Online Shopping Refund Scam — How to Identify & Stay Safe
Severity: HIGH | View Full Scam Details
🛡️ Want to check if you've received this scam?
Check This Scam on BharatSecure →Beware the Online Shopping Refund Scam in India 2026: How Fraudsters Steal Your UPI Money via WhatsApp and OTP
Millions of Indians shopping online are being targeted by fraudsters posing as e-commerce representatives offering fake refunds — a high-risk scam using WhatsApp, UPI, and OTPs to steal your money.
What Is the Online Shopping Refund Scam?
The Online Shopping Refund Scam is a recent and increasingly common fraud in India during 2026. Fraudsters target people who shop on popular Indian e-commerce platforms like Flipkart, Amazon, and Myntra. These scammers pretend to be customer care agents offering unexpected refunds or compensations related to past purchases, creating a fake sense of urgency and goodwill.
These fraudsters often get hold of personal information such as phone numbers and sometimes order details from leaked user databases sold on the dark web. They then reach out to victims through WhatsApp messages, phone calls, or SMS. Many unsuspecting users fall for the trap, believing they are getting genuine refunds. This scam has become widespread across urban and semi-urban India, fueled by increasing smartphone penetration and UPI-led digital payments.
The Indian government and regulators like RBI and CERT-In have issued several advisories warning users against suspicious refund messages and calls. The Indian Cyber Crime Coordination Centre (I4C) has also flagged this scam as a high-severity threat due to its rising victim count and monetary losses.
How This Scam Works — Step by Step
Initial Contact Via WhatsApp or Call: Victims receive a call or WhatsApp message from a number claiming to be official customer support from Amazon or Flipkart. The scammer states that the victim is eligible for a refund or compensation for a recent order.
Sharing Fake Refund Details: The message may include a fake website link or refund details showing a large INR payout awaiting the victim’s confirmation.
Creating a Sense of Urgency: Scammers claim the refund will expire if not claimed quickly, pushing victims to act without thinking.
Request for Personal OTP/UPI PIN: To “verify” identity or “process” the refund, they ask victims to share the OTP (One-Time Password) sent to their phone or request access to their UPI apps by tricking them into entering their UPI PIN.
Remote Authorization of Unauthorized Transfers: Using these OTPs and PINs, fraudsters initiate UPI transactions to transfer money from the victim’s bank account to their accounts. Sometimes, they even convince victims to install remote access apps or share Aadhaar details to access bank details.
Victim Realizes Loss: By the time victims suspect foul play, the money — sometimes lakhs of rupees — is already siphoned off, and recovery becomes difficult.
Scam Exploits Phone Swap or SIM Swap: Some fraudsters even perform SIM swap frauds, where they transfer the victim’s phone number to a new SIM, intercepting OTPs and calls to gain full control over UPI and bank accounts.
Real Warning Signs to Watch For
- Refund or compensation offers that you never applied for or didn’t expect
- Urgent deadlines to provide OTP, UPI PIN, or Aadhaar details immediately
- Messages or calls from random or unknown numbers claiming to be customer care
- Requests to share OTPs or UPI PIN codes — legitimate customer care never asks for these
- Links with strange URLs or unofficial domains claiming to be e-commerce sites
- Pressure to install apps or allow remote access to your phone
- Notification of refunds without any corresponding order or transaction record in your account
What Happens to Victims
People who fall prey to this scam face significant financial losses, often amounting to thousands or lakhs of rupees stolen through fraudulent UPI transactions. Victims frequently experience emotional distress and anxiety, especially when fraudsters use SIM swap tactics, locking them out of their bank accounts and phones.
In many cases, the stolen money is difficult to recover because the transfers go to multiple wallet and bank accounts. Victims may also face issues if their Aadhaar data or bank details were compromised, resulting in identity misuse or repeated fraud attempts.
What RBI and CERT-In Say
The Reserve Bank of India has repeatedly warned consumers to never share OTPs or UPI PINs with anyone, even if the caller claims to be from a bank or e-commerce platform. RBI’s official helpline can be reached at 1800-180-1111 for transaction-related grievances.
CERT-In (Indian Computer Emergency Response Team) advises users to verify unsolicited refund messages by visiting official websites directly rather than clicking on links received via WhatsApp or SMS. They also recommend enabling two-factor authentication and reporting suspicious incidents to cybercrime authorities.
The Indian Cyber Crime Coordination Centre (I4C) encourages victims to use the national cybercrime portal at cybercrime.gov.in and report scams promptly for faster action.
Victims can call the national cybercrime helpline at 1930 to report cyber frauds and get guidance on immediate steps.
How to Protect Yourself
Never Share OTP or UPI PIN Over Call or WhatsApp
Always remember that genuine customer support will never ask for these sensitive details.Verify Refund Claims Independently
Log in to your official e-commerce app or website to check for any refund notifications.Do Not Click on Unsolicited Links
Avoid clicking on links sent via WhatsApp or SMS claiming to process refunds.Use Official Customer Support Channels
Contact the company through their verified phone numbers or app chat support.Keep Your Phone and UPI Apps Password-Protected
Use strong PINs and enable biometric locks where available.Regularly Monitor Bank Statements and UPI Transaction History
Report any unauthorized transaction immediately.Do Not Install Unknown Apps or Give Remote Access Requests
Fraudsters often use remote access tools to steal sensitive data.
What to Do If You've Been Targeted
Immediately Block Your UPI Payment Apps
Change PINs or temporarily disable UPI via your bank’s app or customer care.Report the Incident to Your Bank and Block the Affected Bank Account
Ask for a transaction dispute or fraud claim.File a Complaint on the National Cyber Crime Portal (cybercrime.gov.in)
Provide all details, including scam messages, caller IDs, and transaction details.Call the Cyber Crime Helpline at 1930
Get guidance from law enforcement authorities and expedite investigation.Inform Your Mobile Service Provider If You Suspect SIM Swap Fraud
Request a fresh SIM and block the old one immediately.Keep All Communication Records and Screenshots
This will help during police or bank investigations.
Frequently Asked Questions
Q: Can genuine e-commerce sites contact me via WhatsApp for refunds?
A: Legitimate companies usually inform refunds via email or app notifications, not unsolicited WhatsApp messages or calls. Always verify by logging in to your account directly.
Q: What if I accidentally shared my OTP or UPI PIN?
A: Immediately contact your bank to block transactions and report fraud. Also, inform cybercrime authorities through the 1930 helpline and the cybercrime portal.
Q: How can I verify if a refund link is real or fake?
A: Don’t click on the link directly. Instead, go to the official website or app of the e-commerce platform and check your order or payment status there to confirm.
Scammers are getting cleverer every day, but awareness is your best defense. If you receive any suspicious refund messages or calls, don’t act in haste. Verify all information at BharatSecure.app before sharing personal details or OTPs — stay safe in 2026 and beyond!
Related Scam Alerts
Related Scams in Our Database
- Fake Customer Survey With 2FA Data Capture — Severity: MEDIUM
- WhatsApp Friend Request Impersonation Scam — Severity: MEDIUM
- Social Media Fraud Using RBI 2FA Misinformation — Severity: MEDIUM
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.