The Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs issued a Saturday advisory that fake courier refund scams using malicious UPI collect requests stole an estimated ₹42 crore in September 2026, with complaints jumping as e-commerce parcel volumes rose ahead of Dussehra. Aditya Banerjee’s security desk reviewed the bulletin, which names spoofed SMS headers mimicking Blue Dart, Delhivery and India Post tracking pages.
Modus operandi
Victims receive messages claiming a festival gift package could not be delivered and must pay a ₹20 “readdressing fee” or confirm a refund. Links lead to phishing sites that trigger UPI collect pop-ups for much larger amounts. Because collect requests display the merchant name field attackers control, victims sometimes authorise ₹25,000 transfers believing they are accepting refunds.
I4C said reporting through the 1930 helpline within the golden hour improved freeze success rates to 38% in pilot banks, still low enough to warrant the national alert.
Geography and targets
Complaint heat maps show spikes in Pune, Hyderabad and the National Capital Region commuter belt—cities with high app-commerce penetration. Elderly recipients of gifts from children abroad were over-represented in case files, as were small-business owners awaiting supplier shipments.
Platform response
NPCI reminded banks to throttle first-time collect requests above ₹2,000 unless the payer had an existing relationship with the VPA. Payment apps rolled additional friction screens on Saturday builds, requiring users to type amounts manually when merchant names contain the word “refund.”
Meta and WhatsApp were asked to accelerate takedowns of shortened URLs hosted on newly registered domains—a recurring pattern in I4C’s September takedown log of 1,140 phishing sites.
Protective steps
Shoppers should track parcels only on retailer apps or courier sites typed directly into the browser. Any SMS demanding immediate payment should be cross-checked with the e-commerce order ID. Banks will not reverse authorised UPI pushes solely because the victim mistyped approval.
With Delhi transport disrupted by protest security, fake “failed delivery” SMS may cite road closures; treat those as social-engineering hooks. Report suspicious VPAs through the Sanchar Saathi portal so telecom operators can block numbers used in collect fraud.
Bank playbook
Major lenders activated weekend war rooms matching collect-request VPAs against mule databases shared through I4C. Accounts receiving more than fifty small credits in an hour face automatic holds pending branch verification.
E-commerce firms pledged to embed anti-phishing tips in shipment SMS, though marketplace sellers using third-party logistics still rely on generic tracking links that scammers imitate.
Victim support
The National Consumer Helpline cross-referred parcel fraud complaints to cyber cells after noticing overlap with fake customer-care calls. Counsellors advise photographing the phishing URL before it is taken down to aid takedown requests.
