When buying insurance online, you face five major digital fraud risks: phishing websites mimicking insurer portals, fake IRDAI impersonation calls, fraudulent payment links, identity theft through data harvesting, and AI-powered social engineering scams. The Department of Telecommunications’ Financial Fraud Risk Indicator (FRI), developed under its Digital Intelligence Platform (DIP), now classifies suspicious mobile numbers into Medium, High, or Very High risk categories, and this intelligence is shared with insurers for stronger fraud checks at policy issuance and claims processing.
Quick Summary
- Phishing websites and fake insurer portals that steal premium payments and personal data
- Impersonation calls claiming to be from IRDAI or insurance companies offering fake policy upgrades
- Fraudulent UPI and payment links that redirect money to scam accounts
- Identity theft through fake KYC forms and data harvesting on unverified platforms
- AI-assisted social engineering, including increasingly convincing voice and impersonation scams targeting policyholders
What Are the Most Common Digital Frauds Targeting Online Insurance Buyers?
The digital insurance landscape has become a prime target for cybercriminals who exploit the trust policyholders place in online platforms. Phishing websites that perfectly replicate insurer portals are among the most prevalent threats. These fake sites collect your premium payment and sensitive personal data, leaving you with no policy and a financial loss. Fraudsters also send SMS and WhatsApp messages with links to these cloned websites, often creating urgency by claiming your existing policy will lapse unless updated immediately.
Impersonation fraud has grown significantly, with scamsters posing as officials from the Insurance Regulatory and Development Authority of India (IRDAI) or insurance companies. They call policyholders offering fake benefits, bonus additions, or policy upgrades, and extract OTPs or banking details under the guise of verification. As per the Digital Threat Report 2025-26 released by the Ministry of Electronics and Information Technology (MeitY) along with CERT-In and CSIRT-Fin, social engineering and credential theft have become established attack methods, with threats now surfacing as legitimate sessions and approved payments that are indistinguishable from genuine activity until damage is done.
Payment fraud through fraudulent UPI links and QR codes is another widespread issue. Scammers send payment requests disguised as premium collection links, and once you authorize the payment, the money moves to untraceable accounts. Additionally, fake KYC verification forms on unverified platforms harvest your Aadhaar, PAN, and bank details for identity theft. The Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) had, as of June 30, 2026, helped save more than ₹11,158 crore across more than 32.80 lakh complaints, showing the scale of financial cyber fraud and the importance of rapid reporting.
How Are the Government and Regulators Responding to Insurance Cyber Frauds?
The government has adopted a coordinated, intelligence-led approach to counter telecom-enabled financial frauds. The Department of Telecommunications launched the Digital Intelligence Platform (DIP) in 2024, enabling real-time collaboration among over 1,600 stakeholders including telecom service providers, banks, insurers, and law enforcement agencies. Through the Mobile Number Revocation List (MNRL), mobile numbers disconnected for cybercrime involvement, failed re-verification, or violation of prescribed connection limits are shared with all stakeholders in near real-time, enabling insurers to strengthen fraud controls and prevent misuse of revoked connections.
The Financial Fraud Risk Indicator (FRI) under DIP classifies mobile numbers into Medium, High, or Very High risk categories based on inputs from citizen reports on the Sanchar Saathi platform, the National Cybercrime Reporting Portal (NCRP), and intelligence shared by telecom operators, banks, and financial institutions. This intelligence is securely shared with insurance entities for stronger fraud checks at the time of policy issuance and claims processing. As of June 30, 2026, more than 15.75 lakh SIM cards and 5.77 lakh IMEIs reported by police authorities had been blocked by the Government of India.
Recent insurance-law reforms have strengthened policyholder protection, including provisions allowing IRDAI to order disgorgement of wrongful gains and specified non-compliance penalties that can reach ₹10 crore. For health insurance, IRDAI prescribes a decision on cashless pre-authorization within one hour and final authorization within three hours. These are health-insurance claim timelines and should not be treated as a universal rule for every type of insurance claim.
How Can You Identify and Report Insurance Payment Frauds in Real Time?
The sooner you report a financial cyber fraud, the greater the opportunity for banks, payment intermediaries and law-enforcement agencies to attempt to stop or trace the funds. The Department of Telecommunications’ Financial Fraud Risk Indicator (FRI) classifies suspicious mobile numbers into Medium, High, or Very High risk categories, and banks and UPI service providers already use this intelligence to flag or stop transactions involving high and very high risk numbers in real time. If you receive a payment warning from your banking or UPI application about the number you are paying, pause and verify independently before proceeding.
To identify potential frauds, watch for these warning signs: unsolicited links requesting premium payments, messages creating urgency about policy lapse, callers asking for OTPs or claiming to be from IRDAI, and websites with slight misspellings of insurer names. You can verify mobile connections issued in your name on the Sanchar Saathi portal (www.sancharsaathi.gov.in) and report any connections that are not yours. As of June 30, 2026, more than 15.75 lakh SIM cards and 5.77 lakh IMEIs reported by police authorities had been blocked by the Government of India.
RBI’s digital-payment security framework requires regulated entities to maintain appropriate authentication, fraud-risk management, monitoring, reconciliation and customer-protection controls. The exact requirements vary according to the type of regulated entity and payment service involved. Consumers should never disclose their UPI PIN, passwords or authentication credentials to another person, even when the caller claims to represent a bank, insurer or regulator.
| Provision | Timeline or Detail | Regulatory Basis |
|---|---|---|
| Cashless pre-authorization | Within 1 hour | IRDAI Press Note |
| Final authorization (cashless) | Within 3 hours | IRDAI Press Note |
What Steps Should You Take Immediately After Detecting an Insurance Payment Fraud?
The sooner you report a financial cyber fraud, the greater the opportunity for banks, payment intermediaries and law-enforcement agencies to attempt to stop or trace the funds. If you suspect your insurance premium has been diverted to a fraudulent account, call the National Cybercrime Helpline 1930 immediately. This helpline facilitates prompt reporting and, where possible, freezing of fraudulent transactions. You must also file a complaint on the National Cyber Crime Reporting Portal (www.cybercrime.gov.in), which handles complaints across all categories of cybercrime.
As of June 30, 2026, CFCFRMS had helped save more than ₹11,158 crore across more than 32.80 lakh complaints. This figure represents money saved/prevented through the system; it should not be described as an average amount recovered per complaint. For reporting suspected fraud calls, SMS, or WhatsApp messages specifically, use the Chakshu feature on the Sanchar Saathi portal (www.sancharsaathi.gov.in) or its mobile application available on Android and iOS. You should also check the mobile connections issued in your name on the same portal and report any connections that are not yours.
RBI’s digital-payment security framework requires regulated entities to maintain appropriate authentication, fraud-risk management, monitoring, reconciliation and customer-protection controls. The precise obligations depend on the regulated entity and payment service involved. If a transaction is fraudulent, report it to your bank or payment provider immediately and use the national cyber-fraud reporting channels without delay.
How Does the Financial Fraud Risk Indicator Work to Protect Policyholders?
The Financial Fraud Risk Indicator (FRI), developed under the Department of Telecommunications’ Digital Intelligence Platform (DIP), classifies mobile numbers into three risk categories — Medium, High, or Very High — based on the likelihood of their involvement in financial fraud. The classification draws on inputs from multiple sources, including citizen reports on the Sanchar Saathi platform, the National Cybercrime Reporting Portal (NCRP), and intelligence shared by telecom operators, banks, and financial institutions, along with other telecom-related parameters.
This intelligence is securely shared through DIP with insurance entities for stronger fraud checks at two critical touchpoints: policy issuance and claims processing. Banks and UPI service providers are already using FRI intelligence to stop or flag transactions involving high and very high risk mobile numbers in real time. If your banking or UPI application cautions you about a number you are paying, you should pause and verify independently before proceeding. As of June 30, 2026, more than 15.75 lakh SIM cards and 5.77 lakh IMEIs reported by police authorities had been blocked by the Government of India.
The Mobile Number Revocation List (MNRL) operates as a core component of DIP, sharing mobile numbers disconnected for reasons including cybercrime involvement, failed re-verification, telecom service provider internal analysis, and violation of prescribed connection limits. By providing these disconnected numbers in near real-time, MNRL enables insurers and other stakeholders to strengthen fraud controls and prevent misuse of revoked mobile connections. Launched in 2024, DIP enables real-time collaboration among more than 1,600 stakeholders, including telecom service providers, banks, financial institutions, law enforcement agencies, and government departments, institutionalizing a whole-of-ecosystem approach to fraud prevention that shifts fraud management from reactive to proactive and preventive.
How Do IRDAI’s Recent Regulatory Reforms Strengthen Your Protection Against Digital Fraud?
Recent insurance-law reforms have strengthened policyholder protection. Certain specified non-compliance penalties can reach ₹10 crore, creating a stronger regulatory deterrent. The exact penalty depends on the provision and nature of the non-compliance, so ₹10 crore should not be presented as a universal penalty for every breach.
For health insurance, IRDAI’s 2024 framework provides a moratorium period of 60 continuous months of coverage. The detailed rules and exceptions in the applicable regulations and policy wording should be checked before making a claim or interpreting a non-disclosure issue.
| Provision | Earlier Position | Current Position | Regulatory Basis |
|---|---|---|---|
| Moratorium period | 8 years | 60 months (5 years) | IRDAI 2024 regulations |
| Maximum penalty for non-compliance | ₹1 crore | ₹10 crore | Sabka Bima Sabki Raksha (Amendment of Insurance Laws) Act, 2025 |
| Cashless pre-authorization | No specific timeline | Within 1 hour | IRDAI Press Note |
| Final authorization | No specific timeline | Within 3 hours | IRDAI Press Note |
| Health insurance free-look period | Up to 30 days for eligible policies of one year or more | 30 days from receipt of policy document, if no claim is made during the period | IRDAI Health Insurance FAQs / 2024 framework |
| FRI risk classification | Not available | Medium, High, Very High | DoT Digital Intelligence Platform |
What Is the Real Financial Impact of an Insurance Phishing Scam?
Consider a typical scenario: A 40-year-old professional purchases a health insurance policy with ₹10 lakh sum insured online. The annual premium is ₹15,000. She receives a message appearing to be from the insurer, warning that her policy will be cancelled unless she updates her KYC immediately. The link leads to a cloned portal that mirrors the insurer’s website. She enters her net banking credentials and approves a ₹15,000 payment. The money moves to a mule account and is withdrawn within hours.
CFCFRMS had, as of June 30, 2026, helped save more than ₹11,158 crore across more than 32.80 lakh complaints. This is a system-wide figure for money saved/prevented and should not be converted into an “average recovery per complaint” because the saved amount is not the same as money recovered from victims. In an insurance-specific phishing case, the actual loss and recovery outcome depend on the transaction and how quickly it is reported.
If the victim reports immediately through helpline 1930 and the National Cyber Crime Reporting Portal, banks, payment intermediaries and law-enforcement agencies may be able to act before funds are moved further. There is no universal 24-hour recovery deadline; outcomes depend on the transaction, the institutions involved and how quickly the fraud is reported.
What Should You Do Next?
Take these concrete steps today to safeguard your insurance purchases and respond effectively if you encounter a digital fraud:
- Verify the portal URL before every transaction. Check that the web address matches the insurer’s official domain exactly. HTTPS only indicates that the connection is encrypted; it does not by itself prove that a website is genuine. Avoid clicking links from unsolicited messages — type the URL directly or use the insurer’s official app.
- Check your registered mobile connections on Sanchar Saathi. Visit www.sancharsaathi.gov.in and report any mobile numbers issued in your name that you do not recognize. This prevents fraudsters from using your identity to create accounts for insurance fraud.
- Use strong authentication and never disclose credentials. Follow the security controls recommended by your bank or payment provider, and never share your UPI PIN, password, OTP or other authentication credentials with another person.
- Never share OTPs or banking credentials with unsolicited callers. If someone claiming to represent IRDAI, an insurer, a bank or a government agency asks you to disclose an OTP, UPI PIN, password or banking credential, do not share it. Disconnect and verify the request independently through an official channel.
- Save the 1930 helpline and cybercrime.gov.in in your contacts. If a financial cyber fraud occurs, report it as soon as possible. Faster reporting can give banks, payment intermediaries and law enforcement a better opportunity to stop or trace funds.
- Review your insurance policy documents carefully after purchase. Check the policy number, sum insured, nominee details, and premium amount against what you authorized. Report discrepancies to the insurer immediately through official channels.
- Monitor transaction alerts from your bank and UPI apps. If you receive a payment warning about a high-risk number, pause and verify independently before proceeding. Banks and UPI service providers use Financial Fraud Risk Indicator intelligence to flag suspicious transactions in real time.
Related Reading
Frequently Asked Questions
How can I verify if an online insurance portal is genuine before making a payment?
Check that the website address matches the insurer’s official domain exactly. HTTPS only indicates an encrypted connection; it does not prove that the website is genuine. Verify the insurer or intermediary independently through the official IRDAI website rather than relying only on a registration number displayed on the site. Avoid payment links received through SMS or WhatsApp. Treat a request to pay a premium into an individual’s personal bank account or UPI ID as a major warning sign and verify it independently with the insurer.
What should I do if I accidentally shared my OTP with a fraudster posing as an insurance company?
Immediately contact your bank or payment provider through its official customer-care channel to report the unauthorized activity and secure the affected account or payment access. Then call the National Cybercrime Helpline 1930 without delay. File a complaint on the National Cyber Crime Reporting Portal (www.cybercrime.gov.in) with details of the communication. Also report the fraudulent number on the Chakshu facility through the Sanchar Saathi portal to prevent the number from being used for further frauds.
Can I get my money back if I paid an insurance premium to a fake website?
Recovery depends on how quickly you report the fraud. Call 1930 immediately to report the financial cyber fraud — this helpline facilitates prompt reporting and, where possible, freezing of fraudulent transactions. File a complaint on the National Cyber Crime Reporting Portal and inform your bank to initiate a transaction reversal. As of June 30, 2026, CFCFRMS had helped save more than ₹11,158 crore across more than 32.80 lakh complaints. The figure represents money saved/prevented through the system, not a guaranteed recovery amount for each victim. Recovery is not guaranteed, so prevention and immediate reporting remain essential.
How does the Financial Fraud Risk Indicator protect me when buying insurance online?
The Financial Fraud Risk Indicator (FRI), developed by the Department of Telecommunications under its Digital Intelligence Platform, classifies mobile numbers into Medium, High, or Very High risk categories based on inputs from citizen reports on the Sanchar Saathi platform, the National Cybercrime Reporting Portal, and intelligence shared by telecom operators, banks, and financial institutions. This risk intelligence is securely shared with insurance entities for stronger fraud checks at the time of policy issuance and claims processing. Banks and UPI service providers use FRI signals to flag or stop transactions involving high and very high risk mobile numbers in real time, providing an additional layer of protection before you complete a premium payment.
What role does the Sanchar Saathi portal play in preventing insurance frauds?
The Sanchar Saathi portal (www.sancharsaathi.gov.in) allows you to check all mobile connections issued in your name and report any that are not yours — this prevents fraudsters from using your identity to obtain SIM cards for scams. You can also report lost or stolen handsets to ensure they are blocked and traced. Through the Chakshu feature on the portal, you can report suspected fraud calls, SMS, or WhatsApp messages directly. This reporting contributes to the wider telecom-fraud intelligence ecosystem. The Department of Telecommunications shares FRI intelligence through DIP with insurers and other financial-sector entities for stronger fraud checks. As of June 30, 2026, more than 15.75 lakh SIM cards and 5.77 lakh IMEIs reported by police authorities had been blocked by the Government of India.
Sources
- Press Information Bureau — Financial Fraud Risk Indicator (FRI), September 2026
- Press Information Bureau — CFCFRMS 2.0 and cyber-fraud reporting, July 2026
- Press Information Bureau — National Cybercrime Response Mechanism, July 2026
- IRDAI — Health Insurance FAQs and timelines
- IRDAI — Health Insurance Master Circular and related circulars
- Press Information Bureau — Insurance policyholder grievance redressal, August 2026
Protect yourself today: Before buying insurance online, verify the insurer’s credentials on the IRDAI website, never share OTPs with unsolicited callers, and bookmark the official portal of your chosen insurer. If something feels off, trust your instincts — pause, verify independently on the Sanchar Saathi portal, and report suspicious activity on the National Cyber Crime Reporting Portal. Your vigilance is the strongest defense against digital insurance frauds.
Article Information
Published: September 12, 2026
Last Fact-Checked: September 13, 2026
Category: Insurance
Regulatory Body: Insurance Regulatory and Development Authority of India (IRDAI)
Written by C.K. Gupta, M.Com & Tax Editor at TaxGST.in — 18+ years of experience in Indian taxation (in practice since 2007), helping readers understand IRDAI regulations, insurance policy terms, and claim procedures.
Official Resources
Disclaimer: This article is for informational purposes only. Insurance policy terms, IRDAI regulations, and claim procedures may change. Always verify current details on the IRDAI website and your policy document. Consult a licensed insurance advisor for personalized advice.
.
Discover more from TaxGst.in
Subscribe to get the latest posts sent to your email.



