Cyber Safety & Digital Protection

Official Citizen Awareness & Scam Prevention Guide

Stay vigilant and protect your digital identity and hard-earned money. Cyber criminals continually deploy deceptive links, fake investment calls, and impersonation scams. Use this verified guide to spot fraud early and stay safe online.

Cyber Crime Prevention Handbook
New
Cyber Crime Prevention β€” Handbook: Do's and Don'ts

Simple, practical tips published especially for senior citizens, homemakers, and students to avoid scams and safeguard their bank accounts.

Cyber Crimes β€” Stay Safe Online

In today's world, we use mobile phones and the internet daily for banking, shopping, and chatting with loved ones. But along with these conveniences come serious threats called cyber crimes β€” offenses perpetrated using computers, smartphones, and online platforms.

Fraudsters prey on innocent people by stealing confidential information and money through forged lottery messages, fake jobs, or threatening calls. Remember β€” there is no easy or free money online. Any urgent demand to click a link or share credentials is a trap.

Common Cyber Crimes Include:

🚨 Online Frauds

Fake customer care numbers, false lottery wins, unverified investment schemes, and deceptive part-time job offers.

🎣 Phishing & Vishing

Fraudulent SMS or voice calls pretending to be bank managers asking for confidential OTPs, UPI PINs, passwords, or CVV.

πŸ‘€ Identity Theft

Criminals stealing your photos, Aadhaar, or personal documents to create fake profiles, take loans, or defraud your contacts.

πŸ›‘ Cyber Bullying & Extortion

Harassing messages, morphing blackmail, and fake "digital arrest" video calls intimidating students and senior citizens.

To Stay Safe:

❌

Never share your OTP, PIN, or passwords with anyone:

Official authorities, bank personnel, and telecom providers will never ask for your passwords or PIN.

❌

Do not click unknown links or download untrusted apps:

Never click on unverified SMS/WhatsApp links or install screen-sharing software (like AnyDesk/TeamViewer).

πŸ”’

Check that a website starts with https:// before entering bank or card details:

⚠️ NOTE: Remember that all https:// is not automatically safe (just like a criminal coming in a police uniform is not a real police officer!). Always verify the exact website domain name.
πŸ—£οΈ

If something looks suspicious, talk to a trusted person or report it:

If you are unsure about any message or call, show it to a trusted family member or a local support person before replying or paying.

Official Cyber Crime Support & Emergency Escalation:

National Helpline: 1930 β€’ Official Portal: cybercrime.gov.in

Govt of India Helpline
FINAL TAKEAWAY

Stay alert, stay informed, and use technology wisely.

Directory of Known Cyber Scams & Attack Details

Recent Threats First

Search and browse verified attacks in India, victim target groups, and exact prevention steps. Entries are ordered with the most recent emerging threats and latest scams first.

Viral 80s Retro AI Photo Trend & Biometric Data Harvesting Scam

Sep 2026 – Present (Viral Craze / Emerging Threat)
Target:
Social media users, youth, content creators, and general smartphone users participating in viral AI photo challenges.

Exploiting the viral social media craze where users generate 1980s retro portraits, threat actors deploy rogue third-party apps, phishing links, and deceptive websites promising free vintage makeovers. These platforms harvest high-resolution facial biometrics, extract embedded EXIF metadata (GPS coordinates, timestamps, device IDs), and seek invasive device permissions (gallery, contacts, background activity, and keystroke logging). The harvested biometric maps and likenesses are exploited for deepfake creation, synthetic identity theft, and extortion, or sold to illicit data brokers on dark web forums.

Prevention & Safety Tip

β€’ Avoid uploading personal or family photos to unverified third-party AI apps and unfamiliar web links. β€’ Strip EXIF metadata (GPS coordinates, device details) before uploading photos to any digital service. β€’ Carefully review and reject excessive device permissions (such as contacts, camera, or persistent background execution). β€’ Review the platform's data retention policies to ensure photos are deleted immediately and not used for model training. β€’ If victimized by deepfake morphing or unauthorized data use, report immediately to the National Cyber Crime Helpline at 1930 or via cybercrime.gov.in.

AI-Powered Identity Theft via Apps

Jan 2024 – Oct 2025 (rising trend)
Target:
Users of AI/photo editing apps; teenagers; influencers.

Malicious apps use uploaded selfies or IDs to clone user data, create fake profiles, or commit financial fraud using AI.

Prevention & Safety Tip

β€’ Avoid uploading personal/official documents. β€’ Read app permissions. β€’ Use verified apps only. β€’ Audit data privacy settings regularly.

Matrimony Scam via Fake Profiles (India)

Jan 2025 – Oct 2025 (ongoing)
Target:
Individuals seeking partners on dating/matrimony sites.

Fraudsters create fake or AI-generated profiles on dating and matrimonial platforms to lure people into relationships and extract money. Victims are often ghosted after payments.

Prevention & Safety Tip

β€’ Verify identity via video calls. β€’ Avoid sending money. β€’ Use trusted apps. β€’ Report suspicious profiles.

Identity Theft & Account Takeovers (ITRC Reports)

Jun 2024 – Sep 2025
Target:
Users with multiple online accounts or reused passwords.

Increasing cases of stolen credentials and impersonation leading to takeover of social media, email, or bank accounts.

Prevention & Safety Tip

β€’ Use unique strong passwords. β€’ Enable MFA everywhere. β€’ Monitor accounts & bank alerts. β€’ Avoid sharing personal info publicly.

Gucci / Balenciaga & Kering Customer Data Breach

May 2025 – Jul 2025
Target:
Luxury brand customers; high-net-worth individuals.

Data of ~7.4 million customers leaked (names, addresses, purchase data), exposing individuals to personalized phishing and scams.

Prevention & Safety Tip

β€’ Change passwords. β€’ Ignore fake brand emails. β€’ Monitor purchases & cards. β€’ Report suspicious contacts immediately.

Phishing Impersonating Big Tech Brands

Apr 2025 – Ongoing
Target:
General online users; anyone using email, cloud, or mobile services.

Cybercriminals impersonate Microsoft, Google, Apple, and others in emails/SMS to steal login details or deliver malware through fake links.

Prevention & Safety Tip

β€’ Check sender addresses carefully. β€’ Don’t click suspicious links. β€’ Enable MFA. β€’ Never enter credentials on unverified domains.

FASTag KYC Update & Deactivation Phishing Scam

2024 – Present (High Prevalence)
Target:
Vehicle owners, transport operators, and highway commuters.

Exploiting NHAI compliance mandates, scammers send SMS alerts claiming the user's FASTag has expired or is deactivated due to pending KYC. The message includes a link to a fraudulent payment gateway designed to harvest bank account or wallet login details.

Prevention & Safety Tip

β€’ Update FASTag KYC exclusively through your issuing bank's portal or the IHMCL website. β€’ Do not open shortened links (e.g., bit.ly) or third-party web addresses received via SMS. β€’ NHAI and issuing banks do not request urgent wire transfers to maintain FASTag validity. β€’ Check FASTag operational status directly on the official IHMCL portal (ihmcl.co.in).

Malicious Android APK Distribution (Wedding Card / E-Challan / Banking)

2024 – Present (Surging)
Target:
Everyday Android smartphone users, vehicle owners, and mobile banking users.

Attackers send weaponized Android APK files disguised as wedding invitation cards (.apk), pending traffic challan notices, or banking updates via WhatsApp and SMS. Once installed, the malware acquires accessibility permissions to read incoming SMS OTPs and drain bank accounts.

Prevention & Safety Tip

β€’ Never download or install `.apk` files received over WhatsApp, Telegram, or SMS. β€’ Install apps strictly from the official Google Play Store. β€’ Ensure 'Install unknown apps' is disabled in your device settings. β€’ Factory reset your device immediately if you suspect a malicious app was installed.

SIM Swap & Unauthorized eSIM Migration Fraud

2023 – Present (High Impact)
Target:
High-net-worth individuals, crypto traders, and online banking users.

Attackers gather a victim's personal information through phishing and then request a replacement SIM or eSIM profile from the telecom provider using forged identity documents. Once the original SIM is deactivated, fraudsters receive all incoming SMS OTPs and access financial accounts.

Prevention & Safety Tip

β€’ If your mobile network suddenly disconnects or shows 'No Service' unexpectedly, contact your telecom operator immediately. β€’ Never forward carrier-generated eSIM activation QR codes or numeric confirmation codes sent via SMS. β€’ Set a carrier-level PIN or security password on your mobile service account. β€’ Avoid publishing your primary banking mobile number across public social media profiles.

Credit Card Reward Points Expiry Smishing Scam

2023 – Present (Ongoing)
Target:
Credit card and debit card holders across Indian banks.

Attackers send text messages stating that reward points worth thousands of rupees will expire today unless redeemed via an attached link. The link opens a spoofed net-banking portal that harvests card details, CVV, and OTPs for unauthorized transactions.

Prevention & Safety Tip

β€’ Banks do not send web links via SMS to redeem reward points for direct cash credits. β€’ Check and redeem reward points strictly inside your official mobile banking app. β€’ Never input your card number, CVV, or OTP on external web forms. β€’ Block your card immediately through net banking if you suspect your details were entered on a phishing site.

Fake Stock Market & Pre-IPO Allotment Scam (SEBI Imposter)

2023 – Present (Surging)
Target:
Retail stock investors, corporate employees, and retirees.

Victims are added to WhatsApp/Telegram groups claiming affiliations with reputed foreign institutional investors or SEBI-registered brokerages. They are lured with insider stock tips and directed to install customized trading apps showing fabricated profits, followed by extortion when attempting withdrawals.

Prevention & Safety Tip

β€’ Verify broker and advisor credentials on the SEBI portal (sebi.gov.in) before investing. β€’ Never transfer investment funds to personal bank accounts or unknown corporate entities. β€’ Apply for IPOs strictly through your own bank's verified ASBA facility. β€’ Treat any scheme guaranteeing fixed, risk-free stock market returns as fraudulent.

AEPS Biometric Cloning & Micro-ATM Fraud

2023 – Present (High Impact)
Target:
Rural and semi-urban bank account holders, property transactors, and senior citizens.

Scammers obtain fingerprint impressions from public land registry documents or silicone molds and pair them with leaked identity credentials. They use cloned biometric impressions at micro-ATMs and Customer Service Points (CSPs) to withdraw funds without needing an OTP.

Prevention & Safety Tip

β€’ Lock your biometrics using the official UIDAI portal or the mAadhaar mobile app. β€’ Unlock your biometrics only temporarily when you need to make an authenticated transaction. β€’ Monitor bank account SMS alerts regularly for unexpected cash withdrawal notices. β€’ Immediately notify your bank to disable AePS on your account if not in use.

Part-Time Work-from-Home & Telegram Review Rating Scam

2023 – Present (High Volume)
Target:
College students, job seekers, and homemakers seeking supplementary income.

Victims receive unsolicited WhatsApp or Telegram messages offering high daily payouts for liking YouTube videos, rating hotels, or reviewing apps. After paying small initial bonuses to earn trust, fraudsters demand large prepaid deposits for 'crypto merchant tasks' and freeze the deposited money.

Prevention & Safety Tip

β€’ Legitimate companies never ask you to pay money or deposit security funds to work. β€’ Avoid joining unverified Telegram or WhatsApp groups offering high guaranteed payouts. β€’ Never share your bank account or UPI details with unknown recruiters online. β€’ Block the sender and report the incident on cybercrime.gov.in.

Fake Courier & Customs Narcotics Parcel Scam (FedEx / DHL Impersonation)

2023 – Present (High Volume)
Target:
Everyday citizens, students, and professionals awaiting packages.

Scammers send an automated IVR call claiming an international parcel containing narcotics and illegal passports was intercepted by customs in Mumbai. The call is then transferred to a fake cyber cell officer who demands payment under threat of immediate arrest.

Prevention & Safety Tip

β€’ Courier companies never call to demand money or connect you to police officers. β€’ Do not share your bank details or national identification numbers over phone calls. β€’ Check tracking directly on the courier's official website using your tracking number. β€’ Report fraudulent callers to 1930 immediately.

Digital Arrest Scam (CBI / Police / ED Impersonation)

2023 – Present (High Alert)
Target:
Senior citizens, retirees, homemakers, and corporate employees.

Fraudsters pose as law enforcement or judicial officers on WhatsApp or Skype video calls featuring staged police station backgrounds. They accuse victims of money laundering or drug trafficking, place them under a fake 'digital arrest', and coerce them into transferring funds to 'verification accounts'.

Prevention & Safety Tip

β€’ Law enforcement agencies never arrest, interrogate, or conduct trials over video calls. β€’ Never transfer money to prove innocence or verify bank accounts. β€’ Disconnect the call immediately and contact your local police station. β€’ Dial the National Cyber Crime Helpline at 1930 or report on cybercrime.gov.in.

Video Call Morphing & Private Video Blackmail Scam

2022 – Present (Ongoing)
Target:
Social media users, young adults, and working professionals.

Fraudsters initiate unsolicited WhatsApp video calls displaying inappropriate imagery or capturing the victim's face, which is then edited into compromising footage. Scammers threaten to send the clip to friends, family, and social media contacts unless money is paid immediately.

Prevention & Safety Tip

β€’ Do not accept video calls from unknown or foreign numbers on messaging apps. β€’ Turn on 'Silence unknown callers' in WhatsApp privacy settings. β€’ Never pay extortionists, as making a payment typically leads to escalated demands. β€’ File a formal complaint at your local cyber police station and on cybercrime.gov.in.

Electricity Bill Disconnection SMS Scam

2022 – Present (Ongoing)
Target:
Household bill payers, elderly citizens, and small business owners.

Scammers send alarming SMS messages stating electricity will be disconnected tonight due to an unpaid bill, urging the recipient to call an executive's mobile number. When called, the fraudster instructs the victim to pay a token amount via screen-sharing apps (like AnyDesk) to seize control of their phone.

Prevention & Safety Tip

β€’ Electricity distribution companies never send notices from personal 10-digit phone numbers. β€’ Never install screen-sharing software (AnyDesk, TeamViewer, RustDesk) on caller instructions. β€’ Pay utility bills exclusively through official DISCOM portals or authorized Bharat BillPay channels. β€’ Verify bill dues directly on your electricity provider's official website.

Illegal Instant Loan & Blackmail Apps

2022 – Present (Ongoing)
Target:
Gig workers, low-income earners, and students needing emergency funds.

Predatory lending apps offer collateral-free instant loans while demanding permission to access phone contacts, photos, and camera. When borrowers fail to pay exorbitant daily fees, agents morph private photos into obscene images and harass the victim's contacts.

Prevention & Safety Tip

β€’ Borrow exclusively from RBI-registered banks and verified NBFCs. β€’ Never grant camera, photo gallery, or contact permissions to loan apps. β€’ Check the lender's legitimacy on the RBI Sachet portal (sachet.rbi.org.in). β€’ Report extortion attempts directly to the local police cyber cell and at 1930.

UPI QR Code 'Scan to Receive Money' Reverse Phishing

2021 – Present (High Prevalence)
Target:
Online sellers, small retailers, and everyday digital payment users.

Fraudsters contact sellers on classifieds or marketplaces pretending to buy goods and send a QR code or payment request link. They trick the victim into believing that scanning the code and entering their UPI PIN is required to receive payment, which instead deducts funds.

Prevention & Safety Tip

β€’ Receiving money via UPI never requires entering a UPI PIN or scanning a QR code. β€’ A UPI PIN is used exclusively to deduct money from your account. β€’ Decline incoming collect requests on UPI applications from strangers. β€’ Report fraudulent UPI IDs to your banking app and the NPCI portal.

Fake Customer Care Numbers & Search Engine SEO Poisoning

2020 – Present (Persistent)
Target:
E-commerce shoppers, air travelers, and general internet users.

Cybercriminals create fraudulent listings and paid search engine advertisements displaying their numbers for airline helplines, banks, or courier services. When citizens search and call these numbers, the impersonator extracts card credentials or asks for remote access under the pretext of issuing a refund.

Prevention & Safety Tip

β€’ Obtain customer service numbers exclusively from the company's verified app or official website. β€’ Avoid dialing phone numbers listed in search engine ads or unverified map markers. β€’ Authentic customer support will never request your PIN, CVV, or remote screen access. β€’ Hang up immediately if a representative asks you to make a transaction to receive a refund.

Frequently Asked Questions

Call the National Cyber Crime Helpline at 1930 or visit the official portal at cybercrime.gov.in to file a complaint. Report as quickly as possible to increase the chance of recovering lost funds.

Phishing is when fraudsters send fake emails, SMS, or calls pretending to be your bank or a government agency, asking for OTP, UPI PIN, or CVV. Never share these details with anyone. Banks will never ask for your PIN or OTP.

KYC update fraud involves SMS or WhatsApp messages threatening to block your bank account or SIM card unless you complete a 'KYC update' via a malicious link. Always verify such requests directly with your bank through official channels.

Immediately call your bank's customer care to block your account and cards. Then report the incident on cybercrime.gov.in or call 1930. Change all your banking passwords and UPI PINs immediately.