Live UPI Fraud Advisories — RBI, NPCI, CERT-In, State Cyber Cells
What authorities consider live right now.
L2 = live advisories from authorities. What RBI/NPCI/CERT-In say is happening now — not incidence counts like L1, not media attention like L3. Most actionable for shopkeepers. Updated every 6h from official RSS/circulars. Never merged into one score.
Fake Screenshot Fraud Rising in Bengaluru — Verify the Bank SMS, Not the Screenshot
Fake Screenshot Fraud Rising in Bengaluru — Verify the Bank SMS, Not the Screenshot
Karnataka Cyber Crime warns shopkeepers of a rise in fake-payment-screenshot fraud during the evening rush, roughly 7-9pm, in Bengaluru. Always verify the bank's own credit SMS or app balance, never a screenshot handed to you.
Discontinue UPI P2P Collect Requests from Oct 1 to Curb Fraud
All member banks, PSPs, UPI apps must discontinue P2P collect requests. Change in response to growing concerns over UPI fraud via collect request misuse. Experts praised — eliminating a high-risk feature makes UPI more secure.
Banks Must Audit Systems via CERT-In Empanelled Auditor — Limit Check-Transaction API
Relentless transaction-status checks by banks fuelled the April 12 UPI outage — 5 hours, the longest in 3 years. Banks must audit their systems via a CERT-In empanelled auditor on use of the check-transaction API and share reports by Aug 31 2025.
Measures to Prevent UPI Fraud — Device Binding, 2FA, Daily Limits
NPCI has mandated: stringent device binding between a customer's mobile number and device, two-factor authentication, features notifying the customer during the transaction journey, daily debit limits, and limits/curbs on use cases abused by fraudsters. Banks must also run AI/ML-based fraud monitoring to generate alerts and decline suspicious transactions.
- Device binding
- Two-factor authentication
- Daily debit limits
- AI/ML fraud monitoring
Banks to Undergo Special Security Audit via CERT-In Empanelled Auditors
All supervised entities — banks, payment system operators, and prepaid payment instrument issuers — are advised to conduct a special audit through CERT-In empanelled auditors to ensure best security practices are followed.
Warning Letter to Fintech — Penalty and Ban for Unauthorised Use of UPI IDs
NPCI observed unauthorised use of UPI APIs by certain participants. UPI APIs are strictly for facilitating UPI payments and required user verification for fraud prevention. Certain fintech firms authenticating users via UPI IDs violates NPCI and RBI guidelines.
Document Interactions — Save Screenshots for LEA Investigation
NPCI urges users to document interactions by saving screenshots and messages, which can help law enforcement agencies during investigation. Indians lost Rs 485cr across 6.32 lakh incidents in FY25 till September, per Ministry of Finance data.
Real-Time Payee Name Validation Before Fund Transfer — To Be Explored
With the aim of curbing fraud and improving the payment experience, RBI will explore introducing real-time payee-name validation before an actual fund transfer, similar to the facility that already exists for UPI/IMPS.
- 1During the 7-9pm rush, hold the item until your bank's SMS/app confirms credit — a screenshot alone can be faked in seconds.
- 2If a customer asks you to approve a collect request, it's fraud — decline. The feature is removed from Oct 1.
- 3System stability affects every shop on UPI — banks are now limiting how often apps can poll for status.
- 4Check your app's daily transaction limits — fraudsters specifically target high-value collect requests.
- 5Stick to UPI apps from banks/PSPs that are actually audited — avoid unfamiliar APK downloads.
| Source | Cadence | Last advisory added |
|---|---|---|
| NPCI UPI Circulars HTML page scrape for circular PDF links + Medianama/ET BFSI RSS reporting | Weekly | 29 Jul 2025 |
| RBI Press Releases HTML page scrape for "UPI" / "fraud" / "payee validation" mentions | Monthly | 30 May 2024 |
| RBI Annual Report Manual entry — no reliable PDF text layer, same as fraud_l1_stats | Yearly (May) | 30 May 2024 |
| CERT-In Advisories & RSS RSS feed parse for UPI / fake-app alerts | Weekly | 25 Nov 2024 |
| National Cybercrime Reporting Portal State cyber cell advisories entered manually via the admin API | Manual / as reported | 11 Sept 2026 |
| Press Information Bureau — RSS RSS feed parse for "UPI fraud" / "digital payment fraud" releases | Weekly | — |
Sources: NPCI circulars via npci.org.in, Medianama, Economic Times BFSI; RBI Annual Report and Press Releases via rbi.org.in; CERT-In via cert-in.org.in; PIB via pib.gov.in; cybercrime.gov.in for state cyber cell advisories. These are official advisories — what authorities consider live right now — not an incidence count like L1. Updated every 6h via a scheduled worker. Never merged with L1 statistics or L3 media attention into one score.