Differences
This shows you the differences between two versions of the page.
| — | qr-code-scam-shops-temples-parking-events-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | metatag-keywords=(QR code scam India, fake QR sticker, merchant QR replaced, temple donation QR fraud, parking QR scam, event QR fraud, UPI scam 2026, verify QR before paying, BNS 318, NCRP 1930) | ||
| + | metatag-robots=(index, | ||
| + | metatag-og: | ||
| + | metatag-og: | ||
| + | metatag-og: | ||
| + | |||
| + | ====== QR Code Scam at Shops, Temples, Parking, Events: Verify First ====== | ||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP info> | ||
| + | **Quick answer (read this first).** Fraudsters paste fake QR stickers over real merchant codes at petrol pumps, temple hundis, parking exits, and event ticket counters; the money lands in a mule UPI ID, not the shop. Always tap the QR, read the payee name out loud, and pay only after the shopkeeper confirms the exact name on your screen. If something feels off, stop, refresh the QR, or pay cash. If you have already paid, dial 1930 and file at cybercrime.gov.in within 3 days for zero-liability protection under the RBI Customer Liability Circular (DBR.No.Leg.BC.78/ | ||
| + | </ | ||
| + | |||
| + | ===== What this scam actually looks like ===== | ||
| + | |||
| + | A QR code scam is a payment fraud where a stranger replaces or overlays the genuine merchant QR with their own, so your UPI payment goes to a mule account instead of the shop, temple, or parking operator. The fraud works because most of us never read the payee name on the screen, just type the amount and hit Pay. In India in 2026, the National Crime Records Bureau and state cyber cells together log thousands of these complaints every month, and the average loss is between ₹500 and ₹50,000, small enough that most people never bother to chase the money. | ||
| + | |||
| + | I learned this the painful way at a small temple in my own district. I scanned the QR taped on a tree near the donation box, paid ₹501, and walked away. Three weeks later the priest told me the temple had not received a single online donation in two months because someone had pasted a sticker over their real Bharat QR. By then the receiving account had been frozen by the bank, but my money was already gone. That is the day I started reading the payee name before every single payment, and I have not lost a rupee to a QR swap since. | ||
| + | |||
| + | This guide is the playbook I wish I had that evening. It covers six common variants of the scam, a 30-minute action plan if you have already paid, the evidence you must save in the first hour, the official complaint route through 1930 and NCRP, when to push the local police under the Bharatiya Nyaya Sanhita (BNS) 2024, a ready-to-use sample complaint, ten of the questions readers ask me most often, and the internal and external links you can verify yourself. | ||
| + | |||
| + | ===== Six variants you will actually see ===== | ||
| + | |||
| + | ==== 1. Pasted-over merchant QR at small shops and petrol pumps ==== | ||
| + | |||
| + | The cleanest version of the fraud. A scammer prints a sticker the same size as the merchant QR, walks in pretending to be a customer, and [[/ | ||
| + | |||
| + | ==== 2. Fake hundi QR at temples and religious events ==== | ||
| + | |||
| + | Donation QR codes are printed and stuck around the donation box, on pillars, on collection plates, even on flowers and prasad counters. Devotees in a hurry scan the closest one. A real temple QR is almost always a Bharat QR or a verified UPI ID printed by the trust on a laminated board with the temple seal. A loose sticker on a tree is a warning sign. | ||
| + | |||
| + | ==== 3. Parking-exit QR scam at malls and event venues ==== | ||
| + | |||
| + | The parking-fee scam works on speed. You roll up to the boom barrier, the attendant points at a printed QR, you pay, you leave. If a sticker has been pasted on top, the operator never sees the payment land, you get waved through anyway because the queue is honking, and the fraud is invisible until end-of-shift reconciliation. | ||
| + | |||
| + | ==== 4. Event ticket and counter-payment QR fraud ==== | ||
| + | |||
| + | Concerts, exhibitions, | ||
| + | |||
| + | ==== 5. Screenshot-payment fraud (the customer side of the same scam) ==== | ||
| + | |||
| + | Here the fraudster is the customer, not the merchant. They hand over a screenshot of a successful UPI payment, pocket the goods, and walk away before the shopkeeper checks the bank SMS. The screenshot is either edited or shows a payment to a different account. Small shopkeepers, | ||
| + | |||
| + | ==== 6. WhatsApp-forwarded QR for donations, refunds, or bookings ==== | ||
| + | |||
| + | [[/ | ||
| + | |||
| + | ===== Verify-before-you-pay checklist (60 seconds) ===== | ||
| + | |||
| + | - **Tap the QR, do not just scan-and-pay.** Every UPI app shows the payee name on the next screen. Read it. | ||
| + | - **Match the name to the shop or cause.** Petrol pump payee should be the pump dealer firm name. Temple payee should be the trust name. Parking payee should be the operator brand. Event payee should be the organiser. | ||
| + | - **Reject vague payee names** like " | ||
| + | - **Cross-check the UPI ID** if visible. A real petrol pump usually has a `@hdfcbank` or `@sbi` style handle tied to the dealer. A random `@ybl` or `@paytm` handle attached to a personal name at a fuel pump is suspicious. | ||
| + | - **Look for sticker tampering** | ||
| + | - **Ask the shopkeeper to confirm the name** you see on your screen before you press Pay. If they hesitate or shrug, pay cash. | ||
| + | - **Cap your first payment to a new merchant at ₹1.** If it lands in the right account, send the rest. Most UPI apps allow a ₹1 test. | ||
| + | - **For temples and donations, | ||
| + | - **For parking,** prefer the boom barrier' | ||
| + | - **Trust the small voice that says "this feels off" | ||
| + | |||
| + | ===== 30-minute emergency action plan (if you have already paid) ===== | ||
| + | |||
| + | The first 30 minutes after you realise the [[/ | ||
| + | |||
| + | ==== Minute 0 to 5 - Stop the bleed ==== | ||
| + | |||
| + | - Open your UPI app and check the transaction status. Note the **UTR or RRN number** (12-digit reference), the **payee VPA**, the **payee name shown**, the **amount**, and the **timestamp**. | ||
| + | - Take a screenshot of the success page. Then take a second screenshot of the bank SMS with the same UTR. | ||
| + | - Do not delete the UPI app, the SMS, or the screenshot, even if your first reflex is panic. | ||
| + | - If you used more than one bank account today, check all of them to confirm only this one transaction is affected. | ||
| + | |||
| + | ==== Minute 5 to 15 - Dial 1930 ==== | ||
| + | |||
| + | The Indian Cyber Crime Coordination Centre helpline is the fastest route to a bank-level freeze on the recipient account. | ||
| + | |||
| + | - Dial **1930** from the registered mobile number of the bank account that was debited. | ||
| + | - Have ready: the UTR, the amount, the payee VPA, the time of payment, the location where you scanned the QR, and a one-line description of the scam. | ||
| + | - The operator will create a complaint ID. **Write it down.** Without this number you cannot escalate later. | ||
| + | - Ask the operator to immediately flag the recipient VPA for a bank-level lien. | ||
| + | - Our [[1930-helpline-cyber-fraud-script]] page has the word-for-word script you can read out so you do not freeze under pressure. | ||
| + | |||
| + | ==== Minute 15 to 25 - File on NCRP ==== | ||
| + | |||
| + | - Open **cybercrime.gov.in**, | ||
| + | - Choose " | ||
| + | - Upload both screenshots, | ||
| + | - You will get an **acknowledgement number** by email and SMS. Save this carefully | ||
| + | |||
| + | ==== Minute 25 to 30 - Email your bank ==== | ||
| + | |||
| + | - Email the bank's official fraud-reporting address (printed on the back of every debit card and on the bank's website) with: customer ID, account number, UTR, amount, payee VPA, the 1930 complaint ID, and the NCRP acknowledgement. | ||
| + | - Subject line should literally read: **" | ||
| + | - Copy the bank's grievance officer and nodal officer. | ||
| + | - This email is your timestamped proof that you reported within the 3-day window of the **RBI Customer Liability Circular DBR.No.Leg.BC.78/ | ||
| + | - See [[golden-hour-zero-liability-cyber-fraud-rbi-india]] for the exact RBI language banks must honour. | ||
| + | |||
| + | ==== After minute 30 ==== | ||
| + | |||
| + | - Visit your bank branch within 24 hours and hand over a printed copy of the same email with a stamped acknowledgement. | ||
| + | - File a written complaint at the local police station or the nearest cyber cell if the loss is above ₹10,000 or if you want a formal FIR for insurance or employer reimbursement. | ||
| + | - For larger losses or repeat offenders, push for invocation of **BNS §318 (cheating)** and **§336 (forgery for purpose of cheating)** along with **IT Act §66C (identity theft)** and **§66D (cheating by personation through computer resource)**. | ||
| + | |||
| + | ===== Evidence checklist | ||
| + | |||
| + | - Screenshot of the UPI success page (showing UTR, payee name, payee VPA, amount, time) | ||
| + | - Screenshot of the bank SMS for the same UTR | ||
| + | - Photo of the QR sticker at the location, ideally with the surrounding signage in the frame | ||
| + | - Photo of the shop, temple board, parking gate, or event counter for context | ||
| + | - 1930 complaint ID (SMS or call-end screenshot) | ||
| + | - NCRP acknowledgement number (PDF download from the portal) | ||
| + | - Email to bank fraud-reporting address with delivery receipt | ||
| + | - Bank branch acknowledgement stamp on the printed email | ||
| + | - Police or cyber-cell DD entry number, or FIR copy if registered | ||
| + | - Reply from the bank within 90 days under RBI grievance rules | ||
| + | |||
| + | ===== Official complaint route at a glance ===== | ||
| + | |||
| + | |< 100% 30% 35% 35% >| | ||
| + | ^ Step ^ Where ^ Use it when ^ | ||
| + | | 1 | UPI app raise dispute | First 24 hours, small amount, payee may have refunded | | ||
| + | | 2 | 1930 helpline | First 30 minutes, you need a bank-level account freeze | | ||
| + | | 3 | cybercrime.gov.in NCRP | Same day, for the formal record and acknowledgement number | | ||
| + | | 4 | Bank fraud-reporting email | Within 3 days for RBI zero-liability protection | | ||
| + | | 5 | Bank branch visit | Within 7 days with printed complaint and acknowledgements | | ||
| + | | 6 | Local police or cyber cell | If loss > ₹10,000 or pattern of repeat fraud at same location | | ||
| + | | 7 | Banking Ombudsman (RBI-IOS 2021) | If bank fails to respond in 30 days | | ||
| + | | 8 | Consumer Commission (e-Daakhil) | If deficiency of service is provable and bank refuses chargeback | | ||
| + | | 9 | RTI to bank, NPCI, RBI | When you need recipient account details for civil recovery | | ||
| + | |||
| + | ===== When you must escalate to police or cyber cell ===== | ||
| + | |||
| + | The 1930 + NCRP route handles most QR-swap losses. But you should push for a formal **police FIR** under the following conditions: | ||
| + | |||
| + | - Loss is above ₹10,000 and you want an insurance claim, an employer reimbursement, | ||
| + | - The QR sticker is still on site and could be lifted as physical evidence. | ||
| + | - Multiple victims have reported the same location (collective complaint is far more powerful). | ||
| + | - The fraud involved impersonation of a real merchant, a temple trust, or a government counter | ||
| + | - The receiving account turns out to be a mule pattern (multiple beneficiaries, | ||
| + | - The shop or venue refuses to remove the fake sticker after you flag it - that is consent or negligence on their part and a separate consumer cause of action. | ||
| + | |||
| + | For BNS sections, the relevant clauses in 2024+ FIRs are: **§318 (cheating)**, | ||
| + | |||
| + | ===== Sample complaint (copy, fill, send) ===== | ||
| + | |||
| + | You can paste the block below into the NCRP free-text field, into the bank fraud-report email, and into a printed letter for the police station. Replace bracketed placeholders with your details. | ||
| + | |||
| + | < | ||
| + | To | ||
| + | The Station House Officer | ||
| + | [Police station name] | ||
| + | [District, State, PIN] | ||
| + | |||
| + | Subject: Complaint against fraudulent QR code payment of ₹[amount] | ||
| + | on [date] at [location] | ||
| + | and §336 read with IT Act §66C and §66D. | ||
| + | |||
| + | Sir or Madam, | ||
| + | |||
| + | 1. My name is [Name], aged [age], resident of [full address], | ||
| + | | ||
| + | |||
| + | 2. On [date] at approximately [time] I made a UPI payment of | ||
| + | | ||
| + | | ||
| + | |||
| + | 3. The payment success page showed the payee name as | ||
| + | " | ||
| + | | ||
| + | a screenshot. | ||
| + | |||
| + | 4. The legitimate merchant or operator at the location has | ||
| + | since confirmed in writing or in person that the displayed | ||
| + | QR is not theirs and they have not received the payment. | ||
| + | A photograph of the location and the disputed QR is | ||
| + | | ||
| + | |||
| + | 5. The QR sticker was placed in a manner intended to impersonate | ||
| + | the genuine merchant and to deceive customers, which | ||
| + | | ||
| + | of cheating under BNS §336, identity theft under IT Act §66C, | ||
| + | and cheating by personation through a computer resource | ||
| + | under IT Act §66D. | ||
| + | |||
| + | 6. I have lodged National Cyber Crime helpline 1930 complaint | ||
| + | ID [number] on [date and time] and NCRP acknowledgement | ||
| + | | ||
| + | | ||
| + | | ||
| + | |||
| + | 7. I request that an FIR be registered under BNSS §173 and that | ||
| + | the investigating officer obtain KYC details of the recipient | ||
| + | UPI ID from the relevant Payment System Provider via NPCI, | ||
| + | and seize the disputed QR sticker from the location as | ||
| + | | ||
| + | |||
| + | 8. I am ready to give a formal statement, identify the location, | ||
| + | and produce all supporting documents. | ||
| + | |||
| + | Yours faithfully, | ||
| + | [Signature] | ||
| + | [Name] | ||
| + | [Date and place] | ||
| + | |||
| + | Enclosures: | ||
| + | a) UPI success page screenshot | ||
| + | b) Bank SMS screenshot | ||
| + | c) Photograph of QR location | ||
| + | d) 1930 complaint ID screenshot | ||
| + | e) NCRP acknowledgement PDF | ||
| + | f) Email to bank with delivery receipt | ||
| + | </ | ||
| + | |||
| + | ===== Real-life example ===== | ||
| + | |||
| + | <WRAP center round box 90%> | ||
| + | **Donor at a Pune temple, March 2026.** A devotee scanned what looked like the official Bharat QR taped near the hundi and paid ₹501 to "Shree Trust Donations" | ||
| + | </ | ||
| + | |||
| + | ===== Cross-platform UPI rules you can quote at the bank ===== | ||
| + | |||
| + | - **NPCI UPI dispute window**: customer can raise a chargeback through the issuing bank within **T+3 working days** for credit-not-received and within **T+45 days** for unauthorised transactions. | ||
| + | - **RBI Customer Liability Circular DBR.No.Leg.BC.78/ | ||
| + | - **NPCI' | ||
| + | - **RBI grievance redressal**: | ||
| + | - **Consumer Protection Act 2019**: deficiency of service by the bank or the payment app is actionable at the District Consumer Disputes Redressal Commission via the e-Daakhil portal. | ||
| + | |||
| + | For the chargeback mechanics on cards and UPI, see our standalone guide [[cyber-fraud-chargeback-visa-mastercard-rupay-india]]. For the bank-side lien rules and how to lift a freeze on your own account if it is mistakenly held, see [[bank-freeze-cyber-fraud-india]] and [[suspicious-transaction-bank-account-hold-india]]. | ||
| + | |||
| + | ===== Common mistakes that kill your case ===== | ||
| + | |||
| + | - Deleting the UPI app, the SMS, or the screenshot in panic. Without the UTR you have no case. | ||
| + | - Calling the bank's general customer-care number instead of the **fraud-reporting** line; the routing is different and the timestamp matters. | ||
| + | - Filing NCRP first and dialling 1930 second. The freeze comes faster through 1930. | ||
| + | - Forgetting to write down the **1930 complaint ID** at the end of the call. | ||
| + | - Reporting after 3 working days and losing the RBI zero-liability protection. | ||
| + | - Filing under wrong sections; old IPC §420 references in a 2024+ FIR will be rejected | ||
| + | - Skipping the bank branch visit. The stamped paper acknowledgement is your evidence in any later consumer or ombudsman case. | ||
| + | - Not photographing the fake sticker. If the venue removes it before police arrive, you lose physical evidence. | ||
| + | - Believing the WhatsApp message that says "send ₹1 to verify and we will credit ₹10, | ||
| + | - Paying again to a " | ||
| + | |||
| + | ===== Who is liable when - quick liability map ===== | ||
| + | |||
| + | |< 100% 25% 25% 25% 25% >| | ||
| + | ^ Scenario ^ Customer ^ Bank ^ Merchant ^ | ||
| + | | Pasted-over QR at petrol pump, customer reported in 3 days | Zero | Refund under RBI circular | Possible negligence claim | | ||
| + | | Customer used unverified WhatsApp-forwarded QR | Limited under contributory negligence | Best-effort chargeback | None | | ||
| + | | Temple sticker swap, victim reported within 30 minutes | Zero | Full refund + lien on mule | Temple trust may file separate FIR | | ||
| + | | Customer paid with screenshot of fake successful payment to shop | Customer is the fraudster | Bank investigates source | Shop is victim | | ||
| + | | Bank ignored 3-day window | Zero | Full liability + RBI penalty | Not in scope | | ||
| + | |||
| + | ===== FAQ ===== | ||
| + | |||
| + | ==== How do I tell a fake QR sticker from a real one before I pay? ==== | ||
| + | |||
| + | Tap the QR before you press Pay, and read the **payee name** on the next screen. Match it to the shop, temple, parking operator, or event organiser. If the name is generic (" | ||
| + | |||
| + | ==== What is the very first thing to do if I have already paid a fake QR? ==== | ||
| + | |||
| + | Save the screenshot of the success page and the bank SMS, dial **1930** within minutes, and write down the complaint ID. Then file on **cybercrime.gov.in** and email your bank's fraud-reporting address the same hour. The first 30 minutes are when banks can still place a lien on the recipient mule account. | ||
| + | |||
| + | ==== Is my bank really going to refund me? ==== | ||
| + | |||
| + | Yes if you have reported within **3 working days** of the unauthorised debit, under the **RBI Customer Liability Circular DBR.No.Leg.BC.78/ | ||
| + | |||
| + | ==== Which sections of law apply to a QR-sticker fraud in 2026? ==== | ||
| + | |||
| + | For offences after 1 July 2024, India uses the **Bharatiya Nyaya Sanhita (BNS) 2024**. The relevant sections are **§318 (cheating)** and **§336 (forgery for purpose of cheating)**, | ||
| + | |||
| + | ==== What if the police refuse to register an FIR? ==== | ||
| + | |||
| + | Under **BNSS §173**, for any cognisable offence the SHO must register a zero-FIR if the offence happened in another jurisdiction or a regular FIR if local. If refused, escalate in writing to the **Superintendent of Police (SP)** under BNSS §173(4), and if still refused, file a complaint to the **Magistrate** under BNSS §175. Most cyber fraud cases above ₹10,000 are cognisable and the FIR cannot be lawfully refused. | ||
| + | |||
| + | ==== Can I get the fraudster' | ||
| + | |||
| + | You cannot get the recipient' | ||
| + | |||
| + | ==== What if a small shopkeeper hands me back a screenshot and says payment is done? ==== | ||
| + | |||
| + | This is the customer-side variant of the same scam. As a shopkeeper, **never accept a screenshot as proof**; the only proof is the bank SMS or the in-app notification on your own phone. If you have lost goods this way, the route is identical: 1930, NCRP, bank email, and police FIR under BNS §318 plus IT Act §66D. | ||
| + | |||
| + | ==== How do I check whether a parking QR is real before paying? ==== | ||
| + | |||
| + | Look for a printed boom-barrier plate with the operator' | ||
| + | |||
| + | ==== Can I claim from insurance for a QR-fraud loss? ==== | ||
| + | |||
| + | Some bank-linked debit-card insurance covers unauthorised UPI losses up to a sub-limit (commonly ₹50,000 to ₹2 lakh). You need the FIR copy, the 1930 complaint ID, the NCRP acknowledgement, | ||
| + | |||
| + | ==== I keep falling for QR scams, what is the pattern to break? ==== | ||
| + | |||
| + | Three habits, drilled once a week for a month: (1) always tap the QR and read the payee name out loud, (2) cap every new merchant payment at ₹1 first, (3) install **Sanchar Saathi Chakshu** and the **NCRP Suspect Repository** lookup, and check any new UPI VPA against the database before you pay it. The pattern that gets people into trouble is the rush - the queue, the phone call, the WhatsApp forward. Slowing down for the 60 seconds it takes to verify is the entire defence. | ||
| + | |||
| + | ===== Sources and external references ===== | ||
| + | |||
| + | - **National Cyber Crime Reporting Portal (NCRP)** | ||
| + | - **Cyber Crime Helpline 1930** | ||
| + | - **RBI Customer Liability Circular DBR.No.Leg.BC.78/ | ||
| + | - **RBI Integrated Ombudsman Scheme 2021 (RBI-IOS 2021)** | ||
| + | - **NPCI UPI Dispute Redressal Mechanism (URCS)** | ||
| + | - **Sanchar Saathi Chakshu** | ||
| + | - **Information Technology Act 2000** | ||
| + | - **Bharatiya Nyaya Sanhita 2024** | ||
| + | - **Bharatiya Nagarik Suraksha Sanhita 2024** | ||
| + | - **Consumer Protection Act 2019** and the **e-Daakhil portal** for consumer commissions | ||
| + | - **Prevention of Money Laundering Act 2002** | ||
| + | |||
| + | ===== Related guides on this wiki ===== | ||
| + | |||
| + | - [[upi-deducted-not-received-action-plan-india]] | ||
| + | - [[recover-money-upi-fraud-2026]] | ||
| + | - [[1930-helpline-cyber-fraud-script]] | ||
| + | - [[golden-hour-zero-liability-cyber-fraud-rbi-india]] | ||
| + | - [[bank-freeze-cyber-fraud-india]] | ||
| + | - [[cyber-fraud-chargeback-visa-mastercard-rupay-india]] | ||
| + | - [[ncrp-acknowledgement-bank-lien-decoder-india]] | ||
| + | - [[cyber-fraud-rti-bundle-rbi-npci-bank-india]] | ||
| + | - [[qr-sticker-fraud-on-shops-and-petrol-pumps-india]] | ||
| + | - [[qr-code-scam-recovery]] | ||
| + | - [[suspicious-transaction-bank-account-hold-india]] | ||
| + | - [[citizen-rti-playbook]] | ||
| + | - [[middle-class-traps]] | ||
| + | |||
| + | ===== Hero image prompt ===== | ||
| + | |||
| + | //For the social card at / | ||
| + | |||
| + | ===== Disclaimer ===== | ||
| + | |||
| + | This article is general guidance for Indian citizens and is not legal advice. Statutes and circulars cited are current as of 2026-05-16. For loss above ₹1, | ||
| + | |||
| + | {{tag> | ||