QR Code Fraud in India: What to Watch Out For
A grounded look at qr code fraud india — the real RBI-reported numbers, the scam patterns that actually occur here, how to report fraud on the 1930 helpline, and what businesses must do to protect their own codes.
What the Real Numbers Say
QR code fraud in India generates a lot of alarming headlines and relatively little reliable data, so it is worth starting with what is actually reported.
The Reserve Bank of India's Annual Report for 2024-25 recorded 11,615 fraud cases in the banking system involving ₹3,497 crore, down sharply from 35,530 cases and ₹5,856 crore the previous year. Within that total, card and internet frauds accounted for 66.8% of cases by number — 7,756 incidents — but only 7.2% of the value, at ₹252 crore.
That shape tells you what qr code fraud india actually looks like on the ground: very high frequency, very low average value. These are large numbers of small, opportunistic scams aimed at individual consumers and small merchants, not a handful of sophisticated technical breaches. The average card-or-internet fraud case in that data works out to roughly ₹3 lakh, and the typical QR-specific incident most people experience is far smaller than that — a few hundred or a few thousand rupees.
That matters for how you defend against it. The defence is not technical sophistication. It is a handful of habits applied consistently.
The Sticker Swap: India's Most Common QR Fraud
The dominant pattern involves no technology at all. A fraudster prints a QR sticker and pastes it over a merchant's genuine payment code — at a kirana counter, a petrol pump, a parking attendant's board, a street-food stall, a parked auto.
The customer scans in good faith, pays, and shows the merchant a successful transaction screen. The merchant, busy, glances at it and waves them on. The money went to the fraudster. Often nobody realises until the merchant reconciles the day's takings and finds a shortfall — by which point several customers have paid and left.
What makes this effective is that everything about the situation is legitimate except the sticker. The shop is real, the merchant is real, the transaction genuinely completes. There is nothing suspicious to notice unless you specifically look at the payee name on your own screen, or the merchant specifically checks their own code.
This is why the two most valuable habits in the whole subject are: customers read the payee name before confirming, and merchants inspect their own codes regularly. Our guide to identifying a fake QR code covers the physical tells in detail.
The "Scan to Receive Money" Trap
This deserves its own section because it is both extremely common and completely avoidable with one rule.
UPI has no scan-to-receive mechanism. Scanning a QR code can only ever initiate a payment from your account. It cannot bring money in. Any code presented as a way to receive a refund, claim a prize, collect a cashback, get a returned deposit, or accept payment from a buyer is fraudulent by construction — not sometimes, not usually, always.
The common presentations:
- The classifieds buyer. On a marketplace app, a "buyer" of your used item sends a QR code claiming it will transfer the payment to you. Often they will send a small amount first to build trust, then send a code for the larger "transfer" which actually debits you.
- The refund scam. A caller from a "customer care" number says your refund needs a QR scan to process.
- The prize or cashback claim. A code in an SMS or on a scratch card, framed as claiming winnings.
- The collect request. Not a QR at all but the same family — a UPI collect request disguised as an incoming payment, which you approve with your PIN and thereby send money.
The rule is simple and has no exceptions: you never enter your UPI PIN to receive money. If a screen is asking for your PIN, money is leaving your account.
Other Patterns Seen in India
Beyond the two dominant ones:
- Fake parking and challan notices. A printed slip under a windscreen wiper with a QR code for "immediate payment" of a fine, leading to a convincing fake payment page.
- Delivery redelivery fees. A code on a package slip or an SMS claiming a failed delivery needs a small fee and card details to reschedule.
- KYC expiry. A code in an SMS or a printed bank notice claiming your KYC needs re-verification, leading to a credential-harvesting page that replicates your bank's login.
- Fake charity and donation codes. Particularly around festivals and disasters, when genuine donation QR codes are also widespread and the fake ones blend in.
- Job and loan application codes. A code leading to a page that collects Aadhaar, PAN and bank details under the pretext of an application.
- Compromised merchant displays. Less common but more damaging: a QR code on a genuine printed standee replaced during production or distribution, before it ever reaches the merchant.
The common thread through all of them is that the QR code is only the delivery mechanism. The actual attack is the page or the payment request behind it, and the actual defence is reading what is in front of you before you act.
How to Report QR Fraud in India
If you have been defrauded, speed materially affects the outcome — funds can sometimes be held or reversed if the report reaches the bank before the money is withdrawn onward.
- Call the national cyber-fraud helpline, 1930. This is the Government of India's dedicated number for financial cyber fraud, and it exists specifically to trigger a rapid hold on transferred funds. Call it first, before anything else.
- File on the National Cyber Crime Reporting Portal at cybercrime.gov.in. This creates a formal complaint record, which you will need for any bank dispute.
- Contact your bank or payment provider through their official app or a published number. Never a number shown on the suspicious page, in the SMS, or given to you by whoever contacted you — fake "customer care" numbers are themselves a major scam category in India.
- Keep evidence. Screenshots of the transaction, the page, the SMS, the UPI reference number, and a photograph of the physical code if there was one.
- Report the physical code. Tell the merchant, and if it was on public infrastructure — a parking board, a municipal notice — report it to the relevant authority so it can be removed.
Do this even for small amounts. Individual reports are what let authorities identify the accounts and patterns behind large numbers of small frauds.
What Merchants Must Do
Merchants are the overlooked victims in QR fraud. A swapped sticker costs them the sale, the goods, and a customer's trust — and they usually find out last.
Practical, low-cost defences:
- Check your own code every morning. Make it part of opening the shop. Photograph the correct state and keep it where staff can compare.
- Mount it so it cannot be covered cleanly. Under acrylic, in a frame, laminated, or printed directly onto a rigid board rather than applied as a sticker.
- Display your business name on and around the code, so a plain replacement sticker looks visibly wrong.
- Confirm the payee name, not just the "payment successful" screen. Train staff to actually look at what the customer shows them. A fraudulent payment shows a successful screen too — the payee name is the only distinguishing detail.
- Cross-check against your own app. The definitive confirmation is a credit notification in your own UPI app, not a screen on the customer's phone.
For marketing QR codes specifically, the same discipline applies with a different consequence: a swapped marketing code sends your customers to someone else's page, under your brand. Inspect high-traffic placements, and use a branded short domain (Premium plan, ₹14,999/month) so the URL preview itself verifies you. Our UPI QR code guide for India covers the payment side in more depth.
Why Dynamic Codes Help on the Business Side
Fraud defence for a business publishing QR codes has a component that static codes simply cannot provide.
If a marketing code is compromised — a destination page defaced, a domain expired and re-registered by someone else, a campaign link repurposed maliciously — a dynamic code lets you repoint it instantly from the dashboard. Every printed copy already in the market starts going somewhere safe within seconds. With a static code, the destination is in the pattern and the only remedy is recalling and reprinting material that may be on ten thousand cartons.
The second benefit is visibility. Dynamic codes generate scan analytics, and anomalies in that data are frequently the first observable sign that something is wrong — a sudden volume spike, scans from a geography your campaign never reached, activity on a code that should be dormant. A static code tells you nothing until a customer complains.
Neither of these stops a fraudster pasting a sticker over your code — nothing does except physical inspection. But they do mean that when something goes wrong with a code you control, you can act in minutes rather than in print cycles.
Create your QR code on SMLLR, check your physical placements regularly, and make sure your customers know where your codes are meant to go.
Frequently Asked Questions
How common is QR code fraud in India?
The RBI's Annual Report for 2024-25 recorded 11,615 fraud cases in the banking system involving ₹3,497 crore, down from 35,530 cases and ₹5,856 crore the previous year. Card and internet frauds were 66.8% of cases by number — 7,756 incidents — but only 7.2% of the value, at ₹252 crore: very high frequency, very low average value.
What is the most common QR code scam in India?
The sticker swap. A fraudster pastes a fake QR sticker over a merchant's genuine payment code at a counter, petrol pump or parking board. The customer pays in good faith, the transaction completes successfully, and the money reaches the fraudster — often unnoticed until the merchant reconciles the day's takings.
Can someone take money from my account by getting me to scan a QR code?
Only if you then approve a payment with your UPI PIN. Scanning alone transfers nothing. The rule with no exceptions is that you never enter your UPI PIN to receive money — if a screen is asking for your PIN, money is leaving your account, not arriving.
Is scan-to-receive a real UPI feature?
No. UPI has no scan-to-receive mechanism — scanning a code can only initiate a payment from your account. Any code presented as a way to get a refund, claim a prize, collect cashback or accept payment from a buyer is fraudulent by construction, always.
How do I report QR code fraud in India?
Call the national cyber-fraud helpline 1930 first — it exists specifically to trigger a rapid hold on transferred funds. Then file on the National Cyber Crime Reporting Portal at cybercrime.gov.in, and contact your bank through their official app or a published number, never a number shown on the suspicious page.
How can a shop protect its payment QR code from being swapped?
Check it every morning as part of opening, and keep a photograph of the correct state for staff to compare against. Mount it under acrylic, in a frame, or printed directly onto a rigid board so a sticker cannot be applied cleanly, and confirm payments against a credit notification in your own UPI app rather than the screen on a customer's phone.
Do dynamic QR codes reduce fraud risk?
For a business publishing codes, partly. A dynamic code can be repointed instantly from the dashboard if a destination is ever compromised, and its scan analytics often show an anomaly before anyone complains. Neither stops someone physically pasting a sticker over your code — only inspection does that.