Differences
This shows you the differences between two versions of the page.
| — | cyber:otp-bank-scam [2026/07/10 19:37] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | metatag-title=(OTP Bank Call Scam Recover Your Money 2026)& | ||
| + | metatag-og: | ||
| + | metatag-twitter: | ||
| + | |||
| + | ====== OTP / Bank-Call Scam: Recover Your Money 2026 ====== | ||
| + | |||
| + | {{https:// | ||
| + | |||
| + | **Reviewed on:** 2026-06-19. | ||
| + | |||
| + | <WRAP info> | ||
| + | |||
| + | ===== What just happened to you ===== | ||
| + | |||
| + | The call sounded legitimate. The caller knew your name, last four card digits, and even your recent transaction. They said your account was flagged for fraud and that you needed to " | ||
| + | |||
| + | This is a vishing attack (voice phishing) built around OTP capture. The criminal had already obtained your card details, possibly from a data breach or a phishing SMS, and needed only the one-time password to push through a transaction. Sharing the OTP is the trigger, but the RBI's limited-liability rules still offer you a path to recovery, provided you act fast. | ||
| + | |||
| + | This page focuses on the OTP/vishing modus and the steps to freeze your account and file a claim. For the broader process of disputing fraudulent transactions across any channel, see [[cyber: | ||
| + | |||
| + | ===== Step 1: Block your account right now ===== | ||
| + | |||
| + | Do not read the rest of this article first. Open your banking app or call your bank's 24-hour helpline and do all of the following: | ||
| + | |||
| + | - Say the words " | ||
| + | - Ask them to note the exact time of your call. This timestamp is evidence for your RBI liability claim. | ||
| + | - Request a complaint or service request number and note it down. | ||
| + | - Ask the agent to "raise a chargeback" | ||
| + | |||
| + | Most private and public sector banks have 24-hour helplines accessible from the number on the back of your card or on their official website. If you cannot reach your bank, walk to the nearest ATM and block your card yourself using the ATM menu. | ||
| + | |||
| + | ===== Step 2: Call 1930 and file at cybercrime.gov.in ===== | ||
| + | |||
| + | The National Cybercrime Helpline **1930** is operated by the Ministry of Home Affairs. When you call, you report a financial fraud. The operator logs your complaint and can coordinate with banks to flag the account where the money landed, making it harder for the fraudster to withdraw it. | ||
| + | |||
| + | You must also file a written complaint at [[https:// | ||
| + | |||
| + | - Select the option to register a complaint and choose the financial fraud category. | ||
| + | - You can report with or without creating an account; registering lets you [[check-status: | ||
| + | - Fill in your name, mobile number, bank account details, the amount lost, the date and time of the fraud, and a factual description of how the call proceeded. | ||
| + | - Note the complaint acknowledgement number the portal gives you. | ||
| + | |||
| + | File this complaint on the same day. The earlier the complaint reaches the portal, the sooner law enforcement can coordinate a freeze on the destination account through the Citizen Financial Cyber Fraud Reporting and Management System. | ||
| + | |||
| + | ===== Step 3: Visit your bank branch with a written complaint ===== | ||
| + | |||
| + | On the next working day, visit your branch and submit a written complaint. Bring: | ||
| + | |||
| + | - A printout or copy of your cybercrime portal complaint with the acknowledgement number. | ||
| + | - Your bank statement showing the unauthorised debit. | ||
| + | - Any SMS or call records from the time of the fraud. | ||
| + | |||
| + | Ask the branch to mark the complaint as an " | ||
| + | |||
| + | ===== The RBI limited-liability rule: what you are owed ===== | ||
| + | |||
| + | The Reserve Bank of India circular of 6 July 2017 sets out when a bank must refund you and how much. | ||
| + | |||
| + | **Zero liability (full refund):** You owe nothing and must be refunded in full if: | ||
| + | |||
| + | * The bank itself was negligent or there was a deficiency in their system, OR | ||
| + | * A third party broke in without any negligence on your part AND you reported the transaction within **three working days** of the bank sending you an alert (SMS, email, or app notification). | ||
| + | |||
| + | **Critical point on OTP sharing:** The circular classifies OTP sharing as customer negligence because you shared a credential. However, this does not end your claim entirely. Post-reporting liability shifts to the bank. That means any debit that happens after the moment you notified your bank is the bank's responsibility, | ||
| + | |||
| + | **Limited liability (partial refund) for delayed reporting: | ||
| + | |||
| + | ^ Delay in reporting ^ Account type ^ Maximum customer liability ^ | ||
| + | | 4 to 7 working days | BSBD / Jan Dhan account | Up to Rs 5,000 | | ||
| + | | 4 to 7 working days | Savings account, prepaid card, MSME account (limit below Rs 25 lakh) | Up to Rs 10,000 | | ||
| + | | 4 to 7 working days | Other current / cash credit accounts (limit above Rs 5 lakh) | Up to Rs 25,000 | | ||
| + | | Beyond 7 working days | All accounts | Bank's board-approved policy applies | | ||
| + | |||
| + | **Bank' | ||
| + | |||
| + | * The bank must credit the disputed amount to your account (as a shadow reversal) within **10 working days** of your complaint. | ||
| + | * The bank must close the complaint and determine final liability within **90 days**. | ||
| + | * If the bank fails to resolve within 90 days, it must compensate you separately for the delay. | ||
| + | |||
| + | ===== Step 4: Escalate if the bank does not respond ===== | ||
| + | |||
| + | If the bank rejects your claim without a satisfactory explanation, | ||
| + | |||
| + | - File online at [[https:// | ||
| + | - Select your bank and describe the grievance. Attach your bank complaint reference number and the cybercrime portal acknowledgement. | ||
| + | - The Ombudsman can direct the bank to refund the loss amount and award additional compensation for harassment or mental agony; verify the current award limits on cms.rbi.org.in. | ||
| + | - The service is free for complainants. | ||
| + | |||
| + | You can also contact [[cyber: | ||
| + | |||
| + | ===== What the scammer told you versus reality ===== | ||
| + | |||
| + | ^ What the caller said ^ Reality ^ | ||
| + | | "I am calling from your bank's fraud department." | ||
| + | | "We need to verify your identity with the OTP." | OTPs authorise transactions, | ||
| + | | "This will cancel the fraud on your account." | ||
| + | | "Your account will be blocked if you do not cooperate." | ||
| + | |||
| + | A genuine bank security call will ask you to visit a branch or use the official app. It will never ask for a one-time password, full card number, PIN, or internet banking password. | ||
| + | |||
| + | ===== FAQ ===== | ||
| + | |||
| + | ==== I shared the OTP. Will the bank still refund me? ==== | ||
| + | |||
| + | Possibly yes, in part. Sharing the OTP counts as negligence under the RBI circular, so you may not get a zero-liability refund. However, any debit after you report to the bank is the bank's responsibility. File your complaint immediately and let the bank determine liability. If you disagree with their decision, escalate to the RBI Ombudsman. Do not assume you have no claim. | ||
| + | |||
| + | ==== How quickly must I report to get the best outcome? ==== | ||
| + | |||
| + | Within three working days of the bank's alert SMS or email. Reporting sooner, ideally within hours, also helps law enforcement freeze the destination account before the fraudster withdraws the money. | ||
| + | |||
| + | ==== What if I did not get an SMS alert from the bank? ==== | ||
| + | |||
| + | If the bank failed to send an SMS or email alert (which they are required to do), that counts as negligence on the bank's side. Mention this explicitly in your written complaint and to the Ombudsman. | ||
| + | |||
| + | ==== The bank says the transaction is " | ||
| + | |||
| + | An authenticated transaction is not the same as an authorised transaction. You were deceived into sharing the OTP. File your complaint using the RBI circular reference (DBR.No.Leg.BC.78/ | ||
| + | |||
| + | ==== Can I file a police FIR separately? ==== | ||
| + | |||
| + | Yes. A cybercrime portal complaint and an FIR are separate. Visit your local police station or state cyber cell and file an FIR under relevant provisions of the IT Act 2000 and BNS 2023. The FIR strengthens your case if the bank disputes your claim or if you pursue the matter in court. | ||
| + | |||
| + | ==== What if money was sent via UPI? ==== | ||
| + | |||
| + | Raise a dispute directly in the UPI app (Google Pay, PhonePe, Paytm) under " | ||
| + | |||
| + | ==== Is there a limit on how much the Ombudsman can award? ==== | ||
| + | |||
| + | The RBI Integrated Ombudsman can direct the bank to refund the amount lost and award additional compensation for harassment or deficiency in service. There is no filing fee. Check the current award limits on [[https:// | ||
| + | |||
| + | ===== File an RTI to get answers ===== | ||
| + | |||
| + | **File an RTI to:** //Reserve Bank of India (the public authority that regulates bank fraud reporting obligations and runs the Ombudsman scheme)// | ||
| + | |||
| + | Use an RTI application under Section 6(1) of the RTI Act 2005 addressed to the Central Public Information Officer, Reserve Bank of India, to ask: | ||
| + | |||
| + | * What are the prescribed timelines under the July 2017 circular for banks to resolve unauthorised-transaction complaints, and what action does RBI take when banks breach those timelines? | ||
| + | * How many complaints were received by the RBI Integrated Ombudsman in the last financial year relating to unauthorised electronic transactions, | ||
| + | * What oversight does RBI exercise over banks' 24/7 fraud-reporting helplines, and how are non-compliant banks penalised? | ||
| + | * What is the procedure for a customer to access the record of their own complaint filed under the Ombudsman scheme? | ||
| + | * How does RBI verify that banks correctly apply the zero-liability and limited-liability rules when adjudicating customer claims? | ||
| + | |||
| + | → **[[https:// | ||
| + | |||
| + | **Helpline: | ||
| + | |||
| + | ===== Sources ===== | ||
| + | |||
| + | * RBI Master Circular on Customer Protection, 6 July 2017 (RBI/ | ||
| + | * National Cyber Crime Reporting Portal: [[https:// | ||
| + | * RBI Complaint Management System (Integrated Ombudsman): [[https:// | ||
| + | * NPCI UPI dispute information: | ||
| + | |||
| + | //By Dr. Shrawan Kumar Pathak// | ||
| + | |||
| + | ===== What are the most common OTP scam techniques used in India in 2026? ===== | ||
| + | |||
| + | | Scam Type | How it works | Red flags | | ||
| + | | **Fake SMS forward** | Scammer calls claiming to be from bank/RBI, asks you to forward the OTP SMS to a number | No bank ever asks you to forward OTPs | | ||
| + | | **SIM swap fraud** | Scammer obtains a duplicate SIM using fake KYC, receives your OTPs directly | Your phone suddenly loses signal for no reason | | ||
| + | | **Screen mirroring app** | Scammer asks you to install AnyDesk/ | ||
| + | | **Malicious link** | SMS with link to fake bank website that captures login + OTP | Check URL carefully; official sites use .gov.in or bank domains | | ||
| + | | **WhatsApp impersonation** | Scammer poses as family member on WhatsApp, asks for OTP sent to your number | Always verify by calling the person directly | | ||
| + | | **Investment scam OTP** | Fake trading app asks for OTP to " | ||
| + | |||
| + | ===== What is the RBI zero liability rule for OTP fraud? ===== | ||
| + | |||
| + | Under RBI Master Directions on Customer Liability (2017, updated), the customer liability is limited as follows: | ||
| + | |||
| + | | Scenario | Customer liability | Time to report | | ||
| + | | **Unauthorised transaction, | ||
| + | | **Reported within 4-7 days** | Limited to the transaction value (subject to caps) | Within 4-7 working days | | ||
| + | | **Reported after 7 days** | As per bank policy; full liability may apply | Beyond 7 working days | | ||
| + | |||
| + | The zero liability applies when the fraud is due to bank system failure, third-party breach, or contributory negligence of the bank. For customer negligence (sharing OTP), banks may still process the claim but the outcome depends on the investigation. | ||
| + | |||
| + | **Key action:** Report immediately to your bank and file a police complaint within 3 days to maximise zero liability protection. | ||
| + | |||
| + | ===== How to file a cyber fraud complaint for OTP scam? ===== | ||
| + | |||
| + | - **Step 1: Report to bank.** Call the bank customer care immediately and ask them to block the account and reverse the transaction. Note the complaint reference number. | ||
| + | - **Step 2: File on National Cyber Crime Portal.** Register a complaint at [[https:// | ||
| + | - **Step 3: File FIR at local police station.** If the amount is significant, | ||
| + | - **Step 4: Report to RBI Ombudsman.** If the bank does not respond within 30 days or rejects your claim, file a complaint at [[https:// | ||
| + | - **Step 5: Preserve evidence.** Keep screenshots of SMS, call logs, bank statements, the transaction reference, and any app installation records. | ||
| + | |||
| + | For a detailed guide on UPI and digital payment fraud, see [[upi-fraud-complaint|UPI Fraud Complaint Guide]] and [[fake-fund-recovery-agent-scam-india|Fake Fund Recovery Agent Scam]]. | ||
| + | |||
| + | ===== How to protect yourself from OTP scams: safety checklist ===== | ||
| + | |||
| + | - **Never share OTP, PIN, CVV, or passwords** with anyone, including bank officials, police, or family members on phone. | ||
| + | - **Never forward OTP SMS** to any number, no matter what the caller says. | ||
| + | - **Do not install screen sharing apps** (AnyDesk, TeamViewer, QuickSupport) when someone calls about your bank account. | ||
| + | - **Enable SIM lock/PIN** on your mobile to prevent SIM swap fraud. | ||
| + | - **Check SMS sender IDs:** Official bank SMS comes from designated sender IDs like SBI-SMS, HDFCBNK. Fake SMS comes from random numbers. | ||
| + | - **Set transaction limits:** Lower your daily UPI and card transaction limits to minimise potential loss. | ||
| + | - **Do not click links in SMS or WhatsApp** that ask for banking details. Always type the bank URL manually. | ||
| + | - **Register for DND:** Activate Do Not Disturb to reduce scam calls. Register at [[https:// | ||
| + | - **Use only official bank apps:** Download banking apps only from official app stores. Check the developer name before installing. | ||
| + | |||
| + | ===== How to use RTI to track your cyber fraud complaint? ===== | ||
| + | |||
| + | - **File RTI with the cyber crime cell:** Ask for the status of your complaint, the investigating officer assigned, and the steps taken. | ||
| + | - **File RTI with the bank (if public sector):** Ask for the investigation report, the liability determination, | ||
| + | - **File RTI with RBI:** Ask whether the bank has reported the fraud under RBI norms and what action RBI has taken on your Ombudsman complaint. | ||
| + | |||
| + | For RTI templates, see [[guide/ | ||
| + | |||
| + | {{tag> | ||
| + | |||