iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout TruAlt Bioenergy Q1 Net Zooms to ₹59.27 Crore on Higher Revenues, Capacity Expansion India’s cotton sowing crosses 100 lakh hectares as monsoon picks up, area expands in key states UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout TruAlt Bioenergy Q1 Net Zooms to ₹59.27 Crore on Higher Revenues, Capacity Expansion India’s cotton sowing crosses 100 lakh hectares as monsoon picks up, area expands in key states
Home ›› Technology ›› Cybersecurity ›› Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals

Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals

India's cyber-fraud landscape is pivoting from device takeover to real-time social engineering, with victims executing transfers under live phone guidance. A Biocatch report shows attempted fraud sessions fell 12% but value rose 35%. Meanwhile, the CBI identified over 8.5 lakh mule accounts in 2025, with total complaints linked to Rs 22,496 crore in fraud.

iG
iGEN Editorial
July 27, 2026
Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals

India's cyber-fraud landscape is undergoing a decisive shift, with fraudsters moving away from remote takeover of devices to real-time social engineering, where victims themselves execute transactions under live phone instruction, even as a sprawling network of mule accounts enables the laundering of proceeds.

Shift to Active Call Guidance

According to the July 2026 report by Biocatch (a company that assists global banks on fraud prevention) on digital banking fraud trends, total attempted fraud sessions declined 12% between H2 2025-H1 2026 and the corresponding previous period. However, the value of attempted fraud payments rose 35%, signalling a pivot towards fewer but higher-value attacks.

This change is being driven by a move away from technology-heavy methods such as Remote Access Trojans to more direct psychological manipulation. Detection of such malware fell from 2.5% to 1.7% of fraudulent sessions.

At the centre of this shift is the rise of "active call guidance" frauds, where scammers remain on a phone call with victims and guide them step by step through fund transfers. The share of fraudulent sessions occurring during such calls rose from 3.9% to 4.5%.

Mobile-Led Fraud Surge

This new model is being amplified by a surge in mobile-led fraud. Mobile banking fraud sessions jumped 67%, driven by an 86% rise on iOS and 35% on Android, while web-based fraud fell 10%.

Text messages have emerged as the primary entry point, with SMS-based scams rising 146%, typically used to lure victims into calls where social engineering takes over.

Once engaged, victims are often instructed to enter credentials themselves, reflected in a rise in autofill usage for usernames and passwords, reducing the need for direct system compromise.

Metric Change
Total attempted fraud sessions -12%
Value of attempted fraud payments +35%
Mobile banking fraud sessions +67%
iOS fraud sessions +86%
Android fraud sessions +35%
Web-based fraud -10%
SMS-based scams +146%
Active call guidance share 3.9% → 4.5%
Remote access trojan detection 2.5% → 1.7%

Mule Account Infrastructure

Behind these front-end scams lies a critical but less visible layer: mule accounts, which form the backbone of the fraud economy.

The CBI in 2025 identified more than 8.5 lakh mule accounts across more than 700 bank branches. Overall, 26.5 lakh mule cases were logged nationally, linked to cyber-fraud complaints amounting to Rs 22,496 crore, of which Rs 9,055 crore was blocked or declined through intervention mechanisms. Authorities froze more than 4.5 lakh mule accounts in a year.

Money mules (individuals) are recruited through fake job advertisements, social media, or messaging platforms, often without full awareness of the criminal intent.

These accounts are either newly opened with legitimate KYC or rented from existing account holders. Once activated, they are used for rapid "layering" of funds, moving money across multiple beneficiaries at high speed using instant payment systems such as UPI, before eventual dispersal into cash, cryptocurrency, or international channels.

The "mule-as-a-service" model decentralises operations, allowing fraudsters to bypass banking controls and later consolidate funds, often converting them into cryptocurrency before transferring them abroad.

Implications for Enterprise Security

For enterprise technology decision-makers, the report highlights a critical vulnerability in the financial infrastructure that underpins supply chains and trade payments. The rise of social engineering and mule networks means that even robust technical controls can be bypassed through human manipulation. Businesses should reassess their fraud detection strategies, focusing on behavioural analytics and real-time transaction monitoring, as recommended by Biocatch's findings. The shift to mobile and SMS-based attacks also underscores the need for employee training and multi-factor authentication beyond SMS.


Sources: Business-Today

Keep Reading

Recommended Stories

World Cup Scams Are Getting Harder to Spot as AI Fuels Surge in Fraudulent Domains Technology

World Cup Scams Are Getting Harder to Spot as AI Fuels Surge in Fraudulent Domains

The 2026 FIFA World Cup has triggered an unprecedented wave of sophisticated scams, with AI-generated websites and phishing campaigns making fraud harder to spot. More than 13,000 FIFA-themed domains were registered in early 2026, with roughly one in 41 identified as malicious. Cybersecurity firms warn that AI is both enabling attackers and powering defenses, but collaboration and human vigilance remain critical.

June 22, 2026
Why Your Help Desk Remains the Biggest Security Risk in Your Organization Technology

Why Your Help Desk Remains the Biggest Security Risk in Your Organization

TechRadar reports that help desk social engineering attacks, like those that hit MGM Resorts, Marks & Spencer, and Harrods, bypass most security controls. AI has amplified the threat, with phishing scams up 85% and average losses doubling to $2,060. Best practices include hardening identity operations and tying device enrollment to identity.

June 15, 2026
Surge in AI-Powered Scams Hits UK: 4.1 Million Fraud Cases, £1.3bn Stolen in 2025 Technology

Surge in AI-Powered Scams Hits UK: 4.1 Million Fraud Cases, £1.3bn Stolen in 2025

UK Finance's annual report reveals 4.1 million fraud cases in 2025, up 11% year-on-year, with losses of £1.3bn. Criminals increasingly use artificial intelligence to mimic voices and create fake profiles, targeting victims via social media and dating apps. Banks urge tech companies to strengthen platform security and monitoring.

June 14, 2026
Android Is Fighting Phone Scams With a New Feature to Prove Who’s Calling Technology

Android Is Fighting Phone Scams With a New Feature to Prove Who’s Calling

Google has introduced a new Android security feature that uses the RCS communication standard to verify caller identity and flag spoofed calls. The feature, rolling out for Android 12 and later, aims to combat AI-powered voice cloning scams by providing a hardware-based confirmation signal between Android phones.

June 14, 2026