Despite UPI system changes, social engineering fraud continues to exploit trust

A longstanding scam exploiting trust in India’s UPI payment system persists despite recent regulatory changes, highlighting the importance of user vigilance against social engineering tactics sa that fraudsters continue to manipulate victims into authorising unauthorised transactions.

One of the oldest UPI confidence tricks in India has survived a major change to the system. The National Payments Corporation of India told banks and payment apps to stop peer-to-peer collect requests from 1 October 2025, but the underlying fraud still appears in buyer-seller deals, fake refunds, prize claims and QR-code ploys because the victim is persuaded to approve the debit personally. (avantiscdnprodstorage.blob.core.windows.net)

What people call UPI PIN fraud is usually not a breach of the payments network at all, but a case of social engineering. NPCI says a UPI PIN is the 4-6 digit code used to authorise bank transactions, that customer support will never ask for it, and that a payment is processed only when the user goes to the request and explicitly hits the pay option on the registered device. In other words, the criminal typically wins not by breaking into the account, but by getting the account holder to approve the transfer. (npci.org.in)

That is why confusion is the fraudster’s main tool. Moneycontrol noted that a collect request is not inherently fraudulent and can be used legitimately by businesses or friends to ask for payment, but it can be presented in a way that resembles money coming in. One common trap starts when a supposed buyer on an online marketplace says, “Please approve the request so I can transfer the amount.” If the target then types in the UPI PIN, the app is not crediting the account; it is authorising money to leave it. (moneycontrol.com)

Another version begins with a small real transfer meant to disarm suspicion. India Today reported that fraudsters may first send a token amount, then say it was a mistake or claim an emergency and push the victim to send it back through a payment request. NPCI responded in January 2025 by saying it had not observed cases on the UPI platform matching the “jumped deposit” description exactly, but it repeated the key consumer point: a UPI PIN is not needed to receive funds, only to approve an outgoing payment. (indiatoday.in)

The pattern is not new. The Times of India reported Bengaluru cases as far back as 2019 in which fraudsters first sent Rs 10 or Rs 20 to gain trust, then moved on to larger requests by QR code or collect-call style prompts. The paper quoted Puneet Kapoor of Kotak Mahindra Bank saying criminals would often test an account with Rs 10,000, then Rs 20,000, and keep raising the amount until the balance was exhausted. Axis Bank’s Sanjeev Moghe told the newspaper that the victims were not confined to older or less experienced users; urban professionals were also being caught out. (timesofindia.indiatimes.com)

What makes the scam particularly damaging is the speed of the payment rail. NPCI’s FAQ says a UPI payment cannot be stopped once it has been initiated, and Mint reported that although NPCI has a dispute-resolution framework for fraud complaints, the recovery process can still be cumbersome. Moneycontrol says anyone who approves a fraudulent request should contact the bank immediately, while Vishal Gehrana of Karanjawala & Co told Business Standard that reporting within 24 hours to helpline 1930 or through the national cybercrime portal may improve the chances of recovery. (npci.org.in)

The best defence is to slow down before authorising anything. Check who sent the request, decline unknown payment demands, never share a UPI PIN or OTP, and do not install screen-sharing or remote-access apps at a stranger’s instruction, according to Business Standard and NPCI’s fraud-awareness guidance. The Department of Telecommunications says Chakshu on the Sanchar Saathi platform can be used to report suspected fraud calls, SMS messages or WhatsApp contacts; if money has already gone, victims should use 1930 or the cybercrime portal instead. (business-standard.com)

The lesson is broader than India or UPI. The US Federal Trade Commission warns that payment-app scams are effective because funds are often difficult to recover once sent, and says any unexpected request should be checked with the supposed sender using contact details you trust, not the ones in the message. Mint drew a similar conclusion in its comparison with the e-rupee: changing the payment design may remove one route for fraud, but it does not protect anyone who is rushed, manipulated or talked into handing over control of the transaction. In instant payments, prevention matters far more than reversal. (consumer.ftc.gov)

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.