A telephone that instantly freezes after clicking a social media commercial or unfamiliar hyperlink might look like a routine technical glitch. Nevertheless, in a rising type of digital fraud, the frozen display screen can be utilized as a distraction to create panic, manipulate customers, and finally acquire entry to delicate monetary info.
Cybersecurity consultants warn that such incidents are more and more transferring past conventional phishing. Fraudsters are combining malicious functions, social engineering, remote-access instruments and Android permissions to compromise units and manipulate customers into authorising fraudulent transactions.
Based on Harish Kumar, CEO, Fast Heal Applied sciences, the frozen display screen is commonly “not the true occasion, however the distraction.” Scammers might use faux error messages, commercials or calls posing as buyer assist representatives to persuade victims that there’s a downside with their telephone, banking software or UPI account. “Victims might then be persuaded to obtain an APK disguised as a reward, cashback, verification or service software,” Kumar informed NDTV.
As soon as put in, malicious functions can abuse accessibility, notification and different permissions to watch exercise, learn OTPs, management components of the display screen and probably simulate person actions. Kumar factors to the India Cyber Menace Report 2026, ready by researchers at Seqrite Labs, which paperwork how faux service and utility functions can request SMS, name and notification entry to reap delicate info.
The sophistication of those assaults additionally implies that fraudsters don’t essentially must defeat UPI’s underlying safety mechanisms. Ruchin Kumar, Vice President – South Asia, Futurex, informed NDTV that attackers sometimes search to compromise the system, credentials, authentication factors or transaction circulate surrounding the fee moderately than “break” UPI encryption.
“This might contain intercepting SMS-based OTPs, stealing banking credentials by faux functions or phishing pages, abusing Android accessibility permissions, or utilizing screen-sharing functions to look at the sufferer in actual time. In some instances, social engineering does a lot of the work, with the sufferer unknowingly coming into their very own UPI PIN or approving a transaction,” Ruchin added.
This makes the ensuing transaction significantly tough to differentiate from a reliable fee. The sufferer might have technically authenticated the transaction, though the authentication was obtained by manipulation or system compromise.
The issue, nevertheless, will not be restricted to banking functions or cybersecurity software program. Ravindra Singh, Managing Director, Delcom Telesystems, emphasises that the system, functions and person are all a part of the safety chain. “Fraudsters are more and more exploiting belief in expertise by creating urgency round a supposed technical issue after which persuading customers to put in remote-access, screen-sharing or verification functions,” Singh informed NDTV.
How To Keep Protected
Due to this fact, the fast response after a suspicious freeze is crucial. Customers ought to disconnect cellular information and Wi-Fi, keep away from coming into banking credentials or UPI PINs, and chorus from following directions from unsolicited callers claiming to offer technical assist. Suspicious functions must be eliminated, pointless accessibility and device-administration permissions revoked, and the system scanned utilizing a trusted safety answer.
If monetary info might have been compromised, customers ought to contact their financial institution by an official channel, test current transactions, change related credentials from a clear system and report suspected financial fraud by helpline quantity 1930.
As digital funds change into more and more embedded in on a regular basis life, the safety of a transaction is determined by greater than authentication alone. Sturdy system safety, safe functions, fraud monitoring and knowledgeable person behaviour should work collectively. The only warning signal might due to this fact be a very powerful one: a real financial institution or service supplier is not going to ask a buyer to put in a remote-access software or share their display screen to resolve a routine UPI concern.