Loyalty program fraud: how brands get gamed and how to stop it
Every rupee a trade scheme puts on the table attracts two audiences: the retailers and influencers you built it for, and a smaller crowd working out how to take the money without moving the product. Fraud is not a reason to avoid trade schemes — brands that run them well hold leakage to low single digits — but it is a design discipline, not an afterthought. This is the full taxonomy of how Indian channel programs get gamed, the signals that expose each attack, and the layered controls that keep budgets honest without punishing genuine users.
Why trade loyalty attracts fraud in the first place
Trade programs pay real money — ₹5–15 per wire coil, ₹10–50 per paint pail, ₹30–100 per lubricant carton, 0.5–2% of invoice value on slabs — to hundreds of thousands of participants the brand has never met. The payout rail is instant UPI, the claim evidence is a QR scan or an invoice photo, and the people closest to the product (dealers, godown staff, field sales) understand the rules better than head office does. That combination — cash, scale, anonymity and insider knowledge — is exactly what fraud feeds on.
The economics matter too. On a house-wire counter earning 5–8% margin, a scheme worth 1–1.5% is a 15–25% profit uplift — worth participating in honestly. But for a dealer who can scan 500 coils in an afternoon at ₹10 each, that is ₹5,000 for an hour of a helper's time, repeated every dispatch. Fraud in trade loyalty is rarely a shadowy outsider; it is usually a channel partner arbitraging a control gap you left open.
A useful mental model: fraud rate is a design output, not a fate. Reward values set above the effort cost of gaming, codes printed where they can be photographed, payouts with no identity binding — these produce 10%+ leakage. The same budget with layered controls produces 1–4% flagged volume, of which perhaps half confirms as fraud. That is the healthy range, and this article is about how to get there.
The seven families of trade loyalty fraud
Dealer bulk scanning
The attack: the dealer or distributor scans QR codes on cartons in the godown before dispatch, capturing rewards meant for retailers, electricians or painters downstream. It is the single most common trade fraud because the dealer has physical custody of every code and idle staff to do the scanning. How it looks in data: hundreds of scans from one device or one UPI handle, at one lat-long, inside business hours, often in carton-sequence order (serial numbers ascending), with zero scans of those codes ever appearing downstream. Controls: per-device and per-account daily caps (e.g. 20–40 scans/day for a retailer identity, near-zero tolerance for a dealer identity scanning retail codes), geo-fencing against known godown locations, scan-sequence detection, and — strongest of all — a second inner code accessible only on opening the pack, so shelf scans and site scans must reconcile.
Code harvesting from photographs and waste
The attack: codes photographed on shelf stock, in transit or at a rival counter; discarded packaging collected from construction sites and kabadiwala channels; in the worst cases, code databases leaked from a printing vendor. Harvested codes get redeemed by people who never touched the product. How it looks in data: codes redeemed far from their dispatch territory, long gaps between dispatch and scan followed by sudden batch redemption, the same handful of accounts redeeming codes from many unrelated dealers' stock. Controls: scratch layers or inner-flap placement so an unsold product's code cannot be photographed; activation-at-dispatch so codes are inert until the brand ships them; territory validation; and printer-side security — split files, serialisation at a separate vendor, audit rights in the printing contract.
Mule UPI handles and identity farming
The attack: one actor registers many accounts — family members' SIMs, staff Aadhaar-linked numbers, purchased KYC kits — to multiply per-account caps and route payouts to handles that cannot be traced back. A dealer running bulk scans almost always pairs it with mule handles. How it looks in data: many accounts sharing a device fingerprint, IP range or delivery address; UPI handle names that do not match registered PANs; clusters of accounts created in one week that only ever redeem, never engage. Controls: device fingerprinting, one-PAN-one-account rules, UPI name-to-PAN fuzzy matching before first payout, cooling periods (72 hours to 7 days) on newly registered accounts, and payout caps that make farming uneconomic below the effort threshold.
Ghost retailers and fake enrolments
The attack: outlets that exist only on paper — enrolled by a field officer chasing an onboarding target, or invented by a dealer to absorb scheme allocations. Ghost outlets then become vehicles for pooled claims. How it looks in data: outlets with no geo-verified storefront photo, enrolments clustered on the last two days of the field team's target month, outlets whose claimed purchases never correlate with any dealer's dispatches to that pincode. Controls: geo-tagged storefront photo with GSTIN/shop-licence capture at enrolment, random physical audits (3–5% of new enrolments), enrolment-to-first-genuine-scan conversion tracking per field officer, and clawbacks on officer incentives when their enrolments go dormant.
Invoice doctoring and duplicate claims
The attack: in invoice-based schemes, the same invoice submitted twice (cropped differently), values inflated with editing tools, fake bills from cooperative wholesalers, or genuine bills claimed by someone other than the buyer. How it looks in data: hash-identical or near-duplicate images across accounts, invoice totals that are suspiciously round, invoice numbers out of sequence with the issuing dealer's known series, claimed volumes exceeding the dealer's primary offtake. Controls: perceptual image hashing, OCR cross-checks of GSTIN and invoice-number patterns, reconciliation of claimed secondary volume against primary billing per dealer per month, and random call-backs to issuing dealers.
Pooled billing and slab manipulation
The attack: three counters route purchases through one account to hit a higher slab or a trip target, then split the reward — or a dealer books month-end primary sales against a friendly retailer's name to dress up growth. Less larcenous than other frauds, but it corrupts your data and overpays the marginal rate. How it looks in data: one account's volume tripling in target months while neighbouring accounts go quiet; marginal payout at slab edges above ~6% (which makes pooling worth the coordination); purchases spiking on the last three days of every period. Controls: slab qualification on rolling 3-month averages rather than single months, GSTIN-matched billing, marginal-rate design that keeps the edge payout in the 2–6% band, and trip targets gated on monthly minimums rather than one annual number.
Employee and vendor collusion
The attack: the most damaging family. Field staff approving ghost claims for a cut, program admins with manual-credit rights topping up friendly accounts, printing-vendor staff leaking live code files, warehouse staff diverting scheme gift stock. Insider fraud is low-frequency but high-severity — single incidents can run into lakhs. How it looks in data: manual credits clustered under one admin login, approval rates near 100% for one field officer while peers reject 10–15%, gift-stock reconciliation gaps. Controls: maker-checker on every manual credit, immutable audit logs, admin-action anomaly reports reviewed by someone outside the program team, vendor NDAs with serialisation split across suppliers, and periodic surprise reconciliation of physical reward stock.
Detection: the signals that expose almost everything
Nearly every attack above leaves fingerprints in four signal families. A serious program scores every scan and claim against all four in real time, before money moves.
- Velocity. Scans per account per hour and per day; scans per device; payout value per account per week. A genuine electrician scans 3–15 units a day with natural gaps; a bulk scanner does 200 in ninety minutes. Velocity rules catch the crude majority of fraud on their own.
- Geo-clustering. Where scans happen relative to where product was dispatched, and how many accounts share a location. Fifty "retailers" scanning within a 30-metre radius of a known godown is not a coincidence; codes from a Nagpur dealer's stock redeeming in Patna is a harvesting chain. Practitioner benchmark: in a clean program, well under 10% of scan volume comes from dealer-location clusters; when it climbs past 20–25%, you are funding the godown, not the trade.
- Device and identity fingerprints. Device IDs, OS/browser signatures, IPs and SIM signals shared across accounts; UPI names diverging from registered names; PANs reused across "different" outlets. Identity graphs turn twenty innocent-looking accounts into one visible actor.
- Temporal patterns. Humans selling product scan across the day with lunch dips and evening peaks; fraud scans in tight bursts, after hours, or in serial-number order. Period-end spikes flag slab manipulation; long-dormant codes redeeming in batches flag harvested databases.
The output should be a per-transaction risk score with three bands: auto-approve (the vast majority — the happy path must stay instant), hold-for-review (step-up verification: selfie with product, OTP, invoice request), and auto-block. Modern platforms add ML anomaly detection on top, but the four rule families above catch 80–90% of losses and are explainable when a dealer disputes a suspension — which matters, because you will be having those conversations.
The layered control stack
No single control survives contact with a motivated dealer. Defence works in layers, each cheap on its own, expensive to defeat in combination:
- Physical layer: serialised one-time QRs, scratch panels or inner-pack placement, tamper-evident labels, a second inside-the-pack code for high-value SKUs. This is also where anti-counterfeit and loyalty share infrastructure — the same scan that pays the reward verifies the product is genuine.
- Data layer: activation-at-dispatch, territory mapping, one-time redemption, code status lifecycle (printed, activated, scanned, redeemed, blocked).
- Identity layer: PAN and UPI verification, device fingerprinting, one-identity-one-account, cooling periods on new accounts.
- Behavioural layer: velocity caps, geo rules, temporal anomaly scoring, risk-banded step-up friction.
- Economic layer: reward values below the industrial-gaming threshold, marginal slab rates of 2–6%, split payouts (part on purchase, part on verified sell-through), rolling-average qualification.
- Governance layer: maker-checker on manual actions, published penalty ladder (warning, forfeiture, suspension, termination), monthly fraud reviews with field-team accountability, and clean 194R/TDS handling so clawbacks do not create tax mess. Remember that Section 194R TDS at 10% applies once any participant's benefits cross ₹20,000 in a financial year — deduct before payout, because recovering tax from a mule handle after the fact is fantasy.
Worked example of the economic layer. Suppose a paint brand pays ₹40 per 20-litre pail scan. A dealer moving 600 pails a month could harvest ₹24,000 by bulk scanning — comfortably worth a helper's time. Now split the reward: ₹15 to the retailer on counter scan, ₹25 to the painter on an inner-lid code revealed at opening. The dealer's harvestable value drops to ₹9,000, each half needs a different identity type to redeem, and the two scans must reconcile within the platform. Add a 30-scan daily cap per retail account and the industrial version of the attack collapses to pocket change — without reducing what a genuine counter or painter earns.
What a healthy fraud dashboard looks like
Benchmarks from well-run Indian trade programs cluster in these ranges — treat them as instrument readings, not targets to hit exactly:
- Flagged volume: 1–4% of scans/claims held for review. Below 0.5% usually means blind spots; above 8–10% means either a detection tune-up or a program design that invites gaming.
- Confirmed fraud: 0.5–2% of gross claim value blocked or clawed back.
- False-positive friction: under 5% of genuine transactions should ever see step-up verification, and holds should clear within 24–48 hours — every day of delay in a held payout costs trust you paid marketing money to build.
- Dealer-cluster scan share: under 10% of volume from known dealer/godown geo-clusters, monitored weekly.
- Repeat-offender rate: falling quarter on quarter — if the same accounts keep reappearing, your penalty ladder is a suggestion, not a deterrent.
One caution from the field: fraud numbers spike at predictable moments — the fortnight before Diwali when festive schemes stack (see festive trade schemes), the closing week of annual trip qualifications, and the first month after any reward-value increase. Staff your review queue for those windows, and never launch a value increase without re-running the gaming arithmetic.
Finally, treat enforcement as channel management, not policing. Most first offences by genuine counters are opportunism, not organised crime — a warning plus forfeiture retains the counter and spreads the deterrent story through the market faster than any circular. Save termination and legal action for rings, insiders and vendors. The goal is not zero fraud; it is fraud held cheaply below the level where it distorts your data or your budget, while 96%+ of participants experience nothing but instant, reliable rewards. How you set those reward values in the first place is covered in our guides to budget planning and ROI calculation.
Frequently asked questions
What percentage of loyalty program claims are typically fraudulent?
Well-instrumented trade programs in India typically flag 1–4% of scan or claim volume for review, and confirm fraud on roughly half of what they flag. A program flagging under 0.5% is usually not looking hard enough; one flagging over 8–10% usually has a design problem — rewards set so high they invite industrial-scale gaming — rather than just a detection problem.
What is dealer bulk scanning and why is it the most common fraud?
Dealer bulk scanning is when a dealer or distributor scans QR codes on cartons in the godown before dispatch, capturing rewards meant for the retailer or influencer downstream. It is the most common fraud because the dealer has physical access to every code, a smartphone, and staff with idle time. It shows up as high-velocity scans from one device at one location during business hours, often in carton-sequence order.
How do fraudsters harvest QR codes without buying the product?
Common routes: photographing exposed codes on shelf stock or in transit, collecting discarded packaging from sites and kabadiwalas, leaked code databases from printing vendors, and social media groups where codes are traded. Defences are physical (scratch layers, inner-pack placement, codes revealed only on opening) plus digital (one-time redemption, activation-at-dispatch so unsold codes are inert).
Should a brand prosecute loyalty fraud or quietly block it?
For most trade fraud, blocking, clawing back points and suspending accounts is more practical than prosecution — the amounts per actor are small and the perpetrators are often your own channel partners. Reserve legal escalation for organised rings, employee collusion and printing-vendor leaks. What matters commercially is a published, consistently enforced penalty ladder: warning, points forfeiture, suspension, termination and blacklisting across schemes.
Do fraud controls reduce genuine participation?
Badly designed ones do — an OTP on every scan or manual approval of every claim will kill adoption among low-literacy users. Good programs keep the happy path instant (scan, validate, pay within seconds) and apply friction selectively: step-up verification only when risk signals fire, cooling periods only on new accounts, manual review only above value thresholds. Aim for under 5% of genuine transactions ever seeing extra friction.
Are fraud payouts subject to TDS under Section 194R?
TDS under Section 194R applies to benefits actually provided — so amounts paid out before fraud was detected have usually already suffered (or should have suffered) 10% TDS once the recipient crossed ₹20,000 in the financial year. Clawbacks and forfeitures need clean accounting entries. This is one more reason to detect before payout rather than after: recovering money and unwinding TDS from a mule UPI handle is close to impossible.