India witnessed a 146% surge in SMS-based banking scams between the second half of 2025 and the first half of 2026 compared with the corresponding period a year earlier, highlighting a sharp rise in mobile-driven financial fraud, according to a report released by fraud prevention and behavioural intelligence company BioCatch.
The report found that overall mobile fraud sessions increased by 67% during the period, including an 86% rise on iOS devices and a 35% increase on Android devices. In contrast, fraud originating through web browsers declined by 10%, indicating that cybercriminals are increasingly shifting their focus to mobile platforms.
According to Tom Peacock, Director of Global Fraud Intelligence at BioCatch, SMS scams remain highly effective because they exploit a communication channel that users generally trust. Fraudulent text messages are often designed to appear genuine, prompting recipients to act quickly before they have an opportunity to verify the authenticity of the message.
The report, based on proprietary transaction data from BioCatch’s banking customers in India, also recorded a 35% increase in the total value of attempted fraudulent payments. At the same time, the average duration of scam-related phone calls declined by 31%, while the median fraud session length fell by 32%, suggesting that cybercriminals are completing fraudulent transactions more quickly than before.
Peacock said the combination of higher-value fraud attempts and shorter interaction times indicates that scammers are becoming increasingly efficient. He noted that fraudsters are now relying on well-rehearsed social engineering tactics and automated techniques to convince victims and move funds before warning signs become apparent.
The report attributes part of this trend to India’s rapid adoption of the Unified Payments Interface (UPI), mobile banking, e-commerce and online investment platforms, all of which have significantly expanded the country’s digital payments ecosystem. While these innovations have improved financial inclusion and convenience, they have also created more opportunities for cybercriminals to target users.
Despite the increase in the value of attempted fraud, BioCatch observed a 12% decline in the total number of attempted fraud sessions among its customers, suggesting that improved fraud detection and prevention systems may be helping financial institutions block a greater proportion of attacks before they succeed.
Subhashish Bose, Global Advisory Director at BioCatch, said greater collaboration among banks, the Reserve Bank of India (RBI), the Indian Cyber Crime Coordination Centre (I4C) and law enforcement agencies is strengthening India’s ability to combat financial fraud. He added that behavioural intelligence enables banks to continuously assess user activity rather than relying solely on one-time authentication, helping detect suspicious transactions earlier and respond more effectively.
A Researcher at Algoritha Security said SMS phishing, commonly known as “smishing,” continues to evolve as cybercriminals combine fake banking alerts, malicious links and social engineering techniques to steal credentials and authorise fraudulent transactions. Users should avoid clicking links received through unsolicited text messages, verify requests directly through official banking channels and enable multi-factor authentication wherever available.
Cybersecurity experts also advise customers to keep their mobile operating systems and banking applications updated, never share OTPs or banking credentials, and immediately report suspicious messages to their bank and the national cyber crime helpline 1930 or through the National Cyber Crime Reporting Portal if fraud is suspected.
