PhonePe Hack Leads to Fake Refund Calls Triggering Massive Fraud Cases

PhonePe-Hack-Leads-to-Fake-Refund-Calls-Triggering-Massive-Fraud-Cases

Digital Wallet Breaches Expose Vulnerabilities in Financial Systems

In recent weeks, two distinct cases of cyber-enabled financial crimes have come to light in Lucknow, India. These incidents demonstrate the evolving tactics employed by cybercriminals to deceive victims and exploit vulnerabilities in digital wallets and online service platforms.

“According to Professor Triveni Singh, a renowned cybercrime expert and former IPS officer,”Cybercriminals are increasingly relying on social engineering rather than traditional hacking methods. They use OTPs, links, APK files, and fake calls to psychologically manipulate users into compromising their own security.”

The first case involved a resident of Mohanlalganj, Bhupendra Kumar, whose digital wallet was compromised on March 30, 2026. Over the course of several hours, Kumar received multiple One-Time Passwords (OTPs) on his phone, prompting alerts about login attempts on his Aadhaar-linked services and account. Unbeknownst to him, a total of ₹38,900 was withdrawn from his PhonePe account via four unauthorized transactions. It is believed that the perpetrators accessed Kumar’s login credentials or intercepted the OTPs, allowing them to execute the transactions quickly.

A second case revealed an even more sophisticated tactic employed by scammers. On March 8, a resident of Sector I, Eldeco Udyan-1 in Basant Bihar, placed a food order through an online delivery app but canceled it due to a delay. The victim then searched online for the customer care number and received a call from an unknown number. The caller claimed to be a customer support executive and sent a file, assuring that opening it would process the refund. However, upon opening the file, malware was installed on the victim’s device, resulting in two unauthorized transactions totaling ₹95,999 being siphoned off from the victim’s bank account.

Experts have attributed these types of scams to the use of Remote Access Tools (RATs) or malicious APK files, which enable cybercriminals to gain control of a user’s smartphone and access sensitive information such as OTPs and banking credentials. Furthermore, investigators have observed that fraudsters often manipulate search engine results by placing fake customer care numbers online, making it easier to lure victims into their schemes.

  • Precautions to Take:

  • Exercise extreme caution when interacting with unfamiliar links or files.
  • Verify customer care numbers from official sources.
  • Never share OTPs or banking details with anyone, as this can lead to significant financial loss.



About Author

en_USEnglish