Asked by a reader in Bengaluru

My UPI was used without my knowledge. I never shared anything. Who bears the loss?

Answered by Advocate Sharan Jain··Cyber Crime & Online Fraud

Legal Shorts · 75 words

Report the unauthorised UPI debit to your bank immediately and keep proof of the time. Under RBI rules, bank fault can mean zero customer liability. A third-party breach, with neither bank nor customer at fault, also attracts zero liability if reported within three working days of receiving the bank's communication. Customer negligence follows a different rule. Ask for the transaction and alert records. The bank bears the burden of proving customer liability under this framework.

Short sources checked:

WhatsApp

A UPI debit you did not make and could not have prevented is an unauthorised transaction in the strict sense, and the Reserve Bank's circular of 6 July 2017 was written for exactly this. For a third-party breach where neither the bank nor customer is at fault, reporting within three working days of receiving the bank's communication gives zero customer liability. Bank negligence or deficiency causing the unauthorised transaction also attracts zero liability, regardless of reporting time. Customer negligence has different consequences. The bank has to prove otherwise. What decides the case is the written record of when you reported and what the bank can show about how the debit got through.

Which limb of the RBI circular am I in?

Third-party breach is defined in the 2017 circular as a case where "the deficiency lies neither with the bank nor with the customer but lies elsewhere in the system". A SIM swap, malware, a merchant or app breach, or a data leak may fall within this category if the deficiency lies with neither the bank nor the customer. The mechanism alone does not decide negligence. In this limb your liability turns on how fast you reported, counted in working days of your home branch from the bank's alert, excluding the day of the alert. Where the loss flows from the bank's own negligence or deficiency, liability is zero whether or not you reported.

Your liability in a third-party breach, paragraphs 6 to 8 of the 6 July 2017 circular
Time taken to report after the bank's alertYour liability
Within three working daysZero
Four to seven working daysThe transaction value or the cap for your account type, whichever is lower: Rs 5,000 for a basic savings account, Rs 10,000 for other savings accounts, prepaid instruments, MSME current accounts, individual current accounts with balance or limit up to Rs 25 lakh and credit cards with limit up to Rs 5 lakh, Rs 25,000 for other current accounts and higher-limit cards
Beyond seven working daysAs per the bank's board-approved policy, which it must give you at account opening
Any time, where the bank itself was negligent or deficientZero

The Reserve Bank's amended directions of 24 June 2026, which apply to transactions on or after 1 January 2027, spell the third-party limb out to include deficiency on the part of a third-party application provider, a payment aggregator, a payment gateway or a telecom service provider, which is to say the UPI app and the phone company by name, and move the zero-liability window to five calendar days. They also define bank negligence to include not sending mandatory alerts and not acting diligently on a customer's report. For a transaction today the 2017 bands apply, but the 2026 text is a useful statement of what the regulator has always treated as outside the customer's control.

What if my SIM was swapped or my phone was compromised?

Then the bank's argument that "the OTP went to your registered number" proves nothing, because the number was in someone else's hands. The Bombay High Court dealt with this on 6 April 2026 in Subodh C. Korde v Union of India, Writ Petition 11990 of 2023. The customer's BSNL SIM had been replaced on a false loss report, beneficiaries were added and Rs 38,04,000 moved out of his HDFC accounts through logins from a Chennai IP that did not match his genuine transactions from Pune. The bank said it had sent alerts and OTPs. It could not place a single original delivery log before the court, and its own investigation report showed the transactions were "not alerted" because of a risk score. The court held that the burden of proving customer negligence under paragraph 12 lay on the bank and had not been discharged, that the customer had shared nothing and reported promptly, that the zero-liability limb was triggered, and it directed the bank to remit the amount with interest within eight weeks.

The lesson is procedural. Write to your telecom operator the same day asking for the date, time and outlet of any SIM replacement on your number and the identity documents produced, and use the Sanchar Saathi portal to check the mobile connections in your name and to report the fraud communication through Chakshu. A sudden loss of signal before the debits is itself evidence, so note the time it happened.

What do I do in the first three days?

  1. Call 1930 and file the financial fraud complaint on cybercrime.gov.in with the UPI transaction IDs, the receiving VPA or account, the amounts and times. Keep the acknowledgement number.
  2. Report to the bank in writing, by email and through the app, within the same day, and ask it to block UPI on the account, register the dispute and send a hold request to the beneficiary bank. Paragraph 5 of the circular requires the bank to acknowledge immediately with a complaint number and to record the time.
  3. Raise the dispute inside the UPI app as well, against each transaction, and keep the ticket numbers.
  4. Ask the bank in writing for the shadow credit of the disputed amount within ten working days under paragraph 9, value-dated to the date of the debit.
  5. Ask for the transaction logs, the device ID and IP recorded against each debit, and the alert delivery log, citing paragraph 12.
  6. Keep the phone unwiped, and if it was compromised, keep the app or link that did it. Electronic evidence needs a certificate under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, and the device is the source.

What if the bank still refuses?

Insist on the refusal in writing with reasons, because paragraph 10 requires the complaint to be resolved and any customer liability established within ninety days, failing which the compensation is paid anyway. Then the Reserve Bank Integrated Ombudsman Scheme, 2026, free, online at cms.rbi.org.in, after thirty days without a satisfactory reply and within ninety days after that, with compensation up to Rs 30 lakh for consequential loss and Rs 3 lakh for harassment, and no bar from a pending FIR. A consumer complaint for deficiency in service under the Consumer Protection Act, 2019 runs in parallel, and a claim against the entity whose system was breached can go to the adjudicating officer under Section 46 of the Information Technology Act, 2000 relying on Section 43 for unauthorised access. On the criminal side the fraudster committed identity theft under Section 66C of the IT Act, which covers dishonest use of another person's password or unique identification feature, cheating by personation under Section 66D, and cheating under Section 318(4) of the Bharatiya Nyaya Sanhita, 2023.

Our guide on UPI and bank fraud recovery under the RBI rules lays out each band, and the answer on a bank refusing to refund deals with the escalation letters.

The one fact that wins these cases

Time of report. Everything in the circular is counted from the bank's alert to your notice, and a phone call with no ticket number is, in evidence, a call that never happened. Send the email the same hour, even a three-line one, keep the sent copy, and do not close the account, because the alert history and the statement are your proof. If you did share an OTP under pressure, the analysis changes, and the sibling answer on the shared-OTP defence is the one to read.

Sources

The law this answer relies on, so you can read it yourself.

  1. 1.RBI: liability for unauthorised electronic banking transactions, 6 July 2017 Read the source
  2. 2.Bharatiya Nyaya Sanhita, 2023. Official consolidated text on India Code, the Government of India repository of Central Acts. Read the source
  3. 3.Bharatiya Sakshya Adhiniyam, 2023. Official consolidated text on India Code, the Government of India repository of Central Acts. Read the source
  4. 4.Consumer Protection Act, 2019. Official consolidated text on India Code, the Government of India repository of Central Acts. Read the source

The short answer's sources were checked on 12 September 2026. Statutes and judgments can change, so check the current position before you act on anything here.

Nothing there yet? Send the question in and it gets answered here.

Related legal service

Dealing with this yourself rather than reading about it? Our Bangalore advocates work in this area.

Go deeper on this

This answer is the short version. These guides cover the same ground in full, with the procedure, the timelines and the leading cases.

SJ

Answered by

Advocate Sharan Jain

Advocate based in Bangalore, practising before the Karnataka High Court and District, Sessions, Consumer and Family courts. Answers public legal questions to make Indian law more accessible.

This answer is general information on Indian law as at September 5, 2026, published for public education. It is not legal advice, it does not take account of your facts, and reading it does not create an advocate-client relationship. Law changes and every case turns on its own circumstances. Please consult a qualified advocate about your own matter.

People also asked

Cyber & Online Fraud

The bank says I shared my OTP so the loss is mine. Is that actually the law?

Sharing an OTP can count as customer negligence, but the RBI rule is more specific than a blanket refusal. For an unauthorised transaction caused by that negligence, the customer bears the loss until it is reported. Losses after reporting fall on the bank. Other rules apply where the bank was at fault or a third-party breach caused the loss. Report immediately and ask the bank to identify the evidence and rule supporting its decision.

Consumer Protection

Money was taken from my account fraudulently and the bank says it is my fault. What now?

Report the transaction to the bank immediately and keep the complaint number. RBI's framework distinguishes bank fault, customer negligence and third-party breaches. Zero liability for a third-party breach depends on reporting within the specified period, while sharing credentials can change who bears the loss. Ask for the bank's written investigation and calculation. If unresolved, check the current RBI Ombudsman process and deadlines. Do not assume that reporting cybercrime by itself also counts as notifying your bank.

Cyber & Online Fraud

I lost money to an online scam. What do I do in the first hour?

Call 1930 and notify your bank immediately, then complete the complaint on cybercrime.gov.in. Give the transaction number, amount, time and receiving account or UPI ID. Prompt reporting can help the authorities try to stop further movement of the money, but it does not guarantee recovery. Save the messages and payment records, and secure any account the scammer accessed. Ask the bank for a complaint number and written response about your disputed transaction.

Cyber & Online Fraud

I called 1930 but the money has already left the account it went to. Can I still recover it?

Keep pursuing the complaint even if the first receiving account is empty. Give the investigating officer and your bank every transaction reference so they can examine the onward trail. Separately, ask your bank to assess liability under the RBI rules for unauthorised transactions. Those rules do not promise reimbursement for every scam payment, especially a transfer you authorised yourself. Save the acknowledgement and follow up in writing. A failed initial hold is not the same as a completed investigation.

Cyber & Online Fraud

My money went into a mule account. Can the bank that holds that account be made to refund it?

A receiving account being used by scammers does not, by itself, establish that its bank must reimburse you. Report the transfer immediately through 1930 and your own bank, and provide the receiving account details to investigators. Ask for preservation of the transaction trail and action on any funds still available. Your own bank's liability for an unauthorised debit is a separate question under RBI rules. Recovery from a recipient or bank needs a basis supported by the evidence.

Cyber & Online Fraud

Someone is harassing and threatening me online. What can I actually do?

Save the full messages, account details and dates, then report the account to the platform and the conduct to the cybercrime portal or police. Threats intended to cause alarm can amount to criminal intimidation under Section 351 BNS. Not every rude message meets that test. Explain the pattern and quote the threats accurately. If you face immediate danger, seek urgent police help. Blocking the account can protect you, but keep an evidence copy first if safe.

S Jain & Attorneys · Ask Me

Still not the question you had in mind?

Search the column, or send your question in. Questions of general interest are answered here, anonymously, so the next person does not have to ask.