
Credit card fraud India 2026 can begin at a street ATM, a shop counter, a fake payment page, or a convincing call from someone who already knows your name and bank. The physical card may never leave your wallet. A stolen number, expiry date and CVV can be enough to attempt online purchases, while copied magnetic-stripe data and an observed PIN can support counterfeit-card misuse.
The safest response is speed. If an unfamiliar debit or purchase OTP appears, lock the card in the official banking app before investigating. Then call the issuer through a verified number, dispute the transaction and preserve every alert. This guide explains how card and debit card fraud India schemes work, the cases behind the warning, and the exact controls to use.
Suspicious card transaction happening now?
Lock the card in the official bank app, call the number printed on the card, and call 1930 if money has moved. File at cybercrime.gov.in. Never call a number pasted near an ATM or sent in the suspicious message.
The Scale of Card Fraud in India in 2026
The strongest current national measure is broader than card cloning alone. The RBI Annual Report 2024 to 2025 recorded 13,516 bank-reported fraud cases in the card/internet category involving ₹520 crore. Card and internet fraud made up 56.5 percent of reported fraud cases by number in that table.
Those figures need context. RBI's table covers frauds of ₹1 lakh and above reported during the year. A case may have occurred earlier, the amount involved is not necessarily the final loss, and thousands of small consumer disputes are outside that table. It therefore shows the weight of digital-payment fraud inside bank reporting, not the total number of Indians who experienced card misuse.
RBI has reduced some risk through EMV chip and PIN cards, additional authentication for domestic online payments, tokenisation, alerts for every card transaction, and customer controls for ATM, POS, online, international and contactless use. Fraudsters respond by targeting the person, merchant page or weaker part of the transaction chain.
The 6 Methods Scammers Use to Steal Card Details in India
Method 1: ATM Fraud India and Card Skimming India 2026
Card skimming India 2026 typically uses a reader placed over or inside an ATM card slot to copy magnetic-stripe data. A pinhole camera, false keypad or person watching nearby captures the PIN. Criminals can encode copied data onto another card and attempt withdrawals or POS transactions. EMV chips make simple cloning harder, but the physical setup remains a warning because terminals may still expose stripe data or criminals may combine skimming with card trapping and social engineering.
For ATM fraud India, inspect the slot and keypad before use. If a part looks loose, bulky, mismatched or unusually fixed, stop. Cover the keypad fully with your free hand. Prefer a monitored ATM inside a bank branch. If the machine retains the card, stay at the kiosk and call the official bank number from its website or app, not a sticker beside the machine.

Method 2: Online Phishing and Fake Payment Pages
A phishing message says a bill failed, reward points will expire, KYC is incomplete, or a parcel needs a small fee. The link opens a cloned bank or merchant page that records the card number, expiry date, CVV and sometimes an OTP. A padlock only means the connection is encrypted. It does not prove the site belongs to the bank.
Open the merchant or bank independently. Check the full hostname, not just its logo. For a new seller, follow the online shopping fake site checks and use the RakshaAI website safety checker before entering any payment information.
Method 3: Card Not Present or CNP Fraud India
CNP fraud India means the physical card is not presented. The criminal attempts an online, telephone or recurring transaction using stolen credentials. Domestic online card payments generally require additional authentication, but overseas merchants and permitted recurring arrangements can behave differently. This is why an international charge can appear without the OTP pattern a cardholder expects.
Disable international and online transactions when they are not required. Set a low online limit, enable every alert and review recurring merchants. If a ₹1 or other small verification charge appears, do not wait for a larger debit before acting.
Method 4: POS Terminal Skimming and Card Cloning in India
At a shop, restaurant or fuel station, a dishonest operator may take the card out of sight, swipe it through an extra reader or use a tampered terminal. In a wider card cloning India chain, stolen ATM data can also be encoded onto cards and monetised through POS machines controlled by the network.
Keep the card in sight, ask for the terminal to be brought to you, check the amount on its screen and cover the PIN. Contactless or tokenised wallet payment reduces how often a merchant handles the physical card, but always verify the displayed amount before tapping.
Method 5: Vishing and Fake Bank Calls
A caller claims to raise the credit limit, reverse an annual fee, redeem points or stop a suspicious transaction. Stolen customer data makes the pitch specific. The caller then sends a link or asks for the card number, CVV, PIN or OTP. A genuine bank employee does not need your PIN, CVV or transaction OTP over a call.
End the call. Open the official app or dial the number printed on the card yourself. Caller ID can be spoofed, and knowing your bank or last four digits is not proof of authority.
Method 6: Data Breach or Compromised Merchant Checkout
Card data can be exposed when a merchant, processor or checkout page is compromised. CERT-In describes online skimming in which attackers inject JavaScript sniffers into e-commerce sites or third-party software to collect card and billing data. RBI's card-on-file tokenisation rules reduce stored-card exposure by replacing actual card data with a merchant-specific token.
Prefer tokenisation at a trusted merchant, do not save a card on an unknown site, and remove saved tokens for services you no longer use. A breach can also expose names and contact details that make the next phishing call more persuasive, even when full card data was not stolen.

Debit Card Fraud India: Warning Signs Your Card Has Been Compromised
- A purchase, cash withdrawal or small card-verification debit you do not recognize.
- OTPs or authentication prompts for payments you did not start.
- International or online charges while those features should be unused.
- Several declined attempts followed by a successful transaction.
- A bank alert that your card controls, phone number or transaction limit changed.
- A merchant you used reports a breach, or your saved card suddenly stops working.
- Your card is missing, retained by an ATM, or returned after being out of sight.
Do not dismiss a tiny charge. Criminals sometimes test whether credentials work before attempting more. Lock first, then verify with the issuer.
How to Block Card India Guide: Secure It in 60 Seconds
How to lock your credit or debit card immediately in India:
- Open your bank's official app, choose Cards, then Block or Lock Card. This often takes under 60 seconds.
- Call your bank's 24-hour fraud helpline. Use the number on the back of your card or on the bank's official website.
- For a specific transaction dispute, use the app or call the issuer and ask for a dispute or chargeback reference.
- Enable SMS, email and app alerts for every amount in the bank app settings.
- Switch off international usage if you do not need it and turn it on only for the required period.
- Use the app's online, POS, ATM and contactless controls to disable unused channels and set low limits.
- Never enter a full card number into a breach checker. If compromise is possible, ask the issuer to replace the card.
Most issuers support immediate customer-initiated blocking. RBI's card directions require multiple 24-hour reporting channels and say a lost card must be blocked immediately after the issuer is informed. Blocking the card should come before a long support conversation.

RBI liability rule, stated accurately
Reporting within three working days gives zero customer liability for a third-party breach when the deficiency lies neither with the bank nor the customer. Bank negligence also creates zero liability regardless of reporting time. If the customer shared payment credentials, the customer can bear loss until the bank is notified. Report immediately and let the evidence determine the category.
Real Card Fraud Cases Reported in India
- Karnataka ATM skimming conviction: The Indian Express reported in January 2025 that a 2020 Tumakuru skimming burst produced 63 complaints and about ₹30 lakh in withdrawals over two days. Police said a pinhole camera and skimmer captured data and PINs. Two accused were convicted in December 2024 and sentenced to eight years.
- Delhi ATM card trap and fake helpline: The Indian Express reported in April 2026 that police arrested an alleged mastermind after a card was trapped with adhesive and a fake kiosk helpline directed the victim to re-enter his PIN and leave. Police linked the group to at least 50 attempts and said at least 22 people had been defrauded between 2018 and 2025.
- Gurugram credit-limit phishing: Hindustan Times reported in June 2026 that police arrested five people over an alleged fake call centre. A complainant reported losing about ₹28,000 after a caller sent a credit-limit link. Investigators said stolen customer data supported calls and captured details were used for online purchases.
- Surat POS route for cloned cards: The Times of India reported in April 2026 that Surat cybercrime police arrested three people accused of supplying POS machines to gangs using cloned debit cards. Police said more than ₹11 lakh reached three linked accounts. These are police allegations, not findings of guilt.
These incidents show different stages of the same economy: capture the card or credentials, obtain authentication, create or use a payment route, then move the proceeds. They should not be added together as a national total.
What to Do If Your Card Has Been Used Fraudulently
- Lock or block the card: use the issuer's official app or verified helpline. Ask whether the linked account needs a debit freeze too.
- Report every transaction: raise the dispute with the issuer and save the complaint and card fraud chargeback India reference. Do not assume blocking automatically disputes earlier charges.
- Call 1930 immediately: give the bank complaint number, amount, time, merchant and transaction reference. Complete the complaint at cybercrime.gov.in.
- Preserve evidence: keep alerts, statements, OTP messages, emails, the phishing URL, call logs, screenshots, ATM location, receipts and the physical card. Do not publish full card details.
- Replace exposed credentials: request a new card and PIN. Change the banking and primary email passwords from a clean device if phishing or malware may be involved.
- Escalate in writing: use the issuer's grievance and nodal officer route. If it does not reply within 30 days, rejects the complaint or gives an unsatisfactory resolution, file through RBI CMS.
Follow the detailed recover money guide and the related bank account fraud response. Fast reporting can help, but no website or bank can promise recovery.
30 Second Instagram Reel Script
0 to 4 seconds: Hook
Visual: close shot of a card entering an ATM. Voice: "Your card can be in your wallet and still be misused."
4 to 13 seconds: Six methods
Visual: show the six-method grid. Voice: "ATM skimming, fake payment pages, CNP fraud, POS cloning, fake bank calls and stolen merchant data all target your card."
13 to 23 seconds: Warning and action
Visual: show an unknown transaction alert, then the lock guide. Voice: "Unknown charge or OTP? Open the official bank app, tap Cards, then Lock. Switch off online and international use too."
23 to 30 seconds: Emergency CTA
"Money taken? Call the number on your card and 1930 now. Save this reel and share it with every card user."
On-screen text: LOCK CARD | CALL BANK | CALL 1930 | SAVE EVIDENCE
Frequently Asked Questions
What is card skimming and how common is it in India?
Card skimming uses a hidden reader at an ATM, POS terminal, or compromised checkout page to copy card data. A camera, keypad overlay, or observation can capture the PIN. India does not publish a current national skimming-only total, so claims about exact prevalence should be treated carefully. Police cases show that physical skimming and related card-trap fraud remain active. Inspect the card slot, cover the keypad, and prefer monitored ATMs.
What is CNP fraud in India?
Card Not Present or CNP fraud happens when card details are used online without the physical card. Criminals may obtain the number, expiry date and CVV through phishing, stolen customer data, malware, or an infected checkout page. RBI requires additional authentication for domestic online card transactions, subject to permitted exceptions, but international or recurring transactions can work differently. Disable online or international use when you do not need it.
How long does a credit card chargeback take in India?
A card fraud chargeback in India does not have one universal 30 to 45 day RBI deadline. Card network and issuer dispute timelines vary. Under the RBI framework applicable on 7 August 2026, the bank must make the applicable shadow reversal within 10 working days after notification and determine liability within its board-approved period, not exceeding 90 days. If the issuer does not reply within 30 days, or its response is unsatisfactory, the customer can approach the RBI Ombudsman through CMS.
Should I use a credit or debit card for safer online shopping in India?
A credit card can reduce the immediate impact on your bank balance and may offer useful issuer dispute processes, but it is not fraud-proof. A debit card takes money directly from the linked account. For either card, use a known merchant, verify the domain, prefer tokenisation, keep transaction limits low, and disable online or international use when it is not needed. Never save card details on an unverified website.
How can I check if my card details are on the dark web in India?
There is no reliable public search that can prove a specific card number is absent from criminal markets. Never enter your full card number, PIN, CVV, or OTP into a breach-check website. Warning signs include unknown transactions, unexpected purchase OTPs, card verification charges, and overseas debits. Lock the card and contact the issuer if any sign appears. You can review exposure indicators linked to an email or phone, but that is not a card-number guarantee.
How to block card India: what is the fastest method?
Open the official bank app and use Cards, then Block or Lock Card. You can also call the 24-hour number printed on the card or listed on the bank’s official website. RBI directions require issuers to offer multiple round-the-clock reporting channels and to block a lost card immediately after being informed. Save the complaint reference and dispute each unauthorized transaction separately.
Sources and Credits
- Reserve Bank of India Annual Report 2024 to 2025: bank fraud totals, card/internet figures, scope and reporting limitations.
- RBI customer protection circular dated 6 July 2017: customer liability, shadow reversal and complaint-resolution framework applicable on 7 August 2026.
- RBI Credit Card and Debit Card Issuance and Conduct Directions: 24-hour reporting channels and immediate blocking requirements.
- RBI Journey in the Second Decade of the Millennium: EMV, AFA, card alerts, tokenisation and transaction controls.
- RBI card-on-file tokenisation circular: restrictions on storage of actual card data and merchant-specific tokens.
- CERT-In online skimming advisory: JavaScript sniffers and compromised merchant checkout pages.
- The Indian Express, 4 January 2025: Tumakuru ATM-skimming investigation and conviction.
- The Indian Express, 9 April 2026: Delhi card-trap and fake-helpline case.
- Hindustan Times, 7 June 2026: Gurugram credit-limit phishing call-centre case.
- The Times of India, 23 April 2026: Surat POS machines allegedly supplied for cloned-card use.
Do not enter card details on a page you have not verified
Check an unfamiliar payment or shopping website before entering any personal or financial information.
Open the website safety checkerMore from RakshaAI Blog

AI Scam India: How Artificial Intelligence Is Making Fraud More Dangerous in 2026

Bank Account Fraud India 2026: How Scammers Access and Empty Your Account

SMS Scam India: Text Message Fraud Surges 146%. Every Type Explained
Stay Protected Online
Use RakshaAI to check websites, phone numbers, and UPI IDs for scams free, instant, no sign-up required.
RakshaAI is a private platform by Ehatech Services Pvt. Ltd. Not affiliated with any government body. Editorial policy