India

Phishing simulation for India’s
UPI, KYC and WhatsApp lures.

In India, employees are targeted through UPI collect requests, KYC-update texts, GST and income-tax refund lures, payroll changes on WhatsApp and “digital arrest” style calls.

Regulators & frameworks
DPDP Act and Rules 2025, CERT-In, SEBI CSCRF, RBI Cybersecurity Directions 2026, IRDAI Guidelines 2026
Channels to rehearse
SMS and RCS, WhatsApp, voice calls, email, Teams and Slack
Local lure patterns
UPI collect requests, KYC updates, GST and income-tax refunds, “digital arrest” calls
KeenSec evidence
Simulation results, reporter logs, certificates, policy acknowledgements

Simulated Indian lures

The messages your people
actually receive.

Simulated examples of lures common in India.

Simulated example
WhatsApp

“Refund desk” · unknown number

Your GST refund is ready

We have sent a UPI collect request to release your refund. Approve it and enter your UPI PIN to receive the amount.

  • A collect request takes money, it never pays it
  • PIN asked to “receive” funds
Simulated example
Voice call

Caller claiming to be an investigating officer

“Digital arrest” pressure call

“A parcel in your name has been seized. Stay on this call, tell no one, and move your funds to a safe account while we verify you.”

  • Isolation: “tell no one”
  • Payment to clear your name
Rehearsed as an IVR or agentic AI voice call.

Regulators and frameworks

What Indian frameworks expect,
and the evidence you can show.

FrameworkApplies toPeople-side relevanceKeenSec evidence
DPDP Act 2023 + DPDP Rules 2025Organisations processing digital personal dataFrom May 2027: reasonable security safeguards, and personal data breaches reported to the Data Protection Board and affected people.Workforce awareness evidence: data-handling training, simulation results, policy acknowledgements
CERT-In Directions and advisoriesOrganisations covered by the DirectionsPhishing attacks reported within 6 hours; 2025–2026 advisories recommend phishing training with realistic simulations.Phishing Reporter logs with automated analysis, so suspicious messages reach your team with the analysis attached
SEBI CSCRFSEBI-regulated entitiesMandatory awareness programmes, a Board programme and periodic assessment, for example phishing test success rate.Training completions and certificates, simulation results by team
RBI Cybersecurity Directions 2026Banks, NBFCs and other RBI-regulated entitiesAwareness for new recruits, annual management and Board training, periodic evaluation of staff awareness.Simulation, training and policy records
IRDAI Guidelines 2026Insurers and intermediariesTracked awareness training, phishing handling and an annual assurance audit.Simulation, training and policy records

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

Questions buyers ask

Frequently asked questions.

Does KeenSec make us DPDP compliant?

No. KeenSec helps you build workforce awareness evidence toward DPDP’s reasonable security safeguards: training records, simulation results and policy acknowledgements. Your auditor and counsel decide compliance.

Can we simulate UPI collect and KYC-update scams?

Yes. KeenSec runs UPI collect, KYC-update, GST-refund and payroll-change scenarios over SMS and RCS, WhatsApp, email and voice, each with a matching just-in-time lesson.

Does the Phishing Reporter work with our mail platform?

Yes. It works across every major mail platform, and every report is analysed automatically.

Let’s connect the dots

Rehearse India’s real lures.
Prove it to every regulator.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo