Fraud Isn’t Just Calls and SMS Anymore: How Fake Websites Are Stealing From Indians Right Now
When people think about online fraud in India today, the first images that come to mind are usually a scary phone call, a suspicious SMS with a link, or the now widely-discussed “digital arrest” video call scam. What gets far less attention, and arguably deserves just as much caution, is a fraud that doesn’t call you or message you at all. It simply waits for you to search, click, and type, on a website built to look exactly like one you already trust.
In August 2026, the Supreme Court of India itself had to issue a public notice warning citizens about a fraudulent website, sp-court-in.com, built to closely resemble the Court’s own official portal, sci.gov.in, and designed specifically to harvest people’s personal and banking details through phishing. If the Supreme Court of India can be impersonated convincingly enough to require a formal public warning, it’s worth taking seriously just how sophisticated fake websites targeting ordinary consumers, taxpayers, and shoppers have become.

Quick Answer
Fake websites are a distinct and growing category of online fraud in India, separate from phone-based scams like digital arrest calls, and they generally fall into a few recognisable types: cloned government portals designed to steal personal and banking data, fake e-commerce sites that take payment for products that never arrive, and hijacked or compromised legitimate websites, including actual government domains, that quietly redirect visitors to fraudulent content. In August 2026 alone, the Supreme Court Registry issued a fresh public advisory against a fake website impersonating its official portal, its third such warning since July 2025, and cybersecurity researchers separately reported that more than 100 Indian government and public-sector domains had been compromised earlier in the year to push gambling content through search engines. Before entering any personal, banking, or payment information on a website, the essential checks are to verify the exact domain name against the organisation’s officially published web address, look for a genuine, matching SSL certificate rather than just any padlock icon, and never trust a link received through an SMS, WhatsApp message, or search ad without independently confirming it through the organisation’s own verified channel first.
About This Guide
This guide is based on official public advisories from the Supreme Court of India Registry, the Employees’ Provident Fund Organisation, Delhi Police’s Cyber Cell, and reporting on a June 2026 mass compromise of Indian government domains, current as of August 2026. FinanceChecks.com is not a law enforcement agency, cybersecurity firm, or government body, and this article is intended purely for consumer awareness. If you believe you’ve entered sensitive information on a fraudulent website, act immediately using the steps outlined later in this article rather than waiting.
The Different Ways a Fake Website Actually Works
Cloned government and institutional portals. This is the most alarming category, precisely because it exploits the trust people place in official-looking domains. Fraudsters register a domain name that looks almost identical to a genuine government or institutional website, often differing by a single character, an added hyphen, or a different extension, and then build a visually convincing replica of the real site. The Supreme Court’s own August 2026 advisory is a clear, recent example: the fraudulent domain sp-court-in.com was built specifically to resemble sci.gov.in, the Court’s actual website, and the Registry warned it could be used to solicit passwords, personal details, and banking information from unsuspecting visitors. This was not an isolated incident either; the Registry had already flagged 16 separate fake domains impersonating the Supreme Court in a single notice back in July 2025, and another fraudulent domain in April 2026, showing this is a persistent, evolving problem rather than a one-time event. Separately, in June 2026, cybersecurity researchers reported that attackers had compromised more than 100 actual Indian government and public-sector domains, using a technique where Google’s search crawler was shown normal-looking content while real visitors arriving from search results were redirected to offshore gambling and betting platforms, a method specifically designed to stay undetected by both search engines and casual visual inspection. The Employees’ Provident Fund Organisation also issued its own warning on August 11, 2026, cautioning members specifically about fake websites, phishing links, and fraudulent messages targeting their provident fund accounts.
Fake e-commerce and shopping websites. According to Delhi Police’s Cyber Cell, this fraud takes a couple of distinct forms. In one version, fraudsters clone the look of a genuine, well-known brand’s website, sometimes even a recognisable electronics or mobile phone brand, and offer products at unusually low prices to attract buyers. In the other version, fraudsters don’t bother imitating any specific real brand at all; they simply build an entirely new-looking store, list products at steep discounts, and disappear once payment is collected. In both versions, the pattern is identical: the customer pays online and never receives the product, and the website, along with any contact information listed on it, typically vanishes shortly afterward. These operations frequently run through paid social media advertising on platforms like Facebook and Instagram, since fraudsters can advertise for a short window before being flagged and removed, cycling through new fake stores repeatedly. Cash-on-delivery orders aren’t fully safe from this either; a variant involves fraudulent sellers shipping a cheap, unrelated item, sometimes literally a brick or a piece of plastic, inside packaging that the courier doesn’t allow customers to open before paying.
Fake booking and travel portals. A related pattern specifically targets travellers and pilgrims. The Indian Cyber Crime Coordination Centre has previously issued public alerts about fraudulent websites and social media pages offering fake bookings for popular pilgrimage and tourist services, including helicopter bookings for religious sites, where fraudsters build convincing but entirely fake booking platforms, collect payment, and never deliver any actual reservation.
Compromised legitimate websites. This is the category most likely to catch even careful, security-conscious users off guard, because the underlying website is genuinely real; it’s simply been quietly taken over or manipulated by attackers without the visitor being able to tell. The mass compromise of over 100 government domains in June 2026, used to inject gambling redirects specifically for mobile users arriving through search results, is a clear example of how a website can look completely legitimate on the surface, since site administrators themselves reportedly saw only a normal page, while still being actively used to defraud or mislead visitors.
Why This Category of Fraud Is Genuinely Harder to Spot Than a Scam Call
A phone call demanding money or threatening arrest has an obvious, immediate tell: the urgency and the direct ask are usually jarring enough to eventually trigger suspicion, even if it takes a while. A fake website doesn’t behave that way. It sits passively, waiting to be found through a search result, a social media ad, or a shared link, and it only needs to look convincing for the handful of seconds it takes someone to type in their PAN, bank details, or card number. There’s no live conversation to second-guess, no voice to sound suspicious, just a form field and a submit button. This is precisely why the Delhi High Court has separately taken up the broader structural issue, ruling that e-KYC should be made mandatory for domain name registrations in India specifically because of cases involving fraudulent websites impersonating established, legitimate brands, and directing domain registrars to retain verified identity information that can be handed to investigating authorities when formally required.
How to Actually Check If a Website Is Genuine
Check the exact domain name, character by character, not just the general look of the site. Fraudulent domains impersonating the Supreme Court have used variations like sp-court-in.com, scigovjudicial.com, and supremecourtofindiagov.com, all designed to look plausible at a glance while differing from the genuine sci.gov.in domain. For any government website, the safest general rule is to check specifically for a .gov.in or .nic.in domain extension, and to independently navigate to the site by typing the address yourself or searching for the organisation’s name, rather than clicking a link sent to you.
Don’t treat a padlock icon or “https” as proof of legitimacy on its own. A padlock simply means the connection between your browser and the website is encrypted; it says nothing about whether the website itself is genuine or trustworthy. Fraudulent sites, including well-built fake e-commerce and phishing portals, routinely carry a valid SSL certificate and the padlock icon, since obtaining basic encryption certificates is neither difficult nor expensive for anyone building a website, fraudulent or otherwise.
Be specifically cautious of any link that arrived via SMS, WhatsApp, email, or a social media ad, rather than one you found by deliberately navigating to an official source yourself. This applies whether the message claims to be about a parcel delivery, a government scheme, a refund, or an unbeatable discount. If in doubt, don’t click the link at all; instead, open a browser separately and navigate to the organisation’s website by typing its known address or searching for it directly.
For e-commerce specifically, be wary of unusually steep discounts, missing or vague contact details, and a complete absence of any track record or reviews beyond the platform hosting the ad itself. Genuine online reviews can also be gamed; fraudulent sellers sometimes pay for large volumes of fake positive reviews or influencer-style promotional videos specifically to appear more trustworthy than they are, so reviews alone, particularly reviews only visible on the seller’s own site or social page, aren’t sufficient proof of legitimacy.
For government portals and schemes specifically, cross-check the website against the parent department’s officially published list of verified domains, rather than trusting a site simply because it displays government emblems or a minister’s photo. Fraudulent sites impersonating schemes and government job portals have historically used official-looking logos and even video content to appear legitimate, none of which are difficult for a fraudster to copy.
Never provide an OTP, CVV, or full card details to anyone over a call claiming to be from “customer service” for an order you placed online. Genuine customer service processes for verifying or resolving an order essentially never require your OTP or full card number read aloud over a call; this is one of the most common tactics used specifically after a fake or hijacked order confirmation message has already drawn a shopper in.
You May Also Like To Read About:
What to Do If You’ve Already Entered Information on a Suspicious Website
Change the passwords on any accounts where you’ve reused the same password as the one entered on the suspicious site, since fraudsters frequently test stolen credentials against multiple platforms.
Contact your bank immediately if any banking, card, or UPI details were entered, and ask them to monitor or temporarily block the account or card if there’s any indication of compromise; most major Indian banks maintain a dedicated fraud helpline for exactly this situation.
Report the incident at the National Cyber Crime Reporting Portal, cybercrime.gov.in, or call the national cybercrime helpline at 1930, and preserve screenshots of the fraudulent website and any related messages as evidence.
If the impersonated organisation has published an official advisory or contact channel for reporting fake domains, as the Supreme Court Registry and EPFO have both done, report the specific fraudulent URL to them directly as well, since this helps trigger a formal takedown process.
Monitor your bank statements and credit report closely over the following weeks, since stolen financial information is sometimes used gradually rather than immediately, to avoid triggering early fraud detection systems.
My Take
What I find genuinely striking about this category of fraud, more than the phone-based scams that tend to dominate public conversation, is how little it actually requires from the victim beyond a moment of ordinary, everyday trust. Nobody has to be pressured into a panic or isolated on a video call for a fake website to work; they simply have to search for something, click a result that looks plausible, and fill in a form the way they’ve filled in hundreds of legitimate ones before. That the Supreme Court of India, an institution about as authoritative as they come, has needed to issue three separate public warnings against domains impersonating its own website since mid-2025 tells you this isn’t a fringe problem being solved quietly in the background; it’s an active, evolving cat-and-mouse game that ordinary consumers are being asked, implicitly, to help fight simply by getting slightly more careful about the URLs they trust. The good news is that the actual defence here is genuinely simple, checking the exact domain and never trusting a link you didn’t go looking for yourself, even if building the habit of doing it every single time takes some deliberate effort.
Frequently Asked Questions
1. How can I tell if a government website is genuine? Check for a .gov.in or .nic.in domain extension specifically, and navigate to the site by typing the known address yourself or searching for the organisation’s name directly, rather than clicking a link sent to you through SMS, WhatsApp, or email.
2. Does a padlock icon or “https” in the address bar mean a website is safe? No, not on its own. The padlock only confirms the connection is encrypted; it says nothing about whether the website itself is genuine. Many well-built fraudulent websites, including phishing and fake shopping sites, carry a valid SSL certificate and padlock icon.
3. What happened with the fake Supreme Court website in 2026? In August 2026, the Supreme Court Registry issued a public notice warning that a fraudulent domain, sp-court-in.com, was impersonating its official website, sci.gov.in, and could be used for phishing to obtain personal and banking information. This was the Registry’s third such public warning since July 2025.
4. Can real government websites actually be hacked and used for fraud? Yes. In June 2026, cybersecurity researchers reported that attackers had compromised more than 100 genuine Indian government and public-sector domains, using techniques to redirect visitors arriving from search engines to gambling and betting platforms, while site administrators saw only a normal-looking page.
5. How do fake e-commerce websites typically operate? They either clone the appearance of a genuine, recognisable brand’s website or create an entirely new-looking store, offer products at steep discounts, collect online payment, and then disappear without delivering the product, often advertising through short-lived social media ad campaigns.
6. Is Cash on Delivery completely safe from online shopping fraud? Not entirely. Some fraudulent sellers ship a cheap, unrelated item in sealed packaging that couriers don’t allow customers to open before paying, meaning the buyer ends up paying for something worthless even though it was technically a “Cash on Delivery” order.
7. What should I do if I’ve already entered my details on a suspicious website? Change passwords on any accounts using the same credentials, contact your bank immediately if banking or card details were involved, report the incident at cybercrime.gov.in or by calling 1930, and monitor your bank statements closely over the following weeks.
8. Are online reviews a reliable way to check if a shopping website is genuine? Not entirely. Fraudulent sellers sometimes pay for large volumes of fake positive reviews or promotional content specifically to appear trustworthy, so reviews alone, especially those only visible on the seller’s own site, aren’t sufficient proof of legitimacy.
9. Why is it risky to click links in SMS or WhatsApp messages about deliveries, refunds, or government schemes? These messages are a common vector for fake websites designed to look like courier services, e-commerce platforms, or government portals. It’s safer to independently navigate to the organisation’s known website yourself rather than clicking a link you didn’t go looking for.
10. What legal steps has India taken to address fake websites impersonating real brands and institutions? The Delhi High Court has ruled that e-KYC should be mandatory for domain name registrations in India, specifically citing cases involving fraudulent websites impersonating established brands, and has directed domain registrars to retain verified identity information that can be provided to investigating authorities when formally required.
Disclaimer
This article is intended for general informational and educational purposes only. FinanceChecks.com is not a law enforcement agency, cybersecurity firm, or government body, and this article does not constitute legal or technical security advice. Information regarding specific fraudulent domains and public advisories referenced here reflects publicly reported information as of August 2026 and may not represent a complete or current list of active threats. If you believe you have encountered a fraudulent website or been a victim of online fraud, contact the National Cyber Crime Reporting Portal at cybercrime.gov.in or call the national cybercrime helpline at 1930 for official guidance specific to your situation.
Shuchi founded Finance Checks after spending 16+ years working in corporate, managing operations and distribution. She managed her own finances, learned and read regularly and helped people make sense of their savings, loans, insurance, and investments.
She started this site to offer the kind of clear, honest financial guidance she wished was more available when she was learning to manage her own money. Every article is researched personally, checked against official sources such as the Reserve Bank of India, SEBI, or the Income Tax Department, and revisited whenever regulations or figures change. She is upfront about how the site earns money through ads and select affiliate partnerships, and she does not let either influence what she actually recommends to readers.