August 17, 2026 · 9 min read

How Hundreds of Crores Vanish Every Year — and What Businesses Can Do About It

How Hundreds of Crores Vanish Every Year — and What Businesses Can Do About It
Fraud Risk & Digital Payments

UPI Fraud in India: How Hundreds of Crores Vanish Every Year — and What Businesses Can Do About It

UPI processes more real-time payments than any system on earth. That same scale has made it the single largest channel for payment fraud in India — and increasingly, businesses, not just individuals, are the ones left absorbing the loss. Here is what the numbers show, and what a practical control framework looks like.

Published by Paaramarsh Business Solutions · Forensic Audit & Payment Fraud Advisory

The Scale of the Problem

UPI's growth in India has been extraordinary — and so has the growth in fraud riding on top of it. Government data tabled in the Lok Sabha traces a clear trajectory: UPI-related fraud losses have climbed from a relatively modest ₹242 crore in FY2021–22 to over ₹1,000 crore in FY2023–24, before easing slightly as newer safeguards took effect.

₹242 cr
UPI fraud losses, FY2021–22
₹1,087 cr
UPI fraud losses, FY2023–24 (13.42 lakh cases)
₹981 cr
UPI fraud losses, FY2024–25 (12.64 lakh cases)
₹805 cr
UPI fraud losses, FY2025–26 (till Nov — 10.64 lakh cases)

Put another way: India is currently losing roughly ₹2–3 crore a day to UPI fraud, spread across well over a million individual incidents a year. And this figure sits inside a larger digital-payments fraud problem — the RBI's FY2024–25 Annual Report noted that digital payment frauds (including UPI, cards, and internet banking) accounted for 56.5% of all reported banking fraud cases that year.

Why the fraud count is rising even as the amount eases: officials attribute the trend primarily to scale, not system failure — UPI now processes over 20 billion transactions a month. But scale is exactly the point for a business owner: even a fraud rate that looks small in percentage terms adds up fast when transaction volumes are this large, and every business accepting UPI payments is now, statistically, operating inside a high-fraud-volume payment rail.

How UPI Fraud Actually Works

Almost none of today's UPI fraud is a technical hack of the system itself. NPCI's infrastructure is robust; the fraud happens because scammers manipulate people into authorising their own loss. Four patterns account for most of the incidents businesses and their customers encounter.

1. The Collect Request Scam

A fraudster sends a UPI "collect request" disguised as an incoming refund, payment confirmation, or rebate. The victim, believing they are about to receive money, enters their UPI PIN — which actually authorises an outgoing payment to the fraudster. This remains one of the most common scams reported today, frequently targeting people selling items online or awaiting a routine refund.

2. QR Code Swapping

Fraudsters replace or overlay a merchant's legitimate QR code with one that redirects payment to their own account, or present a QR code framed as necessary to "receive" a payment — when scanning it actually initiates one. This has become a specific and growing risk for small retail and service businesses that display a static QR code at their counter.

3. Impersonation & the "Boss Scam"

Scammers pose as bank officials, delivery agents, customer-support executives, or — in a pattern the Indian Cyber Crime Coordination Centre (I4C) has specifically flagged to companies in 2026 — as a senior executive urgently instructing a junior employee to make a payment. These calls and messages rely on urgency and authority to bypass normal verification.

4. Fake Payment Screenshots

A buyer shows a forged UPI payment confirmation screenshot as proof of payment and walks away with goods or services before the business notices no money has actually landed in its account — a scam that specifically and disproportionately targets merchants and small businesses rather than individual consumers.

Why Businesses Are Increasingly the Target

Early UPI fraud coverage focused almost entirely on individual consumers. That's shifting. Three factors are pushing more fraud toward businesses specifically:

  • Merchant QR codes are a fixed, physical attack surface. Unlike a phishing link sent to one person, a swapped or overlaid QR code at a shop counter can defraud every customer who scans it until someone notices.
  • Fake payment screenshots exploit trust at the point of sale — a business that doesn't verify each UPI credit in real time, particularly during busy periods, is exposed to systematic loss of goods or services against payments that never arrived.
  • Impersonation scams are moving up the org chart. The 2026 "Boss Scam" advisory from I4C specifically warns companies about fraudsters impersonating senior executives to pressure finance or accounts staff into urgent UPI or bank transfers — a corporate variant of the classic vishing scam, aimed at the person with payment authority rather than a retail customer.

What NPCI and RBI Have Already Done

Regulators have not been passive. Recent and ongoing measures include:

  • Daily transaction caps of ₹1 lakh on most P2P and merchant UPI payments, with higher limits reserved for specific approved categories.
  • Removal of "collect requests" for many use cases from October 2025 onward, directly targeting the most common scam vector.
  • Clear display of the beneficiary's registered name before a payment is confirmed, making impersonation and fake-account fraud easier to spot before money moves.
  • AI-driven mule-account detection systems and real-time fraud monitoring shared by NPCI with participating banks.
  • A zero-liability refund policy for customers who report fraud within 3 days without negligence on their part, with partial protection extending to 7 days.

These measures reduce fraud, but they don't eliminate a business's exposure — particularly for fraud types like fake screenshots or QR swapping, which succeed regardless of how secure the underlying UPI rail is, because the manipulation happens at the human, not the system, level.

A Practical Control Framework for Businesses

Control Area What to Implement
Payment verification Never release goods or services on the strength of a screenshot alone — verify every UPI credit directly in your bank statement or merchant app before completing a transaction, especially during high-footfall periods.
QR code hygiene Physically inspect displayed QR codes regularly for tampering or overlay stickers; where transaction volumes justify it, move to a dynamic, POS-integrated QR system rather than a static printed code.
Staff training Brief accounts and front-line staff specifically on the collect-request trap and the "Boss Scam" impersonation pattern — both rely on staff not knowing the mechanism, not on any technical weakness.
Payment authorisation controls Apply the same segregation-of-duties principle used to prevent traditional payment fraud to UPI and digital transfers — require a second verification step for urgent, unusual, or high-value requests, even (especially) when they claim to come from a senior executive.
Reconciliation frequency Reconcile UPI/digital payment receipts against bank records daily, not monthly — the sooner a discrepancy is caught, the better the odds of recovery under RBI's short reporting windows.
Incident response Keep the National Cyber Crime Helpline (1930) and cybercrime.gov.in reporting process documented and known to staff — RBI's zero-liability protection is time-bound, so speed of reporting materially affects recovery odds.
The forensic-audit angle: most UPI fraud losses businesses suffer are not caught by a routine statutory audit, because individually they look like small, explainable discrepancies — a missing credit here, a disputed sale there. It is only when these are aggregated and traced systematically, the way a forensic review does, that the true scale and pattern of loss becomes visible.

Key Takeaways

Insight Detail
Scale drives fraud volume UPI fraud losses have run between ₹800 crore and ₹1,100 crore annually over the past three fiscal years, with well over a million reported incidents each year.
Fraud is social engineering, not hacking Collect-request scams, QR swapping, impersonation, and fake screenshots all rely on manipulating a person's action — not breaching UPI's technical infrastructure.
Businesses are an expanding target Corporate impersonation ("Boss Scams") and merchant-focused fraud (QR swapping, fake screenshots) are growing categories distinct from consumer-focused P2P scams.
Controls exist and work Payment verification discipline, staff training, segregation of authorisation duties, and fast reconciliation meaningfully reduce a business's exposure — none of it requires new technology, only process discipline.

Sources

  • Lok Sabha data tabled by the Union Ministry of Finance, December 2025 (via The420.in, NationPress)
  • Reserve Bank of India, Annual Report FY2024–25
  • National Payments Corporation of India (NPCI) — public statements on fraud monitoring and controls
  • Indian Cyber Crime Coordination Centre (I4C) advisories, 2026
  • The Tribune — "10 dangerous digital payment scams you must know in 2026"
  • Business Standard — "Digital arrest to UPI fraud: How to stay safe from top cyber scams"
#UPIFraud #DigitalPaymentSecurity #FraudDetection #ForensicAudit #CyberCrime #ComplianceMatters #RiskManagement #MSMEAdvisory
Disclaimer: This article is prepared for informational and awareness purposes only. The statistics cited are drawn from publicly available government data, regulatory reports, and news coverage as understood at the time of writing, and fraud figures are subject to revision as official data is updated. This content should not be construed as legal, financial, cybersecurity, or regulatory advice. Businesses are advised to consult qualified professionals and refer to official RBI/NPCI guidance when designing their own fraud-control frameworks. Paaramarsh Business Solutions does not claim responsibility for independent verification of every fact referenced above.
#UPI fraud India#digital payment fraud#UPI scam prevention#QR code fraud#business fraud controls#forensic audit UPI