For years, staying safe online came down to a few simple rules: don't click on suspicious links, ignore calls from unknown numbers and be wary of emails riddled with spelling mistakes. Those rules still matter. But cybercriminals have quietly changed their tactics. Instead of trying to fool people with obvious scams, they are exploiting something far more powerful — trust.
 
Just last week, Sahil, a friend in the IT business, received a message from an account resembling his regular vendor. The ‘vendor’ sent an invoice file on WhatsApp and asked Sahil to check and make the payment. It all looked like a normal business transaction. However, the moment Sahil opened the attached file, he lost access to his WhatsApp account. Because it was not an invoice but an .apk (Android package kit) file named ‘invoice’. Since he knows how such things happen, Sahil managed to retrieve his account, but it still took him almost a day. In the meantime, the fraudster, who stole his account, tried to send similar files to his contacts. But since Sahil called and informed all his regular contacts, there was no further takeover of any account from his contacts. 
 
Earlier this month, an accountant from a jewellery firm in Navi Mumbai received a WhatsApp message from an unfamiliar number, but the profile picture was of the company’s owner. The sender had simply used the owner's photograph to create a fake WhatsApp account that looked completely genuine. Believing he was carrying out legitimate instructions from his boss, the accountant transferred the money as requested. By the time anyone realised they had been duped, the company had lost ₹10.70 crore. The fraud came to light only during a WhatsApp group call when the real owner said he had never sent those messages.
 
There was no sophisticated hacking, no stolen passwords and no breach of the company's computer systems. The fraud worked because someone trusted what appeared to be a perfectly ordinary WhatsApp message from a familiar face or name.
 
That, in a nutshell, is where cybercrime is heading in 2026 and beyond.
 
The New Fraud Formula: Make Everything Look Normal
Not long ago, online scams often fell apart for smart eyes because something usually looked out of place — a strange web address, poor grammar, or a request that simply didn't feel right. Today's fraudsters have become much more sophisticated. Rather than creating obviously fake situations, they insert themselves into genuine ones.
 
Instead of building fake hotel websites, they contact people about bookings they have actually made. Rather than stealing WhatsApp passwords, they persuade users to approve a new linked device. Instead of sending random phishing emails, they impersonate banks, courier companies, government offices or even employers using information that is often publicly available.
 
The victim genuinely believes she/he is carrying out an ordinary task, such as confirming a payment, approving a device, or responding to a routine request. That is precisely why these scams succeed.
 
According to Gen's H1 2026 Threat Report, scams now account for nearly 46% of all threat detections worldwide, while malicious online advertisements contribute almost another 30%. Tech support scams alone resulted in more than 20mn (million) blocked attacks during the first six months of the year. 
 
For Indian internet users, these figures should serve as a warning, as many of these techniques closely resemble fraud already affecting banking, travel, messaging apps and online shopping in the country.
 
Hotel Bookings Are Becoming an Attractive Target
One of the trends highlighted in Gen's report is what researchers call ‘reservation hijack scams’. Imagine booking a hotel through a well-known travel website. A few days before your trip, you receive a WhatsApp message or an email quoting your booking reference and explaining that a technical issue requires you to reconfirm your payment.
 
At first glance, nothing appears unusual. The hotel name is correct, the booking dates match and even the payment amount looks right. That is exactly what makes these scams so dangerous.
 
The only dubious thing is the payment link. But since every other detail matches, you will most likely overlook ‘your sixth sense’ and open the link.
 
Some criminal groups are believed to obtain genuine reservation details through compromised hotel systems or travel partners, making it extremely difficult for travellers to distinguish legitimate payment requests from fraudulent ones.
 
If you are planning a holiday, especially during the festive season, be wary of any unexpected request for additional payment, however convincing it may appear. Instead of clicking the link provided, contact the hotel or booking platform directly using the telephone number listed on its official website or app.
 
WhatsApp Account Can Be Hijacked without Anyone Stealing Your Password
This is a growing threat involving WhatsApp's entirely legitimate ‘Linked Devices’ feature. Instead of trying to steal login credentials, fraudsters persuade users to scan a QR code or approve a browser as a linked device.
 
Once you approve the request, you have effectively opened the door yourself. The fraudster can read conversations, view photographs and documents and access your contact list without ever needing your password or a one-time password (OTP).
 
From there, they may impersonate you, ask your family or friends for emergency money, or quietly collect personal information for future fraud.
 
This is no longer a theoretical risk.
 
The Indian Cyber Crime Coordination Centre (I4C), as well as market regulator SEBI (Securities and Exchange Board of India), have already warned about campaigns in which fraudsters impersonated regulators and targeted senior executives through WhatsApp. By using malicious files, they hijacked WhatsApp Web sessions and sent fraudulent payment instructions from accounts their victims trusted completely. CERT-In has also warned about malware campaigns spreading through compromised WhatsApp accounts using attachments that appear to come from known contacts.
 
Closer to home, officials in the Mumbai collector's office received WhatsApp messages this May that appeared to come from the collector herself. The messages displayed her name and photograph and requested urgent financial assistance for a so-called government project. Fortunately, alert staff verified the request before transferring any money. The incident showed just how convincing impersonation scams have become — even government departments are being targeted.
 
Fake Customer Support Is Getting Harder To Recognise
Tech support scams have existed for years, but they have become far more polished. The crude pop-up windows claiming that a computer has been infected have largely disappeared. In their place are convincing Microsoft, Google or antivirus support pages, realistic browser alerts and online advertisements that closely resemble genuine customer support services.
 
Victims are encouraged to call a telephone number displayed on the screen. Once they do, the fraudster persuades them to install remote-access software or reveal sensitive banking information.
 
The presentation has become far more professional, but the objective remains exactly the same — gaining access to your device or your bank account.
 
Online Shopping Fraud Has Moved to the Checkout Page
Online shopping has become second nature for millions of Indians. We compare prices, place orders and make payments within minutes. Cybercriminals know this, and they are increasingly targeting the moment we feel most comfortable — the checkout page.
 
One growing threat is web skimming. In these attacks, criminals secretly plant malicious code on shopping websites that follow poor security protocols. When customers enter their card details during payment, the information is quietly copied and sent to the attackers without the buyer noticing anything unusual.
 
According to Gen, nearly 1mn web-skimming attacks were blocked during the first half of 2026, more than double the number recorded in the previous six months. What makes this particularly worrying is that victims may be shopping on websites that appear completely genuine. The page looks normal, the payment goes through and the order may even be delivered. Only later do they discover unauthorised transactions on their card.
 
The lesson is simple: appearances alone are no longer enough to judge whether an online transaction is safe.
 
Artificial Intelligence Is Adding a New Layer to Old Scams
Artificial intelligence (AI) has taken cybercrime well beyond deepfake videos and cloned voices. Modern AI tools can browse the internet, write convincing emails, interact with software and carry out tasks using the permissions users have already granted.
 
Criminals have already started exploiting these capabilities.
 
Instead of persuading people to download malicious software directly, they are looking for ways to misuse AI-powered applications and automated tools that already have access to everyday digital services. If an AI assistant has permission to access files, emails or online accounts, an attacker may try to manipulate it into performing actions the user never intended.
 
The risk is not AI itself. The real danger lies in granting permissions without fully understanding what an application or AI tool is allowed to do.
 
As AI becomes a larger part of everyday life, users will need to pay closer attention to the permissions they approve, just as they do with mobile apps today.
 
Why Indian Users Are Particularly Exposed
India's rapid move towards digital payments, online banking and app-based services has transformed everyday life. Paying through UPI, booking travel online, scanning QR codes, chatting on WhatsApp and watching reels have become routine for millions of people.
 
Unfortunately, these same habits have also created fresh opportunities for fraudsters. 
 
Cybercriminals know that Indian consumers regularly receive OTPs, payment requests, delivery notifications and banking alerts. Rather than inventing elaborate stories, they simply insert themselves into activities people already carry out every day.
 
Check the SMS. Its header shows AD-DBINT-S and indicates that ₹3850 has been received in the MCX account wallet for the mobile number. It has a short URL also. However, the recipient does not even have a trading account or wallet. Plus, the short URL, when expanded, reveals a dubious link allegedly for some online game. DBINT, the five-letter SMS header, is trying to impersonate 'DBINTL', the official header of DB (International) Stock Brokers Ltd. (Note: TRAI, our telecom regulator, mandates a six-letter SMS header for the sender.) 
 
A message about a courier parcel, a hotel booking, a tax refund or a bank verification no longer feels unusual because these are all part of modern life.
 
That is precisely why these scams are becoming more successful.
 
How To Stay One Step Ahead
The encouraging news is that most of these scams can still be prevented. You do not need advanced technical knowledge or expensive software. A few sensible habits can make it much harder for criminals to succeed.
 
1.Always verify payment requests independently. If a hotel, airline, bank or courier suddenly asks for additional money, contact the organisation using the phone number or customer support details listed on its official website or mobile app. Never rely on the contact details provided in an unexpected message.
 
2.Review your WhatsApp ‘Linked Devices’ regularly. Remove any browser or computer you do not recognise.
 
3.Never install software simply because someone claiming to be technical support asks you to. Genuine companies do not contact customers out of the blue and ask them to install remote-access software.
 
4.Ignore customer support numbers displayed in online advertisements or pop-up messages. If you need help, search for the company's official website yourself.
 
5.Use credit cards where possible when shopping on unfamiliar websites. They generally offer stronger protection against fraudulent transactions than direct bank transfers.
 
6.Enable multi-factor authentication (MFA) for email accounts, banking apps, social media and messaging services. It provides an additional layer of protection if your password is compromised.
 
7.Keep your devices and apps updated. Those update notifications may be inconvenient, but they often fix security weaknesses that criminals actively exploit.
 
8.Treat QR codes with caution. Scanning one can sometimes approve a linked device, redirect you to a fake website or initiate an unauthorised payment.
 
9.Most importantly, don't rush. Scammers thrive on creating panic and urgency. Whether the message claims your bank account will be blocked, your parcel will be returned or your booking will be cancelled, pause for a moment and verify the request before taking any action.
 
Trust Is Now the Real Target
The biggest lesson from these incidents is that cybercrime is no longer just about malicious software or fake websites. Increasingly, it begins with a perfectly ordinary request that appears to come from someone or something you already trust.
 
  • Would a hotel really ask you to complete a payment through WhatsApp?
  • Would a government official genuinely send a personal message asking for money?
  • Would your bank suddenly ask you to install software or an attached app before resolving a problem?
  • Would someone you know really ask you to scan a QR code to ‘verify’ your WhatsApp account?
 
These are the questions that matter today because cybercriminals are no longer trying to break into our digital lives from the outside. They are slipping into trusted conversations, familiar brands and everyday routines.
 
Cybercriminals have realised that trust is often easier to exploit than technology. Protecting that trust has become every internet user's first line of defence.
 
As Gen's latest Threat Report makes clear, cybercrime is no longer a series of isolated problems. Scams, identity theft, malware, privacy breaches, AI misuse, and financial fraud are increasingly linked, forming a single chain of attack. Breaking that chain often begins with one simple habit — pausing to verify before you trust.
 
Stay Alert, Stay Safe!