fake amazon pay fraud – CyberFrauds.in https://CyberFrauds.in Empowering Digital India Sat, 08 Jan 2022 01:59:36 +0000 en-US hourly 1 https://wordpress.org/?v=6.6.1 214567315 Fraud Alert: Fake Payment Apps https://CyberFrauds.in/fraud-alert-fake-payment-apps/ https://CyberFrauds.in/fraud-alert-fake-payment-apps/#respond Thu, 06 Jan 2022 04:48:36 +0000 https://CyberFrauds.in/?p=358 Over the past 5 years, India has seen an unprecedented growth and acceptance of digital payments through payment wallets and UPI based apps like PayTM, PhonePe, GooglePay, AmazonPay and many more. Along with these, there are many more Bank-based UPI apps like SBI’s YONO and ICICI Bank’s iMobile that also let users make UPI payments to merchants directly from their accounts. In December 2021 alone, there were total 4.56 billion transactions worth ₹8.26 lakh crore (₹8,260,000,000,000) [Source: NPCI Website].

This magnitude of the digital payments has naturally made it lucrative for Fraudsters too to attack unsuspecting customers and merchants alike through a variety of frauds. However, today we talk about one such fraud that is perpetrated through Fake Payment Apps which have come into existence. This is not carried out by some third party on unsuspecting customers, this is a first party fraud carried out by the customers themselves on unsuspecting Merchants.

Modus Operandi

  1. Fraudsters install a Fraudulent Payment app on their phones / devices
  2. After purchases at the store, at the time of making payment, they open this app and pretend to scan the QR Code
  3. They would actually be typing the Name and Phone Number (read from the QR Code display and type it manually while the merchants believe the user is typing amount
  4. The spoof app produces a dummy “Payment Successful screen as displayed below
  5. This screen is showed to Merchant who believes that the payment is successful – especially small-time merchants who are not very technology savvy
Left: Screen on Fraudster’s phone to enter the Merchant and Payment detailsRight: Screen displayed to Merchant making them believe Payment went through

Magnitude of Fraud

Since this Fraud is localized to the Merchants, the Banking System does not come to know about such frauds. The Merchants at best may contact their Acquirer Banks or Wallet Providers to find out why the payments didn’t go through. The Service Providers/Acquirers who have no clue about these payments can’t be of much help and Merchants in turn may be dissatisfied with their Acquirer Bank.

List of Fraudulent Apps

Before I provide a list of such apps, here is a word of caution. OK! make that several sentences

  1. These apps may be legal but the acts perpetrated may be illegal
  2. Spoofing a payment this way is a punishable offense under various sections of Indian Penal Code
  3. Since these apps cannot be distributed through the usual Apple App Store or Google Play Store, they are distributed as .apk installers on Android platform, hence they are potentially unsafe
  4. Such apps could install virus/malware on your phone or compromise data on your phone

Since the publishers of these apps call them as Prank Apps and distributed directly, it is possible that these apps do not come to the attention and scrutiny of Google Platform or the Police Department. It is possible that some of the links beow

  • Spoof PayTM App
  • Google Pay Spoof App
  • Prank Payment App

How to Protect Yourself?

If you are a Merchant or often receive digital payments from different people through such apps as GooglePay, PhonePe, PayTM or AmazonPay, it is important to be vigilant and not be defrauded. Here are some simple steps you can take

  1. Enable and check SMS or in-app notifications for all payments
  2. If you have PayTM Account, install PayTM for Business on Phone/Device and active Sound Alerts
  3. You can also buy a PayTM Soundbox and activate it. Every time there is a successful payment, an announcement happens on the sound box
  4. Check the balance after each transaction. If your app is crashing for some reason (can happen at times), safeguard your interest by following additional measures mentioned below
  5. At shops, ask the customer to show the confirmation once again, observe it closely for any name misspellings or number mistype (since the names and numbers are manually entered in a hurry and under pressure of committing a crime, there is a chance that the values are incorrectly typed
  6. Place the QR codes at places in the shop such that when the customers scan the QR codes through phone, you can see their screen. While this is not always possible due to shop layout, try to make adjustments in the QR code placement or place mirrors at strategic places if your business supports it

While this type of fraud is very difficult to catch, the shopkeepers’ presence of mind can prevent their losses and falling pray to such spurious elements.

Now, have you come across any more such apps? Do you have a better tip or trick to prevent yourself from such frauds? Do let us know by commenting below.

]]>
https://CyberFrauds.in/fraud-alert-fake-payment-apps/feed/ 0 358