
The offer arrives at 10:35 in the morning, in a family WhatsApp group, four days before Dhanteras. Diwali Mega Sale, 90 percent off, today only. An iPhone at Rs 8,999 against a struck through Rs 99,900. Free shipping, cash on delivery, easy returns. The page looks like every other festive banner on the phone that week, because at that point in the calendar every banner looks like that.
The only thing that separates it from a real sale is the address bar, which reads flashdeals-zone.shop.
Festive season scam India 2026 is not a different kind of fraud from the rest of the year. It is the same fraud, working better, because the season removes every circumstance that would normally make it look strange. Between Sharad Navratri on 11 October, Dussehra on 19 October, Dhanteras on 6 November and Diwali on 8 November, Indians will buy from sellers they have never used, pay unfamiliar merchants, act on time limited offers and open dozens of forwarded links, all while cooking, travelling and hosting. Every one of those behaviours is unusual in March. In October it is just Tuesday.
This guide covers the seven festive fraud formats, the documented Indian cases behind each one, the rules that make festive shopping safe, and a check you can run on any unfamiliar sale site in under a minute. Read it now, five weeks before Navratri, rather than after the transfer has gone out.
The 60 second version
- 1Festive fraud is ordinary fraud that stops looking strange, because urgency and unfamiliar sellers are normal in October
- 2McAfee found 69 percent of Indian festive shoppers were exposed to scams and around one in three fell victim
- 3Fake sale sites live on lookalike domains and cheap extensions such as .shop, .top and .xyz
- 4A 90 percent discount on a current generation phone is the bait, not the deal
- 5Never pay a festive seller by UPI to a personal ID, because there is no buyer protection on it
- 6Never donate through a QR code on a board or in a forward, verify the charity yourself
- 7Check any unfamiliar sale site at rakshaai.co before card entry, and call 1930 the same hour if money has moved
Why the Festive Season Is Peak Scam Season in India
Fraud does not need new techniques in October. It needs cover, and the festive season supplies more of it than any other period in the Indian calendar.
Start with the background numbers. CERT-In handled 29,44,248 cybersecurity incidents in 2025, up from 20,41,360 in 2024, a rise of roughly 44 percent in a single year. City level loss figures moved in the same direction. Delhi residents lost about Rs 2,100 crore to cyber fraud in 2025 against roughly Rs 1,100 crore in 2024, and cybersecurity firm SecurEyes put Karnataka losses for 2025 at over Rs 2,000 crore. That is the baseline the festive season lands on top of.
Now add what the season itself changes. McAfee festive season research for India found that 69 percent of festive shoppers were exposed to scams, that around one in three fell victim, and that 37 percent of those victims lost money. Ninety one percent reported receiving suspicious shopping related messages, and the research put the daily exposure at roughly 12 scam attempts per person across text, email and social media. Seventy two percent said they feared AI driven scams more than the year before, and 69 percent said they had encountered deepfake celebrity endorsements during holiday sales.
Those numbers describe a specific mechanism, and it is worth naming precisely, because it is what your family is actually up against.
A fake shop in March stands out. A fake shop in October is one of a thousand banners. A countdown timer in March is suspicious. In October, real sales genuinely do run for 48 hours, so the timer stops being a signal. Buying from a seller you have never used is unusual in March. In October it is how gift shopping works. A large payment to a new merchant is a red flag in March, and completely routine during Dhanteras. And the person making the decision is distracted, hosting, cooking and shopping across four tabs.
Scammers are not smarter in October. They are simply harder to see, and they know exactly when the window opens.
The 7 Festive Season Scam Types to Watch For
These are the seven formats that dominate the Indian festive season. They overlap and they often chain together, but each one has a distinct entry point and a distinct defence.

Seven festive fraud formats
What each one looks like between Navratri and Diwali, and where the money actually goes
1Fake big sale websites cloning real platforms
Lookalike domains impersonating Flipkart, Amazon, Myntra and brand stores, advertising impossible discounts on phones, electronics and jewellery, and taking payment by UPI to a personal ID.
2Fake Diwali gifting portals
Corporate and bulk gifting sites that collect advance payment for hampers, sweets and gift cards, deliver nothing, and disappear once the festival passes. Gift card requests impersonating a boss belong here too.
3WhatsApp festive offer forwards
Fake coupons, lucky draws and deal codes circulated as forwards, leading to phishing pages that harvest card details, or to APK files that hand over remote access to the phone.
4Charity and donation scams near festivals
Unverified QR codes and UPI IDs on boards, posters and forwards near pandals and temples, collecting donations that reach a private account rather than a registered charity.
5Counterfeit festive products
Fake or under carat gold with spurious hallmarks, non genuine electronics, inferior decorations at inflated prices, and adulterated sweets and dry fruits from unverified sellers.
6Fake booking sites for Dussehra and Navratri events
Garba and dandiya season passes, Durga Puja events and concerts sold as counterfeit passes or through pages that vanish, sometimes with holograms convincing enough to pass at the gate.
7Festival cashback and reward point fraud
Fake bank cashback portals and reward point expiry warnings that capture card number, CVV and OTP, or charge a small activation fee to a fraudulent account.
Scam 1: Fake Big Sale Websites Cloning Real Platforms
This is the largest category by volume and the one the hero image at the top of this article shows. A fake festive sale India operation registers a domain that reads almost like a real platform, builds a storefront on a template, buys social media advertising, and runs until the payments stop clearing.
The domain is the tell. Real platforms are flipkart.com, amazon.in and myntra.com. Fake ones read flipkart-diwali-offer.com, amazon-indiasale.com or a generic name on a cheap extension such as flashdeals-zone.shop. Research into the 2025 holiday period identified more than 2,000 newly created domains targeting peak shopping, including over 1,000 fraudulent .shop sites impersonating established brands such as Apple, Samsung, Ray-Ban and Dell, many of them sharing hosting infrastructure and sitting behind a reverse proxy to frustrate takedowns.
India specific work has found the same pattern with festive keywords attached. CloudSEK researchers documented 828 unique malicious domains pulled from the Facebook Ads Library, running phishing campaigns against e-commerce, recharge, jewellery, crypto and gambling audiences, with domains built by typosquatting real brands. Domains containing Diwali and Pooja keywords were hosted on a Hong Kong based network and redirected to Chinese betting pages, and one jewellery e-commerce site registered in early October pushed visitors to download an Android application carrying a trojan. CERT-In has separately warned about festival themed campaigns impersonating well known brands, circulated on WhatsApp, Telegram and Instagram, with links predominantly on .cn, .top and .xyz extensions.
The economics are visible on the page if you do the arithmetic in rupees rather than percentages. During one sale period, India Today identified 11 Flipkart lookalike sites advertising iPhones for under Rs 1,000. Nobody is handing a stranger a phone and Rs 80,000 of goodwill. Our online shopping scam guide covers the non festive version of this format in more detail.
Scam 2: Fake Diwali Gifting Portals
The fake Diwali gifting portal India variant targets a different buyer, and often a corporate one. Hampers, sweets, dry fruits and branded gift sets are bought in bulk, in advance, from vendors the buyer has never used, on a deadline that cannot slip. That combination is close to ideal for an advance payment fraud: the goods are not expected immediately, so the absence of delivery is not noticed for weeks, and by the time it is, the festival has passed and the portal has gone.
The consumer version runs through gift cards, and it chains neatly into an impersonation scam. In one documented Bengaluru case, a technology professional lost Rs 4.35 lakh after receiving a message that appeared to come from his own boss, asking him to buy Apple gift vouchers as Diwali gifts for the team. Gift cards are the perfect instrument for this because the value transfers the moment the code is shared, and there is nothing to reverse afterwards.
Two rules cover both versions. Any bulk gifting vendor gets verified as a business before any advance is paid, meaning a GSTIN, a registered address and a working landline. And any request to buy gift cards, from anyone, is confirmed by voice on a number you already have, never by replying to the message that made the request.
Scam 3: WhatsApp Festive Offer Forwards
The forward is the delivery mechanism for most of the other six formats. A coupon, a lucky draw, a brand anniversary giveaway or a deal code arrives from someone you trust, which is precisely why it works. Your cousin is not vouching for the link. She forwarded it because it looked good.
Two outcomes follow. The first is a phishing page that harvests card details, or a processing fee for a prize that does not exist. Hyderabad police documented a case in October 2025 in which a 29 year old woman from Secunderabad lost Rs 1,40,000 after fraudsters posing as store executives persuaded her to pay for a special gift offer and then GST charges on an iPhone 13. The second outcome is worse: an APK file. In the same advisory, a 69 year old Azampura resident lost Rs 1,02,194 after a malicious APK arrived over WhatsApp and gave the attacker remote access to family bank accounts.
Treat an APK arriving over WhatsApp during festive season as the single most dangerous thing on your phone. No genuine brand distributes its shopping app that way.
Scam 4: Charity and Donation Scams Near Festivals
Festive charity scam India works because giving during the festival is a social expectation, and because a QR code carries no identity. A printed code is just a container for a payment address. Anyone can generate one, print it, and stick it on a board.
That is not hypothetical. In 2023 the Badrinath Kedarnath Temple Committee filed a police complaint after boards soliciting donations through QR codes appeared at the temples, boards the committee confirmed it had not installed. The same pattern appears near pandals during Navratri and Durga Puja, on posters, and in WhatsApp forwards appealing for festival relief or a medical emergency.
The defence is boring and total. Do not scan to donate. Go to the charity official website yourself, or donate through GiveIndia.org, which vets the organisations it lists. Genuine charities publish registration details, including FCRA registration where relevant, and issue receipts you can use for 80G. A stranger with a QR code offers none of that.
Scam 5: Counterfeit Festive Products, Gold, Electronics and Sweets
A counterfeit Diwali product India case usually involves a real delivery, which is what makes it harder to spot than non delivery fraud. You received something. It is simply not what you paid for.
Gold is where the money is, and hallmark fraud is an established industry rather than an occasional crime. BIS enforcement has seized jewellery carrying spurious BIS markings along with the laser marking machines used to imprint counterfeit hallmarks, and separate raids in Haryana uncovered four unlicensed hallmarking centres operating across Hisar, Jind and Bhiwani. A Rajasthan case involved non precious metals including copper and brass sold to buyers as 22 carat gold, and lower carat gold sold as higher grade. BIS itself issues an advisory before Dhanteras every year for exactly this reason.
The check takes under a minute. A genuine hallmark carries the BIS logo, the purity mark, a six digit HUID, the assaying centre mark and the jeweller mark, and the HUID can be verified in the BIS CARE app before you pay. Do that in the shop, not at home. For electronics, buy from the brand or an authorised seller rather than an unknown storefront advertising the festive price. For sweets and dry fruits, an unverified seller is a food safety risk more than a financial one, but the principle holds.
Scam 6: Fake Booking Sites for Dussehra and Navratri Events
Garba and dandiya nights, Durga Puja events, Ramleela shows and festival concerts all sell passes, often in a rush, often through informal channels. That creates room for counterfeit passes good enough to survive a glance at a crowded gate.
The clearest documented case is the Mumbai garba pass scam. In October 2023, MHB Nagar police arrested four people, led by a web designer from Virar, who had produced and sold counterfeit season passes for Navratri events including a Rangratri Dandiya night and a Durgavedi Navaratri Utsav Samiti event. More than 1,000 people had bought fake passes at Rs 3,000 each, a fraud of over Rs 30 lakh, and police seized 1,000 counterfeit passes together with 1,000 hologram stickers, a laptop and printers, valued in total at about Rs 35.10 lakh. The alleged mastermind told police he had been inspired by the television series Farzi.
Concert tickets follow the same pattern outside the festival calendar. A BTech dropout in Delhi sold 69 counterfeit tickets to a Diljit Dosanjh Dil-Luminati show, taking about Rs 4,76,870 from buyers. Buy passes only from the official organiser or the official ticketing platform for the event, and treat a resale on Instagram or in a WhatsApp group as a fake until proven otherwise.
Scam 7: Festival Cashback and Reward Point Fraud
Cashback fraud is effective because the real offers are everywhere. Banks and card issuers run genuine festive cashback campaigns, so a fake one does not have to invent anything implausible. It only has to copy a bank page, add urgency, and wait.
Two variants dominate. The first is a fake cashback or reward portal reached through an SMS, email or social media advertisement, which collects card number, CVV and OTP, or charges a small activation or processing fee to a fraudulent account. The second is a reward points expiry warning, which pushes you to act before points are lost. Both rely on you arriving through a link rather than through your own bank app.
The rule that removes the whole category is simple. Never reach a cashback offer through a link. Open your bank or card issuer app yourself and read the offer there. If the offer is genuine, it will be published inside the app, because the bank has to disclose the terms. If it exists only in a message, it is a phishing page.
Festive Season Safe Shopping Rules
This is the section to screenshot and send to your family group before Navratri starts.
How to shop safely during festive season in India:
- 1
Type sale URLs directly, never open them from SMS or WhatsApp
Reaching a sale by typing flipkart.com or amazon.in yourself removes the entire category of lookalike domain fraud in one step, because you can only land on the real platform.
- 2
Check any unfamiliar sale website at rakshaai.co before entering card details
Domain age, SSL, blacklist status and business identity take seconds to check and expose the fakes, which are almost always registered weeks before the season.
- 3
Treat 70 to 90 percent off on genuine brands as proof of a fake
Authorised sellers cannot sustain those margins on current generation electronics or hallmarked gold. An impossible price is not a deal, it is the bait.
- 4
Use a credit card or cash on delivery for new or unfamiliar sellers
Card payments carry chargeback rights and marketplace payments carry platform protection. A UPI push payment to a personal ID has neither and is very hard to recover.
- 5
Verify cashback and reward offers inside your bank app only
Log in yourself and read the offer in the official app or website. If the offer exists only in a message or an advertisement, it is a phishing page.
- 6
Never donate through a QR code or link shared in a group
Donate at the charity official website or through GiveIndia.org. Anyone can print a QR code and stick it on a board near a pandal.
- 7
Track every purchase and screenshot the confirmation immediately
Non delivery is the most common festive outcome. Screenshots of the listing, the price, the chat and the payment are what a bank dispute and a cybercrime complaint are built on.
Share festive awareness: warn your family group about these scam types before shopping starts.

How to Verify a Festive Offer or Sale Before Buying
Seven checks, none of which takes more than a few seconds, and any one of which is usually enough on its own.
- Read the domain character by character before anything else. flipkart-diwali-offer.com is not flipkart.com. Check the extension too, because festive fraud clusters on cheap new extensions such as .shop, .top, .xyz and .cn.
- Check the domain age and safety record at rakshaai.co. A domain registered three weeks before Navratri, with no reviews and no business identity, is a seasonal shop built to close. Age is the hardest signal for a scammer to fake.
- Apply the price arithmetic. Work out the rupee discount, not the percentage. A phone listed at Rs 8,999 against a market price of Rs 89,999 means a stranger is offering to hand you Rs 81,000. Nobody does that.
- Look at what the checkout is actually asking for. A genuine platform checkout does not ask you to send UPI to a personal ID, does not ask for the OTP outside the payment screen, and does not add a GST or clearance fee after the price.
- Test the reviews rather than counting them. Five reviews all rated five stars, posted in the same week, in the same tone, are marketing copy. Look for dated reviews, photographs and complaints, because real listings have complaints.
- Find the business behind the site. A real seller publishes a GSTIN, a registered address, a working phone number and return and refund policies that name a company. A blank contact page means there is nobody to chase.
- Verify the physical goods separately where it matters. For gold, buy from a BIS registered jeweller and check the six digit HUID in the BIS CARE app before paying. For electronics, confirm the seller is the brand or an authorised seller.
The comparison below is the same product on two pages. Everything a scammer can copy has been copied. What they cannot copy is the domain, the payment rail and the review history.

Documented case, October 2023
Mumbai garba pass racket sold 1,000 fake Navratri season passes
- Police station
- MHB Nagar, Mumbai
- Arrested
- four accused, led by a web designer from Virar
- Victims
- more than 1,000 buyers
- Price per pass
- Rs 3,000 for a counterfeit season pass
- Fraud value
- over Rs 30 lakh
- Events targeted
- a Rangratri Dandiya night and a Durgavedi Navaratri Utsav Samiti event
- Seized
- 1,000 fake passes, 1,000 hologram stickers, a laptop and printers, about Rs 35.10 lakh in total
- Reported motive
- the alleged mastermind told police he was inspired by the series Farzi
Two more things are worth building into the season rather than checking case by case. Use a single card with a modest limit for all festive shopping, so that a compromise is contained and easy to spot on one statement. And keep every confirmation, because fake online sellers delete listings and accounts the moment a complaint starts, and a screenshot taken at the time of purchase is what a bank dispute is built on. Our guide on how to check a fake website covers the technical signals in more depth, and the website safety checker runs those checks for you on any domain.
30 Second Instagram Reel Script
Format: open on the festive offer, reveal the domain, run the seven formats fast, land on the two defences. Shoot vertical 9:16, burn in Hindi and English captions for sound off viewers.
On-screen caption: Fake Diwali sales, fake gifting portals, fake charity QR codes and counterfeit gold peak between Navratri and Diwali. Read the domain, do the rupee arithmetic, never pay a stranger by UPI, and check any unfamiliar site at rakshaai.co before you enter card details. If money has moved, call 1930 the same hour and file at cybercrime.gov.in.
Frequently Asked Questions
How do I verify a Diwali sale website is real and not fake in India?
Check that the URL is exactly the real platform, so flipkart.com, amazon.in or myntra.com, and not a variation such as flipkart-sale.com, amazon-indiasale.com or flipkart-diwali-offer.com. Festive fraud runs on lookalike domains, and researchers repeatedly find them clustered on cheap new extensions such as .shop, .top, .xyz and .cn. Open the site at rakshaai.co before you enter card details, because a domain registered three weeks ago with no reviews and no business identity is the single strongest signal you are on a fake. Then apply the arithmetic test. If the deal is impossible, for example a current generation iPhone at 90 percent off, it is not a deal at all. During one sale period India Today identified 11 Flipkart lookalike sites advertising iPhones for under Rs 1,000. Nobody sells a phone at that price, and no genuine platform asks you to pay a stranger by UPI to complete an order.
Are festive cashback offers from banks real?
Bank and credit card cashback offers during the festive season are real, and that is exactly why the fake versions work. Scammers build portals that mimic a bank offer page, then either harvest your card number, CVV and OTP, or charge a small processing or activation fee to a fake account. The rule that removes the risk entirely is to never reach a cashback offer through a link. Log in to your bank app or your card issuer app yourself, and read the offer inside the official app or the official website you typed. A genuine cashback offer will always be visible there, because the bank has to publish the terms. If an offer exists only in an SMS, an email, a WhatsApp forward or a social media advertisement, treat it as a phishing page until you have found the same offer inside your own bank app.
How do I know if a Diwali charity collection is legitimate?
Legitimate charities publish their registration details, including FCRA registration where they receive foreign contributions, and most established ones are listed on GiveIndia, which vets the organisations it lists. Never donate through a QR code or a UPI ID shared in a WhatsApp forward, pasted on a poster, or stuck on a board near a pandal or a temple. In 2023 the Badrinath Kedarnath Temple Committee filed a police complaint after boards soliciting donations through QR codes appeared at the temples, boards the committee had not put up. A QR code is just a container for a payment address, and anyone can print one and stick it anywhere. Donate by going to the charity official website yourself, or through GiveIndia.org, and keep the receipt for your records and for 80G purposes.
What are the most common scam product categories during Diwali in India?
Four categories carry the most risk. Gold and jewellery is first, because hallmark fraud is an established industry. BIS enforcement teams have seized jewellery carrying spurious BIS markings along with the laser marking machines used to imprint them, and have found unlicensed hallmarking centres operating in multiple districts, while a Rajasthan case involved copper and brass sold as 22 carat gold. Buy only from a BIS registered jeweller and verify the six digit HUID in the BIS CARE app before you pay. Electronics is second, where the risk is a non genuine or non functional unit sold through a lookalike site or a social media seller. Decorations and diyas are third, where the harm is inferior goods at inflated prices rather than outright theft. Sweets and dry fruits from unverified sellers are fourth, where adulteration is a food safety issue rather than a cyber one. In every category, the defence is the same: a verified seller, a traceable payment and a written invoice.
What should I do if I was scammed during a festive sale in India?
Move in the first hour, because that is when money can still be held. Call 1930, the national cybercrime helpline, and file at cybercrime.gov.in the same day, quoting the transaction reference. Raise a chargeback or a dispute with your bank or card issuer immediately if you paid by card, and report the transaction as unauthorised in writing so the bank has a dated record. If you bought through a real marketplace, open a complaint on the platform as well, because platform protection covers non delivery and counterfeit goods. For a consumer grievance about a product or a refund, file at consumerhelpline.gov.in or call the National Consumer Helpline on 1915. Finally, report the fake sale website at rakshaai.co so the next shopper who checks that domain sees a warning instead of a discount.
Why is the festive season the peak period for online fraud in India?
Because everything a scammer needs is supplied by the season itself. Volume rises, so a fake shop sits inside a flood of genuine offers instead of standing out. Urgency is normal, because real sales genuinely do run for 48 hours, which means a countdown timer stops being suspicious. Unfamiliar sellers are normal, because people buy gifts from places they have never bought from before. Large payments to new merchants are normal. And distraction is at its highest, because people are travelling, cooking, hosting and shopping at the same time. McAfee festive season research for India found that 69 percent of festive shoppers were exposed to scams, that around one in three fell victim, and that 37 percent of those victims lost money. The season does not create new fraud techniques. It removes the context in which the old ones look strange.
Is it safe to buy from an Instagram or WhatsApp seller during the festive season?
It can be, but only with the protections a marketplace would otherwise give you, because a social media seller gives you none of them by default. There is no escrow, no dispute window, no verified identity and often no return address. Three rules make it survivable. First, verify the business itself rather than the page, so check the GSTIN, a working landline or address, and the domain if they have one, before you pay. Second, pay in a way that can be reversed, so a credit card or cash on delivery, and never a UPI transfer to a personal ID, because a UPI push payment to an individual has no buyer protection and is extremely difficult to recover. Third, screenshot the product listing, the price, the chat and the payment confirmation, because if the seller deletes the account, those screenshots become your only evidence for the bank and for cybercrime.gov.in.
Sources and Credits
- The420.in, CERT-In Reports Over 29 Lakh Cyber Incidents in 2025 and Vision IAS, CERT-In Handled Around 30 Lakh Cyber Incidents in 2025: the 29,44,248 incidents handled in 2025 against 20,41,360 in 2024, a rise of roughly 44 percent in one year.
- Deccan Chronicle, 69 Percent of Festive Shoppers Exposed to Scams and Techshots, AI Powered Scams Surge During Diwali, Targeting One in Three Indians: McAfee festive season research for India, including 69 percent of festive shoppers exposed to scams, roughly one in three falling victim with 37 percent of victims losing money, 91 percent receiving suspicious shopping messages, 72 percent fearing AI driven scams more than the previous year, 69 percent encountering deepfake celebrity endorsements, and an average of about 12 scam attempts per person per day.
- Storyboard18, 45 Percent of Indian Consumers Have Fallen Victim to Deepfake Shopping Scams: the finding that 45 percent of Indian consumers say they or someone they know has fallen for a deepfake shopping scam, and that of those who lost money, 46 percent lost over Rs 41,500.
- eCommerceNews, Festive Season Cyber Fraud Surges as Shoppers Seek Discounts: the SecurEyes figure of over Rs 2,000 crore in Karnataka cyber fraud losses in 2025, and the observation from Uma Pendyala of SecurEyes that the celebratory, urgent atmosphere around festive deals and deliveries makes people more likely to skip basic security checks.
- The Indian Witness, Delhi Loses Rs 2,100 Crore to Cyber Scams in 2025: the Delhi loss figure of about Rs 2,100 crore in 2025 against roughly Rs 1,100 crore in 2024.
- BforeAI, 2025 Retail Holiday Threat Report and The420.in, Researchers Warn of Expanding Fake Retail Sites Targeting Peak Shopping Season: the more than 2,000 newly discovered domains targeting the 2025 holiday shopping period, the more than 1,000 fraudulent .shop sites impersonating brands including Apple, Samsung, Ray-Ban and Dell, the shared hosting infrastructure across scam clusters, and the use of a reverse proxy service to complicate takedowns.
- Daijiworld, Scammers Using Diwali and Pooja Domains to Con Users This Festive Season: the CloudSEK finding of 828 unique malicious domains identified from the Facebook Ads Library, the typosquatting technique used to imitate real shopping brands, the hosting of Diwali and Pooja keyword domains on a Hong Kong based network with redirects to Chinese betting pages, the jewellery e-commerce domain pushing a trojan carrying Android application, and the comment from Rishika Desai of CloudSEK on the spike in fake domain hosting for online shopping scams.
- Deccan Herald, CERT-In Cautions of Fake Festival Gift Messages: the CERT-In advisory on festival themed phishing campaigns impersonating prominent brands, circulated on WhatsApp, Telegram and Instagram, and the concentration of the associated links on .cn, .top and .xyz domains.
- Goodreturns, Beware of Online Scams During Flipkart Big Billion Days and Amazon Great Indian Festival: the India Today identification of 11 Flipkart lookalike sites advertising iPhones for under Rs 1,000 during a sale period, and the pattern of cloned storefronts on slightly altered domain names.
- NewsMeter, Hyderabad Police Warn Against Fake Shopping Sites and Lucky Draws: the October 2025 Hyderabad cyber crime advisory, the case of a 29 year old Secunderabad woman who lost Rs 1,40,000 to a special gift offer and GST charges on an iPhone 13, and the case of a 69 year old Azampura resident who lost Rs 1,02,194 after a malicious APK arrived over WhatsApp.
- Business Standard, Diwali Gift Card Scam Costs Bengaluru Techie Rs 4.35 Lakh and Storyboard18, Techie Loses Rs 4.35 Lakh in Apple Diwali Gift Card Scam: the Bengaluru technology professional who lost Rs 4.35 lakh after a message purporting to come from his boss asked him to buy Apple gift vouchers as Diwali gifts.
- LatestLY, Mumbai Garba Pass Scam, Cops Bust Rs 30 Lakh Fake Navratri Ticket Scam: the October 2023 MHB Nagar police case, the four arrests led by a web designer from Virar, the more than 1,000 victims who paid Rs 3,000 each for counterfeit season passes to a Rangratri Dandiya night and a Durgavedi Navaratri Utsav Samiti event, the seizure of 1,000 fake passes, 1,000 hologram stickers, a laptop and printers valued at about Rs 35.10 lakh, and the accused claim of having been inspired by the series Farzi.
- The Tribune, BTech Dropout Who Sold Fake Tickets to Diljit Dosanjh Concert Held: the sale of 69 counterfeit tickets to the Dil-Luminati tour in Delhi, taking about Rs 4,76,870 from buyers.
- Business Today, Fake QR Codes for Donation Appear Near Badrinath and Kedarnath: the police complaint filed by the temple committee after donation boards carrying QR codes appeared at the temples without its authorisation.
- ThePrint, BIS Raids Hallmarking Centre in Andhra Pradesh and Seizes Gold Jewellery With Fake Markings: the seizure of 72.71 grams of jewellery without mandatory HUID and carrying spurious BIS markings, along with the laser marking machine, computer and storage device used to imprint counterfeit hallmarks.
- FICCI CASCADE, Gold Jewels With Fake Hallmark Seized and Consumer protection guidance on the Rajasthan fake hallmarking case: the BIS north regional office raids that uncovered four unlicensed hallmarking centres across Hisar, Jind and Bhiwani, and the Rajasthan case in which copper and brass were sold as 22 carat gold and lower carat gold was represented as 22 carat.
- All India Radio News, BIS Urges Hallmark Assured Gold and Silver Purchases Ahead of Dhanteras: the components of a genuine hallmark, being the BIS logo, purity mark, six digit HUID, assaying centre mark and jeweller mark, and the advice to verify the HUID through the BIS CARE app.
- National Cybercrime Reporting Portal: the official complaint route for online financial fraud, and India national cybercrime helpline, 1930.
- National Consumer Helpline: the consumer grievance route for non delivery, counterfeit goods and refund disputes, reachable on 1915.
Festival dates for 2026 referenced in this article are Sharad Navratri from 11 to 19 October, Dussehra on 19 October, Dhanteras on 6 November and Diwali on 8 November. Dates follow the lunisolar calendar and vary by panchang and region, so confirm locally. Survey figures are reported with the research firm named alongside them, and case details are reported at the stage each case had reached at the time of publication. Naming an accused person is not a finding of guilt.
More from RakshaAI Blog

Online Shopping Scam India: How to Buy Safely on Any Platform in 2026

Fake Online Sellers India - 8 Warning Signs + Platform Guide

Transnational Cyber Fraud India: How Southeast Asian Scam Compounds Target You
Stay Protected Online
Use RakshaAI to check websites, phone numbers, and UPI IDs for scams free, instant, no sign-up required.
RakshaAI is a private platform by Ehatech Services Pvt. Ltd. Not affiliated with any government body. Editorial policy