Launch offer — up to 85% off across all services | Free Educational Brief with every drafting order | Claim it →

UPI and Digital Payment Fraud in India: Legal Remedies, Cyber Crime Complaint Process, and Recovery Options

A phone rings, a caller claims to be from your bank or a courier company, and within minutes your UPI account has been drained — sometimes without you ever sharing an OTP. UPI now carries the overwhelming majority of India’s digital retail payment volume, and digital-payment fraud has grown in step with it: fake customer-care numbers, remote-access screen-sharing apps, QR-code “collect” requests disguised as refunds, SIM-swap takeovers, and phishing links are now the most common ways ordinary account holders lose money. The good news is that Indian law gives victims a genuinely layered set of remedies — regulatory, criminal, and civil — and the outcome very often turns on how fast you act and how correctly you invoke each layer. Here is exactly how the law works, step by step. If you need a cyber crime complaint or fraud-recovery document professionally drafted, you can place your order through our order form.

3 DaysTo Report for Zero Liability
1930National Cyber Fraud Helpline
45 DaysUPI Chargeback Window
90 DaysBank Complaint Resolution Cap

There is no single “UPI fraud law” in India. Instead, a fraud victim’s rights are assembled from several statutes and regulatory instruments that operate together:

The Payment and Settlement Systems Act, 2007 is the parent statute for the entire electronic-payments ecosystem, including UPI, which is operated by the National Payments Corporation of India (NPCI) under authorisation from the Reserve Bank of India. Section 23A of the Act empowers the RBI to require system providers to ring-fence customer funds — deposit them separately or maintain liquid assets — and gives customers a first and paramount charge over those ring-fenced funds ahead of other creditors if a payment system provider becomes insolvent.

The Reserve Bank of India’s 2017 circular on customer liability (RBI/2017-18/15, DBR.No.Leg.BC.78/09.07.005/2017-18, dated 6 July 2017) is the single most important document for anyone who has lost money to a fraudulent electronic transaction. It creates a graded liability framework — zero liability, limited liability, and full liability — depending on who was at fault and how quickly the customer reported the transaction, and it places the burden of proving customer negligence squarely on the bank.

The Information Technology Act, 2000 supplies both civil and criminal teeth. Section 43 creates civil liability for unauthorised access, data theft and related computer misconduct; Section 43A makes a body corporate liable to pay compensation if its negligence in protecting sensitive personal data causes wrongful loss; Section 66C punishes identity theft (fraudulent use of another person’s password, electronic signature or unique identification feature); and Section 66D specifically punishes cheating by personation using a computer resource or communication device — the precise offence committed by a fraudster who calls pretending to be your bank or a delivery agent.

The Bharatiya Nyaya Sanhita, 2023 (BNS), which replaced the Indian Penal Code with effect from 1 July 2024, supplies the general criminal-law backbone. Section 318 defines and punishes cheating (consolidating what were earlier Sections 415, 417, 418 and 420 IPC), with punishment rising to seven years where the cheating induces delivery of property. Section 319 specifically punishes cheating by personation — pretending to be someone else, or substituting one person for another — with imprisonment of up to five years.

The Consumer Protection Act, 2019 lets a victim treat an unresolved, wrongly-decided, or delayed bank response as a “deficiency in service” (defined in Section 2(11) as any fault, imperfection, shortcoming or inadequacy in the manner of performing a service, including negligence causing loss) and pursue compensation before a Consumer Commission.

Finally, the Reserve Bank – Integrated Ombudsman Scheme, 2021 (RBIOS 2021) gives customers of banks, NBFCs, and payment system participants a single, cost-free grievance-redressal window when a regulated entity’s own internal complaint process fails to resolve the dispute.

Legal Purpose and Background

UPI’s design made it spectacularly convenient — and that same convenience is what fraudsters exploit. A UPI transaction authorised with a valid MPIN is, from the payment rail’s point of view, a fully authorised transaction; the system has no independent way of knowing that the person who typed the MPIN was tricked into doing so by a fake customer-care call, a fraudulent “refund” collect request, or a malicious screen-sharing app. This is precisely the gap the RBI’s 2017 liability circular was written to address: it does not ask “was the transaction technically authorised,” it asks “who was actually at fault,” and it puts the burden of answering that question on the bank rather than the customer.

Before the 2017 circular, banks routinely closed fraud complaints on the simple ground that the transaction carried a valid OTP or PIN, treating that alone as conclusive proof of customer negligence. Courts have since made clear that this reasoning does not survive scrutiny where the customer was deceived into authorising the transaction — the Gauhati High Court’s 2024 ruling against the State Bank of India, discussed below, is a direct and recent illustration of this shift. The legal architecture now recognises that being deceived is not the same thing as being negligent, and it builds a reporting-time-based liability ladder around that distinction rather than an all-or-nothing rule.

Common Types of UPI and Digital Payment Fraud

Recognising the mechanism of a fraud matters because it usually determines which legal provision applies and which institution (bank, NPCI, or police) is the right first port of call.

Fake customer-care / phishing calls. A fraudster obtains a customer’s number — often after the customer searches for a company’s “customer care number” on the open internet and reaches a fraudulent listing — and, posing as a genuine representative, talks the victim into sharing an OTP, installing a remote-access app, or scanning a “refund” QR code. This is the classic fact pattern in the Pallabh Bhowmick case discussed below, and squarely attracts Section 66D of the IT Act (cheating by personation using a computer resource) and Section 319 BNS (cheating by personation).

Malicious QR codes and “collect” requests. UPI “collect” requests are designed for a payee to request money from a payer; fraudsters exploit the fact that many users do not distinguish a “collect” prompt from a genuine incoming-payment notification, and scanning or approving the request actually debits the victim’s account rather than crediting it.

Remote-access/screen-sharing apps. Apps such as those used for “remote troubleshooting” give the fraudster live visibility of the victim’s screen, including OTPs and MPIN entry, and are frequently the technical mechanism behind fake customer-care and fake refund frauds.

SIM-swap fraud. A fraudster fraudulently obtains a duplicate SIM card for the victim’s registered mobile number (often through social engineering at a telecom outlet or using leaked personal data), which lets them intercept OTPs and take over UPI, net-banking and mobile-banking access.

Phishing links and fake apps. Malicious links (via SMS, WhatsApp, or email) direct victims to fake banking or e-commerce pages that harvest credentials, or induce the download of fake applications designed to look like a legitimate bank or UPI app.

Data-breach-enabled fraud. Where a merchant or third-party platform suffers a data breach and customer information (name, phone number, purchase history) leaks, that information is frequently used to make a subsequent phishing or impersonation call far more convincing — again, exactly what occurred in the Pallabh Bhowmick case, where the fraudster used information from a breached retailer’s database.

Fake loan-app and “instant approval” fraud. Unauthorised lending apps induce victims to link UPI or bank credentials in exchange for a promised loan, then either siphon funds directly or use the linked access for later unauthorised debits; several of these apps operate without valid NBFC or RBI authorisation altogether.

Task-based and investment scams routed through UPI. Victims are lured with small, genuine-looking payouts for simple “tasks” (liking videos, rating products) to build trust, then asked to make progressively larger UPI payments toward a fictitious “investment” or “unlock” fee that is never returned — a pattern that has become one of the fastest-growing categories reported on the National Cyber Crime Reporting Portal.

Immediate Steps After a Fraudulent Transaction

Speed is the single biggest factor a victim actually controls. The following sequence should ideally begin within minutes of discovering the fraud.

1

Call 1930 immediately. The national cyber-fraud helpline, 1930, feeds directly into the National Cyber Crime Reporting Portal (NCRP) at cybercrime.gov.in, run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs. Reporting within the “golden hour” — the first hour or so after the fraudulent transaction — meaningfully increases the chance that a lien or freeze can be placed on the beneficiary account before the money is withdrawn or moved further (“layered”) through additional accounts.
2

File a complaint on the NCRP portal (cybercrime.gov.in). Register a detailed complaint with transaction IDs, timestamps, the amount, the beneficiary UPI ID/account details if known, and any screenshots or call logs. You will receive an acknowledgment number — keep it; you will need it for your bank and Ombudsman complaints.
3

Notify your bank in writing, the same day if possible. Call the bank’s helpline to block your card/UPI immediately, then follow up with a written complaint (email or the bank’s grievance portal) explicitly stating that the transaction was unauthorised. The clock for the RBI’s zero-liability window (3 working days) and limited-liability window (4–7 working days) runs from when the bank’s communication about the transaction reached you — so the sooner you notify, the stronger your liability position.
4

Ask your bank to raise a chargeback / dispute with NPCI. For UPI transactions this goes through NPCI’s centralised UPI Dispute Redressal Mechanism (UDRM), which coordinates your bank (remitter) and the recipient’s bank (beneficiary) through the URCS platform. Get your bank’s dispute reference number in writing.
5

File a police FIR if the amount is significant or the NCRP complaint does not get satisfactory traction, particularly for offences under Section 318/319 BNS and Section 66C/66D IT Act. Many victims file the NCRP complaint and the FIR in parallel rather than waiting for one before the other.
6

Preserve evidence. Do not delete the call log, SMS, WhatsApp messages, screenshots of the app used, or the transaction confirmation. This evidence is frequently decisive both in the bank’s internal investigation and in any later Ombudsman, consumer forum, or court proceeding.

Bank and RBI Liability Framework

The RBI’s 2017 circular divides electronic banking transactions into remote/online transactions (internet banking, mobile banking, card-not-present transactions, prepaid instruments) and face-to-face/proximity transactions (ATM, POS), and then builds a three-tier liability structure that applies to both categories.

Zero liability. A customer bears no loss at all in two situations: first, where the unauthorised transaction resulted from contributory fraud, negligence, or deficiency on the part of the bank, regardless of whether the customer reported it; second, where the loss was caused by a “third-party breach” — a deficiency that lies neither with the bank nor with the customer but elsewhere in the system — provided the customer notifies the bank within three working days of receiving the bank’s communication about the transaction.

Limited liability. If the customer was genuinely negligent (for example, having actually and knowingly shared payment credentials), the customer bears the loss up to the point of reporting; anything lost after reporting is the bank’s responsibility. Where the fault lies neither with the bank nor the customer (a third-party breach) but the customer reports between four and seven working days after receiving the bank’s communication, liability is capped: Rs. 5,000 for basic savings accounts, Rs. 10,000 for most other savings accounts, prepaid instruments and smaller current/credit-card limits, and Rs. 25,000 for larger current accounts and higher credit-card limits. Beyond seven working days, liability reverts to the bank’s own Board-approved policy.

Process guarantees. Once notified, the bank must credit the disputed amount back to the customer’s account (a “shadow reversal”) within 10 working days, without waiting for any insurance claim to be settled first, and value-dated to the date of the unauthorised transaction. The complaint itself must be resolved, and liability determined, within 90 days of receipt — failing which the compensation prescribed by the circular must be paid regardless. Crucially, paragraph 12 of the circular places the burden of proving the customer’s negligence entirely on the bank; the customer does not have to prove their own innocence.

In practice, the most common friction point is banks treating a valid OTP/MPIN entry as conclusive proof that the customer was negligent and closing the complaint on that basis alone. Courts have not settled this question in one direction. The Gauhati High Court rejected that reasoning in 2024 (see Important Judgments below), holding that being deceived into entering an OTP is not the same as negligently sharing it, and that the bank must produce actual evidence of negligence rather than infer it from the mere fact that the transaction went through. The Delhi High Court, ruling the other way in 2026 on different facts, held that “customer negligence” under Clause 7(i) of the circular is illustrative, not exhaustive, and can extend to clicking a suspicious phishing link or using an unknown application — so a bare denial of sharing an OTP does not, by itself, automatically make the bank liable, particularly where the transaction went through two-factor authentication with no evidence the bank’s own systems were breached. In practice, outcomes turn heavily on the specific facts: how the credentials were actually compromised, what evidence exists of a system-side breach (as in confirmed SIM-swap cases), and how quickly the customer reported the transaction.

Note — instrument currently in force. The substantive liability rules described above (zero liability, limited liability, the Rs. 5,000/10,000/25,000 caps, the three-working-day reporting window, and the 90-day resolution cap) originated in the 2017 circular and, as of this writing, are the rules in force — now housed within the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Directions, 2025 (effective 28 November 2025), which consolidated the 2017 circular’s provisions without materially changing them. See the next section for a confirmed, already-issued change to this framework that takes effect on 1 January 2027.

What Changes From 1 January 2027

The Reserve Bank has already issued — not merely proposed — a further amendment that will materially change this framework for electronic banking transactions undertaken on or after 1 January 2027: the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026 (RBI/2026-27/167, dated 24 June 2026). Readers dealing with a fraud that occurs on or after that date should apply the new rules, summarised below; readers dealing with a fraud before that date remain under the framework described in the previous section.

  • Reporting window extended. The zero-liability reporting window for third-party-breach cases moves from three working days to five calendar days from the date of occurrence (not from the date the bank’s alert is received, as under the 2017 rules).
  • Faster resolution. Banks must examine, establish liability, and respond within 45 calendar days for domestic cases (60 for cross-border), down from the earlier 90-day outer limit.
  • Negligence is expressly defined on both sides. The amendment codifies specific examples of bank negligence (failing to send mandatory alerts, not providing 24×7 reporting channels, not acting diligently after a report, system breaches) and customer negligence (sharing or failing to protect PIN/password/OTP, delaying reporting, ignoring clear scam warnings, downloading malicious apps) — directly addressing the interpretive dispute between the Gauhati and Delhi High Court rulings discussed above.
  • Mandatory SMS alerts above Rs. 500. Banks must send instant SMS alerts for all electronic banking transactions above Rs. 500 (optional, but free, below that threshold).
  • New one-time compensation mechanism for small-value fraud. A bona fide individual (including a sole proprietor) who loses up to Rs. 50,000 to a fraudulent transaction attributable to their own negligence — and who reports it to both the bank and the National Cyber Crime Reporting Portal/1930 within five calendar days — becomes eligible for a one-time payment of 85% of the net loss or Rs. 25,000, whichever is lower, funded jointly by the RBI, the customer’s bank, and the beneficiary bank. This is available once in a customer’s lifetime and applies to frauds occurring within one year of the new rules taking effect.

Criminal Law Remedies

Digital-payment fraud is very often prosecutable under several overlapping provisions simultaneously.

Section 66C, Information Technology Act, 2000 — punishes identity theft: fraudulently or dishonestly making use of another person’s electronic signature, password, or any other unique identification feature (which, in the UPI context, extends to a stolen or misused MPIN, UPI PIN, or registered credential). Punishment: imprisonment up to three years and a fine which may extend to Rs. 1 lakh.

Section 66D, Information Technology Act, 2000 — punishes cheating by personation carried out by means of any communication device or computer resource: the fake “bank representative,” “courier agent,” or “customer care executive” scenario falls squarely within this section. Punishment: imprisonment up to three years and a fine which may extend to Rs. 1 lakh.

Section 43 / 43A, Information Technology Act, 2000 — Section 43 creates civil (compensatory) liability for unauthorised access to a computer resource and related conduct; Section 43A specifically makes a body corporate liable to pay compensation where its negligence in maintaining reasonable security practices for sensitive personal data causes wrongful loss or gain — relevant where a merchant’s or platform’s data breach enabled the fraud, as in the Louis Philippe/SBI case discussed below.

Section 318, Bharatiya Nyaya Sanhita, 2023 — the general cheating provision, applicable wherever deception induced the victim to part with money or property. Punishment ranges from three years (general cheating) up to seven years and a fine where the cheating induces delivery of property or the making/alteration of a valuable security — squarely covering a fraudulently induced fund transfer.

Section 319, Bharatiya Nyaya Sanhita, 2023 — cheating by personation, covering a fraudster who pretends to be another person (a bank official, a company representative, or even a specific named individual) to induce the victim to act. Punishment: imprisonment up to five years, or fine, or both.

An FIR can, and frequently does, invoke several of these provisions together, since a single fraudulent call-and-transfer sequence typically satisfies both the cheating provisions of the BNS and the identity-theft/personation provisions of the IT Act.

Filing a Cyber Crime Complaint — Step by Step

The National Cyber Crime Reporting Portal is designed to let a victim file a complaint without visiting a police station, though a formal FIR remains available and, for larger amounts, advisable in parallel.

Step 1 — Call 1930 or go to cybercrime.gov.in. For financial fraud specifically, the portal has a dedicated “Report Financial Fraud” pathway which flows directly to the concerned bank/payment system for a lien request, in addition to being logged as a police complaint.

Step 2 — Register or log in and select the correct category (“Report Financial Fraud” for UPI/bank/card fraud, as distinct from “Report Other Cyber Crime” for non-financial offences such as harassment or defamation).

Step 3 — Provide complete transaction details: date and time of each transaction, amount, transaction/UTR reference numbers, the app used (bank app, Google Pay, PhonePe, Paytm, etc.), the phone numbers or identifiers used by the fraudster, and — if available — the beneficiary’s UPI ID, account number, or bank name.

Step 4 — Upload evidence: screenshots of the transaction, the fraudulent call/message, and any correspondence with the platform whose customer-care number was spoofed.

Step 5 — Note your acknowledgment/complaint number and use it in every subsequent communication with your bank, the Banking Ombudsman, or the police, since it is often cross-referenced across these parallel processes.

Step 6 — Follow up. The portal allows complaint tracking; where a lien has been placed on the beneficiary account, funds may be held pending investigation, and separately claiming that amount back typically requires a court or police direction once the criminal investigation identifies the rightful claimant.

Step 7 — File a police FIR for a formal criminal investigation where the NCRP process alone does not yield recovery, particularly for larger amounts, or where you need an FIR copy for insurance, employer, or civil-proceeding purposes. Under the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS), which replaced the Code of Criminal Procedure alongside the BNS, a “Zero FIR” can be lodged at any police station regardless of where the offence technically occurred, and is then transferred to the station with proper jurisdiction — relevant where a victim is unsure which state or city the fraudster or the beneficiary bank branch is located in, which is common in cyber fraud given that the fraudster and the victim are rarely in the same place.

Civil and Regulatory Remedies

Bank’s internal grievance redressal. Every regulated entity must resolve a complaint within the timelines fixed by its Board-approved policy and the RBI’s 2017 circular, subject to the 90-day outer limit.

Reserve Bank – Integrated Ombudsman Scheme, 2021. If the bank’s response is unsatisfactory, delayed, or simply wrong, a customer can escalate to the RBI Ombudsman under RBIOS 2021, which folded together the earlier Banking Ombudsman Scheme, the NBFC Ombudsman Scheme, and the Ombudsman Scheme for Digital Transactions into one centralised process, administered through the Centralised Receipt and Processing Centre in Chandigarh. This process is free, does not require a lawyer, and is exactly the route the customer used — successfully, on appeal — in the Gauhati High Court case discussed below.

Consumer Protection Act, 2019. A bank’s failure to properly investigate, wrongly attributing negligence to the customer, or an unreasonable delay, can independently be pursued as a “deficiency in service” under Section 2(11) before the District, State, or National Consumer Commission (depending on the value of the claim), with the added possibility of compensation for the mental agony and harassment caused, not merely the principal amount.

Civil suit for recovery. Where regulatory and consumer-forum avenues are inadequate or the amounts are very large, an ordinary civil suit for recovery of money (potentially alongside a claim in tort for the bank’s or platform’s negligence) remains available, though it is slower and costlier than the Ombudsman or consumer-forum routes.

NPCI/UPI Dispute Redressal Mechanism (UDRM) and chargeback. Independent of the criminal and RBI-liability tracks, a customer can ask their bank to raise a formal dispute/chargeback through NPCI’s centralised URCS platform for unauthorised, failed, or fraudulent UPI transactions. NPCI’s dispute window was revised to a uniform 45 days across categories, operationalised from 25 July 2024 (Operating Circular UPI-OC-No-198-FY-24-25), replacing the earlier, more fragmented category-specific timelines. The remitter bank and the beneficiary bank are both required to respond within the process, and the beneficiary bank must confirm whether the disputed funds were in fact credited to, and remain with, the recipient.

ZeroLiability if Bank at Fault, Any Time
10 DaysShadow-Reversal Credit Timeline
Rs 25,000Max Capped Liability (Higher Slabs)
BankBears Burden of Proving Negligence

Recovery Options: Chargeback, Ombudsman, Consumer Forum, Civil Suit

These routes are not mutually exclusive, and victims frequently pursue more than one at the same time:

  • Bank chargeback/dispute via NPCI UDRM — fastest route where the beneficiary account still holds the funds or the transaction qualifies as a processing/technical failure rather than a completed, laundered fraud.
  • RBI zero/limited liability claim — the strongest route where the transaction was genuinely unauthorised (as opposed to a customer voluntarily but deceptively induced transfer) and reported within the circular’s timelines.
  • RBI Integrated Ombudsman Scheme complaint — free escalation once the bank’s own response is unsatisfactory or the 30-day (or applicable) internal timeline lapses without resolution.
  • NCRP-triggered account freeze/lien — does not itself return money to the victim but can preserve funds in the fraudster’s beneficiary account pending investigation, which is often the only way any recovery becomes possible once money has left the victim’s own bank.
  • Consumer Commission complaint — appropriate where the core grievance is the bank’s deficient handling of the complaint itself, and where compensation beyond the principal sum (for harassment, mental agony, litigation cost) is sought.
  • Criminal complaint/FIR — necessary for the fraudster’s prosecution and, indirectly, often necessary to unlock any funds frozen in the beneficiary account, since a court or investigating authority typically must direct release of those funds to the rightful owner.
  • Civil suit — the residual route where other mechanisms fail or the sums involved are large enough to justify the cost and time of ordinary litigation.

Important Judgments

Case Core Issue Holding Practical Significance
State Bank of India v. Pallabh Bhowmick and 4 Ors., Gauhati High Court, WA/364/2022 (13 September 2024) Whether a bank can deny liability for a fraudulently induced UPI/payment-gateway transaction merely because it was completed with a valid OTP/MPIN Bank failed to discharge its burden (RBI circular, para 12) of proving actual customer negligence; being deceived into entering an OTP is not the same as negligently sharing credentials; third-party-breach transaction reported within 3 working days attracts zero liability under the 2017 RBI circular Confirms that banks cannot treat “the OTP was entered” as automatic proof of customer negligence, and reinforces that the RBI’s zero-liability clock runs from prompt reporting, not from the nature of the fraud technique used
State Bank of India v. Hare Ram Singh & Anr., Delhi High Court, 2026:DHC:4833-DB (Division Bench, June 2026) Whether a customer’s bare denial of sharing an OTP automatically makes the bank liable for a vishing-induced internet-banking fraud “Customer negligence” under Clause 7(i) of the 2017 RBI circular is illustrative, not exhaustive, and extends to clicking a suspicious link or using an unknown application; without forensic evidence of a system-side breach, a writ court cannot presume the bank was at fault merely because two-factor authentication was used The leading counterweight to Pallabh Bhowmick: shows that outcomes turn on the specific facts and available forensic evidence, not on a blanket rule that deception always defeats a negligence finding
DAV Public School v. Senior Manager, Indian Bank, Midnapore Branch and Ors., (2019) 20 SCC 31 Bank’s liability framework for unauthorised electronic transactions relied upon as governing precedent Applied by the Gauhati High Court as the controlling authority for assessing bank liability on facts involving disputed negligence Establishes that the RBI’s customer-liability framework, not a bank’s unilateral internal assessment, governs disputes of this kind

Practical Implications and Common Mistakes

  • Delaying the report. Every day of delay after receiving the bank’s transaction communication moves the case further down the RBI’s liability ladder — from zero liability, to a capped amount, to the bank’s discretionary policy. Reporting within three working days is the single most consequential action a victim can take.
  • Only calling the bank and skipping 1930/NCRP. The bank can reverse a transaction internally in some cases, but only the NCRP/1930 route (or a police complaint) can trigger a freeze on the beneficiary account before the money is withdrawn or moved onward.
  • Assuming an OTP entry automatically means “negligence” — or automatically means it doesn’t. Neither extreme is correct: the Gauhati High Court held that a customer deceived into entering an OTP has not necessarily been negligent, while the Delhi High Court held that clicking a suspicious link can itself count as negligence even without express OTP-sharing. What actually matters is the specific evidence of how the credentials were compromised — which is exactly why preserving evidence (the next point) matters so much.
  • Not preserving evidence. Screenshots, call logs, and message threads are frequently the deciding factor in Ombudsman and consumer-forum proceedings; deleting them (even inadvertently, by clearing an app’s cache) can seriously weaken an otherwise strong claim.
  • Treating the NCRP complaint as the end of the process. Filing on cybercrime.gov.in starts the process; it does not by itself compel the bank to reverse the transaction or guarantee a fund freeze — the bank complaint, and where necessary an FIR, must be pursued in parallel.
  • Not escalating to the RBI Ombudsman when the bank’s internal response is inadequate. Many victims stop at an unfavourable bank decision without realising that a free, lawyer-free escalation route exists and has, in reported cases, reversed the bank’s own finding of negligence.
  • Confusing a “collect” request with an incoming payment. Approving a UPI collect request always results in a debit from your account, never a credit — a mistake that alone accounts for a large share of QR-code-related frauds.

Preventive Practices That Also Strengthen a Later Legal Claim

Prevention and legal readiness overlap more than most people realise — the same habits that reduce the chance of fraud also make it far easier to prove zero liability if fraud happens anyway.

  • Never search for a “customer care number” on the open internet. Fraudulent listings routinely outrank genuine ones on search engines; always use the number printed on your card, passbook, or the company’s verified app/website.
  • Treat every “refund” or “cashback” request that asks you to scan a QR code or enter your UPI PIN with suspicion. Receiving money never requires entering a UPI PIN — the PIN is only ever needed to send or approve a payment.
  • Never install a remote-access/screen-sharing app at the request of an unsolicited caller, regardless of how official they sound or how urgent the situation seems.
  • Register for, and actually read, SMS and email transaction alerts. The RBI circular’s reporting timelines run from when the bank’s communication reaches you, so promptly noticing an alert is directly what preserves your zero-liability window.
  • Keep a record of every transaction confirmation and reference number as a matter of routine, not only after something goes wrong — this evidence is frequently the difference between a fast Ombudsman resolution and a prolonged dispute.
  • Report a lost SIM or an unexpected, unexplained loss of mobile signal immediately to your telecom provider, since it can indicate an in-progress SIM-swap attack, and simultaneously alert your bank to watch for unauthorised transactions on your account.

Frequently Asked Questions

Is my bank required to refund money lost to UPI fraud?

It depends on fault and reporting time. Under the RBI’s 2017 circular, if the bank was itself negligent, or if the fraud resulted from a “third-party breach” reported within three working days, the customer’s liability is zero and the bank must credit the amount (with a shadow reversal) within 10 working days of notification. If the customer was genuinely negligent — for example, knowingly sharing an OTP or MPIN with someone — liability shifts to the customer up to the point of reporting.

What is the “golden hour” and why does it matter?

It refers to the period immediately after a fraudulent transaction — often described as the first hour — during which reporting to the 1930 helpline gives the best chance of the beneficiary bank placing a lien or freeze on the fraudster’s account before the money is withdrawn or transferred further. Once funds are withdrawn in cash or moved through several accounts, recovery becomes significantly harder.

Should I file a police FIR if I’ve already reported on cybercrime.gov.in?

Often yes, particularly for larger amounts. An NCRP complaint is a valuable first step and can trigger a fund freeze quickly, but a formal FIR is usually necessary for a full criminal investigation, for invoking Sections 318/319 of the BNS and Sections 66C/66D of the IT Act against the identified fraudster, and for any later civil or insurance claim that requires a police report.

What if my bank says the transaction was “successful and authorised” and refuses to help?

The burden of proving negligence rests on the bank under the RBI’s framework — a position the Gauhati High Court confirmed in 2024 — but a bank can still discharge that burden with actual evidence, such as showing you clicked a phishing link or used an unverified app, as the Delhi High Court recognised in 2026. Simply asserting that the OTP was “successful” is not, by itself, enough on either side of the argument. If your bank’s internal complaint process rejects your claim without producing cogent evidence, you can escalate free of cost to the RBI’s Integrated Ombudsman Scheme, and separately pursue a deficiency-of-service complaint before a Consumer Commission.

Is the liability framework described here going to change?

Yes, from 1 January 2027. The Reserve Bank has already issued (not merely proposed) amendment directions that extend the zero-liability reporting window from three working days to five calendar days, cut the complaint-resolution timeline from 90 to 45 calendar days, spell out specific examples of bank and customer negligence, and introduce a new one-time compensation mechanism for bona fide small-value fraud (up to Rs. 50,000) attributable to customer negligence. Until that date, the rules described in this guide’s Bank and RBI Liability Framework section remain the ones in force.

Can I get my money back once it has left the fraudster’s account?

It becomes considerably harder. Recovery chances are highest when a lien/freeze is placed on the beneficiary account before withdrawal — which is exactly why fast reporting matters. Once funds are withdrawn in cash or “layered” across multiple accounts, recovery typically depends on the outcome of the police investigation identifying and tracing the fraud chain, and any eventual court or investigating-authority order directing release of frozen funds.

Does the RBI Ombudsman process cost anything or require a lawyer?

No. The Reserve Bank – Integrated Ombudsman Scheme, 2021 is a free grievance-redressal mechanism, and complaints can be filed directly by the customer without engaging a lawyer, through the RBI’s online portal, by email, or in writing to the Centralised Receipt and Processing Centre in Chandigarh.

Conclusion

UPI and digital-payment fraud sits at the intersection of banking regulation, cyber law, and consumer protection, and Indian law responds to it in layers rather than through any single remedy. The RBI’s 2017 liability circular decides who bears the loss and how fast; the IT Act and the Bharatiya Nyaya Sanhita supply the criminal teeth against the fraudster; the RBI Ombudsman and Consumer Protection Act give a free, accessible route when a bank’s own response falls short; and NPCI’s dispute mechanism offers a parallel technical route to recover funds still traceable in the system. None of these routes are self-executing — each depends heavily on how quickly and how correctly the victim documents and reports the fraud. Acting within the first hours, notifying the bank in writing within three working days, and pursuing the NCRP, bank, and — where necessary — Ombudsman or consumer-forum routes in parallel gives a victim the strongest possible position under each of these overlapping frameworks. That framework itself is not static — the Reserve Bank’s already-issued amendment taking effect on 1 January 2027 will extend reporting windows, tighten resolution timelines, and add a new compensation mechanism for small-value fraud, and courts continue to actively work out where the line between deception and negligence falls. Readers should treat this as a fast-moving area and confirm the current position before relying on any specific timeline or figure in a live dispute.

This article is intended as general statutory information and does not constitute legal advice. Lexovia is not a law firm and does not provide legal advice, legal consultation, or legal representation under the Advocates Act, 1961. Statutory provisions, procedural requirements, and case law may vary and are subject to ongoing change. Customers are advised to consult a qualified enrolled advocate before filing a complaint, initiating recovery proceedings, or relying on this guide for a specific dispute.

Need a document drafted or a legal question researched? Lexovia provides statute-backed legal drafting and research, delivered to your inbox — no office visits.

See Services & Pricing →

This document type is also available with a native-language companion — see Services for details.

Scroll to Top