🏹 Happy Dussehra — victory of good over evil!

QR Code and Payment Link Fraud: How It Works and How Banks Stop It

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 17 August 2026 · Updated 01 Oct 2026 · 10 min read · 52 views
QR Code and Payment Link Fraud: How It Works and How Banks Stop It

Almost every complaint that lands at a bank's fraud desk starts the same way: "I only scanned a QR code" or "I just clicked a link to get my refund." That single sentence is the whole story of QR code and payment link fraud — the most common cyber crime pattern hitting Indian bank customers today. The victim believes they are receiving money; in reality, scanning a QR code or approving a UPI collect request always authorises an outward debit, never an inward credit. Understanding that one mechanical fact, and the scripts fraudsters wrap around it, is core exam material under the Prevention of Cyber Crime paper and core protection knowledge for any banker handling grievances.

📲 The Core Deception: Why Scanning Never Pays You

UPI has one unbreakable rule: money moves out of an account only when the holder authenticates a debit with their UPI PIN. A QR code is nothing but an encoded payment address — scanning it can only ever open a "pay" screen, never a "receive" screen. This is the single fact that exposes QR code and payment link fraud the moment a customer understands it. If you are meant to be receiving a refund, cashback, or sale proceeds, no PIN entry should ever be required.

A UPI collect request works the same way. The fraudster, posing as a buyer or refund agent, sends a collect request disguised as money being sent to the victim, with wording like "approve to receive ₹X." A genuine credit never asks for PIN approval — an app asking "enter UPI PIN to proceed" is always initiating an outward payment, whatever language sits above the button. Malicious payment links add a second layer: some lead to a spoofed payment page that harvests card and OTP details, others prompt installation of a screen-sharing app disguised as a "refund utility," after which the fraudster operates the victim's own banking app directly. See the chapter on Computer Hackers for how such remote-access techniques are built.

Diagram showing UPI QR code scan always triggers a debit authorisation, never a credit
Diagram showing UPI QR code scan always triggers a debit authorisation, never a credit

🎭 The Classic Scripts Behind Every Scam

Almost all QR code and payment link fraud cases fit a small set of repeating scripts, and recognising the script is faster than analysing each transaction on its own merits.

The fake buyer script targets sellers on classifieds and resale marketplaces. A "buyer" claims to have sent an advance and sends a QR code or collect request "to confirm the payment," insisting the seller scan or approve it to release funds — instead paying the fraudster. The refund or cashback lure follows failed transactions or fake festive offers, asking the victim to enter a PIN to "release" a stuck refund. The rental and job-advance scam asks a prospective tenant or applicant to pay a token booking amount through a link, often followed by a second "refundable deposit" QR code. The fake charity or parking-fine sticker scam pastes a QR sticker over a genuine donation box or municipal notice, redirecting scanned payments to a personal UPI handle.

⚠️ Common Mistake: Customers assume that because they initiated the scan, the transaction must be safe. The initiating action is irrelevant — only the PIN-entry screen tells you whether money is leaving or entering the account.

Cross-reference these scripts against the broader taxonomy in Channels Of Cyber Crimes, which classifies how each channel — social, marketplace, telecom, physical — is exploited.

Illustration of the fake buyer, refund lure, rental advance and fake charity QR scam scripts
Illustration of the fake buyer, refund lure, rental advance and fake charity QR scam scripts

🏪 Tampered Merchant Codes and Spoofed Payment Pages

At physical shops, fraudsters increasingly paste a duplicate sticker over a genuine merchant's printed QR code, or hand over a portable second code claiming the display code is "not working." Customers who skip the merchant-name confirmation screen that UPI apps show before PIN entry are the ones who fall for it — that name-match step exists precisely to catch a tampered or overlaid code.

Online, a spoofed payment page recreates a bank's or gateway's exact look to capture card number, expiry, CVV and OTP on a form with no real connection to the merchant's processor. Some links instead push an APK disguised as a payment-completion step that installs a remote-access trojan, letting the fraudster transact directly from the victim's device. Related detection techniques sit in the Computer Fraud Protection chapter. Practical guidance is simple: read the payee name before entering a PIN, never install an app from an unknown "support" link, and treat any "scan to receive" instruction as a red flag.

Comparison of a genuine merchant QR code against a tampered overlay sticker
Comparison of a genuine merchant QR code against a tampered overlay sticker

🛡️ How Banks Detect and Contain the Damage

Because QR code and payment link fraud relies on the victim self-authenticating a debit, prevention depends heavily on controls that surround the transaction. Real-time transaction alerts give the customer a narrow window to spot and report a debit before funds move onward. Per-transaction and daily UPI limits cap the loss from a single approved collect request, and a beneficiary cooling period — a mandatory delay before large payments to a newly added payee become active — blocks the fast first-hour cash-out fraud rings depend on.

On the bank's side, mule-account and velocity analytics scan for the signature of fraud proceeds: a personal account suddenly receiving many small credits from unrelated senders, followed by rapid onward transfer. Flagging such accounts quickly is often the only realistic way to recover funds once such a transaction has cleared, since UPI settlement is near-instant and irreversible at the rail level. Banks also correlate device IDs and beneficiary VPA reuse across complaints, feeding results into workflows described in Incident Management.

ControlWhat It DoesStops the Scam?
Real-time transaction alertsNotifies customer instantly of a debit✅ Early detection
Per-transaction UPI limitsCaps loss from one approved request✅ Limits damage
Beneficiary cooling periodDelays large payment to a new payee✅ Slows cash-out
Mule-account velocity analyticsFlags accounts receiving rapid small credits✅ Enables freeze
Scanning without checking the payee nameBypasses the one safeguard UPI apps provide❌ Defeats every control

These layered defences are exactly why exam questions on QR code and payment link fraud frequently pair a technical control with a customer-behaviour failure — both halves are tested together.

📞 The Customer's Route: Reporting and Liability

A customer who has fallen for this kind of fraud should call the 1930 national cyber crime helpline immediately and file a complaint on the National Cyber Crime Reporting Portal, since both feed directly into the fund-freeze workflow banks run with payment intermediaries — speed is the single biggest determinant of recovery.

On liability, the applicable framework is RBI's directions on limiting customer liability in unauthorised electronic banking transactions, which set out zero, limited, or full liability depending on whether the loss stems from a bank-side deficiency, a genuine third-party breach reported promptly, or delayed reporting. Because a QR-scan or link-based transaction is technically authenticated by the customer's own PIN, banks must assess each case against the circular's timelines rather than treating self-authenticated debits as automatically the customer's fault.

💡 Exam Tip: Remember the sequence — helpline first for the golden-hour freeze window, portal complaint for the formal record, then the bank's liability assessment under the RBI framework.

Bankers should also stay alert to Electronic Card Frauds, since spoofed payment pages often harvest card data alongside UPI credentials in the same campaign.

🧠 Practice MCQs: QR Code and Payment Link Fraud

Q1. A customer receives a UPI notification asking them to enter their PIN to "receive" a payment from a marketplace buyer. What does this indicate? (a) A genuine credit is being processed (b) The request is actually a collect request that will debit the account (c) The bank is verifying the customer's identity (d) No PIN is ever required for UPI transactions

Answer: (b) — Entering a UPI PIN always authorises an outward debit; a genuine credit never requires PIN approval.

Q2. Which control most directly slows a fraudster's ability to cash out funds immediately after a large payment to a newly added payee? (a) Real-time SMS alerts (b) Beneficiary cooling period (c) Mule-account velocity analytics (d) Two-factor login

Answer: (b) — A cooling period delays activation of large payments to a newly added beneficiary, buying time to detect and block fraud.

Q3. At a physical shop, what is the most reliable safeguard against a tampered or overlaid merchant QR code? (a) Checking the sticker looks new (b) Verifying the payee name shown before entering the PIN (c) Asking for a cash discount instead (d) Scanning twice to confirm the amount

Answer: (b) — UPI apps display the actual payee name before PIN entry; verifying it catches a tampered code even if the sticker looks genuine.

Q4. A bank's fraud analytics team notices a personal savings account receiving numerous small credits from unrelated senders followed by rapid onward transfers. This pattern is most indicative of what? (a) Salary crediting delays (b) A mule account laundering scam proceeds (c) A merchant settlement account (d) A joint family account

Answer: (b) — Rapid, unrelated small credits followed by quick withdrawal or transfer is the classic velocity signature of a mule account.

Q5. What should a victim of QR code and payment link fraud do first, before filing a detailed written complaint? (a) Wait 30 days to see if the amount is auto-refunded (b) Call the 1930 cyber crime helpline immediately (c) Change their UPI PIN only (d) Contact the fraudster to request a reversal

Answer: (b) — Calling 1930 immediately triggers the fund-freeze workflow with banks and payment intermediaries within the golden hour, which is critical for recovery.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Can scanning a QR code alone ever credit money to my account?

No. A QR code only encodes a payment address; completing any transaction from it, including entering a PIN, always initiates a debit from your account, never a credit.

Why does a UPI collect request sometimes look like it is sending me money?

Fraudsters word the notification to sound like an incoming payment, but the underlying action is a collect request. Approving it with your PIN authorises the requester to debit your account.

What is the fastest way to report QR code and payment link fraud?

Call the 1930 national cyber crime helpline immediately and follow up with a complaint on the National Cyber Crime Reporting Portal so banks can attempt to freeze the funds before they are withdrawn.

Am I always liable if I scanned the code or clicked the link myself?

Not automatically. Liability is assessed under RBI's framework for unauthorised electronic transactions, which considers how promptly you reported the incident and whether the loss involved a bank-side or third-party deficiency.

✅ Conclusion: Make the Pull-Not-Push Rule Second Nature

Every variant of QR code and payment link fraud — the fake buyer, the refund lure, the rental advance, the fake charity sticker, the tampered merchant code, or the spoofed payment link — collapses under one question: does this action authenticate a debit or a credit? Bankers who can explain that distinction clearly, alongside the alerts, limits, cooling periods, and mule-detection controls behind it, are equipped to prevent losses and guide customers through the 1930 helpline, portal complaint, and liability process when prevention fails. For related fraud typologies, revisit SIM swap fraud in banking, swift payment fraud controls, and preventing business email compromise fraud, and for the broader IT-security roadmap see post-quantum readiness in banks. Browse more chapters in Prevention of Cyber Crime, and test your readiness now: take a free mock test →

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading