BioCatch flags a shift to higher-value mobile and SMS payment fraud in India
Attempted fraudulent payment value rose 35% even as fraud sessions fell 12%, according to BioCatch. Mobile fraud sessions climbed 67% and text-message scams surged 146%, underscoring rising risk for retailers and payment partners as fraud moves to faster, higher-value attacks.
What happened
BioCatch says Indian digital-payment fraud is shifting toward faster, higher-value mobile and text-message scams, fuelled by money mule networks. Authorities
Key facts
- Attempted fraudulent payment value rose 35%
- Attempted fraud sessions fell 12%
- Text-message scams rose 146%
- Fraud-related phone-call duration fell 31%
- Median attempted fraudulent transfer value rose 1.7x per session
- Mobile fraud sessions rose 67%
- iOS mobile fraud rose 86%
- Android mobile fraud rose 35%
- Web-based fraud sessions fell 10%
- More than 8.5 lakh mule accounts detected across 700+ bank branches in 2025
- 26.48 lakh mule cases linked to ₹22,496 crore in cyber-fraud complaints
- ₹9,055 crore in transactions prevented through the suspect registry
Why this matters
Payment platforms and retailers should evaluate partnerships or acquisitions in mobile fraud detection and SMS-scam prevention to close escalating omnichannel security gaps.
What to watch
- Continued divergence between attempted fraud value and fraud-session volume, indicating increasing attacker precision.
- A sustained rise in mobile-originated chargebacks, especially on new devices or accounts with recent credential changes.
- Growth in SMS-link click-through complaints, SIM-swap indicators, OTP reset requests or merchant-brand impersonation reports.
- Higher authorization declines or checkout abandonment after banks introduce stricter mobile payment controls.
- Fraud concentration in high-ticket categories such as electronics, gift cards, travel, luxury, digital goods and rapid-delivery orders.
- Payment aggregators or regulators issuing new authentication, SMS sender-verification or liability requirements in India.
- Deploy behavioral and device-risk scoring across mobile web, app, SMS-link and payment-page journeys; escalate only anomalous high-value transactions.
- Audit SMS communications for spoofable sender IDs, unsafe payment links and OTP/social-engineering exposure; shift customers toward verified in-app notifications where possible.
- Tighten controls on account changes preceding payment, including new-device login, beneficiary addition, address change, wallet top-up and high-value order edits.
- Segment fraud rules by transaction value, device age, account tenure, payment rail and delivery destination rather than using blanket mobile friction.
- Prepare chargeback and customer-support playbooks for account-takeover cases, including rapid order holds, delivery interception and credential reset flows.
- Require payment partners to share fraud telemetry, false-positive rates and response SLAs; prioritize vendors with consortium-level behavioral intelligence.