📱Test our Android app — free beta!Join Beta GroupYou'll receive the install link by email after joining.

Differences

This shows you the differences between two versions of the page.


online-payment-fraud-recovery-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1
Line 1: Line 1:
 +{{htmlmetatags>metatag-title=(Online Payment Fraud Recovery in India)
 +metatag-description=(Lost money to UPI, card or netbanking fraud in India. The RBI 3-working-day zero-liability rule, 1930 helpline, NCRP complaint, FIR and RBI Ombudsman path explained.)
 +metatag-keywords=(online payment fraud recovery india, upi fraud recovery, ncrp complaint 1930, rbi customer liability framework, bank chargeback india, cybercrime fir india, money lost online how to get back, payment fraud refund 3 day rule, upi scam refund, netbanking fraud refund, card fraud chargeback india, rbi ombudsman fraud, cybercrime portal, npci dispute redressal, bharatiya nyaya sanhita 318)}}
 +
 +====== Online Payment Fraud Recovery in India ======
 +
 +
 +
 +{{ :social:auto:online-payment-fraud-recovery-india.png?direct&1200 |Online Payment Fraud Recovery in India — RTI Wiki}}
 +
 +<WRAP center round info 95%>
 +**Quick Reply:** Lost money to UPI, card or netbanking fraud in India. The RBI 3-working-day zero-liability rule, 1930 helpline, NCRP complaint, FIR and RBI Ombudsman path explained.
 +</WRAP>
 +
 +If you just lost money to an online payment scam in India, the next 3 working days decide whether your bank must refund you. The legal framework favours the victim, but only if you follow a specific written sequence. This guide walks through that sequence in the order that actually works.
 +
 +<WRAP important>
 +**Direct answer.** Call 1930 and file at [[https://www.cybercrime.gov.in|cybercrime.gov.in]] (National Cybercrime Reporting Portal, NCRP) within 24 hours. Send a written email to your bank within 3 working days, quoting the **RBI Circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017 on Limiting Liability of Customers in Unauthorised Electronic Banking Transactions** - this caps your liability at zero if you reported within 3 working days and were not negligent. File an FIR. Preserve every screenshot. Wait 30 days, then escalate to the [[https://cms.rbi.org.in|RBI Ombudsman (cms.rbi.org.in)]]. Do NOT keep using the compromised account, and do NOT pay any "release fee" to a "recovery agent".
 +</WRAP>
 +
 +===== The 24-hour and 3-working-day clock =====
 +
 +Time is the single biggest factor in fraud recovery. The RBI customer-liability circular ties your refund right to how fast you reported, in three buckets:
 +
 +  - **Within 3 working days** of receiving the bank's transaction alert: zero customer liability if you were not part of the fraud and did not share OTP or password.
 +  - **Within 4 to 7 working days**: limited liability up to ₹5,000 / ₹10,000 / ₹25,000 depending on account type (BSBDA / regular savings / current account).
 +  - **Beyond 7 working days**: the bank's policy decides; refund becomes harder.
 +
 +Within the first 24 hours, you also have the cybercrime side: a complaint at NCRP or a call to 1930 lets the cyber cell push freeze instructions to the recipient bank before the money is moved out. Once the money is laundered through a chain of mule accounts, recovery becomes far harder.
 +
 +Report inside 24 hours to NCRP, write to your bank within 3 working days, and keep evidence of both timestamps.
 +
 +===== Step 1: Call 1930 immediately =====
 +
 +The Indian Cybercrime Coordination Centre (I4C) runs the 1930 helpline on top of the [[https://www.cybercrime.gov.in|National Cybercrime Reporting Portal]]. When you call, the operator opens a "ticket" linked to your bank account and pushes a near-real-time hold request to the recipient bank's nodal officer.
 +
 +What to keep ready before calling:
 +
 +  * Your phone number (the one linked to the account).
 +  * The exact transaction amount and time.
 +  * UPI transaction ID (UTR) or RRN.
 +  * Recipient UPI ID, account number, or merchant name.
 +  * Your bank account number (last 4 digits at minimum).
 +  * SMS / email alerts from the bank.
 +
 +If 1930 is busy, file the complaint directly at cybercrime.gov.in - the portal opens a ticket in the same I4C system. Save the acknowledgement number; that number is your proof of reporting time.
 +
 +<WRAP alert>
 +**Warning: do not pay any "recovery agent".** Within hours of a fraud, scammers may message you on Telegram or WhatsApp claiming to be "ex-cyber officers" who can recover your money for a fee. They are recovery scammers - the second wave of the same network. Real recovery never asks you to pay anything. The only legitimate channels are 1930, your bank, NCRP, and the RBI Ombudsman.
 +</WRAP>
 +
 +===== Step 2: Write to your bank within 3 working days =====
 +
 +Phone calls do not count for the 3-working-day rule. The RBI customer-liability circular protects you only if your report is "in writing", and the burden of proving you were negligent falls on the bank, not you. Email or written letter both qualify.
 +
 +Send your email to:
 +
 +  * Your branch's official email (printed on your passbook).
 +  * The bank's grievance redressal officer (listed on the bank's website).
 +  * The bank's nodal officer for fraud (listed on the RBI Ombudsman portal).
 +  * CC yourself.
 +
 +===== Sample email to the bank (copy and adapt) =====
 +
 +<WRAP center round box>
 +**To:** branch-manager@[bank].com; nodaloffice@[bank].com
 +**CC:** your own backup email
 +**Subject:** Unauthorised electronic transaction - account [last 4 digits] - reported within 3 working days under RBI customer-liability circular dated 6 July 2017
 +
 +Dear Sir/Madam,
 +
 +I, [Name], hold savings account number ending [XXXX] at your [branch] branch. I am writing to formally report an unauthorised electronic banking transaction on my account.
 +
 +On [date] at approximately [time], an amount of ₹[amount] was debited from my account vide [UPI ID / RRN / transaction reference], to beneficiary [recipient UPI / name / account]. I did not authorise this transaction. I did not share my OTP, PIN, password, CVV, or UPI PIN with any party.
 +
 +This communication is sent within 3 working days of the bank alert (alert dated [date], time [time]), within the meaning of the RBI Circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017 on Limiting Liability of Customers in Unauthorised Electronic Banking Transactions. My liability is therefore zero and I request a full reversal of ₹[amount] within 10 working days, as required by paragraph 8 of the said circular.
 +
 +I have also filed:
 +  * National Cybercrime Reporting Portal complaint reference [NCRP ack no], dated [date]
 +  * Police FIR / e-FIR (in process / filed) at [police station] on [date]
 +
 +Please:
 +  1. Reverse the disputed amount to my account on a "shadow credit" or provisional basis as required by the circular.
 +  2. Issue a written acknowledgement with a complaint reference number.
 +  3. Block my debit card and reset internet banking and UPI credentials.
 +  4. Coordinate with the recipient bank's nodal officer to freeze the receiving account.
 +  5. Provide me with the dispute resolution timeline.
 +
 +Failing satisfactory resolution within 30 days, I will escalate to the Reserve Bank - Integrated Ombudsman under the Reserve Bank - Integrated Ombudsman Scheme, 2026.
 +
 +Attachments: SMS / email alert screenshot, NCRP acknowledgement, FIR copy (if available), bank statement extract.
 +
 +Regards,
 +[Name]
 +[Phone] | [Email] | [Address]
 +Account: [number] | [Branch]
 +</WRAP>
 +
 +Send this from the email registered on your bank account. Do not delete the sent copy.
 +
 +===== Step 3: File an FIR or e-FIR =====
 +
 +For amounts above ₹2 lakh, an FIR is mandatory under most state cybercrime SOPs. For smaller amounts, an "NCRP complaint" is treated as equivalent to an FIR for many banking purposes, but a proper FIR is still useful for chargebacks and ombudsman cases.
 +
 +You can file:
 +
 +  * **Online via NCRP** at cybercrime.gov.in - the portal forwards the complaint to your district cybercrime cell and many states auto-convert it to an FIR for losses above their threshold.
 +  * **At a police station in person** - any police station, not just a "cyber" station, must accept your complaint. **Section 173 of the Bharatiya Nagarik Suraksha Sanhita (BNSS), 2023** (which replaced CrPC 154) requires registration of an FIR for a cognisable offence, and the BNSS gives statutory backing to the "zero FIR" so jurisdiction cannot be used as a ground to refuse. A station that refuses can be approached at the SP / DCP level via written complaint.
 +  * **e-FIR** in states that allow it (Delhi, Haryana, UP, MP, Maharashtra and others) - online via the state police portal.
 +
 +Cite the right offences in your FIR:
 +
 +  * **Information Technology Act, 2000 Section 66C** - identity theft (using your password / OTP).
 +  * **Information Technology Act, 2000 Section 66D** - cheating by personation using a computer resource.
 +  * **Bharatiya Nyaya Sanhita (BNS), 2023 Section 318** - cheating (replaces IPC 420).
 +  * **BNS, 2023 Section 319** - cheating by personation.
 +  * **BNS, 2023 Section 336** - forgery of an electronic record.
 +  * If you were threatened, **BNS, 2023 Section 308** - extortion.
 +
 +The FIR copy is required for the bank's chargeback to a credit-card network and is useful for a District Commission consumer complaint if the bank stalls.
 +
 +===== Step 4: Preserve evidence (the 30-minute discipline) =====
 +
 +Most fraud refunds fail not because the law is weak but because the victim deleted the SMSes during cleanup. Within 30 minutes of the fraud, do the following:
 +
 +<WRAP tip>
 +**Evidence preservation checklist:**
 +  * [ ] Take screenshots of every SMS or email alert from the bank.
 +  * [ ] Take screenshots of the UPI app transaction screen with timestamps.
 +  * [ ] Export your bank statement (PDF, last 30 days) and save with a named copy.
 +  * [ ] Take screenshots of any chat / call log with the fraudster (WhatsApp, SMS, call duration).
 +  * [ ] Take a screenshot of the NCRP acknowledgement page.
 +  * [ ] Note the recipient UPI handle, account number, IFSC, and transaction reference - in writing.
 +  * [ ] If you clicked a phishing link, screenshot the URL and the email or message that delivered it.
 +  * [ ] Keep the original device unwiped - cyber forensics may need to extract metadata.
 +  * [ ] Save all evidence to two separate cloud locations (do not rely on the device).
 +  * [ ] Record the times of every action (NCRP filing time, bank email send time, call durations) in a chronological note.
 +</WRAP>
 +
 +If you reset your phone, change your SIM, or wipe the messaging app, you may lose admissible evidence. Save first, clean later.
 +
 +===== Step 5: Bank chargeback (cards) and UPI dispute (NPCI) =====
 +
 +If the loss was on a credit or debit card, your bank can raise a "chargeback" with the Visa, Mastercard, RuPay, or Amex network. Chargebacks have strict timelines under each network's rulebook:
 +
 +  * Visa, Mastercard: typically 120 days from transaction date for "fraud / unauthorised" reason code.
 +  * RuPay: 120 days, varies by reason code.
 +  * Amex: 60 to 120 days.
 +
 +Ask your bank in writing to "raise a chargeback under the relevant fraud reason code". Ask for the chargeback reference number and expected timeline.
 +
 +For UPI, the dispute resolution mechanism is operated by [[https://www.npci.org.in|NPCI]] under the UPI dispute resolution framework. The first port of call is your bank or payment app's grievance officer (GPay, PhonePe, Paytm, BHIM all have one). If the issue is not resolved in 30 days, NPCI's UDIR (UPI Dispute Resolution) and the RBI Ombudsman take over. Cite the NPCI dispute mechanism in your bank email.
 +
 +===== Step 6: Escalate to the RBI Ombudsman after 30 days =====
 +
 +If your bank does not refund within 30 days of your written complaint, file at [[https://cms.rbi.org.in|cms.rbi.org.in]] under the **Reserve Bank - Integrated Ombudsman Scheme, 2026 (RB-IOS 2026)**, in force from 1 July 2026. The Ombudsman is free, online, and binding on the bank. Under RB-IOS 2026 the Ombudsman can award compensation up to **₹30 lakh** for consequential loss arising out of the grievance, plus up to **₹3 lakh** for mental harassment, time, and expense (the "One Nation One Ombudsman" framework; cost-free to the customer).
 +
 +You need:
 +
 +  * The bank's written reply (or proof you waited 30 days without a satisfactory reply).
 +  * Your original written complaint to the bank.
 +  * NCRP complaint reference and FIR.
 +  * Bank statements and SMS evidence.
 +
 +The Ombudsman process is largely paper-based, with hearings only when needed.
 +
 +===== Where to file what, and when =====
 +
 +^ Channel ^ When to use ^ Cost ^ Typical time ^ What you get ^
 +| 1930 helpline | Within hours of fraud | Free | Real-time | Account freeze attempt |
 +| NCRP (cybercrime.gov.in) | Within 24 hours | Free | 24-hour acknowledgement | Cybercrime ticket / e-FIR in some states |
 +| Bank written email | Within 3 working days | Free | 10 working days for shadow credit | Refund per RBI circular |
 +| Police FIR | Within 7 days; mandatory above ₹2 lakh in most states | Free | Variable | Investigation + chargeback proof |
 +| Card chargeback | Within 60-120 days (network rule) | Free | 30-90 days | Reversal via Visa / MC / RuPay |
 +| NPCI UDIR (UPI) | After bank refuses | Free | 30-60 days | UPI-side reversal |
 +| RBI Ombudsman (cms.rbi.org.in) | After 30 days bank delay | Free | 30-90 days | Binding order, up to ₹30 lakh + ₹3 lakh harassment |
 +| Consumer Commission (e-Daakhil) | If bank refuses despite Ombudsman | ₹100-₹500 filing fee | 3-9 months | Refund + compensation |
 +| Civil court | Large amounts, complex evidence | Higher | 1-3 years | Refund + damages |
 +
 +===== What NOT to do (red zone) =====
 +
 +<WRAP alert>
 +**Do NOT do any of these - each one wrecks your case:**
 +  * Do NOT keep using the compromised UPI app, debit card, or netbanking session. Lock everything immediately.
 +  * Do NOT factory reset your phone "to be safe" before evidence preservation - you will erase admissible logs.
 +  * Do NOT share your OTP, PIN, password, UPI PIN, or CVV with anyone, including someone claiming to be from the bank, RBI, NCRP, or police. No real authority asks for these.
 +  * Do NOT pay any "release fee", "tax", "processing charge", or "GST" demanded by anyone offering to "release" or "recover" your money. That is the recovery-scam second wave.
 +  * Do NOT install any "remote access" or "screen sharing" app like AnyDesk, TeamViewer, or QuickSupport on the instruction of any caller.
 +  * Do NOT delete WhatsApp / SMS / call logs to "free up space" until the case is closed.
 +  * Do NOT post your full account number or NCRP reference publicly on social media; the same fraud network monitors these.
 +  * Do NOT accept a refund offer from "recovery groups" on Telegram - they will ask for your bank login next.
 +  * Do NOT keep paying EMIs or bills from the compromised account if you can move the auto-debits to a fresh, clean account first.
 +</WRAP>
 +
 +===== Special case: UPI fraud where the recipient is a "merchant" account =====
 +
 +If the recipient handle ends in @paytm, @ybl, @okaxis, @ibl, or another payment-app suffix, NPCI's mule-account framework allows the receiving payment service provider (PSP) to freeze and reverse if reported within the dispute window. Mention specifically in your NCRP complaint and bank email: "Recipient UPI handle [handle] - request immediate beneficiary freeze under NPCI mule-account guidelines".
 +
 +===== Special case: card-not-present (CNP) international transactions =====
 +
 +If your card was used on an offshore website (often a gaming, dating, or crypto site as cover), this is a "card not present" fraud. RBI's Additional Factor of Authentication (AFA) framework requires a second factor for card transactions processed in India. If your card was charged without OTP or 3D Secure where AFA was mandated, that is a clean liability shift to the bank. Cite the RBI AFA framework in your email.
 +
 +===== Special case: AePS / Aadhaar-enabled withdrawal =====
 +
 +If money was withdrawn from your account using an Aadhaar-enabled Payment System (AePS) device at a "BC" point, you have a separate path. The biometric was likely cloned. See our dedicated guide: [[https://righttoinformation.wiki/aeps-aadhaar-fraud-recovery|AePS / Aadhaar-enabled payment fraud recovery]]. The 3-working-day RBI rule still applies, plus you can lock your Aadhaar biometrics on UIDAI's portal.
 +
 +===== Special case: salary-account fraud at workplaces =====
 +
 +Some frauds target the corporate-salary-account window of large IT services and BPO employees, where salary credits arrive on a fixed day. The fraud often takes the form of a fake "HR" email asking you to "verify" your account. The recovery sequence is the same as above, plus your employer's CISO and the bank's corporate-banking team get looped in.
 +
 +===== If your phone or SIM was hijacked =====
 +
 +A subset of frauds happens because your SIM was cloned or "swapped" by a fraudster who tricked the telecom company. If your phone suddenly shows "no signal" for hours and then payments leave your account, this is a SIM-swap scam. Recovery steps:
 +
 +  * Call your telecom helpline (use a different phone) and demand SIM block + reactivation log.
 +  * File a complaint at [[https://www.trai.gov.in|trai.gov.in]] for the unauthorised SIM swap.
 +  * Add the telecom company as a respondent in your bank case - the SIM was the entry vector.
 +  * Lock your UIDAI Aadhaar to prevent further OTP-based bypass.
 +
 +===== Common scam types and the right complaint angle =====
 +
 +  * **UPI "auto-pay" / collect request** - someone sends you a "request" you accidentally approved. Cite IT Act 66D + BNS 318 + the RBI customer-liability circular.
 +  * **Phishing email or fake bank SMS** - cite IT Act 66 + 66C + BNS 318 + 319.
 +  * **Fake "AnyDesk" / customer-support call** - cite IT Act 66D + BNS 318.
 +  * **"[[online-job-offer-scam-pay-to-apply|Job offer]]" with deposit** - cite BNS 318 + 319 (cheating, personation). See [[https://righttoinformation.wiki/fake-job-executive-course-scams-india|fake job and executive course scams]] and [[https://righttoinformation.wiki/fake-linkedin-recruiter-scam-india|fake LinkedIn recruiter scam]].
 +  * **Loan-app extortion / fake EMI** - cite BNS 308 (extortion) + 351 (criminal intimidation). See [[https://righttoinformation.wiki/loan-app-harassment-india|loan app harassment in India]].
 +  * **Edtech "course" charge that won't refund** - this is a service deficiency, not pure cyber fraud. See [[https://righttoinformation.wiki/edtech-refund-complaint-india|edtech refund complaint in India]].
 +  * **AePS / Aadhaar-enabled withdrawal at BC point** - see [[https://righttoinformation.wiki/aeps-aadhaar-fraud-recovery|AePS Aadhaar fraud recovery]].
 +  * **Crypto wallet drain / trading scam** - cite BNS 318 + 319 + 336. RBI does not regulate crypto, but the IT Act and BNS apply to the cheating itself.
 +
 +===== Sample 7-day timeline =====
 +
 +  - **Hour 0-1**: Call 1930. File at cybercrime.gov.in. Lock UPI, debit card, internet banking. Take screenshots.
 +  - **Hour 1-3**: Send written email to bank. Lock SIM if SIM-swap suspected. Save evidence to cloud.
 +  - **Hour 3-24**: Visit police station, file FIR. Lock Aadhaar at UIDAI.
 +  - **Day 2-3**: Bank should issue acknowledgement and shadow credit. If not, send a follow-up.
 +  - **Day 4-10**: Bank should reverse under the RBI customer-liability circular (zero-liability path).
 +  - **Day 10-30**: If bank stalls, write a final reminder. Prepare RBI Ombudsman papers.
 +  - **Day 31+**: File at cms.rbi.org.in. Send copy to your bank with "Ombudsman complaint filed" in the subject.
 +  - **Day 90+**: If still no relief, file at the e-Daakhil consumer commission.
 +
 +===== When the bank says "you shared OTP, you are responsible" =====
 +
 +This is the bank's standard first defence. The legal position is more nuanced. The RBI customer-liability circular puts the burden of proving customer negligence on the bank, not you. Sharing OTP under social-engineering pressure (impersonation of bank / RBI / police) has been treated by multiple Ombudsman orders as "fraud-induced sharing", not negligence. Your reply email to the bank should specifically rebut: "I was induced by impersonation of [bank / RBI / police / family]; the disclosure was extracted by deception, which under the customer-liability circular and consistent Ombudsman orders is fraud-induced and not negligence on my part."
 +
 +===== Frequently Asked Questions =====
 +
 +==== What is the 3-working-day rule and is it really automatic? ====
 +
 +The 3-working-day rule is the customer-protection lever inside the RBI Circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017. If you report an unauthorised electronic transaction to your bank in writing within 3 working days of the bank's transaction alert, and you did not contribute to the fraud through gross negligence (such as writing your PIN on the card), your liability is zero and the bank must credit the disputed amount within 10 working days. The burden of proving that you were grossly negligent shifts to the bank.
 +
 +==== Is calling 1930 enough, or do I need to file at cybercrime.gov.in too? ====
 +
 +Both. Calling 1930 opens an immediate ticket and triggers a freeze attempt at the recipient bank, but the call alone does not create a permanent paper-trail you can attach to the bank email or Ombudsman case. Filing at cybercrime.gov.in immediately afterwards generates a written NCRP acknowledgement number, which is the document you actually need. Do both: call 1930 first for speed, file at cybercrime.gov.in within the same hour for paper.
 +
 +==== Will the police actually register an FIR for an online fraud? ====
 +
 +Yes. Section 173 of the BNSS, 2023 (which replaced CrPC 154) makes it mandatory for any police station to register an FIR for a cognisable offence, regardless of jurisdiction - the BNSS gives statutory backing to the "zero FIR". If a station refuses, write to the SP / DCP and copy the State Human Rights Commission and the State CID's cyber wing. The NCRP filing is itself treated as an FIR-equivalent in many states for losses above their threshold.
 +
 +==== Can I get my money back if I voluntarily transferred it to a scammer? ====
 +
 +Harder, but not impossible. Voluntary transfers under deception (someone claiming to be a relative in trouble, an HR department, a delivery courier) can still constitute "cheating by personation" under BNS, 2023 Sections 318 and 319. The bank may argue this falls outside the RBI customer-liability circular's "unauthorised" definition. But you can still attempt: (a) NCRP freeze if the recipient account is still active, (b) chargeback if it was on a card, (c) civil suit for recovery, (d) Ombudsman complaint citing inadequate fraud monitoring. Speed matters - the earlier you act, the better the odds.
 +
 +==== Does the bank really give a "shadow credit" in 10 working days? ====
 +
 +The RBI circular at paragraph 8 envisages a credit (often called a "shadow credit") of the disputed amount within 10 working days of the customer's written report, while the bank investigates. Many banks delay this, especially if they want to argue customer negligence. A clear written email citing the specific circular paragraph and copying the nodal officer pushes most banks to give the credit. If they still refuse, that refusal itself becomes a deficiency under the Consumer Protection Act, 2019 and a separate ground in your RBI Ombudsman complaint.
 +
 +==== Should I close my bank account after a fraud? ====
 +
 +Generally, no - not immediately. Closing the account ends the dispute trail with that bank and complicates the refund. Instead, lock everything that can be locked: debit card, internet banking, UPI, mobile banking. Open a fresh, clean account at another bank for new transactions and salary credits, but keep the compromised account open with zero balance and active monitoring until the dispute closes. Move SIPs and auto-debits to the new account in writing. Once the refund is credited and the dispute fully closes, you can reassess whether to close the old account.
 +
 +==== What is the RBI Ombudsman and how is it different from a court? ====
 +
 +The **Reserve Bank - Integrated Ombudsman Scheme, 2026 (RB-IOS 2026)**, in force from 1 July 2026, is a free, online dispute-resolution mechanism for banking, NBFC, and payment-system grievances (the "One Nation One Ombudsman" framework). You file at cms.rbi.org.in after waiting 30 days from your written complaint to the bank. The Ombudsman can award compensation up to **₹30 lakh** for consequential loss, plus up to **₹3 lakh** for mental harassment, time, and expense. The process is faster than a civil suit, paper-based, and has no lawyer requirement. For most online payment fraud cases, the Ombudsman is the correct forum after the bank refuses.
 +
 +==== Can I file a consumer commission case against the bank? ====
 +
 +Yes. Banking is a "service" under Section 2(42) of the Consumer Protection Act, 2019, and a wrongful debit or refusal to refund is a "deficiency in service" under Section 2(11). You can file at the e-Daakhil portal at the District Commission for amounts up to ₹50 lakh, the State Commission for amounts between ₹50 lakh and ₹2 crore, and the National Commission above ₹2 crore (these pecuniary limits were set by the Consumer Protection (Jurisdiction of the District/State/National Commission) Rules, 2021). Many victims combine the RBI Ombudsman path with a parallel consumer complaint. See our [[https://righttoinformation.wiki/consumer-court-how-to-file-india|how to file a consumer court case]] guide.
 +
 +==== What if the fraudster is in another country? ====
 +
 +International cyber fraud is harder but not hopeless. The Mutual Legal Assistance Treaty (MLAT) network and Interpol Red Notices apply for large amounts. For a citizen, the practical route is: (a) NCRP forwards to I4C, which liaises with international agencies; (b) FIR with the cyber cell; (c) bank chargeback if it was a card transaction (chargebacks work even for offshore merchants); (d) RBI Ombudsman against your bank for any failure of monitoring. Money routed through Indian mule accounts is more recoverable; money already converted to crypto and moved offshore is mostly not.
 +
 +==== Are recovery agents on Telegram or YouTube safe to hire? ====
 +
 +No. The "recovery agent" market is dominated by the same fraud networks. Real recovery is free - 1930, NCRP, your bank, RBI Ombudsman, and the consumer commission. Anyone asking for a "registration fee", "GST", "release charge", "tax clearance", or "advance commission" is a recovery scammer. Some pose as "ex-cyber officers", "law firms", or "specialised recovery experts" with fake testimonial videos. They will eventually ask for your remaining bank credentials. The single most reliable signal: if they want money upfront, they are scamming you.
 +
 +===== Sources and official links =====
 +
 +  * RBI Circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017 - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions - [[https://www.rbi.org.in|rbi.org.in]]
 +  * Reserve Bank - Integrated Ombudsman Scheme, 2026 (RB-IOS 2026) - file at [[https://cms.rbi.org.in|cms.rbi.org.in]]
 +  * National Cybercrime Reporting Portal - [[https://www.cybercrime.gov.in|cybercrime.gov.in]] | helpline 1930
 +  * NPCI UPI Dispute Resolution - [[https://www.npci.org.in|npci.org.in]]
 +  * Information Technology Act, 2000 (Sections 66, 66C, 66D) - [[https://www.meity.gov.in|meity.gov.in]]
 +  * Bharatiya Nyaya Sanhita, 2023 (Sections 308, 318, 319, 336, 351) - [[https://www.indiacode.nic.in|indiacode.nic.in]]
 +  * Bharatiya Nagarik Suraksha Sanhita, 2023 (Section 173) - [[https://www.indiacode.nic.in|indiacode.nic.in]]
 +  * Consumer Protection Act, 2019 - [[https://consumeraffairs.nic.in|consumeraffairs.nic.in]]
 +  * UIDAI Aadhaar lock / unlock - [[https://www.uidai.gov.in|uidai.gov.in]]
 +  * TRAI complaint portal - [[https://www.trai.gov.in|trai.gov.in]]
 +
 +===== Related on RTI Wiki =====
 +
 +  * [[https://righttoinformation.wiki/fake-job-executive-course-scams-india|Fake job and executive course scams in India]] - parent article in this series
 +  * [[https://righttoinformation.wiki/edtech-refund-complaint-india|Edtech refund complaint in India]]
 +  * [[https://righttoinformation.wiki/aeps-aadhaar-fraud-recovery|AePS / Aadhaar-enabled payment fraud recovery]]
 +  * [[https://righttoinformation.wiki/loan-app-harassment-india|Loan app harassment and EMI extortion in India]]
 +  * [[https://righttoinformation.wiki/fake-linkedin-recruiter-scam-india|Fake LinkedIn recruiter scam in India]]
 +  * [[https://righttoinformation.wiki/fake-university-degree-scam-india|Fake university and degree scam in India]]
 +  * [[https://righttoinformation.wiki/coaching-institute-refund-rights-india|Coaching institute refund rights in India]]
 +  * [[https://righttoinformation.wiki/consumer-court-how-to-file-india|How to file a consumer court case in India]]
 +  * [[https://righttoinformation.wiki/file-consumer-complaint-ncdrc-2026|How to file a consumer complaint at NCDRC]]
 +
 +//Last reviewed: 17 July 2026.//
 +
 +{{tag>banking upi fir rbi 1930 payment fraud recovery}}