Travel tips

Ustraveldocs Login Scam: How Visa Agent Fraud Works in India

An agent took the ustraveldocs login, changed the security answers, then billed in stages. What ports back in two days, what does not, and where to report it.

By Sergei PolinUpdated

Sergei Polin traces every visa fee to the official source and dates it.

In this guide8 sections

The scheme runs in a fixed sequence: an agent takes the visa-portal login to "check the calendar," changes the account's security-question answers, sends a fabricated screenshot of a completed booking, then follows with an escalating payment demand paid in rising instalments — one documented case charged ₹12,000, then a further ₹12,000 for "dependants," then a further ₹12,000 to "release the hold." The account, not the money, is what can still be recovered, and only within a specific window: writing to the portal's own support desk from the email address still registered on the account, with a new email address ready to receive the data, restores access in roughly two working days in the documented cases. Ten documented cases in this corpus share that same shape, and share the same result on the money side — none of it came back. This page separates the two problems that are actually solvable, the account and the still-missing appointment, from the one that, on the evidence available, is not: the rupees already paid.

Recognising the pattern is the point of the section above, not judging how the login was shared in the first place. The mechanism repeats identically whether the amount was ₹5,000 or ₹36,000, whether the contact came through Telegram, WhatsApp or a Facebook group, and whether the applicant had used an agent before.

What happened — the mechanism, step by step#

The mechanism stayed constant across every documented case, regardless of month or amount. An applicant unable to find an appointment through the public calendar agreed to let someone else check on their behalf. That handover required only two pieces of information: the portal login and the answers to the account's security questions, set once at account creation and asked again, alongside the password, at every subsequent login.

The short version repeats across every documented case: a shared ustraveldocs login, security question answers changed soon after, and a fake appointment screenshot — all before any money is asked for. This is visa agent fraud in India in miniature; the shape stays constant even as the price and the platform change.

In one documented case (13 October 2024), the agent changed the security-question answers shortly after receiving them, then sent a screenshot of a completed booking for 10 December 2024 at Hyderabad. Only then did the demand start: ₹12,000 for the applicant, a further ₹12,000 for two dependants added to the same application, and a further ₹12,000 to release the hold on the security-question answers. The account does not confirm every figure was paid in full; it does confirm the order the demands arrived in.

A separate case from July 2025 shows the same shape at different prices. An agent in a Facebook group of roughly 977 members quoted ₹20,000 per person, discounted it to ₹10,000 for two appointments, sent a fake appointment screenshot, and took the ₹10,000. He then demanded ₹10,000 more, said to cover "2 people." When the applicant pushed back, the agent moved to direct threats: a claim to have the applicant's details, a threat to report the applicant as fraud, and a threat of a US entry ban. A further ₹30,000 demand followed, citing "defamation" and an "emergency slot booking" fee.

A third case from October 2025 ran through PayPal and UPI rather than a single transfer: ₹10,000 quoted and paid, a further ₹10,000 demanded "for 2 people" and paid under pressure, and only after both payments cleared did the credentials return — to an appointment date that had never actually moved. A fourth applicant, in May 2026, lost ₹8,000 the same way through a Telegram contact.

What repeats across all four cases is not the amount. It is the order: login and security-answer access first, a fabricated or misrepresented booking image second, and only then a demand that grows in stages, each stage justified by a new, invented complication. Four different agents, four different platforms, amounts from ₹8,000 to more than ₹40,000 requested in stages — the mechanism is the constant, not the price or the platform.

The login itself was never the real prize. The account holds a passport number, date of birth, phone number, home address and the applicant's full booking history in one place. The security-question answers are what gate re-entry to all of that once a password reset has already been tried and failed to help.

<!-- visual-slot -->

What you can still recover, in the next 48 hours#

What follows is the fix — what applicants and search engines alike call account recovery ustraveldocs — in the order that matters most.

That requirement is not arbitrary. Changing the email registered to an account requires a message from the currently-registered address with a scanned passport page attached. That is a step a scammer holding only the password and the security-question answers cannot complete. One applicant (28 April 2026) confirmed the mechanic worked in their favour for exactly that reason: the scammer who had changed their security answers still could not take over the registered email itself. A second applicant (2 August 2024) reported the sequence and its timing directly: after emailing support-india@ustraveldocs.com and supplying a new address, "over all it has taken 2 working days to get my account updated with new email id."

  1. Try the standard password reset first. The reset link goes to the account's primary registered email. A scammer holding only the password and the security-question answers cannot redirect or intercept it.
  2. Open a new personal email address that has never been used on the ustraveldocs account. This becomes the new username once the account is ported.
  3. Write to support-india@ustraveldocs.com from the still-registered email address. State that the account is inaccessible because the security-question answers were changed, attach the passport bio page, and give the new email address the account should be ported to. Each email raises its own case ID, visible under the account's feedback menu once access returns — worth tracking if more than one request has to be sent.
  4. Ask, in the same message, whether any other request has been raised against the passport number. In at least one documented case, the same agent also tried to change the registered email; catching a second, concurrent request early prevents a second lockout.
  5. Expect roughly two working days. Documented cases range from about 24 hours, when a report reached a US Mission customer-care contact directly, to a few days by email alone. Any visa fee already paid is reported as portable to the new profile, not lost with the account.
  6. On first login to the restored account, replace the password and every security-question answer immediately, before doing anything else with the account.

What cannot be recovered#

In ten documented cases in this corpus, the money paid to an agent did not come back. Not one.

The payment mechanics explain part of why. Money moved by UPI or wallet transfer to a personal ID, not to a registered business account with any invoice trail behind it. In the PayPal case above, the agent structured the charge as a personal transfer rather than a protected purchase. The applicant's own dispute with PayPal settled in the seller's favour rather than as a refund, and the credentials came back only after both payments cleared — to a promised early date that had never actually existed.

The first case above carries a second, separate loss that recovering the account does not undo. By the time the applicant regained access, the agent had already rescheduled the appointment to a date roughly 24 hours out. The portal allows five reschedules per application, but only if the current appointment sits more than 48 hours away — inside that window, rescheduling is blocked outright, regardless of how many of the five remain unused. That is what happened here: the appointment fell inside the 48-hour window, and rescheduling was not possible. The account's final reported loss, ₹18,000, is tied to that operational mechanic rather than to the direct extortion payments — a distinct kind of damage, not an additional instalment of the same one.

Every incumbent advisory implies that contacting a bank or filing a police report gets the money back. The documented cases in this corpus do not show that outcome. Filing a cyber-crime complaint can, per one participant's account, lead to a UPI freeze on the receiving account — which stops the money moving further and can matter for the next applicant targeted by the same account — but freezing the destination is not the same as the rupees returning to the person who sent them.

You are not the only one — the numbers#

One participant's account, posted in the same July 2026 thread that produced two of the price points above, put a number on the scale of it: roughly 2,000 agent- and bot-booked appointments were cancelled across 2025, after the US Mission in India apparently identified the pattern from its own side. That figure has no official confirmation anywhere — the Mission publishes no cancellation count — so it is one participant's report, not a stated fact. What it does establish, at any order of magnitude, is that whatever detection method is running catches enough volume to act on a pattern, not on isolated complaints one at a time.

The same thread ran to hundreds of comments over the better part of a week, on a single question — is it safe to book a visa slot through an agent — that would not generate that volume of firsthand replies if the mechanism it describes were rare. Independent cases documenting the identical login-then-escalate shape surface across at least eight separate months between March 2024 and July 2026, involving different agents and different platforms every time.

You still do not have an appointment — here is that problem, separately#

Recovering the account restores the calendar access an applicant already had before any of this happened. It does not create a new appointment, and it does not change how scarce fresh slots are — that is a separate problem, with its own mechanics, not a consequence of the fraud. Fresh B1/B2 slots in India have been dropping mostly between 2 a.m. and 4 a.m. IST rather than the mid-morning window applicants relied on through most of 2025, because scripts based in the US typically reach the queue before an Indian applicant is awake.

The full mechanics of that gap — which free monitors actually catch a release before it is gone, and the OFC-and-interview city split that widens the pool of usable dates without paying anyone — are covered on US visa slot checker mechanics and ustraveldocs explained rather than repeated here. What drives the underlying scarcity sits on US visa appointment wait times. Which Telegram channels are purely informational, as distinct from the transactional kind described above, is separated out on US visa slot Telegram channels explained. None of those four pages costs anything to use; what they cost is attention, not rupees.

Reporting it: cyber crime, the embassy, and what each one actually does#

Channel

What it can actually do

Realistic timeline

What it will not do

ustraveldocs support desk (support-india@ustraveldocs.com)

Restores account access and ports existing data — passport number, application history, fees already paid — to a new login

Documented cases: roughly two working days, sometimes closer to 24 hours

Recover money already paid to an agent; investigate or identify the agent

National Cyber Crime Reporting Portal (cybercrime.gov.in)

Registers a formal complaint against the payment; per one participant's report, can result in a UPI freeze on the receiving account

No published service-level timeline found on an official page

Guarantee a refund; guarantee the frozen account still holds recoverable funds by the time it is frozen

Relevant US consular post's fraud-reporting email (in.usembassy.gov)

Logs the reported agent or method against the applicant's own case file for review

Not published — the post states reports are "thoroughly reviewed" but cannot disclose what action, if any, is taken, citing privacy law

Recover money; confirm to the applicant what happened as a result of the report

Bank or UPI provider

Can flag a transaction, or attempt a dispute on some payment rails

Varies by provider; UPI transfers settle near-instantly and are hard to reverse once cleared

Guarantee reversal, particularly once a UPI transfer has already settled

The consular fraud-reporting route is post-specific, not one address for the whole country. The four Indian posts publish separate emails: New Delhi at NDCONSINQ@state.gov, Mumbai at Mumbaif@state.gov, Chennai at ChennaiAF@state.gov, and Hyderabad at HYDFPU@state.gov. The post's own guidance asks for the case number if one exists, the full name exactly as it appears on the passport, date of birth, passport number, and as detailed a description of the suspected activity as possible, screenshots and dated correspondence included.

Two more searches lead to the same section: police complaint visa agent, and how to file one. An FIR at a local station is a separate, parallel option and does not require going through the cyber-crime portal first, though most of the documented reports in this corpus route through the online portal instead. An MEA advisory describes these patterns in general terms — fee scams, credential theft and, in some categories, forged visa stickers — but does not process an individual complaint the way cybercrime.gov.in and the relevant consular post do. Treat an MEA advisory as background, not as a reporting channel in itself.

Inbound and outbound fraud are two different things with one name#

Every case described above runs outbound: an Indian passport holder handing a login to someone else to book a foreign consulate's appointment. A second, unrelated fraud runs inbound: a fake website selling a foreign traveller a fraudulent Indian e-Visa.

The Consulate General of India, San Francisco's fake e-visa website advisory, last updated 31 July 2026, addressed that pattern directly. A number of lookalike sites mimic the government's own e-Visa application pages, and the correct portal for India's e-Visa is indianvisaonline.gov.in — a fact worth checking against the advisory itself rather than trusting a summary.

The two get conflated because both searches land on the same phrase, "fake visa agent India," and an advisory written for one direction gets read as if it covers the other. A searcher whose ustraveldocs login was taken to book a US appointment is in the outbound case this page covers. A searcher applying to enter India from abroad, misled by a lookalike e-Visa site, is in the inbound case the San Francisco consulate's advisory describes — a different mechanism, with a different fix: apply again, directly, at the correct government portal, and report the lookalike site, rather than trying to recover a login that was never actually taken in the first place.

How the same scheme appears next time#

Every case above is a textbook advance-fee visa fraud: payment requested in stages, against a login that a real calendar-checking service never needed in the first place. The pattern has a small number of fixed markers, independent of which platform it arrives on.

It starts with an unsolicited approach — a message in a large Telegram or Facebook group, or a referral through someone who already paid — offering to check the calendar faster than an applicant could manage alone. A booking image arrives before any money changes hands, timed to build confidence rather than to confirm anything: no case in this corpus shows a real confirmation email accompanying that image at the same stage. The price then rises in stages, each justified by a new, specific-sounding complication — a second dependant, a "hold" on the account, a "defamation" claim, an "emergency booking fee" — rather than staying at the figure first quoted. Payment is asked for through a personal UPI ID or a "friends and family" wallet transfer, not a business account with an invoice.

<!-- visual-slot -->

Offers that describe themselves as "guaranteed slot," "early appointment service" or "we will book for you" are the same offer under three names. The scheduling portal gives no outside party a channel to a booking other than the applicant's own logged-in session, so none of those three claims describes anything the system can actually deliver. This is visa agent fraud in India's underlying business model: no fixed address, no traceable ownership, nothing beyond a chat handle and a phone number — community vocabulary already has a name for that shape, a ghost consultancy. A calendar-checking service that only sells time has no operational reason to ask for a login at all. The fuller case for and against paying someone for that time, weighed against the documented outcomes on both sides, is on the deliberator page.

This page does not name any individual, phone number or company reported as fraudulent anywhere in this corpus, for the reasons set out in our editorial standard, editorial policy and legal notice. It describes the pattern so it can be recognised, not the people running it.

VisaGyan is not affiliated with any government, embassy, consulate, VFS Global, BLS International or ustraveldocs; we book nothing, sell nothing and refer no agent, consultant or service named or described on this page.

Sources cited only — expert review pending. For individualized advice, consult a licensed professional.

Frequently asked questions

An agent has my ustraveldocs login — what do I do now?
Try the standard password reset first; the link goes to the account's primary registered email, which the agent generally cannot redirect. Then open a new email address never used on the account, and write to support-india@ustraveldocs.com from the still-registered address, attaching the passport bio page. Documented cases show the account data porting to the new login in roughly two working days.
Will I get my money back if a visa agent scammed me?
No documented case in this corpus recovers the money paid to an agent. A cyber-crime complaint can, per one participant's account, get the receiving UPI account frozen, which stops the money moving further but is not the same as a refund reaching the applicant. The account and its data are separately recoverable; the rupees already paid are not.
How do I report a visa agent in India?
Three channels, and none of them reverses the payment on its own: the National Cyber Crime Reporting Portal (cybercrime.gov.in) for the transaction itself, the relevant U.S. consular post's fraud-reporting email (listed on in.usembassy.gov) if the agent worked the U.S. visa system, and ustraveldocs support for account access. Each does one job; none guarantees the money back.
How can I tell whether an appointment screenshot is real?
A screenshot alone proves nothing — documented cases show fabricated booking images sent before any money changed hands. The only real confirmation is an official email from the portal to the applicant's own registered address, or logging into the account directly. If login is already blocked, no image sent by a third party can substitute for that check.
Is a fake e-Visa website the same problem as a fake visa agent?
No — the two run in opposite directions. A fake visa agent takes an Indian applicant's login to book a foreign consulate's appointment (outbound). A fake e-Visa website sells a foreign traveller a fraudulent Indian e-Visa (inbound), the subject of the Consulate General of India, San Francisco's advisory. Both surface under similar searches, but the mechanism and the fix differ completely.