Diwali 2026 phishing playbook — 828 fake ad domains, 1-in-3 Indians duped, and the UPI + deepfake trap.
Diwali 2026 falls on November 8. India will run its largest annual online-payment surge in the eight weeks leading up. McAfee's 2025 Global Holiday Shopping Scams Study — the last full-year India benchmark before this year's festive season — found one in three Indian consumers duped by holiday scams, 37 percent suffering financial loss, and 46 percent of losers losing more than ₹41,500. Quick Heal's Seqrite Labs identified 828 distinct phishing domains running paid Facebook Ads in a single festive window. This post breaks down the 2026 playbook — the five brands attackers impersonate most, the three tactics dominating, the 828-domain infrastructure fingerprint, and the 30-second Trust Score check to run before every festive payment.
The Indian festive-scam benchmark
McAfee's 2025 survey of Indian consumers produced the numbers most defenders reference as their baseline going into Diwali 2026.
- 1 in 3 Indians duped, 37% lose money, 46% of losers lose more than ₹41,500 Small basket, high frequency, high per-victim take.
- 12 scam attempts per day per consumer during peak festival weeks Texts, emails, WhatsApp forwards, sponsored social posts. 91% report receiving suspicious messages. Exposure is universal.
- 49% fake 'gift card wins', 40% 'limited-time offers', 27% 'refund alerts' The lure taxonomy is tight and repeatable — which is also why the domain infrastructure behind it is repeatable.
- 77% of Indian shoppers transact on smartphones Mobile web is the fraud surface — truncated URL bars, subtle SSL indicators, two-finger tap to pay.
- 72% believe AI-driven scams are more dangerous than last year 84% report increased concern about deepfake scams. AI-produced ad creative and celebrity impersonation is genuinely new for Diwali 2026.
The five brands attackers impersonate most during Diwali
From Seqrite Labs' Facebook Ads Library sweep, CERT-In festival advisories and consumer-report telemetry, the impersonation shortlist concentrates on brands with the highest transaction velocity in the window.
- IRCTC and airline booking portals Peak-season IRCTC handles 13 lakh+ daily bookings. Fake booking sites clone the interface and drop payment straight to attacker UPI IDs.
- Flipkart Big Billion Days, Amazon Great Indian Festival, Meesho Mega Blockbuster Hyphenated brand-adjacent domains — bigbillion-offers.top, flipkart-diwali.shop, meesho-mega.online — that look plausible when clipped on a mobile URL bar.
- UPI apps: PhonePe, Google Pay, Paytm, BHIM Fake cashback/refund landing pages that trigger a real UPI collect request. User sees an amount, thinks they are receiving money, approves the PIN, sends money instead.
- Retail banking: HDFC, SBI, ICICI, Axis KYC re-verification lures during the festival window — call-to-action that seems seasonally reasonable and lands the user on a credential-harvest form.
- Instant-loan and BNPL: Bajaj Finserv, Kissht, Slice, Simpl Instant-approval lures with a 'processing fee' UPI request. The fee is the fraud; no loan exists.
The three tactics dominating Diwali 2026
Quick Heal's festive advisory names three attack shapes explicitly. Everything else is a variant.
- AI-personalised phishing campaigns GenAI writes the ad creative, the landing page copy, the follow-up SMS, and the fake customer-service transcript — in localised Hindi, Marathi, Tamil, Bengali. Broken English is a solved problem for the attacker.
- Counterfeit booking and e-commerce portals Pixel-perfect clones of IRCTC, Flipkart, Amazon India — served over HTTPS, indexed in Google, and increasingly appearing as sponsored results directly next to the real brand.
- UPI and QR-code redirection A QR sticker or 'pay to receive cashback' link that opens a real UPI collect request. User reviews an incoming amount, approves without reading direction, money leaves their account.
The 828-domain Facebook Ads infrastructure fingerprint
Seqrite's single most useful finding — 828 distinct phishing domains surfacing paid Facebook Ads in one festive window. Facebook Ads Library is public, making the whole cluster queryable.
- Cheap-TLD bulk registration .top, .shop, .online, .xyz, .click, .store — TLDs whose registration cost is under ₹100 and whose abuse rates are documented in every registrar reputation dataset.
- Registration age under 30 days A legitimate merchant does not register a Diwali domain in October and expect Google to trust it by November. Phishing operators do — they only need two weeks of ad clicks.
- Nameserver concentration Cloudflare and a small set of low-cost DNS providers dominate the phishing NS distribution. NS + bulk-registered brand-adjacent name + fresh creation_date is a three-flag composite.
- Wildcard SSL from free CAs Let's Encrypt and ZeroSSL issue within minutes of DNS provisioning. Every domain in the 828 set is HTTPS by default — the padlock is a base feature of the phishing kit, not an anti-phishing signal.
The UPI collect-request inversion
The single most Diwali-specific fraud. UPI request confirmations are visually similar to UPI receive confirmations, especially on cluttered mobile screens.
- The lure 'Your ₹2,000 cashback for Diwali offer #DIW26 has been approved. Confirm on your UPI app to receive.'
- The deep-link Tapping opens the UPI app with a pre-filled collect request from an attacker VPA. The screen shows the amount prominently.
- The mistake Victim reads the amount, sees an official-looking merchant name (DIWALIREWARDS@upi), approves the PIN thinking they are receiving.
- The rule that stops it UPI collect requests always require your PIN to SEND money. Receiving money never requires a PIN. If a 'cashback' asks for your UPI PIN, it is a send. Cancel.
Deepfake celebrity endorsements
The 2026-specific escalation. 69% of Indian consumers encountered fake celebrity endorsements in festive advertising per McAfee; 45% report someone they know fell for a deepfake shopping scam.
- Video ads with recognisable faces Cricketers, film stars, popular anchors — endorsing a specific brand's Diwali offer they have no relationship with. Visual quality has crossed the threshold where casual scrolling does not catch it.
- Voice clones on WhatsApp calls Impersonating a family member with an urgent Diwali gift request, or a bank manager confirming a KYC update.
- Fabricated news screenshots Times of India, NDTV, Hindustan Times layouts announcing celebrity-backed Diwali offers with a shortened URL to a phishing landing page.
- The infrastructure defense is unchanged The deepfake is the lure; the domain is the trap. Domainscan checks the trap.
The 30-second check before you pay
For a consumer holding a phone in a Diwali sale scroll, the useful check fits in the interval between tapping a link and entering a payment method.
- Paste the URL into Domainscan WHOIS age, registrar reputation, NS pattern, MX presence, SSL age, reverse IP, and blacklist correlation checked in parallel. Any two red flags = do not pay.
- Check the domain, not the URL bar Mobile browsers truncate. A URL that shows flipkart.com... could be flipkart.com.diwali-offers.top. Trust Score resolves the full domain.
- Go through the official app for known brands IRCTC, PhonePe, Flipkart, banks, UPI services — legitimate Diwali offers are always available in the app. Ad-linked landing pages are almost never necessary.
For brand owners: the four-week runway
The window to harden your posture before Diwali 2026 is closing. Assume 2026 inventory exceeds last year's 828.
- Enrol your brand in the Typosquat monitor Character-substitution, hyphenation, prefix/suffix and cheap-TLD sweeps — the full permutation set is generated and re-checked daily. New registrations trigger alerts within hours.
- Enforce DMARC p=reject On every domain you own, including parked and marketing subdomains. The lure-email tier spoofs the brand's From header; DMARC alignment is what makes the receiver's inbox provider reject it.
- Report paid ads impersonating your brand weekly Facebook Ads Library, Google Ads Transparency Centre and X Ads Repository are all queryable. Weekly sweeps surface the paid impersonation tier free brand monitors miss.
- Publish an authoritative 'how to identify our Diwali offers' page On your real domain, in the language your customers use. Rank it for your brand+diwali+scam queries. Consumers who search for verification usually find whichever page ranks first.
What to do this week
- Consumers: bookmark Domainscan Trust Score Any Diwali offer link on WhatsApp, SMS or social — paste, wait five seconds, read the score, decide.
- Consumers: install official apps Do all Diwali purchases through the app. Ad-linked landing pages are the highest-risk vector.
- Brand owners: WHOIS + DNS sweep of the ten most likely typosquat variants today Anything registered in the last 60 days across .top / .shop / .online / .xyz = investigate.
- Brand owners: publish a Diwali advisory on your own domain 4 weeks before Early October publish accrues Google trust before the search spike.
- Everyone: share the UPI rule 'PIN = send, no PIN = receive.' One sentence blocks the most common Diwali UPI trap class.
Source
Consumer benchmark: One in Three Indians Duped in Festive-Season Scams as AI and Deepfakes Rewrite Cybercrime Playbook — coverage of the McAfee 2025 Global Holiday Shopping Scams Study (Pratim Mukherjee, October 12, 2025). Domain-inventory and technique data: Quick Heal / Seqrite Labs advisory on AI-powered cyber scams targeting Diwali shoppers across India (Sneha Katkar, October 7, 2025). Both are the last full-cycle India festive benchmarks available before Diwali 2026 (November 8, 2026).