Get the RTI Wiki appFree on iPhone and Android.

Online payment fraud: recovery steps and bank liability

Immediate steps after UPI, card, wallet or net-banking fraud

Speed matters after an unauthorised or fraud-induced payment, but no channel can promise recovery. Your job is to stop further access, alert the bank through an official channel, call 1930, create a National Cyber Crime Reporting Portal record and preserve evidence. The legal position then depends on how the transaction occurred, who was negligent, when the bank was notified and what the bank's terms and RBI rules require.

Quick answer: Call 1930 promptly for cyber financial fraud, report at cybercrime.gov.in, and notify the bank or payment provider immediately using the number or in-app route from its official website. Block compromised cards, UPI access, net banking and SIM access as needed. Save the transaction ID, UTR, amount, time, beneficiary, screenshots and complaint references. Do not pay a “recovery agent”, scan a QR code for a refund or share an OTP or UPI PIN.

Searches for online payment fraud recovery India and UPI fraud complaint should produce a 1930 acknowledgement and a bank ticket — not a private “refund cell”. Rapid reporting is useful. It is not a published golden-hour recovery rate.

Recovery ladder: where to file what

Use this ladder in order. Parallel unofficial “recovery agents” are a second scam.

Step Channel What you are asking for
1. Stop further loss Official bank / UPI / card app; operator if the SIM died Block card, UPI, net banking; freeze further access
2. Report the cyber financial fraud 1930 then cybercrime.gov.in Acknowledgement; attempt to flag the payment trail
3. Open the bank dispute Bank fraud desk + written complaint Ticket, identification of the debit, dispute / recall / chargeback as applicable
4. Preserve evidence Your own folder + portal uploads Chronology the bank and police can use
5. Escalate a service failure Bank nodal officer, then cms.rbi.org.in after 30 days if maintainable Review of the regulated entity's handling, not a criminal investigation
6. Consumer route if it is a genuine seller dispute NCH / e-Jagriti Seller or platform deficiency — not a substitute for 1930 after a scam debit

If the account is later frozen because a disputed amount passed through it, that is a different problem from seeking reimbursement as the victim. Use bank freeze after cyber fraud. The 1930 call script is on the 1930 helpline page.

First 15 minutes: stop further loss

Use a safe device if the phone may be remotely controlled or infected.

  1. Disconnect a remote-access or screen-sharing session.
  2. Ask the bank to block or restrict the affected card, account channel or UPI access.
  3. Change the bank, email and wallet passwords from a trusted device.
  4. If the SIM has unexpectedly stopped, contact the operator and follow the SIM-swap response steps. Check unknown connections on TAFCOP / Sanchar Saathi.
  5. Call 1930 and record the acknowledgement.
  6. File or complete the report at the official cybercrime portal.
  7. Do not delete the app, chats, call log or payment notification until evidence is preserved.

An authorised payment induced by deception and a technically unauthorised transaction may be treated differently by the bank. Report the facts accurately rather than describing every scam as “hacking”.

Information to collect before reporting

Field Where to find it
Amount, date and exact time Bank or wallet transaction history
UTR, UPI reference or transaction ID Payment detail screen or statement
Beneficiary VPA, account, merchant or wallet Transaction detail and receipt
Your bank and payment channel App, card, net banking, wallet or QR flow
How the fraud happened Call, fake support, collect request, remote access, phishing, SIM swap or account takeover
Suspect contact Phone number, email, social account, website or app identity
Evidence Screenshots, chat export, URL, call log, invoice and device alert
Reports already made Bank ticket, 1930 acknowledgement and NCRP report number

Never publish unmasked bank, card, Aadhaar or complainant details in a public post. Give them only through verified official channels when required.

Call 1930 and complete the cybercrime record

The National Cyber Crime Reporting Portal directs cyber financial-fraud victims to 1930 and the portal. Tell the operator the account and transaction facts, not a long legal argument. The 1930 checklist gives a ready sequence. If the line is busy, file on the portal and retry 1930; do not wait for an unofficial “golden hour” promise.

Have ready: the mobile linked to the account; exact amount and time; UTR / UPI reference; beneficiary VPA, account or merchant; last four digits of the account; the SMS or email alert.

An acknowledgement is evidence that a report entered the system. It is not proof that funds have been frozen, traced or recovered. Follow the instructions attached to the acknowledgement and complete the portal record promptly with documents. The portal's published one-page workflow instruction asks for the victim's mobile, bank or wallet details, transaction ID, date, card information where relevant and screenshots; that document is labelled for Delhi, so follow any State-specific direction given in your case. Track the record on cybercrime complaint status. Portal filing: file a cybercrime complaint.

Notify the bank separately

Do not assume the 1930 call automatically becomes your bank dispute. Use the bank's official fraud channel and ask it to:

  • block further unauthorised activity;
  • register a written complaint with date and time;
  • identify the transaction and channel;
  • consider recall, lien, chargeback or dispute action applicable to that channel;
  • preserve logs and beneficiary details for the investigating agency;
  • state its decision and the rule applied;
  • provide the escalation and nodal-officer route.

For UPI, NPCI's current complaint page says fraudulent, unidentified or unauthorised transactions should be raised with the respective bank. NPCI's UPI FAQ also warns that a UPI payment cannot be stopped after it has been initiated. A complaint may help investigation or dispute handling, but it is not an automatic cancellation.

Sample email to the bank (copy and adapt)

Send this from the email registered on the account. Do not write that zero liability is automatic. Ask the bank to classify the facts under the circular.

To: [branch / grievance / fraud email published on the bank website]
Subject: Unauthorised / fraud-induced electronic transaction — account ending [XXXX] — reported on [date time]

Dear Sir/Madam,

I, [name], hold account ending [XXXX] at [branch]. On [date] at [time], ₹[amount] was debited vide [UTR / UPI reference] to [beneficiary as shown]. I [did not authorise this transaction / authorised a payment after the following deception: short facts].

I reported to your official channel at [time] under ticket [number], and to 1930 / cybercrime.gov.in under acknowledgement [number].

Please:
1. Keep the affected card / UPI / net-banking channel blocked.
2. Register a written unauthorised-transaction complaint and send the acknowledgement.
3. Consider recall, lien, chargeback or the dispute process that applies to this channel.
4. Preserve logs and beneficiary details for the investigating agency.
5. Give a written decision that identifies the transaction, the facts relied on, and the RBI circular / Board-approved policy applied, including any shadow-reversal timeline that applies to these facts.

I will not share OTP, UPI PIN or remote access with anyone claiming to recover the amount.

[Name] [mobile] [address]
Attachments: statement extract, SMS/email alert, 1930/NCRP acknowledgement, screenshots.

Phone notice is still useful for a fast block. Follow it with this writing so the timestamp of the bank complaint is on record.

RBI customer-liability rules are conditional

The RBI circular's three-working-day rule is not an automatic refund rule for every scam. Its outcome depends on the cause and reporting time.

Situation in the RBI framework General liability position
Fraud, negligence or deficiency lies with the bank Zero customer liability, irrespective of whether the customer reported the transaction
Third-party breach where deficiency lies neither with bank nor customer, reported within three working days of bank communication Zero customer liability under the circular's conditions
Same third-party situation reported in four to seven working days Limited liability according to the circular's table and account type
Reported beyond seven working days Liability is determined under the bank's Board-approved policy
Loss caused by customer negligence, such as sharing payment credentials Customer bears the loss until reporting; loss after reporting is borne by the bank under the circular

The bank must credit a shadow reversal within 10 working days after notification for covered unauthorised transactions and resolve the complaint and determine liability within the period in its policy, not exceeding 90 days under the circular. These protections depend on the circular's scope and facts. A transfer that the customer knowingly authorised after a scammer's deception can raise a different dispute from an account-takeover transaction.

Ask the bank to classify the transaction and give the written basis for its liability decision. Do not accept a phone statement that “UPI never has protection” or that “three days always means refund”.

Card chargeback and UPI dispute

If the loss was on a credit or debit card, ask the bank in writing to raise a chargeback under the fraud / unauthorised reason code that the network and the bank's terms allow. Ask for the chargeback reference. Network windows are set by the card scheme and the bank, not by this page; do not assume a number of days copied from an unofficial article.

For UPI, raise the dispute in the UPI app or with the account-holding bank as NPCI's current page instructs. Attach the cybercrime acknowledgement, the statement highlighting the debit, and a short account of how the credential or approval was obtained. Follow NPCI's escalation through the provider and banks before treating NPCI as the first desk. Related: recover money after UPI fraud and UPI deducted but not received.

UPI collect, QR and refund traps

To receive money, you ordinarily do not need to enter a UPI PIN. A collect request or QR flow can be a request for you to pay. Read the payer, payee and amount on the authorisation screen.

If a fake merchant-support agent says a refund requires:

  1. scanning a QR code;
  2. approving a collect request;
  3. entering a UPI PIN;
  4. sharing an OTP;
  5. installing a remote-access app;
  6. making a small “verification” payment;

stop the call. Verify support inside the merchant's official app or website. For shopping-related deception, also use the cashback and shopping-scam guide. Courier-OTP plays: courier OTP scam.

Special cases on the same ladder

The same 1930 + bank + evidence ladder applies. Add the extra lock that matches the vector:

  • AePS / Aadhaar-enabled withdrawal at a BC point — lock biometrics on UIDAI's official portal and see AePS Aadhaar fraud recovery.
  • Card-not-present / international debit — tell the bank if no OTP or additional factor was asked where the bank's process normally requires it; ask it to apply the unauthorised-transaction framework to those facts.
  • SIM hijack — block the SIM from another phone, check TAFCOP, then continue the payment-fraud ladder. SIM-swap recovery.
  • Wrong NEFT/RTGS to a genuine account you typed — that is often a bank-transfer error, not cyber fraud; use NEFT/RTGS wrong-account refund.
  • Loan-app harassment after a debitloan-app harassment.

Escalate a bank-service failure

First use the bank's grievance and nodal-officer process. Preserve the complaint date and complete response. If the bank rejects the complaint, gives an unsatisfactory response, or does not respond within 30 days, the RBI Integrated Ombudsman Scheme, 2021 may provide a cost-free route through cms.rbi.org.in for qualifying deficiency in service. Guide: banking ombudsman complaint.

The Ombudsman does not investigate the criminal network or guarantee recovery from the beneficiary. Frame the complaint around the regulated entity's failure: delayed blocking, no complaint acknowledgement, incorrect liability assessment, no reasoned decision or failure to follow an applicable payment-dispute process.

Preserve a clean evidence pack

Keep one chronological folder with:

  • bank statement and transaction detail;
  • 1930 and NCRP acknowledgements;
  • bank complaint and every escalation;
  • screenshots with date, URL and app identity;
  • call logs and messages;
  • device or SIM alerts;
  • merchant invoice or order record;
  • a one-page chronology written while events are fresh.

Do not edit screenshots to “make them clearer”. Keep originals and make redacted copies for routine correspondence. Do not factory-reset the phone before this pack exists.

Sample seven-day chronology (actions, not promises)

This is a checklist of your actions. It is not a service-level agreement and not a recovery forecast.

  1. Hour 0–1: Block access. Call 1930. File at cybercrime.gov.in. Screenshot alerts.
  2. Hour 1–3: Written bank complaint. Lock SIM if a swap is suspected. Save evidence off the device.
  3. Day 1–3: Follow portal instructions. Add missing documents. Confirm the bank ticket in writing.
  4. Day 4–10: If the circular's shadow-reversal rule applies to these facts, ask the bank in writing what date it used. If it does not apply, ask for the written classification.
  5. Day 10–30: One reminder to the nodal officer if there is no reasoned reply.
  6. After 30 days without a satisfactory reply: Consider CMS / Integrated Ombudsman if the complaint is maintainable.
  7. In parallel: Police / portal follow-up as instructed. Consumer filing only for a genuine seller or service dispute.

What NOT to do

  • Do not keep using the compromised UPI app, card or net-banking session.
  • Do not share OTP, PIN, password, UPI PIN or CVV with anyone, including a caller claiming to be from the bank, RBI, NCRP or police.
  • Do not pay a “release fee”, “tax”, “GST” or crypto to a recovery agent.
  • Do not install remote-access software on a caller's instruction.
  • Do not delete chats to “free space” before the pack is saved.
  • Do not post the full account number or NCRP reference on social media.
  • Do not treat a 1930 acknowledgement as a guaranteed freeze.

What the RBI Rule Actually Says

The Reserve Bank of India circular RBI/2017-18/15 (DBR.No.Leg.BC.78/09.07.005/2017-18, dated 6 July 2017) is the governing document. It applies to all scheduled commercial banks, small finance banks, regional rural banks, and payments banks.

The circular creates three categories of customer liability:

Zero liability (you owe nothing):

  • The bank itself was at fault, for example a data breach on its systems, a deficiency in its processes, or fraud by a bank employee.
  • A third party (someone outside both you and your bank) breached the system AND you reported the unauthorised transaction to your bank within 3 working days of receiving the bank's communication (SMS or email alert) about that transaction.

Limited liability (you bear a capped amount):

If you reported between 4 and 7 working days after receiving the bank alert, your maximum personal loss is:

Account type Your maximum liability
Basic Savings Bank Deposit (BSBD) accounts Rs 5,000
Savings accounts, PPIs, MSME accounts, individual current or cash-credit accounts with limit up to Rs 25 lakh, credit cards with limit up to Rs 5 lakh Rs 10,000
All other current, cash-credit, overdraft accounts, credit cards above Rs 5 lakh Rs 25,000

Your bank must compare the capped amount above with the actual transaction value and apply whichever is lower.

Your liability determined by bank policy: If you reported after 7 working days, your bank's Board-approved policy decides. This is why speed matters.

Important: If you shared your OTP, PIN, or password with the caller, the RBI circular treats that as your negligence. In that case you bear the full loss until you report it; losses after you notify the bank shift back to the bank. See how OTP scams work for how to avoid this trap.

Step 4: UPI Transactions - Additional Path

If the fraud happened via UPI, you can also raise a dispute through your UPI app (Google Pay, PhonePe, Paytm, BHIM etc.) using the in-app “Report an issue” or “Raise dispute” option. The dispute flows through the acquiring bank. For more detail on the UPI-specific process, verify the current mechanism on npci.org.in, as NPCI updates these procedures periodically. Also see how to file a UPI fraud complaint.

What If the Bank Refuses or Delays?

If your bank does not respond within 30 days, or gives an unsatisfactory response, escalate to the Reserve Bank - Integrated Ombudsman Scheme. File at cms.rbi.org.in. You do not need a lawyer. The Ombudsman covers banks, NBFCs, and prepaid payment instrument issuers.

For a detailed walkthrough of filing with the Ombudsman, see how to use the Banking Ombudsman.

The Ombudsman can:

  • Direct the bank to reverse the fraudulent debit
  • Award compensation for mental agony and harassment (up to limits prescribed in the scheme)
  • Direct the bank to pay interest for delayed reversal

File an RTI to: //the Reserve Bank of India (RBI)//

If you want official data or internal records about fraud complaint processing, ask RBI under the RTI Act 2005.

  • How many unauthorised electronic transaction complaints were received in the last financial year and how many were resolved within 90 days?
  • What action has RBI taken against banks that failed to make shadow reversals within 10 working days under circular DBR.No.Leg.BC.78/09.07.005/2017-18?
  • What is the total amount involved in unauthorised electronic transaction complaints resolved under the Integrated Ombudsman Scheme in the last financial year?
  • What inspections or audits has RBI conducted to verify bank compliance with mandatory SMS/email alert requirements for electronic transactions?
  • How many banks have been penalised for non-compliance with the zero-liability / limited-liability customer protection framework?

Use our free AI RTI Drafter to generate a complete Section 6(1) application.

I shared my OTP with the fraudster. Can I still get a refund?

This is treated as customer negligence under the RBI circular, so you bear the full loss that occurred before you reported it to your bank. Once you notify your bank, the bank covers any further losses. That said, file with your bank and on 1930 anyway. Some banks may still offer partial relief as a goodwill gesture, and the police record matters for an FIR if you choose to escalate.

The fraudster called pretending to be from my bank. Is that a third-party breach?

The answer depends on whether you shared credentials. If the caller extracted your OTP or PIN and used it, courts and banks generally treat that as the customer's contributory negligence because the credentials passed through you. If the fraud happened entirely without you providing anything (for example a SIM-swap attack or a card-skimming breach), that is more likely a third-party breach. Report to 1930 and let the bank's investigation run, but also file an FIR with your local police.

I got a message saying my refund is being processed. Is it real?

Be very careful. Fraudsters often call or message victims saying “we are processing your refund, share an OTP to receive it.” No legitimate bank or government agency will ever ask you for an OTP to credit money. If you receive such a message, it is a second fraud attempt.

Frequently asked questions

What number should I call for online financial fraud?

Call 1930 promptly and also notify your bank through its official fraud channel. Complete the report at cybercrime.gov.in.

Does a 1930 complaint guarantee recovery?

No. It creates and routes a report; recovery depends on transaction tracing, timing, available funds, bank action and investigation. No official golden-hour percentage is stated here.

Can I cancel a UPI payment after entering the PIN?

NPCI's UPI FAQ says a payment cannot be stopped once initiated. Report fraud immediately so the bank and police can consider the available response.

Does reporting within three days always mean zero liability?

No. The RBI rule depends on whether the transaction was unauthorised, where the deficiency or negligence lay and when the bank's communication and customer report occurred.

What if I shared an OTP or UPI PIN?

Report immediately and tell the truth. Under the RBI circular, customer negligence can make the customer liable for loss until the report, while loss after reporting is borne by the bank within the framework.

Can the RBI Ombudsman arrest the scammer?

No. It handles qualifying service complaints against regulated entities. Police investigate crime.

Should I pay an agent who promises fund recovery?

No. Recovery-agent impersonation is a common second scam. Use official bank, police, NCRP and regulator channels.

Should I file a consumer complaint too?

Use consumer remedies for a genuine seller or service dispute. A criminal impersonation or payment fraud still needs prompt bank and cybercrime reporting.

Official sources

Was this useful?
- views