A fake customer care scam often begins with something completely genuine: a failed payment, delayed refund, faulty appliance, cancelled booking or locked bank account. The victim wants help, searches for a support number and makes the call themselves.
That is precisely what makes the fraud dangerous.
India’s National Cyber Crime Reporting Portal has warned that criminals manipulate customer-care details on search engines, online listings and social media, creating fake helplines that appear to belong to banks, financial institutions, shopping platforms and other companies. Once a victim calls, the fraudster impersonates support staff and attempts to obtain money, banking credentials or control of the victim’s device.
The scam is not limited to obviously suspicious calls from strangers. A fake number can appear exactly where someone expects to find legitimate help.
The420.in documented one such pattern in Varanasi, where at least 114 people were allegedly cheated of nearly ₹1.50 crore after searching online for contact numbers. Victims were allegedly directed towards fake listings, websites and social-media profiles before being asked for credentials or remote access.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
How Does a Fake Customer Care Scam Work?
The scammer waits for you to search for help
Unlike many phishing attacks, customer-care fraud can reverse the usual relationship between scammer and victim.
The fraudster does not necessarily contact you first. Instead, criminals can publish fake support pages, manipulate contact information or place fraudulent numbers where people searching for assistance may find them. The I4C advisory specifically warned about manipulation of search-engine results, Google Maps information and social-media customer-care details.
A high position in a search result should therefore never be treated as proof that a phone number belongs to the company named beside it.
The caller is given a believable support script
Once contacted, the fake executive may behave like an ordinary support agent. They may discuss a refund, delivery problem, card issue, failed booking or service complaint.
The next request is the dangerous part.
The fraudster may ask for an OTP, card number, CVV, banking password or PIN. In other versions, the victim is directed to click a link, complete a form or install an application supposedly required for verification or troubleshooting.
Union Bank of India’s cyber-awareness material describes the same pattern: criminals create or alter customer-care information online and then trick callers into disclosing personal or banking information or installing malicious or remote-access applications.
A ₹1 or ₹10 “verification” can become the entry point
Small payments can make a request appear harmless. A fake agent may say a token transaction is needed to register a complaint, verify an account or release a refund.
The amount is not the real issue. The victim may instead be approving a payment request, exposing credentials, entering details into a phishing page or giving the fraudster another route into the account.
The420.in reported a Prayagraj case in which a teacher allegedly contacted a customer-care number found through an online search and was asked to pay a ₹25 service charge. She later reported four transactions totalling nearly ₹9 lakh from her account.
The Most Common Fake Customer Care Tricks
A fake support number is only the beginning. The theft itself can take several forms.
OTP, PIN and card-detail theft: A caller asks for an OTP, UPI PIN, CVV, password or other secret credential under the pretext of verifying the complaint. These details should not be disclosed to someone claiming to provide customer support.
Remote-access or screen-sharing fraud: The victim is instructed to install software that allows another person to view or control the phone. Legitimate remote-support software can become dangerous when access is handed to an unknown caller. The420.in has separately explained how scammers misuse screen-sharing and remote-access tools to observe banking activity and authentication information.
Fake refund and QR-code fraud: A scammer claims that scanning a QR code or approving a payment request is necessary to receive money. A request that actually authorises a debit should not be mistaken for a refund.
Malicious links and forms: A fake executive sends a page that resembles a bank, airline, courier company or merchant site and asks the victim to enter financial information.
Social-media support impersonation: A user complains publicly about a company. A fraudulent account quickly replies or sends a direct message, offers “support” and moves the conversation to a phone number or messaging app. I4C has specifically warned that criminals monitor online complaints and use fraudulent contact information to approach people seeking help.
How to Verify a Customer Care Number Before Calling
The safest rule is simple: verify the channel, not the person answering it.
Start with the company’s own mobile application or type its official website address yourself. For a bank, also check the number printed on your card, passbook, account statement or other official material.
Do not authenticate a support number merely because it appears in a search result, map listing, sponsored result, social-media comment, WhatsApp message or online forum.
If somebody contacts you after you posted a complaint online, close that conversation and independently open the company’s official app or website. Contact support from there.
India’s cybercrime advisory tells consumers to use customer-care numbers from official bank or company websites and not to disclose card numbers, CVV, ATM PINs, passwords or OTPs.
The National Cyber Crime Reporting Portal also now provides a Report Suspect facility for suspicious phone numbers, WhatsApp or Telegram handles, URLs, email addresses, SMS identifiers and social-media URLs.
Seven Red Flags During a Customer Care Call
Treat the interaction as suspicious if the supposed support executive asks you to share an OTP, PIN, CVV or banking password; install a remote-control application; share your screen; scan a QR code or approve a payment request to “receive” money; transfer funds to a “safe”, “temporary” or “verification” account; enter banking credentials on a link sent through WhatsApp or SMS; or refuses to let you end the call and verify the request through the organisation’s official number.
The safest response is to disconnect and start again through an independently verified official channel.
What Should You Do If You Have Already Sent Money?
Speed matters after a financial cyber fraud, but there is no legitimate guarantee that reporting within a particular number of minutes will recover the money.
First, contact your bank, card issuer, UPI-linked bank or wallet provider through its official fraud-reporting channel. Ask it to register the fraudulent or disputed transaction and preserve the complaint/reference number.
Then call 1930, India’s national cybercrime helpline for rapid reporting of financial cyber fraud, and report the incident through the National Cyber Crime Reporting Portal at cybercrime.gov.in. The Ministry of Home Affairs says CFCFRMS was created to enable rapid reporting and prevent fraudsters from siphoning away reported funds.
As of June 30, 2026, the government said more than ₹11,158 crore had been “saved” across more than 32.80 lakh complaints through CFCFRMS. “Saved” should not be read as “already refunded”. Money that is intercepted or placed on hold may still require investigation, verification and the applicable restoration process before it can be returned.
For a detailed explanation of what happens after reporting, see The420.in’s guide to Cybercrime Helpline 1930 and the money-recovery process.
Preserve the scammer’s phone number, customer-care listing, webpage URL, advertisement, chats, emails, QR codes, screenshots and transaction records. Keep the UTR, RRN or transaction ID where available. The NCRP advises complainants to provide as much supporting information as possible because it can assist the investigating police officer.
If remote access was installed or credentials were disclosed, secure your banking and email accounts through a clean device and official channels. Revoke unnecessary device permissions, remove suspicious applications and change compromised credentials.
Does Two-Factor Authentication Stop Customer Care Fraud?
Not by itself.
RBI’s Authentication Mechanisms for Digital Payment Transactions Directions, 2025, which required compliance from April 1, 2026, retained a minimum two-factor approach while allowing authentication methods beyond SMS OTP. The framework also allows issuers to apply additional risk-based checks.
Two-factor authentication makes unauthorised access harder, but social engineering can turn the victim into part of the authentication process. A scammer may persuade someone to disclose a factor or approve a transaction themselves.
That is why an OTP should not be treated as a harmless code simply because the caller already knows your name, account number or complaint details.
Will Your Bank Refund Money Lost to Fake Customer Care Fraud?
There is no automatic yes or no. The answer depends on how the transaction occurred and which liability rules apply.
RBI’s framework for unauthorised electronic banking transactions gives customers zero liability in specified situations, including a bank’s contributory fraud or deficiency and certain third-party breaches reported within three working days. But where the loss is caused by customer negligence, such as sharing payment credentials, the customer bears losses occurring before the bank is notified. The circular also requires eligible shadow reversal within 10 working days and places the burden of proving customer liability on the bank.
That framework specifically addresses unauthorised electronic transactions. A fake customer-care case in which the victim was deceived into deliberately authorising a UPI transfer or other payment may raise a different question from a transaction executed without the customer’s authority. The precise classification depends on the facts and the applicable bank and RBI rules.
Do not assume that entering an OTP or authorising a transaction makes reporting pointless. Inform the bank and 1930 immediately and let the transaction be formally examined.
If a grievance against an RBI-regulated entity remains unresolved, the Reserve Bank Integrated Ombudsman Scheme, 2026, effective July 1, provides a cost-free escalation mechanism. A customer must ordinarily approach the regulated entity first. A complaint may then be filed through RBI’s Complaint Management System if there is no response within the applicable period, generally 30 days, or if the response is unsatisfactory, subject to the scheme’s maintainability and limitation requirements.
Which Indian Laws Can Apply to a Fake Customer Care Scam?
The exact sections depend on the conduct proved during investigation.
Under the Information Technology Act, 2000, Section 66C deals with identity theft involving fraudulent or dishonest use of another person’s electronic signature, password or other unique identification feature. Section 66D covers cheating by personation using a communication device or computer resource.
Under the Bharatiya Nyaya Sanhita, 2023, which replaced the IPC framework from July 1, 2024, Section 318 deals with cheating and Section 319 with cheating by personation.
Older online guides that continue to treat IPC Sections 419 and 420 as the default current provisions should therefore be updated for offences governed by the post-July 2024 criminal-law framework.
The same applies to procedure. The Bharatiya Nagarik Suraksha Sanhita, 2023 replaced the CrPC from July 1, 2024. Police decide the applicable provisions on the evidence and circumstances of each complaint.
The 2026 amendments to the IT Rules are also sometimes mentioned broadly in cybercrime coverage. Those amendments significantly address intermediary duties concerning synthetically generated information, including AI-manipulated content. They should not be presented as the principal criminal provision for an ordinary fake customer-care number scam.
Likewise, the Digital Personal Data Protection framework should not be casually cited as though every provision of the 2025 Rules became operative at once. MeitY published a phased enforcement framework alongside the final DPDP Rules.
Why Fake Support Numbers Remain Effective
The scam exploits intent more than technical sophistication.
A person searching for customer care already has a problem and wants it solved quickly. The fraudulent number appears at exactly that moment. Because the victim initiated the call, the interaction can feel safer than an unsolicited message.
That psychological advantage disappears once consumers stop treating search visibility as identity verification.
The critical habit is to break the chain before calling: open the company’s official app, type its official website address, or use contact information already supplied by the institution.
When money has already moved, the priority changes. Stop further access, notify the financial institution, call 1930, complete the NCRP complaint and preserve the evidence.
FAQ: Fake Customer Care Scams
What is a fake customer care scam?
It is a fraud in which criminals impersonate a company’s support staff, often using bogus customer-care numbers, fake webpages, manipulated listings or social-media accounts. The objective may be to obtain money, payment credentials or access to the victim’s device.
How can I check whether a customer care number is genuine?
Use the company’s official app, type its official website address directly, or use contact details printed on official bank or company material. Do not rely on search ranking, map listings or social-media replies alone.
Can a bank executive ask for my OTP, UPI PIN or CVV?
Do not disclose these secret payment credentials to a caller claiming to be customer support. Government and banking cyber-awareness material specifically warns against sharing OTPs, PINs, passwords and CVVs.
Do I need to scan a QR code to receive a refund?
Be suspicious of anyone telling you that approving a payment request or scanning an unknown QR code is required simply to receive money. Verify the refund process through the company’s official channel before taking any payment-related action.
What should I do immediately after losing money?
Notify your bank or payment provider, call 1930, report the case on the National Cyber Crime Reporting Portal and save all transaction and communication evidence.
Does calling 1930 guarantee my money will be refunded?
No. The system is designed for rapid reporting and tracing or stopping fraudulent funds where possible. The government’s figure for money “saved” through CFCFRMS should not be interpreted as a guarantee of recovery in every complaint.
Will my bank refund a payment I made after speaking to a scammer?
It depends on the facts. RBI has specific liability protections for unauthorised electronic transactions, but a transaction personally authorised after deception may require a different assessment. Report it immediately rather than assuming either that refund is guaranteed or that recovery is impossible.
The420 Insight
Save your bank’s genuine fraud-reporting number before you need it, preferably from its official app, website or card. Bookmark the National Cyber Crime Reporting Portal as well. If a support call ever turns into a request for an OTP, remote access, QR scan or transfer, disconnect and verify the request independently.
If money has already moved, do not spend the first hour trying to understand every detail. Contact your bank and 1930 first, then preserve and organise the evidence.
About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics