UPI Fraud and WhatsApp Hijacking: A Kerala Business Protection Guide

Most cybersecurity advice for small businesses talks about firewalls and ransomware. But ask shopkeepers in Thrissur, wholesalers in Ernakulam, or clinic owners in Kozhikode what actually cost them money last year, and you hear a different list: a customer who showed a fake UPI payment screenshot and walked out with goods, a WhatsApp Business number that suddenly started messaging customers asking for advance payments, a supplier email that quietly changed the bank account on an invoice. Fraud against Kerala businesses today is mostly social engineering wrapped around everyday payment and messaging tools — and the defences are mostly procedural, not technical.

This guide catalogues the schemes circulating in 2026, how to recognise each one mid-attempt, and the small set of habits that block almost all of them.

UPI Fraud Patterns That Target Merchants

The fake payment screenshot is the most common. A customer "pays" at the counter and shows a convincing payment-success screen — generated by one of dozens of screenshot-faking apps — and leaves with the goods before the shop owner notices no credit alert arrived. The defence is a rule, not a technology: goods leave only after the credit appears in your banking app or the soundbox announces it. Train every staff member that a customer's screen is not proof of anything. During busy hours, this rule slips — which is exactly when fraudsters visit.

The refund-and-callback scam targets owners directly. Someone calls claiming they "accidentally" sent money to your UPI ID and pressures you to return it. Either no money ever arrived, or it arrived from a mule account involved in other fraud — and "returning" it makes your account part of the laundering chain, which can get it frozen during investigations. Never act on a phone call about a transfer; verify in your own statement and, if a genuine stray credit exists, return it only through your bank's formal process so a record exists.

QR sticker swaps hit physical shops. Fraudsters paste their own QR code over the merchant's printed code, and payments quietly flow to a stranger until reconciliation catches it. Check your displayed QR codes weekly — scan them yourself and confirm the name shown — and prefer soundbox setups, where a missing payment announcement gets noticed within minutes instead of days.

WhatsApp Business Account Hijacking

For many Kerala businesses, the WhatsApp Business number is the storefront — catalogue, order book, and payment channel in one. That makes it a target worth stealing. The takeover almost always happens the same way: the attacker triggers a WhatsApp registration on their own phone using your number, then calls you pretending to be a courier, bank, or even WhatsApp itself, and talks you into reading out the six-digit OTP that just arrived. The moment you share it, your account registers on their device. Some variants instead ask you to dial a forwarding code (beginning with *21* or **67*) that diverts your calls — and with them, voice OTPs.

Once inside, attackers message your customer list asking for advance payments to a new UPI ID, often replicating your tone and even ongoing conversations. The brand damage usually outlasts the direct theft — customers who paid a fraudster through "your" number do not return easily. Businesses investing in WhatsApp as a serious sales channel, including automation-heavy retail setups, should treat account security as part of that investment, not an afterthought.

Three settings close most of the risk. Enable two-step verification inside WhatsApp (Settings → Account → Two-step verification) — this PIN is demanded at re-registration, so a stolen OTP alone is not enough. Never read any OTP to any caller, full stop; no legitimate organisation asks. And register the business on WhatsApp Business API through an official provider if revenue justifies it — API accounts sit on company infrastructure rather than a single staff phone, eliminating the SIM-level attack entirely.

Invoice and Vendor Bank-Change Fraud

The quiet, expensive one. An email arrives from a regular supplier — same logo, same signature, near-identical address with one letter off, or sometimes the supplier's genuinely compromised mailbox — announcing "updated bank details" for the next payment. Accounts teams processing dozens of invoices comply without suspicion, and the money lands in a mule account. Exporters and traders dealing with new overseas counterparties face the same pattern at higher stakes.

The control is non-negotiable and costs nothing: any change to a vendor's bank details is confirmed by a phone call to a number you already have on file — never a number from the email requesting the change. Make this a written rule for whoever handles payments, including family members who help with accounts. Pair it with payee whitelisting and per-day transfer limits in your business banking, so even a successful deception has a capped blast radius.

"Digital Arrest" and Director-Targeting Scams

Business owners are disproportionately targeted by intimidation scams because they have liquid funds and a reputation to protect. The "digital arrest" script — callers posing as police, customs, TRAI, or the CBI, claiming a parcel or PAN linked to your number is involved in crime, then keeping you on a video call while you "verify" funds by transferring them — has cost Indians thousands of crores and continues evolving. Variants aimed at businesses cite fake GST violations or court summons.

The recognition rule is absolute: no Indian law enforcement agency conducts arrests, investigations, or "fund verification" over video calls, and none ask for transfers. The moment a call combines authority, urgency, and money movement, it is a scam — hang up and dial the national cybercrime helpline 1930 if in doubt. Brief your family and senior staff specifically, because these scripts deliberately isolate the victim ("do not tell anyone, the case is confidential").

The Protection Checklist, In Priority Order

If you implement only the first three items, you eliminate the majority of incidents I see. One: WhatsApp two-step verification PIN on every business number, today. Two: the credit-confirmation rule for UPI — goods move only after your own app confirms. Three: the callback rule for any bank-detail change. Four: separate the business bank account from personal, with transaction alerts on and sensible per-transaction limits. Five: use a password manager and unique passwords for email, banking, and social accounts — email compromise is upstream of most invoice fraud. Six: turn on login alerts and two-factor authentication for the business email itself. Seven: brief every employee — including weekend and temporary staff — on the screenshot, OTP, and QR patterns above; fraudsters deliberately target whoever looks newest at the counter.

Businesses handling customer data at scale should fold these habits into their broader compliance work — the same governance mindset covered in our DPDP Act preparation guide for Kerala SMEs — and anyone choosing payment infrastructure should weigh fraud tooling alongside rates in our Indian payment gateway comparison.

Lookalike Websites and Brand Impersonation

A newer pattern worth a paragraph of vigilance: fraudsters cloning a business's website or social profile to harvest its customers. Kerala's gold and textile retailers were early targets — fake Instagram pages running "online-exclusive offers" under a trusted shop's name, collecting advance UPI payments from customers who believed they were dealing with the real brand. Travel agencies and tuition centres see the same pattern seasonally, timed to holiday bookings and admission cycles.

You cannot prevent someone from registering a lookalike page, but you can shrink its window. Search your own business name on Instagram, Facebook, and Google monthly — takedown reporting is fast when the real brand complains with documentation. Publish your official payment identities (UPI ID, account name, website domain) visibly in-store and on your genuine profiles, so customers have a reference to check against. And claim your business name on platforms you don't yet use; a dormant official handle is cheaper than a fraud investigation. If your website handles customer payments directly, an annual security review alongside your provider-vetting checklist closes the technical half of this exposure.

One more layer worth pricing for businesses above roughly ₹1 crore turnover: cyber insurance riders on standard business policies now cover fraud losses, data breach liability, and incident response costs, with annual premiums typically starting around ₹10,000–₹25,000. Read the exclusions carefully — most policies pay only when documented controls (the kind listed in the checklist above) were actually in place, which makes the checklist doubly worth implementing.

If You're Hit: The First Hour Matters Most

Money moved by fraud is recoverable mainly in the window before it is layered onward through mule accounts — banks can freeze funds mid-chain if alerted fast. The sequence: call 1930 (the national cyber fraud helpline) immediately and report the transaction; file the complaint at cybercrime.gov.in with screenshots, transaction IDs, and timestamps; call your bank's fraud line and request a freeze/recall on the beneficiary account; and if a WhatsApp account was stolen, re-register the number on your own phone immediately (registration kicks the attacker's session) and post a notice to customers through other channels warning them to ignore payment requests. Then file at your local police station — Kerala Police's cyber cells act on 1930-routed complaints, and the FIR matters for bank liability and insurance.

Speed beats embarrassment. Many owners delay reporting out of shame, and that delay is what converts a recoverable incident into a permanent loss. For a structured review of your overall exposure — accounts, devices, staff procedures, and recovery plans — our small business cybersecurity playbook for Kerala provides the wider framework this fraud-specific guide slots into.