Last reviewed: 1 September 2026.
Quick Reply: Got a call from “seller” asking for OTP to process refund? Never share. Block UPI mandate, file NCRP 1930, recover money under RBI 2017 rules.
RBI Ombudsman as of 1 July 2026: Bank, certain NBFC, prepaid-instrument and credit-information complaints go under the Reserve Bank - Integrated Ombudsman Scheme, 2026, which replaced RB-IOS 2021 from 1 July 2026. First complain to the entity. If there is no reply in 30 days (or the longer NPCI/card-network window, if it applies) or you reject the reply, file free at cms.rbi.org.in within 90 days. The Ombudsman can award up to Rs 30 lakh for consequential loss and up to Rs 3 lakh for time, expenses and harassment. Complaints received before 1 July 2026 stay under the 2021 scheme. Source: RBI FAQ, updated 1 July 2026 and the RB-IOS 2026 FAQ PDF dated 1 July 2026.
Quick Answer: No genuine seller, marketplace, courier, or bank ever needs your OTP to process a refund. Refunds always flow into your account through the original payment channel (UPI, card, wallet) and require no authentication on your end. The moment a “seller” or “support agent” calls you after a return or dispute and asks you to “share OTP,” “approve a request,” or “scan a QR code,” it is a confirmed scam attempt to either drain your account via a UPI autopay mandate or hijack your SIM/banking session. Hang up, do not press any number, and if you have already shared anything, dial NCRP 1930 within 60 minutes and freeze your bank account through the official channel. Report inside the zero-liability window — within 3 working days of the bank's alert — and the RBI's customer-protection circular of 6 July 2017 puts the entire loss on the bank.
A homemaker in Pune ordered a ₹2,400 air-fryer, returned it because the heating coil was defective, and waited for the refund. Three days later her phone rang. The caller knew her order ID, the return reason, the courier pickup date, even the partial UPI ID she had paid with. He said the “refund team” could not push the money back because of a “KYC mismatch” and asked her to read out a 6-digit code. She read it. Within 90 seconds ₹1,99,000 left her account in four UPI transactions, all showing as “approved by user” because she had unwittingly authorised an autopay mandate.
— an illustrative account. This guide walks through the same steps such a victim should take, and how the legal framework obliges the bank to refund money when you act inside the reporting window.
The “share OTP for refund” scam is a social-engineering attack that exploits the gap between when you expect money and when it actually arrives. The fraudster has either bought your order data from a leaky logistics partner, scraped it from a fake-courier phishing page, or simply guessed it after you posted a review. They call posing as the seller, the marketplace, the courier, or the payment gateway. The script is always the same:
What you are actually doing when you “share the OTP” is one of three things, depending on which variant the gang runs:
In all three the user has technically pressed “yes.” Do not blame yourself. Indian law treats unauthorised electronic transactions as the bank's liability the moment you report them inside the prescribed window.
One sentence ends every legitimate refund call: “You don't need to do anything, the money will reflect in 3 to 5 working days.” If the caller deviates from that, the call is fraudulent. Specifically:
Hang up. Do not be polite. Block the number, then forward the SMS (if any) to 1909, the DoT's spam-complaint number under the Telecom Commercial Communications Customer Preference Regulations.
The first hour is everything. The RBI's customer-protection circular of 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions creates three liability bands based on how fast you report. Inside the zero-liability band, the bank carries 100% of the loss. The three-day clock runs from when you receive the bank's communication about the transaction — usually the debit SMS itself — so report the same day.
Step 1, minute 0 to 5: dial 1930, the National Cyber Crime Helpline. It loops in every major bank's fraud desk, the issuing and beneficiary banks, and the payment system operator. Quote your UTR. The operator files a stop-payment request within minutes; if the money is still in the mule account, it gets frozen.
Step 2, minute 5 to 15: log into https://cybercrime.gov.in and file a written complaint under “Financial Fraud.” Save the acknowledgement PDF.
Step 3, minute 15 to 30: call your bank's 24×7 fraud line and block all digital channels: net banking, mobile banking, UPI handles, autopay mandates. Use the phrase “I am reporting an unauthorised electronic banking transaction under the RBI customer-protection circular of 6 July 2017.”
Step 4, minute 30 to 60: visit your branch with the acknowledgement, call recording (if any), and a written complaint to the Branch Manager. Get a stamped receipt.
Step 5, within 24 hours: revoke all UPI autopay mandates inside your app (Settings → Autopay → Active mandates → Revoke).
This is the sentence most victims never hear: the bank must refund you, by law, if you reported within the window. Stop apologising and start citing.
Shreya Singhal v. Union of India (2015) 5 SCC 1 held that an intermediary must disable offending content once it gains “actual knowledge” through a court or government order, or lose its safe harbour. Separately, your written grievance to the marketplace's Grievance Officer under the IT Rules 2021 creates a dated, enforceable trail.
Banks routinely tell victims “you yourself entered the OTP, so it is not unauthorised.” This is wrong in law. An OTP shared under deception is vitiated consent, like a signature obtained by fraud. Paragraph 12 of the RBI's 6 July 2017 circular puts the burden of proving customer liability on the bank — the bank must establish that you were negligent, and a code read out under deception is not free-flowing consent.
If your bank refuses to refund within 10 working days, escalate to:
A few telltale patterns that distinguish scammers from real customer-care agents:
This is the most expensive variant. An “approved” UPI autopay mandate gives a merchant standing instructions to debit your account up to a stated cap, daily, weekly, or monthly, for the life of the mandate, with per-transaction debits up to ₹15,000 requiring no further OTP. Fraudsters abuse this with shell merchant IDs.
To check for fraudulent mandates right now:
A detailed walkthrough is at the UPI autopay mandate fraud guide. For the “stuck UTR” problem, see UPI deducted but not received.
Platforms sometimes say “we don't make calls, contact your bank.” This is legally wrong if the scammer used data leaked from the platform: order ID, return reason, partial payment details, courier name. Under IT Act §43A and the 2011 SPDI Rules, the platform is a body corporate handling sensitive personal data and is liable for compensation if it failed reasonable security practices.
File a written complaint with the platform's Grievance Officer (every intermediary must publish the Grievance Officer's name and contact details under the IT Rules 2021). The Grievance Officer must acknowledge within 24 hours and resolve the complaint within 15 days (Rule 3(7)).
If refused, file at https://consumerhelpline.gov.in (Ministry of Consumer Affairs) or at the District Consumer Commission under the Consumer Protection Act 2019 (pecuniary jurisdiction up to ₹50 lakh).
Phone first, paperwork later. This sequence has the best documented recovery rate.
Save these immediately, because retrieving telecom and bank records gets harder with every passing week:
Send everything to the cyber-crime portal in one zip — the complaint form caps the number and size of attachments, so keep the file small.
If 30 days pass and your bank has neither refunded nor given a written explanation, an RTI to the bank's nodal Public Information Officer is the lever that breaks the silence. Public-sector banks (SBI, PNB, BoB, Canara, Union Bank, Indian Bank, etc.) are fully covered under the RTI Act 2005. Private banks are not directly covered, but the RBI is, and an RTI to the RBI asking “what action has the RBI taken on consumer complaint number XYZ filed against [bank name]” produces results.
Sample questions to ask under the RTI Act 2005:
Drafting an RTI to a bank's PIO is non-trivial and the wording matters. The free AI RTI Drafter generates a compliant draft with the correct statutory references in under 60 seconds. For background on how the RTI Act 2005 works end to end, the complete RTI guide is the master reference.
Recovery is partial, slow, and stressful. Prevention is total, instant, and free.
OTP-refund scams overlap with several adjacent fraud families. Each has its own dedicated guide:
If you only remember one thing from this article, remember this checklist. Save it to your phone gallery. The next time someone calls about a “refund,” open this image, follow the boxes in order:
In the illustrative case that opened this article, every rupee came back in 11 days because the steps were followed in order, without delay or self-blame. The law is on your side. Use it loudly.
Last updated: 2026-05-07. This article is not legal advice. For case-specific guidance consult a licensed lawyer or a recognised legal-aid clinic. Statute references current as of the date above; check the latest position before acting.