How Hundreds of Crores Vanish Every Year — and What Businesses Can Do About It

UPI Fraud in India: How Hundreds of Crores Vanish Every Year — and What Businesses Can Do About It
UPI processes more real-time payments than any system on earth. That same scale has made it the single largest channel for payment fraud in India — and increasingly, businesses, not just individuals, are the ones left absorbing the loss. Here is what the numbers show, and what a practical control framework looks like.
The Scale of the Problem
UPI's growth in India has been extraordinary — and so has the growth in fraud riding on top of it. Government data tabled in the Lok Sabha traces a clear trajectory: UPI-related fraud losses have climbed from a relatively modest ₹242 crore in FY2021–22 to over ₹1,000 crore in FY2023–24, before easing slightly as newer safeguards took effect.
Put another way: India is currently losing roughly ₹2–3 crore a day to UPI fraud, spread across well over a million individual incidents a year. And this figure sits inside a larger digital-payments fraud problem — the RBI's FY2024–25 Annual Report noted that digital payment frauds (including UPI, cards, and internet banking) accounted for 56.5% of all reported banking fraud cases that year.
How UPI Fraud Actually Works
Almost none of today's UPI fraud is a technical hack of the system itself. NPCI's infrastructure is robust; the fraud happens because scammers manipulate people into authorising their own loss. Four patterns account for most of the incidents businesses and their customers encounter.
1. The Collect Request Scam
A fraudster sends a UPI "collect request" disguised as an incoming refund, payment confirmation, or rebate. The victim, believing they are about to receive money, enters their UPI PIN — which actually authorises an outgoing payment to the fraudster. This remains one of the most common scams reported today, frequently targeting people selling items online or awaiting a routine refund.
2. QR Code Swapping
Fraudsters replace or overlay a merchant's legitimate QR code with one that redirects payment to their own account, or present a QR code framed as necessary to "receive" a payment — when scanning it actually initiates one. This has become a specific and growing risk for small retail and service businesses that display a static QR code at their counter.
3. Impersonation & the "Boss Scam"
Scammers pose as bank officials, delivery agents, customer-support executives, or — in a pattern the Indian Cyber Crime Coordination Centre (I4C) has specifically flagged to companies in 2026 — as a senior executive urgently instructing a junior employee to make a payment. These calls and messages rely on urgency and authority to bypass normal verification.
4. Fake Payment Screenshots
A buyer shows a forged UPI payment confirmation screenshot as proof of payment and walks away with goods or services before the business notices no money has actually landed in its account — a scam that specifically and disproportionately targets merchants and small businesses rather than individual consumers.
Why Businesses Are Increasingly the Target
Early UPI fraud coverage focused almost entirely on individual consumers. That's shifting. Three factors are pushing more fraud toward businesses specifically:
- Merchant QR codes are a fixed, physical attack surface. Unlike a phishing link sent to one person, a swapped or overlaid QR code at a shop counter can defraud every customer who scans it until someone notices.
- Fake payment screenshots exploit trust at the point of sale — a business that doesn't verify each UPI credit in real time, particularly during busy periods, is exposed to systematic loss of goods or services against payments that never arrived.
- Impersonation scams are moving up the org chart. The 2026 "Boss Scam" advisory from I4C specifically warns companies about fraudsters impersonating senior executives to pressure finance or accounts staff into urgent UPI or bank transfers — a corporate variant of the classic vishing scam, aimed at the person with payment authority rather than a retail customer.
What NPCI and RBI Have Already Done
Regulators have not been passive. Recent and ongoing measures include:
- Daily transaction caps of ₹1 lakh on most P2P and merchant UPI payments, with higher limits reserved for specific approved categories.
- Removal of "collect requests" for many use cases from October 2025 onward, directly targeting the most common scam vector.
- Clear display of the beneficiary's registered name before a payment is confirmed, making impersonation and fake-account fraud easier to spot before money moves.
- AI-driven mule-account detection systems and real-time fraud monitoring shared by NPCI with participating banks.
- A zero-liability refund policy for customers who report fraud within 3 days without negligence on their part, with partial protection extending to 7 days.
These measures reduce fraud, but they don't eliminate a business's exposure — particularly for fraud types like fake screenshots or QR swapping, which succeed regardless of how secure the underlying UPI rail is, because the manipulation happens at the human, not the system, level.
A Practical Control Framework for Businesses
| Control Area | What to Implement |
|---|---|
| Payment verification | Never release goods or services on the strength of a screenshot alone — verify every UPI credit directly in your bank statement or merchant app before completing a transaction, especially during high-footfall periods. |
| QR code hygiene | Physically inspect displayed QR codes regularly for tampering or overlay stickers; where transaction volumes justify it, move to a dynamic, POS-integrated QR system rather than a static printed code. |
| Staff training | Brief accounts and front-line staff specifically on the collect-request trap and the "Boss Scam" impersonation pattern — both rely on staff not knowing the mechanism, not on any technical weakness. |
| Payment authorisation controls | Apply the same segregation-of-duties principle used to prevent traditional payment fraud to UPI and digital transfers — require a second verification step for urgent, unusual, or high-value requests, even (especially) when they claim to come from a senior executive. |
| Reconciliation frequency | Reconcile UPI/digital payment receipts against bank records daily, not monthly — the sooner a discrepancy is caught, the better the odds of recovery under RBI's short reporting windows. |
| Incident response | Keep the National Cyber Crime Helpline (1930) and cybercrime.gov.in reporting process documented and known to staff — RBI's zero-liability protection is time-bound, so speed of reporting materially affects recovery odds. |
Key Takeaways
| Insight | Detail |
|---|---|
| Scale drives fraud volume | UPI fraud losses have run between ₹800 crore and ₹1,100 crore annually over the past three fiscal years, with well over a million reported incidents each year. |
| Fraud is social engineering, not hacking | Collect-request scams, QR swapping, impersonation, and fake screenshots all rely on manipulating a person's action — not breaching UPI's technical infrastructure. |
| Businesses are an expanding target | Corporate impersonation ("Boss Scams") and merchant-focused fraud (QR swapping, fake screenshots) are growing categories distinct from consumer-focused P2P scams. |
| Controls exist and work | Payment verification discipline, staff training, segregation of authorisation duties, and fast reconciliation meaningfully reduce a business's exposure — none of it requires new technology, only process discipline. |
Sources
- Lok Sabha data tabled by the Union Ministry of Finance, December 2025 (via The420.in, NationPress)
- Reserve Bank of India, Annual Report FY2024–25
- National Payments Corporation of India (NPCI) — public statements on fraud monitoring and controls
- Indian Cyber Crime Coordination Centre (I4C) advisories, 2026
- The Tribune — "10 dangerous digital payment scams you must know in 2026"
- Business Standard — "Digital arrest to UPI fraud: How to stay safe from top cyber scams"