Resources / Fraud Intelligence Reports / India Fraud Intelligence Report — Q2 2026
Quarterly Flagship
The Changing Digital Fraud Landscape

India Fraud Intelligence Report — Q2 2026

This is not another typology explainer. It is a quarterly intelligence view — connecting what changed across UPI, cards, lending, merchants and mule networks into one picture of where enterprise fraud risk in India is heading, and what FRM functions should prepare for next.

Published Aug 2026 BANKiQ Fraud Intelligence Unit

Executive Summary

The defining pattern of this quarter is not a new fraud technique — it is the maturing coordination between fraud typologies that used to be tracked separately. UPI social engineering, mule account layering, fake lending applications and merchant collusion increasingly function as stages of the same attack chain rather than isolated incidents. For enterprise fraud risk management (FRM), that means the unit of analysis has to move from the transaction to the entity and the network around it.

23L+

Suspect identifiers held in I4C's Suspect Registry as of January 2026

MHA
27L+

Layer-1 mule accounts shared with participating entities by I4C, by January 2026

MHA
₹9,518.91 Cr

Value of transactions reported declined using I4C's Financial Fraud Risk Indicator data, by January 2026

MHA
₹8,690 Cr+

Amount saved via the Citizen Financial Cyber Fraud Reporting & Management System across 24.65 lakh+ complaints, up to 31 January 2026

MHA

Read together, these figures describe an ecosystem-level response finally catching up to an ecosystem-level problem. The scale of I4C's Suspect Registry and Layer-1 mule-account sharing shows that mule infrastructure — not the initial scam — is now treated as the primary interdiction point by national cyber-fraud coordination. For banks and NBFCs, the practical implication is that entity and network-level signals shared through this ecosystem are becoming a usable input to fraud decisioning, not just a post-facto reporting obligation.

This edition covers what changed this quarter across each major channel, consolidates the detection signals that recur across typologies, and sets out what BANKiQ's analysis suggests institutions should watch going into next quarter — expanded further in the companion Quarterly Fraud Intelligence brief.

Digital Fraud Landscape: What Changed This Quarter?

Three shifts stand out across the typologies covered in this edition. First, authorised-transaction fraud — where the customer completes the transaction themselves under manipulation — continues to grow as a share of overall loss, even as classic unauthorised-access fraud remains comparatively well controlled by existing authentication layers. Second, mule-account infrastructure is being treated, by both fraud rings and by national coordination bodies, as a distinct layer worth attacking or defending in its own right, rather than a byproduct of the original scam. Third, fraud journeys are increasingly crossing product and channel boundaries within a single institution — a pattern channel-specific monitoring was never built to see.

None of these are new phenomena in isolation. What is new this quarter is the degree to which they compound: a socially-engineered UPI transaction is now more likely to route through a tiered mule network built partly from synthetic or coerced identities, some of which were themselves opened through fraudulent lending-app or merchant-onboarding channels.

UPI Fraud

Social-engineering-led fraud remains the dominant UPI loss vector this quarter. Fake customer-care calls, courier and KYC-update pretexts, and screen-sharing app abuse continue to outpace purely technical attack methods. New-beneficiary fraud — a first-time payee immediately used for a high-value transfer — remains one of the most reliable signals available to issuers, alongside device or SIM changes shortly preceding a transaction.

NPCI's ecosystem-level statistics and fraud-awareness resources remain the appropriate reference point for UPI volumes and control guidance; see Sources & References.

Card & Digital Wallet Fraud

Card-not-present testing and wallet-provisioning abuse continue to be the more active fronts this quarter, relative to point-of-sale or physical card compromise. Distributed, low-value card testing across many merchants, and account-takeover-enabled wallet provisioning, both remain harder for single-issuer, single-transaction rules to catch than concentrated high-value fraud.

Digital Lending Fraud

Fraud in digital lending continues to concentrate at origination rather than at repayment — fabricated documentation, device-farm-driven multiple applications, and synthetic identities built to pass automated KYC. Fake lending apps impersonating regulated NBFCs and banks remain an active, separate loss vector: one where the institution being impersonated is the reputational victim rather than the initial financial one.

Merchant & QR Fraud

Merchant-side fraud this quarter continues to show collusive and networked patterns rather than isolated bad actors — QR-code manipulation, refund and reversal abuse, and clusters of aggregator-onboarded merchants sharing settlement details or beneficial ownership. Aggregation's onboarding-speed advantage remains a trade-off against the underwriting scrutiny a directly onboarded merchant would otherwise receive.

Mule Accounts & Fraud Networks

This is the quarter's most consequential structural development. I4C's Suspect Registry and Layer-1 mule-account sharing infrastructure has now reached a scale — over 23 lakh suspect identifiers and over 27 lakh Layer-1 mule accounts shared with participating entities by January 2026 — that makes network-level, cross-institution mule detection genuinely operational rather than aspirational. The May 2026 MoU between I4C and the Reserve Bank Innovation Hub (RBIH), focused specifically on AI-driven detection of mule accounts and cyber-financial fraud, extends this from data-sharing into joint detection capability.

For enterprise FRM, the practical takeaway is that mule detection is shifting from something each institution builds alone toward something increasingly informed by a shared, national-level signal layer.

Social Engineering & Impersonation

Impersonation-led fraud — fake bank officials, fake regulators, digital-arrest scams, investment and employment scams — remains a consistent and growing pressure across channels this quarter, cutting across UPI, cards and lending simultaneously rather than being specific to any one product. RBI's consumer-facing awareness material already tracks several of these categories directly, including digital arrest, money mule recruitment, UPI QR fraud, fraudulent lending apps, and fraudulent calls or SMS — underlining that this is now a recognised, named national risk category rather than an emerging one.

Emerging Technology-enabled Fraud

AI-enabled social engineering — more convincing scripts, faster personalisation, automated reconnaissance on potential victims — is visible this quarter primarily as a force multiplier on existing impersonation techniques, rather than as a wholly new typology. The same underlying technology is beginning to appear on the defensive side, most visibly in the I4C–RBIH collaboration on AI-driven mule and cyber-fraud detection referenced above.

Cross-Channel Fraud Journeys

A growing share of the higher-value cases reviewed this quarter involve a single compromised customer identity touching more than one product — most often a credential or device compromise that enables both a UPI transfer and a lending application, or a card provisioning event, in close succession. Channel-specific fraud systems, by design, only see their own fragment of these journeys.

Key Detection Signals

  1. New-beneficiary or new-payee transactions completed unusually fast relative to a customer's normal behaviour.
  2. Device, SIM, or app-installation changes shortly preceding a high-value or first-of-its-kind transaction.
  3. Rapid pass-through of funds into and out of an account within minutes or hours (mule signature).
  4. Shared devices, IPs, or beneficiaries linking accounts, applications, or merchants that appear otherwise unrelated.
  5. A risk event in one channel (failed authentication, a card dispute) followed shortly by activity in a different product for the same customer.
  6. Document, income or identity attributes inconsistent with bureau, bank-statement, or historical customer data.

What Banks Should Watch Next Quarter

This edition's detailed forward-looking view — five specific developments BANKiQ's analysis flags for the next quarter, each with a directional risk outlook — is published as a companion piece: the Quarterly Fraud Intelligence brief. It is designed to be read alongside this report and updated independently each quarter.

SHARE

Looking for something specific?

Talk to our team directly, or request a demo to see the platform behind the resources.