The National Payments Corporation of India directed member banks and UPI application providers Tuesday to bind device fingerprints and mandatory step-up authentication to collect requests above ₹1 lakh effective 1 October, closing a loophole fraud investigators said mule networks exploited when high-value merchant QR flows spiked during a week of Trump–Xi summit FX volatility and late-month salary credits.

What NPCI changed

According to a circular reviewed by InfoHandle, any UPI collect initiated above the ₹1 lakh threshold must carry a signed device attestation from the payer’s registered handset, a fresh risk score from the issuer’s fraud engine, and a one-time credential challenge unless the payer has whitelisted the merchant through a bank branch process reserved for institutional billers. Collect requests without attestation will hard-decline at the NPCI switch rather than queue for manual review—a shift from the prior regime where some issuers silently held high-value collects in suspense ledgers.

NPCI’s product team said the rule targets “person-to-merchant collect abuse,” not standard scan-and-pay intent flows. Scammers had been generating dynamic collect IDs in messaging apps, persuading victims to approve a single ₹99 test payment, then replaying stolen session tokens to push ₹1.5 lakh–₹3 lakh collects before device binding refreshed.

What banks reported

Indian Banks’ Association fraud officers told InfoHandle that three private-sector lenders logged a combined 4,200 suspicious high-value collects in August alone, with median loss per victim near ₹1.8 lakh. Patterns clustered around jewellery and electronics merchants with freshly issued static QR stickers—merchants who often did not know their MCC codes were misclassified as low-risk.

RBI’s digital payments department received parallel suspicious transaction returns citing device ID rotation through emulator farms hosted on cloud VMs in Mumbai and Hyderabad regions. CERT-In advisories this month already warned of overlay malware capturing UPI PINs; NPCI’s fingerprint mandate is the switch-level counterpart, not a replacement for handset hygiene.

Who must implement

All UPI participating banks, third-party app providers, and payment service providers must certify compliance by 28 September load tests on NPCI’s staging environment. Failure blocks production traffic for non-compliant apps—a stick NPCI used sparingly after the 2020 UPI outage drills but now references explicitly for fraud controls.

Merchant acquirers must refresh Know Your Customer on high-ticket QR merchants quarterly instead of annually, and tag collects with merchant employee device maps where staff phones initiate requests on behalf of walk-in buyers—a common practice in wholesale markets that fraud rings mimicked with stolen credentials.

What customers will notice

Payers approving large collects will see issuer prompts resembling card 3-D Secure: biometric or PIN re-entry, plus a plain-language summary of payee legal name and MCC. NPCI said customers cannot opt out except through branch whitelisting for verified utilities and education fee billers.

Consumer groups asked whether ₹1 lakh is too high for retail victims; NPCI argued lowering the threshold would throttle legitimate B2B UPI adoption. RBI has not commented on a secondary tier, but bankers expect a ₹25,000 soft challenge layer in a follow-on circular after Diwali transaction data arrives.

What is still unknown

NPCI has not published emulator-detection false-positive rates from pilot banks. Apple iOS attestation paths differ from Android SafetyNet successors; smaller banks worry their fraud vendors lack integrated SDK builds before the October deadline. Overseas wallet interoperability pilots are exempt for now, but NPCI staff said exemptions expire if cross-border collect volumes rise.

Liability and next checks

Legal analysts said issuer liability for authenticated collects above the threshold likely shifts toward customers who ignore step-up warnings—language banks are racing to insert into mobile banking terms. Merchant liability for misclassified MCCs remains untested in ombudsman rulings; at least two cases await decisions in Mumbai and Bengaluru.

For the wider UPI ecosystem, the message is narrow but expensive: collect is not “just another payment request.” Until device fingerprints ride every high-value collect, mule desks will keep treating NPCI’s switch as a high-speed laundry rail. October load tests will show whether issuers treated the circular as fraud hygiene or another compliance checkbox—and whether Trump–Xi week’s volatility was a preview of what happens when FX nerves and salary week collide with weak device binding.

Implementation timeline

Banks must file compliance affidavits by 30 September; NPCI will publish a green list of apps cleared for high-value collect before the 1 October cutover. Fraud desks plan joint tabletop exercises with CERT-In on 26 September simulating emulator replay—exercises that will determine whether the ₹1 lakh line holds or becomes another round number fraudsters route around within a quarter.