Science & Technology

Scammers Shift Tactics: Mobile Banking Fraud Sessions Jump 67% in India as Cybercriminals Pivot to Domestic Mule Networks

By GS Team
22 Jul 20263 mins read
TukuTouch Logo
India faces evolving digital banking fraud as mobile-first attacks surge 67%, despite overall session decline. BioCatch reports a 35% jump in attempted fraud value, with scams leveraging UPI's speed and real-time calls. A "mule-as-a-service" economy is growing domestically, with 850,000 mule accounts detected, as syndicates exploit local infrastructure and valid KYC accounts for high-value illicit transfers.

Summarized by AI; it may make mistakes. Check important info

Scammers Shift Tactics: Mobile Banking Fraud Sessions Jump 67% in India as Cybercriminals Pivot to Domestic Mule Networks

Digital banking fraud in India is undergoing a dramatic evolution, with cybercriminals abandoning traditional desktop setups to execute high-speed, mobile-first attacks. According to the latest 2026 Digital Banking Fraud Trends in India report by fraud-prevention leader BioCatch, mobile fraud sessions spiked by 67 % between mid-2025 and mid-2026, fueled by an 86 % surge on iOS devices and a 35 % increase on Android.

While overall attempted fraud sessions fell by 12 %, the financial threat grew drastically. The total value of attempted fraudulent payments reported by Indian banks jumped by 35 %, revealing a shift toward higher-value, more targeted attacks. The report highlights how scam syndicates are streamlining their operations, cutting median session lengths by 32 % and relying heavily on real-time phone calls to guide victims through illicit transfers.

India’s Digital Payment Boom Proves Double-Edged

The meteoric rise of the Unified Payments Interface (UPI), alongside instantaneous mobile banking, e-commerce, and online stock trading platforms, has revolutionized financial inclusion across India. However, that very speed and accessibility have turned the nation into a lucrative target for international and domestic fraud syndicates.

Because real-time payment rails process transactions in seconds, criminals use sophisticated psychological manipulation—often disguised as urgent KYC updates, utility bill warnings, or bank alerts—to trick users into clicking malicious links or authorizing transfers before doubt sets in.

The Rise of the Domestic Mule Economy

As international enforcement actions by agencies like the United Nations Office on Drugs and Crime (UNODC) disrupt scam hubs in Southeast Asian nations like Myanmar, Cambodia, and Laos, syndicates have adapted. Rather than routing funds entirely abroad, cybercriminals are increasingly building localized "mule-as-a-service" networks directly inside India to cash out illicit proceeds.

Investigators led by the Central Bureau of Investigation (CBI) detected over 8.5 lakh (850,000) money mule accounts across more than 700 bank branches in 2025 alone. Fraudsters actively recruit money mules via fake job offers, social media, and messaging apps, coaching recruits on how to bypass bank checks and rapidly disperse funds across multiple accounts before security teams can act.

Subhashish Bose, Director of Global Advisory at BioCatch, noted that international syndicates now rely on local cash-out infrastructure, including Indian payment rails and SIM cards, to convert stolen funds into cryptocurrency.

"Effectively and consistently stopping these losses requires banks to look beyond these transactions and detect mule activity much earlier in the account lifecycle," Bose said, highlighting that scammers frequently exploit real accounts with valid Know Your Customer (KYC) documentation.

Fraud Metric
2025/26 vs. 2024/25
Attempted Fraud Sessions
↓ 12%
Total Value of Fraud Attempted
↑ 35%
Text-Message (SMS) Scams
↑ 146%
Mobile Fraud Sessions
↑ 67%
└─ iOS Mobile Fraud
↑ 86%
└─ Android Mobile Fraud
↑ 35%
Web Fraud Sessions
↓ 10%