
Text-message scams targeting Indian bank customers have experienced a dramatic surge, with fraud affecting Indian banks rising 146% between the second half of 2025 and the first half of 2026 compared with the same period a year earlier, according to BioCatch, a fraud-detection technology company. This increase reflects a strategic shift by cybercriminals who are abandoning voice calls in favor of SMS messages to exploit the trust consumers place in banking alerts. As reported by BioCatch, text messages offer fraudsters a cost-effective way to reach victims instantly, bypassing email filters and creating immediate pressure on recipients.
SMS provides fraudsters with distinct advantages due to its universal reach and integration with legitimate banking communications. According to Srinivas L, joint managing director and CEO of 63SATS Cybertech, "Text is the cheapest way to reach a hundred million people" and works on every phone, appearing alongside legitimate banking messages. The technology enables criminals to create convincing messages in any Indian language at scale using artificial intelligence, while India's high Android penetration makes it easier to distribute malware through sideloaded applications. As noted by Subhashish Bose, director of global advisory at BioCatch, "A text campaign costs next to nothing and reaches victims instantly".
Scammers employ various tactics to create urgency and manipulate victims into sharing sensitive information. According to BioCatch, fake know-your-customer updates and account suspension alerts remain among the most common fraud methods, redirecting users to lookalike banking websites that steal login credentials and one-time passwords. Investment scams have become more sophisticated, promising unusually high returns and directing victims to fake trading platforms that display fabricated profits before blocking withdrawals. Vikram Babbar, partner at EY Forensic & Integrity Services, notes that fraudsters primarily use fear to manipulate victims, often threatening account suspension or fabricating family emergencies. Warning signs include messages that create urgency, requests for OTPs or PINs through SMS, and unsolicited offers for loans or investment materials.
Financial experts emphasize strict verification protocols to combat SMS banking fraud. Prashant Mali, cybersecurity expert, advises that "Banks never ask customers to install remote access applications or APK files to resolve account issues" and warns against scanning QR codes to collect funds. BioCatch recommends that customers verify messages through official customer care numbers and never use information within suspicious messages. Vikram Babbar from EY Forensic & Integrity Services suggests that official mobile banking applications remain the safest channel for customer service requests, as legitimate banking messages generally do not contain links asking customers to update personal information. When in doubt, customers should close suspicious messages and access their bank through official mobile applications or verified customer care numbers.