Executive Summary
The supplied CyberRakshakLabs research examines a reported wave of ₹1–₹5 web-series and entertainment scams. Reports cited in the article say more than 72 complaints were received in one month by the Indore Crime Branch.
The article makes an important distinction: UPI AutoPay itself is legitimate. NPCI supports recurring payment mandates for services such as OTT subscriptions, bills, EMIs and insurance. The security problem arises when a user is socially engineered into authorizing a mandate they did not intend to create.
Why ₹1 Is Such a Powerful Psychological Bait
The attacker does not necessarily need to persuade someone to spend ₹1,000. The supplied research explains that a tiny amount can reduce suspicion because the user may think: “It's just ₹1.”
That low-friction decision can shift attention away from the more important question: What exactly am I authorizing?
The Attack Starts on Social Media
The supplied article describes reported scam links distributed through platforms such as Facebook, Instagram and WhatsApp. Example bait messages include “New Episode Out Now,” “Watch Full Episode,” “Watch Live” and “Only ₹1.”
After the click, the user can be redirected away from the legitimate entertainment platform to a site designed to look like an OTT service.
The Fake OTT Page
The reported fake pages may use show artwork, a play button, subscription information, a payment page and “secure payment” messaging. The goal is to keep the victim focused on getting the content rather than inspecting the authorization request.
The ₹1 Payment Is Where Things Get Dangerous
The supplied research says the user may be asked to pay ₹1–₹5, but the important question is not simply the amount being paid now. It is what the user is authorizing for later.
UPI AutoPay is designed for recurring mandates. The article notes that legitimate services can use this mechanism, while a scammer can attempt to trick a user into approving a mandate they do not understand.
Payment vs Mandate: The Hidden Difference
You authorize → money is transferred.
You authorize → future debits can occur according to the mandate.
The supplied research explains that a ₹1 “trial” can therefore be connected to a larger recurring obligation if the user approves the wrong mandate. It also emphasizes that not every recurring debit is fraudulent because legitimate services use the same payment mechanism.
What a Proper Mandate Should Show
According to the supplied article's summary of NPCI guidance, the mandate interface should clearly identify the AutoPay request and display information such as:
If those details do not match what you intended to purchase, the supplied research's instruction is simple: DECLINE.
Second Attack Path: The Malicious App
The reported campaign can also use a second path: instead of completing the payment on a web page, the victim may be told to download an app to watch the episode.
The supplied article cites a reported case involving a teacher who installed such an app and subsequently experienced phone-data compromise and a ₹10,000 deduction. It explicitly notes that the exact technical mechanism was not publicly established in the reports.
The Three-Branch Attack Chain
Branch A — Mandate Abuse
Branch B — Malicious App
Branch C — Payment Data Theft
Why This Attack Works
The supplied research identifies several psychological triggers:
Each element reduces the amount of thinking required before clicking.
The Real Attack Surface Is Not the ₹1
This is the central CyberRakshakLabs lesson in the supplied article. The real assets may be:
Why Legitimate AutoPay Makes the Scam More Convincing
The supplied research describes a cybersecurity paradox: AutoPay exists to make legitimate recurring payments easier. NPCI supports recurring mandates for legitimate services including OTT subscriptions, utility bills, insurance and other recurring payments.
The technology is therefore not automatically the problem. Deception around the technology is the problem. Users need to understand what they are authorizing.
What Users Should Check Before Paying ₹1
Official OTT app or website? WhatsApp forward? Instagram ad? Facebook post? Unknown message?
Do not trust the logo, colours or show artwork alone. Check the actual domain name.
Look for Recurring, AutoPay, Mandate, Monthly, Weekly, Validity, Maximum Amount and Merchant.
Review active mandates in your payment app. If you find one you do not recognize, revoke it immediately.
The Most Important Rule
The supplied research explains that the UPI PIN is an authentication factor for payment. You should understand what you are authorizing before entering it.
If You Already Approved the Scam
🔥 Final Takeaway
WHO? Who is offering this?
WHERE? Where did the link come from?
WHAT? What exactly am I authorizing?
RECURRING? Is this a one-time payment or AutoPay mandate?
WHY? Why does an entertainment offer need this level of payment or device access?
If you cannot answer those questions:
A ₹1 offer can be cheap entertainment — or an expensive lesson.
CyberRakshakLabs Think Before You Click. Stay Aware. Stay Secure.