SMS scams in India up 146% as mobile fraud sessions surge 67%
Synopsis
Key Takeaways
SMS-based scams targeting Indian bank customers surged 146 per cent between the second half of 2025 and the first half of 2026 compared to the same period a year earlier, while overall mobile fraud sessions climbed 67 per cent in the same window, according to a new report by fraud-intelligence firm BioCatch. The findings point to a decisive shift in how cybercriminals are attacking India's financial system — away from desktops and toward mobile devices.
Scale of the Surge
Within the mobile fraud spike, iOS devices recorded an 86 per cent rise in fraud sessions, while Android saw a 35 per cent increase, according to the BioCatch report. By contrast, web browser-based fraud sessions declined 10 per cent over the same period, underscoring how decisively the attack surface has migrated to smartphones.
Investigators detected more than 8.5 lakh mule accounts across more than 700 branches of multiple Indian banks in 2025. Cyber-fraud complaints in India reached ₹22,496 crore in 2025, alongside 26.48 lakh mule cases. A further ₹9,055 crore in attempted fraud was reportedly declined through the suspect registry.
Fraud Is Getting Faster and More Costly
The report highlights a troubling efficiency gain among fraudsters: risky payment sessions doubled, the median fraud session length fell by 32 per cent, and the median transfer value per fraud session increased 1.7 times. The total value of attempted fraud payments rose 35 per cent, while average call length dropped 31 per cent.
Tom Peacock, Director of Global Fraud Intelligence at BioCatch, said the numbers signal a structural change in criminal operations. 'The combination of higher-value fraud attempts and shorter calls and sessions tells us attackers are becoming far more efficient,' he said. 'Scams are increasingly refined, with criminals using well-rehearsed social engineering and automated techniques to persuade victims and move money before warning signs appear.'
On why SMS scams are proving particularly effective, Peacock noted: 'SMS scams are particularly effective because they exploit trusted communication channels, making fraudulent messages appear legitimate and prompting customers to act before they stop to question what they're seeing.'
Why India Is a Prime Target
India's rapid adoption of the Unified Payments Interface (UPI), mobile banking, e-commerce, and online investment platforms has created one of the world's most active digital payments ecosystems — and, according to the report, one of its most attractive targets for fraudsters. The country's large and fast-growing base of first-time digital users adds a layer of vulnerability, as many remain unfamiliar with social engineering tactics.
This comes amid a broader global trend of fraud migrating to mobile channels, but India's scale amplifies the risk. The 26.48 lakh mule cases recorded in 2025 alone suggest that organised fraud networks are operating at an industrial level within the country's banking infrastructure.
Industry and Regulatory Response
Subhashish Bose, Global Advisory Director at BioCatch, pointed to emerging collaboration as a reason for cautious optimism. 'The encouraging news is that we're seeing greater collaboration between banks, the Reserve Bank of India (RBI), the I4C, and law enforcement,' he said.
Bose added that behavioural intelligence tools are helping banks move beyond one-time authentication to continuous monitoring of user intent, enabling earlier detection of scam activity. The approach marks a shift from reactive fraud management to real-time risk assessment during live payment sessions.
With fraud sessions shortening and transfer values rising, the pressure on banks and regulators to deploy faster, smarter detection tools is only set to intensify in the months ahead.