Quick Reply: Scammer asked you to scan a QR to receive money — and ₹X disappeared? Recover with 1930 + NPCI dispute + bank chargeback + RTI. Full 2026 guide.
RBI Ombudsman as of 1 July 2026: Bank, certain NBFC, prepaid-instrument and credit-information complaints go under the Reserve Bank - Integrated Ombudsman Scheme, 2026, which replaced RB-IOS 2021 from 1 July 2026. First complain to the entity. If there is no reply in 30 days (or the longer NPCI/card-network window, if it applies) or you reject the reply, file free at cms.rbi.org.in within 90 days. The Ombudsman can award up to Rs 30 lakh for consequential loss and up to Rs 3 lakh for time, expenses and harassment. Complaints received before 1 July 2026 stay under the 2021 scheme. Source: RBI FAQ, updated 1 July 2026 and the RB-IOS 2026 FAQ PDF dated 1 July 2026.
Search intent: Emergency / Recovery / Legal
You sold an old phone on OLX. The “buyer” said “I'll send the money — just scan this QR code to confirm receipt”. You scanned. Your bank app opened a payment screen — you typed your UPI PIN — and ₹15,000 left your account instead of arriving. This is a QR-code scam (a.k.a. “scan-to-receive” scam, quishing, or collect-request fraud). The scammer exploits a basic UPI rule: a QR or payment request can pull money out of your account; it never pushes money in. Recovery is racing the clock — the first 30 minutes matter most. MHA's Citizen Financial Cyber Fraud Reporting and Management System (1930) can freeze the recipient account before the money is withdrawn. BNS §318 (cheating), IT Act §66D (cheating by personation), and RBI UPI Guidelines govern liability. This is the complete recovery playbook for 2026.
| Section | What you'll get |
| — | — |
| Quick Answer | Authorities, deadlines, escalation path |
| Quick Action Steps | 12-step printable checklist |
| What Are Your Rights | A always / B with restrictions / C never |
| Real-World Patterns | 5 case studies of QR-code scams |
| Legal Framework | BNS, IT Act, RBI / NPCI / MeitY rules, judgments |
| Step-by-Step Process | 9 sequential moves |
| State-Wise Variations | Cyber cells + helplines |
| Sample Complaint Email | Ready-to-send template |
| Documents Required | Complete checklist |
| Common Mistakes | What citizens get wrong |
| FAQs | 15 frequently-asked questions |
| When to Hire a Lawyer | Triggers for professional help |
| Compensation Possibility | Recovery + bank chargeback |
| Important Numbers | 1930, NPCI, RBI, banks |
| Tools That Help | RTI Drafter, Appeal Builder |
| Internal + External Links | Allied resources |
🔔 Track UPI fraud advisories + RBI / NPCI rules by email. Help RTI Wiki yearly →
The trick is speed — 1930 freezes the recipient account before the scammer can move the money. After that, written records (RTI + Ombudsman) drive accountability.
Illustrative composites of commonly reported QR-scam fact patterns — not documented individual cases.
The right to safe banking + protection of property is part of Article 21 — K.S. Puttaswamy v. UoI (2017). Article 14 (equality) requires the state to treat cyber-fraud victims with the same diligence as physical-property cases. Olga Tellis (1985) on livelihood applies where stolen funds are wages or savings.
Call 1930. Open NCRP at cybercrime.gov.in. File UPI app dispute. Call bank UPI fraud line. The 1930 helpline triggers a freeze instruction to NPCI; NPCI sends an alert to the recipient bank to lien-mark the funds.
Submit detailed complaint at NCRP with all screenshots. Get NCRP complaint number. Bank will send T+0 acknowledgement of dispute.
File FIR at local cyber cell. Cite BNS §318 + §319 + IT Act §66D. Get FIR copy. Lalita Kumari (2014) makes registration mandatory.
Two parallel RTIs. Subject: “Application under §6 RTI Act 2005 — UPI fraud / QR-code scam at consumer no. [..]”. Fee: ₹10 IPO each.
1. Status of NCRP complaint [..] dated [..] and FIR [..] dated [..]. 2. Date and time the recipient account was frozen / lien-marked at NPCI level. 3. Action taken by Cyber Cell — IO assigned, evidence gathered, suspects identified. 4. Bank's NPCI dispute filing date, NPCI dispute reference, T+0 ack date. 5. Chargeback status — under processing / approved / rejected with reasons. 6. RBI circular of 6 July 2017 applicability — am I within the 3-working-day zero-liability window? 7. List of intermediary / mule accounts (anonymised) traced from the funds. 8. Action taken on my prior representations dated [..].
Track at npci.org.in → Dispute Tracking. T+45 disposal target.
Online at cms.rbi.org.in. Free. Cite RBI v. Jayantilal N. Mistry (2016) 3 SCC 525. Bank's failure to follow the RBI / NPCI timeline is the strongest ground.
If FAA dismisses or is silent, file Second Appeal with SIC within 90 days. Parallel Consumer Court complaint under Consumer Protection Act 2019.
Use RTI to track Cyber Cell investigation. Most cases trace to: a chain of mule accounts ending in ATM-cash withdrawal in another state. Recovery odds drop sharply once cash is out — the 1930 30-minute window is critical.
For losses > ₹1 lakh or pattern indicating organised syndicate, escalate to State EOW (Economic Offences Wing) and consider CBI if inter-state. NIA jurisdiction applies if linked to terror financing — rare but possible.
| State | Cyber Cell URL | Helpline (besides 1930) |
| — | — | — |
| Maharashtra | cyber.maharashtra.gov.in | 1930 / 022-22641133 |
| Delhi | cyber-crime.delhi.gov.in | 1930 / 011-23438400 |
| Karnataka | cybercrime.kar.nic.in | 1930 / 080-22094408 |
| Tamil Nadu | cybercrime.tnpolice.gov.in | 1930 / 044-2845-2222 |
| Telangana | cybercrime.telangana.gov.in | 1930 / 040-27852451 |
| Gujarat | dgp.gujarat.gov.in | 1930 / 079-2325-1900 |
| West Bengal | wbpolice.gov.in | 1930 / 033-2214-3260 |
| UP | uppolice.gov.in | 1930 / 0522-2390-484 |
| Kerala | keralapolice.gov.in | 1930 / 0471-2722-768 |
| Punjab | punjabpolice.gov.in | 1930 / 0172-2741-900 |
| Haryana | haryanapolice.gov.in | 1930 / 0172-2548-202 |
| Rajasthan | police.rajasthan.gov.in | 1930 / 0141-2741-900 |
For all states, 1930 is the single national financial-cyber-fraud helpline.
To: bo.[regional-rbi-office]@rbi.org.in
Cc: principal-officer@[your-bank].com; cyber-sp-[district]@[state].gov.in
Subject: UPI / QR-code fraud — consumer no. [XXXX-XXXX-XXXX] —
dispute under RBI circular of 6 July 2017 + Integrated Ombudsman Scheme, 2026
Sir / Madam,
I, [Name], hold account [XXXX-XXXX-XXXX] at [Bank Name], [Branch], IFSC [..].
On [date] at [time], I was a victim of a QR-code / UPI //collect-request//
fraud. The scammer represented [.. context — "OLX buyer" / "refund agent"
/ "tax officer" etc.] and induced me to scan a QR / approve a collect
request, resulting in unauthorised debit of ₹[..] vide UTR [..].
Timeline of my actions:
- [Time]: 1930 call — ack [..].
- [Time]: NCRP complaint — [..].
- [Time]: Bank UPI dispute — [..].
- [Time]: Bank fraud-helpline call — [..].
- [Date]: FIR filed — [..].
Statutory protections invoked:
1. RBI circular of 6 July 2017 — zero liability if reported within 3
working days. I reported within [..].
2. RBI / NPCI dispute timeline — bank must resolve within T+45.
3. //RBI v. Jayantilal N. Mistry// (2016) 3 SCC 525 — banks bound by the Ombudsman framework.
Relief sought:
- Refund of ₹[..] under the RBI circular of 6 July 2017.
- Disciplinary action against bank for non-compliance with NPCI timeline.
- Compensation for charges + interest + harassment.
Documents enclosed:
- Account statement showing fraudulent debit.
- 1930 ack + NCRP ack + FIR copy.
- Bank dispute filing screenshot.
- Chat with scammer + screenshots.
- Bank's reply (or absence thereof).
I file this complaint within 30 days of the bank's reply / non-reply and
well within the 90-day RB-IOS 2026 filing window.
Yours sincerely,
[Name + Account no. + Phone + Email]
A UPI QR (and a UPI collect request) generate a debit transaction from your account to the QR's owner. Receiving money requires the sender to scan your QR, not the reverse. Scammers exploit this asymmetry.
Yes — the transaction completes only after PIN. If you didn't enter the PIN, no debit happens. But your VPA may have been logged for future targeting; consider rotating it.
No — VPA alone is harmless. The PIN is required for any debit. But scammers use VPAs to send collect requests you might inadvertently approve.
Phishing through QR codes. The QR encodes a malicious URL that opens a fake banking page or initiates a payment.
Two rules suffice: (a) “never scan a QR to receive money”, (b) “call 1930 immediately if money disappears”. Write the two rules on a card and keep it in your wallet.
Yes, on grounds of customer negligence (e.g., shared PIN, approved transaction). The RBI circular of 6 July 2017 lays down nuanced rules — Banking Ombudsman often reverses bank denials.
Liability is on the scammer; merchant must report. Customers who paid the wrong QR can dispute. Use dynamic QR codes that change daily to prevent overlay attacks.
Generally no — UPI app routes the dispute through the bank. NPCI is an intermediary between banks. End-user refund happens via your bank's processing.
1930 is the phone-based front-end; NCRP is the web-based front-end. Both feed the CFCFRMS pipeline. File both for redundancy.
Reduced odds — recovery depends on whether mule account still has the money. Chargeback may still succeed via NPCI mechanism even if specific cash is out — banks adjust at network level.
Optional. Banking Ombudsman is faster (30-90 days). Consumer Forum (1-3 years) for damages > what Ombudsman can award (Ombudsman cap = ₹30 lakh consequential loss plus ₹3 lakh harassment under RB-IOS 2026).
Personal data of others (the scammer, mule accounts) is protected under §8(1)(j); aggregate data + your own data remain disclosable.
Yes — §6 RTI allows English or Hindi.
For amounts ≤₹50,000: 60-180 days. For high-value / syndicate cases: 6-18 months. Fact of investigation often pressures intermediary banks to cooperate on chargebacks.
Limited liability. IT Act §79 gives intermediary safe harbour subject to due diligence. If platform failed to remove flagged scammer profile, intermediary safe-harbour can be challenged.
Yes — multiple routes:
| Authority | Number / URL |
| — | — |
| Cyber-fraud / 1930 | 1930 (24×7) |
| NCRP | https://cybercrime.gov.in |
| RBI Banking Ombudsman | https://cms.rbi.org.in / 14448 |
| NPCI | https://www.npci.org.in |
| RBI Sachet (suspect entity) | https://sachet.rbi.org.in |
| MeitY | https://www.meity.gov.in |
| CERT-In | https://cert-in.org.in |
| Bank fraud helplines | SBI 1800-1234, HDFC 1800-202-6161, ICICI 1860-120-7777, Axis 1860-419-5555, PNB 1800-180-2222, BoB 1800-258-44-55 |
| NALSA legal aid | 15100 |
A QR-code scam exploits a single asymmetry of UPI: a QR pulls money out, never pushes it in. Recovery hinges on the golden 30 minutes — dial 1930 + file NCRP + bank dispute. The RBI circular of 6 July 2017 gives you zero liability if reported within 3 working days. The RBI Banking Ombudsman is free and binding. Consumer Forum + Article 226 writ give compensation. Lalita Kumari (2014) 2 SCC 1 and RBI v. Jayantilal N. Mistry (2016) 3 SCC 525 are your strongest anchors. The system works for fast, organised victims who document everything and use every parallel channel.
Last reviewed: 1 September 2026.