Table of Contents
100M+
Active credit card users in India in 2026
CNP #1
Card-Not-Present is the leading fraud type per RBI data
4 Things
Card number, expiry, CVV, OTP — all a fraudster needs
Here’s the uncomfortable truth about credit card fraud: the fraudster never needs your physical card. They just need four pieces of information — your card number, expiry date, CVV, and access to your OTP. Every major scam targeting Indian cardholders is designed to collect exactly those four things, through one of six proven methods.
The good news is that knowledge is complete protection here. Once you understand how each fraud pattern works, you’ll recognise the attack the moment it starts — not after the money has left your account. This guide walks through all of it: the patterns, the 12 rules that close every door, the red flags, and exactly what to do if something does go wrong.
01 The Golden Rule — Read This Before Anything Else
If you remember nothing else from this guide, remember this: your bank will never call, message, or email you to ask for your CVV, OTP, full card number, or expiry date. Ever.
Here’s how the most common credit card scam plays out in India. You receive a call from someone who sounds completely professional. They know your name, sometimes your partial card number, maybe even your last transaction. They say there’s suspicious activity and they need to verify your identity. They ask for your CVV, or send an OTP and ask you to read it out.
The moment you share that information, they use it to authorise a transaction. The card isn’t broken. The bank’s system isn’t broken. You were convinced to hand over the keys. Your bank already has your card details — they will never need you to read them back over a phone call.
Whenever anyone asks for your CVV or OTP — regardless of who they claim to be — hang up immediately. Call your bank back using the number printed on the back of your card or listed in your banking app. A legitimate bank representative will never need your CVV, full card number, or OTP to help you.
Golden Rule
02 Six Fraud Patterns Targeting Indian Cardholders Right Now
These aren’t theoretical scenarios. They are active, widespread, and specifically designed for Indian users and the Indian financial ecosystem. Understanding how each one works is the most practical protection you can carry.
| Pattern | How It Works | How to Spot It |
|---|---|---|
| A. Fake Bank Call | Caller claims to be from your fraud department, sounds credible with partial account details. Asks for your OTP to ‘reverse’ a suspicious transaction | Your bank’s fraud team never asks for an OTP. Hang up. Call the official number on the back of your card |
| B. Phishing Website | A fake website mimics a real merchant or bank. You enter card details to pay. The site captures everything — number, expiry, CVV, and the OTP you enter on the fake 3D Secure page | Check the URL character by character. Payment gateway must be Razorpay, PayU, BillDesk, or CCAvenue. If CVV and OTP are on the same screen, leave immediately |
| C. Fake Customer Care | You post a complaint online. A fake account replies with a fake helpline number. You call and are asked to install AnyDesk or TeamViewer for ‘remote assistance’ | No real bank ever asks you to install a screen-sharing app. End the call immediately |
| D. Fake Refund / Cashback | A message says you have an unclaimed refund. A link asks for your card details to ‘process the credit’ | Real refunds are automatic. No refund process ever requires you to enter card details again |
| E. KYC Expiry Scam | A message mimicking RBI or your bank says your card will be blocked. A link captures your credentials the moment you enter them | RBI and banks do not send KYC requests via WhatsApp or unknown SMS numbers. Ever |
| F. SIM-Swap Attack | Fraudsters convince your mobile operator to issue a new SIM on your number. Every OTP sent to your phone now goes to their device | If your SIM stops working without reason, call your operator immediately. Switch to app-based OTP where possible |
These six patterns account for the overwhelming majority of credit card fraud in India. The specific scripts change — new excuses, new urgency, new pretexts — but the mechanics are always the same: get your card details, get your OTP, or get access to your phone. Knowing the pattern means you recognise the attack even when the specific wording is new.
03 The 12 Non-Negotiable Credit Card Safety Rules — At a Glance
Each of the 12 rules that follow gets its own explanation in this guide. Use this table as a quick-reference summary you can return to anytime — and share with anyone in your family who uses a credit card online.
| # | Rule | What It Protects Against | How to Apply It |
|---|---|---|---|
| 1 | Never share CVV, OTP, or card number | Sharing details with scammers on calls or fake pages | Not with your bank. Not with customer care. Not with anyone. |
| 2 | Enable card tokenisation on every platform | Data breach on merchant platforms exposing your real card number | Enable on Amazon, Flipkart, Swiggy, Zomato, IRCTC, MakeMyTrip |
| 3 | Use a virtual card for risky purchases | Unknown or one-time merchant fraud | Generate via HDFC, ICICI, SBI, Axis banking apps in 60 seconds |
| 4 | Pay only on verified websites | Phishing sites capturing your card details at checkout | Check https://, exact URL spelling, and a known payment gateway |
| 5 | Keep 3D Secure / OTP active always | Unauthorised transactions completed without your approval | Never disable it. If a merchant’s checkout skips OTP, that is a red flag |
| 6 | Switch to app-based OTP | SIM-swap attacks intercepting your SMS OTPs | Enable in HDFC, ICICI iMobile, SBI YONO, or Axis Mobile settings |
| 7 | Set low transaction limits as default | Large-value fraud in a single session | Online: ₹5,000–10,000. International: OFF by default. Raise when needed |
| 8 | Save cards selectively, tokenise always | Stored card data breaches on merchant platforms | Save only on established platforms. Delete tokens from unused sites |
| 9 | Avoid public Wi-Fi for transactions | Wi-Fi interception and keyloggers on shared devices | Use mobile data only. Never transact on a shared or public computer |
| 10 | Enable instant transaction alerts | Delayed fraud discovery allowing multiple unauthorised charges | Enable SMS, email, and app notifications for every single debit |
| 11 | Never install screen-sharing apps on request | Remote access attacks (AnyDesk, TeamViewer) | Hang up immediately if asked. Uninstall any such apps you don’t use professionally |
| 12 | When pressured, stop completely | Urgency-driven decisions made without independent verification | Hang up. Call your bank on the official number. Verify the claim independently |
hare this table with your parents and anyone in your family who uses credit cards online. Senior citizens are disproportionately targeted because fraudsters know they are more likely to trust authority figures and act under urgency. Five minutes of conversation about these rules can protect their financial security.
Pro Tip
04 Rules 1–3 in Depth: Never Share Details, Tokenise, Use Virtual Cards
Rule 1 — Never Share Your CVV, OTP, or Full Card Number
This is the single rule that, if followed consistently, prevents the majority of credit card fraud in India. Your CVV is the three-digit code on the back of your card. Your OTP arrives by SMS or your banking app. Your full 16-digit card number, combined with the expiry date and CVV, is everything a fraudster needs to authorise an online transaction anywhere in the world.
- Not with your bank. Not with customer care. Not on an unexpected form. These three pieces together authorise transactions from your account
- Your bank already has your card details — they will never need you to read them back over a call
- If you have already shared these details with someone you now suspect was a fraudster, block your card immediately and call your bank’s fraud helpline
Rule 2 — Enable Card Tokenisation on Every Platform
RBI mandated card tokenisation in 2022. Instead of storing your actual 16-digit card number on merchant platforms, your card is replaced with a unique secure token specific to that platform. Even if the platform suffers a data breach, your real card number is not exposed — only the token is, which is useless without the original card.
- Enable tokenisation on Amazon, Flipkart, Swiggy, Zomato, IRCTC, MakeMyTrip, and any other platform you transact on regularly
- When saving a card at checkout, look for the ‘tokenise’ or ‘secure card’ option — most major platforms now prompt for this automatically
- Delete old card entries on platforms you no longer use — unused stored data is unnecessary exposure
Tokenisation works silently in the background. Once enabled, you transact exactly as before — but the platform never sees your real card number. It is one of the highest-impact safety steps you can take, and it takes under two minutes per platform.
Rule 3 — Use a Virtual Card for Any Purchase You’re Unsure About
A virtual card is a temporary card number generated by your bank app, linked to your real credit card but completely separate from it. You use it once, and if the virtual card details are ever stolen, your real card is completely unaffected. Simply discard the virtual card and generate a new one.
- HDFC: NetBanking or MobileBanking → Cards → Virtual Card
- ICICI: iMobile → Cards → Virtual Debit/Credit Card
- SBI: YONO → Cards → e-Card
- Axis: Mobile app → Cards → Virtual Card
Use a virtual card for: any unknown merchant, international websites, subscriptions you plan to cancel, and any purchase where you feel even slightly unsure about the platform’s security. The extra 60 seconds to generate one is worth it every time.
05 Rules 4–6 in Depth: Verified URLs, 3D Secure, and App-Based OTP
Rule 4 — Pay Only on Verified Websites With Correct URLs
Phishing websites are built to look exactly like the real thing — same logo, same layout, same product listings. The only reliable distinguishing feature is the URL. One wrong character in the domain means you’re on a completely different website, controlled by a fraudster, that captures every detail you type.
- Check that the URL starts with https:// and that every character of the domain name is exactly correct
- The payment gateway must redirect to a known name: Razorpay, PayU, BillDesk, or CCAvenue
- If the payment page asks for your card details and OTP on the same screen, leave immediately — this is always a fake page
- Never click payment links sent via WhatsApp, SMS, or email — type the merchant URL directly into your browser
Rules 5 & 6 — Keep 3D Secure Active and Switch to App-Based OTP
Every online transaction in India should require OTP verification via 3D Secure authentication. This is your last line of defence before a transaction is authorised — even if a fraudster has your card details, they cannot complete a transaction without the OTP.
- Never disable 3D Secure / OTP authentication, even if a merchant claims it is unnecessary
- If a merchant’s checkout does not trigger an OTP, that is a red flag — consider abandoning the transaction
SMS OTP, however, has a known vulnerability: SIM-swap attacks. If a fraudster convinces your mobile operator to issue a new SIM on your number, every SMS — including your OTPs — goes to them. App-based OTP is tied to your specific device and is not vulnerable to SIM swap.
- HDFC, ICICI iMobile, SBI YONO, and Axis all offer app-based OTP generation — enable it in your banking app settings
- If your SIM unexpectedly stops receiving calls and messages, call your mobile operator immediately to report a possible SIM swap
06 Rules 7–9 in Depth: Limits, Card Storage, and Public Wi-Fi
Rule 7 — Set Low Transaction Limits as Your Default
Your bank app lets you set per-transaction and daily limits for online, international, and contactless payments — and change them instantly. Keeping these low by default means that even if something goes wrong, the maximum exposure is contained. Raise the limit when you genuinely need to, then lower it again immediately.
- Online transaction limit: ₹5,000–10,000 as your default — raise only for specific large purchases
- International transactions: keep OFF unless you are actively travelling or shopping abroad
- Contactless limit: ₹2,000–5,000
- Most bank apps allow instant limit changes: HDFC, ICICI, SBI YONO, and Axis all support this
Rules 8 & 9 — Save Cards Selectively, Avoid Public Wi-Fi
Every website that stores your card details is a potential data breach. The more platforms hold your card, the larger your attack surface. Be selective about where you save, and ruthless about removing it from platforms you no longer use actively.
- Safe to save on (with tokenisation): Amazon, Flipkart, Swiggy, Zomato, IRCTC, MakeMyTrip, and other large, established Indian platforms
- Avoid saving on: small merchant sites, unknown e-commerce apps, platforms you use rarely, or any site that does not support tokenisation
Public Wi-Fi networks can be monitored. Shared computers may have keyloggers that record every keystroke — including your card details and OTPs. Neither is a safe environment for any financial transaction.
- Use mobile data for all card transactions when away from home
- Never enter card details on a shared computer — internet cafés, hotel lobbies, or a friend’s device
- If you must use public Wi-Fi, connect through a reputable VPN before opening any payment page
07 Rules 10–12 in Depth: Alerts, No Screen-Sharing, and the Urgency Rule
Rule 10 — Enable Instant Transaction Alerts
Bank app notifications, SMS, and email for every debit mean you find out within seconds if something unauthorised occurs — not days later when recovery is far harder. Enable all three channels for maximum coverage and set alerts for every transaction, not just those above a threshold.
Rule 11 — Never Install Screen-Sharing Apps at a Caller’s Request
AnyDesk, TeamViewer, QuickSupport — no legitimate bank, payment company, or government department will ever ask you to install these. If someone does, hanging up is the only correct response. Uninstall them from your phone if you don’t use them professionally — their presence is unnecessary risk.
Rule 12 — When Something Feels Urgent, Stop Completely
Urgency is the fraudster’s primary weapon. Real banks, real merchants, and real government departments give you time to verify. Whoever is pressuring you to act in the next five minutes is manufacturing that urgency deliberately — because they know that calm, independent verification would end the call immediately.
- Urgency, fear, and pressure are signals to slow down — not speed up
- Hang up. Call your bank on the official number. Verify the claim independently
- No real financial emergency requires you to share card details or approve a transaction in under five minutes
The moment you feel sudden panic or pressure from any call or message, that feeling itself is the warning sign. Fraudsters are trained to create exactly that emotional state. Recognise it as a manipulation technique — and use it as your cue to slow down, hang up, and verify independently.
08 Red Flags Every Indian Cardholder Must Recognise Instantly
These are confirmed fraud scripts used across thousands of reported cases in India, arriving by phone call, WhatsApp, SMS, and email. If you hear or see any of them, treat the source as fraudulent until independently verified through an official channel.
| What They Say | Why It’s Always a Scam |
|---|---|
| “Your credit card will be blocked — verify your details immediately.” | Banks block cards silently and send an official in-app notice or letter — never an urgent call or WhatsApp message. |
| “We are processing a cashback of ₹1,500 — confirm your CVV.” | Cashback credits never require your CVV. No refund process needs your card details to credit your account. |
| “This is an RBI notification — your card has been flagged.” | RBI does not contact individual customers. RBI does not ask for card details. Ever. |
| “Your KYC is incomplete — card deactivated by tonight.” | KYC processes are handled through your bank’s official app, not WhatsApp links or unknown callers. |
| “Just confirm the OTP we sent — to stop this transaction.” | An OTP authorises a transaction from your account. It does not stop one. Sharing it approves a charge. |
| “You have won a reward — enter card details to claim it.” | No legitimate reward programme asks for card details. This is always a charge attempt, not a credit. |
| “This is a police cybercrime notice — pay the penalty now.” | Police never demand payment via credit card. No government authority in India does this. |
09 What to Do If Your Card Is Compromised — The First 30 Minutes
Time is the single most important factor in credit card fraud recovery. The sooner you act, the higher the chance of limiting the damage and getting your money back. Try to complete all five steps within 30 minutes of discovering the problem.
Step 1
Takes under 30 seconds. Most banks offer a temporary block if you’re unsure — you can unblock without needing a new card. This stops all further transactions instantly, even before you know exactly what happened.
Step 2
Report the fraudulent transaction, ask the bank to flag it, initiate a chargeback investigation, and request a replacement card. Under RBI’s Zero Liability Policy, if you report promptly and the fraud was not caused by your negligence, you are entitled to a full refund.
Step 3
This creates an official legal record, triggers law enforcement involvement, and significantly strengthens your chargeback claim with the bank. 1930 is the national cybercrime helpline, available 24×7.
Step 4
Even before finishing the steps above, if possible. If your device was also compromised, this prevents further unauthorised access to any linked account.
Step 5
Fraudsters often make small test charges before a larger transaction. Raise a chargeback dispute for every unauthorised charge, however small — including micro-amounts of ₹1–10.
Save your bank’s 24-hour fraud helpline in your phone contacts right now. Also save 1930 (national cybercrime helpline, 24×7) and bookmark cybercrime.gov.in. In a stressful moment, searching for these takes precious minutes that directly affect your recovery outcome. SBI: 1800-111-109 | HDFC: 1800-202-6161 | ICICI: 1800-200-3344 | Axis: 1800-419-5959
Pro Tip
10 Final Word — Awareness Is Your Strongest Protection
Credit cards are genuinely among the safest payment instruments available in India. RBI’s regulatory framework, the banks’ fraud detection systems, and the Zero Liability Policy all work in your favour. Fraud doesn’t happen because the system is weak.
It happens because fraudsters exploit four very human things: trust in authority, urgency under pressure, unfamiliarity with how card transactions actually work, and the instinct to act quickly when someone tells you there’s an emergency.
Every rule in this guide addresses one of those four things. Follow them and you remove almost all of your vulnerability — not because you become suspicious of everyone, but because you know exactly how a legitimate card transaction works and you instantly recognise when something doesn’t match that pattern.
Review these rules once a year. The mechanics of fraud never change — only the scripts do. New pretexts appear, new app names are used as cover, but the underlying attack — get your card details, get your OTP — stays the same. An annual five-minute refresh keeps your awareness current and your card secure.
Pro Tip
Quick Reference: Key Portals and Helplines
| Item | Where to Go |
|---|---|
| Cybercrime Helpline (call) | 1930 — national helpline, 24×7 |
| Report credit card fraud online | cybercrime.gov.in — National Cyber Crime Reporting Portal |
| SBI credit card fraud helpline | 1800-111-109 (toll-free, 24×7) or SBI YONO app |
| HDFC credit card fraud helpline | 1800-202-6161 or HDFC MobileBanking app |
| ICICI credit card fraud helpline | 1800-200-3344 or ICICI iMobile app |
| Axis Bank credit card helpline | 1800-419-5959 or Axis Mobile app |
| Block your credit card instantly | Bank app → Cards → Block Card, or call the 24-hour fraud helpline |
| Enable card tokenisation | Bank app → Cards → Manage Card → Tokenisation (or at merchant checkout) |
| Change card limits / international use | Bank app → Cards → Manage Card → Transaction Limits |
| Virtual card — HDFC | NetBanking or MobileBanking → Cards → Virtual Card |
| RBI Ombudsman (unresolved disputes) | cms.rbi.org.in — for disputes not resolved by your bank |
There is no single rule that makes your credit card impenetrable — what works is layering. The Golden Rule covers almost everything: your bank will never ask for your CVV, OTP, or full card number. If anyone does, it is a scam, always. Six fraud patterns cover almost all credit card crime in India — know them and you recognise the attack before it lands. Tokenise your card on every platform, set a low online limit, and keep international use OFF by default. Use a virtual card for unknown merchants — it can be discarded after use with zero impact on your real card. If fraud happens: block the card in 30 seconds, call your bank within 30 minutes, and file on cybercrime.gov.in. RBI’s Zero Liability Policy protects you — but only if you report promptly. Review these rules once a year. The mechanics of fraud never change — only the scripts do.