India
Phishing simulation for India’s
UPI, KYC and WhatsApp lures.
In India, employees are targeted through UPI collect requests, KYC-update texts, GST and income-tax refund lures, payroll changes on WhatsApp and “digital arrest” style calls.
- Regulators & frameworks
- DPDP Act and Rules 2025, CERT-In, SEBI CSCRF, RBI Cybersecurity Directions 2026, IRDAI Guidelines 2026
- Channels to rehearse
- SMS and RCS, WhatsApp, voice calls, email, Teams and Slack
- Local lure patterns
- UPI collect requests, KYC updates, GST and income-tax refunds, “digital arrest” calls
- KeenSec evidence
- Simulation results, reporter logs, certificates, policy acknowledgements
Simulated Indian lures
The messages your people
actually receive.
Simulated examples of lures common in India.
“Refund desk” · unknown number
Your GST refund is ready
We have sent a UPI collect request to release your refund. Approve it and enter your UPI PIN to receive the amount.
- A collect request takes money, it never pays it
- PIN asked to “receive” funds
Caller claiming to be an investigating officer
“Digital arrest” pressure call
“A parcel in your name has been seized. Stay on this call, tell no one, and move your funds to a safe account while we verify you.”
- Isolation: “tell no one”
- Payment to clear your name
Regulators and frameworks
What Indian frameworks expect,
and the evidence you can show.
| Framework | Applies to | People-side relevance | KeenSec evidence |
|---|---|---|---|
| DPDP Act 2023 + DPDP Rules 2025 | Organisations processing digital personal data | From May 2027: reasonable security safeguards, and personal data breaches reported to the Data Protection Board and affected people. | Workforce awareness evidence: data-handling training, simulation results, policy acknowledgements |
| CERT-In Directions and advisories | Organisations covered by the Directions | Phishing attacks reported within 6 hours; 2025–2026 advisories recommend phishing training with realistic simulations. | Phishing Reporter logs with automated analysis, so suspicious messages reach your team with the analysis attached |
| SEBI CSCRF | SEBI-regulated entities | Mandatory awareness programmes, a Board programme and periodic assessment, for example phishing test success rate. | Training completions and certificates, simulation results by team |
| RBI Cybersecurity Directions 2026 | Banks, NBFCs and other RBI-regulated entities | Awareness for new recruits, annual management and Board training, periodic evaluation of staff awareness. | Simulation, training and policy records |
| IRDAI Guidelines 2026 | Insurers and intermediaries | Tracked awareness training, phishing handling and an annual assurance audit. | Simulation, training and policy records |
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
Questions buyers ask
Frequently asked questions.
Does KeenSec make us DPDP compliant?
No. KeenSec helps you build workforce awareness evidence toward DPDP’s reasonable security safeguards: training records, simulation results and policy acknowledgements. Your auditor and counsel decide compliance.
Can we simulate UPI collect and KYC-update scams?
Yes. KeenSec runs UPI collect, KYC-update, GST-refund and payroll-change scenarios over SMS and RCS, WhatsApp, email and voice, each with a matching just-in-time lesson.
Does the Phishing Reporter work with our mail platform?
Yes. It works across every major mail platform, and every report is analysed automatically.
Let’s connect the dots
Rehearse India’s real lures.
Prove it to every regulator.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo