Scam Lab

Practise spotting a scam before it happens to you

Short, fictional demos of the scams Indians face: a fake refund, a digital arrest call, a task job, a trading app. Find the warning signs, choose what you would do, and see why.

46 scam demos · 8 response exercises · English and Hindi

हिन्दी में पढ़ें

What each demo teaches

The three warning signs and the one thing to remember, for every demo.

Payments & UPI

The refund that sends money

A 'refund' chat sends a QR that takes your money instead.

  1. You never have to scan a QR to receive money. Scanning a QR is how you pay.
  2. You enter your UPI PIN only to send money. Receiving money never needs it.
  3. Whoever made the QR typed this note. The screen says 'Paying': ₹2,499 would leave your account.

Remember: Scanning a QR and entering your UPI PIN is how you pay. A real refund needs neither.

Open this demo
The ₹1 trial that bills you monthly

A ₹1 trial page quietly sets up a monthly UPI AutoPay.

  1. ₹1 is only the first charge. Look for what you pay after the trial.
  2. 'Renews automatically' means you allow future debits, not a one-time payment.
  3. This is the real price. One PIN lets ₹1,999 go out every month until you cancel.

Remember: Read the whole AutoPay screen before you enter your PIN. Already approved one? Cancel it in the AutoPay section of your UPI app.

Open this demo
The swapped QR sticker

A new sticker on a shop counter sends your payment to someone else.

  1. A fresh sticker stuck over a shop's QR can be a swap.
  2. A note that explains away a different name is there to stop you checking it.
  3. The name after scanning gets your money. Don't recognise it? Ask the shopkeeper first.

Remember: Before paying, read the name your UPI app shows, not just the sticker.

Open this demo
A screenshot is not payment

You sell your old phone online; the buyer sends a screenshot and says he has paid.

  1. A screenshot is only a picture. It can be edited, or made with a fake payment app.
  2. UPI money usually arrives within seconds. Only your own bank app can show whether it came.
  3. Someone at your door, rushing you to hand over the phone, is pressure so that you skip the check.

Remember: Hand over the item only after the money shows in your own bank app.

Open this demo
The 'sent by mistake' call

An SMS says ₹4,500 arrived; then a stranger calls to get it 'back'.

  1. This 'bank' SMS came from a personal mobile number, and an SMS is not proof anyway. Check your balance in your own bank app.
  2. A real wrong transfer is fixed through the sender's own bank. Ask them to complain there; don't settle it on a call.
  3. Sending money to a different UPI ID is not a 'return'. It is a fresh payment of your own money.

Remember: Check your own bank app, not an SMS. A real wrong transfer is sorted out through the banks, not by paying a caller.

Open this demo
The cashback that asks for an OTP

A cashback link asks for the OTP your bank just sent.

  1. A surprise cashback with a 10-minute deadline is a lure. Check offers only inside the app you already use, not through an SMS link.
  2. You don't need an OTP to receive money. A bank OTP is for approving a payment or a change on your account.
  3. Read the SMS: this code approves a ₹7,500 payment from your card, not a ₹750 cashback.

Remember: Read every OTP SMS before using it. Never type or tell an OTP to claim a reward.

Open this demo

Calls & impersonation

The 'digital arrest' video call

A fake officer on a video call keeps you on camera, alone, until you pay.

  1. A uniform, an ID card or an office backdrop on a video call proves nothing. All of it can be faked.
  2. 'Digital arrest' does not exist in law. You are kept on camera and alone so you cannot check with family or the police.
  3. No agency 'verifies' money by making you send it. The payee on this screen is a private firm, not RBI.

Remember: No Indian agency questions or arrests anyone over a video call. End the call and tell someone you trust.

Open this demo
The parcel that becomes a case

A 'seized parcel' call is transferred to fake police who demand a fee.

  1. A parcel you never sent is the hook. Check any shipment yourself on the courier's official app or site.
  2. The 'police' is on the caller's own line, with the same number. Anyone he connects you to is not a real check.
  3. No police or customs officer takes a fee on a call to keep you out of an FIR.

Remember: Hang up and check the parcel yourself. Call the police only on a number you look up, never through a transfer.

Open this demo
The SIM-block KYC message

An SMS threatens to block your SIM, a fake KYC page takes your number, then an 'agent' calls for your OTP.

  1. A same-day block threat is pressure, not proof.
  2. Anyone can put a company's name in a link. Use the operator's own app.
  3. KYC is never a reason to read out an OTP to a caller.

Remember: Update KYC only in your operator's own app or store, and never read a code out to a caller.

Open this demo
The free eSIM upgrade call

A fake 'customer care' caller wants the code that moves your number to a new SIM.

  1. An upgrade you never asked for can hide a SIM change.
  2. Codes sent to your phone must stay private, whoever asks.
  3. The SMS shows what the code really does: it moves your number, and your OTPs, to someone else's SIM.

Remember: Start any SIM or eSIM change yourself, only in your operator's app or store. If your signal suddenly drops, call your operator and bank at once.

Open this demo
A familiar voice, a new number

A call in your child's voice from a new number asks for urgent money.

  1. A familiar voice is not proof. AI can copy a voice from short clips posted online.
  2. Being told not to call back or tell family blocks the one check that would expose the lie.
  3. This UPI ID belongs to a stranger, not a hospital. Call your son or family on a saved number first.

Remember: Hang up and call back on the saved number, even if the voice sounds exactly right. Agree a family code word.

Open this demo
Blackmail after a video call

A stranger records a video call, then threatens to share it unless you pay.

  1. The threat to send it to everyone is there to panic you into paying fast.
  2. Secrecy helps the blackmailer. Telling someone you trust helps you.
  3. Paying does not guarantee deletion, and it can bring more demands.

Remember: Don't pay or reply. Save screenshots, then report at cybercrime.gov.in (call 1930 if you already paid).

Open this demo
The fake helpline in search results

A helpline number from a search page connects you to a fake agent who wants your card details and OTP.

  1. Fraudsters push fake helpline numbers to the top of search results. Being the first result, or an ad, doesn’t make a number official. Take it from the company’s own app or website.
  2. A refund goes back to the card you paid with. Nobody needs your card number or CVV to send it, so never share them on a call.
  3. Read the SMS: the code approves a ₹4,800 payment from your card. It is not a refund code, and no real agent asks for it.

Remember: Take helpline numbers only from the company’s own app or website, never from search results. No real agent asks for your card details or OTP; if you shared them, block the card at once.

Open this demo
The refund call that wants your screen

A 'refund team' caller gets you to install a screen-sharing app, then log in to your bank.

  1. A refund never needs a new app. Once you read out that code, the caller can connect to your phone.
  2. This warning comes from your own phone. Tapping ‘Start now’ lets the caller see everything on your screen, including every OTP and message that pops up.
  3. No refund needs your bank login. He wants you in the app so he can read the OTPs your bank sends on your shared screen. Never open banking while sharing.

Remember: A refund never needs screen sharing. If you already shared, disconnect, uninstall the app, and call your bank on the number printed on your card or shown in its official app.

Open this demo
The fake police fine page

A video link on an adult site opens a 'police' page that says your phone is blocked.

  1. Police never block a phone through a web page. Delhi Police and PIB Fact Check have called such pop-ups fake.
  2. It is only a browser page in full screen. Close the browser from recent apps; nothing on the phone is locked.
  3. This ‘police fine’ is going to Demo Traders, a private UPI ID. Police never collect a fine through a pop-up or a stranger’s UPI.

Remember: A police notice that pops up on a website is a scam page. Close the browser fully and never pay; police do not collect fines through pop-ups.

Open this demo

Jobs & money mules

The 'rate products, earn daily' job

A part-time job pays ₹150, then wants ₹8,000 before you can withdraw.

  1. A stranger on chat paying you for likes or ratings is how task scams begin. The government has blocked 100+ such sites.
  2. The small payout is bait: they pay a little first so you trust them with more.
  3. A real job never makes you pay to get your earnings out. The ₹12,000 is only a number on their site.

Remember: A job pays you. It never asks you to pay in before you can take your earnings out.

Open this demo
The captcha-job penalty

A work-from-home captcha job ends in a 'penalty' and a legal threat.

  1. Big 'guaranteed' pay for easy typing is the bait. I4C has warned about exactly these captcha-job offers.
  2. Only the company checks your work and it won't show the errors. A score it makes up proves nothing.
  3. A threatening email is not a court order. Scammers use fear to make you pay, then ask for more.

Remember: A job that fails your work and then demands a penalty is the scam itself. Don't pay; keep every message and report it.

Open this demo
The job abroad that starts as a tourist trip

A recruiter sends you abroad as a tourist and wants your passport.

  1. Big pay and free travel for basic skills is the usual lure. CBI says such offers have taken Indians to scam compounds.
  2. Entering as a tourist does not let you work there. A real job abroad gets you a work visa before you fly.
  3. Whoever holds your passport decides if you can leave. Trafficked workers often lose theirs on arrival.

Remember: Before any job abroad, verify the employer and the recruiting agent through the Indian Embassy in that country, and never hand over your passport.

Open this demo
The job-confirmation fee

An SMS 'selects' you for a job, then HR wants a fee on UPI.

  1. You never had an interview, yet you're 'selected'. I4C warns that fake job offers arrive by SMS just like this.
  2. Honest employers never ask you to pay to get a job, 'refundable' or not.
  3. A company fee going to one person's own UPI ID is a clear warning.

Remember: Check the employer's own hiring channel before paying or sharing documents.

Open this demo
Rent out your bank account?

A stranger pays 5% to pass other people's money through your account.

  1. Easy commission for 'using your account' is how fraud gangs find mule accounts, often on social media.
  2. The money lands in an account in your name. When victims complain, police trace it to you and can freeze your account.
  3. Lying to your bank for them won't protect you. Illegal money passing through your account can lead to arrest.

Remember: Never rent or sell your bank account. If money you don't recognise arrives, tell your bank; don't forward it.

Open this demo

Investing & recovery

The stock-tips app that won't pay out

A stock-tips group sends you to an app that shows profit but blocks withdrawal.

  1. No real investment can guarantee returns. SEBI says guaranteed returns in the market are a scam sign.
  2. Fake apps show big profits so you invest more. A number in an app from a chat link is not money you own; check SEBI's list of registered trading apps.
  3. Having to pay a fee to get your own money out is how fake apps work. Real platforms also never take money into someone else's account.

Remember: Verify the broker and official app; do not treat screen profits as proof.

Open this demo
Online romance, then a crypto 'investment'

Someone you met online wins your trust, then gets you to invest in crypto.

  1. Always having a reason not to meet, like work abroad, is a common romance-scam excuse.
  2. An online partner offering to teach you crypto investing is a known romance-scam move.
  3. Having to pay before you can withdraw is how fake investment apps work. The balance on screen is probably not real.

Remember: Keep financial verification independent of an online relationship.

Open this demo
The fake celebrity video ad

A video ad uses a famous face, then a 'manager' calls to sign you up.

  1. AI can copy a famous person's face and voice. The real person may never have said this.
  2. No genuine investment guarantees income. SEBI says to be suspicious of anyone who promises it.
  3. Being told not to check and to pay today is pressure. Check the person's official pages and whether the company is registered with SEBI.

Remember: Appearance is not authentication; verify the claim and the entity separately.

Open this demo
The fake money-recovery offer

After a fraud, a 'recovery team' asks for a fee to get your money back.

  1. Knowing about your loss doesn't make them genuine. Scammers buy and sell lists of fraud victims.
  2. No one can guarantee you'll get lost money back. A 'guarantee' is itself a warning sign.
  3. Genuine help never asks for a fee to return your money. Paying only adds a second loss.

Remember: A stranger who contacts you and charges a fee to recover lost money is running a second scam. Follow up only on cybercrime.gov.in or with your bank.

Open this demo
The free-token claim

A 'free tokens' post leads to a claim site and a wallet approval request.

  1. Tokens you never asked for are bait, not a gift. In your wallet they can't take anything; the trap is the claim site they send you to.
  2. A countdown is there to rush you before you check. It proves nothing.
  3. This approval lets the site spend all your DEMO-USD, with no limit, now or later. Getting free tokens never needs permission to spend your own.

Remember: Read who can spend what before you approve anything in a wallet.

Open this demo
The SIP that was never invested

A chat 'advisor' sells a guaranteed SIP paid to a personal UPI ID.

  1. Mutual fund returns are never guaranteed. SEBI says to be suspicious of anyone who promises assured returns.
  2. A real SIP is paid to the mutual fund scheme through official channels, never to a person's UPI ID.
  3. Their app screen is not proof. Check your folio in your CAS (official statement) or with the fund house directly.

Remember: A bank debit is not proof that mutual fund units were bought in your name.

Open this demo
The VIP IPO allotment

An IPO tips group sells a 'VIP quota' and asks you to transfer the money to them.

  1. No one can guarantee an IPO allotment. NSE warns about groups offering 'institutional accounts' with special privileges.
  2. A real IPO application is made only through your own bank or broker. 'Only through us' steers you away from it.
  3. In ASBA the money stays blocked in your own account and is debited only if shares are allotted. A real IPO never asks you to transfer it.

Remember: Money blocked in your bank is not the same as money sent to someone else.

Open this demo
The UP/DOWN plane game that takes it all

A "VIP signals" group pushes a 30-second dollar trading game.

  1. Buying a dollar “balance” through a stranger’s UPI is not investing. RBI names many such trading apps as unauthorised.
  2. A small first win is bait. ED says one such platform paid early profits to build trust.
  3. The app decides where the plane goes. Depositing more to “win it back” only adds to the loss.

Remember: In an app like this, the operator controls the chart and the result. The early win is there to get a bigger deposit.

Open this demo

Accounts & phishing

The tax-refund email

A refund email leads to a look-alike page that asks for your net-banking login.

  1. 'Verify in 24 hours or lose it' is a pressure trick. Check any refund only on the official tax site you open yourself.
  2. The page calls itself official, but look at the address bar: the real income-tax site ends in .gov.in, and this one doesn't.
  3. No refund needs your net-banking password or OTP. With them, the scammer can log in and empty your account.

Remember: Check a tax refund only on the official site you open yourself; no refund needs your bank login or OTP.

Open this demo
Expiring bank reward points

An SMS about expiring points opens a page that asks for your card details and OTP.

  1. Banks send SMS from a short sender name, not an ordinary 10-digit mobile number. And 'expire TODAY' is there to rush you.
  2. Nobody needs your CVV to give you money. Card number, expiry and CVV are exactly what someone needs to spend from your card.
  3. The 'bank code' is an OTP. It approves a payment from your card; reward points never need one.

Remember: Redeem points only inside your bank's own app; never type your CVV or OTP into a page opened from an SMS link.

Open this demo
The verified-badge lure

An email offers a verified badge, then a page asks for your password and backup code.

  1. You never applied, yet a badge is offered with a 48-hour deadline. Badge offers are a common bait to take over creator accounts.
  2. Real account notices can be checked inside the app itself. A separate sign-in page opened from an email is how passwords get stolen.
  3. A backup code lets anyone into your account without the OTP on your phone. Whoever gets one can lock you out.

Remember: Never type your password or a backup code into a page opened from an email; check badge offers inside the app itself.

Open this demo
A friend asks for your code

A code arrives by SMS, and a friend's account asks you to forward it.

  1. This code is for YOUR number. Whoever enters it gets your chat account on their phone.
  2. A code goes only to the number being logged in, so it can't be your friend's. His account may already be in a scammer's hands.
  3. Refusing a call is a warning sign. A quick call on his usual number shows whether it's really him.

Remember: A login code is for your sign-in, not something to forward.

Open this demo
Rent your messaging account?

A chat offers ₹1,000 a day to link a stranger's device to your account.

  1. Nobody pays ₹1,000 a day for nothing. What they are really buying is the use of your number and your name.
  2. Once linked, you can't control what they send. Scam messages go out from your number, and complaints lead back to you.
  3. Entering their code under 'Link a device' opens your chats on their computer. They can then message as you, even when your phone is off.

Remember: Do not rent messaging access; revoke unfamiliar linked devices.

Open this demo

Apps & malware

The instant loan app that wants your contacts

A quick-loan ad leads to an app that wants your contacts, photos and SMS.

  1. A promise of approval with no documents and no checks is bait. It tells you nothing about who is lending to you.
  2. You get ₹3,500 but owe ₹5,000 within a week. A big cut up front and repayment within days are signs of an illegal loan app.
  3. A loan never needs your contacts, photos or SMS. Illegal loan apps copy this data to threaten you and to message your family and colleagues.

Remember: Before you borrow, find out which bank or NBFC is behind the app. Never give a loan app your contacts, photos or SMS.

Open this demo
The 'power cut tonight' SMS

A power-cut SMS sends you to an 'officer' who asks you to install a bill app.

  1. Power companies give written notice before cutting supply, and send bill SMS from an official sender ID, not a 10-digit mobile number.
  2. A power company never sends an app file to update a bill. An APK from a stranger can take control of your phone.
  3. Viewing a bill does not need your SMS. With SMS access, the app can read the OTPs your bank sends.

Remember: Check your bill yourself in the power company's official app or website. Never install an app someone sends you to 'update' a bill.

Open this demo
The fake traffic-challan app

A message about a traffic fine asks you to install a 'challan' app.

  1. You can check any real challan yourself on the official e-challan website with your vehicle number. Don't take the message's word for it.
  2. Traffic police and the RTO never send an app file to pay a challan. An APK in a chat can be malware.
  3. Accessibility lets an app see your screen and tap for you, even inside your bank app. Viewing a challan never needs it.

Remember: Check a challan yourself on the official e-challan website. Traffic police never send an app file.

Open this demo
The wedding card that is really an app

A wedding card from a friend's number is really an app that reads your OTPs.

  1. Invitation_Demo.apk is an app, not a card: a real card is a photo, PDF or video. The rush to check the venue is bait: hacked accounts send this to their contacts. Call Deepak and ask.
  2. Opening a card never needs Accessibility, SMS or notifications. With them, the app can read your bank OTPs and alerts, record what you type and send it all to the scammers.
  3. You asked for no OTP, so someone else is getting into your account. You never shared it: the 'card' app read it from your SMS and sent it to the scammers.

Remember: A 'card' ending in .apk is an app: never install it, even from a friend. Installed one? Turn off the internet and call your bank and 1930 at once: a quick report can help hold the money. Then report on cybercrime.gov.in and remove the app from Settings > Apps.

Open this demo
An update inside a web page

A web page claims your browser is outdated and hands you an 'update' app to install.

  1. The warning comes from a website (the address bar shows browser-update-center…), not from your browser or phone. Real updates never come from a web page.
  2. On a phone, browser updates come only from the app store. An .apk file from a web page is not an update.
  3. Your phone itself is warning you. A genuine update never needs you to allow unknown apps; saying yes can let malware in.

Remember: Update apps only through your phone's app store, never from a warning on a web page.

Open this demo
The virus popup that takes your screen

A scary popup leads to an app that controls the phone.

  1. A website cannot scan your phone; a scary popup is an advert, not a diagnosis.
  2. Accessibility lets an app read your screen and tap for you, even in banking apps.
  3. The 'repair' screen is a cover. While you keep your hands off, the app works inside your bank app behind it.

Remember: A popup that says your phone is infected is selling fear. Never give Accessibility to an app a popup told you to install. If your screen moves by itself, turn on flight mode and call your bank from another phone.

Open this demo

Shopping & business

The impossible sale

A social ad offers a premium product at a tiny price.

  1. A 90% cut on a premium product, in an ad from a shop you have never heard of, is bait.
  2. No cash on delivery takes away a simple protection: paying only when the parcel is in your hands.
  3. Your UPI app shows a person's bank name, not the shop's. Money sent to a personal account is hard to get back.

Remember: An unknown shop, a huge discount, no COD and a person's name on the UPI screen: that is the fake-shop pattern.

Open this demo
The uniformed seller

A 'soldier' selling a cheap bike asks for a transport charge before you see it.

  1. 'Urgent transfer' is a ready excuse to rush you and to explain why you can't meet.
  2. An ID card photo can be stolen or edited. It does not prove the bike exists.
  3. A charge before you see the item is the whole point of this scam. Pay only after you inspect it.

Remember: A uniform or an ID card proves nothing. Never pay before you have seen the item.

Open this demo
A deposit before the viewing

A cheap flat's 'owner' is abroad and wants a deposit before you see it.

  1. Rent far below the area rate is the bait. The photos may be copied from a real listing.
  2. An 'owner' who can't show the flat may not own it. Visit, or send someone you trust.
  3. Money before any visit or agreement, with keys 'by courier', is what this scam is after.

Remember: Never send a deposit for a flat you haven't seen, to an owner you haven't met.

Open this demo
The 'confirmed seat' agent

A stranger promises confirmed seats on a full train, outside the official booking app.

  1. Only the railway itself can confirm a seat on a full train. A stranger's secret 'quota' is a claim, not a ticket.
  2. Paying a personal UPI ID skips the official booking, its receipt and its refund rules.
  3. A real booking has a PNR you can check right away. Being told not to check is the warning.

Remember: A real booking can always be checked with the railway, airline or hotel. If someone stops you from checking, don't pay.

Open this demo
Pay to claim a prize

An SMS says you won a draw you never entered, then a 'manager' asks for a fee.

  1. You never entered this draw. A surprise prize is a common lure.
  2. If you have to pay to get a prize, it is a scam. A real prize never asks for a fee first.
  3. Secrecy stops you from getting a second opinion.

Remember: Do not pay an unexpected contact to unlock a supposed prize.

Open this demo
The urgent donation appeal

A flood-relief appeal asks you to donate to one person's UPI ID.

  1. Pressure to donate 'before tonight' leaves no time to check. A verified donation route can still help quickly.
  2. Anyone can write 'registered trust' or '80G' on a web page. The claim proves nothing until you check the trust yourself.
  3. A donation should go to the organisation's own verified account, not to one person's UPI ID.

Remember: Verify where the donation goes before responding to urgency.

Open this demo
The changed bank invoice

An email in your supplier's name asks you to pay its invoice into a new bank account.

  1. An email alone cannot prove a bank change. A supplier's mailbox can be hacked or faked, so the new account could be anyone's.
  2. A same-day deadline and a threat to your next shipment push you to skip your normal payment checks.
  3. Being told not to call is the warning sign. Call the supplier on a number you already have on file, not one given in the email.

Remember: Confirm bank changes through a previously trusted channel before payment.

Open this demo

Response & defence

After a leak: the paid 'data removal' offer

A real leak notice arrives, then a stranger asks for money to 'delete' your data.

  1. The company's own notice lists exactly what leaked: name, number and email, not passwords or cards. That is enough for scammers to message you by name.
  2. They list exactly what the notice said had leaked. That only shows they have the leaked data, not that they are an agency that can help.
  3. Once leaked data has been copied, nobody can delete it 'forever'. An upfront fee for a guaranteed fix is how recovery scams work.

Remember: After a leak, trust only the company's own updates. Expect scam messages that quote your leaked details, and never pay anyone to 'delete' leaked data.

Open this demo
After a cracked app steals your logins

A free cracked app, then loan-request emails go out from your ID that you never sent.

  1. A cracked setup that asks you to switch off antivirus is a classic infostealer trap. It quietly copies saved passwords and signed-in sessions.
  2. Mail sent from your real ID, with no OTP or new-login alert, points to a signed-in session copied from your device, not a guessed password.
  3. The laptop may still be infected and can steal the new password too, and the stolen session can stay signed in.

Remember: Treat the infected laptop as unsafe until it is cleaned. From a trusted device, change passwords, sign out all sessions and check the recovery email and phone.

Open this demo
Ransomware at the office: the first hour

Office files lock overnight, IT wants to wipe everything, and an extortion email arrives.

  1. An outside admin login at 2:40 a.m. is a lead on how the attackers got in. Those logs are evidence: keep them for the response team.
  2. Wiping or switching off machines in a rush can destroy evidence, and attackers can return the same way. Disconnect them from the network first.
  3. A ransom note is a claim meant to rush you. Only logs and investigators can confirm what data actually left.

Remember: In the first hour, disconnect affected systems, preserve evidence, follow your incident-response plan and report the incident. Treat the attackers’ claims as unverified.

Open this demo
Which patch comes first?

Your VPN vendor warns of a bug under attack, but IT wants to wait for the monthly update.

  1. A login page open to the internet can be attacked by anyone, from anywhere, at any time, so it needs faster action.
  2. Known active attacks move a patch to the top of the list.
  3. An internet-facing bug under attack cannot wait 12 days; the printer and billing updates can. Apply the vendor’s official fix first.

Remember: Patch internet-facing systems under active attack first, using the fix from the vendor’s own advisory. Routine updates can follow the normal cycle.

Open this demo
After the complaint: the 'fast-track' call

You filed a fraud complaint. Now a caller offers to speed up your refund for a fee.

  1. This is your complaint's own number. You use it to check the status yourself; keep it with your evidence: screenshots, bank statement and the suspect's number.
  2. This is where real updates appear: on the portal after you log in, and at the police station handling your case. A stranger's call is not an update.
  3. Knowing your complaint amount does not make him police. No genuine office charges a fee to speed up a complaint or return money; a fee to his UPI ID is a new loss.

Remember: Track your complaint only on the official portal and with the police station on your case. Never pay a caller to 'speed it up'.

Open this demo
Frozen account, fake 'unfreeze expert'

Your bank account is frozen on a police request. An online 'expert' promises to unfreeze it for a fee.

  1. The SMS says an agency asked for this freeze. Ask the branch, in writing, which agency, its complaint or reference number and the transaction involved. That tells you whom to approach.
  2. No one can promise a date. Lifting a freeze is up to the agency that asked for it, working through your bank, so no ad can guarantee it.
  3. A 'handling fee' to a personal UPI ID, paid from another account, unfreezes nothing; it is just more money lost. Use the bank's written details and the official grievance route for frozen accounts.

Remember: Rely on the bank's written details, the agency named in them and the official grievance route, not on paid 'guarantees'.

Open this demo
Aadhaar leak alert, fake 'lock' app

A leak alert from a stranger pushes you to install a 'protection' app.

  1. The last four digits of your Aadhaar prove nothing: leaked data is exactly what scammers use to sound real. Check your authentication history yourself on official Aadhaar services.
  2. Aadhaar's real lock (for biometrics) is only on official Aadhaar services and in the official app from your phone's app store. An APK sent in a chat is neither.
  3. A 'lock' app has no use for your SMS, contacts or call logs. SMS access alone is enough to read your bank OTPs.

Remember: Check official identity services yourself and watch for misuse; never install 'protection' apps sent in a chat.

Open this demo
Sign-in codes you never asked for

Sign-in codes keep arriving, then a 'security team' calls and asks for one.

  1. You didn't try to sign in, so someone else is trying to get into your account, most likely with your password.
  2. The code does not verify you or block anyone: it lets a new device into your account. Whoever asks for it is the one trying to get in.
  3. 'Do not share it with anyone' has no exceptions, not even the company's own staff. A name on the caller ID proves nothing, and the rush is there to stop you from checking.

Remember: Unexpected sign-in codes mean someone may have your password. From a trusted device, change it, sign out unknown sessions, check recovery methods and use a passkey where offered.

Open this demo