Quick-commerce phishing rate hits 4x e-commerce level, Bureau says

Bureau said suspected phishing on Indian quick-commerce platforms reached 0.4% in Q2 2026, versus 0.1% for e-commerce. The report links the rise to fast fulfilment, promotions and returns, with high-risk sessions nearly doubling over five quarters.

— Source publishedFri, 11 Sept, 2026, 13:00 IST·First seen Sat, 12 Sept, 2026, 16:26 IST·Source ET BrandEquity

What happened

Bureau reports phishing on Indian quick-commerce platforms reached four times e-commerce levels, as ultra-fast fulfilment, promotions and returns create fraud

Key facts

  • Quick-commerce suspected phishing rate reached 0.4% in Q2 2026, versus 0.1% for e-commerce
  • Quick-commerce phishing rose from 0.2% in Q4 2025 to 0.4% in Q2 2026
  • Close to 82 million high-risk quick-commerce sessions were identified across five quarters
  • More than 1 in 23 quick-commerce sessions were high risk by the June quarter
  • Reported fraud totalled INR 48,021 crore in FY2025-26, up 46.4%
  • MuleHunter.AI flags about 20,000 suspected mule accounts monthly across 23 banks

Why this matters

Security, identity-verification and fraud-prevention capabilities are becoming more strategic acquisition or partnership targets for quick-commerce platforms facing escalating phishing risk.

What to watch

  • Quick-commerce phishing rate exceeds 0.5% or remains above 4x the e-commerce benchmark for another quarter.
  • Sharp increases in refund- or coupon-themed complaints, unauthorized UPI collect requests, fake customer-care contacts or delivery-agent impersonation.
  • Higher cancellation, payment-failure or support-contact rates following promotion campaigns or peak-demand events.
  • RBI, NPCI, CERT-In or consumer-affairs guidance specifically targeting marketplace, UPI or quick-commerce scam controls.
  • Competitors begin advertising verified delivery, secure refunds or in-app-only support as a consumer trust proposition.
  • Audit every customer touchpoint used for promotions, refunds, substitutions, returns and delivery support; eliminate ambiguous links and unverified WhatsApp/SMS workflows.
  • Deploy verified sender IDs, in-app support-only policies, contextual payment warnings and delivery-partner/customer OTP safeguards.
  • Build real-time phishing intelligence using complaint data, failed-payment patterns, device signals and lookalike-domain monitoring.
  • Measure fraud controls against conversion, cancellation, repeat purchase and support-contact rates to prevent security friction from eroding convenience.
  • Coordinate with banks, UPI/payment partners, telecom providers and cybercrime cells for rapid account, number and domain takedowns.

Also reported by