iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals

Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals

India's cyber-fraud landscape is pivoting from device takeover to real-time social engineering, with victims executing transfers under live phone guidance. A Biocatch report shows attempted fraud sessions fell 12% but value rose 35%. Meanwhile, the CBI identified over 8.5 lakh mule accounts in 2025, with total complaints linked to Rs 22,496 crore in fraud.

iG
iGEN Editorial
July 27, 2026
Cyber frauds shift to on-call scams and mule networks, Biocatch report reveals

India's cyber-fraud landscape is undergoing a decisive shift, with fraudsters moving away from remote takeover of devices to real-time social engineering, where victims themselves execute transactions under live phone instruction, even as a sprawling network of mule accounts enables the laundering of proceeds.

Shift to Active Call Guidance

According to the July 2026 report by Biocatch (a company that assists global banks on fraud prevention) on digital banking fraud trends, total attempted fraud sessions declined 12% between H2 2025-H1 2026 and the corresponding previous period. However, the value of attempted fraud payments rose 35%, signalling a pivot towards fewer but higher-value attacks.

This change is being driven by a move away from technology-heavy methods such as Remote Access Trojans to more direct psychological manipulation. Detection of such malware fell from 2.5% to 1.7% of fraudulent sessions.

At the centre of this shift is the rise of "active call guidance" frauds, where scammers remain on a phone call with victims and guide them step by step through fund transfers. The share of fraudulent sessions occurring during such calls rose from 3.9% to 4.5%.

Mobile-Led Fraud Surge

This new model is being amplified by a surge in mobile-led fraud. Mobile banking fraud sessions jumped 67%, driven by an 86% rise on iOS and 35% on Android, while web-based fraud fell 10%.

Text messages have emerged as the primary entry point, with SMS-based scams rising 146%, typically used to lure victims into calls where social engineering takes over.

Once engaged, victims are often instructed to enter credentials themselves, reflected in a rise in autofill usage for usernames and passwords, reducing the need for direct system compromise.

Metric Change
Total attempted fraud sessions -12%
Value of attempted fraud payments +35%
Mobile banking fraud sessions +67%
iOS fraud sessions +86%
Android fraud sessions +35%
Web-based fraud -10%
SMS-based scams +146%
Active call guidance share 3.9% → 4.5%
Remote access trojan detection 2.5% → 1.7%

Mule Account Infrastructure

Behind these front-end scams lies a critical but less visible layer: mule accounts, which form the backbone of the fraud economy.

The CBI in 2025 identified more than 8.5 lakh mule accounts across more than 700 bank branches. Overall, 26.5 lakh mule cases were logged nationally, linked to cyber-fraud complaints amounting to Rs 22,496 crore, of which Rs 9,055 crore was blocked or declined through intervention mechanisms. Authorities froze more than 4.5 lakh mule accounts in a year.

Money mules (individuals) are recruited through fake job advertisements, social media, or messaging platforms, often without full awareness of the criminal intent.

These accounts are either newly opened with legitimate KYC or rented from existing account holders. Once activated, they are used for rapid "layering" of funds, moving money across multiple beneficiaries at high speed using instant payment systems such as UPI, before eventual dispersal into cash, cryptocurrency, or international channels.

The "mule-as-a-service" model decentralises operations, allowing fraudsters to bypass banking controls and later consolidate funds, often converting them into cryptocurrency before transferring them abroad.

Implications for Enterprise Security

For enterprise technology decision-makers, the report highlights a critical vulnerability in the financial infrastructure that underpins supply chains and trade payments. The rise of social engineering and mule networks means that even robust technical controls can be bypassed through human manipulation. Businesses should reassess their fraud detection strategies, focusing on behavioural analytics and real-time transaction monitoring, as recommended by Biocatch's findings. The shift to mobile and SMS-based attacks also underscores the need for employee training and multi-factor authentication beyond SMS.


Sources: Business-Today

Keep Reading

Recommended Stories

AI Scammers Outperform Humans in Building Trust, New Study Finds Technology

AI Scammers Outperform Humans in Building Trust, New Study Finds

A new study from four universities tested AI chatbots against human scammers in trust-building phases of pig butchering fraud. The AI outperformed humans, with nearly half of test subjects complying compared to fewer than one in five for humans. The findings highlight the growing threat of AI-powered social engineering, potentially replacing forced-labor workers in Southeast Asian scam operations.

July 30, 2026
World Cup Scams Are Getting Harder to Spot as AI Fuels Surge in Fraudulent Domains Technology

World Cup Scams Are Getting Harder to Spot as AI Fuels Surge in Fraudulent Domains

The 2026 FIFA World Cup has triggered an unprecedented wave of sophisticated scams, with AI-generated websites and phishing campaigns making fraud harder to spot. More than 13,000 FIFA-themed domains were registered in early 2026, with roughly one in 41 identified as malicious. Cybersecurity firms warn that AI is both enabling attackers and powering defenses, but collaboration and human vigilance remain critical.

June 22, 2026
AI fraud hits India's new net users hardest, Amazon trust chief says Technology

AI fraud hits India's new net users hardest, Amazon trust chief says

Amazon's global trust and safety chief Rohan Oommen said AI-powered scams are a major threat to India's first-time online shoppers, whose lower awareness makes them especially vulnerable. Amazon's latest report shows the company removed nearly 300 million fake reviews and took down about 70,000 phishing websites globally last year.

August 4, 2026
Cybercriminals widen net as assessees rush to meet I-T return filing deadline Technology

Cybercriminals widen net as assessees rush to meet I-T return filing deadline

Cybercriminals are exploiting India's income-tax return filing season by sending forged department notices over WhatsApp and setting up phishing sites that clone the official e-filing portal, according to Bengaluru-based security firm CloudSek. The attacks use malware-laden ZIP attachments and fake login pages to steal banking credentials, OTPs and Aadhaar/PAN data.

August 1, 2026