Indian businesses face rising UPI fraud risks amid rapid transaction growth

As UPI transactions in India surge to over ₹29.52 lakh crore, merchants face increasing scams like QR code tampering and impersonation, prompting calls for stricter verification protocols and layered security measures.

As digital payments have become routine for Indian businesses, the same speed that makes UPI convenient has also given fraudsters more room to operate. PayU says merchants are facing a widening range of scams, from fake payment screenshots and QR-code tampering to refund fraud, phishing links and impersonation attempts. NPCI figures cited by the company show that UPI processed more than 22,641 million transactions worth over ₹29.52 lakh crore in March 2026, while government figures presented in Parliament put reported fraud cases at 10.64 lakh, amounting to ₹805 crore, through November 2025.

The core lesson for merchants is simple: a payment should never be treated as settled until it has been confirmed in an official system. PayU argues that relying on screenshots, SMS alerts or customer assurances leaves businesses exposed, especially in fast-moving retail, delivery and small-ticket B2B settings. Industry guides from CyberScamCheck, RingSafe and CommonManLaw point to the same pattern across 2026 scams: fraud works best when staff are rushed, distracted or pressured into acting before they verify the transaction.

Among the most common tricks are edited payment screenshots, swapped QR codes, fake refund claims, phishing links and impersonation of bank staff, payment partners or senior colleagues. CyberScamCheck and IndianUPI both warn that fraudsters often try to extract OTPs, PINs or login details, while RingSafe notes that collect-request scams and QR-swap attacks remain especially persistent. The common defence is to treat any request to “receive money” by entering a UPI PIN as a red flag, not a routine step.

Merchants are advised to build checks into daily operations rather than rely on one-off training. PayU recommends verifying payments through the business dashboard, using dynamic QR codes tied to specific amounts and setting refund approval rules, particularly for larger sums. The company also highlights role-based access controls, settlement reconciliation and real-time alerts as practical ways to narrow the gaps that fraudsters exploit. RingSafe says backend detection at payment-service-provider level adds another layer of protection by catching suspicious patterns before they spread.

Detection depends on spotting behaviour that does not fit normal business activity. PayU points to warning signs such as urgent delivery requests before confirmation, mismatched payer names, repeated refund claims and failed payments from the same device or number. It also recommends daily exception reports that flag high-value transactions, duplicate refunds and settlement mismatches. That approach is echoed across the wider safety guides, which stress that fraud often becomes visible only when teams review transactions systematically rather than waiting for a complaint.

If a business suspects fraud, speed matters. PayU advises stopping fulfilment, preserving evidence, notifying the bank or payment partner, restricting compromised access and reporting the case through official cybercrime channels. Its merchant tools are designed to reduce manual verification, with real-time confirmation, dynamic QR codes, refund workflows, role-based controls and automated reconciliation. For businesses handling high volumes of UPI payments, the company says layered controls are the best defence against scams that increasingly depend on human error.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.