KYCKART
KYCKART Guide · August 2026Guide

Bank Frauds in India: Warning Signs and How Institutions Detect Them

Phishing, smishing, and vishing target bank customers directly. The warning signs, what to do if fraud happens to you, and how RBI’s 2024 Master Directions require banks and NBFCs to detect, classify, and report fraud.

calendar_monthAugust 2026
schedule13 min read
library_books34 Cited Sources
personBhanujeet Choudhary, Head of Compliance

Bank fraud in India cost the banking sector ₹36,014 crore in FY2024-25, nearly triple the ₹12,230 crore reported the year before.[15] This piece covers two sides of that problem: the warning signs that help an individual bank customer recognize fraud aimed at them, such as phishing, vishing, and fake KYC-update messages,[19][20][21][22] and the regulatory system RBI has built for banks and NBFCs to detect and report fraud once it happens, including 2024’s revised Master Directions, fraud registries, and new AI-based detection tools.[1][7][10][12]

For a broader look at bank fraud types and prevention outside the India-specific regulatory detail covered here, see Bank Fraud: Warning Signs, Common Types, and How to Prevent It.

RBI’s Annual Report for FY2024-25 recorded ₹36,014 crore in bank fraud, up 194% from ₹12,230 crore in FY2023-24, even as the number of reported cases fell by about a third, from 36,060 to 23,953.[15]
01

Recognizing Bank Fraud as a Customer

RBI’s Consumer Education and Protection Department has documented the common fraud tactics aimed at bank customers in its public-awareness booklet, “BE(A)WARE,” compiled from reported incidents and RBI Ombudsman complaints.[19] Three commonly discussed tactics are phishing, smishing, and vishing.

Phishing, Smishing, and Vishing at a Glance

TacticChannelHow It Works
PhishingEmail or fake websiteA fraudulent email or cloned bank website asks the recipient to “verify” an account or “update KYC,” redirecting to a fake login page built to capture credentials.
SmishingSMSThe same tactic delivered by text message, often warning that an account will be blocked and containing a shortened or disguised link.
VishingPhone callCaller-ID spoofing impersonates a bank official or law-enforcement officer, pressuring the victim into sharing an OTP or PIN. Some scams now use AI-based voice cloning to sound like a genuine bank employee.

[20]

RBI’s BE(A)WARE booklet lists several other tactics customers should be able to recognize:[19]

  • Screen-sharing and remote-access-app scams
  • SIM swap and SIM cloning
  • QR-code scanning fraud
  • ATM card skimming
  • “Juice jacking” through public charging ports
  • Social media impersonation
  • Fake loan advertisements, OTP-based fraud, counterfeit loan apps and websites, and Ponzi or multi-level-marketing schemes

RBI has also flagged one recurring pattern specifically. Fraudulent SMS messages claim a customer’s account or SIM will be “blocked” within a short window, such as two hours, unless they click a link and “update KYC.” The message creates false urgency. RBI’s general advice in response is not to click such links, not to share an OTP, PIN, or password, and to verify any KYC-update request by contacting the bank directly through its official channels.[22]

warning

A reliable red flag: banks, RBI, and NPCI will never ask a customer for an OTP, UPI PIN, login password, or full card PIN/CVV over a call, SMS, or email. Any request for these credentials is fraudulent, regardless of how legitimate the caller or sender appears.[21]

02

The Scale of the Problem

I4C data shows India recorded around ₹19,812.96 crore lost to financial and cyber fraud in 2025, across roughly 21.8 lakh complaints.[29] The value breaks down heavily toward one category:

Fraud CategoryShare of Value Lost
Investment-scheme fraud77%
Digital arrest scams8%
Credit-card fraud7%
Sextortion4%
E-commerce fraud3%
App/malware-based scams1%

[29]

More than 30,000 “digital arrest” scam complaints were reported in 2025; the Supreme Court of India has estimated close to ₹3,000 crore in nationwide losses from this scam type for the year. A digital arrest scam typically involves fraudsters posing as officials from agencies like the CBI or Enforcement Directorate over video or voice calls, falsely claiming the victim is under investigation, and demanding payment or personal financial information under threat of arrest.[30]

UPI-specific fraud has its own numbers. Parliament data shows 6.32 lakh UPI-fraud incidents worth approximately ₹485 crore in FY2024-25.[31] A LocalCircles survey of over 32,000 respondents across 365 districts, conducted between March and June 2025, found that 20% of families using UPI had experienced fraud at least once since 2022; among those affected, half reported their UPI PIN or app settings were compromised, and 40% reported losing money after clicking a fraudulent payment link shared over SMS, WhatsApp, or social media.[32] Effective 30 June 2025, RBI, NPCI, and the Ministry of Finance mandated that UPI apps display only the bank-registered beneficiary name, not a self-set display name, before a payment is confirmed, specifically to curb payee-impersonation scams.[31]

03

If It Happens to You

Under RBI’s July 2017 circular “Customer Protection: Limited Liability of Customers in Unauthorised Electronic Banking Transactions” (DBR.No.Leg.BC.78/09.07.005/2017-18), a customer bears zero liability in two situations: when the bank contributed to the fraud through negligence or a deficiency in its own systems, or when a third party is at fault and neither the bank nor the customer is responsible, provided the customer reports the unauthorised transaction within 3 working days of the bank’s transaction notification.[23] Reporting between 4 and 7 working days caps liability at a limit set out in the circular, or the transaction amount, whichever is lower; beyond 7 working days, liability is decided under the bank’s own board-approved policy. Once a customer reports the transaction, the bank must credit the disputed amount back within 10 working days, without waiting for any insurance claim to settle, and must resolve the complaint, including any final liability determination, within 90 days.[24]

Per I4C’s Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), India’s national fraud-fund recovery rate improved from roughly 10-11% in 2024 to about 24% in 2025, and more than ₹7,130 crore has been saved across over 23.02 lakh complaints. Reporting within 6 hours of a fraud significantly increases the chance of recovery.[28] Fraud and cybercrime can be reported through I4C’s National Cyber Crime Reporting Portal (cybercrime.gov.in), launched 11 December 2023, or the associated 1930 helpline. That number began in 2020 as 155260, set up by I4C with RBI and banks, and was renumbered to 1930 in 2021 for easier recall.[27]

04

What the Law Calls This

India’s Bharatiya Nyaya Sanhita (BNS), 2023, replaced the Indian Penal Code (IPC) on 1 July 2024. The offence of cheating, previously IPC Section 420, is now covered by BNS Section 318 (general cheating, including provisions covering digital and electronic fraud) and Section 319 (cheating by personation). Punishment is graded: general cheating carries up to 3 years’ imprisonment and/or a fine; cheating involving breach of trust carries up to 5 years; and property-related cheating (dishonestly inducing delivery of property) carries up to 7 years plus a fine.[25]

The Information Technology Act, 2000, was not replaced by BNS and continues to apply to cyber-enabled bank fraud. Section 66C criminalises identity theft (the fraudulent or dishonest use of another person’s electronic signature, password, or other unique identification feature) with up to 3 years’ imprisonment and a fine. Section 66D criminalises cheating by personation using a computer resource, such as impersonating a bank or official online or via a spoofed number, also punishable with up to 3 years and a fine. A single incident, such as using a stolen Aadhaar number to open a fraudulent bank account, can attract IT Act Sections 66C and 66D together with BNS’s cheating and forgery provisions.[26]

05

How Banks and NBFCs Detect and Respond to Fraud

RBI’s 2024 Master Directions

On 15 July 2024, RBI issued three revised Master Directions on Fraud Risk Management (no specific circular/notification number was available in the sourcing for this piece), covering commercial banks and All India Financial Institutions; urban, state, and central cooperative banks; and NBFCs including housing finance companies. The revision rescinded 36 earlier circulars.[1] The Directions classify fraud into categories including breach of trust and misappropriation, use of forged instruments and fictitious accounts, being bribed to grant credit facilities, cash shortfalls, cheating and forgery, fraudulent foreign exchange transactions, and a residual “any fraud not otherwise specified” category.[2] Reporting deadlines under the Directions are tight. Regulated entities must classify and report a fraud within 21 days of detection; for frauds classified as systemic or above a materiality threshold, an initial flash report is due to RBI within 7 days.[3] Frauds of ₹1 crore or more go to the CBI (or the local Economic Offences Wing) within the same 21-day window; frauds below ₹1 crore go to local police. Any fraud above ₹1 lakh must also be reported to RBI via a Fraud Monitoring Return within 21 days of detection, with the clock starting at detection rather than at the end of an internal investigation.[4]

Fraud registries and the natural-justice requirement

RBI maintains a Central Fraud Registry, accessible to all banks, so a borrower who has defrauded one bank can be identified by other banks before extending fresh credit; frauds of ₹1 crore or above are reported into this registry within the 21-day window.[5] Before an account or a person can be classified as having committed fraud, regulated entities must give the borrower an opportunity of hearing, following the Supreme Court’s 27 March 2023 judgment in State Bank of India & Ors v. Rajesh Agarwal & Ors. The Court held that fraud classification carries serious civil consequences, including ineligibility for future credit, and therefore requires natural justice before it’s imposed.[6]

Early Warning Signals and Red-Flagged Accounts

The 2024 Master Directions require regulated entities to strengthen their Early Warning Signals (EWS) and Red Flagging of Accounts (RFA) framework and to set up a dedicated Data Analytics and Market Intelligence Unit to support fraud risk management. An account becomes red-flagged when one or more early warning signals raise suspicion of fraud.[7] The framework applies at a loan-exposure threshold of ₹50 crore or more per bank, regardless of the lending arrangement. A bank’s Risk Management Committee of the Board must approve the specific EWS indicators used and set a turnaround time, preferably no more than 30 days, for examining alerts. Red-flagged account status must be reported on RBI’s CRILC platform within 7 days.[8]

Reporting payment fraud separately

Loan fraud and payment fraud are reported through different systems. RBI operationalised the Central Payments Fraud Information Registry (CPFIR) in March 2020 for payment-fraud reporting by scheduled commercial banks and non-bank PPI issuers, and migrated CPFIR reporting to its supervisory monitoring system DAKSH effective 1 January 2023, adding maker-checker controls, online screen-based reporting, and dashboards and alerts. All RBI-authorised payment system operators and participants must report every payment fraud, including attempted incidents, regardless of value.[9] Separately, under the Prevention of Money Laundering Act, banks and other reporting entities must file a Suspicious Transaction Report with the Financial Intelligence Unit-India within 7 working days of being satisfied that a transaction is suspicious of money laundering, terrorist financing, or other financial crime, regardless of the amount involved.[14]

AI and machine learning enter fraud detection

In 2025, the Reserve Bank Innovation Hub (RBIH), RBI’s innovation arm, developed and began piloting an in-house AI/ML tool called MuleHunter.AI with two large public sector banks to identify mule accounts, studying 19 patterns of mule-account behaviour. The tool is designed to outperform traditional rule-based detection by applying machine-learning models to transaction and account data.[10] An RTI response obtained by MediaNama in late 2025 showed 23 banks had implemented MuleHunter.AI by that point, an expansion beyond the original two-bank pilot.[11] In June 2025, RBI and major public and private sector banks announced they were jointly building a Digital Payments Intelligence Platform (DPIP), a centralised, real-time intelligence-sharing network where participating institutions report fraudulent activity to a single hub that disseminates it to all connected members using AI/ML techniques. RBIH is building the prototype in collaboration with 5-10 banks.[12] Adoption across the sector as a whole is uneven. RBI’s Department of Supervision and FinTech Department surveyed 612 supervised entities, representing close to 90% of sector asset size, between January and May 2025. Only 20.8% of them (127 institutions) reported using or actively developing AI/ML systems, with smaller Urban Co-operative Banks and NBFCs lagging in adoption; 38% of the entities that do use AI said they preferred simple, rule-based models for their explainability and compatibility with legacy systems. RBI published its findings and recommendations as the “Framework for Responsible and Ethical Enablement of Artificial Intelligence” (FREE-AI) report on 13 August 2025.[13]

The FY2024-25 numbers

MetricFY2023-24FY2024-25
Total fraud value reported₹12,230 crore₹36,014 crore
Total fraud cases reported36,06023,953

[15]

RBI attributed part of the FY25 surge in value to the reclassification of 122 old cases worth ₹18,674 crore, which had earlier had their fraud classification removed and were re-examined and re-reported in FY25 to comply with the Supreme Court’s natural-justice ruling described above.[16] Private-sector banks reported the higher case count (14,233 cases, or 59.4% of the banking-sector total), predominantly small-value digital frauds, while public-sector banks accounted for a much larger share of the rupee value, ₹25,667 crore or over 71% of the total, driven by large-ticket loan fraud.[17] Of the ₹36,014 crore total, about ₹33,148 crore (roughly 92%) related to loans and advances (fund diversion, collateral overvaluation, and misrepresented financial statements), while digital-payment fraud accounted for the majority of case volume, 13,516 cases, but a comparatively small value of about ₹520 crore.[18]

Who commits fraud inside institutions

KPMG India’s “Global Profiles of the Fraudster: India Outlook” report, published July 2025 and based on 669 real-world fraud cases, looked at organisational and internal fraud broadly across sectors, a different picture from the customer-facing scams described earlier in this piece. It found the typical Indian fraudster is male, aged 26-45, with more than six years of tenure at the organisation, most often (39%) in a middle-management role. Weak internal controls were identified as the primary enabler, with fraudsters commonly exploiting control gaps and overriding existing processes. Financial services was the industry perceived to have the highest levels of fraudulent activity in India, with over 59% of financial-services respondents saying their organisation had experienced fraud in the preceding two years.[33]

Fraud is not just a breach of policy: it’s a breach of trust. To prevent it, we must understand it. Not just the act, but the actor.[34]

The report argues that effective fraud detection requires combining strengthened internal controls, employee awareness programmes, data-analytics-based continuous monitoring, and a culture of integrity, rather than relying on any single control.[34]

06

What the Data Suggests About Where Detection Effort Should Go

Read together, the FY2024-25 numbers describe two different fraud problems that show up in the same headline total. Private-sector banks carried most of the case count through small-value digital fraud, while public-sector banks carried most of the rupee value through large-ticket loan fraud, and a large part of that value increase traces back to old cases being properly reclassified under the Supreme Court’s natural-justice requirement rather than a fresh wave of new fraud.[16][17][18] The practical implication is that a single “fraud reduction” metric hides which problem is actually moving. A bank getting better at catching digital scams could still be blind to the loan-fraud exposure that drives the larger rupee figure, and vice versa. That split lines up with why RBI runs detection on two separate tracks: EWS, RFA, and the Central Fraud Registry aimed at credit and loan exposure; and CPFIR/DAKSH, MuleHunter.AI, and DPIP aimed at payment and mule-account activity.[5][7][8][9][10][11][12]

The FREE-AI survey findings suggest a gap worth watching. RBI itself is building and piloting centralized AI/ML detection tools, but only 20.8% of the 612 supervised entities surveyed report using or developing AI/ML systems of their own, and over a third of AI users still prefer simple rule-based models for explainability.[13]Read against the centralized tools RBI is rolling out, this suggests the newest detection capability is concentrated at the regulator and a small set of pilot banks rather than distributed across the sector. Closing that gap will likely require the broader base of banks and NBFCs to build out their own AI/ML detection capacity alongside RBI’s central infrastructure.

verified

How KYCKART Helps

KYCKART is a unified KYC and fraud intelligence platform for India’s BFSI sector, built to surface the same categories of signals RBI’s Early Warning Signals framework calls for, alongside the identity verification data needed to catch fraud earlier in the customer lifecycle. Speak with our team to see how it maps to your fraud risk program.

Frequently Asked Questions

This piece summarizes publicly available RBI, PMLA, BNS, and IT Act provisions for informational purposes. It is not legal, tax, or compliance advice. Banks, NBFCs, and individual customers should consult qualified counsel or their own compliance function before acting on a specific fraud classification, reporting deadline, or liability determination described here.


person

Bhanujeet Choudhary

Head of Compliance, KYCKART

Published August 19, 2026

KYCKART Intelligence

See Fraud Signals Before They Escalate

From phishing and vishing aimed at customers to the EWS, Central Fraud Registry, and CPFIR systems RBI requires internally, KYCKART’s fraud intelligence platform gives BFSI teams the identity and detection signals to act on both sides of the problem.

Explore Fraud Intelligencearrow_forward