Most digital banking losses in India do not start with a hacked bank vault. They start with a phone call about “KYC expiry,” a WhatsApp message offering a refund, a UPI collect request for ₹1, or a stranger asking you to install a screen-sharing app “so the bank can verify you.” Once you share an OTP or approve a payment, the money moves in seconds — and recovering it becomes a race against time.
This guide explains how the most common scams actually work, the habits that stop them, and a practical playbook for the first hour after a suspicious debit. It is educational, not legal advice. For official advisories, follow your bank’s security pages and the resources published by the Reserve Bank of India (RBI) and the National Payments Corporation of India (NPCI).
Table of Contents
How digital banking fraud usually works
Fraudsters rarely break encryption. They persuade you to authorise a transfer. Typical stages:
- Hook — urgency or authority (“account will freeze in 2 hours,” “refund pending,” “police case”).
- Credential harvest — they ask for OTP, PIN, card details, or remote access.
- Cash-out — money is moved via UPI, IMPS or card to mule accounts and withdrawn quickly.
- Silence — numbers go dead; recovery depends on how fast you and the banks act.
Understanding that sequence matters more than memorising a tip list. If a stranger creates urgency around banking, assume it is social engineering until proven otherwise through an official channel you initiated.
UPI scams in detail
UPI is safe when used carefully. The weak point is the human approval step. For setup and limits, see our UPI beginner’s guide; this section focuses on fraud patterns.
Collect-request (pull) fraud
A UPI “collect” or “request money” asks you to approve a debit from your account. Scammers send collect requests for ₹1 or for large amounts hoping you tap Approve without reading. Always read the payee name and amount. If you did not expect a collect request, decline it.
QR code overlay / sticker swap
At shops, parking lots or temples, a genuine merchant QR sticker can be covered with a fraudster’s QR. Your app may still show a name that looks similar. Before paying:
- Confirm the merchant / payee name on screen matches the shop
- Prefer UPI IDs the merchant states verbally for larger amounts
- Be extra careful with handwritten or freshly stuck QR codes
Fake refund and “you paid twice” scripts
After an online purchase or hotel booking, someone calls claiming you were double-charged and must “share OTP to reverse.” Refunds never require your OTP. Contact the merchant or bank through official apps only.
Wrong-number / “send ₹1 to verify”
A stranger claims they received money by mistake and asks you to “confirm by sending ₹1” or approving a collect. Do not. If you received an unexpected credit, contact your bank — do not follow the stranger’s instructions.
Daily limits as a safety valve
Most banking and UPI apps let you set per-transaction and daily limits. Cap them at what you actually need. A low daily limit will not stop every scam, but it can reduce how much a compromised session can drain before you notice.
OTP, phishing and fake apps
Read every OTP SMS before typing it
OTP messages usually state purpose and amount (for example, “UPI payment of ₹5,000 to Merchant X”). If the amount or payee is wrong, do not enter the OTP. Sharing an OTP is equivalent to authorising the transaction.
KYC expiry and “RBI / police” calls
Callers claim your KYC expired and the account will freeze unless you share OTP or install a remote app. Real KYC updates happen in branch, official net banking or the bank’s verified mobile app — never via an unsolicited call that demands secrets.
Phishing links and lookalike sites
SMS or email links that say “verify account now” often lead to pages that copy your bank’s login design. Habits that help:
- Type your bank URL manually or use a bookmark you created yourself
- Check for HTTPS and the padlock before entering credentials
- Never open banking links from unknown senders
- Prefer the official app from Google Play / App Store, not APK files from Telegram or WhatsApp
Remote-access apps (AnyDesk, TeamViewer, etc.)
Anyone who asks you to install screen-sharing software “for bank verification” is attempting fraud. Banks do not operate that way. If you already installed such an app during a suspicious call, uninstall it, change banking passwords and PINs from a different device, and call the bank helpline immediately.
Net banking and device hygiene
- Separate PINs — UPI PIN, ATM PIN and phone lock should not be identical. Avoid birthdays and sequential numbers.
- Biometric app lock — enable it so a stolen unlocked phone cannot open UPI apps easily.
- Transaction alerts — turn on SMS and push notifications for every debit. Spotting fraud in minutes beats discovering it in the next statement.
- SIM and UPI hygiene — when you change numbers, deregister the old number from UPI and banking profiles. Recycled SIMs linked to old UPI IDs are a known fraud vector.
- Keep apps updated — banking app updates often include security patches.
- Public Wi-Fi caution — avoid logging into net banking on open café Wi-Fi; use mobile data instead.
Red-flag table
| Scam type | How it works | Your response |
|---|---|---|
| KYC expiry call | Caller claims account will freeze; asks for OTP or remote app | Hang up. Update KYC only via official app/branch. |
| Refund fraud | “You overpaid — share OTP to receive refund” | Refunds never need your OTP. Contact merchant via official channel. |
| UPI collect request | Unexpected request to pull money from you | Decline. Never approve unknown collects. |
| QR overlay | Fake sticker over merchant QR | Verify payee name on screen before paying. |
| Fake job / processing fee | Asks for UPI fee before interview | Legitimate employers do not charge upfront fees. |
| Screen-sharing apps | AnyDesk/TeamViewer for “verification” | Refuse, uninstall if installed, call bank. |
| Lottery / customs / income-tax threat | Threatens arrest unless you pay via UPI | Hang up. Government agencies do not demand UPI bribes. |
First-hour incident response
If you see an unauthorised debit or realise you shared an OTP:
- Minute 0–5: Call your bank’s 24/7 helpline (number on the back of your debit card or official website). Ask them to block UPI, cards, net banking and any suspicious beneficiaries. Note the complaint / reference number.
- Minute 5–15: From a safe device, change net-banking password, UPI PIN and email password if the same mailbox was involved. Uninstall remote-access apps.
- Minute 15–30: Capture screenshots of SMS alerts, UTR/reference numbers and call logs. File a report at cybercrime.gov.in or dial 1930.
- Same day: Submit a written complaint to the bank (email/app ticket) with UTRs and timeline. For large losses, lodge an FIR at the local police station and keep copies.
- Follow-up: Track both the bank ticket and cybercrime complaint IDs. Recovery is not guaranteed for customer-authorised payments, but speed improves the chance that receiving accounts are frozen.
Protecting family accounts (elderly parents and first-time users)
Many successful scams target people who are new to UPI or who trust callers who sound official. If you help parents or relatives with banking:
- Set conservative UPI daily limits on their apps
- Enable transaction SMS alerts to your number as a secondary watch if the bank allows linked alerts
- Agree on a family rule: “Never share OTP — call me first”
- Bookmark the bank’s official site and helpline on their phone; delete random “banking support” contacts
- Practice declining a collect request together once so the UI is familiar under stress
Explain that genuine banks never ask for remote-access apps. A five-minute rehearsal prevents a five-lakh mistake.
Customer liability — why speed and evidence matter
RBI’s customer-protection framework for unauthorised electronic transactions distinguishes cases where the customer shared credentials from cases where the customer did not authorise the payment. Exact timelines and liability caps are defined in RBI circulars and your bank’s board-approved policy — read the version your bank publishes.
In practice:
- Report immediately — delays weaken your position
- Keep evidence — SMS alerts, call recordings if legal in your state, screenshots, UTRs, cybercrime complaint IDs
- Do not negotiate with the fraudster — once money moved, only banks and law enforcement can help
- Watch mule-account patterns — money is often split across multiple accounts within minutes; freezing early is everything
This site cannot determine liability for your case. Ask your bank which category they have logged and escalate in writing if the response is incomplete.
Frequently Asked Questions
Can the bank reverse a UPI fraud transaction?
If you authorised the payment (entered PIN/OTP), reversal is difficult and depends on the receiving bank freezing funds in time. Report within minutes. Unauthorised transactions reported quickly have stronger protection pathways under RBI customer-liability guidance — ask your bank which category applies to your case.
Will a bank ever ask for my OTP on a phone call?
No. Hang up and call back using the number on your card or the bank’s official site.
What should I do in the first 15 minutes after a fraud debit?
Block UPI/cards/net banking via the helpline, change credentials, save UTRs, and file at cybercrime.gov.in / 1930.
Is UPI safe for large payments?
Yes when used carefully. For very large amounts, many people prefer NEFT/RTGS with verified IFSC and a test transfer.
Does installing AnyDesk for “bank verification” ever make sense?
No. That request is a fraud signal.
What is the National Cybercrime Helpline?
Dial 1930 or use cybercrime.gov.in, and always contact your bank in parallel.