Quick Reply: Your bank called, you shared the OTP, and money vanished. Here is how to freeze your account within minutes and use the RBI limited-liability rule to get it back.
Reviewed on: 2026-06-19.
Direct answer. Call your bank immediately to block your account, then dial 1930 and file a complaint at cybercrime.gov.in. Under the RBI's July 2017 circular, reporting quickly limits your liability, and the bank must credit the disputed amount within 10 working days of your complaint while it investigates.
The call sounded legitimate. The caller knew your name, last four card digits, and even your recent transaction. They said your account was flagged for fraud and that you needed to “verify” your identity by sharing an OTP sent to your phone. You shared it. Within seconds, money left your account.
This is a vishing attack (voice phishing) built around OTP capture. The criminal had already obtained your card details, possibly from a data breach or a phishing SMS, and needed only the one-time password to push through a transaction. Sharing the OTP is the trigger, but the RBI's limited-liability rules still offer you a path to recovery, provided you act fast.
This page focuses on the OTP/vishing modus and the steps to freeze your account and file a claim. For the broader process of disputing fraudulent transactions across any channel, see how to get your money refunded after cyber fraud. If the scammer also ported your SIM to steal OTPs going forward, read SIM swap fraud: what to do next.
Do not read the rest of this article first. Open your banking app or call your bank's 24-hour helpline and do all of the following:
Most private and public sector banks have 24-hour helplines accessible from the number on the back of your card or on their official website. If you cannot reach your bank, walk to the nearest ATM and block your card yourself using the ATM menu.
The National Cybercrime Helpline 1930 is operated by the Ministry of Home Affairs. When you call, you report a financial fraud. The operator logs your complaint and can coordinate with banks to flag the account where the money landed, making it harder for the fraudster to withdraw it.
You must also file a written complaint at cybercrime.gov.in:
File this complaint on the same day. The earlier the complaint reaches the portal, the sooner law enforcement can coordinate a freeze on the destination account through the Citizen Financial Cyber Fraud Reporting and Management System.
On the next working day, visit your branch and submit a written complaint. Bring:
Ask the branch to mark the complaint as an “unauthorised electronic transaction” under the RBI circular dated 6 July 2017 (reference: DBR.No.Leg.BC.78/09.07.005/2017-18). Use that exact phrase. It triggers the bank's obligation to handle the complaint under a defined timeline.
The Reserve Bank of India circular of 6 July 2017 sets out when a bank must refund you and how much.
Zero liability (full refund): You owe nothing and must be refunded in full if:
Critical point on OTP sharing: The circular classifies OTP sharing as customer negligence because you shared a credential. However, this does not end your claim entirely. Post-reporting liability shifts to the bank. That means any debit that happens after the moment you notified your bank is the bank's responsibility, not yours. The bank must also prove that the fraud was your fault; the burden of proof lies with the bank, not with you.
Limited liability (partial refund) for delayed reporting:
| Delay in reporting | Account type | Maximum customer liability |
|---|---|---|
| 4 to 7 working days | BSBD / Jan Dhan account | Up to Rs 5,000 |
| 4 to 7 working days | Savings account, prepaid card, MSME account (limit below Rs 25 lakh) | Up to Rs 10,000 |
| 4 to 7 working days | Other current / cash credit accounts (limit above Rs 5 lakh) | Up to Rs 25,000 |
| Beyond 7 working days | All accounts | Bank's board-approved policy applies |
Bank's obligation after you report:
If the bank rejects your claim without a satisfactory explanation, or does not respond to your written complaint within a reasonable period (verify the current eligibility window on cms.rbi.org.in), escalate to the RBI Integrated Ombudsman:
You can also contact how to report cyber fraud via 1930 for guidance on escalating your cybercrime complaint to the state police cyber cell.
| What the caller said | Reality |
|---|---|
| “I am calling from your bank's fraud department.” | Real bank staff never ask for OTP, CVV, or PIN over the phone. |
| “We need to verify your identity with the OTP.” | OTPs authorise transactions, not identities. Sharing one completes a payment. |
| “This will cancel the fraud on your account.” | There is no procedure where an OTP cancels fraud. |
| “Your account will be blocked if you do not cooperate.” | You can block your own account; no OTP is involved. |
A genuine bank security call will ask you to visit a branch or use the official app. It will never ask for a one-time password, full card number, PIN, or internet banking password.
Possibly yes, in part. Sharing the OTP counts as negligence under the RBI circular, so you may not get a zero-liability refund. However, any debit after you report to the bank is the bank's responsibility. File your complaint immediately and let the bank determine liability. If you disagree with their decision, escalate to the RBI Ombudsman. Do not assume you have no claim.
Within three working days of the bank's alert SMS or email. Reporting sooner, ideally within hours, also helps law enforcement freeze the destination account before the fraudster withdraws the money.
If the bank failed to send an SMS or email alert (which they are required to do), that counts as negligence on the bank's side. Mention this explicitly in your written complaint and to the Ombudsman.
An authenticated transaction is not the same as an authorised transaction. You were deceived into sharing the OTP. File your complaint using the RBI circular reference (DBR.No.Leg.BC.78/09.07.005/2017-18) and escalate to the Ombudsman if the bank refuses to process your claim.
Yes. A cybercrime portal complaint and an FIR are separate. Visit your local police station or state cyber cell and file an FIR under relevant provisions of the IT Act 2000 and BNS 2023. The FIR strengthens your case if the bank disputes your claim or if you pursue the matter in court.
Raise a dispute directly in the UPI app (Google Pay, PhonePe, Paytm) under “Help” or “Dispute.” Also report to your bank, as the bank linked to your UPI handle processes the dispute. Timelines and chargeback procedures vary by bank; verify the current process on npci.org.in or with your bank's customer care.
The RBI Integrated Ombudsman can direct the bank to refund the amount lost and award additional compensation for harassment or deficiency in service. There is no filing fee. Check the current award limits on cms.rbi.org.in before filing.
File an RTI to: Reserve Bank of India (the public authority that regulates bank fraud reporting obligations and runs the Ombudsman scheme)
Use an RTI application under Section 6(1) of the RTI Act 2005 addressed to the Central Public Information Officer, Reserve Bank of India, to ask:
→ Use our free AI RTI Drafter to generate a complete Section 6(1) application.
Helpline: Cybercrime National Helpline 1930 (24 hours). RBI Complaint Management System: cms.rbi.org.in.
By Dr. Shrawan Kumar Pathak
| Scam Type | How it works | Red flags |
| Fake SMS forward | Scammer calls claiming to be from bank/RBI, asks you to forward the OTP SMS to a number | No bank ever asks you to forward OTPs |
| SIM swap fraud | Scammer obtains a duplicate SIM using fake KYC, receives your OTPs directly | Your phone suddenly loses signal for no reason |
| Screen mirroring app | Scammer asks you to install AnyDesk/TeamViewer for “ KYC verification”, sees OTP on screen | No bank asks you to install remote access apps |
| Malicious link | SMS with link to fake bank website that captures login + OTP | Check URL carefully; official sites use .gov.in or bank domains |
| WhatsApp impersonation | Scammer poses as family member on WhatsApp, asks for OTP sent to your number | Always verify by calling the person directly |
| Investment scam OTP | Fake trading app asks for OTP to “activate account”, drains linked bank account | Verify SEBI registration at sebi.gov.in before investing |
Under RBI Master Directions on Customer Liability (2017, updated), the customer liability is limited as follows:
| Scenario | Customer liability | Time to report |
| Unauthorised transaction, reported within 3 days | Zero liability | Within 3 working days of receiving communication from bank |
| Reported within 4-7 days | Limited to the transaction value (subject to caps) | Within 4-7 working days |
| Reported after 7 days | As per bank policy; full liability may apply | Beyond 7 working days |
The zero liability applies when the fraud is due to bank system failure, third-party breach, or contributory negligence of the bank. For customer negligence (sharing OTP), banks may still process the claim but the outcome depends on the investigation.
Key action: Report immediately to your bank and file a police complaint within 3 days to maximise zero liability protection.
For a detailed guide on UPI and digital payment fraud, see UPI Fraud Complaint Guide and Fake Fund Recovery Agent Scam.
For RTI templates, see Best RTI Questions and First Appeal Guide.