UPI Auto-Debit and Mandate Fraud
Verdict: Suspicious | Risk Score: 8/10 | Severity: high
Category: UPI
How UPI Auto-Debit and Mandate Fraud Works
Overview: UPI auto-debit and mandate fraud is a growing trick where scammers exploit the convenience of recurring payment features in Indian fintech apps. By deceiving users into authorizing auto-debits, fraudsters siphon funds periodically, often without immediate detection. The danger is compounded by the seamless nature of UPI, which processes transactions instantly and silently in the background. How It Works: 1. Scammer sends what seems like a genuine link or app notification to set up a 'mandate' for bill payment, subscription, or fake cashback offers. 2. Victim clicks and is prompted within the UPI app to approve an auto-debit request, often under the guise of verifying identity or activating a reward. 3. Once approved, scammers can repeatedly debit small or large sums at regular intervals. 4. These recurring withdrawals may go unnoticed for days or weeks, rapidly draining your account. India Angle: Auto-debit features are heavily marketed in India for subscription services and utility payments and are rapidly growing across all fintech platforms. This scam mainly targets urban professionals and students, especially those who manage multiple UPI mandates for streaming or ed-tech apps. It is prevalent in metro cities and IT hubs. Real Examples: - "Dear user, to receive ₹500 reward, kindly authorize the UPI mandate in your app." - "PTM care: Confirm mandate update for uninterrupted cashback benefits." Red Flags: - Unfamiliar or unexplained UPI mandate requests - Sudden auto-debit setup notifications from UPI apps - Messages promising rewards for mandate authorisation - Small, unexplained deductions from your account Protective Measures: - Review every mandate request within the UPI app carefully before approval. - Regularly monitor your bank/UPI statement for recurring transactions. - Revoke mandates from unused or suspicious services immediately within the app. - Enable in-app security such as PIN and biometric checks for mandates. If Victimised: - Immediately revoke the fraudulent mandate via your UPI app. - Contact your bank’s helpline and 1930 cybercrime hotline. - Visit cybercrime.gov.in and lodge a complaint with all transaction details. Related Scams: - Fake app updates seeking UPI access - Fraudulent online subscription renewal calls
How This Scam Works — Detailed Explanation
UPI Auto-Debit and Mandate Fraud is a scheme that has been gaining traction across India, primarily leveraging the ease of transactions that UPI (Unified Payments Interface) offers. Scammers initiate contact often through platforms like WhatsApp, SMS, or even social media. They pose as legitimate businesses or service providers, claiming that they need authorization for a recurring payment or an upgrade to a service that the victim already avails. By luring users with enticing offers and attractive discounts, scammers are able to capture the attention of unsuspecting individuals who might be inclined to authorize an auto-debit without verifying the source adequately.
The tactics employed by these fraudsters are particularly cunning. They utilize social engineering techniques that exploit the natural inclination of users to trust communications that seem official. For instance, they may create messages that mimic a bank’s notification or an app update from an increasingly recognized fintech service. They invoke feelings of urgency, claiming limited-time offers that require immediate action. Users might be tricked into clicking on a seemingly genuine link that prompts them to authorize an auto-debit without reading the fine print, leading them into the trap that these fraudsters have set.
Once a victim has been lulled into providing authorization, the debilitating consequences begin to unfold. A common scenario involves the victim noticing an unexpected small debit from their account that seems harmless at first — for instance, a ₹1 or ₹10 transaction. As these transactions go unnoticed over time, the scammer continues to siphon larger amounts periodically. Victims often come to realize they've been tricked only when they notice several small deductions leading to a significant sum lost over time. A real-life case involved a victim who lost around ₹2 lakh over three months through various small debits labeled under false services in their UPI app, initially advertised as winning rewards through mandate approval from a dubious platform.
The financial hit from UPI Auto-Debit and Mandate Fraud can be sizeable. Reports suggest that in 2022 alone, more than ₹500 crore was siphoned off from unsuspecting individuals through similar scams, according to a Ministry of Home Affairs (MHA) report. With the rapid growth of digital payments in India, the Reserve Bank of India (RBI) and CERT-In have issued multiple advisories urging citizens to be cautious about sharing sensitive information, especially concerning auto-debit authorizations that come without clear explanations. Such advisories are crucial for raising awareness about these fraudulent practices.
To differentiate between legitimate communications and scams, users should scrutinize messages that ask for approvals related to auto-debits. If a notification lacks clear information, doesn’t originate from a known source, or is tied to offers that sound too good to be true, it should raise red flags. Always review recent transactions in your UPI app for any unfamiliar debits and report any suspicious activity immediately. Remember, a genuine service provider will always allow you to review and revoke your mandate with ease.
Visual Intelligence:
BharatSecure's AI has identified this as a used in scams targeting Indian users.
Who Does UPI Auto-Debit and Mandate Fraud Target?
General public across India
Red Flags — How to Identify UPI Auto-Debit and Mandate Fraud
- Requests to approve auto-debit without clear reason
- Unfamiliar mandates in UPI app
- Unexpected small value debits
- Notifications about rewards tied to mandate authorisation
What To Do If You Encounter UPI Auto-Debit and Mandate Fraud
- Report suspicious UPI transactions immediately by calling 1930 or visiting cybercrime.gov.in.
- Contact your bank's helpline, such as SBI at 1800-11-1109 or HDFC at 1800-202-6161, to block further transactions.
- Review your UPI app for any unfamiliar auto-debits and revoke them if applicable.
- Change your UPI PIN and other banking passwords to secure your account.
- Educate yourself about authorized auto-debit processes from reliable bank sources.
- Monitor your bank statements regularly for unauthorized transactions.
How to Report UPI Auto-Debit and Mandate Fraud in India
- Call 1930 — National Cyber Crime Helpline (24x7)
- File a complaint at cybercrime.gov.in
- Contact your bank immediately if money was lost
- Call RBI helpline: 14440 for banking fraud
Frequently Asked Questions
- What to do if I approved a fraudulent UPI auto-debit?
- Immediately report the issue to your bank helpline and call 1930. They can assist in reversing the transactions if appropriate.
- How do I identify UPI auto-debit fraud?
- Look for unexplained or unfamiliar charges in your UPI section and be wary of any communication requesting auto-debit approvals without prior consent.
- How can I report UPI auto-debit fraud in India?
- You can report by calling 1930 for cybercrime or filing complaints on cybercrime.gov.in and simultaneously alerting your bank.
- What steps can I take to protect my account after fraud?
- Change your UPI PIN and passwords, review your transaction history, and monitor for unusual activity regularly.
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.