Fake Banking App & Remote Control Scam — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Critical | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

Fake Banking App & Remote Control Scam in India 2026: How to Spot and Stop It

A dangerous new wave of fake banking apps and remote control scams is targeting Indian users through WhatsApp and phone calls, causing severe financial losses.

What Is the Fake Banking App & Remote Control Scam?

This scam involves fraudsters impersonating bank officials or digital wallet agents to trick users into downloading fake banking apps or granting remote access to their smartphones. It mainly targets everyday smartphone users who may not be fully aware of cybersecurity risks, particularly older adults and digitally inexperienced individuals in India. With the rise of Unified Payments Interface (UPI) and digital wallets, scammers exploit the trust people place in their mobile banking tools.

According to reports received by Indian cybercrime authorities like CERT-In and I4C, cases of these scams have increased sharply in 2025 and early 2026. Victims often receive unsolicited WhatsApp messages or calls from alleged representatives of well-known banks or payment platforms such as Paytm, requesting urgent action to "secure their accounts." The RBI has also issued advisories warning users against sharing OTPs or downloading apps from untrusted sources, highlighting the growing threat posed by these scams.

How This Scam Works — Step by Step

  1. Initial Contact: The victim receives a call or WhatsApp message from someone claiming to be from their bank or digital wallet service. The caller may say the victim’s account or UPI ID is “blocked” or “under suspicious activity.”

  2. Creating Urgency: The caller pressures the victim to act quickly, threatening account suspension or loss of money if they don’t comply immediately.

  3. App Installation: The scammer directs the victim to download a fake banking app, often from a website link shared on WhatsApp or via SMS, not from the Google Play Store or official bank websites.

  4. Remote Control Setup: Alternatively, or in addition, the scammer asks the victim to install remote access software like AnyDesk or TeamViewer, convincing them it’s for “bank verification” or “customer support.”

  5. Collecting Sensitive Info: The victim is then asked to enter personal details such as Aadhaar number, UPI PIN, OTPs, or bank account details on the fake app or share them verbally.

  6. Full Remote Access: With remote control, the scammer navigates the victim’s phone, accesses UPI apps or wallets, and initiates unauthorized transactions, often bypassing two-factor authentication by intercepting OTPs.

  7. Money Transfer: The scammer transfers money instantly via UPI apps or requests the victim to approve transactions, often in small amounts to avoid immediate suspicion.

  8. Victim Realizes: Victims notice missing money only hours or days later, by which time reversing UPI transactions becomes very difficult.

Real Warning Signs to Watch For

What Happens to Victims

Victims often suffer significant financial loss, as UPI payments authorized by the scammer are difficult to reverse unless immediately reported. Many lose amounts ranging from a few thousand to lakhs of INR. Beyond financial damage, victims face emotional stress from feeling betrayed or vulnerable after sharing personal biometric or Aadhaar details. In some cases, misuse of Aadhaar-linked bank accounts and SIM swaps made possible through remote access have led to identity theft and long-term fraud complications.

The panic and urgency induced in victims, especially older adults, make it harder for them to seek help quickly, sometimes leading to delayed reporting and further exploitation.

What RBI and CERT-In Say

The Reserve Bank of India (RBI) regularly issues advisories reminding users never to share their OTPs, UPI PINs, or passwords with anyone. RBI and CERT-In have emphasized that no bank official will ask for your credentials or request you to install remote control software.

CERT-In encourages users to rely strictly on apps downloaded from official sources and to verify any suspicious calls or messages with their bank directly using known numbers. India’s Integrated Crisis Coordination Centre for Cyber Crime (I4C) recommends reporting such incidents immediately on cybercrime.gov.in and calling the 1930 cybercrime helpline.

How to Protect Yourself

  1. Never install apps from unknown links on WhatsApp or SMS — always use official Google Play Store or bank websites.
  2. Do not share OTPs, UPI PINs, Aadhaar details, or bank credentials with anyone, even if they claim to be bank officials.
  3. Be wary of urgent calls demanding immediate action; verify the caller by independently contacting your bank.
  4. Avoid installing remote access apps like AnyDesk or TeamViewer at the request of unknown callers.
  5. Regularly monitor your bank and UPI transaction history for any unauthorized payments.
  6. Set UPI transaction limits through your banking app to minimize potential loss.
  7. Register for mobile number-based fraud alerts via your bank or mobile service provider.

What to Do If You’ve Been Targeted

  1. Immediately block your bank account or UPI ID using your banking app or call your bank's official helpline.
  2. File a complaint on the national cybercrime portal at cybercrime.gov.in detailing the incident.
  3. Inform your mobile service provider to guard against SIM swap fraud.
  4. Call the 1930 cybercrime helpline for guidance and assistance.
  5. Change all related passwords and PINs for your bank accounts, wallets, and Aadhaar-linked services.
  6. Report the scam to RBI and CERT-In through their official grievance channels.
  7. Keep a record of all communications and transactions related to the scam for future reference.

Frequently Asked Questions

Is it safe to install banking apps from WhatsApp links sent by banks?
No. Banking apps should only be downloaded from official app stores like Google Play Store or the bank’s verified website. Links shared via WhatsApp or SMS can be fraudulent and lead to fake apps.

Can remote access apps really give scamsters access to my bank accounts?
Yes. Remote access apps allow scammers to control your phone and access saved credentials and apps like UPI wallets, enabling unauthorized transactions.

What should I do if I accidentally shared my UPI PIN or OTP with a caller?
Immediately notify your bank to block UPI transactions, change your PIN, and report the incident on the cybercrime portal. Quick action can help prevent further loss.

Always verify suspicious messages or calls at BharatSecure.app, and report fraud immediately by calling 1930.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.