If a mobile phone screen suddenly freezes after clicking an advertisement or an unfamiliar link, treating it as just a technical glitch could prove costly. Cybercriminals are increasingly using alleged technical problems as a tool for fraud.
Fake error messages, impersonation of customer support representatives and suspicious mobile applications are being used to frighten users and gain access to their devices and banking information.
Why a Frozen Screen Could Be a Warning Sign
Cybersecurity experts say fraudsters do not necessarily need to break the core security of the Unified Payments Interface, or UPI. Instead, they may exploit weaknesses around the mobile device, user information, authentication process and transaction flow.
A frozen screen can sometimes be part of a larger fraud attempt designed to panic users and make them follow instructions given by criminals.
How does the fake technical problem begin?
Fraudsters may reach users through social media advertisements, messages or unfamiliar links. After a link is opened, a fake error message may appear or the phone may temporarily stop responding normally.
The fraudster may then contact the user while posing as an employee of a bank, technical support service or another service provider.
The victim may be told to download an application to resolve the alleged problem. Such apps can be presented as tools for claiming a reward, receiving cashback, completing verification or accessing a service.
In reality, suspicious applications may contain capabilities that can be misused to monitor or control parts of the device.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Why do app permissions increase the risk?
Suspicious applications may request access to messages, notifications and calls. If users grant such permissions without carefully checking them, fraudsters may attempt to access sensitive information.
In some cases, Android accessibility features and device-control permissions may be misused to monitor activity displayed on the screen or attempt actions on behalf of the user.
Banking information, OTPs and other authentication details can potentially be exposed during such attacks.
Fraudsters may also persuade victims to install screen-sharing or remote-control applications, allowing them to observe activity on the device in real time.
Do fraudsters need to break UPI security?
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said fraudsters do not always need to compromise the underlying security of UPI to successfully carry out a scam.
Instead, criminals can focus on manipulating users into voluntarily sharing sensitive information or approving transactions.
According to Singh, social engineering plays a significant role in such fraud. Criminals may create a sense of urgency by claiming that a technical problem has occurred and then persuade users to enter an OTP, banking credentials or UPI PIN, or approve a transaction.
This means that establishing whether authentication occurred may not always tell the complete story. The circumstances under which the authentication was obtained can also be important.
How can a fraudulent payment appear genuine?
One of the major challenges in such cases is that a payment may technically appear to have been authenticated by the user.
If a fraudster manipulates the victim into entering a UPI PIN or approving a transaction, the payment may resemble a normal authorized transaction.
Screen-sharing and remote-control applications can further increase the risk by allowing criminals to monitor activities on the device and guide victims through subsequent steps.
What should users do if their phone screen freezes?
If a phone starts behaving abnormally after opening an unfamiliar advertisement or link, users should avoid entering banking or payment information.
Turning off mobile data and Wi-Fi can be an immediate precaution. Users should not download an application at the direction of an unknown caller or allow an unfamiliar person to remotely access or view their screen.
Recently installed suspicious applications should also be checked and unnecessary permissions revoked.
Accessibility permissions and device-administration access should be reviewed, particularly for applications that users do not recognise or no longer need.
What if banking information may be compromised?
If there is any possibility that banking information or payment credentials have been exposed, users should immediately contact their bank through an official channel and review recent transactions.
Necessary passwords and credentials should be changed from a secure device where appropriate.
In cases involving financial cyber fraud, victims should report the incident immediately by calling the national cybercrime helpline at 1930.
Why device security matters as much as the UPI PIN
As digital payments become increasingly common, protecting only the UPI PIN or OTP may not be enough. The security of the mobile device, application permissions and the user’s response to suspicious instructions are equally important.
Users should be particularly cautious if someone claiming to represent a bank or service provider asks them to install a remote-control application, share their screen or disclose their UPI PIN to resolve an alleged technical problem.
Such requests should be treated as a serious warning sign.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.