UPI Fraud via Remote Access Apps — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Critical | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

UPI Fraud via Remote Access Apps in India 2026: How Scammers Hijack Your Digital Payments

UPI users across India face a critical new threat in 2026: fraudsters using remote access apps to steal money by manipulating victims over WhatsApp and phone calls.

What Is the UPI Fraud via Remote Access Apps?

This scam involves fraudsters convincing victims to install remote access apps—tools that allow someone else to control a victim’s phone remotely. Targeting primarily elderly people and small business owners who rely on UPI for daily transactions, the scam exploits trust and a limited understanding of remote access technology.

With more than 8 billion UPI transactions every month, fraudsters see a huge opportunity to siphon off money unnoticed. As per cases reported to police and cybercrime forums, these scams have escalated, prompting advisories from CERT-In and warnings from the Reserve Bank of India (RBI) about protecting digital payments. The Indian government’s I4C (Indian Cyber Crime Coordination Centre) also continually tracks such patterns to issue alerts.

Victims are typically contacted via WhatsApp messages or phone calls where fraudsters claim to be from banks, payment apps, or government schemes. Using caller ID spoofing, these calls appear legitimate, increasing their success in gaining victims’ confidence to grant remote access.

How This Scam Works — Step by Step

  1. Initial Contact: The victim receives a WhatsApp message or call claiming to be from their bank, UPI app customer support, or government scheme officials. The caller ID may show a trusted bank or government number via spoofing.

  2. Creating Urgency: The fraudster warns about a security issue, fraudulent transaction, or KYC verification requirement, pressuring the victim to act immediately.

  3. Remote Access Request: The caller persuades the victim to download a remote access app like TeamViewer or AnyDesk, claiming it is essential to "protect" the account or “diagnose technical problems.”

  4. Granting Control: Once the remote access app is installed, and the victim shares the on-screen access code, fraudsters can control their phone remotely.

  5. Gaining Sensitive Info: Using this control, the fraudster opens the UPI app, messaging apps, and bank messages to read OTPs, check the registered phone number, and change settings.

  6. Initiating Unauthorized Transactions: They then request UPI payments or peer-to-peer transfers to their accounts or wallets, bypassing UPI PINs by intercepting OTPs and manipulating SMS permissions.

  7. Disabling Notifications: Some fraudsters also disable transaction alerts or block incoming SMS from banks to delay detection.

  8. Aftermath: The victim only realises money is gone when they check their bank balance or receive unexpected blocking calls from their bank.

Real Warning Signs to Watch For

What Happens to Victims

Victims often suffer significant financial loss because UPI transactions are near-instant and usually irreversible. Unlike credit or debit card disputes, RBI has limited scope to reverse UPI payments once authenticated through a victim’s mobile device. Moreover, fraudsters exploiting remote apps may access Aadhaar-linked services, worsening identity theft risks.

Many victims report emotional distress, reduced trust in digital payments, and complications in business cash flow, especially among small shopkeepers and daily wage earners. In some cases, SIM swap tactics coupled with remote access scams have led to complete takeover of the victim’s phone number, blocking access to mobile banking and recovery options.

What RBI and CERT-In Say

The Reserve Bank of India has repeatedly cautioned users not to share OTPs, UPI PINs, or install unverified applications on the advice of unknown callers. The RBI also provides an official grievance portal and helpline for digital payment fraud at 1800-425-3800.

CERT-In’s guidelines advise users to verify the authenticity of calls, avoid sharing sensitive details, and immediately report suspicious activities related to UPI or banking. The Indian Cyber Crime Coordination Centre (I4C) operates the national helpline 1930, where victims can report cyber fraud cases.

Both regulators emphasize never granting remote access to unknown callers and keeping apps updated to reduce vulnerabilities.

How to Protect Yourself

  1. Never install remote access apps based on a call or WhatsApp message from unknown sources.
  2. Always verify the caller’s identity by hanging up and calling your bank’s official helpline number directly.
  3. Do not share OTPs, UPI PINs, or passwords with anyone, even if they claim to be from RBI, banks, or government authorities.
  4. Regularly check your bank and UPI app notifications for any unknown transactions.
  5. Avoid responding to unsolicited calls or messages asking for Aadhaar or KYC details via WhatsApp.
  6. Disconnect your phone from the internet immediately if you notice screen sharing or remote control without your consent.
  7. Enable two-factor authentication on your UPI apps and keep your phone’s OS and apps updated.

What to Do If You've Been Targeted

Frequently Asked Questions

Q1: Can remote access apps be used for legitimate bank support?
Generally, Indian banks and UPI apps do not ask customers to install remote control apps for support. Any such request should be treated as suspicious and verified independently.

Q2: What if I accidentally shared remote access to a scammer?
Disconnect your phone from the Internet immediately, change all banking and UPI PINs, contact your bank to block payments, and report the incident to cybercrime.gov.in and the 1930 helpline.

Q3: How does caller ID spoofing make these scams effective?
Spoofing falsifies the displayed number on your phone, making calls appear to come from trusted banks or government agencies, increasing victim trust and lower suspicion.

Check any suspicious messages or calls at BharatSecure.app, and report fraud through the 1930 helpline to help protect yourself and others.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.