'Rogue Auto QR Code' Fraud: Is a New UPI Scam Putting Your Bank Account at Risk? Know How It Works

A viral 'Rogue Auto QR Code' scam warning has emerged after a user said that his sister received unauthorised UPI registration alerts after encountering a suspicious QR code in an Uber auto in Mumbai. While claims of a 'silent device-binding' hack are likely overstated, experts warn that sharing phone numbers with untrusted parties facilitates real social-engineering fraud.

All about 'Rogue Auto QR Code' scam (Photo Credits: X/@Ashish_4vedi and Pixabay)

A recent social media post has drawn attention to reports of UPI-related fraud following interactions with auto-rickshaw drivers, highlighting ongoing risks around QR codes and digital payments in India. On August 12, Ashish Chaturvedi, a journalist with CNBC Awaaz, reported that after his sister booked an Uber auto (vehicle MH 02 EF 3779), the driver presented a fraudulent QR code for payment. He further said that his sister paid in cash instead. Shortly afterwards, multiple messages arrived from different banks regarding UPI registration or activation. "My sister suspected this and paid in cash. However, after a few minutes, she started receiving many messages from different banks for UPI registration," the post read.

In his post, Chaturvedi tagged authorities including Mumbai Traffic Police, Maharashtra Cyber, Cyber Dost, and Uber support. His post was shared by another X user who labelled the issue as the "Rogue Auto QR Code" scam and described a sophisticated device-binding attack targeting Android users. ‘Rent a Boyfriend’ Scam Modus Operandi: How Fake Discounts and Dates Lure Young Women Into Blackmail Trap.

Journalist Says His Sister Receives Messages From Different Banks for UPI Registration

How the New UPI Scam Works

What the Viral Explanation Claims

The X user said that a "highly sophisticated UPI scam is targeting commuters using Android phones". "Within minutes, victims are seeing their bank accounts linked to remote devices without their consent," the user added. According to the X user, the fraud works as follows: A custom QR code triggers an Android deep-link intent rather than a standard payment page. This allegedly forces the victim's phone to generate and send a hidden encrypted UPI registration token SMS. Scammers, who have entered the victim's phone number into banking apps on their own burner devices, then use that token so that NPCI systems bind the accounts to the scammers’ phones. Automated processes then pull linked bank accounts, producing a rapid flood of activation messages across multiple banks.

The thread advised immediate steps such as dialling *99# to block UPI, calling the national cybercrime helpline 1930, checking for SMS forwarding, and de-registering UPI profiles in apps. It also recommended scanning QR codes only inside official apps such as Google Pay, PhonePe, BHIM, or bank applications rather than the phone’s default camera.

Context and Technical Clarifications

UPI device binding is a security feature that links a user’s mobile number and device to their accounts. It normally relies on a timed, unique outbound encrypted SMS token generated by an official UPI app during registration, combined with device fingerprinting. NPCI guidelines limit the token validity window (typically ≤45 seconds), block token reuse across numbers, and restrict the process to official app flows.

Analyses of the claims note that a standard payment QR code is designed to open only the payment flow and does not silently force a device-binding registration SMS or enable remote multi-bank binding without additional factors such as SIM control or malware. The flood of registration messages is more commonly linked to scammers obtaining a phone number (for example, from a ride-booking app) and initiating registration attempts on their own devices, which can generate alerts or verification activity on the victim’s side.

Broader QR-code risks remain well documented. These include physical sticker swaps that redirect payments to scammer accounts, and social-engineering tactics that trick users into scanning codes under the false belief they will receive money. In all cases, a UPI QR code initiates an outgoing payment request when scanned and confirmed. Separate, more advanced threats involving malware toolkits that attempt to bypass SIM-based verification have also been reported by cybersecurity firms, though these typically require the victim to install malicious software.

Practical Protection Steps

Authorities and payment operators consistently recommend the following:

  • Scan QR codes only inside official UPI or banking apps, never with a generic camera or third-party scanner.
  • Verify the payee name shown on the payment confirmation screen before entering a UPI PIN.
  • Never scan a code to “receive” money, refunds, or cashback; receiving funds does not require scanning or entering a PIN.
  • If unexpected UPI registration or activation messages appear, dial *99# from the affected SIM to block or disable the UPI profile, contact banks to revoke any unknown devices, and report the incident to 1930 or cybercrime.gov.in.
  • Check for call or SMS forwarding (*#21#) and clear it if present (##002#).
  • Prefer cash or in-app ride payments when dealing with unfamiliar drivers or street vendors if a QR code feels suspicious. Digital Arrest Scam: CBI Arrests 3 Including Ex-Bank Official in INR 1.6 Crore Cyber Fraud Case.Ride-hailing platforms and cybercrime units continue to receive reports of payment-related issues involving auto and taxi drivers. Users who encounter similar incidents are advised to document vehicle details, report them promptly to the platform and local cyber police, and monitor linked bank accounts. The episode underscores the need for caution with any QR code presented in everyday transactions. While the precise “device takeover” mechanism described in the viral posts appears overstated relative to current NPCI protocols, the underlying risks of QR-based fraud and unauthorised registration attempts remain real and evolving.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (Official X Account of Ashish Chaturvedi), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Aug 13, 2026 11:20 AM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).

Share Now

Share Now