Most digital banking losses in India do not start with a hacked bank vault. They start with a phone call about “KYC expiry,” a WhatsApp message offering a refund, a UPI collect request for ₹1, or a stranger asking you to install a screen-sharing app “so the bank can verify you.” Once you share an OTP or approve a payment, the money moves in seconds — and recovering it becomes a race against time.

This guide explains how the most common scams actually work, the habits that stop them, and a practical playbook for the first hour after a suspicious debit. It is educational, not legal advice. For official advisories, follow your bank’s security pages and the resources published by the Reserve Bank of India (RBI) and the National Payments Corporation of India (NPCI).

Non-negotiable rule: No bank, RBI official, NPCI staff member or police officer will ever ask for your OTP, UPI PIN, CVV, net-banking password or screen-sharing access. Hang up and call the number on your debit card or the bank’s official website.

How digital banking fraud usually works

Fraudsters rarely break encryption. They persuade you to authorise a transfer. Typical stages:

  1. Hook — urgency or authority (“account will freeze in 2 hours,” “refund pending,” “police case”).
  2. Credential harvest — they ask for OTP, PIN, card details, or remote access.
  3. Cash-out — money is moved via UPI, IMPS or card to mule accounts and withdrawn quickly.
  4. Silence — numbers go dead; recovery depends on how fast you and the banks act.

Understanding that sequence matters more than memorising a tip list. If a stranger creates urgency around banking, assume it is social engineering until proven otherwise through an official channel you initiated.

UPI scams in detail

UPI is safe when used carefully. The weak point is the human approval step. For setup and limits, see our UPI beginner’s guide; this section focuses on fraud patterns.

Collect-request (pull) fraud

A UPI “collect” or “request money” asks you to approve a debit from your account. Scammers send collect requests for ₹1 or for large amounts hoping you tap Approve without reading. Always read the payee name and amount. If you did not expect a collect request, decline it.

QR code overlay / sticker swap

At shops, parking lots or temples, a genuine merchant QR sticker can be covered with a fraudster’s QR. Your app may still show a name that looks similar. Before paying:

Fake refund and “you paid twice” scripts

After an online purchase or hotel booking, someone calls claiming you were double-charged and must “share OTP to reverse.” Refunds never require your OTP. Contact the merchant or bank through official apps only.

Wrong-number / “send ₹1 to verify”

A stranger claims they received money by mistake and asks you to “confirm by sending ₹1” or approving a collect. Do not. If you received an unexpected credit, contact your bank — do not follow the stranger’s instructions.

Daily limits as a safety valve

Most banking and UPI apps let you set per-transaction and daily limits. Cap them at what you actually need. A low daily limit will not stop every scam, but it can reduce how much a compromised session can drain before you notice.

OTP, phishing and fake apps

Read every OTP SMS before typing it

OTP messages usually state purpose and amount (for example, “UPI payment of ₹5,000 to Merchant X”). If the amount or payee is wrong, do not enter the OTP. Sharing an OTP is equivalent to authorising the transaction.

KYC expiry and “RBI / police” calls

Callers claim your KYC expired and the account will freeze unless you share OTP or install a remote app. Real KYC updates happen in branch, official net banking or the bank’s verified mobile app — never via an unsolicited call that demands secrets.

Phishing links and lookalike sites

SMS or email links that say “verify account now” often lead to pages that copy your bank’s login design. Habits that help:

Remote-access apps (AnyDesk, TeamViewer, etc.)

Anyone who asks you to install screen-sharing software “for bank verification” is attempting fraud. Banks do not operate that way. If you already installed such an app during a suspicious call, uninstall it, change banking passwords and PINs from a different device, and call the bank helpline immediately.

Net banking and device hygiene

Red-flag table

Scam typeHow it worksYour response
KYC expiry callCaller claims account will freeze; asks for OTP or remote appHang up. Update KYC only via official app/branch.
Refund fraud“You overpaid — share OTP to receive refund”Refunds never need your OTP. Contact merchant via official channel.
UPI collect requestUnexpected request to pull money from youDecline. Never approve unknown collects.
QR overlayFake sticker over merchant QRVerify payee name on screen before paying.
Fake job / processing feeAsks for UPI fee before interviewLegitimate employers do not charge upfront fees.
Screen-sharing appsAnyDesk/TeamViewer for “verification”Refuse, uninstall if installed, call bank.
Lottery / customs / income-tax threatThreatens arrest unless you pay via UPIHang up. Government agencies do not demand UPI bribes.

First-hour incident response

If you see an unauthorised debit or realise you shared an OTP:

  1. Minute 0–5: Call your bank’s 24/7 helpline (number on the back of your debit card or official website). Ask them to block UPI, cards, net banking and any suspicious beneficiaries. Note the complaint / reference number.
  2. Minute 5–15: From a safe device, change net-banking password, UPI PIN and email password if the same mailbox was involved. Uninstall remote-access apps.
  3. Minute 15–30: Capture screenshots of SMS alerts, UTR/reference numbers and call logs. File a report at cybercrime.gov.in or dial 1930.
  4. Same day: Submit a written complaint to the bank (email/app ticket) with UTRs and timeline. For large losses, lodge an FIR at the local police station and keep copies.
  5. Follow-up: Track both the bank ticket and cybercrime complaint IDs. Recovery is not guaranteed for customer-authorised payments, but speed improves the chance that receiving accounts are frozen.
Large transfers tip: For property or business payments, prefer NEFT/RTGS with a verified IFSC, send a ₹1 test credit first, and confirm with the recipient by a known phone number — not a number that called you.

Protecting family accounts (elderly parents and first-time users)

Many successful scams target people who are new to UPI or who trust callers who sound official. If you help parents or relatives with banking:

Explain that genuine banks never ask for remote-access apps. A five-minute rehearsal prevents a five-lakh mistake.

Customer liability — why speed and evidence matter

RBI’s customer-protection framework for unauthorised electronic transactions distinguishes cases where the customer shared credentials from cases where the customer did not authorise the payment. Exact timelines and liability caps are defined in RBI circulars and your bank’s board-approved policy — read the version your bank publishes.

In practice:

This site cannot determine liability for your case. Ask your bank which category they have logged and escalate in writing if the response is incomplete.

Frequently Asked Questions

Can the bank reverse a UPI fraud transaction?

If you authorised the payment (entered PIN/OTP), reversal is difficult and depends on the receiving bank freezing funds in time. Report within minutes. Unauthorised transactions reported quickly have stronger protection pathways under RBI customer-liability guidance — ask your bank which category applies to your case.

Will a bank ever ask for my OTP on a phone call?

No. Hang up and call back using the number on your card or the bank’s official site.

What should I do in the first 15 minutes after a fraud debit?

Block UPI/cards/net banking via the helpline, change credentials, save UTRs, and file at cybercrime.gov.in / 1930.

Is UPI safe for large payments?

Yes when used carefully. For very large amounts, many people prefer NEFT/RTGS with verified IFSC and a test transfer.

Does installing AnyDesk for “bank verification” ever make sense?

No. That request is a fraud signal.

What is the National Cybercrime Helpline?

Dial 1930 or use cybercrime.gov.in, and always contact your bank in parallel.

IFSCNOW Editorial

Published by HappyMynds. Practical banking guides based on public RBI/NPCI advisories and common fraud patterns reported by Indian users. See our editorial standards.