
As digital payments become an everyday habit, smartphones have transformed into wallets carrying sensitive financial information including UPI accounts. According to reports from NDTV Profit and cybercrime expert Prof. Triveni Singh, this convenience makes them prime targets for cybercriminals operating at industrial scale. The urgency is underscored by recent data showing Indians lost an estimated ₹22,495 crore to cyber fraud in 2025, with complaint volumes jumping 24 percent to roughly 2.81 million cases even as the total amount stolen stayed flat against the previous year. Government data tabled in the Lok Sabha shows UPI-linked fraud alone crossed ₹805 crore in the first eight months of the current financial year, spread across more than 10.64 lakh incidents. Experts caution that these figures likely understate the real picture, since a LocalCircles survey found that roughly one in five UPI-using households has faced fraud, and more than half of victims never filed a formal complaint.
According to NDTV Profit recommendations and cybercrime expert guidance, users should always review app permissions before using any banking or payment applications. The report advises restricting banking or payments apps from accessing contacts, SMS, or camera unless absolutely necessary. This permission management helps prevent unauthorized access to sensitive information stored on the device. As reported by Prof. Triveni Singh, criminals today succeed far more often by exploiting human trust than by breaching technical systems, with fake APK files, screen-sharing requests and phishing links being the most commonly used tools to empty bank accounts. Users should download banking applications only from official app stores, avoid clicking unsolicited links, and independently verify instructions before authorizing any high-value transfers.
As reported by NDTV Profit and confirmed by Prof. Triveni Singh, turning on Face ID or fingerprint unlocking for both the phone and banking app is recommended to prevent unauthorized access. This biometric authentication ensures that even if the phone is stolen, someone other than the legitimate user cannot access banking applications without proper authorization. The report also recommends enabling auto-screen lock by shortening screen timeout from 1 minute to 30 seconds to ensure quick device lock when left unattended. Biometric authentication, whether fingerprint or facial recognition, should be switched on for both the device and individual banking applications, since it adds a layer of protection that a stolen PIN alone cannot bypass. Modern banking apps like Current and Chime now integrate real-time transaction alerts and instant card lock directly into their mobile applications, providing always-on visibility that limits fraud damage.
According to NDTV Profit and cybercrime expert guidance, setting up SMS and email alerts for all debits, credits, and failed login attempts provides instant notification of unauthorized payments or login attempts. The report also recommends checking and reducing daily transaction limits for UPI, internet banking, and ATM withdrawals to minimize potential losses in case of security breaches. Enabling SMS and email notifications for every debit, credit and login attempt allows a user to catch unauthorized activity within minutes rather than days. Additionally, users should ensure two-factor authentication or multi-factor authentication is strictly required for all logins and high-value transactions, using two or multiple steps to prevent unauthorized transactions. Should fraud occur despite these precautions, speed matters more than almost anything else, with immediate reporting through the National Cyber Crime Helpline at 1930 or the National Cyber Crime Reporting Portal significantly raising the odds of freezing a fraudulent transaction before the money moves beyond reach.
As reported by NDTV Profit and confirmed by Prof. Triveni Singh, regularly checking the "Active Devices" or "Linked Devices" section in banking apps is essential for maintaining account security. The report advises immediately logging out of unrecognized devices or web sessions when discovered. Users should also disable screen-sharing and accessibility permissions for untrusted applications, going to phone settings and "Special App Access" to ensure no untrusted apps have full accessibility permissions. Periodically checking the "linked devices" or "active sessions" section of a banking app is equally important, since an unfamiliar device listed there is often the earliest visible sign that an account has already been breached. Additionally, never get tricked into installing malicious apps that request screen-sharing and accessibility permissions, as these are precisely the mechanisms criminals use to watch OTPs and PINs being entered in real time. Modern banking apps now offer features like "linked alerts" that connect both checking and savings accounts, allowing users to review both accounts weekly and catch fraudulent activity before it becomes unrecoverable.
According to NDTV Profit and cybercrime expert guidance, users should avoid accessing bank accounts or making financial transactions on public Wi-Fi networks due to security risks. The report recommends turning off "auto-connect" in Wi-Fi settings to prevent joining unknown networks. Financial transactions should never be conducted over open Wi-Fi, and the auto-connect option should be disabled so a phone does not silently join an unknown network. This network security practice helps protect against potential cyber attacks and unauthorized access to sensitive financial information. Accessibility permissions and screen-sharing tools should never be granted to unfamiliar applications, since these are precisely the mechanisms criminals use to watch OTPs and PINs being entered in real time. Modern banking apps now offer "fee-free banking" with early pay access and overdraft protection up to $200, making these features more accessible while maintaining security standards.