UPI mandate fraud: spot & stop auto-debit scams (2025–26)
Last reviewed: 1 September 2026.
Quick Reply: Fraudsters hide recurring payment traps in “verify KYC” links. Stop UPI mandates before ₹ drains from your account. Legal remedies + complaint format inside.
Consumer commission jurisdiction as of the 2021 Rules: District Commission where the consideration paid does not exceed Rs 50 lakh; State Commission for more than Rs 50 lakh up to Rs 2 crore; National Commission for more than Rs 2 crore. These figures come from the Consumer Protection (Jurisdiction of the District Commission, the State Commission and the National Commission) Rules, 2021, notified 30 December 2021, not from the higher limits printed in the bare Act. File online at e-jagriti.gov.in. Source: PIB PRID 1786342.
RBI Ombudsman as of 1 July 2026: Bank, certain NBFC, prepaid-instrument and credit-information complaints go under the Reserve Bank - Integrated Ombudsman Scheme, 2026, which replaced RB-IOS 2021 from 1 July 2026. First complain to the entity. If there is no reply in 30 days (or the longer NPCI/card-network window, if it applies) or you reject the reply, file free at cms.rbi.org.in within 90 days. The Ombudsman can award up to Rs 30 lakh for consequential loss and up to Rs 3 lakh for time, expenses and harassment. Complaints received before 1 July 2026 stay under the 2021 scheme. Source: RBI FAQ, updated 1 July 2026 and the RB-IOS 2026 FAQ PDF dated 1 July 2026.
An illustrative case (not a named person): a reader clicked a “verify your PAN” WhatsApp link, entered her UPI PIN once, and lost over ₹1.4 lakh in three weeks through silent auto-debits she never authorised—until her bank SMS woke her at 3 a.m. — an illustrative account
Citizen Crisis Response Network
If your UPI app shows an unexplained mandate under “AutoPay” or “Recurring payments,” pause all mandates, freeze your account via net-banking, screenshot every debit SMS, report at once on 1930 or cybercrime.gov.in and register an FIR citing BNS section 318(4) (cheating and dishonestly inducing delivery of property) or section 319(2) (cheating by personation), and file an NPCI complaint at npci.org.in (Grievance Redressal)—time starts now.
Direct answer (featured snippet)
UPI mandate fraud tricks you into authorising a recurring payment by disguising it as a one-time KYC verification, OTP validation, or prize-claim step. The victim enters UPI PIN once; fraudsters then create a standing instruction (mandate) for daily, weekly, or monthly auto-debits. To stop it: (1) Open your UPI app → AutoPay / Mandates, (2) revoke every unrecognised mandate, (3) block your virtual payment address (VPA) temporarily, (4) screenshot all SMS debits, (5) file a cyber-crime complaint at cybercrime.gov.in and register an FIR citing BNS section 318(4), (6) lodge an NPCI complaint online, (7) invoke your bank's zero-liability policy in writing within three working days under the RBI circular on Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, 6 July 2017.
In this guide
What is UPI mandate fraud and why it exploded in 2025
A UPI mandate (also called AutoPay or e-mandate) is a standing instruction you give once, allowing a merchant or biller to debit your account automatically at fixed intervals—electricity bills, SIP mutual funds, OTT subscriptions. National Payments Corporation of India (NPCI) rolled out UPI AutoPay in 2020 under the Unified Payments Interface framework; complaints about digital-payment fraud have grown every year on the National Cyber Crime Reporting Portal run by the Indian Cyber Crime Coordination Centre (I4C).
Fraudsters weaponised this convenience: they send phishing links disguised as “KYC update,” “courier delivery confirmation,” or “prize voucher claim.” When you click and enter your UPI PIN, you unknowingly approve a recurring payment mandate for ₹5,000–₹15,000 per cycle. Because the first debit is often small (₹1–₹10), victims notice only after multiple hits drain tens of thousands.
The scam thrives on three pillars: 1. Speed—mandate activation is instant; revocation requires manual action. 2. Opacity—many UPI apps bury the “Mandates” menu deep inside settings. 3. Social engineering—messages mimic government agencies (UIDAI, Income Tax, Ministry of Electronics & IT) or trusted brands (Amazon, Flipkart).
City cyber-crime units now register such FIRs routinely under Bharatiya Nyaya Sanhita (BNS) 2023 section 318(4) (cheating and dishonestly inducing delivery of property) and section 319(2) (cheating by personation), usually alongside IT Act 2000 section 66D.
Warning — Even if you have never subscribed to a service, a mandate can be planted if you enter your UPI PIN on a fraudulent payment page that presents itself as a “verification” step.
How fraudsters plant the mandate without your knowledge
Step 1: The lure WhatsApp message, SMS, or email with urgent text: “Your Aadhaar KYC will expire in 24 hours—complete e-KYC now,” “Unclaimed parcel—pay ₹5 delivery fee,” “You won ₹50,000 cashback—verify UPI to claim.”
Step 2: The fake payment page You tap the link; it opens a lookalike UPI intent screen branded with RBI or UIDAI logos. The collect-request says “Verification ₹1” or “Refundable security ₹10.”
Step 3: The hidden checkbox Buried in fine print below the amount field: “I authorise recurring debits for service activation.” The checkbox is pre-ticked or rendered in 6pt grey text on white background. NPCI's UPI operating rules require explicit user consent for mandates, but fraudsters either lie about the amount or chain multiple smaller mandates.
Step 4: PIN entry You enter your six-digit UPI PIN believing it is a one-time payment. In reality, you just approved a standing instruction. The fraudster's app (often registered as a rogue merchant via a shadow payment aggregator) now holds a valid mandate ID.
Step 5: Silent debits Every day, week, or month the mandate auto-executes. Your bank sends SMS: “₹4,999 debited to XYZ Services.” By the time you investigate, five debits have occurred.
Step 6: Roadblocks to revocation Some scam merchants change their merchant category codes (MCC) to exempt categories (education, insurance) where banks hesitate to chargeback. Others register the mandate on a different VPA than your primary handle, so you don't see it in your main app.
Most citizens miss this — UPI apps group mandates under AutoPay, Recurring Payments, or Manage Mandates; if you use multiple apps (Google Pay, PhonePe, Paytm), check all of them—a mandate planted via one app can debit any linked bank account.
Seven red flags before you enter your UPI PIN
1. Unsolicited “verification” request No genuine government or bank system asks you to pay ₹1 for KYC. Aadhaar updates are done only through the myAadhaar portal or an enrolment centre, never through a UPI link.
2. URL mismatch Legitimate payment pages display the merchant VPA clearly. If you see a generic string like “PAY2VERIFY@paytm” or a randomised handle, stop.
3. Pre-ticked consent checkbox NPCI rules require opt-in, not opt-out. Any pre-selected “I agree to auto-debit” violates UPI AutoPay guidelines.
4. Amount listed as ₹0 or ₹1 Classic decoy. The mandate itself may authorise ₹15,000 per cycle, but the initial transaction shows ₹1 to bypass scrutiny.
5. Pressure language “Complete within 10 minutes or account will be blocked,” “Final notice,” “Legal action pending.” All hallmarks of social engineering.
6. No itemised service description A valid subscription (Netflix, Jio) tells you exactly what, how much, and how often. Fraudsters use vague labels: “Service Activation Fee,” “Verification Charge.”
7. Request from a non-business number Messages from 10-digit mobile numbers instead of six-digit sender IDs (e.g., “UIDAI,” “RBISMS”) are red flags.
Do this immediately — Before entering UPI PIN on any payment screen, check your UPI app's mandate list first; if a new entry appears without your action, you are on a phishing page—exit and report.
Immediate steps the moment you spot an unauthorised auto-debit
Minute 0–5: Contain the damage 1. Open your UPI app → Settings → AutoPay / Mandates. 2. Revoke every unrecognised mandate. Screenshot before and after. 3. If the fraudulent mandate does not appear in the app (because it was created via a different UPI handle), call your bank's 24×7 helpline and request temporary account freeze or debit-block on that account number. 4. Log into net-banking, download six months' statement (PDF + Excel), highlight every suspicious debit.
Minute 5–30: Preserve evidence 5. Screenshot all SMS alerts showing debits (date, time, amount, merchant name, UPI transaction ID / UPI Ref No / RRN). 6. If you still have the phishing message, screenshot it with full headers (sender number, timestamp). 7. Do not delete the message or call the fraudster's “customer care” number—that invites further social engineering.
Hour 1–24: Formal complaints 8. File FIR at your local cyber-crime police station or online at cybercrime.gov.in. Mention BNS, 2023 sections 318(4) (cheating and dishonestly inducing delivery of property) and 319(2) (cheating by personation), and IT Act 2000 section 66D (cheating by personation using a computer resource). Obtain the acknowledgement number. 9. Simultaneously lodge a complaint on the NPCI portal: https://www.npci.org.in/what-we-do/grievance-redressal (select UPI → Unauthorised Transaction). 10. Email your bank's nodal officer (name and email mandated on bank's website under RBI norms) with subject line “Zero-Liability Claim: Unauthorised UPI Mandate Debits—Account [Your A/c No].” Attach FIR copy, transaction screenshots, timeline.
Day 2–3: Invoke zero-liability and chargeback 11. Under the RBI circular on Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (6 July 2017), if you report an unauthorised electronic transaction within three working days, you are entitled to zero liability—the bank must reverse the debits. 12. Send a written letter (registered post AD + email) invoking Consumer Protection Act 2019 section 2(11) (deficiency in service) and demanding:
- Immediate reversal of ₹[total amount],
- Compensation for consequential loss (bounced cheques, penalty interest),
- Written confirmation within seven working days.
13. If the bank delays beyond 30 days, escalate free of cost under the Reserve Bank – Integrated Ombudsman Scheme, 2026 (RB-IOS) at cms.rbi.org.in.
Trust signal — Keep a dated copy of every complaint; if the bank gives no reply within 30 days, that silence itself makes you eligible to file a free complaint under RB-IOS 2026 at cms.rbi.org.in.
Legal remedies: BNS, 2023, IT Act 2000, and Payment & Settlement Systems Act 2007
Bharatiya Nyaya Sanhita 2023 - Section 318(4): Cheating and dishonestly inducing delivery of property—the fraudster deceives you into handing over money (successor to IPC section 420). Punishment: imprisonment up to seven years + fine. - Section 319(2): Cheating by personation—impersonating a government body or trusted entity to induce payment. Punishment: imprisonment up to five years, or fine, or both. - Section 316: Criminal breach of trust—if the fraudster was a payment aggregator or merchant onboarded by a Payment Service Provider (PSP), their misuse of mandate infrastructure may constitute breach of trust.
Information Technology Act 2000 - Section 66D: Punishment for cheating by personation using computer resource—imprisonment up to three years + fine up to ₹1 lakh. - Section 43: Penalty for damage to computer, computer system, computer network—liable to pay damages by way of compensation (civil remedy).
Payment and Settlement Systems Act 2007 - Sections 17–18 and 26: RBI can issue binding directions to payment-system participants, and operating a payment system without RBI authorisation is penal; this is the lever NPCI and PSP banks use against rogue merchants, not a citizen-facing charge.
Consumer Protection Act 2019 - Section 2(11): Deficiency in service—bank's failure to block a fraudulent mandate or delay in chargeback is actionable. - 2021 Rules: District Consumer Commission where consideration paid does not exceed ₹50 lakh; State Commission more than ₹50 lakh up to ₹2 crore. - Section 41: Appeal from a District Commission order lies to the State Commission within 45 days (extendable for sufficient cause).
RBI circular on Customer Protection, 6 July 2017 (the operative liability rule) - Zero liability if an unauthorised transaction is reported within three working days; limited liability of ₹5,000 / ₹10,000 / ₹25,000 by account type (or the transaction value, if lower) if reported within 4–7 working days; later reporting falls to the bank's board-approved policy. - The bank must give the zero-liability credit within 10 working days of its decision.
Citizen tip — If your loss exceeds ₹1 lakh, file both FIR (criminal) and consumer complaint (civil + compensation); a criminal conviction strengthens your consumer case, and you can seek punitive damages in addition to actual loss.
Filing your cyber-crime FIR: mandatory particulars and timelines
Jurisdictional confusion resolved Under Bharatiya Nagarik Suraksha Sanhita (BNSS) 2023 section 173(1), you may file an FIR at any police station in India for a cognizable cyber offence; that station will either investigate or transfer (e-FIR) to the jurisdictional station (usually your residence or the bank branch location). In practice, approach: 1. Your local cyber-crime cell (if city has one), 2. The jurisdictional police station (Sub-Divisional Police Officer rank or above), 3. National Cyber Crime Reporting Portal: cybercrime.gov.in (online complaint; acknowledgement number generated immediately).
Mandatory particulars in your FIR - Complainant details: Full name, Aadhaar number, mobile, email, address. - Incident timeline: Date and time of phishing link received, date and time of PIN entry, dates of each auto-debit. - Financial particulars: Bank name, account number, IFSC, UPI VPA, total amount debited. - Evidence list: Attach printed screenshots of SMS, phishing message, bank statement (highlight debits in yellow), mandate screenshot from UPI app. - Accused description: “Unknown fraudster impersonating [UIDAI / RBI / Amazon], operating merchant VPA [insert VPA], mobile number [if visible], using payment aggregator [if known].” - Statutory sections invoked: BNS, 2023 sections 318(4), 319(2); IT Act 2000 section 66D. - Relief sought: Investigation, arrest of accused, recovery of ₹[amount], compensation, directions to NPCI and bank for chargeback.
Timeline clocks - File FIR within 24 hours of discovering the fraud to preserve digital forensic evidence (transaction logs expire or get overwritten after 48–72 hours in some systems). - Police must record information about a cognizable offence (BNSS, 2023 section 173(1)); if the station refuses, send the substance in writing by post to the Superintendent of Police under section 173(4). - Obtain FIR acknowledgement number and certified copy within 72 hours; escalate to Superintendent of Police if station-house officer (SHO) delays.
Warning — If the SHO refuses to register FIR citing “it is a civil matter” or “approach bank first,” invoke BNSS, 2023 section 173(4): send the substance of your complaint in writing by post to the Superintendent of Police, who must investigate himself or direct a subordinate officer to do so; failing that, apply to the Magistrate under section 175(3).
NPCI and bank escalation: complaint formats and statutory clocks
NPCI complaint procedure 1. Visit https://www.npci.org.in/what-we-do/grievance-redressal 2. Click “Register Grievance” → select UPI → sub-category Unauthorised Transaction / Fraudulent Mandate. 3. Fill form: Transaction date, UPI Ref No (from SMS), amount, brief description, upload FIR copy + screenshots. 4. NPCI issues ticket number within 24 hours. 5. NPCI forwards complaint to your Payment Service Provider (PSP bank / UPI app issuer) and the fraudulent merchant's PSP. 6. The PSP bank is expected to respond within the turnaround time NPCI publishes for UPI complaints. 7. If no resolution, NPCI escalates to PSP's nodal officer; final NPCI decision within 30 days.
Bank nodal officer escalation - RBI mandates every bank publish nodal officer name, email, phone on their website (homepage → Grievance Redressal). - Email subject: “Zero-Liability Claim & Chargeback Request: Unauthorised UPI Mandate—Account [Number]” - Body: Attach FIR acknowledgement, NPCI ticket number, transaction list, timeline, statutory basis (RBI customer-protection circular of 6 July 2017), demand for provisional credit within 10 working days. - Ask the bank to acknowledge in writing and conclude within 30 days; 30 days of silence makes you eligible to file free at cms.rbi.org.in under the Reserve Bank – Integrated Ombudsman Scheme, 2026.
Banking Ombudsman (RBI Integrated Ombudsman Scheme, 2026) - File online: https://cms.rbi.org.in (Complaints Management System) - Eligibility: Complaint to bank's nodal officer made, 30 days elapsed without resolution OR bank rejected claim. - The Ombudsman can award up to ₹30 lakh for consequential loss, plus up to ₹3 lakh for time, expenses and harassment. - The Ombudsman's award binds the bank unless the bank appeals within 30 days.
Consumer forum parallel track - District Consumer Forum: File within two years of cause of action (CPA 2019 section 69). - Costs: Filing fee is nil for claims up to ₹5 lakh and ₹200 for claims of ₹5–10 lakh; no lawyer is mandatory. - Compensation: Actual loss + mental agony + litigation cost (often 10–20 % of claim amount). - Timeline: Most forums decide within 90–180 days at district level (though delays are common).
Most citizens miss this — You can run parallel tracks—FIR (criminal), NPCI complaint (regulatory), Banking Ombudsman (quasi-judicial), consumer forum (civil)—they do not bar each other; final compensation may come from whichever resolves first.
Case law and regulatory touchpoints
Regulatory position on burden of proof Under the RBI customer-protection framework (6 July 2017), once you report an unauthorised transaction within the prescribed time, it is for the bank to show either your negligence or that you really authorised the transaction. Mere system logs showing “successful PIN authentication” do not by themselves prove you knowingly created a recurring mandate; the bank must rule out phishing, malware or social engineering before holding you liable.
What good practice looks like NPCI and PSP banks regularly warn UPI users against “verify KYC” scams; in practice you should expect to see the mandate details (frequency, amount, merchant name) before PIN entry, an SMS alert when a mandate is created, and a way to revoke mandates inside the UPI app. - If any of these safeguards is missing, treat it as a red flag and say so in your complaint.
RBI (Commercial Banks – Digital Payment Security Controls) Directions, 2026 These directions govern how banks secure digital payments, including additional factor of authentication; the customer-liability slabs themselves come from the 6 July 2017 circular above. - Rogue merchants and their aggregators are dealt with under RBI's payment-operator directions and NPCI's risk rules—raise the merchant VPA in your NPCI complaint so it reaches that process.
I4C (Indian Cyber Crime Coordination Centre) — verified 2024 figures In 2024 the National Cyber Crime Reporting Portal (cybercrime.gov.in) received about 36.4 lakh cyber-crime complaints reporting losses of about ₹22,845 crore, of which roughly ₹1,100 crore was recovered. Report at once on 1930 or cybercrime.gov.in—early reporting is what makes freezing of mule accounts possible.
Freezing the fraud proceeds — the real route Police can seize property under BNSS, 2023 section 106, and attach or forfeit proceeds of crime under section 107 with the Superintendent of Police's approval; ask the investigating officer in writing to freeze the mule accounts receiving your mandate debits.
Trust signal — Courts consistently hold that the timing of your complaint is decisive; even a one-day delay beyond the three-day window can shift liability, so treat the clock as a hard deadline, not a guideline.
Frequently asked questions
Can fraudsters create a UPI mandate without my UPI PIN?
No. UPI mandate creation always requires your six-digit PIN because it is classified as a debit transaction under NPCI rules. However, fraudsters disguise the mandate approval screen as a “verification” or “refund” page so you think you are authorising a one-time payment, not a recurring instruction. The PIN entry is genuine—the fraud lies in the misrepresentation of what you are approving.
I entered my PIN on a fake page but no money was debited yet—am I safe?
Not necessarily. If the page was a UPI mandate setup screen, the fraudster now holds an active mandate that can trigger debits later (daily, weekly, or monthly schedule). Immediately check your UPI app → AutoPay / Mandates section. If you see an unrecognised entry, revoke it. Even if nothing shows, inform your bank and request a precautionary freeze on UPI transactions for 24 hours while you monitor.
My UPI app does not show any fraudulent mandate but money keeps getting debited—what is happening?
Three possibilities: 1. The mandate was created on a different VPA linked to the same bank account (e.g., you use PhonePe primary, but fraudster registered mandate via your Paytm VPA). 2. The merchant disguised the mandate under an innocuous name (“Insurance Premium,” “Donation”) that you may have scrolled past. 3. The mandate was created at the bank level (e-NACH / e-Mandate via net-banking session hijack, not UPI app), so it won't appear in UPI app—check net-banking → Standing Instructions or Mandates.
Solution: Log into net-banking, go to Mandates / Standing Instructions, revoke all, call bank helpline, request detailed merchant onboarding data for every debit RRN.
Will revoking the mandate get my money back?
Revoking stops future debits but does not automatically refund past debits. You must separately invoke chargeback and zero-liability: 1. File FIR (creates legal record). 2. Complain to NPCI (triggers investigation). 3. Send zero-liability claim letter to bank (starts refund clock). All three tracks run in parallel. Refund typically takes 30–90 days depending on bank responsiveness.
The bank says I authorised the mandate by entering my PIN so they will not refund—can they deny liability?
No. RBI's customer liability framework (circular of 6 July 2017) applies irrespective of how the fraud occurred—phishing, malware, SIM-swap, or social engineering. The question is: did you intend to authorise a recurring payment to that merchant for that amount? If the answer is no, and you reported within three working days, you are entitled to zero liability. The bank's system logs showing “PIN authenticated” do not override RBI's zero-liability rule. Cite the RBI customer-protection circular of 6 July 2017 and escalate to the Banking Ombudsman at cms.rbi.org.in if the bank refuses.
Can I get compensation beyond the stolen amount for mental harassment?
Yes, under Consumer Protection Act 2019. Consumer forums routinely award: - Actual financial loss (the debited amount), - Consequential loss (bounced cheque penalties, loan EMI delays), - Mental agony and harassment (typically 10–20 % of financial loss, sometimes up to ₹50,000 in egregious cases), - Litigation costs (₹5,000–₹25,000).
Cite deficiency in service (bank's failure to block mandate promptly, delayed chargeback). Attach medical certificates if you suffered stress-related health issues, and affidavit detailing time lost in police stations, bank branches, etc.
What if the fraudster used a foreign payment aggregator or VPA registered abroad?
NPCI's UPI ecosystem is India-only; however, some fraudsters use Indian shell merchants onboarded by rogue payment aggregators. If the VPA ends in @paytm, @ybl (Yes Bank), @oksbi (SBI), @icici, the merchant is ultimately onboarded by an Indian PSP, so NPCI has jurisdiction. File NPCI complaint; NPCI will serve notice to that PSP and suspend the merchant VPA. If the merchant is genuinely offshore (rare in UPI), escalate to the Cyber Crime Police and the Ministry of Home Affairs via the I4C route; India has mutual legal assistance arrangements with a number of countries for cyber-crime cooperation.
How long does it take to get FIR acknowledgement from cybercrime.gov.in?
The portal auto-generates an acknowledgement number instantly upon submission. This is not an FIR number yet—it is a “complaint registration number.” The complaint is forwarded to the jurisdictional police station, which must record the information under BNSS, 2023 section 173(1); once an FIR is registered you should get an SMS with the FIR number. If days pass with no FIR number, call the helpline 1930 and escalate.
Citizen tip — Screenshot your cybercrime.gov.in submission page showing date-time stamp; this proves you reported within the critical three-day window even if the police delay FIR registration—courts accept portal acknowledgement as evidence of timely complaint.
Sample FIR text for UPI mandate fraud
To, The Station House Officer, Cyber Crime Police Station, [City] [Address] Subject: FIR for Cheating by Personation and Unauthorised UPI Mandate Creation Respected Sir/Madam, I, [Your Full Name], son/daughter/spouse of [Parent/Spouse Name], aged [Age], residing at [Full Address], Aadhaar No. [XXXX-XXXX-1234], Mobile [+91-XXXXXXXXXX], hereby lodge a formal complaint under Bharatiya Nyaya Sanhita 2023 Sections 318(4), 319(2), and Information Technology Act 2000 Section 66D. FACTS: 1. On [Date], at approximately [Time], I received a WhatsApp message from mobile number [+91-XXXXXXXXXX] purporting to be from UIDAI, stating "Your Aadhaar KYC will expire in 24 hours. Complete e-KYC immediately: [fraudulent link]." 2. Believing the message to be genuine, I clicked the link, which opened a webpage branded with Aadhaar and Government of India logos. The page requested UPI payment of ₹1 as "verification charge." 3. I entered my UPI PIN [do NOT write actual PIN—write "six-digit PIN"] on [Date] at [Time], believing I was making a one-time ₹1 payment. 4. Between [Start Date] and [End Date], I received SMS alerts from my bank, [Bank Name], showing the following debits from my account [Account No.], all to merchant VPA "[fraudulent VPA]": - [Date]: ₹4,999, UPI Ref No. [XXXXXXXXXXXX] - [Date]: ₹4,999, UPI Ref No. [XXXXXXXXXXXX] - [Total]: ₹[Total Amount] across [Number] transactions. 5. On [Date], I checked my UPI app [App Name] under AutoPay/Mandates and discovered an unauthorised recurring payment mandate to "[Merchant Name]" for ₹5,000 per day, which I never knowingly authorised. 6. I immediately revoked the mandate and informed [Bank Name] customer care (call reference no. [XXXXXX]) and NPCI (grievance ticket no. [XXXXXX]). EVIDENCE ENCLOSED: - Annexure A: Screenshots of phishing WhatsApp message - Annexure B: Screenshots of SMS debit alerts - Annexure C: Bank account statement (highlighted) - Annexure D: Screenshot of fraudulent mandate in UPI app - Annexure E: NPCI complaint acknowledgement PRAYER: I request you to: (a) Register FIR under BNS, 2023 Sections 318(4), 319(2); IT Act 2000 Section 66D, (b) Investigate and trace the accused via merchant VPA, payment aggregator, mobile number, and bank account, (c) Coordinate with NPCI and I4C for technical forensics, (d) Facilitate recovery and return of ₹[Amount], (e) Issue certified FIR copy for submission to bank and consumer forum. Date: [DD/MM/YYYY] Place: [City] Signature: _______________ [Your Full Name] Mobile: [+91-XXXXXXXXXX] Email: [[email protected]]
Sample NPCI complaint letter
<code> To, Grievance Redressal Officer National Payments Corporation of India 1st Floor, Trade World, Kamala Mills Compound, Senapati Bapat Marg, Lower
