Payments
UPI QR security and common scams
You never scan a QR code to receive money, and you never enter your UPI PIN to receive money: both actions only ever send it. Most UPI QR fraud is social: scan-to-receive stories, collect-request abuse, fake refunds and stickers pasted over genuine merchant codes. Check the payee name every time.
The one sentence that defeats most UPI fraud
You never scan a QR code to receive money. Scanning initiates a payment from you; entering your UPI PIN authorises money leaving your account. There is no flow (none), in which receiving money requires you to scan anything or type your PIN. Every scam below is a story built to make a victim forget this sentence.
The design is genuinely sound: a UPI QR code contains only an address and labels, it cannot pull funds, and every payment requires the payer's explicit PIN. The attacks all target the human, not the protocol.
The common scams
"Scan this to receive your money." A buyer on a classifieds site, a fake lottery, a cashback agent. Someone owes you money and sends a QR code to "collect" it. The code is a payment request; the PIN you enter sends your money to them. The tell is definitional: if money is coming to you, there is nothing to scan and no PIN to enter.
Collect-request abuse. UPI supports requests that appear in your app asking you to approve a payment. Fraudsters fire these at victims with names like "Refund" or "Verification", hoping someone taps approve and enters a PIN on autopilot. Approving a collect request always sends money. Decline anything you did not initiate.
The fake refund. "We overcharged you / your delivery failed. We are processing your refund, please scan and confirm." Same mechanics, with urgency and an apologetic script. Real refunds arrive without your participation.
Overlay stickers. The one physical attack: a fraudster's code pasted over a merchant's genuine standee, diverting takings until someone notices. It needs no technical skill and is the dominant fraud against shops: the pattern is dissected in stickers placed over real codes.
Screen-share "support". A fake helpline talks the victim into installing a screen-sharing app, then watches or drives the UPI app directly. Not a QR attack, but it harvests the same accounts; no bank or PSP ever needs to see your screen.
Merchant checklist
- Inspect your standee at every opening. Run a finger over the code: an overlay sticker has an edge. Laminated prints make overlays lift visibly.
- Print your business name large, matching what the app shows. Customers are your tamper detection, but only if they can compare. A customer saying "it shows a different name" is an alarm; see wrong-name troubleshooting.
- Scan your own code weekly and decode-verify it after any reprint.
- Watch settlement daily. A quiet day on a busy counter means the money is going somewhere, the full counter setup is in UPI QR for a small shop.
Customer checklist
- Read the payee name on the confirmation screen, every time. It is the one check that catches overlays, and it costs two seconds.
- Never scan or enter a PIN to receive money. Repeat it until it is reflexive.
- Decline unexpected collect requests, whatever they are labelled.
- Check the amount before the PIN, on open-amount codes you typed it yourself.
- Treat urgency as a signal. Legitimate payments survive a ten-second pause; scams do not.
Donation standees deserve special care on both sides: goodwill plus low attention is exactly what overlay fraud feeds on, covered in UPI QR for donations.
FAQ
Can someone steal money if I scan their QR code?
Not from the scan alone. Money moves only when you confirm a payment with your UPI PIN. The scam is convincing you that scanning and entering the PIN will bring money in. It never does, it only sends.
What is the scan-to-receive scam?
A fraudster claims they are paying you and sends a QR code to "collect" it. The code actually initiates a payment from your account, and the PIN you enter authorises it. Receiving money never requires scanning or a PIN.
How do shops protect their UPI QR standee?
Inspect it at every opening for pasted-over stickers, laminate it so overlays lift, print the business name large beside the code so customers spot mismatches, and check settlement daily for unexplained quiet.
Is it safe to pay by scanning a QR code at a shop?
Yes, provided you read the payee name on your confirmation screen and it matches the business. The protocol requires your PIN for every payment; the real risks are overlay stickers and social engineering, both defeated by that one check.
Try it: free, no signup
Related
- The UPI QR code format, parameter by parameter, A UPI QR code is a upi://pay deep link. pa (the VPA) and pn (payee name) are required; am, cu, tn, tr, mc and mode are optional. NPCI standardised it, so…
- A UPI QR code for a small shop, Generate a static code from your VPA with no amount, print it at 4 cm or larger on matt stock, put your business name in large text beside it, and check…
- A UPI QR code for donations, Open amount, VPA registered in the organisation's name, name printed large, laminated standee. The donation-specific details that build donor trust.
- QR code stickers placed over real ones: the overlay attack, The cheapest QR attack is a printed sticker pasted over a genuine code. Why it works, where it happens, and what venues can do to make overlays obvious.
- UPI QR code shows the wrong name, The pn parameter is only a hint: UPI apps display the bank-registered name for the VPA. When a differing name is normal, and when it is a warning sign.