Government service payments are a favourite target for fraud, for a simple reason: the applicant is expecting to pay someone they do not know, for something they do not fully understand, often under time pressure. That is exactly the situation a scam needs.
The defences are few and they are mechanical. Learn them once.
The rules that do not change
- You never need to approve a UPI request to RECEIVE money. If someone says a refund requires you to approve a collect request, it is theft - approving sends money out.
- No genuine agency, bank or department will ask for an OTP. Not to verify you, not to confirm a refund, not for any reason.
- No one legitimate needs remote access to your phone. Requests to install AnyDesk, TeamViewer or similar are a standard part of these frauds.
- Your card CVV and PIN are never needed by a person. Only by the payment page itself.
- Urgency is a technique. A real government deadline does not require you to pay in the next ten minutes to a number sent over WhatsApp.
Checking where you are paying
- Look at the domain, not the page design. Official Indian government portals sit on gov.in or nic.in domains; lookalikes use near-miss spellings and extra words.
- Type the address yourself or use a bookmark rather than following a link from a message.
- Check for the padlock, but do not rely on it - a fraudulent site can have one too. The domain name is the real signal.
- Be suspicious of any page reached from a sponsored search result for a government service.
How we handle payments
We tell you our service fee and, where a separate statutory fee applies, that it is separate and where it goes - before you pay anything. We do not ask for OTPs, we do not send UPI collect requests, and we do not need remote access to your device.
If you are ever contacted by someone claiming to be from us and asking for any of those things, it is not us. Call the number published on this site and confirm.
If it has already happened
- Call your bank immediately and report the transaction as unauthorised - speed materially affects recovery.
- Report it on the national cybercrime portal, cybercrime.gov.in, or call the cyber helpline 1930.
- Preserve everything: screenshots, the number that contacted you, the UPI handle, the transaction reference.
- Change the credentials of any account involved, and revoke any remote-access app you were asked to install.