education
How Scammers Exploit UPI Collect Requests: Mechanics and Protection Guide
Learn how scammers exploit UPI collect requests and intent hijacking to deceive buyers and merchants, and discover essential architectural defenses to protect users.
Among the various cyber fraud techniques documented across India, the UPI Collect Request scam remains one of the most prolific. Fraud syndicates exploit social engineering and cognitive bias to reverse transaction flows, turning what the victim believed was an incoming payment into a disastrous outward debit.
Whether you run an online store processing customer refunds or sell goods on consumer marketplaces, understanding how collect requests are weaponized is critical for protecting both your brand and your customers.
The Anatomy of a UPI Collect Request Scam
In the original NPCI UPI 1.0 specification, two transaction models were introduced:
- Push Transaction (Pay): The customer initiates a payment to a merchant’s VPA or scans a QR code.
- Pull Transaction (Collect): The merchant initiates a request specifying the customer’s UPI handle, triggering a push notification on the customer’s phone requesting approval.
The Fraudulent Collect Attack Workflow:
┌─────────────────────────────────────────────────────────────┐
│ 1. Contact: Fraudster poses as buyer, customer support, │
│ or bank executive promising an instant refund. │
│ │ │
│ 2. Payload: Fraudster triggers a ₹15,000 Collect Request │
│ with note: "REFUND_APPROVED_CLICK_TO_CREDIT" │
│ │ │
│ 3. Social Engineering: Fraudster urges victim: │
│ "Open Google Pay, accept the request, and enter PIN." │
│ │ │
│ 4. Execution: Victim enters UPI PIN. Bank debits ₹15,000 │
│ from the victim and immediately credits the scammer. │
└─────────────────────────────────────────────────────────────┘
By customizing the transaction note (tn) with misleading text such as "Payment Received from Indian Army" or "Tax Refund Approved", scammers deceive unsuspecting users into believing they are authorizing a deposit.
The Golden Rule: UPI PIN is Only for Sending Money
Every merchant, customer support agent, and consumer must memorize this foundational architectural rule of Indian banking:
┌──────────────────────────────────────────────────────────────────┐
│ THE FUNDAMENTAL UPI RULE │
├──────────────────────────────────────────────────────────────────┤
│ ENTERING A UPI PIN = MONEY LEAVES YOUR BANK ACCOUNT │
│ RECEIVING MONEY = ZERO ACTION / ZERO PIN REQUIRED │
└──────────────────────────────────────────────────────────────────┘
Whenever money is deposited into your bank account via UPI, the transaction is processed via the NPCI clearing switch as a Direct Credit (Push). Funds arrive automatically, and you will receive an SMS from your bank. You do not need to “accept”, “unlock”, or “authenticate” incoming money.
Intent Hijacking and Spoofed Push Notifications
Beyond simple social engineering, sophisticated scammers also deploy technical exploits:
- App Hijacking via Accessibility Services: Malicious APKs installed via fake courier tracking links read the screen and automatically tap the “Approve” button on incoming collect requests.
- Phishing Refund Webpages: Scammers create clone landing pages of popular D2C brands. When a customer attempts to track a lost package, the page asks for their UPI ID and immediately fires a collect request for the order amount under the guise of “Order Confirmation”.
Why Modern Gateways Have Deprecated Collect Requests
In earlier years, e-commerce checkouts offered an option: “Enter your UPI ID (e.g., user@okhdfcbank) and click Pay”. The gateway would fire a collect request, and the customer would have to open their phone, find the notification, and approve it.
This workflow has been largely phased out by tier-1 brands due to two major flaws:
- Abysmal Conversion Rates: Over 35% of collect requests fail because notifications get delayed, muted, or buried by OS battery optimization.
- Severe Fraud Association: Because scammers used collect requests to trick consumers, users developed deep mistrust toward unexpected collect popups.
Instead, modern payment infrastructure has shifted entirely toward Dynamic QR Codes on desktop and UPI Intent Deep Linking on mobile browsers.
LEGACY (Collect Request):
Desktop Web ──► User enters UPI ID ──► Collect API ──► Phone Notification (35% Drop-off + Fraud Risk)
MODERN (Dynamic QR / Intent):
Desktop Web ──► Instant Dynamic QR ──► Customer Scans with Camera ──► Direct Push Payment (98% Success)
Merchant and Customer Protection Runbook
If your brand operates an online store or customer support desk, implement these defensive controls:
- Adopt Dynamic QR Codes: Deprecate legacy “Enter UPI ID” input fields at checkout. Replace them with instant Dynamic QR codes generated by platforms like VyaparGateway.
- Add In-App Anti-Fraud Warnings: If your customer support team handles cancellations, display a permanent banner in customer portals: “Our team will never send a collect request or ask for your UPI PIN to process a refund.”
- Never Refund via P2P Channels: Always process customer refunds directly back through the original payment reference (RRN/UTR) using automated bank payout APIs, rather than sending manual transfers to phone numbers provided in support chats.
Direct answers
Frequently asked questions
- Do you ever need to enter your UPI PIN to receive money?
- Never. Under the UPI architecture, receiving or accepting incoming funds never requires entering a UPI PIN. A UPI PIN is strictly used to authenticate debit instructions from your bank account.
- What is a UPI Collect Request?
- A Collect Request (P2P Pull) is an API mechanism where a payee asks a payer for money by sending a notification to their UPI app. When the payer approves the notification and enters their UPI PIN, the funds are debited from the payer's account and sent to the requester.
- Why do OLX and marketplace sellers get targeted by collect scams?
- Scammers pose as enthusiastic buyers, agree to pay an advance, and then send a Collect Request disguised as an approval request, telling the seller: 'Click approve and enter your PIN to claim the advance payment.'
Build your payment flow
Explore the API and browser-only merchant tools.
Create UPI checkout orders, verify signed events, or test the free calculators and generators without exposing credentials.