FRAUDJune 12, 2026 · 10 min read·0

Payment Scam Websites: 12 Red Flags Fraudsters Hope You Miss

The exact patterns that show up on fake checkout pages — newly-registered domains, hidden WHOIS, suspicious nameservers, fake trust badges, and the QR-code tricks costing Indians ₹400 crore a year.

R
DomainScan
𝕏 Share
Fraud

Payment scam websites are no longer the typo-ridden Geocities pages of the early 2000s. They’re pixel-perfect clones of real checkout flows, served over HTTPS, ranked in Google Ads, and engineered to push you past your own caution. The Indian Cybercrime Coordination Centre logged over ₹400 crore in online payment fraud in the last financial year alone — and the average loss per victim keeps going up.

The thing is, fake checkout pages all leak the same way. After you’ve looked at a few hundred of them, the patterns repeat. Below are the twelve red flags we see most often, grouped by where they show up: the domain, the page, and the payment moment.

How modern payment scams work

Three things make 2026’s payment scams different from the ones you grew up warned about.

  • The infrastructure is cheap and disposable. A scammer registers a domain, throws up a cloned store, runs a week of ads, takes the money, and abandons the domain before law enforcement can move. The whole cycle costs less than $50.
  • The bait is paid traffic, not spam email. Most victims land on a fake checkout via a Google Ad, an Instagram promotion, or a sponsored Telegram post — sources they implicitly trust.
  • The payment rails are irreversible. UPI, crypto, and bank transfer can’t be charged back the way card payments can. Scammers route you toward those rails on purpose.

Red flags #1–4: the domain itself

The fastest checks happen before you even read the page. Look at the URL bar.

  1. The domain is brand-new. Less than 90 days old is suspicious. Less than 30 days old, on a site that’s actively selling, is a near-certain scam. WHOIS shows registration date in seconds.
  2. The WHOIS is fully redacted. Privacy services are normal — most real domains use them. What’s not normal is a redacted record on a domain claiming to be a registered Indian company with a GSTIN. Real businesses verify their registrant details for credibility.
  3. The TLD is obscure. Real Indian retailers use .com, .in, or .co.in. Be cautious of .xyz, .top, .shop, .online, and .store on sites pretending to be major brands. Those TLDs are cheap and dominate scam registrations.
  4. The URL has a brand name plus a suffix. flipkart-deals.store, amazon-india-offer.xyz, myntra-sale.top — real brands own their root domain. They don’t run promotions on a separate suspicious URL.
Check WHOIS and domain age
Registration date, registrar, privacy status — the first signals to verify.
Try it

Red flags #5–8: the page you land on

Once you’re on the page, the next signals are visual and structural.

  1. Discounts that don’t match the brand’s history. 80–90% off iPhones, branded shoes “clearance” sales, ₹999 PS5s. Real brands have margin floors. If the price breaks the floor, the page is fake.
  2. Mismatched logos and trust badges. Look closely. Fake sites grab logos from Google Images and shove them in. Resolution is off, colors are slightly wrong, badges link nowhere or to dead URLs. Click the “Verified by Visa” badge — on a real site it goes somewhere; on a scam site it doesn’t.
  3. No working customer support. Phone numbers that don’t connect, email addresses on free Gmail accounts, chat widgets that auto-respond with generic text. Real retailers, even small ones, have at least one channel that actually replies.
  4. Trust signals point nowhere. “Trusted by 50,000 customers” with no reviews. A Trustpilot widget that doesn’t link to a real Trustpilot profile. “Featured in Forbes” with no actual article. Each of these alone is weak signal; three together is a pattern.

Red flags #9–12: the payment moment

The moment you click Pay is when the scam earns its money — and where it’s the most obvious if you know what to watch for.

  1. The checkout URL changes to a different domain. Real payment gateways open in a subdomain of the merchant or in a clearly-branded gateway page (Razorpay, Stripe, PayU). If the URL jumps to something completely unrelated mid-checkout, stop.
  2. The site insists on bank transfer or UPI only. Scammers avoid card payments because cards can be charged back. If a site refuses cards, refuses cash on delivery, and pushes hard toward direct UPI or NEFT — that’s deliberate.
  3. The UPI ID looks personal. vinod.kumar1987@oksbi on a checkout page claiming to be a registered company. Real merchants have business UPI handles ending in things like @axisb, @razorpay, or @hdfcbank — never a personal Gmail-style handle.
  4. Pressure tactics during payment. Countdown timers that reset, “only 1 left in stock,” popups that say someone else is buying it right now. Real e-commerce uses urgency too, but scam sites lean on it because urgency stops people from running the checks above.
Hard rule
If the site refuses card payments and only accepts UPI / bank transfer / crypto — walk away. Even if the offer is real, you have no recovery path if anything goes wrong.

India-specific: UPI & QR scams

A few patterns deserve a paragraph of their own because they’re uniquely Indian and uniquely successful.

  • The collect-request flip. You’re trying to receive money (refund, prize, sale proceeds). The scammer sends a UPI collect request that looks like an incoming credit. You approve it, and you’re actually authorizing a debit. Always read the request — “Pay ₹X to Y” means you’re paying, not receiving.
  • The dynamic QR. Scammers print QR codes that lead to a fake payment page, not a real UPI intent. The fake page asks you to enter your UPI PIN to “confirm” — a real UPI flow only ever asks for the PIN inside your bank’s app, never on a webpage.
  • The “test transaction.” The scammer offers to send a small amount to verify your account. They send ₹1, then ask you to send ₹1 back to “confirm” — and now they have your UPI handle, your phone number, and your willingness to transact. The real attack comes next.

What to do if you spot any of these

Spotting one red flag means slow down. Spotting two means run a full check. Spotting three or more means leave the site without paying, and report it.

  1. Don’t pay. Even if you’ve already added items to a cart, the loss of a few minutes is nothing compared to the loss of the money.
  2. Run a Domain Trust Score scan. WHOIS, SSL, DNS, blacklist — all in one place. Takes under a minute and confirms what your gut is telling you.
  3. Report it. File on cybercrime.gov.in if you’re in India. Report to Google Safe Browsing. Report to the brand being impersonated — they often have a security team that takes these down within hours.
  4. Warn the next person. Post the URL (with hxxp:// instead of http:// so links don’t auto-render) in any group where the same scam might spread.
Scan a suspicious URL
Twelve checks composited into one Trust Score. Free, no signup.
Try it

FAQ

What is the most common payment scam website pattern in India?

The brand-impersonation discount page: a clone of a major retailer (Flipkart, Amazon, Myntra, Croma) on a lookalike domain, advertising 70–90% off via paid ads, accepting only UPI. It’s the highest- volume pattern by far.

Can a website with HTTPS still be a scam?

Yes. HTTPS only encrypts the connection. It doesn’t verify the operator’s honesty. The majority of payment scam sites in 2026 have valid SSL certificates from free authorities like Let’s Encrypt.

How fast can a fake checkout page disappear?

Often within 7–14 days. Scammers run a domain for as long as it takes to get noticed, then move to a fresh one. This is why domain age is such a strong signal — the scam is racing against detection from day one.

Are UPI scams reversible?

Rarely, and only if you act fast. Report to your bank within 24 hours, file on the national cybercrime portal, and request a hold on the recipient’s account. Recovery rates drop sharply after the first day and approach zero after a week.

#payment scam#fake checkout page#UPI fraud#online payment fraud#phishing website#red flags#scam detection
R
Writes about online fraud, payment security and the patterns scammers reuse until they get caught.
RELATED POSTS
NEW POSTS, NO SPAM

One short email when we publish.

~2 posts a month, no marketing, unsubscribe in one click.