Fake Link-based UPI Payment Scam

Verdict: Suspicious | Risk Score: 9/10 | Severity: critical

Category: UPI, WhatsApp, Phishing

How Fake Link-based UPI Payment Scam Works

Overview: The fake link-based UPI payment scam is a rapidly rising fraud targeting users of UPI apps like PhonePe, Google Pay, and Paytm. Scammers craft deceptive messages or posts pretending to offer rewards, cashback, or quick sales, but the real aim is to trick victims into transferring money unknowingly. This method is highly dangerous as it exploits the speed and convenience of UPI, resulting in instant fund loss with little chance of reversal. How It Works: Scammers send a WhatsApp or SMS message claiming to offer products, services, or cashback, along with a payment link resembling a genuine UPI collect request. When victims click or scan the QR code, they unknowingly authorize a debit from their own account, believing they are receiving money or offers. Sometimes, the scammer may call pretending to be a seller or buyer and instructs the victim to "accept payment" or "enter UPI PIN," but it is actually a payment request taking money out. India Angle: Urban and semi-urban areas are most affected. The scam leverages popular Indian marketplaces like OLX, Facebook Marketplace, and Quickr, as well as festival campaigns or sudden deal offers. Sellers and buyers aged 25-45, especially first-time digital payment users, form the main victim group. Real Examples: - WhatsApp: “Your cashback of ₹5000 from Amazon is ready! Click the link to claim.” - Seller scenario: "Interested in your fridge for sale. Please accept my payment by clicking this link." - Buyer scenario: "Pay a small token amount via UPI link to book the scooter." Red Flags: - Requests to "accept payment" by entering UPI PIN - Unknown QR codes or payment links - Urgent or too-good-to-be-true offers - Communication only via messaging apps, no face-to-face Protective Measures: - Never enter UPI PIN to "receive" money - Remember: UPI PIN should only be used for sending money, not receiving - Always check sender details and payment request purpose - Complete sales on trusted platforms with official payment gateways If Victimised: - Contact your bank or UPI app support immediately - Call 1930 and report at cybercrime.gov.in - Notify the marketplace where the fraud occurred Related Scams: - Fake buyer/seller OLX frauds - Lottery or cashback scam links - App phishing websites mimicking UPI apps

How This Scam Works — Detailed Explanation

The fake link-based UPI payment scam primarily exploits common digital communication platforms such as WhatsApp and SMS to reach potential victims. Scammers often create fake profiles or use the names of known companies to send messages that appear legitimate. For instance, they may pose as representatives from popular e-commerce platforms, or they may impersonate friends offering exclusive deals. Victims may receive a text or message that claims they have won a gift or cashback. These communications often contain links to fraudulent sites mimicking trusted payment portals. Given the popularity of UPI apps like PhonePe, Google Pay, and Paytm in India, especially for quick transactions, these scams are particularly effective and have proliferated rapidly.

To capture the victims’ attention, scammers utilize various psychological tactics to instill a sense of urgency and fear of missing out. They often advertise enticing offers such as significant cashbacks or discounts on merchandise, leveraging consumer behaviors and the allure of instant rewards. Most scams require the victim to click on a mysterious link or scan a QR code to process what they believe is a payment or payout. Victims frequently receive instructions to enter their UPI PIN under the pretext of confirming their identity or to receive the promised funds. This tactics preys on the natural instinct to act quickly, catching victims off-guard and leading them to share sensitive information unknowingly.

Once a victim clicks the link and follows the instructions, the situation escalates quickly. Typically, the victim is redirected to a fake website resembling their UPI app, where they are asked to confirm payment details, including their UPI ID and PIN. For example, a user of Google Pay might receive a message claiming they've won ₹5,000 and just need to confirm their details to unlock the reward. Upon entering their PIN, they unknowingly authorize a money transfer to the scammer’s account, and the funds disappear without a trace. Reports from CERT-In have highlighted individual cases where victims lost amounts ranging from ₹10,000 to ₹50,000, resulting in a disturbing rise in overall financial crime due to UPI-related fraud.

This winter, multiple reports surfaced indicating that the fake link-based UPI payment scam has amassed a staggering collection of scams leading to losses around ₹1,500 crore across the nation. The Ministry of Home Affairs (MHA) has confirmed that cases of digital fraud have been on the rise, particularly since more people adopted digital payment methods after the demonetization initiative in 2016. Similarly, the Reserve Bank of India's (RBI) recent guidelines urge consumers to remain vigilant when dealing with unfamiliar links or requests for personal financial information. The impact of such scams not only leads to heavy financial losses but also erodes trust in digital payment systems, compelling users to reconsider their reliance on UPI.

To protect yourself from falling into this trap, it is crucial to develop a keen eye for spotting the difference between legitimate communications and scams. Legitimate payment links will always direct you to official applications or websites and will never ask for sensitive information like your UPI PIN under the guise of ‘confirming’ a payment or prize. Furthermore, any communication prompting urgency or extraordinary offers should raise red flags. Always verify the source before engaging in any digital financial transactions, especially if they appear unsolicited or too good to be true. Remember, if you are unsure, it's better to take a moment to double-check than to risk losing your hard-earned money.

Visual Intelligence:

BharatSecure's AI has identified this as a used in scams targeting Indian users.

Who Does Fake Link-based UPI Payment Scam Target?

General public across India

Red Flags — How to Identify Fake Link-based UPI Payment Scam

  • Request to enter UPI PIN to receive money
  • Mysterious links or QR codes from unknown numbers
  • Urgent offers or large cashbacks
  • Payment links asking for confirmation outside official app

What To Do If You Encounter Fake Link-based UPI Payment Scam

  1. Report the scam immediately to the cybercrime helpline at 1930 or visit cybercrime.gov.in.
  2. Contact your bank's customer service (SBI: 1800-11-1109, HDFC: 1800-202-6161) to freeze any potentially compromised accounts.
  3. Change your UPI PIN and any other account passwords to secure your financial information.
  4. Examine your bank statements for any unauthorized transactions and dispute them promptly.
  5. Educate your family and friends about this scam to prevent further victimization in your community.
  6. Stay updated on the latest scams by following advisories from CERT-In or financial institutions.

How to Report Fake Link-based UPI Payment Scam in India

  • Call 1930 — National Cyber Crime Helpline (24x7)
  • File a complaint at cybercrime.gov.in
  • Contact your bank immediately if money was lost
  • Call RBI helpline: 14440 for banking fraud

Frequently Asked Questions

What to do if I shared my OTP in a UPI scam?
Immediately contact your bank's customer support hotline (SBI: 1800-11-1109, HDFC: 1800-202-6161) to secure your account. Report the incident to cybercrime at 1930 or cybercrime.gov.in.
How can I identify a fake link-based UPI payment scam?
Look for urgent offers, requests for your UPI PIN or OTP, and links from unknown senders. Legitimate companies will never ask for sensitive information via unsecured channels.
How should I report this type of scam in India?
You can report any incidents to the cybercrime helpline at 1930 or visit cybercrime.gov.in. Additionally, notify your bank immediately to block any unauthorized transactions.
What are the recovery steps after this scam?
Contact your bank right away to report the unauthorized transaction. They can help review your case and may initiate a fraud investigation to recover lost funds.

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.