A smartphone that suddenly becomes unresponsive after a user clicks on an advertisement or an unfamiliar link may initially appear to be a simple technical problem. However, cybersecurity experts warn that such incidents can sometimes be part of a larger fraud attempt designed to create panic and persuade users to hand over access to their devices or financial information.
The so-called frozen screen UPI scam combines technical tricks with social engineering. Fraudsters may use fake error messages, malicious applications, remote-access software and excessive Android permissions to convince victims that their phone, banking application or UPI account has developed a problem.
According to Harish Kumar, CEO of Quick Heal Technologies, the frozen screen may serve primarily as a distraction rather than being the actual objective of the attack.
How the Frozen Screen Scam Works
After creating the impression that something has gone wrong, scammers may contact the victim while posing as customer support or technical assistance representatives. They can claim that the user’s banking application or UPI account needs to be verified or repaired.
The victim may then be instructed to install an application, often in the form of an APK, which is presented as a verification, cashback, reward or service application.Kumar told NDTV that victims can be persuaded to install such applications because they believe doing so will resolve the supposed technical issue or help them claim a reward. Once installed, the malicious application may request access to sensitive Android functions.
How Malicious Apps Can Put User Data at Risk
Applications with excessive permissions can potentially access notifications, SMS messages and other information on the device. Abuse of accessibility permissions can also give malicious software greater control over certain elements of a phone.
According to Kumar, the India Cyber Threat Report 2026 by researchers at Seqrite Labs documents how fake service and utility applications can seek SMS, call and notification permissions to collect sensitive information. Such access can potentially help fraudsters obtain information that could be used to facilitate financial fraud.
Scammers May Not Need to Break UPI Security
Experts say these scams do not necessarily require criminals to defeat the security mechanisms built into UPI. Ruchin Kumar, Vice President – South Asia at Futurex, told NDTV that attackers can instead target the device, login credentials, authentication factors or the payment process surrounding a transaction.
Potential methods include stealing banking credentials through fake applications or websites, intercepting SMS-based OTPs, misusing Android accessibility features and using screen-sharing applications to monitor a victim.Social engineering can also play a major role. A victim may unknowingly enter their UPI PIN or approve a payment after being convinced that they are resolving a technical problem.
As a result, the transaction may appear to have been legitimately authenticated even though the victim was manipulated into approving it.
Why Scammers Create a Fake Technical Emergency
The scam relies heavily on urgency and fear. When users believe their phone or banking application has stopped working, they may be more likely to follow instructions from someone claiming to be a technical support representative.
Ravindra Singh, Managing Director of Delcom Telesystems, told that fraudsters are increasingly exploiting people’s trust in technology by creating a sense of urgency and then persuading them to install remote-access, screen-sharing or verification applications.The apparent technical failure therefore becomes a way to gain the victim’s trust and move the conversation towards device access or financial information.
How to Protect Yourself
If a phone suddenly freezes after clicking an unfamiliar advertisement or link, users should avoid immediately following instructions from unknown callers or messages.
They should:
Disconnect mobile data and Wi-Fi if they suspect a malicious application or remote access.
Avoid entering banking credentials or UPI PINs.
Do not install APK files received through unsolicited messages, advertisements or phone calls.
Avoid giving unknown people remote access or screen-sharing control.Review and disable unnecessary accessibility, notification and device-administration permissions.
Remove suspicious applications and scan the device using a trusted security solution.
Verify any claimed banking or technical problem directly through the institution’s official channels.
What to Do If You Suspect Financial Fraud
Anyone who believes their banking information or payment account may have been compromised should immediately contact their bank through an official channel and review recent transactions.
A transaction can appear to be properly authenticated even when a user has been manipulated into approving it. The key warning signs are therefore important: a sudden frozen screen followed by an unsolicited support call, a request to install an APK, a demand for remote access or a request for banking information should be treated with caution.
Genuine banks and payment service providers do not require customers to hand over control of their devices or share sensitive credentials to resolve a routine UPI issue. When faced with such a situation, users should stop the interaction and independently verify the problem through an official channel.

