Differences
This shows you the differences between two versions of the page.
| — | upi-autopay-mandate-fraud-india [2026/08/28 18:29] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== UPI AutoPay Mandate Fraud: Cancel and Stop Debits 2026 ====== | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | {{page> | ||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** UPI AutoPay mandate fraud India: spot unauthorised recurring debits, cancel mandates in your UPI app, file UDIR and RBI Ombudsman complaints, and recover money. | ||
| + | </ | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | A Hyderabad teacher noticed three monthly debits of ₹999 from her ICICI account in March 2026, all marked as " | ||
| + | |||
| + | ===== First 10 Minutes: Do This ===== | ||
| + | |||
| + | - Take screenshot of the debit SMS, the UPI app history, and the bank statement entry. | ||
| + | - Note the exact time and the UPI Reference (UTR) or RRN number. | ||
| + | - Do not delete any chat messages, emails, or app history about the mandate. | ||
| + | - Raise the complaint on your UPI app first (Help → Raise Dispute → UDIR). | ||
| + | - Escalate to RBI Ombudsman 14448 or [[https:// | ||
| + | |||
| + | ===== Detailed steps for this scenario ===== | ||
| + | |||
| + | - **Open the UPI app you use** (Google Pay, PhonePe, Paytm, BHIM, or your bank app). Go to **Profile → Manage AutoPay** or **Settings → Mandates**. | ||
| + | - **Read every active mandate.** Note merchant name, amount, frequency, next debit date. Anything you do not recognise is a candidate to revoke. | ||
| + | - **Tap Revoke / Pause** on the suspicious mandate. UPI apps require a UPI PIN to confirm. | ||
| + | - **Wait for the SMS confirmation** that the mandate has been cancelled. Save it. | ||
| + | - **Open the bank's NetBanking** (HDFC NetBanking → Bill Pay → Mandate Management; SBI YONO → Manage SI; Axis Mobile → Subscriptions). Cross-check that the bank also shows the mandate as cancelled. | ||
| + | - **Lock UPI in the app** for 24 hours via Profile → Block UPI ID, to prevent further mandate creation while you investigate. | ||
| + | - **File a UDIR dispute** in the UPI app for the most recent unauthorised debit. UDIR is [[https:// | ||
| + | |||
| + | ===== Documents and screenshots needed ===== | ||
| + | |||
| + | * Bank statement showing the disputed debits, with date and reference number. | ||
| + | * UPI app screenshot of the active mandate and the merchant name. | ||
| + | * The mandate creation SMS (banks send a one-time SMS when an AutoPay is set up). | ||
| + | * UPI debit SMS for each occurrence. | ||
| + | * Email of any subscription confirmation you received. | ||
| + | * Screenshot of the merchant' | ||
| + | * UDIR dispute reference number once you file in-app. | ||
| + | * NCRP complaint number once filed at [[https:// | ||
| + | |||
| + | ===== Where to complain first ===== | ||
| + | |||
| + | - **In-app UDIR dispute.** Every UPI app has a Help / Raise Dispute path. UDIR (UPI Dispute Resolution Initiative) gives a 30-day resolution window under [[https:// | ||
| + | - **Bank' | ||
| + | - **Merchant' | ||
| + | - **NPCI' | ||
| + | |||
| + | ===== When to escalate ===== | ||
| + | |||
| + | ==== Tier 1: in-app UDIR + bank nodal officer ==== | ||
| + | |||
| + | 7 to 30 days. Most cases resolve here when proof is clean and the dispute is filed within 3 working days of the disputed debit. | ||
| + | |||
| + | ==== Tier 2: RBI Ombudsman (RB-IOS 2026) ==== | ||
| + | |||
| + | Free filing at [[https:// | ||
| + | |||
| + | ==== Tier 3: Consumer court via e-Daakhil + FIR ==== | ||
| + | |||
| + | For service deficiency, file at [[https:// | ||
| + | |||
| + | ===== How to Identify UPI AutoPay Mandate Fraud Early ===== | ||
| + | |||
| + | Fraud mandates are rarely obvious. Here are the top red flags citizens discover only after weeks of silent debits: | ||
| + | |||
| + | * **Debits from an unknown merchant name** on your bank statement or UPI history — often an abbreviation or shell-company name you have never seen. | ||
| + | * **Small recurring amounts** (₹99, ₹199, ₹299, ₹499, ₹999) that look like legitimate subscription charges but are from apps you never installed. | ||
| + | * **No mandate-creation SMS** in your message history, even though a mandate exists. This may indicate a phishing page that captured your UPI PIN without the bank's consent flow. | ||
| + | * **Multiple mandates** to different merchant names created on the same day or within hours — a hallmark of a screen-sharing scam where the fraudster set up several mandates at once. | ||
| + | * **Mandate frequency you did not choose** (daily or weekly instead of monthly) — fraudsters prefer frequent small debits to avoid detection. | ||
| + | * **Mandate amount just under ₹15,000** (the current NPCI no-additional-OTP threshold for standard UPI AutoPay), maximising exposure per debit cycle. | ||
| + | * **Bank statement shows "UPI AutoPay" | ||
| + | * **UPI app shows mandates** even after you cancelled them — sometimes mandates are re-created by the merchant via a separate backend process. | ||
| + | |||
| + | **How to audit every active mandate in 2 minutes:** | ||
| + | |||
| + | - Open Google Pay → Profile → Manage AutoPay → sort by //Amount// descending. | ||
| + | - Open PhonePe → Profile → Settings → AutoPay → check each entry. | ||
| + | - Open Paytm → Profile → AutoPay & Mandates. | ||
| + | - Open BHIM → Bank Accounts → Mandates. | ||
| + | - Open your bank app (e.g., SBI YONO, HDFC MobileBanking, | ||
| + | - Write down every merchant name, amount, frequency, and next debit date. Revoke anything you do not recognise. | ||
| + | |||
| + | ===== How to Cancel a UPI AutoPay Mandate Immediately ===== | ||
| + | |||
| + | Cancelling a mandate stops future debits but does **not** automatically reverse past debits. Do both: | ||
| + | |||
| + | **Step-by-step cancellation in every major UPI app:** | ||
| + | |||
| + | - **Google Pay:** Profile → Manage AutoPay → tap the mandate → Cancel AutoPay → enter UPI PIN. | ||
| + | - **PhonePe: | ||
| + | - **Paytm:** Profile → AutoPay & Mandates → select mandate → Cancel → UPI PIN. | ||
| + | - **BHIM:** Bank Accounts → Mandates → select → Revoke → UPI PIN. | ||
| + | - **SBI YONO:** Manage SI → select mandate → Cancel. | ||
| + | - **HDFC NetBanking: | ||
| + | - **Axis Mobile:** Subscriptions → select → Cancel. | ||
| + | |||
| + | **If the app does not let you cancel:** | ||
| + | |||
| + | - Write to your bank's nodal officer by email, quoting the UMN (Unique Mandate Number) and demanding cancellation under the [[https:// | ||
| + | - If the bank does not cancel within 7 working days, escalate to the [[https:// | ||
| + | - See also our companion guides: [[/ | ||
| + | |||
| + | ===== How to Get a Refund for UPI AutoPay Fraud ===== | ||
| + | |||
| + | Getting your money back requires a structured escalation. The RBI [[https:// | ||
| + | |||
| + | **Zero-liability rule:** Where the unauthorised transaction is caused by the bank's negligence, a technical failure, or a third-party breach, you have **zero liability** if you report it to the bank within **3 working days** of receiving the bank's communication about the debit. The bank must reverse (shadow-reverse) the amount within 10 working days. | ||
| + | |||
| + | **Limited liability tiers (per RBI Master Direction, Table 1):** Where neither the bank nor you are at fault but the breach is elsewhere in the system, your per-transaction liability is capped (lower of the transaction value or the cap below), based on the account type and the reporting delay: | ||
| + | |||
| + | | Reporting timeframe | Maximum customer liability per transaction | | ||
| + | |---------------------|--------------------------------------------| | ||
| + | | Within 3 working days (third-party breach) | ₹0 (zero liability) | | ||
| + | | 4 to 7 working days | BSBD accounts: ₹5,000 · Other savings / PPI / credit cards up to ₹5 lakh limit / current accounts up to ₹25 lakh: ₹10,000 · Credit cards above ₹5 lakh limit / other current accounts: ₹25,000 | | ||
| + | | Beyond 7 working days | As per the bank's Board-approved customer protection policy (banks must publish this on their website) | | ||
| + | |||
| + | If the loss is due to your own negligence (you shared the PIN, fell for a phishing page), you bear the entire loss until you report it; the bank bears anything lost after you report. The burden of proving customer negligence lies on the bank. | ||
| + | |||
| + | **Refund action plan:** | ||
| + | |||
| + | - **Step 1 (Day 0):** File a UDIR dispute in-app. Note the reference number. | ||
| + | - **Step 2 (Day 0–1):** Email the bank's nodal officer with screenshots, | ||
| + | - **Step 3 (Day 7–30):** If the bank does not respond, file at [[https:// | ||
| + | - **Step 4 (Day 30+):** File at [[https:// | ||
| + | - **Step 5:** If the fraud is part of a cyber-crime pattern, report at [[https:// | ||
| + | |||
| + | ===== UPI Fraud Complaint on the NPCI Portal: Step-by-Step ===== | ||
| + | |||
| + | NPCI operates the UPI Dispute Resolution Initiative (UDIR) for recurring-payment disputes. Every UPI app integrates with UDIR — you do not need to visit the NPCI website to file, but you can escalate there if the in-app dispute fails. | ||
| + | |||
| + | **How to file a UDIR dispute (in-app):** | ||
| + | |||
| + | - Open your UPI app (Google Pay, PhonePe, Paytm, BHIM, or bank app). | ||
| + | - Navigate to **Help → Raise Dispute** or **Transaction History → tap the disputed debit → Raise Dispute**. | ||
| + | - Select reason: **" | ||
| + | - Upload screenshots: | ||
| + | - Submit. You will get a **UDIR reference number** on screen. Save it. | ||
| + | - Resolution window: **30 days**. The bank must investigate and respond. | ||
| + | |||
| + | **If the in-app UDIR fails or is unavailable: | ||
| + | |||
| + | - Visit [[https:// | ||
| + | - Download the NPCI complaint form, fill it, and email it to the NPCI grievance address listed on that page. | ||
| + | - Quote your UDIR reference number, UTR/RRN, mandate UMN, and bank complaint number. | ||
| + | |||
| + | **NPCI escalation contacts:** | ||
| + | |||
| + | - NPCI toll-free: **1800-120-1740** (UPI helpline). | ||
| + | - NPCI website: [[https:// | ||
| + | - NPCI grievance email: Available on the dispute redressal page. | ||
| + | |||
| + | For broader cyber-fraud context, see [[/ | ||
| + | |||
| + | ===== How to File an RTI for UPI Fraud Investigation ===== | ||
| + | |||
| + | If your bank or the RBI is slow to act, a Right to Information application can compel disclosure of systemic data — dispute volumes, resolution rates, and internal advisories. RBI, NPCI (if treated as a public authority), and public-sector banks are covered under the RTI Act 2005. | ||
| + | |||
| + | **When to file an RTI:** | ||
| + | |||
| + | - The bank has not responded to your complaint in 30 days. | ||
| + | - You suspect systemic AutoPay fraud (many affected customers, same merchant). | ||
| + | - You want to know whether RBI has issued advisories on mandate verification. | ||
| + | - NPCI dispute resolution has stalled or returned an unsatisfactory answer. | ||
| + | |||
| + | **What to ask in the RTI (sample questions): | ||
| + | |||
| + | - Total number of UPI AutoPay mandate disputes filed with [Bank / RBI] in FY 2025-26. | ||
| + | - Percentage resolved in the customer' | ||
| + | - Any internal advisory or master circular issued in the last 24 months on mandate consent verification. | ||
| + | - Grievance Officer details for UPI/AutoPay complaints as required by IT Rules 2021 Rule 3(2). | ||
| + | |||
| + | **Where to file:** | ||
| + | |||
| + | - RBI: File at [[https:// | ||
| + | - Public-sector banks: File via [[https:// | ||
| + | - NPCI: File via the NPCI website or [[https:// | ||
| + | |||
| + | See our comprehensive guides: [[/ | ||
| + | |||
| + | Reserve Bank of India and any public-sector bank involved are public authorities under the RTI Act 2005. The following Section 6(1) application can compel disclosure of action taken on systemic AutoPay disputes: | ||
| + | |||
| + | < | ||
| + | The Public Information Officer | ||
| + | Reserve Bank of India / [Public-sector bank] | ||
| + | [Address] | ||
| + | |||
| + | Subject: Application under Section 6(1) of the RTI Act 2005 | ||
| + | |||
| + | Madam / Sir, | ||
| + | |||
| + | I, [Name], resident of [Address], request the following | ||
| + | information under Section 6(1) of the Right to Information | ||
| + | Act 2005: | ||
| + | |||
| + | 1. The total number of UPI AutoPay mandate disputes filed | ||
| + | with [Bank / RBI] in the financial year 2025-26. | ||
| + | 2. The percentage of such disputes resolved in the customer' | ||
| + | | ||
| + | 3. Any internal advisory or master circular issued in the | ||
| + | last 24 months on the verification of mandate consent | ||
| + | | ||
| + | 4. The Grievance Officer for UPI and AutoPay grievances at | ||
| + | | ||
| + | Rules 2021 Rule 3(2). | ||
| + | |||
| + | I enclose the prescribed fee of ₹10 by Indian Postal Order | ||
| + | no. __________. A reply within 30 days under Section 7(1) | ||
| + | of the RTI Act 2005 is requested. | ||
| + | |||
| + | Yours sincerely, | ||
| + | [Name, address, contact] | ||
| + | DD-MM-2026 | ||
| + | </ | ||
| + | |||
| + | ===== UPI Autopay vs Standing Instruction (SI): What Is the Difference? ===== | ||
| + | |||
| + | Citizens often confuse UPI AutoPay mandates with bank standing instructions (SI), NACH/eNACH mandates, and e-mandates for cards. Understanding the difference determines where you complain and how you cancel. | ||
| + | |||
| + | | Feature | UPI AutoPay (eMandate) | Bank Standing Instruction (SI) | NACH / eNACH Mandate | Card e-Mandate (Recurring) | | ||
| + | |---------|------------------------|--------------------------------|----------------------|----------------------------| | ||
| + | | **Platform** | UPI (NPCI) | Core banking (bank-internal) | NPCI NACH | Visa / Mastercard / RuPay | | ||
| + | | **Setup** | UPI PIN once | NetBanking / branch form | e-sign / physical form | OTP + card details | | ||
| + | | **Additional OTP per debit?** | No (standard recurring up to ₹15,000; raised to ₹1 lakh for credit-card bills, mutual fund SIPs, and insurance) | No | No | No (up to ₹15,000; ₹1 lakh for the same enhanced categories) | | ||
| + | | **Cancel where** | UPI app → Manage AutoPay | NetBanking / branch | Bank / sponsor | Bank / card issuer | | ||
| + | | **Dispute system** | UDIR (NPCI) | Bank internal grievance | Bank / NPCI NACH | Chargeback (Visa/ | ||
| + | | **Regulator** | RBI + NPCI | RBI | RBI + NPCI | RBI | | ||
| + | |||
| + | **Key takeaway:** UPI AutoPay is the **highest fraud risk** of the recurring-payment options because the setup requires only a UPI PIN, mandates are created in-app (phishing-prone), | ||
| + | |||
| + | For more on related mandate types, see [[/ | ||
| + | |||
| + | ===== Bank Responsibility for UPI AutoPay Fraud: What the Law Says ===== | ||
| + | |||
| + | Banks are not automatically liable for every fraud — but the RBI Master Direction 2017 and the Reserve Bank - Integrated Ombudsman Scheme 2026 create specific duties and timelines. | ||
| + | |||
| + | **Bank' | ||
| + | |||
| + | - **Verify consent before mandate creation:** The UPI/NPCI framework requires UPI PIN authentication. If a mandate was created without valid PIN entry, the bank bears liability. | ||
| + | - **Zero-liability reversal:** If the unauthorised transaction is the bank's fault or a third-party breach reported within 3 working days, the bank must reverse the debit (shadow reversal) within 10 working days — per [[https:// | ||
| + | - **7-day response window:** The bank's grievance officer must respond within 7 working days of receiving the complaint. | ||
| + | - **90-day resolution cap:** The bank must resolve the complaint and establish liability within 90 days; otherwise the customer is paid compensation as prescribed. | ||
| + | - **SMS notification: | ||
| + | - **Fraud reporting to RBI:** Banks must report frauds to the RBI under the Master Direction on Frauds Classification and Reporting (via the Fraud Reporting and Monitoring System) and comply with the National Cybercrime Reporting Portal framework for digital frauds. | ||
| + | |||
| + | **When the bank is liable:** | ||
| + | |||
| + | - The mandate was created without your UPI PIN (technical failure or security breach). | ||
| + | - The bank failed to send the mandate-creation SMS. | ||
| + | - The bank failed to act on your complaint within 7 working days. | ||
| + | - The bank failed to reverse the debit after a valid zero-liability claim. | ||
| + | |||
| + | **When the bank may deny liability: | ||
| + | |||
| + | - You entered the UPI PIN on a phishing page (customer negligence). | ||
| + | - You shared your PIN or allowed screen sharing with a fraudster. | ||
| + | - You authorised the mandate knowingly but forgot. | ||
| + | - You reported beyond 7 working days (limited liability applies from day 4). | ||
| + | |||
| + | **If the bank wrongly denies liability: | ||
| + | |||
| + | - File at [[https:// | ||
| + | - Cite the Master Direction zero-liability clause and your 3-day reporting proof. | ||
| + | - File a consumer complaint at [[https:// | ||
| + | |||
| + | See [[/ | ||
| + | |||
| + | ===== RBI Ombudsman Complaint for UPI Fraud: Full Process ===== | ||
| + | |||
| + | The Reserve Bank - Integrated Ombudsman Scheme 2026 (RB-IOS 2026, in force 1 July 2026) is a free, lawyer-free mechanism to resolve banking disputes including UPI AutoPay fraud. It replaced the 2021 scheme. | ||
| + | |||
| + | **Eligibility to file:** | ||
| + | |||
| + | - You must have first complained to the bank (Tier 1). | ||
| + | - The bank did not resolve within 30 days, OR rejected your complaint, OR gave an unsatisfactory reply. | ||
| + | |||
| + | **How to file:** | ||
| + | |||
| + | - Online: Visit [[https:// | ||
| + | - Phone: Call **14448** (RBI Ombudsman helpline, 9:30 AM–5:30 PM, weekdays). | ||
| + | - Email: File via the CMS portal; it routes to the correct Ombudsman office. You can also write to [email protected]. | ||
| + | - In person: Visit the nearest RBI Ombudsman office. | ||
| + | |||
| + | **What to include:** | ||
| + | |||
| + | - Bank complaint reference number and date. | ||
| + | - UDIR reference number. | ||
| + | - UMN, UTR/RRN of disputed debits. | ||
| + | - Screenshots of the mandate, debits, and complaint correspondence. | ||
| + | - Your bank account number (masked: XXXX1234). | ||
| + | - Amount claimed (debited amount + compensation for mental agony, if any). | ||
| + | |||
| + | **Jurisdiction and limits (RB-IOS 2026):** | ||
| + | |||
| + | - Compensation: | ||
| + | - Filing fee: **Free.** | ||
| + | - Decision timeline: Typically 30–60 days from filing. | ||
| + | - Appeal: If dissatisfied, | ||
| + | |||
| + | **If the Ombudsman closes your complaint unfavourably: | ||
| + | |||
| + | - Appeal to the Appellate Authority (details in the Ombudsman' | ||
| + | - File a consumer complaint at [[https:// | ||
| + | - File a writ petition under Article 226 of the Constitution in the High Court. | ||
| + | - See [[/ | ||
| + | |||
| + | For step-by-step walkthroughs, | ||
| + | |||
| + | ===== UPI Fraud Types Comparison Table ===== | ||
| + | |||
| + | Not all UPI fraud is the same. The table below compares the most common UPI fraud types, their mechanics, and the correct complaint path for each. | ||
| + | |||
| + | | Fraud Type | How It Happens | Red Flag | First Action | Complaint Path | Liability Rule | | ||
| + | |------------|----------------|----------|--------------|----------------|----------------| | ||
| + | | **AutoPay/ | ||
| + | | **QR code scan fraud** | Fraudster sends QR code "to receive money" → victim scans → money debited | "Scan this QR to receive payment" | ||
| + | | **Screen-sharing scam** | Fraudster asks to install AnyDesk/ | ||
| + | | **Phishing link fraud** | Fake UPI payment link captures credentials | SMS/email with payment link | Do not click → change PIN | Bank → Cybercrime | Zero liability if PIN not entered | | ||
| + | | **SIM swap fraud** | Fraudster ports your SIM → receives OTP → resets UPI PIN | SIM stops working suddenly | Contact telecom immediately | Bank → TRAI → Cybercrime | Zero liability if reported within 3 days | | ||
| + | | **Fake customer care fraud** | Fake helpline number → asks for UPI PIN or OTP | "Tell me your UPI PIN to verify" | ||
| + | | **Collect request fraud** | Fraudster sends UPI collect request → victim approves | " | ||
| + | |||
| + | For more on specific fraud types, see [[/ | ||
| + | |||
| + | ===== Sample complaint text ===== | ||
| + | |||
| + | < | ||
| + | To, The Grievance Officer | ||
| + | [Bank Name] | ||
| + | [Date: DD-MM-2026] | ||
| + | |||
| + | Subject: Unauthorised UPI AutoPay debit on account [XXXX1234], | ||
| + | UMN reference [paste UMN here], demand for reversal + | ||
| + | mandate cancellation under RBI Master Direction 2017 | ||
| + | |||
| + | Madam / Sir, | ||
| + | |||
| + | I write under Rule 3(2) of the IT (Intermediary) Rules 2021 and | ||
| + | the RBI Master Direction on Limiting Liability of Customers in | ||
| + | Unauthorised Electronic Transactions 2017 to report and dispute | ||
| + | the following debit: | ||
| + | |||
| + | Amount: | ||
| + | UTR / RRN: | ||
| + | Mandate UMN: | ||
| + | Merchant: | ||
| + | |||
| + | I did not authorise this AutoPay mandate. I have not used the | ||
| + | named merchant' | ||
| + | |||
| + | (a) Immediate revocation of the mandate within 24 hours. | ||
| + | (b) Reversal of the disputed debit to my account within | ||
| + | seven working days. | ||
| + | (c) Investigation of how the mandate was created on my UPI | ||
| + | ID and a written report of findings. | ||
| + | (d) Confirmation in writing that my account is not enrolled | ||
| + | in any other AutoPay mandate without my fresh consent. | ||
| + | |||
| + | I attach: bank statement, UPI app mandate screenshot, debit SMS, | ||
| + | mandate-creation SMS (if received). | ||
| + | |||
| + | I have separately filed UDIR reference no. _______ in my UPI app | ||
| + | and a complaint at cybercrime.gov.in vide _______. | ||
| + | |||
| + | If this is not resolved within 30 days, I shall escalate to the | ||
| + | RBI Ombudsman under the Reserve Bank - Integrated Ombudsman | ||
| + | Scheme 2026. | ||
| + | |||
| + | Yours sincerely, | ||
| + | [Name] | ||
| + | [Mobile registered with the bank] | ||
| + | [Email] | ||
| + | </ | ||
| + | |||
| + | ===== Consumer court / e-Daakhil route ===== | ||
| + | |||
| + | For service deficiency (bank failed to verify consent before creating the mandate, or merchant created mandate without consent), file at the District Consumer Disputes Redressal Commission via [[https:// | ||
| + | |||
| + | ===== Official sources to verify before you act ===== | ||
| + | |||
| + | * **NPCI UPI dispute redressal: | ||
| + | * **RBI Master Direction on Limited Customer Liability (6 July 2017):** [[https:// | ||
| + | * **RBI Ombudsman portal (RB-IOS 2026):** [[https:// | ||
| + | * **NCRP (cyber crime):** [[https:// | ||
| + | * **National Consumer Helpline:** [[https:// | ||
| + | * **DigiLocker (for any payment-related document): | ||
| + | * **e-Daakhil consumer court filing:** [[https:// | ||
| + | * **RBI online RTI portal:** [[https:// | ||
| + | * **Central RTI online portal:** [[https:// | ||
| + | |||
| + | ===== Related RTI Wiki guides ===== | ||
| + | |||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | * [[/ | ||
| + | |||
| + | ===== Frequently asked questions ===== | ||
| + | |||
| + | ==== What is a UPI AutoPay mandate? ==== | ||
| + | |||
| + | A UPI AutoPay mandate (also called eMandate) is a recurring-payment authorisation set up on your UPI ID. Once authorised once with your UPI PIN, the merchant can debit up to a pre-set amount on a fixed schedule (daily, weekly, monthly, yearly) without further OTP. Standard recurring payments are allowed up to ₹15,000 per debit without per-transaction OTP under the current [[https:// | ||
| + | |||
| + | ==== How do I see all active UPI mandates on my account? ==== | ||
| + | |||
| + | Open your UPI app and go to Profile → Manage AutoPay (Google Pay), Settings → Mandates (PhonePe), Profile → AutoPay (Paytm), or the equivalent on your bank's UPI app. Each app shows merchant, amount, frequency, and next debit date. You can also call your bank or check NetBanking → Bill Pay → Mandate Management. See [[/ | ||
| + | |||
| + | ==== Can a merchant create a UPI AutoPay mandate without my consent? ==== | ||
| + | |||
| + | No. Every UPI mandate creation requires the user to enter UPI PIN on a screen that shows the merchant name, amount, and frequency. If a mandate exists that you did not authorise, possible causes are: a phishing screen captured your PIN, a family member used your phone, or a screen-sharing scam tricked you. Revoke and dispute immediately. See [[/ | ||
| + | |||
| + | ==== How do I cancel a UPI AutoPay mandate? ==== | ||
| + | |||
| + | In your UPI app, open the mandate, tap Revoke or Pause, and enter UPI PIN. The bank sends an SMS within minutes confirming cancellation. Save the SMS. If revoke fails, write to the bank's nodal officer and quote RBI Master Direction 2017. See [[/ | ||
| + | |||
| + | ==== What is UDIR and how do I file a UDIR dispute? ==== | ||
| + | |||
| + | UDIR (UPI Dispute Resolution Initiative) is [[https:// | ||
| + | |||
| + | ==== Can I get a chargeback for an unauthorised UPI AutoPay debit? ==== | ||
| + | |||
| + | UPI does not offer a Visa-style chargeback. The equivalent path is UDIR + bank investigation under the [[https:// | ||
| + | |||
| + | ==== What if my bank refuses to reverse the debit? ==== | ||
| + | |||
| + | Escalate to the RBI Ombudsman under the Reserve Bank - Integrated Ombudsman Scheme 2026 at [[https:// | ||
| + | |||
| + | ==== How do I prevent AutoPay fraud in future? ==== | ||
| + | |||
| + | * Never share UPI PIN. [[https:// | ||
| + | * Audit your active mandates monthly. Most apps show a //Manage AutoPay// dashboard. | ||
| + | * Enable UPI Lite for small payments (lower exposure). See [[/ | ||
| + | * Watch the screen carefully when creating any mandate. Verify merchant name and amount before entering PIN. | ||
| + | * Treat any //screen sharing// request from a stranger as fraud. See [[/ | ||
| + | |||
| + | ==== Is AutoPay fraud a criminal offence in India? ==== | ||
| + | |||
| + | Yes. Creating a mandate by deceptive means is cheating under BNS 2023 Section 318 (general cheating) and Section 66D of the IT Act 2000 (cheating by personation by computer resource). The bank's failure to verify consent can attract Consumer Protection Act 2019 Section 2(11) deficiency in service. See [[/ | ||
| + | |||
| + | ==== Will the police accept an FIR for a small AutoPay debit? ==== | ||
| + | |||
| + | Yes. Under BNSS 2023 Section 173, information disclosing a cognisable offence must be recorded. If the police refuse, file a complaint to the Magistrate under BNSS Section 175(3) for a direction to investigate. The NCRP complaint at [[https:// | ||
| + | |||
| + | ==== What is the difference between UPI AutoPay and e-mandate for cards? ==== | ||
| + | |||
| + | UPI AutoPay is set up via your UPI ID and authenticated with UPI PIN. Card e-mandates are set up with your card details and an initial OTP. Both allow recurring debits without per-transaction OTP up to ₹15,000 (₹1 lakh for credit-card bills, mutual fund SIPs, and insurance) under the RBI e-mandate framework. The dispute path differs: UPI AutoPay uses UDIR; card e-mandates use the chargeback mechanism of your card network (Visa/ | ||
| + | |||
| + | ==== Can I file an RTI to find out how many AutoPay fraud complaints my bank has received? ==== | ||
| + | |||
| + | Yes. If your bank is a public-sector bank (SBI, PNB, Bank of Baroda, etc.) or you are querying the RBI, file under Section 6(1) of the RTI Act 2005. Ask for dispute volumes, resolution rates, and any advisories on mandate verification. File at [[https:// | ||
| + | |||
| + | ==== How long does the RBI Ombudsman take to resolve a UPI fraud complaint? ==== | ||
| + | |||
| + | Typically 30–60 days from filing. The Ombudsman may extend this for complex cases. If the Ombudsman does not resolve within 3 months, you can treat it as a deemed rejection and appeal to the Appellate Authority or file in consumer court. See [[/ | ||
| + | |||
| + | ==== What is the ₹15,000 no-OTP threshold and can I reduce it? ==== | ||
| + | |||
| + | Under the RBI e-mandate framework (as implemented by NPCI for UPI AutoPay), standard recurring payments can debit up to ₹15,000 per transaction without an additional OTP; the threshold is ₹1 lakh for credit-card bills, mutual fund SIPs, and insurance. You cannot reduce this threshold system-wide, | ||
| + | |||
| + | ==== Can a private bank like HDFC or ICICI be taken to the RBI Ombudsman? ==== | ||
| + | |||
| + | Yes. RB-IOS 2026 covers all scheduled commercial banks, including private banks (HDFC, ICICI, Axis, Kotak), certain NBFCs, and PPI issuers. File at [[https:// | ||
| + | |||
| + | ==== I authorised a mandate but the merchant is overcharging or not delivering. Can I dispute it? ==== | ||
| + | |||
| + | Yes. This is a service-deficiency dispute rather than a fraud dispute. File a UDIR dispute selecting //Service not received// or //Amount mismatch//. If the merchant does not resolve, escalate to consumer court under CPA 2019 Section 35. See [[/ | ||
| + | |||
| + | ==== What should I do if I gave a fraudster screen-sharing access? ==== | ||
| + | |||
| + | - Immediately disconnect the call. | ||
| + | - Uninstall the screen-sharing app (AnyDesk, TeamViewer, etc.). | ||
| + | - Change your UPI PIN and net banking password from a different device if possible. | ||
| + | - Lock UPI in your bank app (Profile → Block UPI ID). | ||
| + | - Check all mandates and revoke any you do not recognise. | ||
| + | - File at [[https:// | ||
| + | - See [[/ | ||
| + | |||
| + | ==== Are there any government helplines specifically for UPI fraud? ==== | ||
| + | |||
| + | Yes: **1930** (cybercrime helpline — call within the golden hour to freeze the fraudulent account), **14448** (RBI Ombudsman — for bank-level disputes), and **1915** (National Consumer Helpline — for merchant disputes). See [[/ | ||
| + | |||
| + | //Last reviewed: 17 July 2026.// | ||
| + | |||
| + | {{tag> | ||