Skip to content
DnsLister Forum

Where domain hunters compare notes

Found a fake PhonePe-style recharge website through an Instagram ad investigated it and got it taken down

Found a fake PhonePe-style recharge website through an Instagram ad investigated it and got it taken down

I came across an advertisement on Instagram for a website claiming to offer extremely cheap mobile recharges. As a developer, I was curious about what was actually happening behind the scenes, so I opened the website to inspect it.

My first impression was basically: this looks like a scam.

The website was advertising ridiculously cheap recharge plans, such as ₹499 for 365 days, for operators like Jio, Vi, etc. That immediately raised a red flag because the pricing didn't make sense compared with legitimate operator plans.

The UI also looked very similar to PhonePe, which made me even more suspicious.

So instead of actually making a payment, I decided to investigate the payment flow.

What I found

I entered a random phone number just to see what payment methods were offered and proceeded to the checkout/payment page.

It offered UPI payment options, including a QR code.

When I tried the UPI intent option, the displayed merchant/payment name was simply:

«Mobile recharge»

That was already suspicious.

Then I selected the QR payment option and inspected the QR code rather than making any payment.

After decoding/inspecting the QR, I found the UPI ID:

«paytm.s417lzb@pty»

I then checked that UPI ID using PhonePe, and the recipient name displayed as:

«Santosh Kumar»

So we have a website presenting itself with a PhonePe-like interface, advertising unrealistic recharge prices, and ultimately directing payments toward a UPI ID associated with a personal name.

At that point, the whole thing looked extremely suspicious to me, and I did not make any payment.

What I did next

I reported the domain to its registrar, Internet.bs, with screenshots and the relevant information.

Unfortunately, I didn't receive an update from them.

So I also reported the website to the hosting/CDN provider, Bunny.net (Bunny CDN), explaining what I had found and providing screenshots and evidence.

And honestly, their response was surprisingly fast.

Their support team reviewed the report and took action, and the website subsequently went offline.

Huge appreciation to the Bunny.net team for taking the report seriously and acting quickly. 👍

Please be careful

The main reason I'm posting this is to remind people not to trust websites just because they appear in social-media advertisements.

A website can look polished, use familiar branding, show a QR code, and still be completely unrelated to the company it appears to represent.

Don't make a payment just because the website looks legitimate. Verify the merchant and payment recipient first.

I personally didn't fall for it I was just curious enough to inspect what the site was actually doing. 😄

I've attached screenshots of the website, recharge offer, payment interface, and QR/UPI information for reference.

Stay safe out there. 🚨

https://www.reddit.com/gallery/1wntgw3

Source: r/UPI · by /u/sabirans04

Leave a Reply

Your email address will not be published. Required fields are marked *