India processes over 16 billion UPI transactions monthly. Fraud, while a small percentage by volume, represents thousands of crores in annual losses — and the attack vectors are shifting faster than most fraud management systems can track.
This analysis draws on data from vcurd's transaction monitoring network, MHA Cyber Crime Portal public disclosures, and NPCI's quarterly fraud statistics. We examined 2.3 lakh (230,000) confirmed fraud cases across FY2025–26 Q1–Q3 to identify the dominant attack patterns, geographic concentrations, and emerging techniques.
Methodology note: Data is aggregated and anonymised. "Confirmed fraud" means transactions that were disputed and resolved in the customer's favour, or transactions flagged and subsequently confirmed by the issuing bank. This analysis does not include unreported fraud.
Top Attack Vectors in FY26
The fraudster calls the victim posing as a bank, delivery company, or government official and sends a UPI collect request — framed as "receiving a refund" or "verifying an account." The victim approves the collect, not realising they are authorising a payment, not receiving one. This is the dominant fraud vector in FY26, up from 29% in FY25. The shift is driven by widespread awareness of OTP-sharing scams; fraudsters have adapted to avoid asking for OTPs directly.
The fraudster ports the victim's mobile number to a new SIM using forged documents, gaining access to all OTP-authenticated services. Account takeover cases have the highest average loss because the fraudster has full control — they can reset UPI PINs, add beneficiaries, and drain linked savings accounts before the victim notices. Time between SIM swap and first fraudulent transaction: median 47 minutes.
Funds from social engineering or account takeover are immediately transferred to a network of mule accounts — often 3–5 hops deep — before cash-out. The mule accounts are frequently held by individuals who were recruited via job scams promising ₹1,500–3,000 per "transfer." 74% of mule accounts in our dataset had registered addresses in MHA high-risk districts. Average time from victim payment to cash-out: 4.2 hours.
Physical QR codes at small merchants (parking lots, street vendors, religious sites) are replaced with fraudster-controlled QR codes. Victims scan and pay, money goes to the fraudster's account. This attack is concentrated in urban metros — Mumbai, Delhi, Bengaluru, and Hyderabad account for 61% of QR code fraud cases. Difficult to detect at transaction scoring time since the payment appears legitimate.
Victims are recruited into fake investment platforms through social media (Telegram, WhatsApp groups) and make repeated voluntary UPI payments believing they are investing. The highest average loss of any category. Fraud only becomes apparent when withdrawal is denied. These cases are hard to catch with velocity-based rules because payments are spaced days apart and amounts vary.
FY25 vs FY26: Key Metric Changes
Geographic Concentration
Fraud in India is not uniformly distributed. The MHA Cyber Crime Portal has identified a cluster of districts that disproportionately originate fraud, and this pattern has strengthened in FY26:
- Jamtara cluster (Jharkhand): Jamtara, Deoghar, Giridih, Dhanbad, Bokaro collectively account for 14% of all social engineering fraud cases — despite representing less than 1% of India's population. Infrastructure of fraud call centers, fraud script libraries, and mule account recruiters is deeply embedded in local networks here.
- Mewat cluster (Haryana/Rajasthan border): Nuh, Palwal, Alwar, and Bharatpur form a contiguous high-risk zone. Specialisation: collect request abuse and fake OTP calls. Mobile penetration is high, digital literacy is low — creating a pool of potential mule recruits.
- Urban metros (emerging): Investment scam payments are concentrated in Bengaluru, Mumbai, and Hyderabad — high-income, high-digital-literacy populations are disproportionately targeted for large-value investment fraud, not the small-ticket social engineering scams that dominate Tier-2/3 cities.
Implications for Fraud Detection Systems
These patterns have direct implications for how fraud models should be built and tuned:
Collect request flows need separate treatment
The dominant FY26 vector — collect request abuse — is technically a legitimate UPI flow that the victim deliberately approves. Standard amount-velocity rules miss these cases entirely. Detection requires: (a) flagging collect requests to new payees from accounts that have not previously received collect requests, and (b) behavioral biometrics signals (hesitation time, device orientation changes) that hint at social manipulation.
SIM-swap integration is not optional
With 22% of high-value cases driven by SIM swap, any fraud system without telco SIM-swap integration is missing its second-largest risk category. The integration is technically straightforward — it is an organizational and procurement challenge, not an engineering one.
Graph depth matters for mule detection
With median mule hop depth increasing to 3.4, first-hop mule detection is insufficient. A fraud detection system that only flags direct recipients misses 60%+ of the layering chain. Network-based scoring using tools like NetworkX — building directed graphs of VPA→VPA flows and computing centrality measures — catches second and third-hop mules that simple rules cannot.
Investment fraud requires time-window expansion
Investment scam payments are made voluntarily, over days or weeks, to the same beneficiary. Velocity rules that look at 1-hour or 24-hour windows miss these entirely. A 30-day rolling window with cumulative amount thresholds to new payees in specific transaction categories is needed.
How vcurd Addresses FY26 Patterns
Each of the dominant FY26 vectors maps to a specific vcurd capability:
- Collect request abuse → New-beneficiary rules + behavioral flags in the rule engine
- SIM-swap account takeover → SIM-swap signal (+15 pts) in the Mule Score engine
- Mule network layering → NetworkX graph analysis with in-degree/out-degree scoring
- Geographic concentration → MHA district overlay in Mule Score + Fraud Heatmap
- Investment fraud → Extended-window velocity rules (30-day) with category filters