction fast, before money moves across mule accounts[31][32][33]. Loan fraud is the reverse, low in volume but concentrated in value, which points toward due diligence and classification discipline before and around the loan itself, the same territory where the Supreme Court’s natural-justice requirement in SBI v. Rajesh Agarwal and RBI’s Early Warning Signals mandate now sit[3][4]. A bank or NBFC that tracks “fraud reduction” as a single case-count number risks getting better at the high-volume, low-value problem while the concentrated-value problem, most of it legacy loan accounts working through RBI’s classification process, keeps moving through the system largely unchanged.

verified

How KYCKART Helps

KYCKART is a unified KYC and fraud intelligence platform for India’s BFSI sector, built to give institutions the identity data and Early Warning Signals needed to tell high-volume, low-value digital fraud apart from concentrated, high-value loan fraud, rather than tracking both under one case-count metric. Speak with our team to see how it maps to your fraud risk program.

Frequently Asked Questions

person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 12, 2026 · Updated August 13, 2026

KYCKART Intelligence

Catch Fraud Before It Compounds

From digital arrest scams to mule accounts to legacy loan fraud, KYCKART’s unified platform gives BFSI institutions the identity and fraud intelligence signals RBI’s EWS framework calls for, in one system.

Explore Fraud Intelligencearrow_forward