Technology

How UPI frauds work, and how to protect yourself

Most UPI frauds don't break the system; they trick you into approving a payment yourself. Here are the common patterns, the one rule that defeats most of them, and what to do in the first hour if money is gone.

Illustrative cover: How UPI frauds work, and how to protect yourself
Illustration: Pointales

Most UPI frauds do not hack UPI. They persuade you to authorise a payment yourself, by scanning a code, approving a request, entering your UPI PIN or handing over control of your phone. The single most useful rule follows from that: you never need to enter your UPI PIN, or scan a QR code, to receive money. The Reserve Bank of India puts it plainly: transactions involving receipt of money do not require scanning QR codes or entering a PIN. If anyone asks you to do either “to receive” a refund, prize or payment, it’s a scam.

If you are new to how UPI moves money between banks, start with our explainer on how UPI works, and who pays for it.

The common patterns

“Approve this request to receive money”

UPI lets a payee send a payment request, which the payer approves with their PIN. Fraudsters misused this by sending requests with messages like “Enter your UPI PIN to receive money”, a pattern the RBI warned about in 2022. Approving the request sent money out.

NPCI, which runs UPI, directed banks and apps to stop person-to-person collect requests from 1 October 2025 to curb this fraud. Merchant requests, such as some bill or shopping payments, can still appear. The rule stays the same: any screen that asks for your PIN is a payment from you.

QR codes “to get your refund”

A QR code holds the details of an account to pay into. RBI’s Ombudsman office, in its BE(A)WARE booklet, describes fraudsters who contact people under various pretexts and trick them into scanning QR codes with payment apps, “which allows the fraudsters to withdraw money”. The common version targets people selling something online: the “buyer” sends a QR code and says scanning it will release the payment. It won’t. Scanning and entering your PIN pays them.

Fake customer care numbers

People search online for a bank’s or app’s helpline and call the first number they find. The BE(A)WARE booklet notes that contact details shown on search engines are “often camouflaged by fraudsters”. The fake agent then asks for card details, a PIN or OTP, or for you to install an app “to fix the problem”. Take helpline numbers only from the official app or website, or the back of your card.

Screen-sharing and remote-access apps

Here the “support agent” asks you to install a screen-sharing or remote-access app. RBI’s booklet says fraudsters use these apps to “watch / control your mobile / laptop” and then make payments through your banking or payment apps. Once someone can see your screen, they can see every OTP and PIN you type. No genuine bank or UPI app needs this to resolve a complaint.

Fake payment screenshots

This one targets shopkeepers and online sellers. The “customer” shows a screenshot or a spoof app’s “payment successful” screen, and no money ever arrives. Payment company Razorpay’s advice is simple: open your own UPI app or check your bank SMS to confirm the money has arrived. Don’t rely on the payer’s phone. A soundbox or your own app is proof; their screen is not.

“I sent money to you by mistake”

A stranger calls or messages to say they transferred money to you by accident and asks you to send it back. Sometimes a small amount really was credited. Sometimes there is only a fake SMS that looks like a bank alert. The “return” then goes through a QR code, a request or a link they control, or it goes to a different account from the one that paid you.

The protection is the same as above. Check your balance in your own bank app, not in an SMS. If money genuinely arrived by mistake, tell the person to raise it with their own bank. Don’t send anything to a number, QR code or UPI ID they supply. If you’re unsure, ask your bank before you act.

If you have lost money: the first hour

Speed matters. The sooner a complaint is logged, the sooner the banks involved can be alerted.

  1. Call 1930, the national cybercrime helpline. It feeds the Citizen Financial Cyber Fraud Reporting and Management System, run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs. The system was launched in 2021, and All India Radio reported in December 2025 that it had saved more than ₹7,000 crore across more than 23 lakh complaints.
  2. File a complaint on cybercrime.gov.in, the National Cyber Crime Reporting Portal, under “Financial Fraud”. Keep the transaction reference (UTR) numbers, screenshots and the fraudster’s number or UPI ID.
  3. Tell your bank through its official app, website or helpline. Ask it to block UPI or your card if needed, and note the complaint number and time.
  4. Remove any remote-access app you installed, and change your UPI PIN and banking passwords from a safe device.

To report a suspicious call, SMS or WhatsApp message before any money is lost, use the Department of Telecommunications’ Chakshu facility on Sanchar Saathi. The portal itself says Chakshu is not for reporting money already lost. For that, use 1930 or cybercrime.gov.in.

Will the bank refund you? The rules, as of October 2026

The current rules come from RBI’s July 2017 circular on limiting customer liability in unauthorised electronic banking transactions. They have since been folded into RBI’s 2025 directions on responsible business conduct.

Situation (current rules)Your liability
Bank’s own fault or negligenceZero, whenever reported
Breach elsewhere in the system, reported within 3 working days of the bank’s alertZero
Same, reported within 4–7 working daysCapped at the transaction amount or a limit: ₹5,000 for basic savings (BSBD) accounts, ₹10,000 for most other savings accounts, up to ₹25,000 for some current accounts and high-limit credit cards, whichever is lower
Reported after 7 working daysAs per the bank’s board-approved policy
Loss caused by your own negligence, such as sharing your PIN or OTPYou bear the loss until you report it to the bank

Under the same circular, the bank must credit the disputed amount to your account (a “shadow reversal”) within 10 working days of your complaint, and must resolve it within 90 days. The burden of proving customer liability lies on the bank.

The catch is that many UPI scams involve a payment you authorised yourself, under deception, and the 2017 rules were written for unauthorised transactions. That is changing. On 24 June 2026 the RBI issued amendment directions that widen protection to other categories of “fraudulent” electronic transactions, shorten complaint processing times and introduce compensation for small-value frauds. These take effect on 1 January 2027. Until then, the table above applies.

Your checklist

  • Never enter your UPI PIN or scan a QR code to receive money.
  • Read the screen before typing your PIN: it should say pay, the amount and the payee you expect.
  • Never install screen-sharing or remote-access apps at a stranger’s request.
  • Get helpline numbers only from official apps, websites or your card.
  • Shopkeepers and sellers: confirm payments in your own app, soundbox or bank SMS, never on the buyer’s screen.
  • Don’t “return” money to a stranger; let their bank handle it.
  • Never share OTPs. Stronger sign-in methods help elsewhere; see our guides to two-factor authentication and passkeys.
  • If money is gone, call 1930 at once, then file on cybercrime.gov.in and inform your bank.

The point: Almost every UPI scam ends with you entering your PIN, scanning a code or handing over your screen. Receiving money never needs any of these. If money is lost, call 1930 and your bank within the hour. Under current RBI rules, how quickly you report it also affects how much you can recover.

Sources