Get the RTI Wiki appFree on iPhone and Android.

How to recover money lost to UPI fraud — complete 2026 guide

RBI Ombudsman as of 1 July 2026: Bank, certain NBFC, prepaid-instrument and credit-information complaints go under the Reserve Bank - Integrated Ombudsman Scheme, 2026, which replaced RB-IOS 2021 from 1 July 2026. First complain to the entity. If there is no reply in 30 days (or the longer NPCI/card-network window, if it applies) or you reject the reply, file free at cms.rbi.org.in within 90 days. The Ombudsman can award up to Rs 30 lakh for consequential loss and up to Rs 3 lakh for time, expenses and harassment. Complaints received before 1 July 2026 stay under the 2021 scheme. Source: RBI FAQ, updated 1 July 2026 and the RB-IOS 2026 FAQ PDF dated 1 July 2026.

· 2026/08/22 03:33

How to recover money lost to UPI fraud 2026 — RTI Wiki citizen guide

Last reviewed: 1 September 2026.

Quick Reply: The first 60 minutes decide everything. Do these three things in parallel, not one after the other:

  1. Call 1930 — the national cybercrime helpline (24×7, MoHA). Operator coordinates an immediate fund-freeze with the receiving bank.
  2. Call your bank's 24×7 fraud line (SBI 1800-11-2211, HDFC 1800-258-6161, ICICI 1860-120-7777, Axis 1860-419-5555) — ask for an instant debit-freeze on your account.
  3. Open the UPI app (PhonePe / GPay / Paytm) → “Help” → “Report fraud / unauthorised transaction” → submit the transaction ref.

Within 24 hours, file a detailed complaint at cybercrime.gov.in. Within 3 working days, file a written dispute with your bank using their DRC (Dispute Resolution Committee) form. Under the RBI Limited Liability Circular dated 6 July 2017, if you report within 3 working days you are entitled to zero liability — the bank refunds you in full and recovers from the fraudster's bank later.

A victim's story — "₹2.4 lakh gone in one OTP, ₹2.1 lakh recovered in 75 days"

An illustrative case (not a named person). A 39-year-old IT manager in Pune. Got a call on 14 March 2025 at 11:42 am from a number that displayed a bank's name on Truecaller.

“The voice was calm, professional, even bored. He said my account would be deactivated in two hours if I didn't complete a 'pending KYC verification'. He read out my last four PAN digits — correctly. He asked me to read out an SMS code 'to confirm I'm the rightful holder'. I read it. Within four seconds, ₹2.4 lakh was debited from my SB account in three transactions to a current account at another bank in a name I'd never heard. I knew immediately what had happened. I called 1930. Total wait time on the helpline that morning — 9 minutes. The operator was sharp. She took the transaction IDs, my account number, the receiving account number from my SMS alerts, and within 35 minutes she had registered the case on NCRP. Parallelly I called my bank's fraud line. By 1:15 pm — about 90 minutes from the fraud — My bank confirmed they had flagged the receiving account; ₹1.6 lakh was already frozen there. By evening I had filed the full complaint at cybercrime.gov.in with 12 screenshots, the call recording, my bank statement, and the suspect mobile number. The cyber police station registered an FIR in 8 days under BNS 2023 §316/§318 plus IT Act §66D. The bank's internal investigation took 71 days. The Banking Ombudsman award came on the 75th day — ₹1.6 lakh refunded to me from frozen funds, ₹50,000 paid by the bank under the partial-liability slab (because by the bank's reckoning my report at 90 minutes counted as Day 1 — but the dispute form at the branch was signed Day 4, and they tried to use that), and ₹30,000 written off as unrecoverable. One OTP cost me ₹30,000 net. Without 1930 within the first hour, it would have been the full ₹2.4 lakh.

— an illustrative account

By I4C-compiled data, India logged over 36 lakh financial cyber-fraud complaints in 2024 with losses above ₹22,800 crore — of which only a small fraction (a little over ₹1,100 crore) came back through the 1930 pipeline. The single biggest predictor of recovery is how fast you call 1930. After the first 24 hours the odds fall sharply, and after a week they are poor — the money has usually been cashed out at the receiving end, and under the RBI circular full liability has shifted to you.

What this is — and the law that protects you

A UPI fraud is any unauthorised debit from your bank account through a UPI / IMPS / NEFT / RTGS rail where you did not knowingly authorise the receiving party. Common variants:

  • OTP fraud — caller poses as bank / NPCI / “RBI” and tricks you into reading an OTP.
  • KYC update scam — SMS or call says “your account will be blocked” and routes you to a fake link.
  • Fake QR scan — instead of receiving money you scan a “collect request” QR that debits you.
  • Screen-share scam — fraudster makes you install AnyDesk / TeamViewer / QuickSupport “to fix a stuck refund” and then operates your phone.
  • AnyDesk / remote-access fraud — variant of the above; full account drain.
  • Bank-executive impersonation — caller “from card desk” / “loan dept” extracts CVV + OTP.
  • Dating / matrimonial / sextortion fraud — emotional grooming → “emergency” UPI transfer → blackmail.
  • UPI auto-debit fraud / silent mandate — you approve a small mandate that quietly auto-debits later.

The core protection is the RBI Circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017 (“Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions”). The core rule:

  • Reported within 3 working days of receiving the transaction alert → zero liability on the customer. Bank refunds in full within 10 working days of report.
  • Reported within 4-7 working days → liability capped: ₹5,000 (BSBDA), ₹10,000 (most savings + ₹25 lakh credit cards), or ₹25,000 (high-balance / premium cards).
  • Reported after 7 working days → liability per the bank's Board-approved policy — usually 100% on the customer.

Other statutes you will see cited on FIRs and notices:

  • IT Act 2000 §66C — identity theft (use of someone's electronic signature / password / unique identifier).
  • IT Act 2000 §66D — cheating by personation using computer resource (the standard “OTP / KYC” charge).
  • BNS 2023 §316 — criminal breach of trust.
  • BNS 2023 §318 — cheating (replaces old IPC §420; 7 years + fine for cheating with delivery of property).
  • BNSS 2023 §173 — police's mandatory duty to register FIR for any cognisable offence (codifies Lalita Kumari v. Govt of UP, (2014) 2 SCC 1).

RBI's limited-liability rule (memorise this)

When you report Your liability
Within 3 working days ₹0 (zero)
Within 4–7 working days ₹5,000–₹25,000 depending on account type
After 7 working days Decided by bank's internal policy — usually full loss

The clock starts from the bank communication of the transaction (SMS / email).

Step-by-step process — three parallel tracks

Step 1 — Within the first hour: 1930 + bank fraud line + freeze

Open three things at the same time — your phone for 1930, a second phone or family member's phone for the bank line, and your UPI app.

  • 1930 — pickup typically inside 10 minutes. Have ready: your name, mobile, account number, transaction IDs, receiving UPI ID / account number, suspect mobile / fake caller's number. Operator registers the case on the National Cybercrime Reporting Portal (NCRP) and triggers the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) — the live fund-freezing pipe to member banks and wallet providers.
  • Bank fraud line — ask for an immediate debit-freeze on your account, stop-payment on cards, and a complaint reference number (note it down — you will need it for the written dispute and the Ombudsman).
  • UPI app → “Help” → “Report a Fraud” → fill the in-app form → screenshot the acknowledgement.

Do not click any link the fraudster sent. Do not install anything new. Do not reset your phone — you may destroy evidence.

Step 2 — Within 24 hours: file at cybercrime.gov.in

  • Open https://cybercrime.gov.in → “File a complaint” → “Report financial fraud” → register with mobile OTP.
  • Upload, in this order: bank SMS alerts (screenshots), bank statement showing the debits, transaction receipts from your UPI app, screenshots of any chat / call log with the fraudster, the fraudster's mobile number / UPI ID / website link.
  • The system generates an acknowledgement number beginning with the year (e.g., 2026XXXXXXXXX). Keep it safe — it links to the 1930 case automatically.
  • Within 15 days convert the online complaint to an FIR at your local cyber police station — the portal sends a copy of your complaint to the SP cyber cell; visit the PS with a printout + ID.

Step 3 — Within 3 working days: written dispute to the bank

This is the legal trigger for the 3-day zero-liability clock under the RBI circular. The 1930 call alone is not a written dispute.

  • Visit your bank's home branch (or the nearest branch). Ask for the Dispute Resolution Committee (DRC) form — sometimes called Form FRM, Form DRC, or “Unauthorised Transaction Dispute Form”.
  • Fill: transaction date / time / amount / reference, what happened, what protective steps you took, the 1930 case number, the cybercrime.gov.in acknowledgement, the FIR number (if filed).
  • Get a stamped acknowledgement copy with date and the receiving officer's signature. This is your single most important document.
  • Email a soft copy the same day to the bank's Nodal Officer (every bank lists this on its grievance page) and CC the Principal Nodal Officer.

Step 4 — Bank investigation + transaction reversal

  • The RBI framework requires the zero-liability amount to be credited within 10 working days of the decision; complex investigations can take longer — chase in writing every 15 days.
  • If the funds are still in the receiving bank's account, your bank may issue a Transaction Reversal (TR) — credit to your account, claim to be settled with the receiving bank.
  • For inter-bank cases the NPCI Online Dispute Resolution (ODR) mechanism is used — your bank initiates, NPCI brokers, receiving bank responds in T+5 days.

Step 5 — If unresolved at 90 days: Banking Ombudsman (RBIOS)

  • Free, online, fast. Open https://cms.rbi.org.in → “File a Complaint” → choose “Mobile / Electronic Banking” → fraud type.
  • Eligible only if (a) bank has rejected your complaint, OR (b) bank has not replied in 30 days from your written complaint, OR © you are unsatisfied with the bank's reply.
  • RBIOS has a 30-day SLA for first hearing and can award up to ₹30 lakh plus ₹3 lakh for time, expenses and harassment.
  • The Ombudsman directly applies the RBI Limited Liability Circular — most well-documented zero-liability cases are decided in your favour.

Step 6 — In parallel: the FIR

  • Cyber-crime is a cognisable offence. Police must register the FIR — Lalita Kumari is binding on every SHO.
  • If the SHO refuses, write to the SP / DCP under §173(4) BNSS, or move the Magistrate under §175(3) BNSS.

Step 7 — Civil suit for residual recovery (only for large amounts)

If the fraud amount is large (typically > ₹10 lakh) and the criminal recovery is slow, a summary suit under Order 37 CPC against the receiving account-holder (whose KYC the police will have on the FIR) is sometimes used to attach their property. This needs an advocate; NALSA can give a free panel lawyer if your annual income is under ₹3 lakh.

Step 8 — Hardening: what to do the same evening

  • Change your UPI PIN on every UPI app you use.
  • Change your net-banking password and m-banking MPIN.
  • Disable UPI Lite, UPI AutoPay, and any standing instructions you don't recognise.
  • Revoke screen-share / accessibility permissions on all installed apps.
  • Run Sanchar Saathi (sancharsaathi.gov.in) → check connections issued on your name; report fake SIMs.

Understanding the UPI chargeback

“Chargeback” in UPI is not identical to a credit card chargeback (which is a bilateral reversal scheme between card networks). In UPI, the dispute mechanism works through NPCI's dispute management layer, and the process is initiated by your PSP bank on your behalf after you file a complaint with the bank.

There is no direct “raise a chargeback” button for consumers at the NPCI level. You file with your bank, your bank logs it with NPCI, and NPCI arbitrates between the originating and beneficiary banks. For the current NPCI dispute flow and any updates to the in-app process, verify directly at npci.org.in, as NPCI periodically revises the dispute handling guidelines for member banks.

What chargeback can and cannot do:

  1. It can reverse a failed, duplicate, or technically erroneous transaction.
  2. It can sometimes freeze and recover funds from a fraudster's account if the complaint reaches the bank before withdrawal.
  3. It cannot reverse an authorised payment made under fraud once the funds have been withdrawn from the mule account.

Failed or wrong transactions: the automatic refund rule

This situation is different from fraud. If a UPI payment failed (debited but not credited to the receiver), or you paid the wrong person accidentally, the applicable rule is RBI circular RBI/2019-20/67 dated 20 September 2019 on “Harmonisation of Turn-Around Time and customer compensation for failed transactions.”

Key rules under this circular:

  1. If the beneficiary bank cannot credit the receiver, the beneficiary bank must auto-reverse the funds to your account by T+1 (the next business day after the transaction date).
  2. If the reversal is delayed beyond the prescribed timeline, your bank must pay you ₹100 per day as compensation, automatically, without you filing a separate claim.
  3. The circular covers UPI, IMPS, card-to-card transfers, NACH, and Aadhaar-enabled systems.

If you do not receive the auto-reversal within T+1, raise a complaint with your bank citing this circular. If the bank still does not act within 30 days of your complaint, escalate to the RBI Integrated Ombudsman (see Step 4).

For the broader money-refund process, see how to get defrauded money refunded.

Sample helpline + fee + SLA table

+-----------------------------------+--------------------------------------+
| 1930 cybercrime helpline (MoHA)   | FREE. 24x7. First-hour fund-freeze.  |
+-----------------------------------+--------------------------------------+
| cybercrime.gov.in complaint       | FREE. Acknowledgement instant.       |
|                                   | Convert to FIR within 15 days.       |
+-----------------------------------+--------------------------------------+
| Bank DRC / Dispute form           | FREE. Stamped acknowledgement is     |
|                                   | the legal trigger for RBI circular.  |
+-----------------------------------+--------------------------------------+
| RBI Limited Liability Circular    | Day 0-3 → ZERO liability             |
| 6 July 2017 — slabs               | Day 4-7 → ₹5,000 / ₹10,000 / ₹25,000 |
|                                   | Day 8+   → as per bank's policy      |
+-----------------------------------+--------------------------------------+
| Bank timelines                    | Zero-liability credit within 10      |
|                                   | working days of the decision.        |
+-----------------------------------+--------------------------------------+
| Banking Ombudsman (RBIOS)         | FREE. cms.rbi.org.in. 30-day SLA.    |
|                                   | Award up to ₹30L + ₹3L compensation. |
+-----------------------------------+--------------------------------------+
| FIR registration                  | FREE. Cognisable offence — must be   |
|                                   | registered (Lalita Kumari, BNSS 173).|
+-----------------------------------+--------------------------------------+
| RTI to PIO RBI Mumbai             | ₹10 IPO / DD. BPL = free.            |
+-----------------------------------+--------------------------------------+

Bank fraud helplines — quick reference

+-------------------------+-----------------------------+
| State Bank of India     | 1800-11-2211 / 1800-425-3800|
+-------------------------+-----------------------------+
| HDFC Bank               | 1800-258-6161               |
+-------------------------+-----------------------------+
| ICICI Bank              | 1860-120-7777               |
+-------------------------+-----------------------------+
| Axis Bank               | 1860-419-5555               |
+-------------------------+-----------------------------+
| Punjab National Bank    | 1800-180-2222               |
+-------------------------+-----------------------------+
| Bank of Baroda          | 1800-258-44-55              |
+-------------------------+-----------------------------+
| Kotak Mahindra Bank     | 1860-266-2666               |
+-------------------------+-----------------------------+
| Yes Bank                | 1800-1200                   |
+-------------------------+-----------------------------+
| IndusInd Bank           | 1860-267-7777               |
+-------------------------+-----------------------------+
| Union Bank of India     | 1800-22-2244                |
+-------------------------+-----------------------------+

State-wise cyber cells and helplines

State Cyber Cell Helpline (besides 1930)
Maharashtra cyber.maharashtra.gov.in 1930 / 022-22641133
Delhi cyber-crime.delhi.gov.in 1930 / 011-23438400
Karnataka cybercrime.kar.nic.in 1930 / 080-22094408
Tamil Nadu cybercrime.tnpolice.gov.in 1930 / 044-2845-2222
Telangana cybercrime.telangana.gov.in 1930 / 040-27852451
Gujarat dgp.gujarat.gov.in 1930 / 079-2325-1900
West Bengal wbpolice.gov.in 1930 / 033-2214-3260
UP uppolice.gov.in 1930 / 0522-2390-484
Kerala keralapolice.gov.in 1930 / 0471-2722-768
Punjab punjabpolice.gov.in 1930 / 0172-2741-900
Haryana haryanapolice.gov.in 1930 / 0172-2548-202
Rajasthan police.rajasthan.gov.in 1930 / 0141-2741-900

Common reasons recovery fails

  • Reported after 7 working days. RBI circular shifts full liability to the customer. Even RBIOS will rarely overturn this unless you can prove genuine inability to report (hospitalised, abroad with no signal, etc.).
  • Money already cashed out. Mule accounts withdraw within hours. Once the cash is out at an ATM in a different state — or has been routed onward to crypto / abroad — recovery falls below 5%.
  • Bank claims “OTP shared = customer negligence”. This is a standard but often wrong defence. The RBI circular explicitly covers transactions where the customer has been deceived (social engineering). Fight it at RBIOS — they routinely overrule banks on this.
  • Cybercrime cell over-burdened. Some PSs sit on cases for weeks before triggering the freeze. Always escalate via the SP cyber cell after 72 hours.
  • Receiving account is in a co-operative bank or PPI wallet — slower freeze pipeline; recovery harder.
  • Customer disputed at the call centre but never filed the written DRC form. Without the written form on file, the bank's position is “no formal complaint received”.
  • Fraudster used your own approved auto-pay mandate (subscription scams). Banks treat these as authorised; you must revoke the mandate.
  • Multi-step layering. Funds bounce through 4-5 accounts in 30 minutes. Each hop adds one bank to coordinate. Reporting at minute 15 vs minute 90 changes everything.

What not to do after a fraud

- Do not call back any number the fraudster gave you. They often pose as “bank fraud department” staff to drain more.

  1. Do not share OTPs, PINs, or UPI PINs with anyone, including callers claiming to be from NPCI or RBI. Neither organisation ever calls to ask for these.
  2. Do not uninstall your banking app before filing the complaint. Transaction logs stored in the app are evidence.
  3. Screenshot the fraudulent transaction entry in your UPI app before raising a dispute.

Common mistakes to avoid

* Calling 1930 too late — every minute reduces recovery odds.

  • Skipping written bank complaint within 3 working days — drops you to ₹5K-₹25K liability bracket.
  • Trusting “recovery agents” charging fees — second-stage scam.
  • Not citing RBI MD July 2017 — strongest framework.
  • Sharing OTP / PIN with anyone — never.
  • Skipping Banking Ombudsman — free + binding + fastest legal route.
  • Forgetting NPCI ODR for unresolved disputes.
  • Letting “unfreezing fee” extortion happen.

If stuck — the escalation ladder

Rung 1 — Bank's nodal grievance officer

Every bank's website lists a Customer Service / Grievance Redressal page with a Nodal Officer (state-level) and a Principal Nodal Officer (national). Email the principal nodal officer with: 1930 case number, cybercrime.gov.in acknowledgement, DRC form, FIR number, full transaction list, and your demand (full refund under RBI 2017 circular, with interest).

Rung 2 — CGRO at the bank's regional office

The Consumer Grievance Redressal Officer (CGRO) is mandated for every public-sector bank under DFS guidelines. They have power to overrule a branch-level rejection. SLA: 30 days.

Rung 3 — Banking Ombudsman (RBIOS)

The most important escalation. Open https://cms.rbi.org.in → register → file complaint. Pre-condition: 30 days must have passed since your written complaint to the bank, OR the bank must have rejected it. Free. 30-day SLA. Award up to ₹30 lakh + ₹3 lakh compensation. Decisions are appealable to the Appellate Authority (Deputy Governor) within 30 days.

Rung 4 — Securities Appellate Tribunal (only for investment fraud)

If the fraud was a fake-broker / fake-IPO / pump-and-dump that involved a registered intermediary, SAT (Mumbai, with benches in Delhi & Chennai) hears appeals from SEBI orders. Not for plain UPI fraud.

Rung 5 — Right to Information (RTI)

The Reserve Bank of India is a public authority under §2(h) RTI Act 2005 — confirmed by the Supreme Court in Reserve Bank of India v. Jayantilal Mistry, (2016) 3 SCC 525. Banks themselves are public authorities only if substantially government-owned (PSU banks yes; private banks no — but the RBI's regulatory file on a private bank is RTI-able from RBI).

RTI helps here when:

  • The bank has sat on your written dispute and the RBIOS hearing is months away — RTI to PIO, RBI Mumbai (DEPR / DBS / Consumer Education and Protection Department) asking for: (a) the bank's compliance report on the Limited Liability Circular for FY 2024-25, (b) the number of zero-liability cases the bank rejected and the basis, © any RBI inspection / supervisory action arising from cyber-fraud non-compliance.
  • The cyber police station has refused FIR — see RTI for FIR not registered.
  • The 1930 / cybercrime.gov.in case shows “closed” without your knowing why — RTI to the SP, Cyber Cell of your district for the closure report and reasons.
  • You want similar-fraud trend data (useful for class-action / advocacy / media) — RTI to RBI for the fraud-trend and supervision data it collects.

RTI does NOT help here when:

  • You want your money back today. RTI gives information, not a refund. The right forum for the refund itself is your bank → CGRO → RBIOS.
  • The bank has decided the case in its 90-day window and you simply disagree — file at RBIOS, not RTI.
  • You want the fraudster identified — that's a police / cyber-cell job, not RTI; the police get the call records via §94 BNSS, you cannot get them via RTI (third-party personal information bar under §8(1)(j)).
  • The transaction was clearly authorised by you (you typed the UPI PIN voluntarily, no impersonation involved) — RBI circular does not cover voluntary transfers.

What the RTI actually gets you: disclosable, redacted, refused

<!– from /scammed-on-upi-recovery-steps –>

Always disclosable

* Your transaction details + UTR + RRN with timestamp.

  • Bank dispute ack + status + processing log.
  • NPCI dispute reference + investigation outcome.
  • NCRP complaint ack + status update.
  • RBI MD July 2017 §[..] applicability assessment.
  • Bank Nodal Officer details.
  • Aggregate fraud-pattern data for your zone (anonymised).
  • Cyber Cell IO + investigation status.

Disclosable with redaction

* Other affected customers' details — names disclosable; account numbers masked.

  • Mule account details — anonymised in mid-investigation.

Not disclosable

* Aadhaar number (Aadhaar Act §28).

  • Mid-investigation file (§8(1)(h)).
  • Scammer's identity (until chargesheet).

Leading judgments

* SBI v. Pallabh Bhowmick (NCDRC 2023) — bank duty in induced authorisation.

  • Adit Aggarwal v. State of UP (HC 2024) — bank's vigilance + 1930 timeline.
  • K.S. Puttaswamy (2017) — privacy + property.
  • Lalita Kumari (2014) — Zero-FIR.

Real-world recovery patterns

* Mumbai 2024 — OLX seller scammed via fake UPI collect-request; ₹47,000 lost. 1930 in 18 minutes; recipient frozen; reversal in 11 days. Full recovery.

  • Bengaluru 2025Bharat Pe QR replaced at small shop. Customer disputed; bank chargeback under RBI MD §6. ₹2,200 returned in 8 days.
  • Delhi 2024 — fake “refund of ₹599” collect-request → ₹47,000 debited. NCRP + FIR + Banking Ombudsman. ₹28,000 recovered after 87 days.
  • Pune 2025 — induced-authorisation case (paid for “police verification”). Speed of 1930 (within 90 min) → bank chargeback success.
  • Hyderabad 2024 — Telegram task scam — ₹85,000. Slow reporting (4 days). Only ₹12,000 recovered.

Can compensation be claimed?

- Bank chargeback under RBI MD July 2017.

  1. Insurance under RBI MD §9.
  2. RBI Banking Ombudsman — up to ₹30 lakh for consequential loss plus ₹3 lakh for harassment.
  3. Consumer Forum — ₹5,000-₹50 lakh.
  4. §19(8)(b) RTI Act — Information Commission compensation.
  5. Article 226 writ for systemic failures.

Penalties and consequences

* Fraudster: Section 66D IT Act (3 years + ₹1 lakh) + BNS Section 318/319 (up to 7 years).

  • Bank (for delay or denial): RBI penalty + Banking Ombudsman compensation up to ₹30 lakh.
  • You (if delayed > 7 days): partial or full loss as per bank policy.

FAQs

Q. The fraudster is calling again threatening to “report me”. What do I do?
Block the number, screenshot every threat, add it to your existing cybercrime.gov.in case as a fresh upload, inform the IO. Threats from a fraudster trying to discourage your complaint are a separate offence under BNS §351 (criminal intimidation).

Q. I shared the OTP. Will I still get a refund?
Yes — if you were deceived (social engineering) and you reported within 3 working days, the RBI circular gives you zero liability irrespective of whether you “shared” the OTP. The bank's standard “OTP shared = your fault” line is not law. Fight it at RBIOS — its orders routinely apply the circular to social-engineering cases.

Q. The 1930 number was busy. Is there a backup?
Yes — immediately file at https://cybercrime.gov.in (the same backend as 1930) and call your bank's fraud line. Document the busy-1930 attempts (call log screenshot) — it strengthens your “reported in time” claim.

Q. My account is with a small co-operative bank that doesn't have a 24×7 fraud line. What do I do?
Call 1930 first (still works — co-operative banks are on the NCRP rail too), then call the co-op bank's branch manager. UCBs are regulated by RBI since the 2020 amendment to the Banking Regulation Act, so the Limited Liability Circular and RBIOS both apply.

Q. I lost ₹4 lakh on a fake share-trading WhatsApp group. Is it covered?
That's investment fraud, not pure UPI fraud — but the same 1930 + cybercrime.gov.in route applies. Recovery rates here are lower because you typed the UPI PIN voluntarily; the angle is “cheating by inducement” under BNS §318 + IT Act §66D. Also report to SEBI's SCORES portal (scores.sebi.gov.in) and tag the broker (if any).

Q. Can the bank refuse the DRC form?
No. RBI's Master Circular on Customer Service makes it mandatory to accept and acknowledge any written grievance. If a branch refuses, email the Principal Nodal Officer the same day and complain to RBIOS (refusal-to-receive itself is a deficiency in service).

Q. How long after the Ombudsman award before I get my money?
The bank has 30 days from the date of the award to comply, failing which the RBI can impose a penalty. Most awards are honoured in 2-3 weeks.

Q. Is the RBI Ombudsman award final?
The bank can appeal within 30 days to the Appellate Authority (a Deputy Governor of RBI). The customer can also appeal — but you can also choose to go to Consumer Forum for parallel relief, especially if you also want compensation for mental harassment.

Was this useful?
- views