Cloned Amazon and Flipkart Phishing Sites

INDIA — By BharatSecure Threat Intelligence Team ·

Suspicious Risk: 9/10 Severity: Critical BharatSecure Threat Intelligence

Category: UPI, WhatsApp, Phishing

Verdict Summary

Cloned Amazon and Flipkart Phishing Sites shows strong scam indicators common in fraud targeting Indian users. Do not share OTPs, passwords, or payments — verify the source independently.

Risk score: 9/10 · Severity: Critical · Verdict: Suspicious

Scam Intelligence: Cloned Amazon and Flipkart Phishing Sites

Proprietary signals from BharatSecure's scam-tracking database.

Top affected regionsIndia, students, urban, general
Last reportedMay 30, 2026

How Cloned Amazon and Flipkart Phishing Sites Works

Overview: In this scheme, scammers create lookalike versions of Amazon and Flipkart websites to trick Indian shoppers into sharing their personal and financial details. Targeted users receive fake sale offers or urgent discount alerts, clicking on links that lead to fraudulent websites. This scam is dangerous as it enables identity theft and direct financial loss. How It Works: During periods like Diwali sales or the Great Indian Festival, fraudsters set up websites with names or appearances almost identical to Amazon/Flipkart—often with deliberate spelling errors (e.g., "flipkart.gift"). Victims receive WhatsApp forwards, emails, or social media ads promoting exclusive deals. When users click through, they are prompted to enter login, UPI, or card details. The site captures these details for misuse or unauthorized transactions. India Angle: This scam thrives in both English and regional languages. It spikes during sale festivals and targets bargain-hunters nationwide. Young adults and students, eager for the latest gadgets or fashion, are especially at risk. Phishing links are distributed through WhatsApp groups, Telegram, and mass SMS, even in tier-2 and tier-3 cities. Real Examples: A Bangalore student gets a WhatsApp forward: "Flipkart Flash Sale! 90% OFF only for today: flipkart.gift/5555". Clicking the link, she enters card and OTP, only to find money missing minutes later. In another case, a Kolkata man finds "amazzon.help" in a Facebook ad, directing him to a fake login page mimicking the real site. Red Flags: - Website URLs with spelling mistakes or strange endings (e.g., .gift, .help) - Messages urging urgent action for 'exclusive deals' - Requests for login credentials, OTP or payment details upfront - Page redirects after entering information Protective Measures: - Always check the URL—type the website address [ADDRESS_REDACTED] - Ignore urgent sales offers from unknown senders - Enable two-factor authentication on ecommerce accounts - Do not enter OTP, UPI PIN, or card details unless on the official site If Victimised: - Immediately change passwords associated with the account - Contact your bank/UPI provider to block card or freeze account - Report at 1930, cybercrime.gov.in, and inform the marketplace Related Scams: - UPI payment page phishing via SMS links - Fake delivery notification SMS with malicious URLs - Bogus customer care sites soliciting refunds or technical support

How This Scam Works — Detailed Explanation

Scammers have become adept at targeting Indian shoppers by setting up cloned websites of popular e-commerce platforms like Amazon and Flipkart. During high-traffic sales events, such as Diwali sales or the Great Indian Festival, these fraudsters blanket social media and messaging apps such as WhatsApp with tempting offers. Users are drawn in by flashy advertisements promising the latest electronics or fashion at unbelievable prices. Once a user clicks on these ads, they are redirected to a website that resembles the legitimate platforms almost perfectly, prompting them to enter their personal and financial details under the guise of completing a purchase.

To make the scam even more alluring, these websites often employ psychological tricks such as displaying 'limited time offers' or showing countdown timers, creating a false sense of urgency. Savvy scammers will sometimes even throw in a bonus, like an additional discount for users who log in or register through the phishing site. By manipulating human emotions such as greed and fear of missing out, they successfully convince victims to part with sensitive information that can lead to identity theft and financial losses. This design minimizes user skepticism, as most web traffic is directed through URLs that closely mimic the originals, with only slight spelling or formatting differences.

Once unsuspecting victims land on these cloned sites, the danger escalates rapidly. Users are prompted to share sensitive information such as their UPI PIN, Aadhaar numbers, or banking credentials. For example, if a user believes they are about to secure a fantastic deal on a smartphone for ₹9,999, they might enter their banking details and OTP, convinced of the site's legitimacy. Instead, within moments, their information is intercepted by these cybercriminals, leading to unauthorized transactions. Reports indicate that victims have lost sums ranging from ₹10,000 to over ₹1 crore, with many cases going unreported due to embarrassment or lack of awareness.

The impact of this scam is significant in India, where the digital payment landscape is rapidly evolving. According to the Ministry of Home Affairs (MHA), instances of cyber fraud have exploded, with reported losses exceeding ₹2,000 crore in just the past fiscal year alone. The RBI and CERT-In continue to issue advisories warning the public to be wary of such schemes, especially around festive seasons when spending spikes. These organizations have identified cloned Amazon and Flipkart phishing sites as critical threats, leading to ongoing campaigns encouraging users to report any suspicious activities or websites immediately.

To differentiate between legitimate communications and these cloned websites, users must keep an eye out for red flags. Confirm the URL of the site; legitimate e-commerce platforms use secure protocols (https://). Beware of misspelled URLs or unfamiliar domains, particularly those that adjust their familiar naming patterns. Any communication requesting sensitive information such as OTPs, UPI PINs, or banking credentials should raise alarms. Therefore, awareness and education are pivotal for mitigating this scam and preventing future victims from falling prey to it.

Visual Intelligence:

BharatSecure's AI has identified this as a used in scams targeting Indian users.

Who Does Cloned Amazon and Flipkart Phishing Sites Target?

General public across India

Red Flags — How to Identify Cloned Amazon and Flipkart Phishing Sites

  • Strange or misspelled URLs in offer messages
  • Urgent claims of limited-period discounts
  • Requests for OTP, UPI PIN or banking credentials
  • Website design nearly matching but minor differences from real site

What To Do If You Encounter Cloned Amazon and Flipkart Phishing Sites

  1. Report any suspicious transactions to your bank immediately using helplines like SBI 1800-11-1109 or HDFC 1800-202-6161.
  2. Contact the cybercrime helpline at 1930 or visit cybercrime.gov.in to file a formal complaint.
  3. Keep monitoring your bank and e-wallet statements for any unauthorized transactions.
  4. Change your online banking passwords immediately to safeguard your accounts.
  5. Educate your friends and family about this scam to spread awareness.
  6. If you shared sensitive details, consider freezing your Aadhaar or UPI services temporarily.

How to Report Cloned Amazon and Flipkart Phishing Sites in India

  • Call 1930 — National Cyber Crime Helpline (24x7)
  • File a complaint at cybercrime.gov.in
  • Contact your bank immediately if money was lost
  • Call RBI helpline: 14440 for banking fraud

Frequently Asked Questions

What to do if I shared my OTP in a UPI scam?
Immediately contact your bank's customer service to report the incident, using helplines such as SBI 1800-11-1109 or HDFC 1800-202-6161. Follow up with your bank for any further actions required.
How can I identify cloned Amazon and Flipkart phishing sites?
Look for misspelled URLs or strange domain names resembling legitimate websites. Genuine sites will always use secure 'https' in their URLs and not ask for sensitive information like OTPs.
How do I report this type of scam in India?
You can report such scams to the cybercrime helpline 1930 or file a complaint at cybercrime.gov.in. Additionally, inform your bank about the fraud.
How can I recover my money after falling victim to this scam?
Contact your bank immediately to request a reversal of unauthorized transactions. Keep copies of all communications for reference. Also, ensure your account details are secure going forward.
🛡️

How This Scam Works — BharatSecure AI

Spreading fast

A plain-language breakdown based on 100 real reported scams of this type.

How they reach you Observed primary contact occurs via unsolicited phone calls, WhatsApp/SMS messages, and social media/dating platforms, where fraudsters impersonate bank officials, customer support, government agents,
How they gain your trust Trust is reportedly established through impersonation of authority (banks, RBI, PM-Kisan, army officers) or emotional bonding (love-bombing, family/friend impersonation), often reinforced by AI deepfa
How they take your money UPI is the dominant rail across all records, primarily via disguised 'collect/request money' notifications tricking victims into entering their PIN, d
Who they target Documented targets span the general population but concentrate on the elderly and digitally inexperienced (often via caregiver dependency), urban professionals, students, homemakers, small business ow
How they manipulate you
  • authority bias (impersonating banks/government/officials)
  • urgency and scarcity (account frozen, limited-time offer, emergency)
  • trust/reciprocity exploitation (familiar voices, love-bombing, small initial payouts)
Warning signs
  • Receiving a UPI 'collect/request money' notification and being asked to enter your PIN to 'receive' funds (PIN is never needed to receive money)
  • Unsolicited calls/messages claiming account freeze, KYC expiry, or suspicious transaction, pressuring you to share OTP, UPI PIN, or click a link
  • Requests to install remote-access/screen-sharing apps (AnyDesk, TeamViewer) for 'support' or 'refund' assistance
  • Mismatched or misleading recipient names/VPAs (e.g., 'Verified Merchant', 'Bank Refund Dept') or slightly altered UPI IDs
  • Pressure via emotional urgency, deepfake voice/video of familiar people, forged payment screenshots, or too-good-to-be-true offers (free recharge, prizes, grants, loans, high-return investments)

Related Scams in India

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.