UPI Fraud via Remote Access Apps — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: Critical | View Full Scam Details
🛡️ Want to check if you've received this scam?
Check This Scam on BharatSecure →UPI Fraud via Remote Access Apps in India 2026: How Scammers Hijack Your Digital Payments
UPI users across India face a critical new threat in 2026: fraudsters using remote access apps to steal money by manipulating victims over WhatsApp and phone calls.
What Is the UPI Fraud via Remote Access Apps?
This scam involves fraudsters convincing victims to install remote access apps—tools that allow someone else to control a victim’s phone remotely. Targeting primarily elderly people and small business owners who rely on UPI for daily transactions, the scam exploits trust and a limited understanding of remote access technology.
With more than 8 billion UPI transactions every month, fraudsters see a huge opportunity to siphon off money unnoticed. As per cases reported to police and cybercrime forums, these scams have escalated, prompting advisories from CERT-In and warnings from the Reserve Bank of India (RBI) about protecting digital payments. The Indian government’s I4C (Indian Cyber Crime Coordination Centre) also continually tracks such patterns to issue alerts.
Victims are typically contacted via WhatsApp messages or phone calls where fraudsters claim to be from banks, payment apps, or government schemes. Using caller ID spoofing, these calls appear legitimate, increasing their success in gaining victims’ confidence to grant remote access.
How This Scam Works — Step by Step
Initial Contact: The victim receives a WhatsApp message or call claiming to be from their bank, UPI app customer support, or government scheme officials. The caller ID may show a trusted bank or government number via spoofing.
Creating Urgency: The fraudster warns about a security issue, fraudulent transaction, or KYC verification requirement, pressuring the victim to act immediately.
Remote Access Request: The caller persuades the victim to download a remote access app like TeamViewer or AnyDesk, claiming it is essential to "protect" the account or “diagnose technical problems.”
Granting Control: Once the remote access app is installed, and the victim shares the on-screen access code, fraudsters can control their phone remotely.
Gaining Sensitive Info: Using this control, the fraudster opens the UPI app, messaging apps, and bank messages to read OTPs, check the registered phone number, and change settings.
Initiating Unauthorized Transactions: They then request UPI payments or peer-to-peer transfers to their accounts or wallets, bypassing UPI PINs by intercepting OTPs and manipulating SMS permissions.
Disabling Notifications: Some fraudsters also disable transaction alerts or block incoming SMS from banks to delay detection.
Aftermath: The victim only realises money is gone when they check their bank balance or receive unexpected blocking calls from their bank.
Real Warning Signs to Watch For
- Calls or messages pressuring you to install unknown apps urgently.
- Requests to share remote access app codes or allow screen sharing.
- Callers claiming to be bank or government officials but refusing to provide verifiable employee ID or callback number.
- Sudden requests for UPI PIN, OTP, or access to your registered mobile device.
- Spoofed caller IDs that look official but have unusual prefixes or country codes.
- Unexpected installation of apps not downloaded by you.
- Any communication asking for your Aadhaar or banking details under the guise of "verification" via WhatsApp.
What Happens to Victims
Victims often suffer significant financial loss because UPI transactions are near-instant and usually irreversible. Unlike credit or debit card disputes, RBI has limited scope to reverse UPI payments once authenticated through a victim’s mobile device. Moreover, fraudsters exploiting remote apps may access Aadhaar-linked services, worsening identity theft risks.
Many victims report emotional distress, reduced trust in digital payments, and complications in business cash flow, especially among small shopkeepers and daily wage earners. In some cases, SIM swap tactics coupled with remote access scams have led to complete takeover of the victim’s phone number, blocking access to mobile banking and recovery options.
What RBI and CERT-In Say
The Reserve Bank of India has repeatedly cautioned users not to share OTPs, UPI PINs, or install unverified applications on the advice of unknown callers. The RBI also provides an official grievance portal and helpline for digital payment fraud at 1800-425-3800.
CERT-In’s guidelines advise users to verify the authenticity of calls, avoid sharing sensitive details, and immediately report suspicious activities related to UPI or banking. The Indian Cyber Crime Coordination Centre (I4C) operates the national helpline 1930, where victims can report cyber fraud cases.
Both regulators emphasize never granting remote access to unknown callers and keeping apps updated to reduce vulnerabilities.
How to Protect Yourself
- Never install remote access apps based on a call or WhatsApp message from unknown sources.
- Always verify the caller’s identity by hanging up and calling your bank’s official helpline number directly.
- Do not share OTPs, UPI PINs, or passwords with anyone, even if they claim to be from RBI, banks, or government authorities.
- Regularly check your bank and UPI app notifications for any unknown transactions.
- Avoid responding to unsolicited calls or messages asking for Aadhaar or KYC details via WhatsApp.
- Disconnect your phone from the internet immediately if you notice screen sharing or remote control without your consent.
- Enable two-factor authentication on your UPI apps and keep your phone’s OS and apps updated.
What to Do If You've Been Targeted
- Immediately contact your bank’s customer support and request to block or freeze your UPI transactions.
- Change your UPI PIN and account passwords using your own device, not through any call instructions.
- File a complaint on the national cybercrime portal at cybercrime.gov.in or call the 1930 cybercrime helpline for assistance.
- Report the unauthorized transaction to your bank and RBI grievance portal if applicable.
- Inform your mobile service provider to check for SIM swap or unauthorized mobile number changes.
- Consider lodging a police report providing all available evidence like call logs, messages, and app screenshots.
Frequently Asked Questions
Q1: Can remote access apps be used for legitimate bank support?
Generally, Indian banks and UPI apps do not ask customers to install remote control apps for support. Any such request should be treated as suspicious and verified independently.
Q2: What if I accidentally shared remote access to a scammer?
Disconnect your phone from the Internet immediately, change all banking and UPI PINs, contact your bank to block payments, and report the incident to cybercrime.gov.in and the 1930 helpline.
Q3: How does caller ID spoofing make these scams effective?
Spoofing falsifies the displayed number on your phone, making calls appear to come from trusted banks or government agencies, increasing victim trust and lower suspicion.
Check any suspicious messages or calls at BharatSecure.app, and report fraud through the 1930 helpline to help protect yourself and others.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Related Scams in Our Database
- Confinement and Forced Scam Labour Abroad — Severity: CRITICAL
- Thailand Transit to Cyber Trafficking Scam — Severity: CRITICAL
- Kidnapping Threat With AI-Cloned Voice — Severity: CRITICAL
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.