India explainer

The Other Side of the UPI Miracle: Fraud at the Speed of Payment

UPI is the most impressive payments system on earth, and I'd defend it against most of its critics. But a rail built for instant, final, low-friction transfer is also a rail built for instant, final, low-friction theft — and the loss lands on whoever can least afford it.

I want to begin by saying something that gets lost the moment anyone raises the subject of UPI fraud: the Unified Payments Interface is the most impressive piece of payments engineering on the planet, and I do not say that loosely. In August 2026, NPCI reported roughly 24.5 billion UPI transactions in a single month, worth about ₹29.8 lakh crore — on the order of 790 million payments a day. It is free at the point of use. It works between banks that do not like each other. It works on a ₹6,000 phone held by a vegetable seller in a district town who never had a card machine and never will. Hundreds of millions of people got access to the formal payment system in about a decade, and they got it without paying two per cent to anybody. Nothing else at that scale comes close.

And every property that makes it extraordinary makes it dangerous. A rail built for instant, final, low-friction transfer is also a rail built for instant, final, low-friction theft. That is not a flaw someone forgot to fix. It is the same design, read from the other side.

What the numbers say, and what they do not

Official figures on UPI-linked fraud have been placed before Parliament and published in RBI reporting, and they are worth stating carefully because they are routinely mangled. On the reported numbers, UPI-related fraud ran to roughly ₹1,087 crore across about 13.4 lakh incidents in FY 2023–24, roughly ₹981 crore across about 12.6 lakh incidents in FY 2024–25, and about ₹805 crore across some 10.6 lakh incidents in the part of FY 2025–26 reported so far. Treat all of these as official estimates of reported fraud rather than as a measurement of what actually happened.

Two cautions matter more than the totals themselves.

The first is arithmetic. Absolute fraud numbers rise when transaction volumes rise, and UPI volumes have been compounding at more than twenty per cent a year. A headline saying fraud has grown tells you almost nothing on its own; what you want is fraud per crore transacted, or per lakh transactions. On that basis the picture is far less alarming than the headlines and far more useful — the rate has been broadly flat to declining even as the raw counts move around. Any story that reports the crore figure and not the denominator is not reporting, it is decoration.

The second is undercounting. Survey work in India has repeatedly found that a large share of people who lose money never file a formal complaint at all — out of embarrassment, or because the amount felt too small to chase, or because they did not know where to go. Small-value fraud in particular is almost invisible in official data. So the honest summary is this: the reported rate is low, the reported total is large, and the true total is higher than the reported one by an unknown margin.

A rail built for instant, final, low-friction transfer is also a rail built for instant, final, low-friction theft. That is not a flaw someone forgot to fix. It is the same design, read from the other side.

The patterns, concretely

Almost every UPI scam in circulation is a variation on a small number of mechanics. Knowing the mechanics is most of the defence, because the stories change weekly and the machinery does not.

  • The collect-request trap. This is the one I would teach first, because it exploits a genuine interface ambiguity. UPI lets someone request money from you. The request arrives as a notification, and if you enter your PIN it debits you. Fraudsters dress the request up as a refund, a cashback, a prize, a marketplace payment for something you listed for sale. Here is the rule that ends the entire category: you never need your UPI PIN to receive money. Not once. Not ever. If a screen is asking for your PIN, money is leaving, whatever the text above it says.
  • Fake customer-care numbers. Someone searches for a helpline — for a wallet, a delivery firm, a bank, a gas agency — and lands on a number that a fraudster has planted in search results, map listings, or a sponsored ad. The "agent" is calm, helpful, knows the script, and walks the caller into either a collect request or a remote-access install. Use the number printed inside the official app or on the back of your card. Never a number found by searching.
  • QR codes that send rather than receive. A QR code is not a receipt; scanning one initiates a payment from you. The classic version is the online-marketplace buyer who insists on sending you a "scan to receive" code for the sofa you are selling. There is no such thing. Sellers give their UPI ID; they do not scan.
  • Screen sharing and remote-access apps. The victim is persuaded to install a legitimate support tool so the "agent" can "fix" a failed transaction. From that moment the fraudster sees the OTPs, sees the PIN keypad, and in some cases drives the phone directly. No bank, no payment app, and no government department will ever ask you to install a screen-sharing app.
  • SIM swap and OTP theft. Your phone number is the spine of the whole system: it identifies your device to the bank and receives the codes. Get the number and you get the account. A sudden, unexplained loss of mobile signal that persists is not a network problem until proven otherwise — it is the single most under-recognised emergency signal in Indian digital life.
  • Social engineering built on urgency or fear. Every one of the above is delivered in a wrapper designed to stop you thinking: a deadline, a threat, a shrinking window, an authority figure. The most extreme form of this is the impersonation-of-police con I have written about separately in the digital arrest scam, where the fear is sustained over hours. But the same lever — pressure that forecloses reflection — is present in the smallest ₹500 con.
  • Mistaken-transfer and mule-account routing. Money "accidentally" lands in your account; a distressed caller asks you to send it back to a different number. You have just laundered someone's proceeds through your own account and out again. Never return money on the phone's say-so; tell your bank and let the bank reverse it.

Why the victim's own hand is the whole problem

Here is the structural fact that everything else hangs on. In the overwhelming majority of these cases, the victim authorises the transfer. The PIN is entered by the account holder. The device is the registered device. The biometric or the OTP checks out. There is no technical breach anywhere in the chain. From the bank's logs, the transaction is indistinguishable from you paying for groceries.

That is why recovery is so hard, and it is also why liability rules matter far more than most people realise. RBI's framework on unauthorised electronic banking transactions is genuinely good as far as it goes: report a third-party breach within three working days and the customer's liability is zero, the burden of proving customer negligence sits with the bank, and complaints are meant to be resolved in ninety days. But read the word that is doing all the work — unauthorised. A transaction you were tricked into approving yourself is, by the letter of the system, authorised. The protection framework was designed for a world of stolen cards and cloned credentials, and the fraud economy moved to a world of manipulated consent.

So the loss lands on the individual. Not because anyone decided it should, but because nobody has yet decided that it shouldn't. That is a policy vacuum, not a law of nature. Other jurisdictions have begun forcing banks to reimburse authorised push-payment fraud precisely on the argument that the party that designed the frictionless rail — and profits from the volume it carries — is better placed to absorb and reduce the loss than a pensioner in Kottayam. India has not made that move.

If it happens to you: the first hour

Stolen money in a UPI fraud does not vanish. It moves — usually into a "mule" account, then onward or out through an ATM. The window in which it can still be frozen is measured in minutes. Officials call it the golden hour, and the phrase is not marketing.

  1. Call 1930 immediately. This is the national cyber-crime financial-fraud helpline run by the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs, staffed round the clock. Call before you call anyone else. Call before you finish being upset.
  2. File the complaint on the national portal, cybercrime.gov.in, within 24 hours. The helpline call generates an acknowledgement; the portal complaint formalises it and feeds the banking system that places holds on the receiving account.
  3. Tell your bank in writing. Phone them, then follow up in writing so the reporting date is on record — under the RBI framework, the date you notified them is the hinge your liability turns on.
  4. Freeze what can be frozen. Block the card or UPI handle involved. If you suspect SIM swap, get to your telecom operator's store with ID.
  5. Keep everything. Screenshots, transaction reference numbers, the caller's number, the UPI ID the money went to, timestamps. Do not delete the messages out of disgust.
  6. File an FIR if the sum is meaningful. The portal complaint is not a substitute, and banks take a police report more seriously than a ticket number.

Please verify the helpline number and the portal address against your bank's own app or an official government page before you need them — the reason fake helplines work at all is that people look these things up in a panic, and a panicked search is exactly where the planted numbers live.

The loss lands on the individual not because anyone decided it should, but because nobody has yet decided that it shouldn't. That is a policy vacuum, not a law of nature.

Who carries the loss

I keep returning to that question because it is the only one that changes anything. Awareness campaigns are useful and finite; you cannot educate a population of a billion people out of a con that is professionally redesigned every quarter. The victims are disproportionately the people the system was celebrated for including — first-time users, elderly account holders, small traders, people for whom ₹40,000 is not an inconvenience but a year.

What we have built is a system whose benefits are socialised and whose failures are individualised. Volume, convenience and reach accrue to everyone — to the banks, to the apps, to the state that showcases the achievement abroad. The losses sit with whoever happened to answer the phone. That asymmetry is a choice, and choices like it are how a technology built for the public slowly starts serving something else; it is the pattern I have traced in how technology gets captured, and it is visible in the adjacent arguments about what a single dominant rail means for systemic risk in UPI, too big to fail and about what the identity layer underneath it knows, in Aadhaar, UPI and privacy.

None of this is an argument against UPI. I use it fifteen times a week and I would not go back. It is an argument that the hard part of building public infrastructure is not the launch. It is deciding, deliberately, who absorbs the cost when it is used against the people it was built for — and then writing that decision down before another decade of volume growth makes the question too expensive to ask.

Kenney Jacob is the author of Captured, a history of who takes, who pays, and who fights back.

Frequently asked questions

How common is UPI fraud in India?

Reported UPI fraud cases and amounts have risen sharply alongside transaction volumes, with official figures cited in the thousands of crores across recent years. Absolute numbers grow partly because usage grows, so the fraud rate per transaction matters more than the headline total — but both the volume and the human cost are substantial.

What are the most common UPI scams?

The recurring patterns are collect-request scams (approving a 'request' that debits you rather than pays you), fake customer-care numbers, QR codes that send rather than receive, screen-sharing and remote-access apps, SIM-swap and OTP theft, and social-engineering built on urgency or fear. Almost all of them work by getting the victim to authorise the transfer themselves.

Can you get money back after UPI fraud?

Sometimes, and speed is everything — an immediate report to your bank and to the national cyber-crime helpline gives the best chance of freezing funds before they are withdrawn or layered onward. But because UPI transfers are designed to be instant and final, and because most frauds involve a victim-authorised payment, recovery is often difficult and far from guaranteed.

← All articles