Cyber Scammers' New Tactic: Draining Accounts Without Links or OTPs, Then Issuing Threats
Cyber fraudsters are now stealing money without phishing links or OTPs and then threatening victims to withdraw complaints.

Cybercriminals Evolve Tactics, Targeting Bank Accounts Directly
The realm of cybercrime is continuously expanding, with criminals now directly targeting bank accounts. Recent incidents reveal fraudsters successfully siphoning funds without victims clicking any links or sharing One-Time Passwords (OTPs).
These perpetrators are also exerting psychological pressure on victims by threatening them to withdraw complaints or refrain from reporting to the police. This trend indicates that cybercriminals are not just focused on financial loss but are actively trying to prevent legal action by instilling fear.
Advanced Techniques Used by Cyber Scammers
Experts suggest these criminals employ various sophisticated techniques. These can include the misuse of the Aadhaar Enabled Payment System (AePS), the deployment of malware, SIM or device cloning, and the utilization of stolen banking data.
In most such cases, account holders realize the fraud only after the money has been debited from their accounts. This situation causes profound shock and anxiety for victims, especially when they are also threatened against pursuing legal action.
Financial Fraud Through AePS Misuse
The Aadhaar Enabled Payment System (AePS) facilitates banking transactions using Aadhaar numbers and biometric authentication. If cybercriminals manage to breach an individual's essential information and authentication process, they can execute unauthorized transactions.
A key characteristic of AePS fraud is that it does not require the victim to click on any link or share their OTP. This type of fraud directly targets the customer's identity verification mechanism.
Growing Threats via Malware and Cloning
Another prominent technique employed by cybercriminals is the use of malware. They attempt to install malicious software (malware) onto the victim's mobile or other digital devices.
This can occur through downloading suspicious apps, opening unknown files, or installing software from untrusted websites. Once malware is installed, it can steal personal and financial information or conduct unauthorized transactions. Banking services can also be targeted through SIM or device cloning, where criminals obtain new SIM cards using the victim's identity or replicate the functionality of existing devices.
Post-Fraud Threats: A New Stratagem
A particularly disturbing aspect of recent cyber fraud cases is the emergence of threatening phone calls received by victims after the fraud. In these calls, criminals warn victims to withdraw complaints, not report to the police, or face severe consequences if they do not cooperate.
Experts believe that instead of succumbing to such threats, victims should immediately seek legal and banking assistance. The objective of these threats is to intimidate victims into suppressing the case and avoid their identities being exposed.
Immediate Action: Complain at 1930 and Inform Your Bank
If unauthorized transactions have occurred from your bank account, do not waste a single moment. Immediately register your complaint at the national cyber helpline number 1930.
You can also file an online complaint through the National Cybercrime Reporting Portal (www.cybercrime.gov.in). Registering a complaint early significantly increases the chances of stopping suspicious transactions or taking action on the further movement of the siphoned funds.
Concurrently, as soon as you become aware of funds being debited from your account, immediately inform your bank's customer care or the relevant branch. It is also mandatory to provide a written complaint regarding unauthorized transactions. Request the bank to take necessary steps to secure your account, debit/credit card, internet banking, UPI, and other related services promptly.
Block Threatening Numbers and Preserve Evidence
If fraudsters call you to pressure you into withdrawing your complaint, avoid arguing and do not share any of your personal or financial information. Carefully preserve all evidence, including the calls made, messages sent, WhatsApp chats, and any other available proof.
Subsequently, immediately block such numbers. It is crucial to include these threats in your police complaint, as it highlights the seriousness of the case.
Importance of a Written Police Complaint
Victims must file a detailed written complaint at their nearest cyber police station or their local police station. Providing a bank statement, the exact date and amount of the transaction, suspect mobile numbers, call records, messages, and all other digital evidence will aid the police investigation and expedite action.
Precaution is the Best Defense
The most effective way to avoid cyber fraud is to exercise caution. Regularly check your bank account transactions and do not overlook any unauthorized activity, however minor.
Avoid installing any unknown or suspicious apps on your mobile phone. Never share sensitive banking information, such as passwords, PINs, OTPs, or CVVs, with anyone, regardless of how they call or message you. Always refrain from providing confidential financial information in response to any suspicious call or message.
Withdrawing complaints due to threats after cyber fraud is not a solution; it only emboldens criminals. Prompt reporting, immediate notification to the bank, and filing an effective complaint with the police are the strongest protective measures for victims in such cases.
