A UPI debit you did not make and could not have prevented is an unauthorised transaction in the strict sense, and the Reserve Bank's circular of 6 July 2017 was written for exactly this. For a third-party breach where neither the bank nor customer is at fault, reporting within three working days of receiving the bank's communication gives zero customer liability. Bank negligence or deficiency causing the unauthorised transaction also attracts zero liability, regardless of reporting time. Customer negligence has different consequences. The bank has to prove otherwise. What decides the case is the written record of when you reported and what the bank can show about how the debit got through.
Which limb of the RBI circular am I in?
Third-party breach is defined in the 2017 circular as a case where "the deficiency lies neither with the bank nor with the customer but lies elsewhere in the system". A SIM swap, malware, a merchant or app breach, or a data leak may fall within this category if the deficiency lies with neither the bank nor the customer. The mechanism alone does not decide negligence. In this limb your liability turns on how fast you reported, counted in working days of your home branch from the bank's alert, excluding the day of the alert. Where the loss flows from the bank's own negligence or deficiency, liability is zero whether or not you reported.
| Time taken to report after the bank's alert | Your liability |
|---|---|
| Within three working days | Zero |
| Four to seven working days | The transaction value or the cap for your account type, whichever is lower: Rs 5,000 for a basic savings account, Rs 10,000 for other savings accounts, prepaid instruments, MSME current accounts, individual current accounts with balance or limit up to Rs 25 lakh and credit cards with limit up to Rs 5 lakh, Rs 25,000 for other current accounts and higher-limit cards |
| Beyond seven working days | As per the bank's board-approved policy, which it must give you at account opening |
| Any time, where the bank itself was negligent or deficient | Zero |
The Reserve Bank's amended directions of 24 June 2026, which apply to transactions on or after 1 January 2027, spell the third-party limb out to include deficiency on the part of a third-party application provider, a payment aggregator, a payment gateway or a telecom service provider, which is to say the UPI app and the phone company by name, and move the zero-liability window to five calendar days. They also define bank negligence to include not sending mandatory alerts and not acting diligently on a customer's report. For a transaction today the 2017 bands apply, but the 2026 text is a useful statement of what the regulator has always treated as outside the customer's control.
What if my SIM was swapped or my phone was compromised?
Then the bank's argument that "the OTP went to your registered number" proves nothing, because the number was in someone else's hands. The Bombay High Court dealt with this on 6 April 2026 in Subodh C. Korde v Union of India, Writ Petition 11990 of 2023. The customer's BSNL SIM had been replaced on a false loss report, beneficiaries were added and Rs 38,04,000 moved out of his HDFC accounts through logins from a Chennai IP that did not match his genuine transactions from Pune. The bank said it had sent alerts and OTPs. It could not place a single original delivery log before the court, and its own investigation report showed the transactions were "not alerted" because of a risk score. The court held that the burden of proving customer negligence under paragraph 12 lay on the bank and had not been discharged, that the customer had shared nothing and reported promptly, that the zero-liability limb was triggered, and it directed the bank to remit the amount with interest within eight weeks.
The lesson is procedural. Write to your telecom operator the same day asking for the date, time and outlet of any SIM replacement on your number and the identity documents produced, and use the Sanchar Saathi portal to check the mobile connections in your name and to report the fraud communication through Chakshu. A sudden loss of signal before the debits is itself evidence, so note the time it happened.
What do I do in the first three days?
- Call 1930 and file the financial fraud complaint on cybercrime.gov.in with the UPI transaction IDs, the receiving VPA or account, the amounts and times. Keep the acknowledgement number.
- Report to the bank in writing, by email and through the app, within the same day, and ask it to block UPI on the account, register the dispute and send a hold request to the beneficiary bank. Paragraph 5 of the circular requires the bank to acknowledge immediately with a complaint number and to record the time.
- Raise the dispute inside the UPI app as well, against each transaction, and keep the ticket numbers.
- Ask the bank in writing for the shadow credit of the disputed amount within ten working days under paragraph 9, value-dated to the date of the debit.
- Ask for the transaction logs, the device ID and IP recorded against each debit, and the alert delivery log, citing paragraph 12.
- Keep the phone unwiped, and if it was compromised, keep the app or link that did it. Electronic evidence needs a certificate under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, and the device is the source.
What if the bank still refuses?
Insist on the refusal in writing with reasons, because paragraph 10 requires the complaint to be resolved and any customer liability established within ninety days, failing which the compensation is paid anyway. Then the Reserve Bank Integrated Ombudsman Scheme, 2026, free, online at cms.rbi.org.in, after thirty days without a satisfactory reply and within ninety days after that, with compensation up to Rs 30 lakh for consequential loss and Rs 3 lakh for harassment, and no bar from a pending FIR. A consumer complaint for deficiency in service under the Consumer Protection Act, 2019 runs in parallel, and a claim against the entity whose system was breached can go to the adjudicating officer under Section 46 of the Information Technology Act, 2000 relying on Section 43 for unauthorised access. On the criminal side the fraudster committed identity theft under Section 66C of the IT Act, which covers dishonest use of another person's password or unique identification feature, cheating by personation under Section 66D, and cheating under Section 318(4) of the Bharatiya Nyaya Sanhita, 2023.
Our guide on UPI and bank fraud recovery under the RBI rules lays out each band, and the answer on a bank refusing to refund deals with the escalation letters.
The one fact that wins these cases
Time of report. Everything in the circular is counted from the bank's alert to your notice, and a phone call with no ticket number is, in evidence, a call that never happened. Send the email the same hour, even a three-line one, keep the sent copy, and do not close the account, because the alert history and the statement are your proof. If you did share an OTP under pressure, the analysis changes, and the sibling answer on the shared-OTP defence is the one to read.