Written by Harwansh Tiwari — Bengaluru-based personal finance builder and founder of Niyamfin. Educational only; not financial advice.
Published · Last reviewed: · Data checked: · Reviewed yearly or after major regulatory changes
Sources: Income Tax Department, RBI, SEBI, PFRDA, IRDAI, AMFI · See methodology
UPI and Digital Payment Fraud in India: How Scams Work and How to Avoid Them
How UPI, card, and net-banking fraud actually happens in India — QR code scams, fake customer care numbers, SIM swap, and screen-sharing apps — plus the exact steps to report fraud and recover funds within the RBI's window.
Quick answer
Almost all UPI and digital payment fraud in India relies on tricking you into authorizing the transaction yourself — a fake QR code that debits instead of credits you, a scanning request disguised as 'receiving money', a screen-sharing app installed at a fraudster's request, or a SIM swap that lets someone else receive your OTPs. Report fraud within minutes on the 1930 cyber crime helpline or cybercrime.gov.in — RBI's rules give you zero or limited liability only if you report an unauthorised transaction within 3 working days of noticing it.
UPI processes billions of transactions a month in India, and fraud has scaled right alongside it. Almost none of it involves anyone "hacking" your bank — it relies on getting you to authorize the transaction yourself, willingly, because you were told you were doing something else.
Understanding the mechanics of how these scams actually work is the best defense there is.
The Core Trick: UPI Only Pushes Money Out
This is the single most important thing to internalize: scanning a QR code or entering your UPI PIN always sends money out, never in.
There is no such thing as "scan this QR code to receive payment" or "enter your UPI PIN to get your refund." If someone asks you to do either of those things to get money, it is a scam, every time, with no exceptions.
The Common Scam Patterns
Fake buyer on a classifieds app. You list something for sale on OLX or Facebook Marketplace. A "buyer" says they've sent an advance and asks you to scan a QR code or enter your PIN to "confirm receipt" or "verify the account." Scanning debits you instead — this is one of the most common scams targeting sellers, not buyers.
Fake customer care. You search online for a bank or company's customer care number, but the top result is a fraudulent number planted in reviews or listings. The "agent" asks you to install a screen-sharing app (AnyDesk, TeamViewer, QuickSupport) to "resolve" your issue, then watches you enter your PIN or directly initiates a transaction while you're on the call.
SIM swap fraud. A fraudster, armed with some of your personal details (often from a data leak or phishing), convinces your mobile operator to issue a duplicate SIM in your number. Once your original SIM deactivates, all your OTPs go to the fraudster's phone instead, letting them reset banking app credentials and drain accounts. A sudden, unexplained loss of mobile signal for an extended period is a warning sign, not just an annoyance.
Phishing links via SMS/WhatsApp. Messages claiming your electricity will be cut, a courier is stuck pending a small payment, or your KYC needs urgent updating — all linking to a fake page designed to capture net-banking credentials or card details.
Fake loan or job offer apps. Apps promising instant loans or "work from home" jobs that ask for an upfront "processing fee" via UPI, or request excessive permissions (contacts, SMS access) that are later used for harassment or further fraud.
RBI's Liability Protection — and Why Speed Matters
RBI's rules on customer liability for unauthorised electronic transactions are genuinely favourable to victims — if you act fast.
- Reported within 3 working days: Zero liability, if the fault lies with the bank or a third party (not your own negligence, like sharing your PIN).
- Reported within 4–7 working days: Limited liability, capped at a specified amount depending on your account type.
- Reported after 7 working days: Liability is determined by the bank's board-approved policy — protection is significantly weaker.
The takeaway is blunt: the moment you notice an unauthorised transaction, act immediately. Every day of delay works against you.
What to Do Immediately
- Call your bank's helpline (from the number on your card or passbook, not a number from an SMS or search result) to block the account/card and report the transaction.
- Call 1930, the National Cyber Crime Reporting Portal's dedicated helpline, or file a complaint at cybercrime.gov.in. This is designed for real-time action — reporting within the "golden hour" gives banks and payment apps a genuine chance to freeze the funds at the receiving end before withdrawal.
- File a formal written complaint with your bank, and follow up with a police complaint/FIR if the bank doesn't resolve it satisfactorily.
- Escalate to the RBI Ombudsman if your bank doesn't respond adequately within 30 days — this is a free, statutory grievance redress mechanism.
Practical Habits That Prevent Most Fraud
- Never share your UPI PIN, OTP, CVV, or net-banking password with anyone — not bank staff, not "customer care," not family unless it's a joint decision you're actively making together.
- Never install screen-sharing apps at the request of an unsolicited caller.
- Always find customer care numbers from your bank's official app or the back of your card — never from a Google search result or an SMS.
- Set transaction limits on your UPI apps and net banking that match your genuine daily usage, so a compromised session has a capped blast radius.
- Enable transaction alerts (SMS and app notifications) for every debit, however small, so unauthorised transactions are caught within minutes, not days.
Common Mistakes
Assuming a "verified" or "official-looking" QR code or app is automatically safe. Fraudsters routinely create convincing fake versions of well-known apps and QR codes.
Waiting to "see if it resolves itself" before reporting. Every hour of delay reduces the odds of recovery and can forfeit RBI's liability protection.
Reusing the same PIN or password across banking apps. A single compromised credential then exposes every account using it.
Ignoring low-value test transactions. Fraudsters sometimes push a small transaction first to verify a stolen card or account works before attempting a larger one — report even a ₹1 unauthorised debit immediately.
Rebuilding After a Fraud Incident
If you do lose money to fraud, treat it like any other financial shock: lean on your emergency fund rather than new debt while the dispute is pending, since bank/RBI Ombudsman resolution can take weeks. Review your card and account security settings once the immediate crisis is handled, and consider whether your emergency fund is sized adequately for this kind of unplanned shock, not just job loss or medical emergencies.
Use the calculator
Want to estimate this with your own numbers? Use the relevant Niyamfin calculators below.
Data sources checked
Data last checked: 2026-07-19
Disclaimer
This article is for general education only. It does not provide financial, investment, tax, insurance, lending, or legal advice and should not be used as the basis for financial decisions.