Table of Contents

Courier OTP scam India 2026: immediate action

Report a courier OTP or remote-access fraud immediately

A caller who claims that a parcel is blocked by a courier, customs, police or another agency may be trying to frighten you into sharing an OTP, installing remote-access software or transferring money for “verification.” No caller can make a bank account safe by asking for an OTP, UPI PIN, password or transfer to a so-called secure account.

Act now: End the call and disconnect any remote-access session. Contact your bank through its official app, card or website and report the transaction immediately. Call 1930, then complete the complaint at cybercrime.gov.in as instructed. Save the bank complaint number, cybercrime acknowledgement, transaction reference, caller number and screenshots. Prompt reporting improves the chance of stopping funds, but no channel can guarantee recovery.

Searches for courier OTP scam, parcel scam India and OTP fraud report should produce a bank ticket and a cybercrime acknowledgement — not a private “customs refund helpline”.

How the courier OTP scam works

The play is a fear script, not a logistics problem. Typical stages:

  1. A call, SMS or WhatsApp claims a parcel in your name is held by a courier, customs, police or narcotics unit, often for contraband, undeclared cash or “illegal documents”.
  2. The caller is “transferred” to a person using a police, CBI, customs or court title. The displayed number may look official; caller-ID can be spoofed.
  3. You are told arrest, a lookout circular or attachment of property will follow unless you “verify” the account, pay a fee or install a remote-access app so that “support can secure the account”.
  4. An OTP, UPI PIN, net-banking password or screen-share is obtained. Debits follow within minutes, often through more than one mule account.

Related scripts: digital-arrest scam and fake customer-care numbers. A genuine courier, customs office or police station does not collect an OTP or UPI PIN over the phone. A genuine legal process uses a written notice or summons through proper channels, not a video call that demands a transfer.

If you only received the call and shared nothing, still preserve the number and report the suspected fraud communication through Chakshu; see report a scam call. If money moved, Chakshu is not the recovery channel — use the bank, 1930 and the cybercrime portal first.

First 15 minutes

  1. End the contact. Do not continue a video call, “digital arrest,” screen share or transfer.
  2. Disconnect the affected device. Turn off its mobile data and Wi-Fi if a remote-access app or unknown profile is active.
  3. Call the bank immediately. Use a verified official number and ask it to block the affected account, card, UPI or payment channel as appropriate and register an unauthorised-transaction complaint.
  4. Call 1930. Give accurate transaction, bank, mobile and time details. Record the acknowledgement or follow-up instruction. A longer script is on the 1930 helpline page.
  5. Report at cybercrime.gov.in. Complete the online report promptly and upload the evidence requested. Portal walkthrough: file a cybercrime complaint.
  6. Do not send more money to “release,” “verify,” “reverse” or “unfreeze” the first transaction. A recovery agent who contacts you unexpectedly may be another fraudster.

Have these facts ready for the bank and 1930: your name and the mobile you are calling from; bank or UPI app and the affected account (enough to identify the debit, not the password); UTR / transaction ID, amount, date and time; the displayed caller number; whether a remote-access app was installed; the beneficiary account, UPI ID or QR if shown.

If remote-access software was installed

From a different, trusted device:

If it is safe, record the remote-app name, session ID, permissions and installation time before removing it. Then disable its permissions and uninstall it; do not leave an attacker connected merely to preserve evidence. If the device still behaves unexpectedly, keep it offline and obtain trusted technical help before using it for banking again.

OTP-scam reporting steps after the first hour

Once the emergency block and 1930/portal filings exist, complete this sequence. It is the practical OTP fraud report trail.

  1. Confirm the bank ticket in writing. Use the official app dispute flow or email the branch / grievance officer from the bank's website. Ask for a written acknowledgement that identifies the transaction, the time you reported, and the action taken (block, dispute, recall request). Do not assume the 1930 call is automatically the bank dispute.
  2. Complete the cybercrime portal form with a chronology, not a legal essay. Who called, what was claimed, what credential or app was obtained, which debit followed, when you reported to the bank. Upload screenshots the portal asks for.
  3. Report the displayed number on Chakshu as suspected fraud communication if you still have it: Sanchar Saathi Chakshu. That does not replace 1930 after a debit.
  4. Check SIMs issued in your name on TAFCOP / Sanchar Saathi if the caller knew KYC details or an unknown connection appears. Related: unknown mobile numbers in my name and SIM-swap recovery.
  5. Raise the UPI or card dispute through the official app or bank, following NPCI's current sequence on its dispute page where UPI is involved.
  6. Keep one chronology file with every acknowledgement. Track the cybercrime record on cybercrime complaint status.

Prompt reporting gives banks and the portal an earlier chance to act. It is not a published recovery percentage, a “golden hour guarantee”, or proof that a mule account still holds the money.

Documents folder for the first visit

Create the folder on a trusted device, not on the compromised phone if remote access is still possible.

If you still have the number and no money moved, report it on Chakshu as suspected fraud communication. If money moved, do that after the bank and 1930 filings, not instead of them. TRAI's UCC / 1909 route is for spam, not for a debit already taken.

Worked example — illustrative, not a reported case

A caller claims a parcel contains illegal goods and demands a verification OTP. The recipient shares nothing, ends the call, screenshots the number and reports it through Chakshu. If she had read an OTP aloud and seen a debit, she would first call the bank, call 1930 and complete cybercrime.gov.in, then check TAFCOP only if unknown SIMs appear in her name. She would not pay a second “customs release” and would not keep a remote-access app connected “for evidence”.

Evidence to preserve

  1. bank transaction alert, statement entry and UTR/reference number;
  2. caller number, call time and call log;
  3. SMS, chat, email and fake parcel or police document;
  4. remote-app name, session ID and permission screenshots;
  5. bank complaint number and time of reporting;
  6. 1930 and cybercrime.gov.in acknowledgement;
  7. any beneficiary account, UPI ID, wallet or QR details.

Keep originals. Share copies only through verified bank, police or government channels, and mask unrelated account and identity data.

Sample complaint text for the cybercrime portal

Adapt this into the portal's narrative box. Use displayed numbers and placeholders. Do not invent a courier company as the accused merely because its brand was spoken on the call.

On [date] at about [time] I received a call/SMS/WhatsApp from displayed number [number] claiming that a parcel in my name was held by [courier / customs / police title as spoken]. The caller asked me to [share OTP / UPI PIN / install named remote-access app / transfer ₹ amount].

I [did / did not] share [OTP / PIN / screen]. At [time] my [bank / UPI app] showed a debit of ₹[amount], UTR / reference [number], to [beneficiary as shown].

I ended the contact at [time], called the bank at [time], ticket [number], and called 1930 at [time], acknowledgement [number].

I request recording of this online financial fraud, examination of the payment trail, and a written acknowledgement. I am not asking the portal to treat a genuine courier as guilty solely because its name was used on the call.

Sample written dispute to the bank

To
The Branch Manager / Grievance officer
[Bank name], [branch or official email from the bank website]

Subject: Unauthorised electronic transaction after a courier-OTP / remote-access deception — account ending [XXXX]

Sir / Madam,

I, [name], hold account ending [XXXX]. On [date time] ₹[amount] was debited vide [UTR]. I reported this to your official channel at [time] under ticket [number], and to 1930 / cybercrime.gov.in under acknowledgement [number].

Please: (1) keep the affected channel blocked; (2) register this as an unauthorised-transaction complaint; (3) consider recall, lien, chargeback or the dispute process that applies to this channel; (4) preserve logs for the investigating agency; (5) give a written decision that identifies the transaction, the facts relied on and the RBI / Board policy applied.

I will not share OTP, UPI PIN or remote access with anyone claiming to be from the bank.

[Name] [mobile] [date]
Attachments: statement extract, SMS alerts, 1930/NCRP acknowledgement, call-log screenshot.

Bank liability is fact-specific

RBI's customer-liability framework distinguishes bank deficiency, third-party breaches and loss caused by customer negligence such as sharing payment credentials. Where the loss is due to customer negligence, the circular says the customer bears the loss until the unauthorised transaction is reported; loss occurring after the report is borne by the bank. Other zero- or limited-liability rules depend on the cause and reporting time.

This means prompt reporting is essential, but deception does not create an automatic refund. Ask the bank for a written decision that identifies the transaction, the facts relied on and the applicable policy or RBI rule. A fuller recovery ladder is on online payment fraud recovery. If the bank later freezes the account because a disputed credit passed through it, that is a different problem — use bank freeze after cyber fraud.

Raise the payment dispute

Report the unauthorised transaction to the bank even if a complaint has already been filed with 1930. Use the bank or payment app's formal dispute flow and save its service request.

For UPI, NPCI publishes an escalation sequence through the UPI app/provider, its partner bank, the account-holding bank and then NPCI, depending on the unresolved complaint. Follow the current sequence shown on the official dispute page; do not pay a third party to open a dispute.

Cybercrime portal and police follow-up

The Citizen Financial Cyber Fraud Reporting and Management System connects 1930 reporting with participating financial entities so that lawful action can be attempted quickly. The National Cyber Crime Reporting Portal routes complaints to the concerned State or Union Territory law-enforcement agency, which handles investigation and FIR action under applicable law.

Describe facts rather than guessing legal sections: who contacted you, what was represented, what access or credential was obtained, which transaction followed, and when each report was made. If police needs additional records, provide them against an acknowledgement.

For a fuller walkthrough, see how to report a cybercrime complaint and the digital-arrest scam guide.

Escalate an unresolved bank complaint

First make a written complaint to the regulated bank or payment entity. If its reply is unsatisfactory, or it does not reply within 30 days, the RBI's Integrated Ombudsman mechanism may be available through cms.rbi.org.in, subject to the scheme's maintainability rules. The service is free. A longer path is the banking ombudsman guide.

An Ombudsman complaint should include the original bank complaint, acknowledgement, response if any, statement, transaction reference, timeline and the remedy requested. Do not copy the RBI portal on an initial email and treat that as a filed complaint.

Sample RTI for a stalled cybercrime complaint

RTI can seek the action recorded on an acknowledgement. It cannot freeze an account or order a refund. Use RTI for cybercrime complaint status and file RTI online.

To
The Public Information Officer
[Ministry of Home Affairs / the State police cyber unit named on the acknowledgement]

Subject: Information under the RTI Act, 2005 — cybercrime acknowledgement [number]

Sir / Madam,

Under section 6(1) of the RTI Act, 2005, please provide:

1. The current status recorded against acknowledgement / complaint [number] filed on [date] at cybercrime.gov.in / 1930.
2. The date the complaint was forwarded or assigned, and the designation of the unit currently holding it.
3. The action recorded (without disclosing exempt personal data of third parties).
4. Any recorded reason if the complaint is closed or returned.

I enclose the prescribed fee. Please reply within the statutory period.

Name:
Address:
Mobile:
Date:

Do not ask the PIO for the name of the subscriber behind a spoofed number as a fishing request.

What not to do

Frequently asked questions

What should I do first after sharing an OTP?

Contact the bank through an official channel and report the unauthorised transaction immediately, then call 1930 and complete the cybercrime.gov.in complaint as instructed.

Does calling 1930 guarantee recovery?

No. It enables rapid reporting and an attempt to stop the movement of funds, but recovery depends on the transaction trail and action by banks and law enforcement. There is no official recovery percentage attached to a “golden hour”.

Should I keep a remote-access app installed for evidence?

Do not leave an attacker connected. If safe, record the app name, session details and permissions, then disable access and uninstall it. Keep the device offline if compromise may continue.

Will the bank refund me if I was tricked into sharing an OTP?

Not automatically. RBI's framework treats customer negligence and third-party or bank-side breaches differently. Report immediately and ask for a reasoned written decision on the facts.

Can I file only on cybercrime.gov.in and skip the bank complaint?

No. Report to the bank immediately as well. The bank complaint and payment dispute are separate from the cybercrime report.

When can I approach the RBI Ombudsman?

First complain to the regulated entity. If its response is unsatisfactory or there is no response within 30 days, check the current Integrated Ombudsman rules and file through CMS if the complaint is maintainable.

Should I cite criminal-law sections in my online complaint?

You do not need to diagnose the offences. Give a precise chronology and evidence; the concerned law-enforcement agency determines the applicable provisions and investigation steps.

Is the genuine courier automatically liable because its name was used?

No. Impersonation alone does not prove a failure by the genuine courier. Prioritise the bank, 1930, cybercrime portal and police trail, then evaluate any separate consumer claim on its own evidence. A parcel that a genuine operator actually held is a different problem; see Speed Post / parcel loss if the article is an India Post consignment.

Official sources