In short
Card credentials are stolen or socially engineered for use without the physical card The objective is typically to perform unauthorized online card transactions.
What it is
A fraudulent site/caller/message asks for card details or authentication under a purchase, refund or verification pretext. The victim is then pushed to enter card number, expiry, CVV or OTP on an untrusted flow.
How it starts
Card credentials are stolen or socially engineered for use without the physical card.
What they tell you
A fraudulent site/caller/message asks for card details or authentication under a purchase, refund or verification pretext
What they want you to do
Enter card number, expiry, CVV or OTP on an untrusted flow
How you lose money
perform unauthorized online card transactions
What happens next
After the first successful step, the fraudster may demand more money/information, deepen account or device access, or disappear.
Warning signs
trust | urgency | phishing | card credential theft
Where this is documented
India — officially documented by an Indian authority/regulator
How to avoid it
Use only the bank/payment app or official contact details; never share OTP, PIN, password or screen access; verify the payee and transaction purpose before approving.
If it already happened
Contact the bank/payment provider immediately if money moved; report financial cyber fraud promptly via 1930 and cybercrime.gov.in; preserve messages, transaction IDs, phone numbers and URLs.