The real scenario

Priya was paying a seller on an online marketplace. The seller messaged her: "My UPI ID is amazonsupport@icici." Priya typed the address carefully into her GPay and saw the confirmation screen showing "Amazon Support Services" — a name that matched what she expected. She entered her MPIN and paid ₹4,200 for the item. The package never arrived. When she complained to Amazon, they had no record of the transaction. The VPA she'd used was amazonsuprt@icici — missing one letter, registered to an unrelated personal account. The confirm-screen name is set by whoever creates the account. It had been set to "Amazon Support Services" intentionally.

How does one letter cause so much damage?

A Virtual Payment Address (VPA) is just a text string — it can be registered by anyone with a UPI-enabled bank account. There is no verification that the name you display on your account actually matches your legal name or your business. This means a scammer can register flipkartseller@ybl or paytmsupport@paytm and display any display name they choose — including "Flipkart Seller Hub" or "Paytm Official."

The attack works in two ways. First, scammers register typosquat VPAs — addresses that look nearly identical to real ones — and share them in marketplace DMs, WhatsApp groups, and fraudulent customer service numbers. Second, they create VPAs with trusted-sounding display names and use them in collect requests, hoping victims won't read the actual address carefully.

The UPI system resolves the display name only from the account metadata — not from any external registry. Until NPCI implements mandatory name verification for all VPA registrations, users must verify the address character by character.

🚩 Red flags to watch for

🚩
A seller or support agent shares a UPI ID over WhatsApp, Telegram, or SMS rather than through a verified in-app payment flow.
🚩
The display name on the UPI confirm screen shows a brand name (Amazon, Flipkart, Paytm) but the actual VPA is a personal account like random123@ybl.
🚩
You are paying an unusually high amount to a VPA received through an informal channel rather than an official checkout page.
🚩
The VPA looks correct at a glance but contains doubled letters, transposed characters, or missing vowels — amazon vs amazon, support vs support.

✅ How to stay safe

✅
Read the VPA character by character: Before entering your MPIN, expand the details screen and read the full UPI address slowly. Don't trust the display name alone — it can be anything.
✅
Use SatarkScan: Our app cross-checks VPAs against known impersonation patterns and flags addresses registered with brand-name display names against unrelated bank accounts.
✅
Only pay through official channels: Never pay a seller by manually typing their shared VPA. Use the in-app payment flow on Flipkart, Amazon, or Meesho — these route money through escrow, not directly to the seller's personal account.
✅
Save verified VPAs as favourites: Once you have confirmed a legitimate UPI address, save it in your UPI app's Favourites. Future payments go to the saved (verified) address, not whatever is typed or pasted fresh each time.