Recharge and bill-payment fraud is unusually consistent in its mechanics, which makes it unusually easy to defend against once you know the shape.
The three common forms
- The failed-recharge callback. Someone calls claiming your recharge failed and offers to reverse it, then sends a UPI collect request. Approving that request sends money out, it does not bring any in.
- The KYC expiry message. A text warns your number will be disconnected unless you update KYC through a linked app, which is a remote-access tool. Operators never ask you to install anything to keep a number active.
- The overpayment refund. A caller says you were charged twice and asks for an OTP to process the refund. An OTP authorises a payment out of your account; there is no version of it that pulls money in.
The one rule
You never need to approve a payment, enter a PIN, or share an OTP to receive money. Every UPI app makes receiving money a passive act. If any step of a refund asks you to authorise something, it is not a refund.
Where to actually go
Handle a genuinely failed recharge in the operator's own app or the platform you paid on — never through a number from a search result, which is a well-known vector for planted listings. This is also why RechargeHub takes no payments and asks for no details: there is nothing here for that kind of attack to work against.