Differences
This shows you the differences between two versions of the page.
| — | online-seller-otp-refund-scam-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== Online Seller Asking for OTP for Refund: Scam Recovery (2026) ====== | ||
| + | |||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** Got a call from " | ||
| + | </ | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | **Quick Answer:** No genuine seller, marketplace, | ||
| + | |||
| + | ===== A real story from last month ===== | ||
| + | |||
| + | A homemaker in Pune ordered a ₹2,400 air-fryer, returned it because the heating coil was defective, and waited for the refund. Three days later her phone rang. The caller knew her order ID, the return reason, the courier pickup date, even the partial UPI ID she had paid with. He said the " | ||
| + | |||
| + | She got every rupee back inside 11 days. This guide walks through exactly what she did and how the legal framework forces banks to refund you when you act fast. | ||
| + | |||
| + | ===== Section 1: What this scam actually is ===== | ||
| + | |||
| + | The "share OTP for refund" | ||
| + | |||
| + | * "Your refund of ₹X is stuck." | ||
| + | * "We need to verify your account before releasing it." | ||
| + | * "An OTP has been sent, please read it out." | ||
| + | * Or alternatively: | ||
| + | * Or: "Click this link to update your bank IFSC." | ||
| + | |||
| + | What you are actually doing when you "share the OTP" is one of three things, depending on which variant the gang runs: | ||
| + | |||
| + | - **Authorising a UPI autopay mandate** that lets them pull money from your account every day for the next 364 days, up to ₹15,000 per transaction without further OTP, under NPCI's UPI AutoPay rules. | ||
| + | - **Approving a SIM swap** request with your telecom operator, after which they receive every future OTP you would have got. | ||
| + | - **Confirming a " | ||
| + | |||
| + | In all three the user has technically pressed " | ||
| + | |||
| + | ===== Section 2: The exact moment you must hang up ===== | ||
| + | |||
| + | One sentence ends every legitimate refund call: //"You don't need to do anything, the money will reflect in 3 to 5 working days."// | ||
| + | |||
| + | * Any request to **share OTP, PIN, CVV, or password**: scam. | ||
| + | * Any request to **scan a QR code to receive money**: scam (QR codes only //send// money on UPI). | ||
| + | * Any request to **install AnyDesk, TeamViewer, QuickSupport, | ||
| + | * Any request to **make a small ₹1 or ₹10 " | ||
| + | * Any threat that **"the refund will lapse in 10 minutes" | ||
| + | * Any caller claiming to be from **"RBI refund cell" | ||
| + | |||
| + | Hang up. Do not be polite. Block the number, then forward the SMS (if any) to **1909**, the DoT's spam-complaint number under the Telecom Commercial Communications Customer Preference Regulations. | ||
| + | |||
| + | ===== Section 3: If you already shared the OTP, this is the 60-minute drill ===== | ||
| + | |||
| + | The first hour is everything. The RBI Master Direction on Limited Liability of Customers (2017) creates three liability bands based on how fast you report. Inside the **zero-liability** band, the bank carries 100% of the loss. The clock starts the moment the unauthorised transaction is processed, not the moment you discover it. | ||
| + | |||
| + | Step 1, minute 0 to 5: dial **1930**, the National Cyber Crime Helpline. It loops in every major bank's fraud desk, the issuing and beneficiary banks, and the payment system operator. Quote your UTR. The operator files a stop-payment request within minutes; if the money is still in the mule account, it gets frozen. | ||
| + | |||
| + | Step 2, minute 5 to 15: log into **https:// | ||
| + | |||
| + | Step 3, minute 15 to 30: call your bank's 24x7 fraud line and **block all digital channels**: net banking, mobile banking, UPI handles, autopay mandates. Use the phrase "I want to invoke RBI Master Direction on Limited Liability of Customers, 2017, to report an unauthorised electronic banking transaction." | ||
| + | |||
| + | Step 4, minute 30 to 60: visit your branch with the acknowledgement, | ||
| + | |||
| + | Step 5, within 24 hours: revoke all UPI autopay mandates inside your app (Settings → Autopay → Active mandates → Revoke). | ||
| + | |||
| + | ===== Section 4: The legal framework that protects you ===== | ||
| + | |||
| + | This is the sentence most victims never hear: **the bank must refund you, by law, if you reported within the window.** Stop apologising and start citing. | ||
| + | |||
| + | * **IT Act 2000, Section 66D**: cheating by personation using a computer resource. Up to 3 years' imprisonment and ₹1 lakh fine. Covers every "I am the seller, share OTP" call. | ||
| + | * **IT Act 2000, Section 66C**: identity theft using electronic signature, password, or any other unique identification feature. Up to 3 years and ₹1 lakh fine. Covers the fraudster using your OTP. | ||
| + | * **Bharatiya Nyaya Sanhita 2024, Section 318**: cheating, including dishonest inducement to deliver property. Up to 7 years' imprisonment for cheating with knowledge of likely wrongful loss. | ||
| + | * **BNS, 2023, Section 319**: cheating by personation. Up to 5 years. | ||
| + | * **BNS, 2023, Section 336**: forgery, including electronic records. Up to 7 years. | ||
| + | * **RBI Master Direction on Limited Liability of Customers in Unauthorised Electronic Banking Transactions, | ||
| + | * **IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, Rule 4(2)**: significant social-media intermediaries must trace the first originator of fraudulent messages on court order. | ||
| + | * **Information Technology (Reasonable Security Practices) Rules 2011**: e-commerce platforms must protect " | ||
| + | |||
| + | The Supreme Court in //Avnish Bajaj v. State// (2008) settled that intermediaries cannot hide behind "we are just a platform" | ||
| + | |||
| + | ===== Section 5: Why "I authorised it" is not a defence the bank can use ===== | ||
| + | |||
| + | Banks routinely tell victims "you yourself entered the OTP, so it is not unauthorised." | ||
| + | |||
| + | If your bank refuses to refund within 10 working days, escalate to: | ||
| + | |||
| + | - **The bank's Internal Ombudsman** (mandatory in every scheduled commercial bank since 2018). | ||
| + | - **RBI Integrated Ombudsman Scheme 2021**, file at **https:// | ||
| + | - **Consumer Commission** under the Consumer Protection Act 2019, with deficiency-of-service as the cause of action. | ||
| + | |||
| + | ===== Section 6: How to spot the fake refund call before you pick up ===== | ||
| + | |||
| + | A few telltale patterns that distinguish scammers from real customer-care agents: | ||
| + | |||
| + | * Real platforms send refunds **silently**. Flipkart, Amazon, Meesho, Myntra, Nykaa, Snapdeal, JioMart: none call to " | ||
| + | * Real banks **never** ask for OTP. HDFC, ICICI, SBI, Axis, Kotak fraud desks open every call with "we will never ask for OTP." | ||
| + | * Real couriers (Delhivery, Bluedart, Ekart, India Post) never handle refunds. The refund is between you and the seller. | ||
| + | * Caller-ID spoofing is cheap. End the call and dial back via the **app' | ||
| + | * Caller asking for **WhatsApp OTP**: a parallel attack covered in the [[: | ||
| + | |||
| + | ===== Section 7: The autopay mandate trap ===== | ||
| + | |||
| + | This is the most expensive variant. An " | ||
| + | |||
| + | To check for fraudulent mandates //right now//: | ||
| + | |||
| + | - Open your UPI app (PhonePe, Google Pay, Paytm, BHIM, Amazon Pay). | ||
| + | - Navigate to Profile → Autopay (or Mandates). | ||
| + | - Review every active mandate. Anything unrecognised: | ||
| + | - Screenshot before revoking, for the FIR. | ||
| + | |||
| + | A detailed walkthrough is at [[: | ||
| + | |||
| + | ===== Section 8: What to do if the marketplace blames you ===== | ||
| + | |||
| + | Platforms sometimes say "we don't make calls, contact your bank." This is legally wrong if the scammer used //data leaked from the platform//: order ID, return reason, partial payment details, courier name. Under IT Act §43A and the 2011 SPDI Rules, the platform is a body corporate handling sensitive personal data and is liable for compensation if it failed reasonable security practices. | ||
| + | |||
| + | File a written complaint with the platform' | ||
| + | |||
| + | If refused, file at **https:// | ||
| + | |||
| + | ===== Section 9: Reporting tree at a glance ===== | ||
| + | |||
| + | **Phone first, paperwork later.** This sequence has the best documented recovery rate. | ||
| + | |||
| + | - **1930** (NCRP helpline): 0 to 60 minutes after fraud. | ||
| + | - **Bank' | ||
| + | - **https:// | ||
| + | - **Local cyber-crime police station**: within 72 hours if the loss exceeds ₹10 lakh or involves multiple victims. | ||
| + | - **Marketplace Grievance Officer**: within 7 days, email with all evidence. | ||
| + | - **Bank Internal Ombudsman**: | ||
| + | - **RBI Integrated Ombudsman, https:// | ||
| + | - **District Consumer Commission**: | ||
| + | |||
| + | ===== Section 10: Evidence checklist ===== | ||
| + | |||
| + | Save these immediately, | ||
| + | |||
| + | * Screenshot of the incoming-call log. | ||
| + | * Screenshot of the OTP SMS with timestamp. | ||
| + | * Screenshot of every UPI debit and mandate creation. | ||
| + | * Screenshot of active UPI autopay mandates. | ||
| + | * Screenshot of the e-commerce return/ | ||
| + | * Bank statement PDF for 7 days around the fraud. | ||
| + | * Voice recording of the fraud call (if available). | ||
| + | * Order confirmation and return-acceptance emails. | ||
| + | * WhatsApp messages with the " | ||
| + | |||
| + | Send all in one zip to the cyber-crime portal. The upload field has a 10MB cap and 5-attachment limit; a zip counts as one. | ||
| + | |||
| + | ===== Section 11: Filing an RTI to find out what your bank actually did ===== | ||
| + | |||
| + | If 30 days pass and your bank has neither refunded nor given a written explanation, | ||
| + | |||
| + | Sample questions to ask under the RTI Act 2005: | ||
| + | |||
| + | - " | ||
| + | - "State the date on which the bank reported the unauthorised transaction to the National Payments Corporation of India and the beneficiary bank." | ||
| + | - " | ||
| + | - "State whether the matter was referred to the Internal Ombudsman, with date of reference and date of decision." | ||
| + | |||
| + | Drafting an RTI to a bank's PIO is non-trivial and the wording matters. The free [[: | ||
| + | |||
| + | ===== Section 12: Prevention, the only thing that scales ===== | ||
| + | |||
| + | Recovery is partial, slow, and stressful. Prevention is total, instant, and free. | ||
| + | |||
| + | * **Set a UPI per-day cap of ₹10,000** in your UPI app settings. Genuine refunds never exceed this. A fraudster who steals your OTP cannot drain more than ₹10k before being throttled. | ||
| + | * **Freeze ECS/ | ||
| + | * **Use a separate " | ||
| + | * **Enable transaction SMS alerts** for every debit above ₹1, not the default ₹1,000. This makes the first ₹1 " | ||
| + | * **Disable international card transactions** until the day you actually need them. | ||
| + | * **Lock your SIM** with a SIM-PIN (Settings → Security → SIM lock on iOS, Settings → Lock screen on Android). This blocks SIM-swap attacks even if the gang social-engineers your telecom store. | ||
| + | * **Never read out any code, even if the caller " | ||
| + | * **Bookmark the official customer-care number** of every platform you use, do not rely on Google. Google' | ||
| + | |||
| + | ===== Section 13: Cross-link map for related scams ===== | ||
| + | |||
| + | OTP-refund scams overlap with several adjacent fraud families. Each has its own dedicated guide: | ||
| + | |||
| + | * [[: | ||
| + | * [[: | ||
| + | * [[: | ||
| + | * [[: | ||
| + | * [[: | ||
| + | * [[: | ||
| + | * [[: | ||
| + | * [[: | ||
| + | |||
| + | ===== Section 14: One-page action sheet to screenshot ===== | ||
| + | |||
| + | If you only remember one thing from this article, remember this checklist. Save it to your phone gallery. The next time someone calls about a " | ||
| + | |||
| + | - Caller asks for OTP, PIN, password, or QR scan? **Hang up.** No exceptions. | ||
| + | - Already shared? Dial **1930** in the next 5 minutes. | ||
| + | - Open https:// | ||
| + | - Call bank fraud line, invoke "RBI Master Direction 2017." | ||
| + | - Revoke every UPI autopay mandate in your app. | ||
| + | - Collect all 9 evidence items in one zip. | ||
| + | - File grievance with marketplace within 7 days. | ||
| + | - If bank stalls 10 working days, file at https:// | ||
| + | - Use [[: | ||
| + | - Tell three other people about this article. The fraudsters' | ||
| + | |||
| + | The Pune homemaker who lost ₹1,99,000 got everything back in 11 days because she did exactly this, in this order, without delay or self-blame. The law is on your side. Use it loudly. | ||
| + | |||
| + | ---- | ||
| + | |||
| + | //Last updated: 2026-05-07. This article is not legal advice. For case-specific guidance consult a licensed lawyer or a recognised legal-aid clinic. Statute references current as of the date above; check the latest position before acting.// | ||
| + | |||
| + | {{tag> | ||