Your phone freezes right after you tap a link or an ad. Nothing loads, the screen glitches, and for a second you assume it’s just a bad app or a weak network. That small moment of confusion is exactly what a growing category of UPI fraud is built around.

Security researchers tracking this pattern say the freeze itself rarely does anything. Cybersecurity researchers have flagged fake utility and service apps that request access to SMS, notifications and Android’s accessibility features — permissions that have nothing to do with what the app claims to offer, and everything to do with quietly harvesting data once installed. The freeze is just the opening move, designed to unsettle the victim before the real request comes in.

What usually follows is a phone call. Someone claiming to be from your bank or a tech support desk explains that there’s a “problem” with your account or device, and offers to fix it — if you’ll just install an app, or grant it screen access. A cybersecurity executive described the frozen screen as a distraction rather than the actual event, with scammers relying on fake error messages and impersonated support calls to convince victims something has genuinely gone wrong. Once that access is granted, the criminal isn’t hacking anything in a technical sense — they’re simply watching, and eventually acting, through a door the victim opened themselves.

It’s worth being precise about what does and doesn’t cause a loss here. The National Payments Corporation of India has clarified that entering a UPI PIN to check a balance does not authorise any payment — money only moves when someone actively hits “Pay” and confirms it. So the viral version of this scare — that a frozen screen alone can silently drain an account — isn’t accurate. The actual risk shows up once an app with accessibility permissions can read the screen and simulate taps, which is the mechanism that lets money move without the owner realising.

The defence is less technical than it sounds. Never install an app because a caller on the phone told you to, and never hand accessibility permissions to something you didn’t seek out yourself. If a scare call has already led to an install, the fix is to remove the app, then change the UPI PIN and banking passwords once the device is clean — not the other way around. As UPI transaction volumes keep climbing in India, this kind of fraud isn’t really a technology problem. It’s an old con — manufactured urgency, a stranger offering to help — wearing a new, glitchy screen as its costume.