A Vadodara timber trader seeking a credit-card limit increase allegedly lost ₹18.87 lakh after fraudsters used a cashback link and OTPs.

Credit Card Limit Upgrade Trap: Vadodara Trader Loses ₹18.87 Lakh

The420 Web Correspondent
6 Min Read

A promise to increase a credit card limit to ₹2 lakh ended with a Vadodara timber trader allegedly losing ₹18.87 lakh from his bank accounts.

The 37-year-old trader from Tarsali told police that the fraud began on July 31, when a caller introduced himself as an Axis Bank employee. The caller allegedly offered to increase his credit card limit and later sent a WhatsApp link offering ₹4,500 cashback.

The trader opened the link and entered banking information. The following day, the caller allegedly returned with a more specific offer: a credit card limit of up to ₹2 lakh.

The case was reported by Gujarati media on August 30, based on the trader’s complaint to Vadodara Cyber Crime Police. Police have registered a case and are investigating the people, phone numbers, WhatsApp accounts and bank accounts allegedly involved.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

According to the complaint, the WhatsApp link opened a page resembling an Axis Bank website. The trader was asked to proceed with the credit-card process and reportedly indicated that he wanted the upgrade.

The next day, the caller allegedly asked for his debit card details. He also requested OTPs, describing them as part of the verification process.

That was the point at which the fraudsters allegedly obtained the information needed to carry out unauthorised transactions.

The Reserve Bank of India has specifically warned about this pattern. Its consumer-awareness material describes fraudsters impersonating banks or financial institutions, offering loan or credit-limit enhancements, directing customers to forms or links and then persuading them to disclose financial credentials and OTPs.

The RBI’s warning is blunt: customers should never share OTPs, PINs or other confidential banking information, even when the person claims to represent a bank.

₹3 lakh transaction exposed a much bigger loss

The trader first noticed something was wrong on August 3, when he saw an unfamiliar ₹3 lakh transaction while checking his banking application.

He then examined his account activity more closely. According to his complaint, transactions between August 1 and August 6 had removed a total of ₹18,87,513 from his accounts.

The alleged fraud also reached his fixed deposits. Two FDs were reportedly closed without his knowledge, after which the proceeds were transferred to other bank accounts.

This is significant because the incident was not limited to a single card transaction. Once the fraudsters allegedly obtained access to the victim’s banking credentials and OTPs, they were able to move money through multiple transactions and access funds held in fixed deposits.

The trader contacted his bank after discovering the transactions and blocked his accounts and debit card. He also tried calling the alleged fraudsters, but the numbers were reportedly switched off.

He subsequently contacted the national cybercrime helpline, 1930, on August 7 and provided details of the phone numbers, WhatsApp accounts, links and bank accounts connected to the alleged fraud.

A familiar scam with a banking twist

The Vadodara case follows a scam pattern that authorities have repeatedly warned about: the criminal does not begin by asking for money. Instead, the first objective is to appear useful and trustworthy.

A credit-card upgrade sounds like a normal banking service. A cashback offer makes the conversation appear even more genuine. By the time the victim is asked for an OTP, the fraudster has already established a false sense of legitimacy.

The RBI has also warned that fraudsters use fake websites and links to collect account and card information. It advises customers to access their bank’s official website or contact the bank directly rather than using links or phone numbers supplied by unsolicited callers.

Axis Bank’s own customer-protection guidance similarly says customers should not share account details, card numbers, PINs or CVVs over calls, email or other communication channels. It also advises customers to report unauthorised electronic transactions immediately and block a card or account when suspicious activity is detected.

The case also comes amid other major cyber fraud complaints in Vadodara. On August 31, another businessman and his mother allegedly lost ₹1.53 crore in a separate scam involving people impersonating bank and police officials.

For investigators in the ₹18.87 lakh case, the next challenge is tracing where the money went after the initial transfers. Police are examining the transaction trail and the accounts that allegedly received the funds, while also trying to identify the people behind the impersonation.

What this means for you: A bank employee will not need your OTP, PIN or CVV to “upgrade” your credit card. If an unsolicited caller offers a limit increase or cashback, end the call and verify the offer through your bank’s official app, website or customer-care channel.

Stay Connected