Online Banking Fraud: Account Takeover and How Banks Stop It
The bank's systems usually work fine. The fraudster logs in with real credentials, or the customer is talked into paying.
Online banking fraud is any theft through a customer's internet banking or mobile banking access. In almost every case the bank's systems work exactly as designed: the fraudster logs in with real credentials, or the customer is talked into approving the payment.
That is why the IIBF syllabus treats it under Online Transactions rather than hacking. The fight is over credentials, devices and alerts, and the branch officer who knows how takeovers happen is often the first person who can stop the second transaction.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
How Accounts Are Taken Over
Credential phishing
What happens
A fake bank page or 'KYC update' link captures the user ID, password and OTP as the customer types them
Typical red flag
Login from a new device minutes after a link was clicked
Vishing for OTP
What happens
A caller posing as the bank or a KYC desk asks the customer to 'confirm' an OTP
Typical red flag
OTP read out on a call, then a new beneficiary added
Remote access apps
What happens
The customer installs a screen-sharing app for 'support', and the fraudster operates the banking app directly
Typical red flag
Session from the customer's own phone, but behaviour unlike theirs
Banking trojan
What happens
Malware on the phone reads SMS OTPs or overlays a fake login screen
Typical red flag
Sideloaded app, OTPs being consumed without the customer seeing them
SIM swap or call forwarding
What happens
The fraudster gets a duplicate SIM, or tricks the customer into activating call forwarding, so OTPs and bank calls reach them
Typical red flag
Customer's phone loses network or stops receiving bank calls
| Method | What happens | Typical red flag |
|---|---|---|
| Credential phishing | A fake bank page or 'KYC update' link captures the user ID, password and OTP as the customer types them | Login from a new device minutes after a link was clicked |
| Vishing for OTP | A caller posing as the bank or a KYC desk asks the customer to 'confirm' an OTP | OTP read out on a call, then a new beneficiary added |
| Remote access apps | The customer installs a screen-sharing app for 'support', and the fraudster operates the banking app directly | Session from the customer's own phone, but behaviour unlike theirs |
| Banking trojan | Malware on the phone reads SMS OTPs or overlays a fake login screen | Sideloaded app, OTPs being consumed without the customer seeing them |
| SIM swap or call forwarding | The fraudster gets a duplicate SIM, or tricks the customer into activating call forwarding, so OTPs and bank calls reach them | Customer's phone loses network or stops receiving bank calls |
The Call-Forwarding Trap
In December 2025 the Indian Cybercrime Coordination Centre (I4C) warned of fraudsters posing as courier agents who ask people to dial a short code beginning *21* followed by a number. That code switches on call forwarding, so the bank's verification calls and voice OTPs go to the fraudster. Customers should never dial a code a stranger sends them.
What RBI Requires Banks to Do
RBI's Digital Payment Security Controls Directions, reissued for commercial banks on 31 July 2026 in place of the 2021 Master Direction, set the baseline. They came after IIBF's 30 June 2026 cut-off, so papers up to February 2027 are set against the direction it replaced. The main points for online and mobile banking:
- check_circleMulti-factor authentication for payments and fund transfers, with at least one factor dynamic or non-replicable (an OTP, device binding, biometrics or a hardware token).
- check_circleAlerts and multi-factor authentication for every payment, every beneficiary added, changed or deleted, and every change to transfer limits.
- check_circleA cap on failed login attempts, after which access is blocked, plus a secure process to reactivate it.
- check_circleInternet banking: a virtual keyboard option, automatic logout after inactivity, and stronger checks such as adaptive authentication or server-validated CAPTCHA against brute-force attacks.
- check_circleMobile banking: the app must be bound to the device, the customer must be told whenever a new device is registered, and the app should detect remote-access apps and block login while they run.
- check_circleFraud monitoring rules for velocity (many transfers or new beneficiaries in a short time), especially on accounts that have never used digital banking before.
- check_circleA button inside the app or internet banking to mark a transaction as fraudulent, so the bank hears about it at once.
Quick practice on banking operations. No signup.
SMS OTP Is No Longer the Only Option
RBI's Authentication Mechanisms Directions, 2025 note that the payments ecosystem had mostly used SMS OTP as the second factor. From 1 April 2026, banks must still use at least two distinct factors, but they may choose others: device binding, biometrics, PKI tokens or app-based approval. Issuers may also run risk-based checks, adding extra steps when location, device or behaviour looks unusual.
One rule matters for liability: if a loss arises from a transaction authenticated in a way that does not comply with these directions, the issuer must compensate the customer in full.
Terms the Exam Uses
- Account takeover
- A fraudster gains control of a genuine customer's banking login and transacts as that customer.
- Man-in-the-browser
- Malware inside the customer's browser that alters a transaction (amount or payee) after the customer enters it but before it reaches the bank. RBI names it, along with man-in-the-middle attacks, as a risk banks must design against.
- Device binding
- Tying the banking app to one specific handset and SIM, so stolen credentials alone cannot be used from another phone.
- Adaptive authentication
- Choosing how strictly to verify a login or payment based on its risk, for example asking for an extra factor from a new device.
- Money mule
- An account, often rented or opened with borrowed KYC, used to receive and move stolen funds.
How the IIBF Exam Tests This
Expect scenario MCQs: a customer shares an OTP and money moves, so which attack was it, and which control would have stopped it? The common trap is choosing a detective control (an alert) when the question asks for a preventive one (multi-factor authentication or device binding). Also know the IT Act sections in play: identity theft (section 66C) and cheating by personation using a computer resource (section 66D).
FAQs
What is online banking fraud?expand_more
Any fraudulent transaction through a customer's internet or mobile banking access, usually after the fraudster obtains the login details and OTP by phishing, a phone call, malware or a SIM swap.
What should a customer do first after an online banking fraud?expand_more
Report it to the bank immediately through any 24x7 channel so further debits are blocked, then report it on the National Cyber Crime Helpline 1930 or cybercrime.gov.in. Speed matters both for recovering money and for how much of the loss the customer bears.
Which IT Act section applies to online banking fraud?expand_more
Usually section 66C (fraudulent use of another person's password or unique identification feature) and section 66D (cheating by personation using a computer resource). Each carries up to three years' imprisonment and a fine of up to ₹1 lakh.
Is SMS OTP still mandatory for online banking in India?expand_more
No specific factor is mandated. RBI's 2025 authentication directions require at least two distinct factors, one of them dynamic for most transactions, and let banks use alternatives to SMS OTP such as device binding or biometrics.
Next steps
- UPI Fraudarrow_forward
- MFAarrow_forward
- Phishing, Vishing, Smishingarrow_forward
- Customer Liabilityarrow_forward
120 questions, 2 hours, scored instantly.
