BioCatch flags 146% surge in text-message scams targeting Indian digital payments
BioCatch says text-message scams in India rose 146% as fraud shifts towards higher-value, scam-led attacks across UPI, mobile banking and e-commerce. Attempted fraud sessions fell 12%, but attempted payment value increased 35%, underscoring the need for real-time behavioural and device monitoring.
What happened
BioCatch reports a 146% jump in India text-message scams as UPI, mobile banking and e-commerce fraud shifts toward high-value, scam-led attacks. The report
Key facts
- Text message scams surged 146%
- Attempted fraud sessions declined 12%
- Value of attempted fraudulent payments increased 35%
- Risky payment sessions doubled
- Median value per fraud session increased 1.7 times
- Average phone-call duration declined 31%
- Median session length fell 32%
Why this matters
Banks, payment firms and commerce platforms should evaluate partnerships or acquisitions in behavioural biometrics, device intelligence and scam-detection capabilities to address increasingly sophisticated, high-value social-engineering fraud.
What to watch
- RBI, NPCI or major UPI-app mandates on fraud-risk scoring, payee verification, cooling-off periods or liability treatment for scam-induced transfers.
- Continued divergence between falling attempted-fraud session counts and rising average attempted payment value.
- Growth in complaints involving SMS sender spoofing, fake delivery or KYC alerts, remote-access apps and first-time UPI beneficiaries.
- Increases in merchant false positives, payment abandonment or declines for high-ticket mobile transactions.
- Evidence that fraud migrates from UPI toward cards, BNPL, wallet top-ups, gift cards or cash-out through mule merchants.
- Telecom action on sender-ID registration, SIM-swap controls, URL filtering and scam-message blocking.
- Deploy SMS-scam detection signals alongside behavioral biometrics, device intelligence, SIM-change indicators and beneficiary-risk scoring.
- Add contextual in-app warnings before first-time or high-value UPI transfers, explicitly flagging requests initiated through SMS, screen-sharing or remote-access apps.
- Create graduated transaction controls: temporary caps, cooling-off windows and out-of-band confirmation for anomalous high-value payments rather than blanket declines.
- Share confirmed mule accounts, scam URLs, sender IDs and device fingerprints across banks, PSPs, telecom operators and cybercrime reporting channels.
- Review fraud rules by payment value, payee age, device novelty and customer segment; optimize against authorized-push-payment loss, not only unauthorized transaction rates.
- Prepare customer-support and dispute workflows for more scam-led claims, including rapid account freezes and beneficiary recall procedures.