- What is the most common UPI fraud in India?
- Fake payment screenshot — 73% of the 127 community reports we analysed. The fraudster shows an edited screenshot that looks like the payment went through; the shopkeeper hands over goods, but the money never lands. It clusters around 7-9pm rush hour, averaging Rs 3,400 per incident. How to spot it: no bank SMS beep, no balance increase, the customer is in a hurry. What to do: wait for your own bank SMS or check your balance — a screenshot can be faked on any phone in seconds. This is our own L3 pattern analysis, not an RBI/NPCI category — see the live tracker for the underlying reports.
- What is QR collect request fraud?
- A QR code or "Collect Request" that takes money from you instead of sending it — 12% of reports. You approve it thinking you will receive money, but your account is debited instead. NPCI’s July 29 2025 circular discontinued P2P collect requests from Oct 1 2025 specifically to curb this. The red flag: your UPI PIN is asked to RECEIVE money. A real UPI payment only ever needs your PIN to SEND — never to receive.
- How much money is actually lost to UPI/bank fraud in India?
- Three official, non-comparable sources: RBI Annual Report 2023-24 recorded 36,075 bank frauds worth Rs 13,930 crore (all categories, lagging ~12 months). Parliament (Lok Sabha Unstarred Q211, answered 25 Nov 2024) put UPI-specific fraud at 13.42 lakh cases and Rs 1,087 crore for FY24 — an 85% jump in cases over FY23. The same answer’s FY25 partial-year figure (till September 2024) was 6.32 lakh incidents and Rs 485 crore. These three numbers measure different things and are never added together — see L1 Official Statistics for the full, dated breakdown.
- Is UPI itself unsafe?
- No — almost none of the 17 patterns on this page are a technical break of UPI. They are social-engineering tricks: a fake screenshot, a misleading collect request, an urgent phone call, a cloned app. The one genuine account-takeover route, SIM swap, still requires a fraudster to first get your SIM reissued through your telecom operator, not a flaw in UPI’s payment rails.
- Why did NPCI remove UPI collect requests?
- NPCI’s July 29 2025 circular directed all member banks, PSPs and UPI apps to discontinue P2P collect requests from 1 October 2025, in direct response to how often the feature was abused for QR/collect fraud (this page’s #2 pattern). If your app still shows an incoming "collect" request from someone you don’t know, decline it.
- Can my UPI PIN be stolen without me sharing an OTP?
- Yes — screen-sharing apps like AnyDesk or TeamViewer let a fraudster watch your phone screen while you enter your own PIN; no OTP or PIN is ever "given" to them, they simply see it. Never install a screen-share app because someone claiming to be from your bank asked you to.
- What has NPCI mandated to prevent UPI fraud?
- Per NPCI’s prevention measures (cited in Parliament Q211’s annexure, 25 Nov 2024): mandatory device binding between a customer’s mobile number and device, two-factor authentication, in-app transaction notifications, daily debit limits, and bank-side AI/ML fraud monitoring that can decline suspicious transactions automatically.
- What should a shopkeeper do to avoid fake payment screenshot fraud?
- Never release goods on a screenshot alone. Wait for your own bank’s SMS or check your UPI app’s balance directly — the two things a fraudster cannot fake. A sound-box device (announcing the amount out loud on receipt) removes the screenshot step entirely, which is why it has become standard at high-footfall shops.
- Is my UPI ID safe to share for login or verification, not payment?
- No. NPCI issued a warning letter (24 Oct 2024) after finding fintech firms authenticating users via their UPI ID as if it were a login credential — that is a violation of NPCI/RBI guidelines. A UPI ID should only ever be used to receive or send a payment, never as a proof-of-identity or login step.
- Is this page official RBI/NPCI data, or user reports?
- Neither alone — and we never merge them into one score. This page (L3) is a pattern taxonomy built from 127 anonymised community reports plus media coverage: attention-worthy, not verified incidence. For actual official incidence, see L1 Official Statistics (RBI, Parliament). For live regulator warnings and circulars, see L2 Advisories (NPCI, RBI, CERT-In). Each layer links to its primary source.