Online Seller Asking for OTP: Scam Recovery 2026
Last reviewed: 1 September 2026.
Quick Reply: Got a call from “seller” asking for OTP to process refund? Never share. Block UPI mandate, file NCRP 1930, recover money under RBI 2017 rules.
RBI Ombudsman as of 1 July 2026: Bank, certain NBFC, prepaid-instrument and credit-information complaints go under the Reserve Bank - Integrated Ombudsman Scheme, 2026, which replaced RB-IOS 2021 from 1 July 2026. First complain to the entity. If there is no reply in 30 days (or the longer NPCI/card-network window, if it applies) or you reject the reply, file free at cms.rbi.org.in within 90 days. The Ombudsman can award up to Rs 30 lakh for consequential loss and up to Rs 3 lakh for time, expenses and harassment. Complaints received before 1 July 2026 stay under the 2021 scheme. Source: RBI FAQ, updated 1 July 2026 and the RB-IOS 2026 FAQ PDF dated 1 July 2026.
Quick Answer: No genuine seller, marketplace, courier, or bank ever needs your OTP to process a refund. Refunds always flow into your account through the original payment channel (UPI, card, wallet) and require no authentication on your end. The moment a “seller” or “support agent” calls you after a return or dispute and asks you to “share OTP,” “approve a request,” or “scan a QR code,” it is a confirmed scam attempt to either drain your account via a UPI autopay mandate or hijack your SIM/banking session. Hang up, do not press any number, and if you have already shared anything, dial NCRP 1930 within 60 minutes and freeze your bank account through the official channel. Report inside the zero-liability window — within 3 working days of the bank's alert — and the RBI's customer-protection circular of 6 July 2017 puts the entire loss on the bank.
An illustrative case (not a named person)
A homemaker in Pune ordered a ₹2,400 air-fryer, returned it because the heating coil was defective, and waited for the refund. Three days later her phone rang. The caller knew her order ID, the return reason, the courier pickup date, even the partial UPI ID she had paid with. He said the “refund team” could not push the money back because of a “KYC mismatch” and asked her to read out a 6-digit code. She read it. Within 90 seconds ₹1,99,000 left her account in four UPI transactions, all showing as “approved by user” because she had unwittingly authorised an autopay mandate.
— an illustrative account. This guide walks through the same steps such a victim should take, and how the legal framework obliges the bank to refund money when you act inside the reporting window.
Section 1: What this scam actually is
The “share OTP for refund” scam is a social-engineering attack that exploits the gap between when you expect money and when it actually arrives. The fraudster has either bought your order data from a leaky logistics partner, scraped it from a fake-courier phishing page, or simply guessed it after you posted a review. They call posing as the seller, the marketplace, the courier, or the payment gateway. The script is always the same:
- “Your refund of ₹X is stuck.”
- “We need to verify your account before releasing it.”
- “An OTP has been sent, please read it out.”
- Or alternatively: “Please scan this QR code to receive the refund.”
- Or: “Click this link to update your bank IFSC.”
What you are actually doing when you “share the OTP” is one of three things, depending on which variant the gang runs:
- Authorising a UPI autopay mandate that lets them pull money from your account again and again — per-transaction debits up to ₹15,000 go through with no further OTP — under NPCI's UPI AutoPay rules.
- Approving a SIM swap request with your telecom operator, after which they receive every future OTP you would have got.
- Confirming a “collect request” on UPI that pulls money out of your account even though the screen says “to receive.”
In all three the user has technically pressed “yes.” Do not blame yourself. Indian law treats unauthorised electronic transactions as the bank's liability the moment you report them inside the prescribed window.
Section 2: The exact moment you must hang up
One sentence ends every legitimate refund call: “You don't need to do anything, the money will reflect in 3 to 5 working days.” If the caller deviates from that, the call is fraudulent. Specifically:
- Any request to share OTP, PIN, CVV, or password: scam.
- Any request to scan a QR code to receive money: scam (QR codes only send money on UPI).
- Any request to install AnyDesk, TeamViewer, QuickSupport, or “RBI Helper”: scam.
- Any request to make a small ₹1 or ₹10 “verification” transaction: scam.
- Any threat that “the refund will lapse in 10 minutes”: scam.
- Any caller claiming to be from “RBI refund cell” or “income-tax refund department”: RBI does not call individuals, ever, full stop.
Hang up. Do not be polite. Block the number, then forward the SMS (if any) to 1909, the DoT's spam-complaint number under the Telecom Commercial Communications Customer Preference Regulations.
Section 3: If you already shared the OTP, this is the 60-minute drill
The first hour is everything. The RBI's customer-protection circular of 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions creates three liability bands based on how fast you report. Inside the zero-liability band, the bank carries 100% of the loss. The three-day clock runs from when you receive the bank's communication about the transaction — usually the debit SMS itself — so report the same day.
Step 1, minute 0 to 5: dial 1930, the National Cyber Crime Helpline. It loops in every major bank's fraud desk, the issuing and beneficiary banks, and the payment system operator. Quote your UTR. The operator files a stop-payment request within minutes; if the money is still in the mule account, it gets frozen.
Step 2, minute 5 to 15: log into https://cybercrime.gov.in and file a written complaint under “Financial Fraud.” Save the acknowledgement PDF.
Step 3, minute 15 to 30: call your bank's 24×7 fraud line and block all digital channels: net banking, mobile banking, UPI handles, autopay mandates. Use the phrase “I am reporting an unauthorised electronic banking transaction under the RBI customer-protection circular of 6 July 2017.”
Step 4, minute 30 to 60: visit your branch with the acknowledgement, call recording (if any), and a written complaint to the Branch Manager. Get a stamped receipt.
Step 5, within 24 hours: revoke all UPI autopay mandates inside your app (Settings → Autopay → Active mandates → Revoke).
Section 4: The legal framework that protects you
This is the sentence most victims never hear: the bank must refund you, by law, if you reported within the window. Stop apologising and start citing.
- IT Act 2000, Section 66D: cheating by personation using a computer resource. Up to 3 years' imprisonment and ₹1 lakh fine. Covers every “I am the seller, share OTP” call.
- IT Act 2000, Section 66C: identity theft using electronic signature, password, or any other unique identification feature. Up to 3 years and ₹1 lakh fine. Covers the fraudster using your OTP.
- Bharatiya Nyaya Sanhita 2023, Section 318(4): cheating and dishonestly inducing delivery of property. Up to 7 years' imprisonment.
- BNS, 2023, Section 319(2): punishment for cheating by personation. Up to 5 years.
- BNS, 2023, Section 336(3): forgery for the purpose of cheating, including electronic records. Up to 7 years.
- RBI circular “Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions”, 6 July 2017: zero customer liability if reported within 3 working days, capped liability of ₹5,000 to ₹25,000 per transaction if reported within 4 to 7 working days, and after that liability only as per the bank's Board-approved policy. Burden of proof is on the bank, not on you.
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, Rule 4(2): significant social-media intermediaries must trace the first originator of fraudulent messages on court order.
- Information Technology (Reasonable Security Practices) Rules 2011: e-commerce platforms must protect “sensitive personal data” and are liable for compensation under IT Act §43A if they leak your order data to scammers.
Shreya Singhal v. Union of India (2015) 5 SCC 1 held that an intermediary must disable offending content once it gains “actual knowledge” through a court or government order, or lose its safe harbour. Separately, your written grievance to the marketplace's Grievance Officer under the IT Rules 2021 creates a dated, enforceable trail.
Section 5: Why "I authorised it" is not a defence the bank can use
Banks routinely tell victims “you yourself entered the OTP, so it is not unauthorised.” This is wrong in law. An OTP shared under deception is vitiated consent, like a signature obtained by fraud. Paragraph 12 of the RBI's 6 July 2017 circular puts the burden of proving customer liability on the bank — the bank must establish that you were negligent, and a code read out under deception is not free-flowing consent.
If your bank refuses to refund within 10 working days, escalate to:
- The bank's Internal Ombudsman — an internal second-look authority that reviews complaints the bank proposes to reject; ask the bank in writing to refer your rejected complaint to it.
- RBI Integrated Ombudsman Scheme, 2026, file at https://cms.rbi.org.in. Decision is binding up to ₹30 lakh.
- Consumer Commission under the Consumer Protection Act 2019, with deficiency-of-service as the cause of action.
Section 6: How to spot the fake refund call before you pick up
A few telltale patterns that distinguish scammers from real customer-care agents:
- Real platforms send refunds silently. Flipkart, Amazon, Meesho, Myntra, Nykaa, Snapdeal, JioMart: none call to “process” a refund. The email or in-app notification is the only legitimate touchpoint.
- Real banks never ask for OTP. HDFC, ICICI, SBI, Axis and Kotak all publish the same warning: their staff will never ask you for an OTP.
- Real couriers (Delhivery, Bluedart, Ekart, India Post) never handle refunds. The refund is between you and the seller.
- Caller-ID spoofing is cheap. End the call and dial back via the app's official help section, never Google search results (see fake customer-care numbers guide).
- Caller asking for WhatsApp OTP: a parallel attack covered in the WhatsApp OTP fraud explainer.
Section 7: The autopay mandate trap
This is the most expensive variant. An “approved” UPI autopay mandate gives a merchant standing instructions to debit your account up to a stated cap, daily, weekly, or monthly, for the life of the mandate, with per-transaction debits up to ₹15,000 requiring no further OTP. Fraudsters abuse this with shell merchant IDs.
To check for fraudulent mandates right now:
- Open your UPI app (PhonePe, Google Pay, Paytm, BHIM, Amazon Pay).
- Navigate to Profile → Autopay (or Mandates).
- Review every active mandate. Anything unrecognised: revoke immediately.
- Screenshot before revoking, for the FIR.
A detailed walkthrough is at the UPI autopay mandate fraud guide. For the “stuck UTR” problem, see UPI deducted but not received.
Section 8: What to do if the marketplace blames you
Platforms sometimes say “we don't make calls, contact your bank.” This is legally wrong if the scammer used data leaked from the platform: order ID, return reason, partial payment details, courier name. Under IT Act §43A and the 2011 SPDI Rules, the platform is a body corporate handling sensitive personal data and is liable for compensation if it failed reasonable security practices.
File a written complaint with the platform's Grievance Officer (every intermediary must publish the Grievance Officer's name and contact details under the IT Rules 2021). The Grievance Officer must acknowledge within 24 hours and resolve the complaint within 15 days (Rule 3(7)).
If refused, file at https://consumerhelpline.gov.in (Ministry of Consumer Affairs) or at the District Consumer Commission under the Consumer Protection Act 2019 (pecuniary jurisdiction up to ₹50 lakh).
Section 9: Reporting tree at a glance
Phone first, paperwork later. This sequence has the best documented recovery rate.
- 1930 (NCRP helpline): 0 to 60 minutes after fraud.
- Bank's 24×7 fraud line: 0 to 60 minutes, parallel to 1930.
- https://cybercrime.gov.in: within 24 hours, written FIR-equivalent.
- Local cyber-crime police station: in parallel, for the written complaint trail — essential for large losses or multiple-victim frauds.
- Marketplace Grievance Officer: within 7 days, email with all evidence.
- Bank Internal Ombudsman: if bank does not refund within 10 working days.
- RBI Integrated Ombudsman, https://cms.rbi.org.in: once the bank rejects your complaint or lets 30 days pass without a reply.
- District Consumer Commission: parallel track for compensation beyond the refund.
Section 10: Evidence checklist
Save these immediately, because retrieving telecom and bank records gets harder with every passing week:
- Screenshot of the incoming-call log.
- Screenshot of the OTP SMS with timestamp.
- Screenshot of every UPI debit and mandate creation.
- Screenshot of active UPI autopay mandates.
- Screenshot of the e-commerce return/refund page.
- Bank statement PDF for 7 days around the fraud.
- Voice recording of the fraud call (if available).
- Order confirmation and return-acceptance emails.
- WhatsApp messages with the “agent.”
Send everything to the cyber-crime portal in one zip — the complaint form caps the number and size of attachments, so keep the file small.
Section 11: Filing an RTI to find out what your bank actually did
If 30 days pass and your bank has neither refunded nor given a written explanation, an RTI to the bank's nodal Public Information Officer is the lever that breaks the silence. Public-sector banks (SBI, PNB, BoB, Canara, Union Bank, Indian Bank, etc.) are fully covered under the RTI Act 2005. Private banks are not directly covered, but the RBI is, and an RTI to the RBI asking “what action has the RBI taken on consumer complaint number XYZ filed against [bank name]” produces results.
Sample questions to ask under the RTI Act 2005:
- “Provide a copy of all internal correspondence regarding complaint number [your reference] dated [date].”
- “State the date on which the bank reported the unauthorised transaction to the National Payments Corporation of India and the beneficiary bank.”
- “Provide the file noting recommending refund or rejection, along with the name and designation of the deciding authority.”
- “State whether the matter was referred to the Internal Ombudsman, with date of reference and date of decision.”
Drafting an RTI to a bank's PIO is non-trivial and the wording matters. The free AI RTI Drafter generates a compliant draft with the correct statutory references in under 60 seconds. For background on how the RTI Act 2005 works end to end, the complete RTI guide is the master reference.
Section 12: Prevention, the only thing that scales
Recovery is partial, slow, and stressful. Prevention is total, instant, and free.
- Set a UPI per-day cap of ₹10,000 in your UPI app settings. Genuine refunds never exceed this. A fraudster who steals your OTP cannot drain more than ₹10k before being throttled.
- Freeze ECS/NACH/autopay for accounts where you do not need them, by written instruction to the bank. Reactivate only when needed.
- Use a separate “shopping” bank account with only the float you need for online purchases. Keep your salary and savings in a different bank that has no UPI handle linked.
- Enable transaction SMS alerts for every debit above ₹1, not the default ₹1,000. This makes the first ₹1 “test” debit visible.
- Disable international card transactions until the day you actually need them.
- Lock your SIM with a SIM PIN (Settings → Phone → SIM PIN on iOS, Settings → Security → SIM lock on Android). This blocks SIM-swap attacks even if the gang social-engineers your telecom store.
- Never read out any code, even if the caller “verified” your name and order ID. Knowing your data does not authenticate them.
- Bookmark the official customer-care number of every platform you use, do not rely on Google. Google's “knowledge panel” has been gamed by SEO scammers for years.
Section 13: Cross-link map for related scams
OTP-refund scams overlap with several adjacent fraud families. Each has its own dedicated guide:
- WhatsApp OTP fraud for account-takeover variant.
- UPI deducted but not received for the stuck-UTR variant.
- UPI autopay mandate fraud for the silent-recurring-debit variant.
- Fake customer-care number scam for the Google-search-result variant.
- Fake court summons WhatsApp scam for the threat-based extortion variant.
- Coaching institute refund rights for the offline-education refund family, where similar OTP tricks are used.
- Weekend problem solver for the master index of all weekend-published help articles.
- Citizen crisis response network for the live-support directory of state and central helplines.
Section 14: One-page action sheet to screenshot
If you only remember one thing from this article, remember this checklist. Save it to your phone gallery. The next time someone calls about a “refund,” open this image, follow the boxes in order:
- Caller asks for OTP, PIN, password, or QR scan? Hang up. No exceptions.
- Already shared? Dial 1930 in the next 5 minutes.
- Open https://cybercrime.gov.in within 30 minutes, file written FIR.
- Call bank fraud line, invoke the RBI customer-protection circular of 6 July 2017.
- Revoke every UPI autopay mandate in your app.
- Collect all 9 evidence items in one zip.
- File grievance with marketplace within 7 days.
- If bank stalls 10 working days, file at https://cms.rbi.org.in.
- Use AI RTI Drafter to extract the bank's file noting under RTI Act 2005.
- Tell three other people about this article. The fraudsters' business model dies the day every household knows the rule: genuine refunds never need an OTP from you.
In the illustrative case that opened this article, every rupee came back in 11 days because the steps were followed in order, without delay or self-blame. The law is on your side. Use it loudly.
Last updated: 2026-05-07. This article is not legal advice. For case-specific guidance consult a licensed lawyer or a recognised legal-aid clinic. Statute references current as of the date above; check the latest position before acting.
