UPI (Unified Payments Interface) has become India’s fastest-growing payment method—over 12 billion transactions in 2024 alone—but rising adoption has also attracted scammers. The good news: most UPI fraud is preventable with basic security habits and awareness of how scams work. This guide covers the real threats, RBI’s security rules, and actionable steps to keep your money safe.
Key Takeaways
- UPI fraud includes phishing, one-time password (OTP) theft, and fake payment links; most occur because users share sensitive details.
- RBI mandates two-factor authentication (2FA) and transaction limits: ₹200,000 per day by default, though this varies by bank and app.
- Never share your UPI PIN, OTP, debit card details, or CVV—legitimate banks and payment apps will never ask for these.
- Enable transaction alerts, biometric login, and device lock to catch fraud early and prevent unauthorised access.
- If you spot fraud, immediately block your UPI ID, notify your bank, and file a complaint with your payment app and RBI’s NODAL Centre.

What Are the Most Common UPI Scams in India?
UPI fraud typically falls into three categories:
1. Phishing & Fake Links
Scammers send SMS, WhatsApp messages, or emails claiming you’ve won a prize, have a pending tax refund, or need to verify your account urgently. They direct you to a fake website or app that mimics your real bank or payment platform. When you log in or enter details, the scammer captures them instantly.
Example: “Congratulations! You’ve won ₹50,000 in an Amazon lottery. Click here to claim: [fake-link.com].” Once you click and enter your UPI ID and password, the attacker can reset your PIN.
2. OTP & PIN Theft
Scammers trick you into revealing your one-time password (OTP) or UPI PIN by posing as bank staff or customer support. They may call claiming there’s suspicious activity on your account, or they might social-engineer you into typing your PIN during a “verification” call.
Example: “Hello, this is ICICI Bank security. We detected unauthorised access. Please read the OTP you just received so we can verify your account.” You read it aloud; they now control your payments.
3. QR Code & Payment Reversal Scams
A merchant shows you a fake QR code or requests payment for a service that doesn’t exist. Once paid, they claim the transaction “failed” or “bounced” and ask you to re-send money or share screenshots of your payment proof (which may include sensitive data).
Example: A seller on an online marketplace sends you a QR code for ₹5,000. After you pay, they say “payment didn’t go through” and ask you to send ₹5,500 to cover a “fee.” The first transaction actually cleared; the second never existed.
What Security Rules Does the RBI Enforce?
The RBI and NPCI (National Payments Corporation of India) have issued strict guidelines to protect UPI users. Here’s what’s in place as of 2026:
| Security Rule | Details |
|---|---|
| Two-Factor Authentication (2FA) | Every UPI transaction must require a second factor: OTP, biometric (fingerprint/face), or PIN. Per RBI guidelines, single-factor authentication is not permitted. |
| Transaction Limits | Default limit is ₹200,000 per transaction per day; banks can set lower limits. High-value transactions may require additional verification. |
| Fraud Liability | If you report fraud within 7 days, the bank must reimburse you in full (as per RBI’s 2023 circular). After 7 days, liability is shared or may be borne by you, depending on negligence. |
| Device Lock & Biometric | Payment apps must support device-level locks (fingerprint, face recognition, PIN) to prevent unauthorised use if your phone is lost. |
| Transaction Alerts | Your bank must send real-time SMS/push notification alerts for every UPI transaction, successful or failed. |
| UPI Lite | For transactions under ₹200 (or up to ₹2,000 per day), RBI allows “tap-to-pay” without PIN to reduce friction—but with strict per-transaction and daily caps. |
How to Enable Security Features on Your UPI App
Most Indian banks and UPI providers (Google Pay, PhonePe, Paytm, BHIM, WhatsApp Pay) offer built-in security tools. Here’s what to set up:
1. Biometric & Device Lock
- Open your UPI app → Settings → Security.
- Enable fingerprint and/or face recognition login.
- Set a device PIN or pattern lock (independent of UPI PIN).
- Never use simple PINs like 1111 or 1234.
2. Notification Alerts
- Ensure SMS and in-app alerts are enabled in your app settings.
- Check your bank’s website to activate “transaction alerts” on your registered phone number.
- Save the alert phone number; scammers sometimes change it to prevent you seeing fraud.
3. Limit & Timeout Settings
- Many apps allow you to set a daily transaction limit lower than the RBI maximum (e.g., ₹50,000 instead of ₹200,000).
- Enable “auto-logout” after 5–10 minutes of inactivity to reduce risk if your phone is stolen.
4. Suspicious Activity Monitoring
- Review transaction history weekly for unknown payments.
- Check linked bank accounts and registered phone number; if either has changed without your action, contact your bank immediately.
What Should You Never Share Over UPI?
This is the single most important rule:
- UPI PIN: Your 4-digit PIN is your signature. Never type it over the phone, in an email, or on a website. Banks and payment apps will never ask for it.
- OTP (One-Time Password): An OTP is a one-time code sent to your phone. It expires in 10 minutes. If someone has your OTP, they can complete a transaction. Never read it aloud or type it into unverified websites.
- Debit Card Number & CVV: Your 16-digit card number and 3-digit CVV (on the back) are sensitive. Share them only with verified merchants during checkout on secure (HTTPS) websites.
- Registered Mobile Number: If a scammer links your UPI to a different mobile number, they control your account. Never share this number via phone or email.
- Bank Account Details: Your account number and IFSC code can be used in fraud. Only share them with trusted organisations during official processes (e.g., salary deposit).
- Screenshots of Transactions or Proofs: Scammers can use these to impersonate you or create fake refund claims. Avoid sharing them with strangers.
How to Verify a Legitimate Payment Link or Request
Scammers are increasingly using authentic-looking fake websites and apps. Here’s how to verify before you pay:
1. Check the URL
– Hover over links; legitimate URLs belong to official domains (e.g., icicibank.com, googlepay.app, phonepe.com).
– Fraudulent URLs often use lookalikes: “i-citibank.com” or “google-pay-secure.com.”
– Always type the official URL directly into your browser instead of clicking links in emails or SMS.
2. Look for HTTPS & Padlock
– Official websites show a padlock icon and “https://” (not “http://”) in the address bar.
– Encrypted connections protect your data; unencrypted sites are red flags.
3. Verify Direct with the Sender
– If you receive a payment request from a friend or vendor via UPI, confirm by calling or messaging them through a separate verified channel (e.g., phone number you have on file).
– Never assume a message is from your bank, even if the sender ID looks official. Banks typically don’t ask you to click links; they tell you to log in directly.
4. Be Skeptical of Urgency & Prizes
– Scammers create fake emergencies (“Account locked,” “Pay now to avoid fine”) or offer unbelievable prizes (“You’ve won ₹1 Lakh”).
– Legitimate banks give you time to respond; they don’t threaten immediate account closure.
What Happens If Your UPI Account Is Compromised?
If you suspect fraud, act immediately:
Step 1: Block Your UPI ID
- Open your payment app and go to Settings → Security → Block UPI ID (or similar option).
- This stops further transactions on that ID.
- Alternatively, call your bank’s customer service and request a UPI block.
Step 2: Notify Your Bank
- Call your bank’s 24/7 helpline number (on the back of your debit card or on their website).
- Report the fraud and the amount lost.
- Ask them to:
- Review and reverse fraudulent transactions (if possible).
- Reissue your debit card and UPI PIN.
- Check for linked accounts or changes to your registered details.
Step 3: File a Complaint
- Log into your payment app and report the transaction as fraudulent (usually under “Help” or “Report an Issue”).
- File a complaint with the RBI’s NODAL Centre (centralized grievance system) via https://www.pgportal.rbi.org.in or call 1800-425-4000.
- File a police complaint (FIR) at your local cyber crime unit or file online at https://cybercrime.gov.in for evidence and insurance claims.
Step 4: Monitor Your Account
- Watch your linked bank account for suspicious activity over the next 30–60 days.
- Scammers sometimes delay secondary fraud to avoid detection.
- Check your CIBIL score (credit report) to ensure no fraudulent loans or credit lines have been opened in your name.
How Jupiter’s UPI & Digital Banking Simplifies Secure Payments
Jupiter’s platform integrates real-time fraud monitoring, biometric security, and instant transaction notifications to make UPI safer and simpler. With Jupiter, you get a single dashboard to track all payments, set spending limits, and flag suspicious activity—removing the need to juggle multiple payment apps while keeping security at the forefront.
What’s the RBI’s Dispute Resolution Timeline?
Per RBI’s Ombudsman Rules and 2023 Fraud Liability Circular:
| Time Frame | Action |
|---|---|
| Within 7 Days | Report the fraud to your bank. If you report within 7 days and the fraud is confirmed as not your fault, you get full reimbursement. |
| 7–45 Days | Bank investigates. The burden of proof is on the bank to prove you were negligent (e.g., you shared your PIN). If they can’t, you’re reimbursed. |
| 45+ Days | If you don’t report, the liability shifts to you. You may bear the loss unless you can prove the fraud was the bank’s fault (e.g., system breach). |
| Escalation | If your bank denies your claim, you can escalate to the RBI Ombudsman (ombudsman.rbi.org.in) within 30 days. The Ombudsman investigates free of charge. |
Can You Recover Money Lost to UPI Fraud?
Recovery depends on timing and negligence:
- If you report within 7 days and weren’t negligent: Full reimbursement (RBI mandate since September 2023).
- If you report after 7 days: The bank may share liability or demand you prove it wasn’t your fault. Recovery is uncertain.
- If fraud involves your PIN or OTP sharing: Banks may argue you were negligent, reducing or eliminating reimbursement.
- For merchant scams (fake goods, non-delivery): You may file a chargeback via your bank, but success depends on evidence and the merchant’s responsiveness.
Keep all transaction records, screenshots of communication, and police FIR numbers to strengthen your claim.
Why Should You Use Transaction Limits as a Safety Tool?
Setting a daily limit lower than the RBI maximum (₹200,000) acts as a circuit breaker:
- If a scammer gains access to your UPI, they can only steal up to your limit.
- Example: If you set a ₹10,000 daily limit but someone attempts a ₹50,000 transaction, it auto-fails.
- To increase the limit for a legitimate high-value payment, you can temporarily raise it, complete the transaction, and lower it again.
- This is especially useful if you carry your phone into high-risk environments (crowded places, untrusted WiFi zones).
Key Cybersecurity Habits for UPI Users
- Use Strong, Unique Passwords: If you log into your payment app via email/password, use a complex password (mix of letters, numbers, symbols) and don’t reuse it across apps.
- Keep Your Phone Updated: Install OS and app updates immediately; they patch security vulnerabilities.
- Avoid Public WiFi for Payments: Scammers can intercept data on unsecured networks. Use mobile data or trusted home WiFi for UPI transactions.
- Clear Your Browser Cache: After logging into your bank’s website, clear cached passwords and cookies to prevent data theft if someone else uses your device.
- Enable App Notifications: Suspicious login alerts (e.g., “Your Google Pay was accessed from a new device”) warn you of compromise immediately.
- Verify Caller Identity: If someone calls claiming to be from your bank, hang up, look up the bank’s official number, and call them back. This prevents social engineering.