A shop counter handles cash, biometrics and OTPs all day, which makes it a target. Most attempts follow familiar patterns: a caller pretending to be staff, a customer pushing you to skip a safety step, or a screenshot passed off as proof of payment. This guide walks through each pattern, what Payonclick's app already does to protect your account, and where to report an attempt.
Fake "Payonclick staff" calls
The most common attempt is a phone call or message from someone claiming to work for Payonclick, asking for your OTP, TPIN, password, or a remote fingerprint scan on the pretext of "verification," "activation" or "an urgent update."
Payonclick staff never ask for your OTP, TPIN, password or a remote fingerprint scan, for any reason. Anyone who asks is not from Payonclick, even if they know your name, mobile number or shop details.
If you get such a call, hang up. Do not read out any code that arrives by SMS while you are on the call, even if the caller sounds official or already knows details about your account. Contact us directly on +91 99926 88080 (phone and WhatsApp), Monday to Saturday, 10:00 AM to 7:00 PM IST, to check whether anything genuinely needs your attention.
Biometric safety at the counter
Your RD device and your own biometric are the keys to your AEPS service, so they need the same care as cash.
Keep the device with you
Never leave your RD device unattended at the counter or hand it to a customer to "help" with a scan. Only the customer's own finger or iris should touch it, for their own transaction.
Never do daily authentication for someone else
Your daily authentication uses your own Aadhaar. Never let a helper, relative or another shop use your login or complete this check on your behalf.
Never do eKYC for someone else
Aadhaar eKYC and bank eKYC during onboarding must be completed with the actual retailer's own biometric and OTP. Doing this for another person breaks the identity check the rules depend on.
Work from your registered shop
Serve customers from the shop address on file. Location is part of how your account is monitored, so unusual patterns can get your ID flagged.
Our guide to the AEPS operator KYC rules explains why banks watch this closely from 1 January 2026 onward, and what a break in these habits can cost you.
Fake UPI payment screenshots
For UPI cash withdrawal, a screenshot is not proof of payment. Screenshots can be edited, delayed, or taken from an app showing a payment that later reverses or never actually completes on your side.
Never accept a payment screenshot from a customer's phone as proof for a UPI cash withdrawal. Hand over cash only when your own Payonclick app shows the withdrawal as successful. See our UPI cash withdrawal guide for the full flow, including the dynamic QR code that expires after about a minute.
The same principle applies to any service: your own app's status screen is the only proof that counts, never a customer's phone.
Customers pushing to split a withdrawal
Occasionally a customer, or someone coaching them, will ask you to break one large AEPS withdrawal into several smaller ones, often to avoid the Aadhaar OTP required above ₹5,000. Do not agree to this.
- Splitting a withdrawal does not remove any real risk to the customer; it only removes a safety check that exists for their protection.
- It can also draw attention to your account. Banks are required to monitor AEPS operators by risk factors including transaction volume and velocity, and a burst of same-customer withdrawals in quick succession is exactly the kind of pattern that gets reviewed.
Treat any request to "just do it in parts" as a warning sign, whether it comes from the customer or from anyone else at the counter.
Fake refund calls
After a failed or disputed transaction, a customer may receive a call from someone claiming to process their "refund," who then asks for an OTP, a UPI PIN, or remote access to their phone or your app to "complete" it. No refund on the Payonclick platform requires anyone to share a one-time code over a phone call.
- A refund to a wallet after a failed bill payment happens automatically; it does not require an OTP to be read out to anyone.
- If a customer mentions such a call, tell them to hang up immediately and never share an OTP or PIN with a caller, regardless of what the caller claims to know about their transaction.
- Report the genuine transaction status yourself through a support ticket rather than trusting what a caller says about it.
Cash handling: success first, cash second
Every cash service at your counter follows the same rule: cash leaves your drawer only after the app shows success, never before.
| Service | Wait for |
|---|---|
| AEPS cash withdrawal | The app showing the withdrawal as successful |
| Micro ATM withdrawal | The app showing the withdrawal as successful |
| UPI cash withdrawal | The success screen in your own app, not the customer's phone |
A pending status is not a success. If a transaction sits pending, use the manual Check Status option where it is available rather than guessing, and never repeat a transaction while the first attempt's result is unclear. Our pending and failed transaction guide covers what to do for every service.
Account security features already working for you
Your Payonclick account has several protections built in, so understand what they do and never try to work around them:
| Feature | What it does |
|---|---|
| TPIN lockout | Locks for 15 minutes after 5 wrong attempts |
| Password lockout | 3 wrong passwords within 24 hours locks the account; unlock by OTP reset or by an admin |
| Login OTP | A one-time code by SMS confirms a login from a device that isn't trusted |
| Single active session | Only one session is active on your account at a time |
| Trusted devices | Your account recognises devices you use regularly |
These features exist to slow down anyone other than you. Never share the OTP or code behind any of them, even with someone claiming to help you unlock your own account faster.
Where to report fraud
If you or a customer experience financial fraud, act quickly and report it through official channels:
- Call 1930 or file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in for financial fraud. The 1930 helpline is confirmed on the Ministry of Home Affairs' own announcement.
- Sanchar Saathi's Chakshu facility, at sancharsaathi.gov.in, lets citizens report suspected fraud calls, SMS or WhatsApp messages, including fake KYC or payment requests and impersonation of staff, banks or officials.
- Tell our support team too, through a ticket in the portal or app, or by phone or WhatsApp on +91 99926 88080, so we can look at your account if needed.
Save the customer support number, +91 99926 88080, and the 1930 helpline in your shop's phone. In the middle of a suspicious call, having the real number ready to dial makes it easier to hang up and verify.