India’s Computer Emergency Response Team issued an advisory on Monday warning that criminals are impersonating National Highways Authority of India FASTag recharge portals to push fraudulent UPI “collect” requests, a shift from older SMS links that asked victims to install remote-access apps. CERT-In said the campaign targets fleet operators and commuters who top up toll wallets from phones while queued at plazas or idling in industrial estates, where small payment errors are easy to miss against dozens of daily debits.
How the spoof pages work
Investigators described a repeatable funnel. Victims search for “FASTag recharge” or follow shortened links circulated on WhatsApp groups for truck unions. They land on pages that copy NHAI colour blocks, toll-plaza photography, and menu labels closely enough to pass a glance on a bright phone screen. Instead of routing payment through bank-hosted net banking, the site displays a QR code or merchant VPA that triggers a collect request in any UPI app.
The malicious VPAs often use words such as “nhai”, “fastag”, or “wallet” in the handle, but CERT-In stressed that naming alone is not proof of legitimacy. Once a driver approves a collect for what looks like a ₹500 or ₹1,000 top-up, the amount can be higher, or a second collect fires seconds later while the user is still on the fake receipt page. Banks see the transaction as customer-authorised UPI; dispute windows are narrow compared with card chargebacks.
Why toll users are a soft target
NHAI’s electronic toll network processes millions of FASTag reads each day. Legitimate recharge paths include issuer banks, the MyFASTag aggregator, and authorised payment apps. Fleet desks often delegate recharges to drivers who share one corporate UPI ID across several vehicles. CERT-In noted that scammers time campaigns around month-end when prepaid balances run low and plaza operators display low-balance flags at lanes.
Unlike phishing that steals net-banking credentials, collect scams keep users inside familiar UPI interfaces. That reduces suspicion: the payer sees their own bank’s app, not a cloned login. Loss reports reviewed by state cyber cells in Maharashtra and Karnataka in recent weeks cluster around ₹2,000–₹15,000 per incident—small enough to avoid immediate executive attention, large enough to fund mule payouts.
What agencies have confirmed—and what they have not
CERT-In published indicators of compromise, including a list of suspicious domains and VPAs, and asked telecom and payment providers to block them under the Information Technology Act’s emergency measures. NHAI reiterated that it does not operate standalone recharge sites outside its official domain and partner bank apps. Neither agency released a nationwide loss total on Monday; Mumbai and Delhi cyber police said they are merging complaints into a shared ledger for payment-system participants.
What remains unknown is how many fake pages remain live through content-delivery networks that rotate URLs faster than takedown notices. Investigators also have not publicly tied the FASTag lures to the same groups behind IPO lottery scams, though both rely on mule accounts opened with rented SIM kits.
What fleet desks and commuters should do
CERT-In told users to recharge only through bank apps linked to their FASTag issuer or through the official MyFASTag flow, never through search-result ads. Before approving any collect request, payers should verify the beneficiary name displayed in the UPI app against the tag issuer shown on the vehicle sticker. If the name is a personal account rather than a registered merchant, cancel the request.
Turn off auto-approve for collects in apps that offer the setting, and segregate a low-balance UPI ID for toll top-ups instead of using a salary account. Fleet managers should reconcile plaza SMS debits against UPI statements weekly; many scams are caught only when a driver’s recharge total exceeds tag usage.
Liability and the next enforcement steps
Under RBI’s UPI framework, payer banks must display clear beneficiary details, but customer authorisation still shifts liability to the account holder unless fraud is proven through police reports. CERT-In asked payment apps to flag first-time VPAs that receive high-value collects from toll-adjacent IP ranges—a technical measure still being rolled out.
For now, the advisory is preventive. NHAI said it is placing warnings on official recharge screens, and National Payments Corporation of India reminded banks that education material must distinguish “pay to merchant QR” from “approve collect request.” Until domain blocks catch up with new lures, the practical defence is slower thumbs at the toll queue: a rejected collect is cheaper than a cleared one.
State transport corporations that issue fleet FASTags plan briefings at major truck terminals this week, repeating that plaza SMS alerts never include payment links. Cyber cells in at least four states have opened dedicated reporting tags for toll-wallet fraud so complaints can be correlated with CERT-In’s domain feed within 24 hours rather than sitting in general cybercrime queues.








