Asked by a reader in Bengaluru

The bank says I shared my OTP so the loss is mine. Is that actually the law?

Answered by Advocate Sharan Jain··Cyber Crime & Online Fraud

Legal Shorts · 74 words

Sharing an OTP can count as customer negligence, but the RBI rule is more specific than a blanket refusal. For an unauthorised transaction caused by that negligence, the customer bears the loss until it is reported. Losses after reporting fall on the bank. Other rules apply where the bank was at fault or a third-party breach caused the loss. Report immediately and ask the bank to identify the evidence and rule supporting its decision.

Short sources checked:

WhatsApp

The bank is quoting one paragraph of the rule and leaving out three. The Reserve Bank's circular of 6 July 2017, "Customer Protection - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions", does treat sharing credentials as customer negligence. It also says the bank must prove it, that your liability stops the moment you report, and that the bank carries the loss in full where its own systems fell short. Which of those governs your case depends on facts the bank has and you do not, which is why the first move is a written demand for them.

What does the RBI circular actually say about sharing an OTP?

The three limbs of the 2017 circular. Paragraph 6 gives a customer zero liability where the loss arises from contributory fraud, negligence or deficiency on the part of the bank, whether or not the customer reported it, and in a third-party breach where the deficiency lies neither with the bank nor with the customer, provided the customer notifies the bank within three working days of receiving the bank's communication about the transaction. Paragraph 7 provides that where the loss is due to negligence by a customer, "such as where he has shared the payment credentials, the customer will bear the entire loss until he reports the unauthorised transaction to the bank. Any loss occurring after the reporting of the unauthorised transaction shall be borne by the bank." Paragraph 12 provides that "the burden of proving customer liability in case of unauthorised electronic banking transactions shall lie on the bank."

Three further paragraphs matter because banks breach them regularly. Paragraph 5 requires the bank to send SMS alerts for every electronic transaction, to let you object by replying to the alert, to give round-the-clock reporting channels, to acknowledge your report immediately with a complaint number, and to log the date and time its alert reached you and your response reached it, which the circular says "shall be important in determining the extent of a customer's liability". Paragraph 9 requires a shadow credit of the disputed amount within ten working days of your report. Paragraph 10 requires the complaint to be resolved and your liability, if any, established within ninety days, failing which the bank pays the compensation anyway.

Is being tricked into reading out an OTP "negligence"?

This is the contested point, and I will not pretend it is settled. The 2017 circular does not define negligence. Its only illustration is sharing payment credentials, and a bank will say that reading an OTP to a caller is exactly that. The reply is that the same document puts the burden on the bank, so the bank must show, with its own logs, that the OTP was generated for that transaction, was delivered to your registered number, and was then keyed in by the fraudster, and that no alert, fraud filter or velocity check on its side failed. A bank that cannot produce those logs has not discharged paragraph 12, and the question of what you said on a call never arises.

The Bombay High Court applied that method in a judgment of 6 April 2026 in Subodh C. Korde v Union of India, Writ Petition 11990 of 2023. The facts were a SIM swap rather than a shared OTP, and the customer had shared nothing, but the reasoning is the one to borrow: the bank asserted it had sent OTPs, could not place a single original alert log before the court, and its own investigation showed the fraudulent logins came from a different IP than the customer's genuine transactions. The court held the bank had failed to prove negligence, found the customer entitled to zero liability, and directed the refund with interest. Where you did read out the OTP, the argument is harder and the outcome turns on the bank's other failures, so build the written record around those.

One date to know. The Reserve Bank issued amended directions on 24 June 2026 which apply to transactions on or after 1 January 2027. They expressly list, as customer negligence, "providing credentials for carrying out transactions to another person, whether intentionally or otherwise". For transactions after that date the deception argument gets weaker. The same directions widen the bank's duties, define bank negligence to include not sending mandatory alerts and not acting diligently on a report, cut the complaint deadline to 45 days for domestic transactions, and introduce a one-time compensation for small-value frauds up to Rs 50,000, at 85 per cent of the net loss or Rs 25,000, whichever is lower, provided you reported on the portal or 1930 and to the bank within five calendar days. For a transaction today, the 2017 circular still governs.

What should my written complaint say?

  • The date and time you first reported, with the complaint number and the 1930 or cybercrime.gov.in acknowledgement
  • A demand that the bank state, in writing, the paragraph of the circular it relies on and the evidence for it, citing paragraph 12
  • A request for the alert dispatch log for the transaction, with delivery time stamps, the device and IP details recorded against each debit, and whether its fraud detection system flagged anything
  • A request for the shadow credit under paragraph 9, ten working days from your report
  • A note that under paragraph 10 the complaint must be resolved within ninety days
  • A request for the bank's board-approved customer protection policy, which paragraph 7 requires it to give you at account opening and display publicly

Where do I escalate?

  1. The bank's grievance cell, then its nodal or principal nodal officer, in writing, insisting on a reasoned reply rather than a call.
  2. The RBI Ombudsman under the Reserve Bank Integrated Ombudsman Scheme, 2026, in force from 1 July 2026. File after thirty days without a satisfactory reply, and within ninety days of the reply or of that period expiring, online at cms.rbi.org.in. It is free, there is no ceiling on the amount in dispute, compensation for consequential loss can reach Rs 30 lakh with a further Rs 3 lakh for time and harassment, and an FIR is not treated as the same grievance. An advocate cannot represent you unless the advocate is the victim.
  3. A consumer complaint for deficiency in service under the Consumer Protection Act, 2019, before the District Commission for claims up to Rs 50 lakh, filed where you reside under Section 34(2)(d), within two years under Section 69(1). It can carry compensation and costs alongside the refund.

Run the criminal track in parallel. The caller committed cheating by personation using a computer resource under Section 66D of the Information Technology Act, 2000, and cheating under Section 318(4) of the Bharatiya Nyaya Sanhita, 2023. Our guide on UPI and bank fraud under the RBI rules walks through each band, and the answer on choosing between the Ombudsman and the consumer commission explains the sequence.

Where these complaints actually turn

In my experience the case is won or lost on one request: show me the logs. Banks decline hundreds of these disputes with a form letter saying the customer "must have shared the OTP", and most cannot produce a delivery record when a written demand citing paragraph 12 arrives, because the alert went out from a vendor's system and nobody kept the receipt. Do not argue about what you said on the call. Ask what the bank can prove, in writing, and let the ninety-day clock run against it. The related answer on UPI used without your knowledge deals with the cleaner case where nothing was shared at all.

Sources

The law this answer relies on, so you can read it yourself.

  1. 1.RBI: liability for unauthorised electronic banking transactions, 6 July 2017 Read the source
  2. 2.Bharatiya Nyaya Sanhita, 2023. Official consolidated text on India Code, the Government of India repository of Central Acts. Read the source
  3. 3.Consumer Protection Act, 2019. Official consolidated text on India Code, the Government of India repository of Central Acts. Read the source
  4. 4.Information Technology Act, 2000. Official consolidated text on India Code, the Government of India repository of Central Acts. Read the source

The short answer's sources were checked on 12 September 2026. Statutes and judgments can change, so check the current position before you act on anything here.

Nothing there yet? Send the question in and it gets answered here.

Related legal service

Dealing with this yourself rather than reading about it? Our Bangalore advocates work in this area.

Go deeper on this

This answer is the short version. These guides cover the same ground in full, with the procedure, the timelines and the leading cases.

SJ

Answered by

Advocate Sharan Jain

Advocate based in Bangalore, practising before the Karnataka High Court and District, Sessions, Consumer and Family courts. Answers public legal questions to make Indian law more accessible.

This answer is general information on Indian law as at September 5, 2026, published for public education. It is not legal advice, it does not take account of your facts, and reading it does not create an advocate-client relationship. Law changes and every case turns on its own circumstances. Please consult a qualified advocate about your own matter.

People also asked

Consumer Protection

Money was taken from my account fraudulently and the bank says it is my fault. What now?

Report the transaction to the bank immediately and keep the complaint number. RBI's framework distinguishes bank fault, customer negligence and third-party breaches. Zero liability for a third-party breach depends on reporting within the specified period, while sharing credentials can change who bears the loss. Ask for the bank's written investigation and calculation. If unresolved, check the current RBI Ombudsman process and deadlines. Do not assume that reporting cybercrime by itself also counts as notifying your bank.

Cyber & Online Fraud

My UPI was used without my knowledge. I never shared anything. Who bears the loss?

Report the unauthorised UPI debit to your bank immediately and keep proof of the time. Under RBI rules, bank fault can mean zero customer liability. A third-party breach, with neither bank nor customer at fault, also attracts zero liability if reported within three working days of receiving the bank's communication. Customer negligence follows a different rule. Ask for the transaction and alert records. The bank bears the burden of proving customer liability under this framework.

Consumer Protection

The bank has been levying charges I never agreed to. Consumer commission or the banking ombudsman?

First ask the bank to identify the agreed tariff and justify each disputed charge. The RBI Integrated Ombudsman Scheme, 2026 now governs new complaints, with its own prior-complaint requirements and deadlines. A consumer commission may also provide relief for deficient banking services. These routes are not a licence to pursue the same grievance simultaneously or reopen a binding settlement. Check the status of any existing proceeding before choosing, and preserve the statements, tariff disclosures and your written objection.

Cyber & Online Fraud

I lost money to an online scam. What do I do in the first hour?

Call 1930 and notify your bank immediately, then complete the complaint on cybercrime.gov.in. Give the transaction number, amount, time and receiving account or UPI ID. Prompt reporting can help the authorities try to stop further movement of the money, but it does not guarantee recovery. Save the messages and payment records, and secure any account the scammer accessed. Ask the bank for a complaint number and written response about your disputed transaction.

Cyber & Online Fraud

My money went into a mule account. Can the bank that holds that account be made to refund it?

A receiving account being used by scammers does not, by itself, establish that its bank must reimburse you. Report the transfer immediately through 1930 and your own bank, and provide the receiving account details to investigators. Ask for preservation of the transaction trail and action on any funds still available. Your own bank's liability for an unauthorised debit is a separate question under RBI rules. Recovery from a recipient or bank needs a basis supported by the evidence.

Cyber & Online Fraud

I called 1930 but the money has already left the account it went to. Can I still recover it?

Keep pursuing the complaint even if the first receiving account is empty. Give the investigating officer and your bank every transaction reference so they can examine the onward trail. Separately, ask your bank to assess liability under the RBI rules for unauthorised transactions. Those rules do not promise reimbursement for every scam payment, especially a transfer you authorised yourself. Save the acknowledgement and follow up in writing. A failed initial hold is not the same as a completed investigation.

S Jain & Attorneys · Ask Me

Still not the question you had in mind?

Search the column, or send your question in. Questions of general interest are answered here, anonymously, so the next person does not have to ask.