# UPI QR security and common scams

> You never scan a QR code to receive money, and you never enter your UPI PIN to receive money: both actions only ever send it. Most UPI QR fraud is social: scan-to-receive stories, collect-request abuse, fake refunds and stickers pasted over genuine merchant codes. Check the payee name every time.

Source: https://useqr.app/docs/payments/upi-qr-security-and-common-scams · Last reviewed 2026-08-21 · UseQR is free forever, no signup.

---

## The one sentence that defeats most UPI fraud

**You never scan a QR code to receive money.** Scanning initiates a payment *from* you;
entering your UPI PIN authorises money *leaving* your account. There is no flow (none), in
which receiving money requires you to scan anything or type your PIN. Every scam below is a
story built to make a victim forget this sentence.

The design is genuinely sound: a [UPI QR code](/docs/payments/upi-qr-code-format) contains
only an address and labels, it cannot pull funds, and every payment requires the payer's
explicit PIN. The attacks all target the human, not the protocol.

## The common scams

**"Scan this to receive your money."** A buyer on a classifieds site, a fake lottery, a
cashback agent. Someone owes you money and sends a QR code to "collect" it. The code is a
payment request; the PIN you enter sends your money to them. The tell is definitional: if
money is coming to you, there is nothing to scan and no PIN to enter.

**Collect-request abuse.** UPI supports requests that appear in your app asking you to
approve a payment. Fraudsters fire these at victims with names like "Refund" or
"Verification", hoping someone taps approve and enters a PIN on autopilot. Approving a
collect request always sends money. Decline anything you did not initiate.

**The fake refund.** "We overcharged you / your delivery failed. We are processing your
refund, please scan and confirm." Same mechanics, with urgency and an apologetic script.
Real refunds arrive without your participation.

**Overlay stickers.** The one physical attack: a fraudster's code pasted over a merchant's
genuine standee, diverting takings until someone notices. It needs no technical skill and
is the dominant fraud against shops: the pattern is dissected in
[stickers placed over real codes](/docs/security/qr-code-stickers-placed-over-real-ones).

**Screen-share "support".** A fake helpline talks the victim into installing a screen-sharing
app, then watches or drives the UPI app directly. Not a QR attack, but it harvests the same
accounts; no bank or PSP ever needs to see your screen.

## Merchant checklist

- **Inspect your standee at every opening.** Run a finger over the code: an overlay
  sticker has an edge. Laminated prints make overlays lift visibly.
- **Print your business name large, matching what the app shows.** Customers are your
  tamper detection, but only if they can compare. A customer saying "it shows a different
  name" is an alarm; see [wrong-name troubleshooting](/docs/troubleshooting/upi-qr-shows-wrong-name).
- **Scan your own code weekly** and [decode-verify it](/validate) after any reprint.
- **Watch settlement daily.** A quiet day on a busy counter means the money is going
  somewhere, the full counter setup is in
  [UPI QR for a small shop](/docs/payments/upi-qr-for-a-small-shop).

## Customer checklist

- **Read the payee name on the confirmation screen, every time.** It is the one check that
  catches overlays, and it costs two seconds.
- **Never scan or enter a PIN to receive money.** Repeat it until it is reflexive.
- **Decline unexpected collect requests**, whatever they are labelled.
- **Check the amount before the PIN**, on open-amount codes you typed it yourself.
- Treat urgency as a signal. Legitimate payments survive a ten-second pause; scams do not.

Donation standees deserve special care on both sides: goodwill plus low attention is
exactly what overlay fraud feeds on, covered in
[UPI QR for donations](/docs/payments/upi-qr-for-donations).

## FAQ

### Can someone steal money if I scan their QR code?
Not from the scan alone. Money moves only when you confirm a payment with your UPI PIN. The scam is convincing you that scanning and entering the PIN will bring money in. It never does, it only sends.

### What is the scan-to-receive scam?
A fraudster claims they are paying you and sends a QR code to "collect" it. The code actually initiates a payment from your account, and the PIN you enter authorises it. Receiving money never requires scanning or a PIN.

### How do shops protect their UPI QR standee?
Inspect it at every opening for pasted-over stickers, laminate it so overlays lift, print the business name large beside the code so customers spot mismatches, and check settlement daily for unexplained quiet.

### Is it safe to pay by scanning a QR code at a shop?
Yes, provided you read the payee name on your confirmation screen and it matches the business. The protocol requires your PIN for every payment; the real risks are overlay stickers and social engineering, both defeated by that one check.

## Try it

- https://useqr.app/upi
- https://useqr.app/validate
