

A sudden frozen phone screen could signal a UPI fraud attempt, with scammers using fake alerts and malicious apps to gain access to sensitive banking information.
Cybersecurity experts warn that fraudsters are moving beyond conventional phishing methods. Their tactics can involve fake advertisements, error messages and calls from people posing as customer support staff.
The attackers may persuade users to install APK files presented as cashback, rewards, verification or service applications. Such apps can request access to notifications, SMS, calls and accessibility features. Once permissions are granted, the malicious software can monitor activity and potentially read OTPs. It can also control parts of the device and simulate actions on the screen.
Harish Kumar, CEO of Quick Heal Technologies, described the frozen screen as a distraction rather than the main event. He said scammers use the situation to create urgency and push victims towards unsafe actions.
"Victims may then be persuaded to download an APK disguised as a reward, cashback, verification or service application," Kumar told the media.
Ruchin Kumar, Vice President - South Asia at Futurex, said attackers generally target the device, credentials, authentication factors or payment process surrounding a UPI transaction.
He said screen-sharing tools, fake applications and stolen OTPs can help fraudsters gain control. Victims may also be manipulated into entering their UPI PIN or approving a payment themselves.
Ravindra Singh, Managing Director at Delcom Telesystems, highlighted that users, devices and applications all form part of the security chain.
Users facing a suspicious freeze should disconnect mobile data and Wi-Fi. They should avoid entering banking credentials or UPI PINs. Suspicious apps should be removed, while unnecessary accessibility and device-administration permissions should be revoked.
If financial details may have been exposed, users should contact their bank through an official channel. They should check recent transactions and change relevant credentials from a clean device. Suspected financial fraud can also be reported through helpline 1930.
Also Read: Claude AI Models Access Real-World Organisations During Cybersecurity Tests