As UPI transactions reached 24.5 billion in August 2026, risks from digital scams are rising. Users must distinguish between sending and receiving money to prevent unauthorized account debits. Understanding RBI reporting rules and the specific mechanics of QR codes and collect requests is essential to mitigate financial loss in the digital economy.
The Unified Payments Interface (UPI) has established itself as the primary mode of retail payment in India, with transaction volumes crossing 24.5 billion in August 2026. While the platform offers unmatched convenience, its ubiquity has attracted sophisticated fraudulent activities that exploit human error during routine financial interactions. Maintaining account security now requires an active verification process for every digital interaction.
The QR Code Security Rule
A persistent misconception among users is the function of QR codes. Many assume that scanning a QR code is a method to receive money, such as a refund or a prize. In reality, the act of scanning a QR code followed by entering a UPI PIN authorizes a debit from the user's bank account. If an unknown entity sends a QR code under the guise of processing a refund or a transfer, it is typically a scam designed to drain funds. A critical point for users is that UPI PINs are only required when authorizing a payment, never when receiving funds into an account.
Understanding Collect Request Risks
Fraudsters often manipulate users via 'collect requests.' This tactic involves sending a digital request that prompts the victim to 'approve' a transaction. While the victim may believe they are accepting an incoming payment, they are actually initiating a debit. The notification screen typically displays details indicating the user is sending money, not receiving it. Careful scrutiny of the screen text before confirming with a PIN serves as a primary defense against this method. Furthermore, legitimate service agents or bank representatives will never request a UPI PIN to resolve complaints or facilitate transactions. Keeping credentials confidential is the most effective safeguard against such social engineering.
Reporting and Liability Framework
If an unauthorized transaction occurs, the timing of the report significantly influences the potential liability. The Reserve Bank of India (RBI) mandates that reporting suspicious activity within three working days of the transaction can limit customer liability in cases of third-party breaches. However, if the user voluntarily shares sensitive credentials like a UPI PIN, the protection framework may not apply, potentially leaving the customer liable for the entire loss. In the event of an incident, users should immediately engage with official banking channels and their specific UPI application to flag the activity. Additionally, the Ministry of Home Affairs operates the 1930 national cybercrime helpline for reporting financial fraud, which serves as an important resource for victims seeking to initiate an investigation.
