Two missing letters. Same-looking name on the confirm screen. All your money.
The real scenario
Priya was paying a seller on an online marketplace. The seller messaged her: "My UPI ID is amazonsupport@icici." Priya typed the address carefully into her GPay and saw the confirmation screen showing "Amazon Support Services" — a name that matched what she expected. She entered her MPIN and paid ₹4,200 for the item. The package never arrived. When she complained to Amazon, they had no record of the transaction. The VPA she'd used was amazonsuprt@icici — missing one letter, registered to an unrelated personal account. The confirm-screen name is set by whoever creates the account. It had been set to "Amazon Support Services" intentionally.
How does one letter cause so much damage?
A Virtual Payment Address (VPA) is just a text string — it can be registered by anyone with a UPI-enabled bank account. There is no verification that the name you display on your account actually matches your legal name or your business. This means a scammer can register flipkartseller@ybl or paytmsupport@paytm and display any display name they choose — including "Flipkart Seller Hub" or "Paytm Official."
The attack works in two ways. First, scammers register typosquat VPAs — addresses that look nearly identical to real ones — and share them in marketplace DMs, WhatsApp groups, and fraudulent customer service numbers. Second, they create VPAs with trusted-sounding display names and use them in collect requests, hoping victims won't read the actual address carefully.
The UPI system resolves the display name only from the account metadata — not from any external registry. Until NPCI implements mandatory name verification for all VPA registrations, users must verify the address character by character.
🚩 Red flags to watch for
🚩
A seller or support agent shares a UPI ID over WhatsApp, Telegram, or SMS rather than through a verified in-app payment flow.
🚩
The display name on the UPI confirm screen shows a brand name (Amazon, Flipkart, Paytm) but the actual VPA is a personal account like random123@ybl.
🚩
You are paying an unusually high amount to a VPA received through an informal channel rather than an official checkout page.
🚩
The VPA looks correct at a glance but contains doubled letters, transposed characters, or missing vowels — amazon vs amazon, support vs support.
✅ How to stay safe
✅
Read the VPA character by character: Before entering your MPIN, expand the details screen and read the full UPI address slowly. Don't trust the display name alone — it can be anything.
✅
Use SatarkScan: Our app cross-checks VPAs against known impersonation patterns and flags addresses registered with brand-name display names against unrelated bank accounts.
✅
Only pay through official channels: Never pay a seller by manually typing their shared VPA. Use the in-app payment flow on Flipkart, Amazon, or Meesho — these route money through escrow, not directly to the seller's personal account.
✅
Save verified VPAs as favourites: Once you have confirmed a legitimate UPI address, save it in your UPI app's Favourites. Future payments go to the saved (verified) address, not whatever is typed or pasted fresh each time.