Quishing for Session Theft (MFA/OAuth Abuse)

सत्र चोरी के लिए क्विशिंग (एमएफए/ओएथ दुरुपयोग)

INDIA — By BharatSecure Threat Intelligence Team ·

Dangerous Risk: 10/10 Severity: Critical BharatSecure Threat Intelligence

Category: Phishing, Global/Emerging

Verdict Summary

Quishing for Session Theft (MFA/OAuth Abuse) is a confirmed scam. Do not engage — block the sender and report to 1930 (National Cyber Crime Helpline) immediately.

Risk score: 10/10 · Severity: Critical · Verdict: Dangerous

Scam Intelligence: Quishing for Session Theft (MFA/OAuth Abuse)

Proprietary signals from BharatSecure's scam-tracking database.

Scans & lookups1
Last reportedApr 04, 2026
First documentedApr 04, 2026

How Quishing for Session Theft (MFA/OAuth Abuse) Works

  1. Scammers use sophisticated AiTM (Adversary-in-The-Middle) kits to facilitate session hijacking.
  2. A malicious QR code directs the victim to a proxy website controlled by the scammer.
  3. The victim enters credentials on this proxy site, which transparently relays them to the legitimate service.
  4. The legitimate service performs MFA, which the victim completes, unaware they are on a proxy.
  5. The AiTM kit intercepts the authentication session cookie/token after successful MFA, allowing the scammer to hijack the session and bypass MFA.
  6. Scammer gains full access to the victim's cloud account (e.g., Microsoft 365).

How This Scam Works — Detailed Explanation

Quishing for Session Theft (MFA/OAuth Abuse) is a dangerous form of phishing scam targeting users who believe multi-factor authentication (MFA) keeps them safe. Scammers use a combination of phishing by QR code (quishing) and advanced AI-in-the-Middle (AiTM) attack kits to capture login sessions, even when victims use MFA. In India, where mobile banking, UPI payments, WhatsApp messaging, and Aadhaar-linked services are common, such attacks can lead to loss of money and data privacy. Scammers often start by sending fake messages or emails impersonating banks, payment apps, or government systems, asking users to scan a QR code to verify their identity or update security settings.

When a victim scans the QR code using their phone, they unknowingly connect to a malicious app or website controlled by the scammer. This acts as a real-time gateway capturing authentication tokens and session cookies during the login process. The scammers exploit OAuth protocols and the trusted multi-factor steps by intercepting session data using AiTM kits. The victim sees normal prompts for MFA or re-authentication, but these are part of the trap. During or immediately after scanning, slight delays or glitches in the login process may occur, raising suspicion, but many users ignore these signs and proceed.

Once the session tokens are stolen, attackers can access cloud accounts, UPI wallets, Aadhaar services linked to digital IDs, and even WhatsApp Web sessions remotely. This kind of theft bypasses traditional security checks because the attacker effectively “becomes” the user in the system without needing the OTP again. The attackers then misuse the access to transfer money, steal personal data, or conduct fraudulent transactions. Messages urging users to scan QR codes for “security updates” or MFA reset are typical red flags ignored by unaware users, who think they are complying with official requests.

This scam is critically dangerous in India, where digital payments and Aadhaar-based services are deeply integrated into daily life. Victims may lose money from their bank accounts linked with UPI apps, have their WhatsApp accounts hijacked to defraud contacts, or have their Aadhaar details stolen to commit identity fraud. Understanding the tactics of quishing combined with MFA/OAuth abuse is essential to avoid falling victim to this advanced phishing scam.

Who Does Quishing for Session Theft (MFA/OAuth Abuse) Target?

Employees, corporate users, anyone with MFA-protected cloud accounts (e.g., Microsoft 365, Google Workspace).

Red Flags — How to Identify Quishing for Session Theft (MFA/OAuth Abuse)

  • Unusual prompts for MFA or re-authentication via a QR code.
  • Slight delays or glitches during the login process after scanning.
  • The URL in the browser bar is not the expected legitimate domain, even after a successful 'login'.
  • Any message implying a security update requiring QR code scan for MFA reset.

What To Do If You Encounter Quishing for Session Theft (MFA/OAuth Abuse)

  1. Verify the sender's identity carefully before scanning any QR code for authentication or security updates.
  2. Avoid scanning QR codes received via WhatsApp or SMS if they come with unexpected MFA or re-authentication requests.
  3. Inspect the URL in your browser after login; if it’s unusual or doesn’t match the official website, log out immediately and change passwords.
  4. Report suspicious messages to your bank’s official fraud prevention helpline and BharatSecure immediately.
  5. Regularly monitor bank and UPI transaction alerts for unauthorized activity and freeze accounts if needed.

How to Report Quishing for Session Theft (MFA/OAuth Abuse) in India

  • Call 1930 — National Cyber Crime Helpline (24x7)
  • File a complaint at cybercrime.gov.in
  • Contact your bank immediately if money was lost
  • Call RBI helpline: 14440 for banking fraud

Frequently Asked Questions

What is Quishing for Session Theft (MFA/OAuth Abuse)?
Quishing for Session Theft (MFA/OAuth Abuse) is a reported phishing scam that BharatSecure has documented as affecting Indian users. Fraudsters use it to trick victims into sharing money, OTPs, or personal and banking details. It currently carries a risk rating of 10/10 (Critical).
Is Quishing for Session Theft (MFA/OAuth Abuse) dangerous, and how common is it in India?
Yes. This scam is rated Critical severity (10/10) because it can lead to direct financial loss or identity theft. It spreads through SMS, WhatsApp, phone calls, and fake websites, and variants are reported across India throughout the year. Treat any unexpected message or call matching this pattern as suspicious until verified.
How can I protect myself from Quishing for Session Theft (MFA/OAuth Abuse)?
Verify the sender's identity carefully before scanning any QR code for authentication or security updates. Avoid scanning QR codes received via WhatsApp or SMS if they come with unexpected MFA or re-authentication requests. Inspect the URL in your browser after login; if it’s unusual or doesn’t match the official website, log out immediately and change passwords. Report suspicious messages to your bank’s official fraud prevention helpline and BharatSecure immediately. Never share OTPs, UPI PINs, card numbers, or passwords; verify any request independently using official numbers from the company's real website; and avoid clicking links in unsolicited messages.
How do I report Quishing for Session Theft (MFA/OAuth Abuse) in India?
Call 1930 (the National Cyber Crime Helpline) within 24 hours for the best chance of recovering funds, and file a complaint at cybercrime.gov.in with screenshots and transaction details. Notify your bank's fraud team to freeze transactions, and report the suspect UPI ID or phone number to BharatSecure so other users can be warned.
🛡️

How This Scam Works — BharatSecure AI

Spreading fast

A plain-language breakdown based on 500 real reported scams of this type.

How they reach you Primary reach is through digital channels including WhatsApp calls/messages, social media DMs, phishing emails/SMS, and spoofed video calls, often amplified by AI-generated deepfake audio and video im
How they gain your trust Trust is established by impersonating a known, authoritative, or emotionally significant figure—family members, bank officials, corporate executives, government officials, or celebrities—using AI voic
How they take your money Reported rails include UPI and QR-code transfers, IMPS/bank wire transfers, digital wallets, crypto transfers to mule/offshore wallets, and gift cards
Who they target Observed targets span urban professionals, small-business finance/payroll staff, job seekers, and the general public, with documented emphasis on elderly individuals and emotionally vulnerable people.
How they manipulate you
  • Authority bias (impersonating executives, police, government officials)
  • Urgency/scarcity pressure (emergencies, frozen accounts, time-limited transfers)
  • Affinity and emotional trust (cloned voices of loved ones in distress)
Warning signs
  • Unexpected urgent request for money or OTP from a 'known' voice/video contact
  • Pressure to bypass normal verification channels and act immediately
  • Requests to transfer funds via UPI/QR, crypto, or wire to unfamiliar accounts
  • Deepfake or slightly-off video/voice quality on calls claiming to be executives, officials, or family
  • Links to login/verification portals, sideloaded apps, or 'free AI tool' downloads sent unsolicited

Related Scams in India

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.