top of page

Cyber Fraud through QR Codes: Adequacy of Indian Legal Remedies

  • sonalimukhia2002
  • 1 hour ago
  • 16 min read

Author: Haya Zubair, Jamia Hamdard University, New Delhi

Abstract

Digital payments, such as Unified Payments Interface (UPI), mobile wallets, and QR code payments, has transformed the payment system in India into an increasingly inclusive one making economic transactions easier for many Indians. However, the use of these digital payment systems has also led to the rise in various forms of cyber crimes, including QR code frauds. This paper seeks to evaluate the adequacy of the current legal framework in dealing with such cyber risks. Employing doctrinal research method, the paper provides an analysis of the provisions of the Information Technology Act, 2000, Bharatiya Nyaya Sanhita, 2023 and regulations of the Reserve Bank of India and National Payments Corporation of India. It is found out that the main legislation governing cyber crimes in India, does not contain any specific provisions to deal with QR code fraud. Consequently, law enforcement agencies have to bend existing provisions dealing with impersonation and cheating to combat cyber crimes of this nature. Other issues that this research identifies include jurisdictional fragmentation, problems in admitting evidence electronically, lack of technical knowledge on the part of investigators, and low consumer awareness. In order to solve these problems, the research suggests a complete revision of legislation, the creation of dedicated cyber-financial courts, consumer education programs, and use of AI-powered systems for the detection of cybercrimes in India’s UPI system.


Keywords: QR Code Fraud, Cyber Law, UPI Fraud, IT Act 2000, BNS 2023


Introduction

India has undergone a paradigm shift in the last ten years, as far as the adoption of digital payment methods is concerned, owing to the availability of Unified Payments Interface (UPI), mobile wallets, and QR code-based technology. Digital transactions in India have risen sharply in number. As per NPCI, there were more than 22.72 billion transactions worth ₹28.92 lakh crore done via UPI in June 2026 alone, while the average number of transactions through UPI stood at 731 million per day. This trend of digitization has been immensely influential in ensuring financial inclusion, efficiency, and economic development.


However, this process of digitalization has created certain risks too. People and enterprises are becoming victims of cyber financial crimes. From 2021 to 2025, there have been 65,89,201 financial fraud cases reported on the National Cyber Crime Reporting Portal, with total value of the reported amount being above ₹55,050 crores, highlighting the scale of the challenge. This makes it important to assess whether India’s legal framework is adequate to effectively address cyber-enabled financial frauds, especially those perpetrated through QR codes.


Fraud involving QR codes is unique in that the victim is generally unaware of the fact that he is being targeted and ends up authorizing what appears to him to be a legitimate transaction. Cybercriminals have recently begun using QR codes with malicious web addresses or payment codes that end up redirecting the unsuspecting victim either to a fake website or to an unauthorized transaction. As these transactions appear to have been authorised by the user, carrying out investigations and determining liability become more challenging.


This paper will seek to address the question of whether the existing laws that govern cybercrimes are adequate in terms of preventing and combating crimes committed via QR codes. In particular, this paper will seek to establish the fact that although the presence of such laws as the Information Technology Act, 2000 and Bharatiya Nyaya Sanhita, 2023 creates a legal structure, it is insufficient as remain fragmented, reactive, and are not fully equipped to address the unique challenges posed by QR code frauds.


Literature Review

In recent years, research on cyber frauds and cybersecurity in India has significantly increased, reflecting the growing importance of cybersecurity in the country and the rising concerns surrounding cyber frauds. The existing literature has examined issues related to consumer protection and corporate compliance, frauds related to digital payments, and the ability of Indian laws to keep pace with the increasing cybersecurity challenges.


Kumar, Kumar, and Sweety investigate the challenges consumers face in India, particularly in relation to data privacy, online fraud, and transaction-related issues, resulting from the rapid rise of digital services and e-commerce. Through an in-depth examination of the relevant provisions of the Consumer Protection Act, 2019 and the Information Technology Act, 2000, the authors conclude that there are inconsistencies in India’s legal frameworks governing data protection and dispute resolution. Their study highlights the need for greater legislative coordination to ensure effective consumer protection in the digital environment.


In a related study, Reddy and Nandini focus on the relationship between cybersecurity compliance and corporate liability in India. They argue that the existing compliance mechanisms and laws do not fully address the rapidly evolving cyber threats in the country. They further contend that the Digital Personal Data Protection Act, 2023 provides enhanced compliance obligations for organizations while imposing monetary penalties for failing to meet the prescribed standards. Altogether, these three studies offer a more comprehensive insight into how India is strengthening its legal framework on cybersecurity and data protection despite the various challenges in its implementation and enforcement.


A significant body of literature also examines the rapid growth of digital payment systems and the emergence of new forms of financial cybercrime. Chakka and Saheb conducted a study on UPI frauds between 2016 and 2025, which identified several fraudulent schemes and the methods used to detect them. The authors describe frauds involving fake applications, phishing attacks, fake QR codes, fraudulent payment requests, and KYC-related scams. They also analyze the use of different machine learning techniques for fraud detection, finding that some of the tested models demonstrated accuracy of up to 99.74%. They conclude by saying that the techniques used by fraudsters are becoming more advanced, thus requiring even more sophisticated methods of detection and prevention.


Expanding on QR code-related frauds, Bichnigauri et al. explore the concept of "quishing," where malicious QR codes conceal fraudulent links that are difficult for users to identify before scanning. Their study emphasises that the visual similarity between genuine and fake QR codes makes this form of cyber fraud particularly challenging to detect. Likewise, Asrihapsari, Putri, and Anaee conduct a comparative study of national QR code payment systems in Indonesia, India, and Nigeria. Their research identifies significant gaps relating to security, data privacy, and the broader economic implications of QR code payment systems, suggesting that these concerns extend beyond national boundaries.


On the question of effectiveness, both Sharma and Khan argue that India's Information Technology Act, 2000 was not designed to address the contemporary challenges posed by QR code fraud. Enacted long before the widespread use of smartphones and QR code-based payment systems, the Act is no longer fully suited to the realities of today's digital ecosystem. The authors go on to observe that the use of sections like 66D "places a huge task on the prosecution" when faced with complex and ever more innovative forms of fraud. This demonstrates the shortfalls of the current laws.

Collectively, the existing literature shows that cyber fraud has evolved alongside the rapid growth of digital technology, giving rise to new legal, technological, and regulatory challenges. While most studies have focused on consumer protection, corporate compliance, UPI frauds, and cybersecurity, relatively little attention has been given to the legal and practical issues surrounding QR code fraud.


The review also reveals several important research gaps. First, despite the growing incidence of QR code fraud, there is limited legal scholarship specifically examining QR code fraud (quishing) within the Indian context. Second, existing studies primarily discuss cyber fraud and digital payment fraud in general, with comparatively less attention to the legal and regulatory issues unique to QR code fraud. Third, there was insufficient research on whether the existing laws, rules, and regulations are adequate to address QR code fraud and, if not, how the existing lacunas can be addressed. Filling these research gaps will help develop a more comprehensive understanding of the legal issues pertaining to QR code fraud.


Methodology 

This study adopts a doctrinal legal research methodology, supplemented by a qualitative analytical approach. Doctrinal research involves the systematic identification, interpretation, and critical evaluation of legal rules and institutional frameworks governing a specific field—here, the techno-legal landscape of QR code cyber fraud. This method is particularly suited to the study as it enables rigorous examination of primary legal sources to assess the adequacy of existing legal remedies.

The research examines the following primary legal materials: the Information Technology Act, 2000 (sections 43, 43A, 66, 66C, 66D, 72, and 72A), the Bharatiya Nyaya Sanhita, 2023 (sections 316, 318, and 319), the Digital Personal Data Protection Act, 2023, and the Consumer Protection Act, 2019. Subordinate legislation analysed includes the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Consumer Protection (E-Commerce) Rules, 2020, and CERT-In Directions (2022). Regulatory guidelines examined include RBI circulars on digital payments and cyber security, and NPCI operational guidelines for UPI and QR code payments. Key judicial precedents analysed include K.S. Puttaswamy v. Union of India (2017), Shreya Singhal v. Union of India (2015), Anvar P.V. v. P.K. Basheer (2014), Shafhi Mohammad v. State of H.P. (2018), and Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020). Secondary sources include scholarly articles, legal commentaries, government reports, and media reports.


The research employs a qualitative analytical approach involving statutory interpretation, gap analysis, comparative evaluation of different legal instruments, case law analysis, and enforcement assessment to determine the coherence and sufficiency of current laws in combating QR code cyber fraud.


Analysis: Legal Framework for QR Code Cyber Fraud in India 

India’s legal regime against QR code cyber fraud can be said to be plagued by considerable legislative delay, consisting of a haphazard set of technology-neutral statutes, general provisions in penal law, and reactive regulatory circulars – none of which were framed taking into account the functioning of UPI and social engineering or instantaneous digital authentication. This chapter shall analyse the relevant laws, identify interpretational gaps, and subject pertinent case law to scrutiny.


The Information Technology Act, 2000


The IT Act is the primary Indian cyber law, but its applicability to QR fraud exposes some fundamental normative gaps between legislative expectations and technical reality.


Section 43A (Civil Liability) holds liable bodies corporate failing to ensure “reasonable security practices” in the processing of sensitive personal data, causing wrongful loss. In cases of QR fraud, since the breach usually results from leakage of phone numbers/transaction history, this section works more as a regulatory hammer than a legal tool for compensating the victims. It provides no precise definition of reasonable security practices, leaving much room for interpretive leeway and allowing payment intermediaries to escape liability unless gross negligence is proved, which becomes near impossible in advanced phishing schemes.


Section 66C (Identity Theft) is meant to address any abuse of "unique identification features," but this provision does not cover QR fraud adequately. The fraudsters generate a QR code that looks real rather than steal passwords or other biometric identifiers. The clear distinction between usurping the unique identifying feature and spoofing the interface makes this section too crude for prosecuting QR fraud since the provisions do not target the manipulation of the payment gateway architecture. This wording suggests that the identifiers need to be stolen rather than created.


Section 66D (Personation) becomes the main statute used to prosecute criminals by imposing punishments for impersonation by using computer resources. Yet, this provision is built upon the concepts of personation of common law which set very high evidentiary standards for the prosecution. In QR phishing, the fraudsters impersonate fictional authorities such as "Refund Desk" instead of real living people. There are many problems with extending the concept of personation to organizations.


Section 72A (Breach of Confidentiality) makes provisions for punishment of contractual data breach with malicious intent. The section remains largely peripheral as the majority of QR frauds result from social engineering which falls out of its scope of applicability.


Evidentiary Bottleneck (Section 65B) emerges as the most debilitating procedural hurdle. After the decision in Anvar P.V. v. P.K. Basheer, the Supreme Court endorsed restrictive interpretation that mandates a certificate of system custodians for admissibility of electronic evidence. Even though Shafhi Mohammad v. State of H.P. allowed liberal interpretation to accommodate oral evidence, the decision in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal reiterated Anvar as binding precedent mandating compliance with Section 65B(4) certificate. As the QR scams are entirely digital with reliance on UPI trace IDs, server logs, and GPS data, this procedural quagmire becomes utterly debilitating. Under-staffed police stations would fail to secure the required certificate during investigation, thus rendering the entire digital dossier of the case ultra vires evidence procedure and leading to failure of the case even before trial starts. Besides, any crime under the IT Act is bailable unless accompanied by BNS.


Bharatiya Nyaya Sanhita, 2023


The BNS, while bringing in new vocabulary into the penal lexicon, still preserves the old property-oriented epistemology of fraud of the IPC. Sections 316 (criminal breach of trust), 318 (cheating), and 319 (cheating by personation) all assume dyadic and personal relationships involving misrepresentation. In the context of UPI's technology-driven platform, the victim's "consent" is obtained via the PIN—a process presumed to be voluntary by law. The prosecution has to overcome that presumption by showing that the inducement was widespread enough to negate voluntariness—this is a philosophical and legal challenge for the trial court to grapple with. Section 111 (organized crime) can be pursued against the syndicate, but the rigorous requirement of "continuing unlawful activity" and material gain makes it unsuited for smaller cases.


The DPDP Act, 2023


The DPDP Act is a preventive regulation and not a corrective one. The banks and payment aggregators (Data Fiduciaries) need to take certain steps for securing the data that will be penalized up to a fine of ₹250 crores for non-compliance. Notably, the DPDP Act does not have any provision for private right of action for victims of frauds.


Regulatory Framework – RBI & NPCI Guidelines


Even with this operational strategy from both the RBI and NPCI, the measures are cyclical in nature and lack legal enforceability.


Firstly, the 2FA requirement by the RBI  presupposes that the device is secure. This means that QR fraud attacks the human component, thus making the technical protocols obsolete. The RBI did not issue any directive requiring dynamic and non-spoofable QR display mandates like mandatory merchant names display prior to PIN entry.


Secondly, the NPCI directive for 2025 prohibits international transactions through QR code interchange shows administrative skillfulness. However, this directive does not apply to penal laws as these directives apply to Payment System Operators. This is the main drawback since the induced transactions do not come under the ambit of RBI ombudsman.


Enforcement Challenges


Aside from gaps in the statute itself, structural decay undermines the enforcement mechanism. Jurisdictional fissures under the Bharatiya Nagarik Suraksha Sanhita, 2023 involve inter-state cooperation of police agencies, hampered by lack of protocols for real-time reaction. Inadequacies in technical skills hinder forensic data recovery, blockchain tracking, and transaction logs analysis in regular police stations. This leads to arresting mules, leaving masterminds at large.


Bailability of IT crimes renders such crimes less deterring due to favorable cost-benefit calculations for criminals. Combined with widespread digital illiteracy, especially in rural areas, this creates problems. The "golden hour" to freeze funds (15-30 minutes) is wasted when victims call customer care hotlines instead of the cybercrime portal (1930).


Case Law and Judicial Trends


Even though the pronouncements of the Indian judiciary have shaped cyber law jurisprudence, there is no judicial precedent that touches upon QR code fraud. Paradoxes in case law include:


K.S. Puttaswamy v. Union of India recognized privacy as a fundamental right, which has led to a normative transformation in terms of making informational privacy a constitutional duty of State as well as data fiduciaries. In QR fraud, it means that payment intermediaries now have constitutional, and not just contractual, responsibility of protecting data. However, this responsibility cannot be used horizontally in criminal cases against private entities.


Shreya Singhal v. Union of India brought forth the "overbreadth doctrine," declaring Section 66A to be vague, thus requiring legislative precision by enacting narrowly tailored statutes. This judicial approach poses challenges for law enforcement since police are not permitted to use general public nuisance legislation and are required to use only specific provisions such as Section 66D or BNS Section 318. However, both of these sections fail to consider the digital environment, leaving QR scams as an orphan in jurisprudence which can be classified as neither cheating nor hacking. Notably, the recent Karnataka High Court judgment ruled that Shreya Singhal was from the "regime of bygone times," which cannot be "mechanically applied" to today's world of digitization.


The Evidentiary Divide shows the conflict between textualist approach and pragmatist approach to justice. In Anvar P.V., the Court created an unrealistic evidentiary bar by holding the Section 65B certificate as jurisdictional requirement. Shafhi Mohammad tried to salvage the situation by permitting oral evidence to prove the authenticity of electronic documents in certain cases. The question was finally settled in Arjun Panditrao Khotkar, whereby the Court overruled Shafhi Mohammad and upheld Anvar. The result was that the Section 65B(4) certificate becomes mandatory for admissibility of electronic evidence. Nevertheless, it was made clear that certificates can be sought and presented at any stage of trial. In the case of QR fraud, which uses digital footprints as corpus delicti, this ambiguity is a disaster, as it allows criminal lawyers to delay certificate acquisition.


Adequacy of the Legal Remedies in India


The QR Code Fraud Legal Vacuum


The study shows that there is a large legal gap. The IT Act, 2000 has no specific provisions that relate to QR. Prosecutors must rely on general impersonation and cheating laws to catch an attack method that the lawmakers never predicted.


Jurisdictional and Procedural Barriers


Jurisdictional issues are also created as cybercriminals perpetrate fraud in one state against victims in another. Another procedural hurdle is the admissibility of electronic evidence.


Limited Consumer Awareness and Remedies


The Ministry of Home Affairs has set up the Indian Cyber Crime Coordination Centre (I4C) and introduced the National Cyber Crime Reporting Portal (NCRP). The Citizen Financial Cyber Fraud Reporting and Management System has been instrumental in saving financial losses of over ₹11,158 crore in over 32.80 lakh complaints.


However, these are merely reactive measures and not preventive. Many people are still vulnerable due to limited awareness of consumers regarding digital rights and safe practices.


Proposed Reforms


Legislative Modernization: The IT Act must be thoroughly and broadly revised to meet QR code fraud challenges. The need for a special legislative approach to cyber-financial crime would promote clarity and bolster consumer protection.


Specialized Cyber-Financial Courts: It would make the process of case resolution faster.


Enhanced Consumer Education: There is a need to increase consumer awareness and educate consumers about digital rights and safe practices.


Integration of AI-based Detection Systems: With 340 milliseconds latency, AI-based QR code fraud detection systems have reached an accuracy of 96.7%.


Strengthened Regulatory Enforcement: The CCPA calls for greater capability of meaningful monitoring of e-commerce platforms.


International Cooperation: India needs to improve the mechanisms for international cooperation in cybercrime cases.


Conclusion

The speed of digitisation in India's payment ecosystem, as evidenced by an exponential increase in UPI transaction figures crossing 22.72 billion in just one month of June 2026, has increased convenience and financial inclusion like never before. However, this development has also made India vulnerable to attacks from cybercriminals, QR Code fraud being one of them.


It is clear from this doctrinal analysis that there exist many gaps, fragmentation, and procedural inefficiencies in the Indian legal system that make it difficult to enforce the laws and protect the victims of QR Code fraud. First, the Information Technology Act, 2000 does not have any special provisions against QR Code fraud making the prosecution depend upon generic provisions that are not suitable for the digital age. The Bharatiya Nyaya Sanhita, 2023 also holds property-based notions of fraud which do not apply to the consent issues in technology-mediated transactions. The procedural requirement of Section 65B, as interpreted in the case of Arjun Panditrao Khotkar imposes unreasonable evidentiary requirements making important digital evidence inadmissible.


In order to rectify these deficiencies, this research suggests the need for legislative reforms, including laws specifically targeting QR code scams, creation of dedicated cyber financial courts, consumer awareness programs, incorporation of advanced AI detection system that has a 96.7% success rate, stricter regulations and more effective international collaboration.


The protection of India's digital economy requires a dynamic and constantly evolving legislative mechanism. The time for piecemeal reform is over; what is required now is a completely new and modernized approach towards cyber-financial crimes, with QR code scam being just a test run for much larger problems of the digital era.


References

Legislation


  • The Information Technology Act, 2000, No. 21, Acts of Parliament, 2000 (India).


  • The Bharatiya Nyaya Sanhita, 2023, No. 8, Acts of Parliament, 2023 (India).


  • The Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India).


  • The Consumer Protection Act, 2019, No. 35, Acts of Parliament, 2019 (India).


  • The Bharatiya Nagarik Suraksha Sanhita, 2023, No. 9, Acts of Parliament, 2023 (India).


Subordinate Legislation


  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, S.O. 2250(E) (Sept. 8, 2011).


  • Consumer Protection (E-Commerce) Rules, 2020, S.O. 2806(E) (July 23, 2020).


  • CERT-In Directions, 2022, S.O. 1642(E) (Apr. 28, 2022).


Judicial Decisions


  • K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1.


  • Shreya Singhal v. Union of India, (2015) 5 SCC 1.


  • Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473.


  • Shafhi Mohammad v. State of H.P., (2018) 2 SCC 801.


  • Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1.


Regulatory Guidelines and Circulars


  • Reserve Bank of India, "Report on Cyber Security in Digital Payments," RBI Bulletin (Mumbai: RBI, 2025).


  • Reserve Bank of India, Master Direction on Issuance and Operation of Prepaid Payment Instruments, RBI/DPSS/2024-25/135 (Dec. 2024).


  • National Payments Corporation of India, "Operational Guidelines for UPI and QR Code Payments," NPCI Circular No. 12/2025 (Mumbai: NPCI, 2025).


  • National Payments Corporation of India, Circular on International QR Code Transactions, NPCI/UPI/2025/03 (Jan. 2025).


Government Reports

  • Ministry of Home Affairs, Government of India. "National Cyber Crime Reporting Portal: Annual Report 2024-25." New Delhi: MHA, 2025.


  • MINISTRY OF HOME AFFS., GOV’T OF INDIA, Press Release: Cyber Crime Statistics (2024).


  • National Payments Corporation of India (NPCI). "UPI Transaction Statistics." NPCI Annual Report 2025-26. Mumbai: NPCI, 2026.


Journal Articles


  • Al-Eshaq, N. A. M. H., Farag, M. E., & Kattan, I. A. "Establishing a Compensation Fund for Victims of Cyber Fraud: Toward a Legal Framework for Qatar." Edelweiss Applied Science and Technology (2025).


  • Asrihapsari, A., Putri, I. S., & Anaee, A. E. "Analysis of National QR Code Payment Systems: Practices in 3 Developing Countries (Indonesia, Nigeria, and India)." AKUMULASI: Indonesian Journal of Applied Accounting and Finance 4, no. 1 (2025): 76-95.


  • Bichnigauri, A., Kartvelishvili, I., Shonia, L., Bichnigauri, D., & Gudadze, O. "Unveiling Quishing: The Dark Side of QR Codes in Cyber Attacks." Digital Security 2 (2023): 1-8.


  • Chakka, N. B., & Saheb, S. S. "Mobile Payment Fraud Detection in UPIs Through Machine Learning Techniques: A Systematic Review." Malque Publishing* (2026): 1-16.


  • Kashyap, A. K., & Chaudhary, M. "Cyber Security Laws and Safety in E-Commerce in India." Law and Safety 89, no. 2 (2023): 19.


  • Kumar, N., Kumar, P., & Sweety. "Impact of Digitalization on Consumer Rights in India: Legal Frameworks & Issues." Journal of Law and Emerging Technologies* 5, no. 1 (2025): 1-29.


  • Mittal, N., & Kaur, G. "A Comprehensive Socio-Legal Analysis of Cybercrime in India: Patterns, Challenges, and Legal Frameworks." International Journal of Environmental Sciences (2025).


  • Modi, S., Premani, V., & Kaur, M. "Critical Analysis of E-Banking Frauds and Laws in India." International Journal of Health Sciences 5, no. S2 (2021).


  • Muralidharan et al. "AI-Based QR Code Fraud and Scam Detection System for Secure Digital Payments." International Scientific Journal of Engineering and Management (2026).


  • Parveen, S. "Cybercrime Laws: Are They Sufficient in Today's Digital World?" International Journal of Science and Research (2025).


  • Reddy, V., & Nandini, P. "Cybersecurity Compliance and Corporate Liability in India: An Analytical Study." International Journal of Research and Scientific Innovation 13, no. 3 (2026): 1568-1576.


  • Sharma, S. K., & Khan, M. "Unveiling Digital Deceptions: A Holistic Analysis of Online Frauds in India and the Role of Cyber Laws." Integrated Journal for Research in Arts and Humanities 5, no. 4 (2025): 1-15.


  • Singh, P. "Deepfakes, Identity Theft, and the Dark Web: Legal Gaps in AI-Generated Fraud, an Indian Perspective." International Journal of Civil Law and Legal Research 5, no. 2b (2025): 148.


  • Vijaywargia, R. "Digital Banking Frauds in India: A Comparative Legal Study of Rajasthan and Other States." International Journal For Multidisciplinary Research 8, no. 4 (2026).


News Reports


  • Kumar, D. "India Tightens QR-Based Digital Payment Security to Boost UPI Globally." Mint, April 13, 2026.


Websites







Comments


bottom of page