• Home
  • Cover Story
  • The Digital Mirage: When the Annual Sale Becomes a FOMO Trap
Cybercrime in India, festive shopping scams, UPI fraud prevention, 1930 cyber helpline, phishing and fake websites, mule account cybercrime, National Cyber Crime Reporting Portal, I4C suspect registry, Online shopping fraud recovery, Digital payment security

The Digital Mirage: When the Annual Sale Becomes a FOMO Trap

AI Summary

  • Festive Vulnerability: India’s online shopping season acts as a primary hunting ground where fraudsters exploit consumer FOMO through fake websites, phishing tactics, and aggressive countdown timers.
  • Industrialised Crime: Cyber fraud operates as an organised financial infrastructure utilising mule accounts, spoofed logos, and rapid money transfers rather than isolated acts by lone hackers.
  • Defence & Recovery: Quick action through the 1930 helpline and reporting platforms helps reduce losses, avoid secondary refund scams, and combat digital threats.

Convenience has become a vulnerability during the shopping season, driven by fake websites, mule accounts, and the global cybercrime economy.

There is a certain ritualism to the online shopping season in India.

The online shopping season in India has its ritual.

First come the flags. HUGE SAVINGS! Great party. 90% DISCOUNT. The final hours. Just 17 things.

And then the texts… The order needs to be approved. Parcel undeliverable – available for collection. A reward that won’t last long.

We talk. We go to the shop. We pay.

Sometimes we learn the deal wasn’t a deal. He’d been used.

Paradox of India’s Digital Revolution

This is the paradox of India’s digital revolution. Technology has put a marketplace in the hands of hundreds of millions. In a small town, a shopper can buy a phone, book or refrigerator from a trader hundreds of kilometres away. That same infrastructure has also produced a new geography of criminality.

The thief does not need to be outside the house. He needs a domain name, a convincing logo, a payment interface, a stolen database, a mule account – and a WhatsApp message drafted at the right psychological moment.

The “annual shopping scam” isn’t quite annual. It is an industrialised seasonal crime that exploits human behaviour.

Festival of Lies and Deals

India’s festive shopping season is a predictable hunting ground as millions of consumers become more willing to click, pay and take risks all at once.

As the festive season nears, homes – and the calendar of fraudsters who target first-time internet users and older people – are on high alert. The Indian Cybercrime Coordination Centre (I4C) and Amazon India launched #ScamSmartIndia in September 2025.

Phishing is pretending to be a trusted organisation and sending people to fake websites. In its October 2024 advisory, Preventing Online Scams (CIAD-2024-0050), it outlines fake lotteries, job and loan scams, tech-support theatre, and the “digital arrest”, where impersonators pretend to be police on video calls—just a reminder: government agencies don’t conduct official business on WhatsApp or Skype.

Simple formula. First, imitation. A fake website copies the colours, fonts, photos, and even the customer-service language of a real company. Then the hook. Was ₹19,999; now ₹7,999. A ₹60,000 phone is being sold for just ₹29,999.

Scammer and FOMO

It doesn’t mean the consumer is stupid. The scammer is playing on something we all understand: the fear of missing out (FOMO). We don’t have the luxury of time. Stock is sold out. The offer ends tonight. The countdown timer and flashing ‘BUY NOW’ button leave no room for rational thinking.

The bogus site may take your money and run; send you rubbish or collect card details and passwords to use later. In 2019, CERT-In issued an online skimming advisory, CIAD-2019-0026, which said malicious code was inserted on checkout pages or in compromised third-party libraries that serve many shops at the same time.

The shopping scam might not be over once the transaction is complete. Sometimes, the deal is just the beginning.

The scam is a system.

We imagine a lone scammer in a dark room. Reality is more organised. Websites. Domain names. Phishing scripts. Phoney help lines. Database hacked. Mule accounts. Stratified transfers. A slice of crypto. Infrastructure berthed offshore.

The victim discovers a phone number. Investigators could make links.

The Ministry of Home Affairs told Parliament that I4C has operationalised the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) since 2021. It has resolved over 32.80 lakh complaints and saved more than Rs 11,158 crore as of June 30, 2026.

Read more: Rs 11,158 crore. That’s a big change that the unlucky won’t miss. “It’s business.”

The National Cyber Crime Reporting Portal’s official year-on-year figures show where we are headed. The number of complaints related to financial fraud has increased to 6.94 lakh in 2022 (₹2,290 crore) from 2.63 lakh in 2021 (₹551 crore reported). The number increased to 13.10 lakh in 2023 (₹7,465 crore), 19.19 lakh in 2024 (₹22,848 crore) and 24.03 lakh in 2025 (₹22,495 crore). “The data is fluid,” the ministry says.

These reported complaints do not represent a complete census of all cybercrimes in India, and not all are shopping scams. It is easier to report, and more people are reporting. But it’s no longer fringe. It’s becoming an alternative financial system.

Economy’s Mule Account

The crook doesn’t have to handle the stolen money. This can happen through stories of people who were recruited, duped, paid commissions – or who were willing participants. They’re mules.

“On September 10, 2024, I4C launched a Suspect Registry with banks and financial institutions. It now has more than 30.48 lakh suspect IDs. The same registry six months ago had 21.65 lakh identifiers and Rs 9,055 crore. “Crime is growing. So, the machinery is growing.”

The fake site is showing up. The mule account is hidden. The promised refrigerator is a chimaera, and by the time you discover it, the money may have passed through several tiers.

That’s why speed is critical. Not tomorrow. Not after dinner. Now.

1930 Helpline: The Great Race for the Rupee

India’s 1930 helpline exists because cybercrimes are financial crimes at lightning speed. CFCFRMS connects banks, payment intermediaries, telecom operators and police. From April 2026, modules have been added for money recovery and grievances against frozen accounts and liens.

“Fraudulent money transfers do not necessarily need to make people feel ashamed. 1930. Phone. Please inform your bank or payment provider. Save transaction IDs, screenshots, figures, URLs, and messages. You can file a complaint in the National Cyber Crime Reporting Portal.

There is no guarantee of a cure. The longer you wait, the harder it is to get back in.

And 1930 is an intervention number, not some magic refund meter. That’s a crucial distinction because scammers feed off the wound. The second scam is a follow-up to the first: “Sir, your ₹2 lakh can be retrieved. Just pay ₹10,000 as processing charges.” Robbed once, robbed again.

A fake shop is not a cyberwar.

What is APT?

For example, a person who loses ₹30,000 on a fake shopping site is not a victim of an Advanced Persistent Threat (APT). APT is often considered a sophisticated, persistent intrusion attributed to state or state-linked actors for intelligence, disruption or strategic advantage. Cash is demanded in a shopping scam. The ransomware group demands a ransom. Tools can be shared; “Overlap” is not a standard command.

That’s not being soft; that’s journalism.

In March 2024, the United States and the United Kingdom publicly attributed APT31 to activity they associated with China’s Ministry of State Security. Beijing has denied the charge. Kaspersky described 2,026 waves of Silver Fox targeting companies in India and then elsewhere with emails themed around taxes – more than 1,600 malicious emails in the January and February period of the campaign it analysed. No kidding. That does not prove that all fake holiday sites are foreign intelligence operations.

The APT threat is very much real, and CERT-In takes part in international exercises, including the recent APCERT exercises on ransomware and generative AI. Meanwhile, criminal groups can be sophisticated even if they are not state actors. The commercialisation of cybercrime has added capabilities which until now were the preserve of intelligence services.

The dark web is not a secret internet hidden beneath the surface of the regular internet. Tor was created in the 1990s as privacy research at the U.S. Naval Research Laboratory. Later, criminals began using it the same way they use the telephone today. In June 2026, Europol announced it had opened more than fifteen international investigations. And that’s the real story. No basement hooded teens. Financial plumbing.

The Change in 2008

The siren myth says everything changed in 2008. That year China had the largest population of internet users in the world, and on October 31, 2008, the Bitcoin white paper was published. The network itself was launched in January 2009, introduced as cash, not as a criminal currency. Every new door has two sides.

The scammer’s most powerful weapon isn’t technology.

It is psych. You may fear your account will be blocked, your parcel returned, your electricity cut off, the tax department will call, the offer will disappear, or you will be evicted. A phone that costs ₹70,000 is now available for just ₹19,999. Cashback for the click. A refund waiting to be claimed

It’s easier to hack a human than a computer. But a firewall won’t help someone who gives away their password. Two-factor authentication won’t protect the consumer who accepts a fraudulent transaction as a refund. The last battlefield is the mind.

India’s UPI revolution has made payments almost frictionless. And frictionless payments mean instant screw-ups. QR codes can’t determine if the person presenting them is honest. You will need a UPI PIN to authorise payments but not to receive money. You do not have to enter your PIN when withdrawing money. Please do not scan a code when someone asks you to, saying, “Scan this for your refund.” You could be inviting the money to walk out the door.

A credit card creates a new account separate from your main bank balance. For example, the Reserve Bank’s circular on July 6, 2017, allows for zero customer liability in case of third-party breaches if the bank is informed within three working days of the alert. You give out your credentials. The loss will remain your responsibility until it is reported. –no magic bullets. Use your brain. Spot it. Report it quickly.

Lock the Digital Door

Type it yourself on the website. A logo is not a domain name. The trap is one letter changed. Let’s let the faux countdown die. Don’t download any “refund” APKs from WhatsApp. Use different passwords and multi-factor authentication. Device patching: No real banker will ever ask for your OTP. No legitimate executive will ask for your UPI PIN to refund you.

If you’ve been cheated, don’t spend an hour in self-reproach. 1930. Inform the bank. File a complaint on cybercrime.gov.in. Save the evidence. Reset Password. If you have installed any suspicious software, seek help and take the device offline. In case of a genuine seller (non-delivery, defective goods, misleading claims), also contact the National Consumer Helpline (1915) run by the Department of Consumer Affairs. Cybercrime reporting and consumer problem redressal are not mutually exclusive.

The deal we need to reject

We have trained ourselves to believe the internet should make things faster, easier, and cheaper. Convenience costs. The faster the transaction, the less we need to question it. “The more personal the ad, the better somebody might know what we want.” Bad spelling is no longer a defence, with artificial intelligence knocking it out. The machine has learnt to talk like a man. People need to learn to stop.

I’ve seen enough years of technology coming that promises liberation to know that every revolution has a shadow. The printing press multiplied knowledge. It multiplied propaganda—digital payments democratised finance and supercharged financial crime. The answer is not to retreat. It’s reading.

“WhatsApp messages are not identity cards. A blue tick? That’s nothing—no proof of discount. Proof is verification.

The yearly sale is here. You’ll get a ping on your phone. Congratulations! “You’ve been chosen for a special holiday deal.

Maybe you have. Or maybe you haven’t.

Wait. Check. And then tap.

The product is the cheapest thing you can buy in the digital bazaar. The most expensive of all is the illusion of getting a deal.

State-linked cyber-espionage is a separate but serious threat. Online shopping fraud in India is organised and financially sophisticated. That doesn’t prove that foreign APTs are running the festive fake shop. It conflates the two. Speculation. This is where responsible cyber journalism begins.

Endnotes & References

1. Ministry of Home Affairs / Indian Cybercrime Coordination Centre (I4C), Citizen Financial Cyber Fraud Reporting and Management System. Government data released in July 2026 states that more than ₹11,158 crore had been saved through the system across more than 32.80 lakh complaints up to June 30, 2026; 1930 is the dedicated toll-free cyber-fraud reporting helpline.

2. Ministry of Home Affairs, Government of India, National Cyber Crime Reporting Portal and CFCFRMS data. Government figures show the substantial increase in reported financial cyber-fraud complaints between 2021 and 2025 and describe the mechanisms used to identify mule accounts and suspicious identifiers.

3. CERT-In, “Preventing Online Scams”, Advisory CIAD-2024-0050, October 24, 2024. The advisory describes phishing, counterfeit websites, impersonation and other common online scam techniques.

4. CERT-In, “Online Skimming”, Advisory CIAD-2019-0026. The advisory describes attacks against e-commerce sites and third-party libraries designed to capture usernames, passwords and payment-card information.

5. I4C and Amazon India, “ScamSmartIndia”, 2025. The campaign was launched ahead of India’s festive shopping season and focused on consumer awareness concerning online scams and fraud.

6. Indian Express, “Diwali sale scams surge,” October 2025. The report documented fake shopping websites, impersonation of delivery services and unrealistic discounts used to lure consumers during the festive period.

7. Reserve Bank of India, “Customer Protection—Limiting Liability of Customers in Unauthorised Electronic Banking Transactions,” 2017. The RBI framework sets out circumstances in which customers may have zero or limited liability depending on reporting time and the nature of the breach.

8. Department of Consumer Affairs, National Consumer Helpline. NCH 2.0 provides pre-litigation consumer grievance redressal through 1915 and multiple digital channels.

9. CERT-In, “Essential Measures for Industry for Safeguarding Business Operations against Cyber Security Threats”, 2025. CERT-In recommends strong unique passwords, multi-factor authentication, access controls and timely security updates.

10. Tor Project, “History”. Tor’s own historical account traces onion-routing research to the U.S. Naval Research Laboratory in the 1990s, emphasising privacy and anonymity as the original objectives rather than criminal activity.

11. Europol, Internet Organised Crime Threat Assessment (IOCTA) 2024. Europol’s assessment documents the increasing professionalisation and diversification of cybercrime, including online fraud, ransomware, payment fraud and criminal finance.

12. Europol, “Ransomware gangs cut off from EUR 336 million ‘AudiA6’ crypto laundering pipeline,” June 11, 2026. Europol reported that the laundering service was suspected of processing more than €336 million between 2022 and 2025 and was connected to more than 15 international cybercrime investigations.

13. China Internet Network Information Centre (CNNIC), data reported in January 2009. China’s internet population reached approximately 298 million by the end of 2008, and CNNIC reported that China had overtaken the United States as the world’s largest internet population during 2008.

14. Satoshi Nakamoto, Bitcoin: A Peer-to-Peer Electronic Cash System, October 2008. The Bitcoin white paper was circulated on October 31, 2008; the Bitcoin network itself began operating in January 2009. This distinction is important when discussing Bitcoin’s historical relationship with cybercrime.

15. Reuters, “APT31: the Chinese hacking group behind global cyberespionage campaign,” March 2024. The report describes Western government allegations concerning APT31 and its association with Chinese intelligence, while noting China’s rejection of those allegations. �

16. Kaspersky, “SilverFox campaign targeting Indian and Indonesian companies,” April 2026. The research describes a phishing-led APT campaign targeting Indian organisations and demonstrates how social engineering techniques can be incorporated into sophisticated cyber-espionage operations.

17. Ministry of Electronics and Information Technology, Annual Report 2024–25. The report records CERT-In’s participation in cyber drills dealing with APT attacks, supply-chain attacks and AI-enabled cyber threats.

Picture design by Anumita Roy

Leave a Reply

Your email address will not be published. Required fields are marked *

Releated Posts

Digital Tyranny Without Smoke: Silicon Coup and the New Face of Intellectual Plunder

From a WhatsApp chat with Prof Malashri Lal, this DifferentTruths.com essay by Arindam exposes how corporate AI algorithms…

ByByArindam Roy Aug 10, 2026

India’s Silent Education Crisis: Why Access No Longer Means Learning

A hard-hitting account of India’s chronic education failures, institutional collapse, and the rising tide of student protest —…

ByByArindam Roy Aug 3, 2026

The Pulping of Memory: When Algorithms Feasted on the Printed Word

Arindam reflects on the dark reality of AI scraping and industrial book shredding, the destruction of millions of…

ByByArindam Roy Aug 1, 2026

Revolutionising Security: Can AI Finally End Online Fraud?

Arindam explores the critical role of AI in combating online fraud and safeguarding financial security at DifferentTruths.com. AI…

ByByArindam Roy Jul 23, 2026
error: Content is protected !!