LSN News › India

Business · India Bureau

Malicious Apps Exploit UPI Permissions to Drain Bank Accounts

A new fraud technique leveraging fake system glitches and malicious applications is targeting UPI users across India. Once installed, these apps exploit accessibility and notification permissions to monitor financial activity and intercept one-time passwords.

LSN India · 7 September 2026

Security researchers have identified a sophisticated scam targeting India's Unified Payments Interface users, in which cybercriminals use deceptive applications disguised as legitimate tools to gain unauthorized access to banking credentials and transaction data.

The fraud operates through malicious apps that present users with apparent technical glitches—such as frozen payment screens—to trick them into granting excessive device permissions. Once installed, these applications exploit accessibility features and notification permissions to monitor user activity in real-time, including capturing one-time passwords sent by banks for transaction verification.

Unlike traditional phishing schemes, this method bypasses conventional security measures by operating within the legitimate permissions framework of Android devices. Users often grant these permissions believing they are enabling standard app functionality, unaware that the applications can simultaneously monitor multiple processes and intercept sensitive authentication codes.

Experts advise users to download applications exclusively from official sources, carefully review requested permissions before installation, and avoid granting accessibility permissions to unfamiliar apps. Banks have also recommended enabling additional security features such as transaction notifications and limiting UPI transaction limits on devices suspected of compromise.

As digital payment volumes surge across India, authorities and financial institutions continue to strengthen detection mechanisms to identify and block malicious applications before they can compromise user accounts.