Cyber Crime • UPI • Merchant QR • Wrong Beneficiary • Digital Evidence
Merchant QR Replacement: Customer Paid, but the Shop Did Not Receive It — Was the Merchant’s UPI QR Sticker Replaced?
The customer's phone says “Payment Successful”. The merchant's account shows no credit. Before assuming a UPI technical failure, examine a simpler attack: was the merchant's physical QR sticker replaced with another person's VPA? A proper investigation connects the physical QR, app-displayed beneficiary, UPI transaction reference, merchant bank records, CCTV and beneficiary-account trail before deciding who is responsible for the loss.
Current legal and technical review: 20 August 2026
Direct Answer
Yes. If a customer's UPI payment shows successful but the shop genuinely received nothing, one possibility is that the physical merchant QR was replaced or covered by a QR linked to another UPI ID.
But do not diagnose QR replacement merely from the merchant's statement.
Immediately compare:
- the beneficiary name and VPA shown in the customer's transaction history;
- the merchant's genuine UPI ID;
- the QR physically displayed at the counter;
- the merchant's receiving-app / bank statement;
- the transaction reference or RRN;
- CCTV covering the QR display.
PAYMENT SUCCESSFUL
DOES NOT ALWAYS MEAN
THE INTENDED MERCHANT WAS PAID.
A substituted QR can cause a technically successful, customer-authorised UPI transaction to reach the wrong beneficiary.
The central forensic question is:
WHICH VPA DID THE CUSTOMER ACTUALLY AUTHORISE?
Quick Navigation
- How QR replacement works
- First 10-minute triage
- The three-name verification test
- Successful wrong-payee vs failed transaction
- Preserving the physical QR sticker
- CCTV and electronic evidence
- Transaction IDs, VPA and beneficiary tracing
- Merchant-side controls
- Customer-side verification
- Fake screenshot vs genuine payment
- 1930, NCRP and bank reporting
- Criminal-law provisions
- Recovery from wrong beneficiary
- Who bears the loss?
- Bank / PSP / acquirer liability
- RBI Ombudsman 2026
- Forensic audit matrix
- FAQs
How a Merchant QR Replacement Fraud Works
The attack may require no hacking at all.
The QR points to a VPA/account controlled by the fraudster or a mule.
A sticker may be pasted directly over the merchant's genuine QR or the entire display stand may be substituted.
The payment application reads the substituted destination.
The customer enters the UPI PIN believing the payment is going to the shop.
The account encoded in the substituted QR receives the money.
The merchant may discover the problem only after several transactions have been redirected.
The security paradox
Everything in the digital payment flow may work correctly.
The deception happened before the payment instruction entered the network.
That makes this:
A PHYSICAL IDENTITY-SUBSTITUTION ATTACK AT A DIGITAL PAYMENT ENDPOINT.
The First 10 Minutes: What Customer and Merchant Should Do
Customer
- Open the original UPI app transaction history.
- Do not rely only on a gallery screenshot.
- Record the beneficiary name.
- Record the UPI ID/VPA.
- Record transaction number / reference / RRN.
- Record exact time and amount.
- Preserve the bank debit SMS.
Merchant
- Check the actual bank/acquiring application.
- Confirm that payment is absent.
- Photograph the QR in place.
- Inspect edges and sticker layers.
- Do not destroy a suspected fake QR.
- Secure CCTV immediately.
- Locate the merchant's original issued QR/VPA.
Both
Compare:
PAID VPA
with
MERCHANT VPA.
If they differ, stop using the displayed QR and report the suspected fraud immediately.
The Three-Name Test
| Identity Layer | Question |
|---|---|
| Shop identity | What business is the customer standing in? |
| Legitimate merchant QR | What merchant name and UPI ID were issued/onboarded for that shop? |
| Payer app beneficiary | What name/VPA did the payer's app resolve before payment? |
Example 1 — likely normal
SHOP: Raj Medical Hall
APP: Rajesh Kumar
UPI ID: rajmedical@bank
A sole-proprietorship business may legitimately settle into an account in the proprietor's legal name.
Example 2 — high-risk mismatch
SHOP: Raj Medical Hall
APP: XYZ Gaming Services
UPI ID: randomperson123@upi
That mismatch requires immediate verification before PIN entry.
Successful Wrong-Payee Payment vs Failed UPI Transaction
These are legally and technically different cases.
| Scenario | What Happened? | Primary Investigation |
|---|---|---|
| Correct merchant QR; payer debited; merchant not credited | Possible failed/pending/reconciliation issue. | UPI status, bank/acquirer settlement, reversal rules. |
| Fraudulent QR; fraudster credited | Successful payment to unintended beneficiary. | Beneficiary tracing, fraud report, recovery. |
| Correct merchant credited but merchant app notification absent | Confirmation/display problem. | Bank statement and merchant reconciliation. |
| No real payer debit | Possible fake screenshot. | Payer transaction history and merchant records. |
NPCI's failed-transaction mechanisms should not automatically be invoked merely because the intended shop did not receive the money.
If the substituted QR's beneficiary received it, the payment rail may have succeeded exactly as instructed.
Preserve the QR Sticker as Physical Evidence
A common merchant reaction is:
“Remove this fake sticker immediately.”
Stopping further payments is essential.
Destroying the evidence is not.
Before removal
- photograph full counter;
- photograph QR position;
- take close-up front photograph;
- photograph edges;
- take side-angle photographs showing layers;
- record date and time;
- record who discovered it;
- identify persons who handled it.
After controlled removal
Preserve, where practicable:
- suspected fraudulent layer;
- underlying legitimate layer;
- QR stand;
- packaging or adhesive remnants;
- printed UPI ID;
- issue date;
- merchant/acquirer branding;
- any handwriting or markings.
The material should ideally be handled through a proper police seizure/documentation process where a criminal complaint has been initiated.
CCTV Is Often the Bridge Between the Sticker and the Offender
The QR tells investigators:
WHERE THE MONEY WENT.
CCTV may help show:
WHO ALTERED THE PAYMENT DESTINATION.
Preserve more than a WhatsApp clip
Secure:
- original DVR/NVR;
- relevant channel numbers;
- full time window;
- system clock offset;
- export format;
- hash where created;
- Section 63 BSA certificate as applicable;
- chain of custody.
Search the wider movement
The suspect may appear on:
- counter CCTV;
- shop entrance camera;
- adjacent business camera;
- parking camera;
- mall/common-area camera;
- petrol-pump surveillance;
- road camera where lawfully obtainable.
For current proceedings, Sections 61-63 of the Bharatiya Sakshya Adhiniyam provide the framework for electronic/digital records.
Transaction IDs, VPA and Beneficiary Tracing
A proper complaint should not merely say:
“₹7,500 went to the wrong QR.”
Record:
| Field | Entry |
|---|---|
| Payment date | ___ |
| Exact time | ___ |
| Amount | ___ |
| Payer bank | ___ |
| Payer UPI app | ___ |
| Payer VPA | ___ |
| Beneficiary name | ___ |
| Beneficiary VPA | ___ |
| Transaction ID | ___ |
| RRN / reference | ___ |
| Merchant genuine VPA | ___ |
| Displayed QR VPA | ___ |
The transaction reference is the forensic join key
It can connect:
PAYER → UPI TRANSACTION → BENEFICIARY PSP → BENEFICIARY BANK → ACCOUNT → KYC → ONWARD FLOW.
NPCI's complaint interface itself requires transaction-reference/RRN information for payment queries and routes complaints to the relevant participating institution.
Merchant-Side Controls: The Shop Must Protect the Physical Payment Endpoint
Opening check
Before business begins:
- inspect the QR;
- compare merchant name;
- compare UPI ID;
- check issuance/branding information where applicable;
- test with a controlled small payment if necessary.
During business
- keep QR within staff visibility;
- avoid unattended external stickers;
- verify merchant-side payment receipt;
- do not rely only on customer's screenshot;
- investigate repeated soundbox/app silence.
At shift change
Inspect again, particularly at:
- petrol pumps;
- restaurants;
- large retail counters;
- pharmacies;
- high-footfall stalls;
- 24-hour establishments.
At closing
Reconcile:
SALES vs UPI CREDITS vs CASH vs CARD.
A QR replacement remaining unnoticed for three days is far more damaging than one identified after the first mismatched payment.
Customer-Side Control: Read the Payee Before Entering the UPI PIN
NPCI explains that QR merchant information is displayed to the customer after scanning.
RBI has also recognised beneficiary-name verification as an existing feature of UPI.
The four-second rule
Before PIN:
- read beneficiary name;
- look at UPI ID where available;
- compare with merchant/trade identity;
- ask if anything looks unrelated.
Do not normalise an obvious mismatch
A customer standing in:
SUNRISE PHARMACY
should not casually approve a payment to:
ONLINE GAMING SERVICES
without asking why.
But legitimate names can differ
A merchant operated as a proprietorship may display its owner's bank-account name.
The rule is not:
EXACT STRING MATCH OR FRAUD.
The rule is:
VERIFY AN UNEXPECTED BENEFICIARY.
Do Not Confuse QR Replacement With Fake Payment-Screenshot Fraud
Merchant says:
“I did not receive it.”
Customer shows:
“SUCCESS.”
That still does not establish a real transaction.
Check the source
Ask the customer to open:
- UPI application;
- transaction history;
- actual transaction details.
Then check merchant side
- merchant receiving app;
- bank account;
- acquiring interface;
- transaction lookup.
A screenshot is easy to:
- edit;
- reuse;
- simulate;
- generate from fake-payment applications.
Report the Fraud Immediately: Bank + 1930 + NCRP
Once wrong-beneficiary fraud is suspected, speed matters because the money may be transferred onward rapidly.
Customer should notify
- payer bank;
- UPI application / PSP complaint channel;
- National Cybercrime Helpline 1930;
- National Cyber Crime Reporting Portal.
Merchant should also preserve and report
- genuine merchant VPA;
- fraudulent displayed VPA;
- all affected customer transactions;
- CCTV;
- physical QR;
- acquirer details.
Joint reporting can be stronger
The customer proves:
DEBIT AND WRONG BENEFICIARY.
The merchant proves:
NON-RECEIPT AND QR TAMPERING.
Together they can establish a far clearer initial fraud picture than blaming each other at the counter.
Government's CFCFRMS system is specifically intended for immediate reporting of financial cyber fraud and coordination to stop siphoning of funds.
Which Criminal-Law Provisions May Apply?
For post-1 July 2024 incidents, the Bharatiya Nyaya Sanhita should be examined rather than mechanically citing the IPC.
BNS Section 318 — Cheating
This is a central provision where deception fraudulently or dishonestly induces a person to deliver property.
A fraudulent QR can operate as the deceptive mechanism that induces the payer to deliver money to the wrong person.
BNS Section 319 — Cheating by personation
Potentially applicable where the fraudster represents himself or his payment identity as the merchant or another person.
Whether the QR alone satisfies the exact ingredients should be tested on facts rather than assumed.
Forgery provisions
Sections 335, 336 and 340 BNS may require examination where false documents/electronic records are actually made or used.
But:
EVERY REPLACED QR IS NOT AUTOMATICALLY A FORGED DOCUMENT CASE.
Apply the statutory ingredients.
IT Act Section 66D
Cheating by personation through a communication device or computer resource may be relevant depending upon the digital-personation mechanism.
IT Act Section 66C
Identity-theft provisions require dishonest/fraudulent use of another person's password, electronic signature or other unique identification feature.
If the fraudster simply uses his own VPA and pastes it over another merchant's code, Section 66C should not be added mechanically without identifying the protected identity feature actually misused.
Recovery From the Wrong Beneficiary
The financial investigation should move quickly from:
QR
to:
VPA
to:
BANK ACCOUNT.
Section 72 of the Indian Contract Act
Section 72 provides that a person to whom money has been paid by mistake or under coercion must repay or return it.
This can support restitutionary analysis against the unintended recipient.
But recovery is operationally time-sensitive
The beneficiary may immediately:
- transfer funds to another account;
- split the amount;
- withdraw cash;
- convert value;
- route it through a mule network.
That is why legal rights after six months are not a substitute for freezing/intervention in the first hours.
Customer vs Merchant: Who Bears the Loss?
There is no universal rule for QR-replacement cases.
| Fact | Who It May Favour | Why |
|---|---|---|
| Fraudulent QR prominently displayed at merchant's controlled counter | Customer argument strengthens | Customer may argue reasonable reliance on payment destination held out at merchant premises. |
| Customer's app displayed an obviously unrelated beneficiary | Merchant argument strengthens | Customer had a meaningful verification signal before authorisation. |
| Merchant personally told customer “scan this QR” | Customer argument strengthens | Direct representation concerning payment channel. |
| Customer scanned another shop's QR by mistake | Merchant argument strengthens | Less evidence that merchant represented that destination. |
| Merchant handed over goods after checking customer's success screen but not own receipt | Fact-sensitive | Merchant confirmation practice becomes relevant. |
| Merchant had received earlier complaints that QR beneficiary was wrong and did nothing | Customer argument strengthens | Knowledge and failure to act become important. |
| Fraudulent sticker was professionally overlaid moments before payment | Merchant negligence argument weaker | Reasonable inspection opportunity may have been limited. |
The ultimate wrongdoer remains central
Customer and merchant should not lose sight of the person who:
DELIBERATELY SUBSTITUTED THE PAYMENT DESTINATION.
Immediate joint recovery action may be economically more useful than an immediate customer-v-merchant confrontation.
When Can the Bank, PSP, Acquirer or Payment Ecosystem Be Responsible?
UPI contains multiple actors.
If the system correctly paid the encoded VPA
A physical sticker replacement does not automatically prove:
BANK NEGLIGENCE or NPCI FAILURE.
The payer may have authenticated exactly the instruction the substituted QR generated.
Potential ecosystem issues arise if evidence shows
- incorrect merchant QR issued by the acquirer;
- merchant mapping error;
- beneficiary display failure contrary to applicable system design;
- system processing error;
- successful correct-merchant payment not credited;
- unreasonable complaint-handling deficiency;
- other breach of applicable RBI/NPCI obligations.
Merchant-acquirer responsibilities matter
NPCI has placed obligations on UPI acquirers regarding offline merchant QR deployment and compliance with standardised QR-brand guidelines.
But those obligations should not automatically be converted into strict liability for an unknown criminal physically placing a sticker over a genuine QR.
Unauthorised Transaction Rules: Use Them Carefully
RBI's customer-protection framework for electronic banking transactions deals with unauthorised transactions and allocates liability according to bank deficiency, third-party breach, customer negligence and reporting time.
But a common QR-swap case involves the customer personally:
- scanning the code;
- entering the amount;
- entering the UPI PIN;
- authorising the transfer.
The deception lies in:
THE IDENTITY OF THE PAYEE.
Therefore:
FRAUDULENT PAYMENT
≠
AUTOMATICALLY AN
“UNAUTHORISED TRANSACTION”
The classification must be determined before relying on zero-liability provisions.
RBI Ombudsman Route in 2026
The Reserve Bank – Integrated Ombudsman Scheme, 2026 came into effect on 1 July 2026.
It provides a cost-free mechanism for complaints alleging deficiency in service by covered Regulated Entities.
First complain to the Regulated Entity
A complainant must first approach the concerned bank or other covered entity.
Subject to the Scheme, escalation to the RBI Ombudsman can occur where:
- no reply is received within the applicable period; or
- the complainant is dissatisfied with the reply/resolution.
The 2026 FAQ generally refers to 30 days or the longer applicable RBI/NPCI/Card Network timeline where relevant.
Use the correct remedy for the correct problem
RBI OMBUDSMAN:
deficiency in banking/payment service.
1930 / NCRP / POLICE:
criminal fraud and fund interception.
CIVIL / RESTITUTIONARY REMEDY:
recovery and underlying customer/merchant/payment disputes where required.
Master Merchant-QR Replacement Forensic Audit
| Evidence Field | Entry |
|---|---|
| Shop name | ___ |
| Merchant legal name | ___ |
| Merchant genuine VPA | ___ |
| Merchant acquirer | ___ |
| Original QR issue date | ___ |
| Suspicious QR physically present? | ___ |
| Sticker overlay visible? | ___ |
| VPA encoded by suspicious QR | ___ |
| Beneficiary name displayed to payer | ___ |
| Transaction ID | ___ |
| RRN/reference | ___ |
| Amount | ___ |
| Exact time | ___ |
| Payer bank debit confirmed? | ___ |
| Fraudulent beneficiary credit confirmed? | ___ |
| Merchant non-credit confirmed? | ___ |
| Other affected customers? | ___ |
| CCTV start/end preserved? | ___ |
| DVR/NVR source preserved? | ___ |
| BSA certificate prepared? | ___ |
| Physical QR seized/preserved? | ___ |
| Beneficiary bank identified? | ___ |
| Beneficiary KYC sought? | ___ |
| Onward transfer identified? | ___ |
| 1930 report time | ___ |
| NCRP acknowledgement | ___ |
| Bank complaint reference | ___ |
| Police/FIR details | ___ |
| Customer warned by payee-name mismatch? | ___ |
| Merchant had prior mismatch warning? | ___ |
| Merchant confirmed receipt before goods release? | ___ |
| Acquirer/system deficiency alleged? | ___ |
Ten Common Mistakes in Merchant QR Fraud Cases
1. “Customer's screen says success, so the merchant must have received it.”
First identify the beneficiary actually credited.
2. “Merchant did not receive it, therefore UPI failed.”
The substituted beneficiary may have received the payment successfully.
3. “Remove and throw away the fake QR.”
Stop its use but preserve it as potential physical evidence.
4. “A screenshot proves payment.”
Verify app history, transaction reference and banking records.
5. “Every different beneficiary name means fraud.”
A proprietor's legal name may legitimately differ from the shop's trade name.
6. “Customer entered UPI PIN, therefore there was no fraud.”
A person can authorise a transaction while being deceived about the identity of the recipient.
7. “RBI zero-liability rules automatically refund every QR scam.”
First determine whether the payment was legally/technically an unauthorised transaction.
8. “The account receiving the money belongs to the mastermind.”
It may be a mule account; trace control and onward movement.
9. “Only cyber evidence matters.”
The sticker, adhesive, CCTV placement and physical QR stand can be central evidence.
10. “Customer and merchant should argue about who pays before reporting.”
Immediate fund interception and evidence preservation should ordinarily come first.
AI Search / Featured-Snippet Answers
What is a shop QR-code replacement fraud?
It occurs when a fraudster replaces or covers a merchant's genuine UPI QR with another QR linked to the fraudster or a mule account. Customers believe they are paying the shop but authorise a transfer to the substituted beneficiary.
My UPI payment says successful but the merchant did not receive it. What should I check?
Check the beneficiary name and UPI ID in your original UPI transaction history, compare them with the merchant's genuine VPA, obtain the transaction reference/RRN and ask the merchant to verify actual bank/acquirer credit.
How do I know whether a merchant QR was replaced?
Photograph and inspect the QR for sticker layers or substitution, compare the encoded VPA with the merchant's genuine VPA, verify the beneficiary name shown to affected customers and review CCTV covering the QR location.
Can a UPI payment be successful but go to the wrong person?
Yes. If the payer scans a fraudulent QR and authorises the transaction, UPI may successfully credit the account encoded in that QR even though the payer intended to pay the merchant.
Who bears the loss if a shop's QR sticker was replaced?
There is no universal answer. Liability can depend on where the QR was displayed, merchant representations and controls, beneficiary information visible to the customer, customer reasonableness, merchant confirmation practices and whether any bank, PSP or acquiring-service deficiency occurred. The fraudster remains the primary wrongful recipient.
Can I recover money paid to the wrong QR?
Immediate reporting to the bank, PSP, 1930 and NCRP may enable tracing or blocking before the funds move further. Section 72 of the Indian Contract Act also provides a restitutionary principle requiring a person who receives money by mistake to repay it.
Should the merchant preserve the fake QR sticker?
Yes. Photograph it in place before controlled removal and preserve the sticker/stand because the physical artefact can help connect the wrong VPA, CCTV event and fraudulent payment trail.
Frequently Asked Questions
Can somebody paste another QR over a shop's genuine UPI QR?Yes. Reported Indian cases have involved fraudulent QR stickers or QR displays replacing genuine merchant codes.
Does QR replacement require hacking the merchant's bank?No. The fraud can occur entirely through physical substitution of the payment destination.
What does a merchant QR contain?NPCI describes QR integration as storing merchant information including the merchant UPI ID so that merchant information appears on the customer's payment page.
Should customers check the beneficiary name?Yes. UPI provides beneficiary information before authorisation. An unexpected recipient should be verified before entering the PIN.
What if the app displays the proprietor's personal name instead of the shop name?That can be legitimate for a proprietorship. Name differences should be assessed contextually rather than mechanically treated as fraud.
Is the payment failed if the shop did not receive it?Not necessarily. If another beneficiary encoded in the fraudulent QR received the funds, the transaction may be technically successful but directed to the wrong payee.
Can the payer cancel a successful UPI transfer?NPCI's FAQ states that once a UPI payment is initiated it cannot be stopped. Fraudulent wrong-beneficiary cases therefore require complaint, tracing and recovery action.
What is the most important transaction detail?The transaction reference/RRN together with the beneficiary VPA, beneficiary name, amount and exact time creates a strong tracing package.
Can the shop rely on the customer's screenshot?It should independently verify the merchant-side receiving app or bank credit, particularly where the transaction is disputed.
Should CCTV be exported immediately?Yes. Many systems overwrite footage automatically. Preserve the relevant original/source data and evidentiary metadata promptly.
Which evidence law applies to current CCTV?The Bharatiya Sakshya Adhiniyam, 2023 applies to current proceedings, with Sections 61-63 addressing electronic/digital evidence.
Can the customer file a cybercrime complaint?Yes. Wrong-beneficiary UPI fraud should be reported promptly through the relevant financial institution and India's cyber-financial-fraud reporting mechanisms.
What is 1930?1930 is the national cybercrime helpline used for assistance in reporting cyber financial fraud.
Can the merchant also complain?Yes. The merchant is important because it can prove the genuine VPA, non-receipt, physical substitution and CCTV evidence.
Is BNS Section 318 relevant?Potentially yes. It covers cheating where deception dishonestly or fraudulently induces delivery of property. Exact charging depends on facts.
Does IT Act Section 66D always apply?No. It may apply where cheating by personation is carried out through a communication device or computer resource, but its ingredients should be established rather than added automatically.
Is IT Act Section 66C automatically applicable to every QR swap?No. Section 66C requires dishonest or fraudulent use of another person's specified identity credentials/features. A fraudster using his own VPA may require a different legal analysis.
Who should refund the customer?No universal rule answers that question. The fraudster's wrongful receipt, customer reasonableness, merchant control of the displayed QR and any payment-service deficiency must all be examined.
Can the wrong beneficiary be required to return the money?Section 72 of the Indian Contract Act states that a person who receives money by mistake or under coercion must repay it, subject to the facts and appropriate legal process.
Does RBI zero-liability protection automatically apply?No. That framework concerns unauthorised electronic transactions. A customer-authenticated QR payment induced by deception may require a different classification.
Can I complain to RBI Ombudsman?If there is an alleged deficiency in service by a covered regulated entity, the Reserve Bank – Integrated Ombudsman Scheme, 2026 may provide a route after first approaching that entity and satisfying the Scheme's timing and maintainability requirements.
What is the strongest prevention method for shops?Protect and inspect the physical QR, display merchant name/VPA clearly, use merchant-side payment confirmation, reconcile regularly and investigate any beneficiary mismatch immediately.
Official and Research Sources
- NPCI — UPI Frequently Asked Questions
- NPCI — UPI Circulars
- NPCI — Transaction Complaint Facility
- Reserve Bank of India
- RBI Complaint Management System
- National Cyber Crime Reporting Portal
- India Code — Bharatiya Nyaya Sanhita, 2023
- India Code — Bharatiya Sakshya Adhiniyam, 2023
- India Code — Information Technology Act, 2000
- India Code — Indian Contract Act, 1872
Related Detailed Research
- From Cyber Police FIR to Enforcement Directorate: How a Cyber-Fraud Case Can Develop Into a PMLA Investigation
- Foreign Remittances, Overseas Companies and Alleged Fund Layering Under PMLA
Future dedicated cyber-payment articles should separately cover:
- fake UPI payment screenshot fraud;
- UPI collect-request fraud;
- merchant employee replacing QR with personal VPA;
- wrong UPI transfer recovery;
- mule-account freezing and innocent account-holder claims;
- UPI refund / reversal scams.
Professional Consultation for UPI, Merchant QR and Cyber-Financial Fraud Matters
Advocate Ankit Kumar Singh
Supreme Court of India | Patna High Court | Allahabad High Court at Prayagraj | Jharkhand High Court at Ranchi | Calcutta High Court | Delhi High Court and Delhi Courts/Tribunals | Matters concerning Bhopal, Madhya Pradesh | Multiple District Courts
Depending upon the facts, jurisdiction and accepted professional engagement, professional analysis may include:
- UPI and QR fraud complaints;
- merchant QR replacement;
- wrong-beneficiary transfers;
- 1930 / NCRP complaint follow-up;
- bank and PSP representations;
- beneficiary-account tracing;
- mule-account issues;
- account freezing and lien disputes;
- CCTV and electronic-evidence preservation;
- transaction reconstruction;
- BNS / IT Act offence analysis;
- RBI-regulated-entity grievances;
- civil/restitutionary recovery;
- parallel PMLA issues where legally applicable.
Phone:
8294431232
Email:
ankitsingh.legum@gmail.com
Website:
advocateankitkumarsingh.in
Subject to accepted professional engagement, territorial jurisdiction, applicable procedure and local-counsel coordination where required.
Add AdvocateAnkitKumarSingh.in as a Google Preferred Source
For detailed research on cyber fraud, UPI disputes, digital evidence, PMLA and financial crime, readers may add advocateankitkumarsingh.in as a Preferred Source on Google.
Add as Google Preferred SourceLegal Disclaimer: This article provides general legal and cyber-fraud research and does not determine liability in any individual QR-payment dispute. A customer's successful UPI status does not itself prove that the intended merchant was credited, and a merchant's non-receipt does not itself prove QR tampering. Each case requires verification of the beneficiary name/VPA, transaction reference, payer debit, beneficiary credit, merchant account records, physical QR, CCTV and the applicable bank/acquirer/PSP records. RBI rules relating to unauthorised electronic transactions should not be applied mechanically to a transaction personally authenticated by a customer without first analysing whether it legally constitutes an unauthorised transaction. Criminal sections mentioned are fact-dependent and should be invoked only where their statutory ingredients are established. No recovery, freezing, refund or litigation result is guaranteed.
