Skip to main content

Clear Cut Magazine

Fake E-Challans, Online Fraud is Tricking Indians


  • Fake e-challan scams are targeting Indians through SMS and WhatsApp.
  • Scammers steal OTPs, banking details and money.
  • Low financial literacy is increasing vulnerability.
  • Victims often struggle to recover their money.
  • Stronger protection and accountability are needed.

A Meerut resident, Ankur Singh, received a WhatsApp message in September 2025 stating that the regional transport office had imposed a penalty on his vehicle. He hit the link. In a few hours, Rs 15.50 lakh- all his lifetime savings- was gone from his HDFC bank account. Singh is one of the victims in a wave of fraud that has now reached the Parliament.

On August 12, 2026, the Ministry of Home Affairs told the Rajya Sabha, in a written reply by Minister of State Bandi Sanjay Kumar, how it is responding to a nationwide wave of fake e-challan frauds. Fraudsters send SMS or WhatsApp messages mimicking genuine traffic challans, route victims to fake portals resembling the government’s own M-Parivahan site, and harvest OTPs and banking credentials — increasingly through malicious APK files that hijack the phone outright.

But, deeper within the same reply is the more glaring fact that the National Crime Records Bureau (which published its latest data for 2024) does not maintain data to reveal: how many fake e-challan cases have been booked? How many have been closed? Or even the total monetary loss for such victims.

The issue that we are talking about, that we’re talking about numbers, is in itself an extremely disheartening truth; last year NCRB’s Crime in India 2024 revealed crimes in India had crossed the 1 lakh-mark, making the total number of cybercrimes a shocking 1,01,928 – up 17.9%, then last year, with over 73% of it being of fraud. Crimes against senior citizens, who were increasingly being defrauded of their lives using impersonation, have seen a 16.9 percent increase. But so far, the citizen-reporting has helped recover amounts worth more than 11,158 crores from 32.8 lakh complaints. Meanwhile, over 2.77 lakh apps, websites, and accounts found illegal since 2021 were also blocked through its Sahyog portal. – Numbers that reflect prevention instead of estimates of loss.

The deeper story is that of uneven access, which has brought hundreds of millions into the digital banking fold with Jan Dhan, Aadhaar-integrated banking, and a thriving UPI, but has taught them, at a much slower pace, how to identify a phishing link. As surveys by the National Centre for Financial Education would indicate, financial literacy among Indian adults is merely 27%, and among rural and women adults, 24% and 21%, respectively. Studies monitoring rural cybercrime reported a 400% spike in cases in rural and semi-urban regions from 2021 to 2024, outpacing metropolitan cities.

The list of reported cases ranges from accounts by shopkeepers, accounts clerks, and salaried employees to those of first-time digital users, not just the financially deprived; however, the scope of available financial and legal recourse is limited. “Technology is not the real concern, as per advocate Ashwini Kumar,” founding the group My Legal Expert, “as much as psychology, where scams work on a familiar brand name, or message tones.

The point at which India fares very poorly is when the post-click actually occurs. Customers can claim zero liability under the 2017 RBI circular, but only if they are victims of a bank’s own failure or of third-party breaches that are reported immediately, something that becomes messy when an innocent victim willingly disclose an OTP to a scammer (which e-challan victims normally do). Indian courts have, predictably, done yet more shrinking: a December order by the Allahabad High Court stated that the zero-liability circular can’t be stretched to redefine a customer’s “self-authored and sanctioned transactions into third-party induced fraud,” so all evidence lies with the victim.

In the United Kingdom, where mandatory “authorised push payment fraud” (the same trick-the-victim-into-paying method used in e-challan frauds) rules paid over £215 million to defrauded account-holders in 2025, with banks now expected to respond within five days for many cases. An independent review said a 50-50 cost share between the banks involved with the payments protected consumers by blocking £73 million in fraud and almost 35,000 cases of deception within its first year of operation. In Singapore’s shared responsibility approach, telecom operators work with banks and bear accountability for scam messages that slip through the filter, which applies well to fraud delivered mostly over text.

Even the Indian Parliament’s own Standing Committee on Finance has recommended before that banks should pay cyber-fraud victims on a provisional basis. At the same time, the matter is being investigated, rather than having them “run from pillar to post.” Although the Money Restoration and Grievance Redressal Modules, implemented since April 2026, hint at that change. However, as long as recovery remains a privilege rather than a right, the burden of India’s e-challan menace will continue to fall on hopeless citizens like Ankur Singh.


Clear Cut Research Desk
New Delhi, UPDATED: August 14, 2026 16:45 IST
Written By: Yatharth Pathak

Share

Leave a Reply

Your email address will not be published. Required fields are marked *