Skip to content
JoshWellहिन्दी में पढ़ें

UPI, OTP and SIM-Swap Scams: How They Work, and the 10-Minute Phone Lockdown

By Sameer Khan, Digital safety & privacy writerUpdated: 7 September 20268 min read
In a hurry? Quick summary
  • Almost every scam ends the same way — you tap "accept," read out an OTP, or install a screen-share app yourself; banks call this "authorised," so speed and the right helpline matter more than the fine print
  • A UPI "collect request" is a payment demand, not money arriving — approving one with your PIN sends money out, it never brings money in
  • "Digital arrest," fake CBI/police video calls and KYC-update SMS are the fastest-growing patterns in 2026 — no Indian agency arrests anyone over a video call, ever
  • Call 1930 and report at cybercrime.gov.in within the first hour — banks can freeze money mid-transfer, but only in the first few minutes, not the next day
  • A 10-minute lockdown — UPI/app locks, SIM PIN, authenticator 2FA, and removing screen-share apps — blocks almost every pattern below before it starts
See Kaspersky mobile security plans

Every few weeks, someone in your circle has a story: a "refund" that turned into money leaving their account, a call from "the bank" that ended with their SIM going dead, or a video call from someone in a police uniform who kept them on the line for hours. These aren't random unlucky events — they're a small number of well-tested scripts, run at industrial scale, that work because they're built around one thing: getting you to do the fraud to yourself.

This guide covers how the current scam playbook actually works, what to do in the first 30 minutes if it happens to you, and a 10-minute checklist that closes off most of these attacks before they start.

The playbook: how these scams actually work right now

The fake "refund" or UPI collect request. You get a call about a wrong payment, a cashback, or a refund, and you're asked to "accept" a request on your UPI app to receive the money. Here's the trick: a collect request is a payment demand, not an incoming payment. Approving it with your UPI PIN sends money out of your account. No one can put money into your account without your PIN — receiving money never requires you to enter one.

Screen-share apps. A caller — posing as bank support, a delivery agent, or tech support — talks you into installing AnyDesk, TeamViewer, or "QuickSupport" and sharing your screen "to help fix the issue." Once connected, they can see everything on your screen, including OTPs as they arrive, and can often control your phone directly.

OTP-by-call (vishing). No genuine bank, UPI app, or government office ever calls to ask you to read out an OTP. The call itself — regardless of how official it sounds, how much of your real information the caller knows, or what caller ID shows — is the scam.

"Digital arrest" and fake police. A caller claims your Aadhaar, a courier, or a phone number linked to you is tied to a crime — drugs, money laundering, a missing passport — and puts you on a video call with someone in a "police" uniform, sometimes with a fake FIR or court order on screen. You're told to stay on camera and transfer money to a "verification" or "RBI safe" account to avoid arrest. This has no basis in Indian law. No agency arrests anyone by video call, and none will ever ask you to transfer money to "prove your innocence."

Fake KYC-update SMS. A text claims your bank account, PAN, or SIM will be blocked unless you "update KYC" via a link. The link leads to a fake bank login page that harvests your credentials, or to an APK that installs a screen-reading app.

SIM-swap via a fake ID at a telecom store. A scammer who already has your basic details (leaked in a data breach, or gathered via phishing) walks into a telecom outlet with forged ID, reports your SIM "lost," and gets a replacement issued in your number. The moment it activates, your real SIM dies, and every OTP now lands in the fraudster's hands — including the ones that reset your net-banking password.

Job and "task" scams. A WhatsApp or Telegram message offers ₹2,000–₹5,000 a day for simple tasks — liking videos, rating apps. Small payouts arrive genuinely, to build trust. You're then moved into "combo tasks" that require you to prepay from your own money for a promised bigger return, which never comes. Some versions escalate into threats and fake legal notices demanding more money to "close the case."

Loan-app extortion. An unregistered instant-loan app disburses a small amount, then demands repayment at a steep markup within days. When you're late — or even on time — the app's recovery agents harass your phone contacts with morphed photos and threats. This is illegal regardless of what the loan agreement says; RBI-regulated lenders cannot access your contacts, gallery, or location at all.

Red flags, all in one place

  • Any call, SMS, or app asking you to read out an OTP — full stop, always a scam
  • A "refund" or "cashback" that requires you to approve a UPI request rather than simply arriving
  • Pressure to install a screen-share app to "fix" something
  • Any mention of arrest, FIR, customs, or "verification transfer" on a call or video call
  • Links in SMS about KYC, electricity disconnection, or account blocking
  • Your phone suddenly shows "No service" with no explanation
  • A "job" that asks you to pay money first for bigger returns later

What to do in the first 30 minutes if it happens to you

Speed matters more than almost anything else here — money moved through UPI or IMPS can often still be frozen in the receiving account within the first few minutes, but rarely once it's withdrawn.

  1. Call your bank's fraud helpline immediately (printed on your card, or in the bank app) and ask them to freeze the transaction and block your UPI ID/VPA.
  2. Call 1930, the national cyber fraud helpline. It logs your complaint directly into the system banks use to freeze funds, and works around the clock.
  3. File a detailed complaint at cybercrime.gov.in with the transaction ID (UTR number), amount, date, and screenshots — do this even after calling 1930, since it creates the formal record.
  4. On RBI's liability rule (worth understanding honestly): zero liability applies to transactions you did not authorise, reported within 3 working days of the bank's alert. If a scammer talked you into entering your own PIN or reading out an OTP, banks typically treat that as "authorised" — the zero-liability clause may not apply on that technicality alone, even though you were deceived. Reporting within 7 working days still usually caps your liability at a few thousand rupees rather than the full loss, so report anyway, and report fast.
  5. If a SIM swap or unauthorised loan app is involved, additionally report the number via the Chakshu section of the Sanchar Saathi portal (sancharsaathi.gov.in), and change your net-banking password from a device you trust.

The 10-minute phone lockdown

Do this once, today. Most of it takes under a minute per step.

Lock your UPI and payment apps. Turn on the app-lock (fingerprint/face) inside GPay, PhonePe, Paytm, and your bank app, separate from your phone's own lock screen — so a stolen or borrowed phone can't move money even if it's unlocked.

Set a SIM PIN, and check for a SIM-swap alert. Add a PIN to your physical SIM (under phone security settings) so a stolen SIM can't be used in another phone. Save your telecom operator's fraud helpline number in your contacts under a name you'll actually remember to call if your phone suddenly shows "No service."

Check for call/SMS forwarding you didn't set up. Dial *#21# on your phone to see if call/SMS forwarding is silently switched on — a common way OTPs get redirected. Turn it off from settings if you didn't enable it.

Remove screen-share and remote-access apps you're not actively using. Uninstall AnyDesk, TeamViewer, QuickSupport, or similar apps unless you specifically need them right now for a person you trust — and never install one because a caller asked you to.

Audit app permissions. Go through Settings → Apps → Permissions and revoke SMS, Accessibility, and "display over other apps" access for anything that doesn't clearly need it. Accessibility access, in particular, is how malicious apps read OTPs and screens silently.

Check your Google/Apple account security page. Review devices logged in, remove ones you don't recognise, and confirm your recovery phone/email are current — this is the master key to most of your other accounts.

Use unique passwords, not repeats, via a password manager. Reusing one password everywhere means one leaked site compromises everything. A password manager like Dashlane generates and stores a different strong password for every account, so a single breach stays contained.

Turn on 2FA with an authenticator app, not SMS. SMS-based OTPs can be intercepted via SIM swap; an authenticator app (Google Authenticator, Microsoft Authenticator) generates codes on-device that a SIM swap can't touch. Switch this on for email and banking first.

Public Wi-Fi and VPN, honestly. Public Wi-Fi mainly puts you at risk on unencrypted traffic (rare today, since most apps use HTTPS) and on networks with malicious operators. A VPN hides your traffic from that specific network and can be worth it if you're often on airport, cafe or hotel Wi-Fi — but it does nothing against OTP scams, screen-share tricks, or SIM swap, so don't treat it as scam protection.

Turn on Truecaller/DND and use Chakshu. Truecaller flags known scam numbers before you pick up. Registering for DND (via your telecom app or 1909) cuts unsolicited commercial calls. And Sanchar Saathi's Chakshu portal lets you report any suspicious call, SMS, or WhatsApp message directly to the Department of Telecommunications, which has already led to lakhs of fraudulent connections being disconnected.

The bottom line

Nearly every scam on this list needs you to do something — approve a request, read out a code, install an app, stay on a call. Learn the patterns, and that "something" stops happening. If it does happen anyway, speed beats everything: bank helpline, then 1930, then cybercrime.gov.in, all within the first half hour. And the 10-minute lockdown above — app locks, SIM PIN, authenticator 2FA, no unnecessary screen-share apps — closes off most of these scripts before anyone gets the chance to run them on you.

Frequently asked questions

If I get scammed on UPI, will I definitely get my money back?
Not automatically. RBI's zero-liability rule protects transactions you did not authorise — for example, a bank system breach. If you typed your own UPI PIN or read out an OTP because a caller talked you into it, banks usually treat that as an authorised transaction, even though you were deceived. What still helps: report within 3 working days for the best shot at zero liability, and even later reporting (within 7 working days) usually caps your liability at a few thousand rupees instead of the full amount. Reporting fast to 1930 also gives police a real chance to freeze the money in the receiving account before it's withdrawn — that matters more than the liability rule itself.
What exactly should I do in the first 30 minutes after a scam?
Call your bank's 24x7 fraud helpline (number is on the back of your card or the bank app) and ask them to block your UPI ID and freeze the transaction. Then call 1930, the national cyber fraud helpline, and file a detailed complaint at cybercrime.gov.in with the transaction ID, amount, and screenshots. If a SIM swap or unauthorised loan app is involved, also report the number on the Sanchar Saathi portal's Chakshu section. Do all of this before doing anything else — speed decides whether the money can be frozen.
What is 'digital arrest' and is it real?
No Indian law allows anyone to be arrested over a phone or video call. "Digital arrest" is a scam script: a caller claiming to be from the CBI, police, customs or RBI says a parcel or your Aadhaar is linked to a crime, then keeps you on a video call — sometimes for hours — while you "cooperate" by transferring money to a "safe government account" to avoid arrest. Real police never do this, never demand money over a call, and never ask you to stay on video under threat. Hang up, and verify by calling the agency's official number yourself if you're unsure.
How do I know if my SIM has been swapped without my consent?
The classic sign is your phone suddenly showing "No service" or "Emergency calls only" for no reason — no missed payment, no travel, nothing you did. If that happens, call your telecom operator's customer care from another phone immediately and ask if a SIM swap or replacement was processed on your number. Also check your bank and UPI apps for any transactions in that window, and change your net-banking password from a device you trust.
Do mobile security apps actually stop these scams?
Partly. A security app can block malicious links, flag apps trying to read your SMS or screen, and warn you before installing something shady — genuinely useful layers. What it cannot do is stop you from reading an OTP out loud to a caller, approving a UPI collect request yourself, or believing a fake police officer on a video call. Treat it as one layer among several, not a substitute for the habits in this guide.
Medical disclaimer: This article is for information only and is not medical advice. Always consult a qualified doctor about your health, especially before starting any supplement or treatment.

More in this topic