Banking
Unauthorised UPI or card transaction: the first ten minutes matter
Report the debit to your bank immediately, block the payment channel and call 1930. Here is the RBI liability framework and the evidence to preserve.
Report the debit to your bank now, through the number in its official app, website or on the back of your card. Block the affected card or UPI access, ask the bank to stop further debits, and note the complaint number and time. Then call 1930 and file the details on the National Cyber Crime Reporting Portal. Speed matters both for tracing money and for how RBI’s customer-liability rules apply.
Do not wait to decide whether the payment was fraud, a technical error or a merchant dispute. Report the facts first. Do not share an OTP, PIN, CVV or screen-sharing access with anybody who calls claiming to reverse it; a real bank does not need those secrets to register a complaint.
What to do in the first ten minutes
Work down this list without waiting for one channel to finish before starting the next:
- Notify the bank. Use its 24-hour fraud line, app control or internet-banking complaint route. State that the transaction was not authorised by you. Ask it to block the affected instrument and prevent further transactions.
- Secure the payment channel. Temporarily block the card; disable UPI or mobile banking if the device or credentials may be compromised; and sign out other sessions. If a phone has been stolen, also block the SIM through the telecom provider.
- Call 1930. The national helpline is designed for immediate reporting of cyber financial fraud. Give the transaction reference, amount, time, bank and destination details. Complete the portal complaint when instructed.
- Change credentials from a clean device. Change internet-banking and email passwords, reset the UPI PIN where appropriate and remove unknown devices. Blocking a card alone does not secure a compromised email account.
- Write down the timeline. Save the bank complaint number, 1930 acknowledgement, screenshots and the exact time you first saw and reported the debit.
If the event involved a credit card, also check for small test transactions and review recurring mandates. Understanding the normal entries in credit card charges and statements makes an unfamiliar merchant or fee easier to isolate.
Unauthorised debit or mistaken transfer?
The distinction changes the remedy.
An unauthorised transaction is a debit you did not approve: for example, a card-not-present purchase you never made, a UPI payment approved from a compromised device without you, or a transfer caused by a bank-system breach. Tell the bank plainly that you did not authorise it.
A mistaken transfer is one you approved but sent to the wrong UPI ID, mobile number or bank account. Entering the PIN means the payment was authorised even if the beneficiary was not the person you intended. NPCI says a UPI payment cannot be stopped once initiated. Raise a complaint with the app and your bank immediately, ask the bank to contact the beneficiary bank, and preserve the transaction reference. Recovery may depend on the recipient’s consent or further legal process; the unauthorised-transaction liability framework is not a guaranteed refund route.
A merchant dispute is different again: you authorised the payment but the goods, service, cancellation or refund went wrong. Use the card chargeback or UPI merchant-dispute route and provide the order and correspondence. Do not describe an authorised purchase as fraud.
When RBI rules give zero or limited liability
For commercial banks, the current RBI Responsible Business Conduct Directions divide cases by cause and reporting time.
You have zero liability when the loss arose from the bank’s fraud, negligence or deficiency, regardless of when you report it. You also have zero liability for a third-party breach — where neither you nor the bank was at fault — if you notify the bank within three working days of receiving its transaction alert.
If the third-party breach is reported in four to seven working days, liability is capped at the lower of the transaction value and the RBI category limit. The caps are ₹5,000 for Basic Savings Bank Deposit accounts; ₹10,000 for most other savings accounts, prepaid instruments, specified smaller current/credit/overdraft accounts and cards with limits up to ₹5 lakh; and ₹25,000 for the other current/credit/overdraft accounts and cards with limits above ₹5 lakh. Read the bank’s policy for the category that actually describes your account.
After seven working days, the bank’s Board-approved policy applies. “Working days” follow the schedule of your home branch, and the day you received the bank’s alert is excluded.
If the loss occurred because you shared a PIN, OTP or payment credential, RBI places the loss up to the time of notification on the customer. Losses after notification fall on the bank. That is another reason to report first and investigate later. The bank bears the burden of proving customer liability, but that does not mean every disputed debit must ultimately be refunded.
What should happen after you report
The bank must immediately take steps to prevent more unauthorised transactions after receiving your report. Under the current Directions, it should make a shadow reversal within ten working days of your notification, value-dated to the transaction date, so you do not lose interest or incur an extra credit-card interest burden while the case is examined.
That entry can be provisional. It is not a promise that the investigation will end in your favour. The bank must determine liability and resolve the complaint within the period in its policy, which cannot exceed 90 days. Where the liability framework says the customer is protected, a debit-card or bank-account customer should not lose interest; a credit-card customer should not bear additional interest burden.
Watch the next two statements. A fraudulent card debit can affect utilisation and payment reporting if it remains on the account. Pull your free CIBIL report later if the card issuer treated the disputed amount as overdue, and dispute any factual reporting error rather than waiting for the score to recover by itself.
Evidence that makes the complaint usable
Give the bank and cybercrime portal a short, factual pack:
- account or masked card number, transaction date and time, amount, merchant or UPI ID;
- the 12-digit UPI/transaction reference or UTR where available;
- screenshots of the debit alert, bank statement entry and app status;
- phone numbers, email addresses, URLs, chats and remote-access app names involved;
- a statement of whether you entered a PIN, OTP or CVV, and exactly what happened;
- bank complaint number, 1930 acknowledgement and the times you reported both.
Do not alter screenshots or delete messages. Do not forward sensitive evidence publicly. If the phone may be infected, preserve what can be captured safely and then secure the accounts from another device. For a lost card, note when you last possessed it and when it was blocked.
Also inspect other accounts that reuse the same phone number, email or password. Replace weak credentials and keep card controls conservative. The practical habits in the first credit card guide apply even to long-time users: transaction alerts, sensible limits and full-statement review are fraud controls, not beginner features.
How to escalate if the bank does not resolve it
Send a written complaint to the bank’s grievance officer even if you first reported by phone. Quote the original complaint number and ask for its finding on cause, reporting delay, liability category and any rejected evidence. If it denies the claim, ask for the applicable policy clause and investigation outcome in writing.
If the bank’s final response is unsatisfactory, or it has not responded within the applicable complaint period, follow the institution-first clocks in the RBI Ombudsman guide. The Reserve Bank — Integrated Ombudsman Scheme, 2026 covers complaints against regulated entities including banks. Its current filing window runs to 90 days after the applicable reply period expires or after the regulated entity’s last communication, whichever is later. File against the bank, attach the first complaint, and explain the relief sought; the cybercrime complaint does not replace this banking grievance.
Finally, check that the event did not create a credit-reporting error. If it did, correct the underlying account data through the CIBIL dispute process rather than waiting for the score to recover. The priorities remain simple: notify, block, report, preserve, follow up. None guarantees recovery, but delay makes every route harder.
Common questions
Should I call 1930 or my bank first?
Do both immediately. Use the bank's official emergency channel first if it is already open on your phone, because the bank must prevent further unauthorised transactions after receiving your report. Then call 1930 and complete the complaint on the National Cyber Crime Reporting Portal. If the 1930 line is busy, keep trying while another person calls the bank. Record the bank complaint number, cybercrime acknowledgement number and exact time of both reports.
Will the bank definitely refund an unauthorised transaction?
No result is automatic. RBI rules can give you zero or limited liability depending on what caused the loss and how quickly you reported it, but the bank investigates the facts. If you shared a PIN, OTP or other credential, you may bear losses up to the time you notified the bank. A prompt report still stops later losses from being placed on you. Never treat a provisional credit as a final recovery until the bank closes the complaint.
I sent UPI money to the wrong person. Is that an unauthorised transaction?
Usually not. If you entered the UPI ID or selected the recipient and approved the payment with your PIN, you authorised the debit even though the destination was a mistake. NPCI says an initiated UPI payment cannot be stopped. Report it through your app and bank at once and ask for beneficiary-bank coordination, but the RBI unauthorised-transaction liability limits do not create a guaranteed reversal right for a mistaken transfer.
What if the bank says I waited too long?
Ask for the date and time of the bank's transaction alert, the date and time it logged your complaint, and the clause of its Board-approved customer-liability policy being applied. Working days are counted using your home branch schedule, excluding the date the alert was received. If you disagree, make a written complaint to the bank. After its final reply, or if it has not replied within the applicable period, you can escalate through RBI's Complaint Management System.
Should I delete the fraudulent SMS or app after blocking it?
No. Preserve the SMS, email, notification, caller number, chat, URL, UPI ID, card merchant name, transaction reference and screenshots. Do not click the link again or keep a malicious app active merely to collect evidence; photograph or screenshot what is safely visible, then remove access and change credentials from a clean device. Keep the original complaint acknowledgements because later escalation depends on a clear timeline.
Sources
Rates and rules on this page were read directly from the following sources on the dates shown. Figures change — if you are about to act on one, confirm it at the source.
- RBI (Commercial Banks — Responsible Business Conduct) Directions, 2025, updated 1 July 2026
- National Cyber Crime Reporting Portal — Report Other Cybercrime
- National Cyber Crime Reporting Portal — Financial Fraud Reporting Checklist
- Register a complaint
- UPI frequently asked questions
- Reserve Bank — Integrated Ombudsman Scheme, 2026: Frequently Asked Questions