< Back to Blogs

The novel payment frauds in the times of Pandemic

blog-image

I recently tried transferring Rs. 1750/- to a payee account with a nationalized bank using IMPS. It is instantaneous, and my bank allows me to do IMPS transactions up to Rs. 5000/- without any formal registration. I did that, and I received the confirmation message along with the IMPS reference number. I texted the payee to let them know the money has been transferred. So, that's it.

The only hitch was that the payee did not receive the money. I asked him to wait, as his bank's messaging system was probably down and he didn't receive a confirmation message. He is not someone who uses internet banking. He had to go to the ATM the next morning to find out that the amount had not been credited.

That's when I re-examined the message that I received on the payment confirmation. I had made a mistake while typing the payee account number. I keyed in 612 instead of 162 as the last three digits, and it was credited to someone else's account.

Now, what options were available to me?

There were very few, as an IMPS transaction cannot be recalled. However, the payee bank was helpful. I spoke with the bank staff over the phone and emailed them the IMPS reference number and transaction details.

They contacted the account holder, and he confirmed that he had received the money in question. He was not sure who had transferred it, then decided to transfer the funds back to the original payee's account, and resolved the issue.

In my case, the said amount was less, and the person who received the credit was extraordinarily kind and reachable. He did the needful immediately. Otherwise, it would have been a time-consuming affair.

Why is this relevant?

While this anecdote is not a fraud per se, such techniques can be used by fraudsters for deception. The use of available technology to create deceptions makes it easier for fraudsters to dupe.

The COVID-19 pandemic created favorable conditions for digital payment fraud. Consumers moved to e-commerce in large numbers for the first time. Fraudsters quickly adapted to this situation.

COVID payment fraud was not just an opportunistic problem. It was a structural one, created by the collision of rapid digital adoption and equally rapid criminal adaptation.

Some of the examples are:

While the PM Cares fund had pmcares@sbi as the official VPA, fraudsters stole large sums of money using various handles such as pmcarefund@sbi, care@sbi, pmcare@sbi, pncare@sbi, pncares@sbi, pmcaree@sbi, pmcaress@sbi, pmcares@hdfcbank, pmcares@pnb, pmcares@icici, and so on.

At the beginning of the lockdown, masks and hand sanitizers were in short supply. Cybercriminals set up fake e-commerce sites selling sought-after items. They would look like a proper e-commerce site where you make the payment. The goods never get delivered, and when you go back to the website, you find it has been shut down.

Very recently, online delivery of liquor was being spoken about in Tamil Nadu. Suddenly, a link appeared at try-tasmac.web.app, and it turned out to be fake. In these cases, you don't even want to complain anywhere, as you are worried about getting shamed.

When the RBI announced the moratorium, fraudsters called gullible customers posing as bank representatives. They tricked borrowers into sharing bank and OTP details, and then withdrew the money from their accounts.

Malware and phishing messages were sent stating that Netflix accounts were being provided free of cost for the entire lockdown period. When people click on it, malware is installed on your computer or mobile device, and fraudsters can even live-relay your screen. Additionally, around 4,000 domains were registered over the past three months using keywords such as COVID, Corona, Virus, and Vaccines. About 1,700 domains were registered using the keyword "Zoom". Criminals used these domains for phishing attacks.

Digital payment fraud types - what you need to know

Understanding the different types of digital payment fraud helps consumers and businesses recognize threats before they result in losses. The fraud categories that emerged most prominently during the pandemic broadly fall into four groups.

Account takeover fraud targets consumers whose credentials have been compromised. Once a fraudster has access to a bank account or UPI app, they can initiate transfers before the account holder is aware that anything has happened.

Contactless payment fraud has grown alongside the adoption of tap-to-pay and QR-based payments. Contactless transactions require minimal authentication for low-value tickets. The fraudsters exploit this loophole by using stolen cards and compromised devices to execute low-value transactions before the card is blocked.

Social engineering fraud, as seen in the PM Cares VPA example, exploits consumer trust in familiar names and institutions. The fraudster does not need to break any technical security; they need the consumer to make a mistake. Fake VPAs, fake bank representatives, and fake relief funds all work on the same principle.

Fake merchant fraud, as seen on fake e-commerce sites and the TASMAC link, exploits consumers' intent to transact legitimately. The payment goes through correctly. The fraud is in where the payment goes.

Recently, a survey conducted by YouGov and ACI Worldwide among over 1,000 Indian consumers found that half were concerned about digital payments fraud.

Some of the key findings include:

  • Nearly one-third have been recent victims of card or digital payment fraud, or know someone in their immediate family or among their friends who has been defrauded.
  • Fake apps and websites rank among the top concerns, followed by compromised credentials and spyware or malware infections.
  • Card cloning is the biggest concern for credit and debit transactions.

How do you overcome all of this?

Some of the pointers that you can use are:

  • Never share your bank details, PIN, or OTP with anyone.
  • When you visit an ATM, check for skimming devices at the card slot and keep the keypad covered while entering your PIN.
  • Never go to sites that you do not know or that are unverified for your purchases.
  • When you make UPI transactions, make sure you are certain of the VPA address. For large transactions, start with a smaller value and get confirmation from your payee before proceeding.
  • Never click on any links sent via SMS or WhatsApp unless you are certain they are from a credible source.

I don't think you have a choice but to use digital payments. While the technology is secure, fraudsters can use several deceptions that you should be aware of. Digital awareness and caution would help you make the most of technology without getting defrauded.