THE SHORT ANSWER

Before paying, check whether you expected the request, whether the amount or destination changed, and whether urgency is being created. Confirm the requester and payment details through a known channel. Use an independent approver for high-consequence payments.

Verify the request before the payment instrument

  • Did I expect this request and this amount?
  • Has the bank account, UPI ID, QR code or payment method changed?
  • Is the sender discouraging a callback or second approval?
  • Can I confirm the destination with a known contact?

A valid-looking invoice or payment screen shows what will be authorized. It does not prove the underlying business request is legitimate.

Evidence & context: Federal Bureau of Investigation

UPI and QR codes: understand what you are authorizing

NPCI states that scanning a QR code and entering a UPI PIN is used to make a payment, not receive one. Read the app's action and recipient carefully, and never share a PIN or OTP. Features change, so follow current instructions in the official payment app and your bank.

Evidence & context: National Payments Corporation of India

Use controls that do not depend on one inbox

  • Known-channel callback for new or changed payment details
  • Two-person approval above a proportionate threshold
  • Restricted vendor master-data changes
  • A record of who confirmed what, when and through which channel

Controls should be workable enough that staff use them even when work is busy.

If money may have moved incorrectly, act promptly

Contact the bank or payment provider through its official channel, secure affected accounts and preserve transaction records. In India, consult the current National Cyber Crime Reporting Portal and its financial-fraud instructions. No action guarantees recovery.

Evidence & context: Reserve Bank of India

Sources & further reading

  1. Fraud Awareness

    National Payments Corporation of India. Official Indian payment-safety guidance covering QR codes, payment authorization, suspicious links and other common warning signs. Product interfaces and reporting routes can change, so users should verify current instructions in their bank or payment app.

  2. Business Email Compromise

    Federal Bureau of Investigation. Official defensive guidance explaining BEC and recommending independent verification when account numbers or payment procedures change. Reporting routes are United States-specific.

  3. Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions

    Reserve Bank of India. RBI directions on bank reporting channels and response to unauthorised electronic transactions. Rights and timelines depend on the facts and current rules; this module does not provide legal or recovery advice.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗