CYBERRAKSHAK LABS · RESEARCH #043

🔴 The ₹1 Web-Series Trap

What if the ₹1 is not the product you are buying—but the trust the attacker is trying to obtain?

By Vivek Kumar · Published 26 September 2026
RESEARCH#043
CATEGORYCyber Fraud / Digital Payment Security
CRL ASSESSMENTHIGH
RESEARCH LEVELDeep Research
PUBLISHED2026-09-26
Source & social links: LinkedIn Post ↗WhatsApp ↗YouTube ↗
How CyberRakshakLabs researches threats →
₹1 feels harmless. The supplied research describes a reported scam pattern in which a tiny web-series or entertainment payment can become the entry point to a recurring UPI AutoPay mandate, a malicious app installation, or payment-data theft.
₹1–₹5Reported low-value entertainment offers used as the bait.
3Attack branches described in the supplied research: mandate abuse, malicious app, and payment-data theft.
72+Complaints reportedly received by Indore Crime Branch in one month, as cited in the supplied article.
Executive Summary

The supplied CyberRakshakLabs research examines a reported wave of ₹1–₹5 web-series and entertainment scams. Reports cited in the article say more than 72 complaints were received in one month by the Indore Crime Branch.

The article makes an important distinction: UPI AutoPay itself is legitimate. NPCI supports recurring payment mandates for services such as OTT subscriptions, bills, EMIs and insurance. The security problem arises when a user is socially engineered into authorizing a mandate they did not intend to create.

The ₹1 is not necessarily the target. The authorization behind the ₹1 may be.
Why ₹1 Is Such a Powerful Psychological Bait

The attacker does not necessarily need to persuade someone to spend ₹1,000. The supplied research explains that a tiny amount can reduce suspicion because the user may think: “It's just ₹1.”

That low-friction decision can shift attention away from the more important question: What exactly am I authorizing?

₹1 Offer
↓
Low Suspicion
↓
Payment / Mandate Prompt
↓
Potential Larger Consequence
The Attack Starts on Social Media

The supplied article describes reported scam links distributed through platforms such as Facebook, Instagram and WhatsApp. Example bait messages include “New Episode Out Now,” “Watch Full Episode,” “Watch Live” and “Only ₹1.”

After the click, the user can be redirected away from the legitimate entertainment platform to a site designed to look like an OTT service.

The Fake OTT Page

The reported fake pages may use show artwork, a play button, subscription information, a payment page and “secure payment” messaging. The goal is to keep the victim focused on getting the content rather than inspecting the authorization request.

The social-engineering advantage is not the technology alone. It is the reduction of the user's time to think.
The ₹1 Payment Is Where Things Get Dangerous

The supplied research says the user may be asked to pay ₹1–₹5, but the important question is not simply the amount being paid now. It is what the user is authorizing for later.

UPI AutoPay is designed for recurring mandates. The article notes that legitimate services can use this mechanism, while a scammer can attempt to trick a user into approving a mandate they do not understand.

Important distinction: AutoPay ≠ scam. But an unknown AutoPay request combined with a deceptive entertainment offer is a serious warning sign.
Payment vs Mandate: The Hidden Difference
One-time payment
You authorize → money is transferred.
Recurring mandate
You authorize → future debits can occur according to the mandate.

The supplied research explains that a ₹1 “trial” can therefore be connected to a larger recurring obligation if the user approves the wrong mandate. It also emphasizes that not every recurring debit is fraudulent because legitimate services use the same payment mechanism.

What a Proper Mandate Should Show

According to the supplied article's summary of NPCI guidance, the mandate interface should clearly identify the AutoPay request and display information such as:

Merchant / requester
Amount
Frequency
Validity
Debit account
Mandate information

If those details do not match what you intended to purchase, the supplied research's instruction is simple: DECLINE.

Second Attack Path: The Malicious App

The reported campaign can also use a second path: instead of completing the payment on a web page, the victim may be told to download an app to watch the episode.

The supplied article cites a reported case involving a teacher who installed such an app and subsequently experienced phone-data compromise and a ₹10,000 deduction. It explicitly notes that the exact technical mechanism was not publicly established in the reports.

Defensive lesson: An entertainment offer should not require you to install an unknown APK.
The Three-Branch Attack Chain

Branch A — Mandate Abuse

Social Media Ad → Fake Web-Series Link → Fake OTT Page → ₹1–₹5 Offer → Payment / Mandate Request → User Approves → Recurring Debits

Branch B — Malicious App

Social Media Ad → Fake Web-Series Link → Fake OTT Page → “Install App to Watch” → Unknown APK → Permissions / Device Compromise → Potential Data or Financial Theft

Branch C — Payment Data Theft

Fake Offer → Fake Payment Page → Card / Banking / UPI Information → Credential Theft → Fraudulent Activity
Why This Attack Works

The supplied research identifies several psychological triggers:

Curiosity — “The new episode is already available.”
Scarcity — “Limited offer.”
Low price — “Only ₹1.”
Familiarity — Popular show or movie branding.
Urgency — “Watch now.”
Convenience — “Just enter your payment details.”

Each element reduces the amount of thinking required before clicking.

The Real Attack Surface Is Not the ₹1

This is the central CyberRakshakLabs lesson in the supplied article. The real assets may be:

🔐 Payment credentials
📱 Device access
💳 Card information
🔢 UPI authentication
🔄 Recurring mandate
👤 Personal information
📲 Application permissions
The attacker may not be interested in your ₹1. They may be interested in what the ₹1 convinces you to authorize.
Why Legitimate AutoPay Makes the Scam More Convincing

The supplied research describes a cybersecurity paradox: AutoPay exists to make legitimate recurring payments easier. NPCI supports recurring mandates for legitimate services including OTT subscriptions, utility bills, insurance and other recurring payments.

The technology is therefore not automatically the problem. Deception around the technology is the problem. Users need to understand what they are authorizing.

What Users Should Check Before Paying ₹1
CHECK 1 — Where did the link come from?
Official OTT app or website? WhatsApp forward? Instagram ad? Facebook post? Unknown message?
CHECK 2 — Look at the domain
Do not trust the logo, colours or show artwork alone. Check the actual domain name.
CHECK 3 — Read the payment screen
Look for Recurring, AutoPay, Mandate, Monthly, Weekly, Validity, Maximum Amount and Merchant.
CHECK 4 — Check your AutoPay mandates
Review active mandates in your payment app. If you find one you do not recognize, revoke it immediately.
The Most Important Rule
Never enter your UPI PIN just because a website tells you it is required to receive a refund, watch a video, verify your identity or unlock content.

The supplied research explains that the UPI PIN is an authentication factor for payment. You should understand what you are authorizing before entering it.

If You Already Approved the Scam
STEP 1 — Open your UPI/payment application.
STEP 2 — Check Autopay / Mandates / Recurring Payments.
STEP 3 — Identify unfamiliar mandates.
STEP 4 — Revoke or pause the suspicious mandate.
STEP 5 — Contact your bank/payment provider.
STEP 6 — If money has already been lost, report the financial cyber fraud through 1930 and cybercrime.gov.in.
STEP 7 — Preserve screenshots, URL, social-media post, merchant information, mandate ID, transaction ID, UPI ID, SMS and application package/details if installed.
Source discipline: This Research page is based on the supplied CyberRakshakLabs post. Claims about complaint counts, reported incidents and external guidance are presented as described in that source; CyberRakshakLabs does not independently verify those external reports on this page.
The ₹1 Is Not the Threat. The threat is what the ₹1 convinces you to authorize.

🔥 Final Takeaway

WHO? Who is offering this?

WHERE? Where did the link come from?

WHAT? What exactly am I authorizing?

RECURRING? Is this a one-time payment or AutoPay mandate?

WHY? Why does an entertainment offer need this level of payment or device access?

If you cannot answer those questions:

Don't pay. Don't install. Don't proceed.

A ₹1 offer can be cheap entertainment — or an expensive lesson.

CyberRakshakLabs Think Before You Click. Stay Aware. Stay Secure.