SECURITYSeptember 10, 2026 · 9 min read·0

Diwali 2026 Phishing Playbook: 828 Fake Ad Domains, 1-in-3 Indians Duped, and the UPI + Deepfake Trap

McAfee's 2025 Global Holiday Shopping Scams Study — the last full-year India benchmark before Diwali 2026 — found one in three Indians duped by festive-season scams, 37 percent suffering financial loss, average loss over ₹41,500. Quick Heal's Seqrite Labs identified 828 distinct phishing domains running Facebook Ads campaigns in one festive window. Here is the 2026 playbook — the brands attackers impersonate, the domain patterns Domainscan catches, and the 30-second check to run before every festive payment.

A
DomainScan
𝕏 Share
Security

Diwali 2026 falls on November 8. In eight weeks India will run its largest annual online-payment surge — Flipkart Big Billion Days, Amazon Great Indian Festival, Meesho Mega Blockbuster, IRCTC festival rush, and hundreds of smaller brand sales — and the phishing economy has already spun up its inventory. Historically the pattern is not subtle. McAfee’s 2025 Global Holiday Shopping Scams Study — the last full-year India benchmark before this year’s festive season — found one in three Indian consumers duped by holiday-related scams, 37 percent of victims suffering measurable financial loss, and 46 percent of those losing more than ₹41,500. Quick Heal’s Seqrite Labs, working through the Facebook Ads Library, identified 828 distinct phishing domains running paid advertisements against Indian shoppers in a single festive window.

Two conclusions follow. The first is that a paid social ad is no longer a trust signal — Meta’s approval bar is well below the bar attackers can clear at a few dollars per campaign. The second is that the volume is too high for any “check the URL carefully” rule to hold. Detection has to move to the infrastructure — WHOIS, DNS, MX, SSL — and the check has to be fast enough to run between clicking a link and typing a UPI PIN.

The Indian festive-scam benchmark

McAfee’s 2025 survey of Indian consumers produced the numbers most defenders reference as their baseline going into Diwali 2026:

  • 1 in 3 Indian consumers report being duped by a festive-season scam. 37% of those lost money; 46% of losers lost more than ₹41,500. Small basket, high frequency, high per-victim take.
  • 12 scam attempts per day per consumer during peak festival weeks — texts, emails, WhatsApp forwards, sponsored social posts. 91% report receiving suspicious messages. The exposure is universal.
  • 49% of the suspicious messages framed as fake “gift card wins,” 40% as “limited-time offers,” 27% as “refund alerts.” The lure taxonomy is tight and repeatable — which is also why the domain infrastructure behind it is repeatable.
  • 77% of Indian shoppers now transact on smartphones. That means the fraud surface is the mobile web — where URL bars are truncated, SSL indicators are subtle, and taps to pay are two fingers away.
  • 72% of consumers believe AI-driven scams are more dangerous than last year, and 84% report increased concern about deepfake scams — the volume of AI-produced ad creative and celebrity impersonation is genuinely new for Diwali 2026.
Volume alone is the story
Twelve daily scam attempts × eight weeks of festival buildup × 850 million Indian internet users is the operational reason manual triage does not work at this time of year. The defense that scales is a fast infrastructure check on every unfamiliar payment domain.

The five brands attackers impersonate most during Diwali

From Seqrite Labs’ sweep of the Facebook Ads Library, three years of CERT-In festival advisories and consumer-report telemetry, the impersonation shortlist for Diwali 2026 concentrates on the brands with the highest transaction velocity in the window:

  1. IRCTC and airline booking portals. Peak-season IRCTC handles 13 lakh+ daily bookings; airline portals absorb the visa-and-vacation surge. Fake booking sites clone the IRCTC interface and drop payment straight to attacker UPI IDs.
  2. Flipkart Big Billion Days, Amazon Great Indian Festival, Meesho Mega Blockbuster. Domain names with hyphenated brand-adjacent forms — bigbillion-offers.top, flipkart-diwali.shop, meesho-mega.online — that look plausible when clipped on a mobile URL bar.
  3. UPI apps: PhonePe, Google Pay, Paytm, BHIM. Fake “cashback” and “refund” landing pages that trigger a real UPI collect request. The user sees an amount, thinks they are receiving money, approves the PIN, sends money instead.
  4. Retail banking brands. HDFC, SBI, ICICI, Axis. KYC re-verification lures during the festival window — a call-to-action that seems seasonally reasonable and lands the user on a credential-harvest form.
  5. Instant-loan and BNPL brands. Bajaj Finserv, Kissht, Slice, Simpl. Instant-approval lures with a “processing fee” UPI request. The fee is the fraud; no loan exists.

The three tactics dominating Diwali 2026

Quick Heal’s festive advisory names three attack shapes explicitly. Everything else is a variant.

  1. AI-personalised phishing campaigns. GenAI writes the ad creative, the landing page copy, the follow-up SMS, and the fake customer-service transcript — all in localised Hindi, Marathi, Tamil, Bengali. What used to be a giveaway (broken English, generic templates) is now a solved problem for the attacker.
  2. Counterfeit booking and e-commerce portals. Pixel-perfect clones of IRCTC, Flipkart, Amazon India — served over HTTPS, indexed in Google, and increasingly appearing as sponsored results directly next to the real brand.
  3. UPI and QR-code redirection. A QR sticker or a “pay to receive cashback” link that opens a real UPI collect request. The user reviews an incoming amount, approves without reading direction, and money leaves their account.

Combined with a ₹90,000 crore Diwali 2024 e-commerce total (Quick Heal’s baseline figure) and the growth trajectory into 2026, the return on a single successful phishing kit is measured in lakhs per week. That is why the domain inventory keeps expanding.

The 828-domain Facebook Ads fingerprint

Seqrite’s single most useful finding: 828 distinct phishing domains were surfacing paid Facebook Ads in one festive window. Facebook Ads Library is public, which means the domains behind every paid ad are queryable. That produces a defender-friendly fingerprint for the whole cluster.

  • Cheap-TLD bulk registration. The vast majority of the 828 domains sit on .top, .shop, .online, .xyz, .click, .store — TLDs whose registration cost is under ₹100 and whose abuse rates are documented in every registrar reputation dataset.
  • Registration age under 30 days. A legitimate merchant does not register a Diwali domain in October and expect Google to trust it by November. Phishing operators do, because they only need two weeks of ad clicks.
  • Nameserver concentration. Cloudflare and a small set of low-cost DNS providers dominate the phishing NS distribution. Cross-referencing NS records against a bulk-registered brand-adjacent name and a fresh creation_date is a three-flag composite.
  • Wildcard SSL from free CAs. Let’s Encrypt and ZeroSSL issue within minutes of DNS provisioning. Every domain in the 828 set is HTTPS by default — the padlock is now a base feature of the phishing kit, not an anti-phishing signal.

Domainscan runs the same infrastructure checks on any unfamiliar payment URL — WHOIS creation date, registrar reputation, NS pattern, SSL age, MX presence, reverse IP, and blacklist correlation — and composites the twelve signals into a single Trust Score. The check is designed to run in the seconds between opening a WhatsApp link and typing a UPI PIN.

The UPI request trap

The single most Diwali-specific fraud is the UPI collect-request inversion. It works because UPI request confirmations are visually similar to UPI receive confirmations, especially on cluttered mobile screens.

  1. Victim receives a message: “Your ₹2,000 cashback for Diwali offer #DIW26 has been approved. Confirm on your UPI app to receive.”
  2. Message contains a UPI deep-link. Tapping it opens the UPI app with a pre-filled collect request from an attacker VPA. The screen shows the amount (₹2,000) prominently.
  3. Victim reads the amount, sees an official-looking merchant name (DIWALIREWARDS@upi), approves the PIN thinking they are receiving.
  4. ₹2,000 leaves the victim’s account. The attacker VPA is disposable and rotated between campaigns. No receipt matches on either side.
The one UPI rule that stops this class of scam
UPI collect requests always require your PIN to send money. Receiving money never requires a PIN. If a “cashback” or “refund” asks you to enter your UPI PIN, it is a send. Cancel and check with the merchant through their official app.

Deepfake celebrity endorsements

The 2026-specific escalation is the AI-produced celebrity endorsement. 69 percent of Indian consumers report encountering fake celebrity endorsements in festive advertising, per McAfee’s data — with 45 percent saying they or someone they know has fallen for a deepfake shopping scam.

  • Video ads with recognisable faces — cricketers, film stars, popular anchors — endorsing a specific brand’s Diwali offer that the celebrity has no relationship with. The visual quality has crossed the threshold where casual scrolling does not catch it.
  • Voice clones on WhatsApp calls impersonating a family member with an urgent Diwali gift request, or a bank manager confirming a KYC update.
  • Fabricated news screenshots mimicking Times of India, NDTV or Hindustan Times layouts, announcing celebrity-backed Diwali offers with a shortened URL to a phishing landing page.

The infrastructure defense for the deepfake tier is the same as for the counterfeit-portal tier — the domain the ad or the fake news screenshot links to still has to be registered, DNS-configured and SSL-provisioned. The deepfake is the lure; the domain is the trap. Domainscan checks the trap.

The 30-second check before you pay

For a consumer holding a phone in a Diwali sale scroll, the useful check is the one that fits in the interval between tapping a link and entering a payment method. Domainscan’s Trust Score is designed for that window.

  • Paste the URL into Domainscan. WHOIS age, registrar reputation, NS pattern, MX presence, SSL chain age, reverse IP neighbours, and abuse-blacklist correlation are checked in parallel. Any two red flags = do not pay.
  • Check the domain, not the URL bar. Mobile browsers truncate. A URL that shows flipkart.com… could be flipkart.com.diwali-offers.top. The Trust Score resolves the full domain.
  • If the seller is IRCTC, PhonePe, Flipkart, a bank or a UPI service, close the browser and go through the official app. Legitimate Diwali offers from these brands are always available in the app. Ad-linked landing pages are almost never necessary.
Run a Trust Score before you pay
WHOIS, DNS, MX, SSL, reverse IP and blacklist — twelve infrastructure checks in one score. Free, no signup.
Try it

For brand owners: the four-week runway

If you run marketing or security for an Indian brand — retail, banking, travel, UPI, BNPL — the window to harden your posture before Diwali 2026 is closing. The 828-domain Facebook Ads figure from last year understates 2026’s inventory; assume higher. Practical work items in priority order:

  1. Enrol your brand into Domainscan’s Typosquat monitor. Character-substitution (fl1pkart), hyphenation (flipkart-diwali), prefix/suffix (flipkart-offers, diwali-flipkart) and cheap-TLD sweeps across.top, .shop, .online, .xyz — the full permutation set is generated and re-checked daily. New registrations trigger alerts within hours of the domain entering the zone file. Companion post: the 2026 typosquat mechanics deep-dive covers the 301+MX and Ray-ID geo-filter tricks the same operators use.
  2. Enforce DMARC p=reject on every domain you own — including parked domains and marketing subdomains. The lure-email tier of Diwali phishing spoofs the brand’s From header; DMARC alignment is what makes the receiver’s inbox provider reject it.
  3. Report paid ads impersonating your brand. Facebook Ads Library, Google Ads Transparency Centre and X Ads Repository are all queryable. Weekly sweeps for your brand name plus common festival modifiers surface the paid impersonation tier that free brand monitors miss.
  4. Publish an authoritative “how to identify our Diwali offers” page on your real domain, in the language your customers use. Rank it for your brand+diwali+scam search queries. Consumers who search for verification usually find whichever page ranks first — make sure that page is yours.
Audit your DMARC before Diwali
DMARC, SPF and DKIM in one report — enforcement level, alignment, syntax and rotation across every record.
Open Email Security

What to do this week

  1. Consumers: bookmark Domainscan’s Trust Score. Any Diwali offer link received on WhatsApp, SMS or social — paste, wait five seconds, read the score, decide.
  2. Consumers: install the official apps of the brands you actually buy from. Do all Diwali purchases through the app. Ad-linked landing pages are the highest-risk vector this season.
  3. Brand owners: run one WHOIS + DNS sweep of the ten most likely typosquat variants of your brand across .top, .shop, .online, .xyz today. Anything registered in the last 60 days = investigate.
  4. Brand owners: schedule a Diwali advisory blog post on your own domain, in the search languages your customers use. Publish four weeks before Diwali (early October) to accrue Google trust before the search spike.
  5. Everyone: share the “PIN = send, no PIN = receive” UPI rule with the least technical person in your family. That single sentence blocks the most common Diwali UPI trap class.

Source

Consumer benchmark data: One in Three Indians Duped in Festive-Season Scams as AI and Deepfakes Rewrite Cybercrime Playbook — coverage of the McAfee 2025 Global Holiday Shopping Scams Study (Pratim Mukherjee, October 12, 2025). Domain-inventory and technique data: Quick Heal / Seqrite Labs advisory on AI-powered cyber scams targeting Diwali shoppers across India (Sneha Katkar, October 7, 2025). Both are the last full-cycle India festive benchmarks available before Diwali 2026 (November 8, 2026); this post uses their figures as the baseline against which 2026 inventory should be measured.

#diwali 2026#india festive phishing#fake e-commerce india#upi scam#deepfake shopping scam#irctc phishing#flipkart phishing#hdfc sbi phishing#mcafee india#quick heal seqrite#domainscan#prism ai
A
Has stared at more registrar records than is medically advisable.
RELATED POSTS
NEW POSTS, NO SPAM

One short email when we publish.

~2 posts a month, no marketing, unsubscribe in one click.