The rule that stops most UPI fraud
You never need a UPI PIN to receive money. Not once, in any app, under any circumstance. Receiving is automatic; only sending requires authentication. Every scam that follows depends on the victim forgetting this single fact for about thirty seconds.
So the check is simple. If someone says you must enter your PIN, scan a QR code or approve a request in order to get paid, they are taking money from you rather than sending it. Stop there, whatever else the conversation contains.
- Receiving money never requires a PIN, QR scan or approval
- Scanning a QR code always sends money, never receives it
- A 'collect request' asks you to pay, not to be paid
- No bank or app employee ever needs your PIN or OTP
- No legitimate support process needs to see your screen
1. Fake collect requests
A collect request arrives looking like an incoming payment notification, complete with an amount and a sender name that may even read as a refund. Tapping accept and entering your PIN authorises money leaving your account. This is the most common UPI scam and the most misunderstood.
The set-up usually happens on a marketplace. A supposed buyer says they will send an advance, then sends a collect request instead, and hurries you through it. Decline every request you did not personally initiate, and read the screen wording before your thumb reaches the PIN pad.
2. Fake customer-care numbers and 3. screen sharing
Search results, social media replies and sponsored listings are seeded with fake helpline numbers for banks, wallets and delivery firms. Someone with a genuine problem calls the fake number and is walked straight into fraud. Always take support numbers from the bank's own app or the back of your card, never from a search result.
The fake agent's usual next step is to ask you to install AnyDesk, TeamViewer, QuickSupport or a similar remote-access app so they can 'fix' the issue. Once installed, they watch you type your PIN and can operate the phone themselves. No genuine bank asks to view or control your screen.
- Get helpline numbers from the official app, not a search engine
- Never install a remote-access app at a caller's request
- Never read out an OTP, even to someone who quotes your details
- Uninstall any app a caller asked for, then restart the phone
- Change your UPI PIN and bank password after such a call
4. QR code traps and 5. SIM swap
Scanning a QR code sends money. It is presented as 'scan this to receive your refund', and it works because the visual grammar of QR codes suggests a neutral action. There is no refund QR code anywhere in the UPI system.
SIM swap is quieter and more serious. Criminals gather enough personal data to have your number ported to their SIM, after which OTPs land on their device. The warning sign is your phone losing network for no reason and staying dead while other phones work. Treat sudden, unexplained loss of service as an emergency and call your operator from another line.
6. Phishing links and fake banking APKs, 7. fake payment screenshots
SMS and WhatsApp messages about a pending KYC update, an expiring account, a pending challan or an electricity disconnection carry links to cloned bank pages, or to APK files that install a fake banking app capable of reading your messages. Never install an app from a link; use the Play Store or App Store and check the developer name.
The last trick is offline: a buyer shows you a screenshot 'proving' they paid, and you release goods that were never bought. Screenshots are trivial to forge. Only your own bank or UPI app balance is proof of payment.
- No bank does KYC through an SMS or WhatsApp link
- Install banking apps only from official app stores
- An electricity-disconnection SMS at odd hours is a standard lure
- A payment screenshot is not proof; check your own balance
- Turn on transaction alerts so you see every debit immediately
What to do in the first hour after paying a scammer
Call 1930, the national cybercrime helpline, and file at cybercrime.gov.in immediately. Fast reports allow the receiving account to be frozen before funds move onward, which is the single biggest factor in whether money comes back.
Then contact your bank's fraud line with the UPI reference number of each transaction, block the account or card if credentials were exposed, change your UPI PIN and internet-banking password, and remove any app the scammer had you install. Keep screenshots of the chat, the request and the payment records for the complaint.
- Call 1930 and file at cybercrime.gov.in the same hour
- Give your bank the UPI reference for every transaction
- Change your UPI PIN and banking password
- Uninstall remote-access apps and scan the phone
- Keep chats, screenshots and references as evidence
