Beware of these 4 frauds while making payments via UPI amid lockdown
There are various frauds associated with UPI payments, none of which are issues with UPI itself but are modes of deception. Therefore, it becomes important for you to secure your money from frauds associated with UPI payments.
Fraudsters can send you unauthorised payment links via SMS.
Today, along with keeping oneself safe from the coronavirus, one has to be mindful of cybercriminals. These criminals are especially targeting users taking the digital route to conduct financial transactions
One of the channels seeing a rise in frauds is the Unified Payment Interface (UPI), a digital payment platform that facilitates cashless, real-time transactions via mobile phones
Several banks have issued advisories on their social media platforms warning customers of the same and have asked them to practice 'safe banking'.
It is important for all to note: @HDFC_Bank will never ask for your #OTP, #NetBanking/#MobileBanking password,… https://t.co/R1LdzrdlNa
— HDFC Bank News (@HDFCBankNews) 1586437128000
Beware of the fake UPI IDs that are making the rounds in the guise of Prime Minister’s Citizen Assistance & Relief… https://t.co/8iNQW1rcWe
— State Bank of India (@TheOfficialSBI) 1585574671000
Various types of frauds take place on the UPI platform. You should know that none of these are due to the issues with UPI itself but are modes of deception.
How fraudsters can trap you 1. Phishing scams Fraudsters can send you unauthorised payment links via SMS. These fake bank URLs will look almost identical to the original URL. If in a hurry you click on that link, it will direct you to the UPI payment app installed on your phone and will ask you to select any of the apps for auto-debit. Once, you give permission, the amount will get debited from the UPI app instantly.
Rajesh Mirjankar, MD & CEO, Infrasoft Technologies, a Mumbai-based fintech firm said, "Do not click on links in any SMS, especially those from unknown agencies. It could be an attempt to skim money from your account via UPI app. Also remember, the name is not everything on the Internet. For example, www.my.banker.com is not the same as www.mybanker.com. Make a note of the official website and official email ID of your banker, stockbroker, etc., directly from their representatives or official website."
Also, by clicking on the fake URL, it may infect your phone with a virus/malware designed to steal the financial information stored on the device.
Further, Pranjal Kamra, CEO, Finology, a Raipur-based Fintech firm, said, "You should never search for the customer care number on Google. If you have an issue with your transaction, register a complaint on the platform itself or get the number from the official website. With random Google searches you might end up calling a fake call centre," he said.
9 checks for cyber-safety of your money in today's digital world
1/10
For cyber criminals and fraudsters, now is a busier time than ever. As the population shifts its activities online amid a scenario of lockdowns, social distancing and work-from-home, all due to the deadly global coronavirus pandemic, scamsters have a bigger pool of prey to choose from, a bigger hunting ground.
The line between the real and virtual world is becoming finer each day and online frauds more frequent. As we continue to spend more time online, fraudsters are also coming up with newer ways to con us out of our hard-earned money. Keep these 9 things in check to be safe.
For cyber criminals and fraudsters, now is a busier time than ever. As the population shifts its activities online amid a scenario of lockdowns, social distancing and work-from-home, all due to the d..
Read More
Share one time passwords (OTP) with unknown entities or scan unverified quick response (QR) codes and you are sure to lose your money. Many fraudsters are misusing the ‘collection facility’ allowed under UPI wherein he may send a collection request and ask you to approve it to receive money. Most sites, including banking sites, allow you to change passwords with OTP authentication. So by sharing the OTP you could be allowing scamsters to take control of your online banking logins.
QR code with malicious software is yet another new threat. When you are scanning the code, a malicious code will capture details linked to your wallet, bank account, etc. and these can be misused. Exercise caution while scanning. Scan only those codes with known merchants and make sure that the merchant’s name is appearing on the screen.
Share one time passwords (OTP) with unknown entities or scan unverified quick response (QR) codes and you are sure to lose your money. Many fraudsters are misusing the ‘collection facility’ allowed u..
Read More
Fraudsters may send you a mail that is masked to show the sender as a genuine entity, this is basically phishing. You could also get several messages that seem to be from genuine sources such as your bank. Hovering your mouse on and checking the link is of little use due to the increased usage of tiny URL, a system that allows users to hide their long, expanded URLs.
Prevention is better than cure and it is best to not click on any link at all since you cannot distinguish between genuine and fake ones. If at all you have to click, make sure the site opened is secured. Look out for a small lock emblem at the extreme left side of the URL before parting with any personal information.
Fraudsters may send you a mail that is masked to show the sender as a genuine entity, this is basically phishing. You could also get several messages that seem to be from genuine sources such as your..
Read More
The best way to keep frauds at bay is by updating contact details stored with your bank. However, banks and other financial institutions tend to bombard customers with regular doses of promotional mails and SMSes. By ignoring these altogether, you may miss out on important messages too. Your safest bet is to unsubscribe from these promotional offers.
The best way to keep frauds at bay is by updating contact details stored with your bank. However, banks and other financial institutions tend to bombard customers with regular doses of promotional ma..
Read More
Many of us save our debit and credit card details on several sites and apps. However, this is best avoided. This happens when you fail to turn off the auto fill facility in your browser. Turning it off will increase inconvenience but it will make your online transactions more secure.
Many of us save our debit and credit card details on several sites and apps. However, this is best avoided. This happens when you fail to turn off the auto fill facility in your browser. Turning it o..
Read More
Since banking is now at your fingertips thanks to your smartphone, don't neglect protecting your SIM. It takes 20-30 minutes to clone a SIM. If you suddenly lose network, that is a red flag. If you leave your SIM cards unattended, fraudsters with SIM reader/writer can clone it, use it on some other phone and receive the OTPs and other SMSes sent to you by banks.
Since banking is now at your fingertips thanks to your smartphone, don't neglect protecting your SIM. It takes 20-30 minutes to clone a SIM. If you suddenly lose network, that is a red flag. If you l..
Read More
Device finger printing has increased the importance of your gadgets. Offline hacking can happen if you leave the device in someone else's hands, even leaving your phone in a repair shop. Online hacking can include direct attacks or when you download apps or pirated movies from unsecured platforms. As a rule, don’t give permission to all your data— photos, location, email, SMS, microphone, camera, etc. This can be a serious threat because banks send emails and SMSes for every transaction and any app that reads all that will know your exact transaction details.
Among apps, one segment in particular is turning out to be a big problem, namely the gaming/casino apps. They collect details and store it outside India. Some can also read data from other apps. You should also be careful while sharing sensitive information using your mobile, because these shared information get stored there. Lock devices with antivirus software. It is a treat for the hacker when there is an overflow of information and we access such unsecured sites.
Device finger printing has increased the importance of your gadgets. Offline hacking can happen if you leave the device in someone else's hands, even leaving your phone in a repair shop. Online hacki..
Read More
These cards require no PIN authentication and this can be troublesome if the card is misplaced or stolen. The threat has increased ever since RBI hiked its maximum daily usage limit from Rs 2,000 to Rs 5,000 in January. You can limit usage of this facility or block it entirely to ensure safety.
Similarly, you need to exercise caution when transacting in abroad or on foreign websites because not many countries use a second factor authentication system. Some sites also force you to save card details before making payments. Even if you have to store card details, do so only temporarily, delete the details and history as soon as you have made the payment.
These cards require no PIN authentication and this can be troublesome if the card is misplaced or stolen. The threat has increased ever since RBI hiked its maximum daily usage limit from Rs 2,000 to ..
Read More
RBI has come up with various steps to protect bank customers. One of these is the 'positive pay system', under which you can ask your bank to verify details of the cheque if the amount involved is more than Rs 50,000 and this will prevent the misuse of cheque leaves. Just inform the bank about a few details of the cheque- date, name of the payee, amount etc.- electronically. As of now, the positive pay system is voluntary but RBI has allowed banks to make it mandatory for cheques involving over Rs 5 lakh.
Similarly, most bank customers are still not using the facilities to restrict usage of their debit and credit cards. You have the option of keeping your cards inactive or keep very minimal transaction limits on them, so make the most of these features.
RBI has come up with various steps to protect bank customers. One of these is the 'positive pay system', under which you can ask your bank to verify details of the cheque if the amount involved is mo..
Read More
As a best practice, you must guard all and not just your financial data. Fraudsters can even catch hold of non-financial but highly personal information and figure out a way to fraud you. This kind of fraud can be seen in the mushrooming of online loan portals. People can replicate your profile with publicly available/leaked info about you, create a new account and take loans.
Morphing of photos, videos etc. have been common since pre-covid times. So watch your steps on social media. Don’t give out family details on social media either. Refrain from mentioning your date of birth and avoid revealing details that can be linked to your passwords.
As a best practice, you must guard all and not just your financial data. Fraudsters can even catch hold of non-financial but highly personal information and figure out a way to fraud you. This kind o..
With work-from-home almost a mandate now, many people are downloading remote screen mirroring tools which can connect their phones or laptops through WIFI to larger displays like smart TVs.
Beware of fraudsters who pose as bank officials and scam people by gaining remote access to their mobile phone scre… https://t.co/AdgNZ4s1tQ
— State Bank of India (@TheOfficialSBI) 1588782244000
However, not all digital payments app present on the on google play or apple app store are authentic, especially the unverified ones. Once you download an unverified app, it will take information from your phone and can have full control of the device.
ADVERTISEMENT
Apart from this, fraudsters also conduct scams by posing as bank representatives who will ask you to download a third-party app for "verification purposes". Once downloaded, these apps will give them remote access to your phone.
3. Deceptive UPI handles Just because a UPI social media page (Twitter, Facebook, etc.) has the word NPCI, BHIM or names similar to any bank or government organisation in it, does not make it authentic. Many tricksters create such handles to make you reveal your account details through a fake UPI app.
Kamra's advice is that one should not post their contact information on social media while trying to connect with a UPI brand. Generally, people put screenshots of message received on UPl handle. "The brand might not be able to reach your post, but a fraudster might notice it and contact you."
4. Scams using your OTP, UPI PIN Bala Parthasarathy, Co-founder and CEO, MoneyTap, a Bengaluru-based fintech firm said, "A recent UPI fraud is hackers sending "request money" links to the customer. Once the customer clicks on the link and authorises the transaction thinking they'll receive money, the amount gets deducted from their account."
Another thing to be mindful is the OTP. When you make a transaction through your chosen UPI app, you are either required to enter the one-time password (OTP) or UPI PIN. For OTP authentication, your bank sends you an OTP through SMS on your mobile number registered with the bank. Once the OTP is verified, your transaction is processed.
Parthasarathy said, "One of the classic ways in which fraudsters try to scam people is by convincing them to share their UPI PIN and/or OTP over the phone. Once they have the details, they can authenticate UPI transactions and steal money from the customer's account."
Never share confidential details like UPI PIN, OTP, etc. with anyone on the phone. Also, banks never call you to ask these details.
What should you do in the case of digital fraud? Sujay Vasudevan, Vice President, Cyber & Intelligence Solutions (C&I), Mastercard said that along with the application of best-in-class technology to prevent fraudulent transactions, the onus of keeping one's money safe lies with both - the banking and payment entities and the individuals. "Therefore, you need to be vigilant and stay guarded against fraudsters and avoid sharing confidential details like PIN, OTP etc. to keep your money safe," said Vasudevan.
Here are some things you can do to keep your money safe from fraudsters.
Government agencies, banks and other financial institution never ask for financial information via SMS. In the case of a UPI fraud, report it to the bank or e-wallet firm and get the wallet blocked to prevent further losses. You can even report the incident to the police or the cyber-crime cell.
You should download only those apps which are authentic and verified by Google Play Store or Apple Store.
Never ignore the spam warning you get on your phone through the digital payments app. If a user has been reported earlier, a warning would show up while you are transacting with them. UPI apps like Google Pay, PhonePe, etc., alerts the user with a warning if they are receiving a request from an unknown account.