INDIA FINANCE · FINANCIAL SAFETY

UPI Fraud in India: What to Do After a Suspicious Payment

If a UPI payment looks suspicious, act quickly but do not panic. This guide separates an attempted scam from a completed debit, explains what to tell your bank and the official reporting channel, and shows how to protect yourself from a second scam.

Practical, source-linked guidanceUpdated 2026-10-08For general education

UPI Fraud in India: What to Do After a Suspicious Payment

Illustration of a phone showing a UPI fraud alert, a bank report, the 1930 helpline and a protected payment account
A visual guide to upi fraud in india: what to do after a suspicious payment.

A suspicious UPI call, link, collect request or debit can feel overwhelming. The safest response is a short sequence: stop communicating with the caller, check whether money actually left your account, contact your own bank or payment provider through a verified channel, and use the official national cyber-fraud reporting route when money or banking access is at risk. As of 8 October 2026, the Government of India's National Cyber Crime Reporting Portal says that cyber financial fraud should be reported immediately on 1930, and its portal is https://cybercrime.gov.in/ [1]. One important date distinction: RBI's 2026 amendments were issued on 24 June 2026, but they apply only to electronic transactions undertaken on or after 1 January 2027. For a transaction before that date, use the existing customer-liability framework; do not apply the future five-day window or compensation rules early [2] [7] [8] [9]. This is a practical safety guide, not investment advice, legal representation or a promise that a report will recover money. A report creates an official record and can help banks and law-enforcement agencies act, but the outcome depends on the facts, timing, payment trail and applicable rules.

First decide: attempted scam or completed transaction

Treat a fraud attempt seriously even when no debit has appeared. A caller asking for an OTP, UPI PIN, card number, password, screen-sharing access or a remote-control app is trying to obtain access or authorisation. End the call, do not click the link, reject an unexpected collect request, and do not scan a QR code merely to receive money. NPCI specifically says that a UPI PIN is for making a payment, not receiving one, and warns against sharing payment credentials, forwarding messages, using remote-access apps during transactions, or relying on contact details found through an internet search [4].

Now check the bank statement and the UPI app's transaction history using the app you already use. An attempted scam means there is no unauthorised debit or completed transfer visible, although a password, card detail, SIM, device or account may have been exposed. A completed transaction means a debit, transfer, mandate or other bank entry has actually occurred. Do not assume that a failed or pending status is harmless; note the status and ask the bank what it means.

If you disclosed credentials, installed an unknown app, granted screen access, or lost control of your phone or SIM, tell the bank that immediately even if the balance has not changed. Ask what account, UPI, card, beneficiary or digital-banking controls should be blocked or reset. Use only the bank's official app, website, statement, card, passbook or branch details. NPCI says users should find bank contact details from the bank's website and report complaints to the bank or police authorities [4].

The first minutes after an unauthorised UPI debit

For a completed or apparently unauthorised transfer, contact your own bank or payment provider first through its verified 24x7 reporting route. Use the fraud or unauthorised-transaction option in the official app or website, the number printed on the card or statement, phone banking, or a branch. Say clearly that you are reporting an unauthorised or fraudulent electronic banking transaction, give the transaction time and amount, and ask the bank to register it as a complaint. Do not rely on a chat reply from the person who contacted you or on a number supplied by that person.

Ask for the complaint or service-request number and record the date and time the bank received your report. RBI's existing directions require banks to provide 24x7 reporting channels, register the report as a complaint, send an acknowledgement with the complaint number and receipt time, and take immediate steps to prevent further unauthorised transactions after a report [7] [8]. Those requirements do not mean that money will definitely be recovered; they mean you should create a traceable bank report without delay.

Next, report cyber financial fraud on 1930 and through https://cybercrime.gov.in/ [1]. If a telephone operator helps you begin the report, follow the official instructions and save the acknowledgement or complaint reference. The bank report and the national cyber report serve different purposes: the bank can investigate and apply account-level controls, while the national channel routes the incident for cybercrime and financial-fraud response. Do both promptly rather than waiting to see whether the other one succeeds. RBI's 2026 amendments also tell banks to advise customers to use the portal or 1930, but those amendments take effect only on 1 January 2027 [2] [9].

Keep the identifiers and evidence before deleting anything

The NCRP checklist asks a financial-fraud complainant to keep the incident date and time, an incident description, an identity document, the bank, wallet or merchant name, the 12-digit transaction ID or UTR number, transaction date, fraud amount and relevant evidence [1]. This is why the first step is preservation, not a hurried cleanup of messages. Copy the UTR or transaction reference exactly as shown; do not replace it with an order number, phone number or a guessed account number.

Save the debit alert, UPI transaction screen, bank statement entry, confirmation page, collect-request details, UPI ID, beneficiary name, phone number, email address, web address, QR image, call log and chat screenshots. Keep original files where possible, with visible dates and times. If a message contains a link, record the full address without opening it again. Note what you were told, what you clicked, what you entered, and whether an OTP or UPI PIN was used. This factual timeline helps the bank and investigators; it is not an admission of blame.

The portal also lists optional suspect information such as a mobile number, email, bank account, address, social-media handle, website URL or other identifying document [1]. Share only what you have and do not try to investigate, threaten or contact the suspected person yourself. Store copies in a safe place, but do not publish transaction details on social media. NPCI warns users not to post grievance transaction details publicly [4].

Use 1930 and the portal without creating a second risk

The verified national financial-fraud helpline is 1930, and the official reporting portal is https://cybercrime.gov.in/ as confirmed on the portal's own page [1]. Type the address yourself or use a trusted bookmark. Check that the domain is cybercrime.gov.in before entering personal information. A genuine helper will not need your UPI PIN, OTP, password, full card credentials or the screen of your banking app to record a complaint.

When completing the report, describe the incident in plain chronological language: how the contact began, what the other person claimed, what action you took, when the debit appeared, which account or UPI app was involved, and what you have already reported to the bank. Attach the requested evidence in the portal's stated format and size limits. Keep the login, complaint and acknowledgement details. If you cannot complete a field or the portal behaves differently, do not guess; call 1930 or ask your bank how to proceed through verified channels.

Do not treat a portal submission as a refund application or a guarantee of a freeze. The portal facilitates reporting and the NCRP checklist helps authorities receive usable information, but recovery depends on whether funds can be traced or stopped, the bank and beneficiary-bank response, investigation, and the facts of the case. Continue following your bank's verified process after filing. Do not pay a person who promises to recover the amount, obtain a police certificate or speed up a refund.

Understand bank rules by their effective date

As of 8 October 2026, the older RBI customer-liability framework remains the relevant framework for unauthorised transactions that occur before 1 January 2027. Under that framework, a customer has zero liability when the loss results from the bank's own fraud, negligence or deficiency. For a third-party breach outside both the bank's and customer's control, reporting within three working days after receiving the bank's transaction communication gives zero liability; a delay of four to seven working days gives limited liability subject to the account-type cap; after seven working days, the bank's approved policy applies. If the customer shared credentials, the customer bears losses up to the time the bank is notified; later losses are borne by the bank [7] [8]. The bank bears the burden of proving customer liability. These categories are not a finding about any particular case.

Under the existing framework, the bank must provide 24x7 reporting channels, acknowledge a report with a complaint number, take immediate steps to stop further unauthorised transactions and, for eligible zero- or limited-liability cases, credit a shadow reversal within ten working days. The bank must resolve the complaint and establish liability within its policy timeline, not exceeding 90 days. These current time limits differ from the 45-day domestic and 60-day cross-border response caps in the later RBI amendments; the latter do not apply to transactions before their effective date [7] [8] [2] [9]. A deadline for a bank response is not a guarantee that money will be recovered.

For electronic transactions undertaken on or after 1 January 2027, RBI's 2026 amendments introduce a different framework. For an eligible third-party breach, reporting to the bank within five calendar days of the transaction can give zero liability; after that, the bank's policy determines liability. Where a customer is negligent, a separate, conditional compensation mechanism may cover 85% of net loss or ₹25,000, whichever is less, once in the customer's lifetime, for eligible gross losses up to ₹50,000, provided the customer reports to both the bank and 1930 or the portal within five calendar days. This is not automatic reimbursement: eligibility, evidence, recoveries and the bank's examination matter [2] [9].

The 2026 press release lists separate amendment directions for commercial banks, small finance banks, payments banks, local area banks, regional rural banks, urban co-operative banks and rural co-operative banks, with a common 1 January 2027 effective date. The commercial-bank amendment specifies the future 45-calendar-day domestic and 60-calendar-day cross-border response caps. A customer should check the direction and policy for the institution that actually holds the account, and should not delay reporting while trying to choose a liability category [2] [9].

Prevent follow-on scams and protect the account

After a report, scammers may impersonate the bank, police, RBI, NPCI, a court, a cyber cell or a recovery agent. They may say that a small fee, OTP, UPI PIN, screen-share session or remote app is needed to unlock funds. It is not. NPCI says a bank's customer support will never ask for a UPI PIN and advises users never to share the PIN, debit-card credentials or requested SMS with a third party [5]. End unexpected calls and call back using a verified number.

Ask your bank what to do about the UPI profile, linked accounts, cards, net-banking password, mobile number, SIM, device and mandates. Change credentials only through the bank's official app or website, and do not reuse a password. If a remote-access app was installed, disconnect the device from the network while you seek verified help, remove the app only when you can preserve evidence safely, and check the device from a trusted security source. If the phone or SIM is lost or compromised, contact the telecom provider and bank through official channels.

Tell family members that receiving money does not require entering a UPI PIN, scanning a QR code supplied by a stranger, forwarding an SMS, or installing an app at a caller's instruction. NPCI describes UPI as a system with multiple participants, including the app, payer PSP, remitter bank, payee PSP and beneficiary bank [6]. That complexity is a reason to let the bank and official channels coordinate; it is not a reason to hand account access to a self-appointed helper.

Escalate methodically if the bank does not resolve the complaint

Start with the bank or regulated payment provider that holds the affected account, and use its internal grievance or nodal-officer route if the first complaint is not answered. Keep the complaint number, transaction references, copies of correspondence and a short chronology. NPCI's complaint page says fraudulent, unidentified or unauthorised transactions should be raised with the respective bank for redressal; it also says NPCI routes complaints to the relevant member and that the member bank or institution is responsible for resolving them [5]. For a UPI support or status issue, the app's in-app complaint path may also be useful, but it does not replace the bank's fraud report.

If the concerned RBI-regulated entity does not reply within the applicable period or gives an unsatisfactory reply, the RBI Integrated Ombudsman Scheme 2026 FAQ says the customer may approach the RBI Ombudsman. The customer must first approach the regulated entity, retain proof, and generally file within 90 days after the applicable timeline expires or the last communication, whichever is later [3]. The FAQ lists the transaction reference, entity complaint number, relevant documents, facts, loss and relief sought as useful filing details, and says there is no fee for filing [3]. Use the official RBI CMS link from the RBI complaints page, https://cms.rbi.org.in/ [3].

The Ombudsman route is a service-grievance escalation, not a substitute for a police or cybercrime report and not a guaranteed recovery route. A criminal investigation can continue separately, and the FAQ says some matters are outside the Scheme's maintainability rules [3]. If you are unsure which channel fits, report the transaction to the bank and 1930 first, then ask the bank or RBI's official guidance for the next step.

Frequently asked questions

What is the official number to report UPI cyber financial fraud in India?

As of 8 October 2026, use the national cyber financial-fraud helpline 1930 and report through https://cybercrime.gov.in/ [1]. Also contact your own bank or payment provider immediately through a verified channel.

Should I contact the UPI app or my bank first?

For an unauthorised or fraudulent debit, promptly contact the bank or payment provider connected to the affected account and ask it to register a fraud complaint. You can also use the UPI app's complaint route for status or support, but NPCI says fraudulent or unidentified transactions should be raised with the respective bank for redressal [5].

Can I get a refund just because I called 1930?

No. Calling 1930 and filing on the portal creates a report and may support coordinated action, but it does not guarantee recovery. The result depends on the transaction trail, timing, investigation, bank procedures and applicable RBI liability rules.

What details do I need for the cybercrime report?

Keep the incident date and time, bank, wallet or merchant name, 12-digit transaction ID or UTR, transaction date, fraud amount, incident description, identity document and relevant evidence. Suspect contact details and website or social-media information are useful when available [1].

Does entering a UPI PIN help me receive money?

No. NPCI says the UPI PIN is entered for making payments, not for receiving money. Do not scan an unexpected QR code, share an OTP or PIN, forward an SMS, or install a remote-access app at a caller's instruction [4].

When can I approach the RBI Ombudsman?

First complain to the concerned RBI-regulated entity and keep proof. Under the RBI Integrated Ombudsman Scheme 2026 FAQ, escalation is generally available after no reply within the applicable period or an unsatisfactory reply, with a stated 90-day filing window after that point [3].

Conclusion

A calm, documented response is safer than trying to negotiate with a scammer. Stop the contact, check whether the transaction completed, report the debit to your own bank through a verified channel, call 1930, file at https://cybercrime.gov.in/, preserve the UTR and evidence, and save every acknowledgement. These steps improve the quality and speed of reporting but do not guarantee recovery or replace a bank investigation. Protect yourself from the next scam by refusing to share OTPs, UPI PINs, passwords or card details with callers, helpers or anyone promising a refund.

Sources and further reading

Primary and reputable sources are linked so readers can check rules and product terms directly. Rules can change; confirm the current official guidance before acting.

  1. National Cyber Crime Reporting Portal: Financial Fraud Reporting and Complainant Checklist — Indian Cyber Crime Coordination Centre / Ministry of Home Affairs, Government of India

    Official 1930 cyber financial-fraud helpline, 24x7 wording, portal address, reporting purpose and the financial-fraud checklist covering UTR, bank or wallet, date, amount, identity document and evidence.

  2. Reserve Bank of India (Commercial Banks - Responsible Business Conduct) Third Amendment Directions, 2026 — Reserve Bank of India

    The Third Amendment Directions issued on 24 June 2026, which apply to electronic transactions undertaken on or after 1 January 2027; they establish the future reporting and customer-liability framework and must not be treated as the current framework for earlier transactions.

  3. Reserve Bank – Integrated Ombudsman Scheme, 2026: Frequently Asked Questions — Reserve Bank of India

    Official bank-first escalation conditions, applicable waiting period, 90-day filing window, required complaint details, no-fee statement and RBI CMS guidance under the 2026 Ombudsman Scheme.

  4. Fraud Awareness — National Payments Corporation of India

    Official UPI safety warnings: PIN for payments rather than receipts, avoid remote-access apps, do not share credentials or SMS, use verified bank contacts and do not publish transaction details.

  5. Other Product Complaint and UPI Complaint Support — National Payments Corporation of India

    Official direction that fraudulent, unidentified or unauthorised transactions should be raised with the respective bank, plus NPCI member-bank routing, transaction-reference and UPI PIN support information.

  6. About UPI — National Payments Corporation of India

    Official description of UPI participants, app-based complaint support, two-factor authentication and the UPI payment ecosystem.

  7. Limiting Liability of Customers in Unauthorised Electronic Banking Transactions — Reserve Bank of India

    The existing customer-liability framework: zero liability for bank negligence or a third-party breach reported within three working days of the bank's communication, limited liability after a four-to-seven-working-day delay, customer-negligence treatment, 24x7 reporting, acknowledgement, ten-working-day shadow reversal and a maximum 90-day complaint resolution period.

  8. Reserve Bank of India (Commercial Banks - Responsible Business Conduct) Directions, 2025, updated 1 October 2026 — Reserve Bank of India

    Current consolidated commercial-bank directions in force during October 2026, before the customer-protection amendments that take effect on 1 January 2027.

  9. RBI Issues Amendment Directions on Review of Framework of Limiting Customer Liability in Digital Transactions — Reserve Bank of India

    RBI's 24 June 2026 announcement that the amendment directions for multiple bank categories come into effect on 1 January 2027.

PUT THE IDEA TO WORK

Try the next calculator

Explore a related scenario with clear assumptions and no account.

Open Emergency Fund Calculator
← Browse all finance articles · Explore calculators