UPI Fraud in India: Can You Get Your Money Back? Legal and RBI Remedies Explained

  • Post category:Blog
  • Reading time:27 mins read

Introduction

UPI has made digital payments almost effortless.

A person can transfer money within seconds using:

  • a mobile number;
  • UPI ID;
  • QR code;
  • bank account;
  • payment app; or
  • linked wallet.

That convenience has also created opportunities for fraud.

Victims are routinely targeted through:

  • fake customer-care numbers;
  • phishing links;
  • screen-sharing applications;
  • QR-code scams;
  • fake refund requests;
  • collect-request fraud;
  • investment scams;
  • impersonation;
  • digital-arrest scams;
  • remote-access applications;
  • SIM-related fraud; and
  • compromised banking credentials.

When money disappears from a bank account, the first question is usually:

Can I get my money back?

The answer depends heavily on what actually happened.

Under Reserve Bank of India rules, customers can receive zero or limited liability in certain unauthorised electronic banking transactions, particularly where the bank was at fault or where the fraud resulted from a third-party breach and the customer reported it promptly.

But if the customer personally entered the UPI PIN and authorised the transfer after being deceived by a fraudster, the legal position can be more difficult.

That does not mean the victim has no remedy.

Immediate reporting through the bank, the 1930 cyber-fraud helpline, the National Cyber Crime Reporting Portal and the financial-fraud freezing system may still help trace or freeze the funds. As of 30 June 2026, the Government reported that the national cyber-fraud management system had helped prevent more than ₹11,158 crore from being siphoned away across more than 32.80 lakh complaints.

This article explains when a UPI fraud victim may be entitled to a refund, when a bank can refuse liability, why quick reporting matters, how the RBI’s customer-protection rules work, and what legal remedies remain available if the bank does not resolve the complaint.

What Is UPI Fraud?

UPI fraud is a broad expression.

Legally, different kinds of fraud may require different treatment.

For example:

Unauthorised transaction

Money is transferred without the customer’s knowledge or approval.

Examples may include:

  • compromised credentials;
  • account takeover;
  • device compromise;
  • SIM-related attack;
  • system breach; or
  • fraudulent access to the customer’s banking account.

Fraudulently induced transaction

The customer technically authorises the payment but does so because a fraudster deceived or coerced them.

Examples include:

  • fake investment scheme;
  • digital-arrest scam;
  • fake customer-care executive;
  • fake police officer;
  • QR-code scam;
  • fraudulent merchant;
  • fake refund;
  • remote-access scam.

This distinction can become crucial when determining whether RBI’s automatic or limited-liability framework applies.

Why the Difference Between “Unauthorised” and “Authorised Under Deception” Matters

Suppose ₹50,000 leaves your account while you are sleeping.

You never initiated the transaction.

That is a classic unauthorised transaction.

Now consider a different situation.

A fraudster calls and says:

“Your bank account will be blocked. Transfer ₹50,000 to this verification account.”

You become frightened, open your UPI app, enter the beneficiary details, enter your UPI PIN and approve the transfer.

You were cheated.

But technically, you may have personally authorised the payment instruction.

This distinction often determines how banks apply the RBI customer-liability framework.

The RBI’s principal circular concerns unauthorised electronic banking transactions.

Therefore, one should not automatically assume that every cyber-fraud loss must be refunded by the bank.

RBI’s Zero-Liability Rule

RBI’s customer-protection framework provides for zero liability in certain circumstances.

A customer is entitled to zero liability where the unauthorised transaction results from:

  1. fraud, negligence or deficiency on the part of the bank, irrespective of whether the customer reports the transaction immediately; or
  2. a third-party breach where the deficiency lies neither with the bank nor the customer, provided the customer reports the unauthorised transaction to the bank within three working days of receiving communication about it.

This is one of the most important consumer protections in digital banking.

Example of Zero Liability

Suppose a customer’s bank account is compromised because of a security failure outside the customer’s control.

₹1 lakh is transferred without authorisation.

The customer receives an SMS alert and reports the transaction to the bank the same day.

If the case falls within the RBI third-party-breach category and there was no customer negligence, the customer may be entitled to zero liability.

What If You Report After Three Days?

Where responsibility lies neither with the bank nor with the customer, but the customer reports the unauthorised transaction after a delay of four to seven working days, the customer’s liability is limited.

RBI prescribes caps depending on the type of account.

The customer is liable only for the lower of:

  • the transaction value; or
  • the applicable RBI liability ceiling.

If the customer reports beyond seven working days, liability is generally determined according to the bank’s Board-approved customer-protection policy.

The practical lesson is simple:

Reporting speed can directly affect financial liability.

What If the Bank Was Negligent?

Where the unauthorised transaction occurred because of:

  • bank fraud;
  • bank negligence; or
  • deficiency in banking systems,

RBI places the loss on the bank.

The customer’s zero-liability protection applies irrespective of whether the customer immediately reported the transaction.

However, establishing that the bank was responsible may require examination of:

  • transaction logs;
  • authentication records;
  • security controls;
  • login history;
  • device information;
  • alerts;
  • and system failures.

What If the Customer Shared Their Credentials?

RBI’s framework is less favourable where the loss resulted from customer negligence.

The circular gives the example of a customer sharing payment credentials.

In such circumstances, the customer bears the loss until the unauthorised transaction is reported to the bank.

Any further unauthorised loss occurring after the bank is notified should be borne by the bank.

This means that sharing:

  • OTP;
  • password;
  • PIN;
  • card details;
  • login credentials; or
  • other authentication information

can significantly affect refund entitlement.

Does Entering Your UPI PIN Mean You Can Never Get the Money Back?

No.

But it makes the case more complicated.

If you personally approved the payment using your UPI PIN, the bank may argue that the transaction was authorised and therefore does not fall within the classic RBI “unauthorised transaction” framework.

However, that does not mean:

  • the fraud becomes lawful;
  • police cannot investigate;
  • recipient accounts cannot be frozen;
  • funds cannot potentially be restored;
  • or the bank can ignore its own negligence.

The case then becomes more dependent on:

  • cybercrime recovery mechanisms;
  • tracing the beneficiary account;
  • freezing funds quickly;
  • bank-side conduct;
  • transaction monitoring;
  • fraud-detection failures;
  • and the exact manner in which the payment was authorised.

QR Code Scams: Does Scanning a QR Code Make You Receive Money?

No.

This is one of the most common fraud techniques.

A fraudster may tell a victim:

“Scan this QR code to receive your refund.”

The victim scans the code.

The application then asks for a UPI PIN.

The victim enters it.

Instead of receiving money, money leaves the account.

A basic UPI safety principle is:

You normally enter your UPI PIN to authorise a debit/payment—not merely to receive money.

Victims should be extremely suspicious when asked to enter a UPI PIN in order to “receive” a payment.

Collect Request Fraud

Another common method involves a fraudulent UPI collect request.

The victim receives a request that may appear to say:

  • refund;
  • cashback;
  • prize;
  • payment verification; or
  • account activation.

The user approves the request and enters the UPI PIN.

That action authorises payment from the victim’s account.

Before approving a collect request, consumers should check:

  • payee name;
  • UPI ID;
  • amount;
  • purpose;
  • and whether they actually owe the money.

Fake Customer-Care Fraud

Fraudsters frequently create fake customer-support listings online.

A victim searching for a bank, airline, marketplace or wallet customer-care number may unknowingly call a fraudster.

The fraudster may then ask the victim to:

  • install a remote-access application;
  • share their screen;
  • open banking apps;
  • approve a collect request;
  • or transfer a “verification amount.”

Victims should use customer-care numbers only from official websites or applications.

Screen-Sharing and Remote-Access Fraud

Remote-access applications can allow fraudsters to see or control a victim’s screen.

This can expose:

  • account balances;
  • OTPs;
  • UPI apps;
  • transaction information;
  • and other personal data.

If someone claiming to be a bank employee asks you to install a screen-sharing application, treat it as a major warning sign.

Digital Arrest and UPI Transfers

Digital-arrest scams frequently involve UPI or bank transfers.

Fraudsters impersonate:

  • police;
  • CBI officers;
  • ED officials;
  • customs authorities;
  • judges;
  • RBI officials; or
  • other government agencies.

Victims are told that they are under investigation and must transfer money to a so-called:

  • safe account;
  • verification account;
  • security account;
  • or government account.

There is no lawful concept under which police require citizens to transfer money to a “safe account” to avoid digital arrest.

The appropriate response is to end the call and report the fraud immediately.

What Should You Do Immediately After UPI Fraud?

Speed is extremely important.

The recommended practical sequence is:

Bank → 1930 → National Cyber Crime Reporting Portal → Police/Cyber Cell

These steps should ideally be taken immediately rather than waiting to see whether the fraudster responds.

Step 1: Contact Your Bank Immediately

Inform the bank that the transaction is fraudulent or unauthorised.

Ask the bank to:

  • block further UPI transactions where necessary;
  • secure the account;
  • register a formal complaint;
  • provide a complaint/reference number;
  • flag the transaction as disputed;
  • and initiate the appropriate fraud-handling process.

Banks are required to provide customers with channels for promptly reporting unauthorised transactions. RBI also requires banks to take immediate steps to prevent further unauthorised transactions once the customer reports the incident.

Step 2: Call 1930

For financial cyber fraud, call:

1930

immediately.

The National Cyber Crime Reporting Portal currently directs victims of cyber-financial fraud to call 1930 for immediate reporting.

The purpose is not merely to create a complaint record.

Rapid reporting can allow participating financial institutions and law-enforcement systems to attempt to trace and stop the flow of money.

Why 1930 Can Be So Important

Cybercriminals often move stolen funds quickly through multiple accounts.

A transfer may go through:

  1. the victim’s account;
  2. first-layer mule account;
  3. second-layer mule account;
  4. wallet;
  5. another bank;
  6. cash withdrawal;
  7. cryptocurrency or another channel.

The longer the delay, the more difficult recovery can become.

The Government’s Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) was created to facilitate immediate reporting and help stop siphoning of funds. By 30 June 2026, the Government said the system had helped save more than ₹11,158 crore across more than 32.80 lakh complaints.

Step 3: File a Complaint on the National Cyber Crime Reporting Portal

The official portal is the Government of India’s National Cyber Crime Reporting Portal.

Financial-fraud victims should complete the complaint and preserve the acknowledgement/reference details.

The portal allows cybercrime complaints to be reported and tracked.

The complaint should include as much information as possible, such as:

  • transaction ID;
  • UPI reference number;
  • amount;
  • date and time;
  • fraudster’s UPI ID;
  • bank details;
  • phone numbers;
  • WhatsApp messages;
  • screenshots;
  • QR code;
  • website link;
  • email;
  • account statement;
  • and complaint reference from the bank.

Step 4: Approach the Police or Cyber Crime Police Station

For serious financial fraud, victims should also approach:

  • local police;
  • cybercrime police station;
  • or the relevant State cybercrime unit.

Provide the cybercrime complaint reference and all documentary evidence.

Depending on the facts, criminal offences may arise relating to:

  • cheating;
  • personation;
  • identity theft;
  • criminal intimidation;
  • forgery;
  • and offences involving computer resources.

Can the Police Freeze the Fraudster’s Bank Account?

Potentially, yes.

If funds can be traced and remain in recipient or intermediary accounts, law enforcement and financial institutions may take steps to place a hold or lien on the suspected proceeds in accordance with legal procedure.

This is one reason immediate reporting matters so much.

The Government’s July 2026 update states that the new SOP for CFCFRMS includes procedures concerning:

  • complaint processing;
  • bank coordination;
  • grievance redressal;
  • removal of lien markings; and
  • restoration of defrauded funds to rightful claimants.

Does Freezing the Account Mean You Automatically Get the Money Back?

No.

A freeze and a refund are not the same thing.

Freezing prevents funds from being moved.

Restoration may require additional procedural steps, depending on:

  • investigation;
  • ownership of funds;
  • competing claims;
  • police action;
  • court orders;
  • applicable SOPs;
  • and the bank’s role.

Victims should therefore continue following up even after being told that the amount has been “put on hold.”

What Is a Mule Account?

A mule account is a bank account used to receive or transfer proceeds of fraud.

Sometimes the account holder knowingly participates.

In other cases, a person may allow another individual to use the account without fully understanding the purpose.

UPI fraud proceeds frequently move through multiple mule accounts to make tracing more difficult.

This is why money should never be received or transferred on behalf of unknown people merely in exchange for commission.

Can NPCI Refund the Money?

NPCI operates the UPI payment system, but fraudulent or unauthorised transaction complaints are generally required to be raised with the customer’s bank for redressal.

NPCI’s complaint page itself specifically states that complaints relating to fraudulent, unidentified or unauthorised transactions should be raised with the customer’s respective bank.

NPCI can facilitate transaction-status and complaint routing in certain payment-system situations, but the customer’s bank remains a key point of redress for fraud disputes.

What If the UPI Transaction Failed but Money Was Debited?

This is different from fraud.

Sometimes a UPI transaction fails technically but the amount is debited.

Such cases ordinarily fall under transaction-failure and reversal rules rather than cyber-fraud law.

The customer should raise the dispute through:

  • the UPI app;
  • bank;
  • or NPCI complaint system.

The transaction reference number or RRN should be preserved.

What If Money Was Sent to the Wrong UPI ID?

This is also different from fraud.

If you voluntarily transferred money to the wrong person because of a typing or selection mistake, the transaction may have been validly authorised.

The bank may attempt to contact the beneficiary bank or account holder, but automatic reversal cannot always be guaranteed.

Consumers should carefully verify:

  • recipient name;
  • UPI ID;
  • amount;
  • and bank confirmation screen

before entering the UPI PIN.

RBI Rules on Reversal of Unauthorised Transactions

Where the RBI zero- or limited-liability rules apply, the bank must make a shadow reversal of the disputed amount within the prescribed period rather than waiting indefinitely for insurance or final investigation.

The RBI circular requires the bank to credit the amount involved in the unauthorised transaction within 10 working days from the customer’s notification, subject to the liability framework and other conditions.

The credit must be value-dated to the date of the unauthorised transaction.

This protection is especially important because victims should not have to remain without funds for months merely while the bank investigates.

Who Has the Burden of Proving Customer Liability?

RBI places the burden on the bank.

In unauthorised electronic banking transactions, the burden of proving customer liability lies on the bank.

This is a significant consumer-protection rule.

A bank should not simply respond:

“The transaction was done using your account, therefore you are liable.”

If the customer disputes authorisation, the bank may need to establish the facts that legally make the customer responsible.

What Evidence Can a Bank Examine?

The bank may examine:

  • UPI authentication logs;
  • device binding;
  • transaction timestamps;
  • IP or network records;
  • login history;
  • OTP records;
  • UPI PIN authentication;
  • beneficiary details;
  • app information;
  • fraud alerts;
  • customer communications;
  • and complaint timing.

These records can become important if the matter later reaches the Ombudsman or court.

What If the Bank Rejects Your Complaint?

Do not stop at a customer-care response.

Ask the bank for:

  • written reason for rejection;
  • transaction authentication details;
  • complaint closure report;
  • internal grievance escalation mechanism;
  • nodal officer details;
  • and the bank’s Board-approved customer-liability policy.

RBI requires banks to maintain and publicly disclose customer-protection and grievance-handling policies concerning unauthorised electronic transactions.

RBI Ombudsman Remedy

If the bank does not resolve the complaint satisfactorily, a consumer may be able to approach the RBI Ombudsman.

The Reserve Bank – Integrated Ombudsman Scheme, 2026 came into force on 1 July 2026, replacing the earlier 2021 scheme for new complaints.

It provides a cost-free, non-adversarial grievance-redress mechanism for complaints involving deficiency in service by RBI-regulated entities covered by the Scheme.

A customer should ordinarily first complain to the bank or regulated entity before approaching the Ombudsman.

What Can the RBI Ombudsman Examine?

Depending on the complaint, the Ombudsman process may examine allegations concerning:

  • failure to follow RBI directions;
  • wrongful rejection of an unauthorised-transaction complaint;
  • unreasonable delay;
  • deficient grievance handling;
  • failure to reverse funds where RBI rules require reversal;
  • or other service deficiencies.

The Ombudsman does not function as a criminal court.

It addresses service-related complaints against regulated entities.

Cybercrime investigation should continue separately where necessary.

Can You Approach a Consumer Commission?

Potentially, yes.

Banking services fall within consumer-protection law in appropriate circumstances.

A victim may consider a consumer complaint where there is alleged:

  • deficiency in banking service;
  • failure to follow RBI directions;
  • negligent security;
  • wrongful refusal to reverse an unauthorised transaction;
  • or unreasonable grievance handling.

The appropriate forum and strength of the claim depend on the facts.

Can the Bank Say “You Used the UPI PIN, So Case Closed”?

Not necessarily.

Entering the UPI PIN is highly relevant, but it may not resolve every legal issue.

The bank must still consider:

  • whether the transaction was genuinely authorised;
  • whether credentials were compromised;
  • whether the system behaved properly;
  • whether fraud-monitoring systems raised alerts;
  • whether the bank complied with applicable RBI requirements;
  • and whether there was any bank-side deficiency.

However, where the victim knowingly entered the UPI PIN and intentionally instructed the bank to transfer money—although under deception—the bank may have a stronger defence under the RBI unauthorised-transaction framework.

That is why fraud recovery and bank liability must be analysed separately.

Example 1: Account Hacked Without Customer Involvement

₹75,000 is transferred from a customer’s account while the customer is asleep.

The customer never shared credentials.

They report the transaction within hours.

This is the type of case in which RBI zero-liability protection may become strongly relevant if the transaction resulted from a third-party breach and the customer was not negligent.

Example 2: Customer Shares UPI PIN

A victim tells a fraudster their UPI PIN.

The fraudster uses it to carry out unauthorised transactions.

RBI allows greater customer liability where the loss was caused by the customer’s negligence, such as sharing payment credentials, until the fraud is reported.

Example 3: Digital Arrest Scam

A fraudster impersonating a police officer convinces a victim to transfer ₹3 lakh to a “safe account.”

The victim personally authorises the transaction.

This is clearly fraud from a criminal-law perspective.

But automatic reimbursement under RBI’s unauthorised-transaction rules may be more difficult because the victim personally initiated the payment.

Immediate use of:

1930 + bank complaint + NCRP + police

becomes especially important.

Example 4: QR-Code Refund Scam

A seller tells the victim:

“Scan this QR code and enter your PIN to receive ₹10,000.”

The victim follows the instructions.

₹10,000 leaves the account.

The payment may appear technically authorised because the victim approved the debit.

The fraud should still be reported immediately, but bank-liability analysis may depend on the exact facts.

Example 5: Bank Security Failure

A systemic weakness at the bank allows attackers to access customer accounts without proper authentication.

If the loss resulted from bank negligence or deficiency, RBI’s zero-liability rule places the loss on the bank.

Can You Sue the Fraudster?

Yes, if the fraudster can be identified.

A victim may have criminal and civil remedies.

But in practice, online fraudsters frequently:

  • use fake identities;
  • route money through mule accounts;
  • operate from different States;
  • or operate internationally.

That is why rapid freezing of funds is often more important than merely obtaining a later judgment against an unknown fraudster.

Criminal Law Applicable to UPI Fraud

Depending on the facts, offences under the Bharatiya Nyaya Sanhita, 2023 may include provisions relating to:

  • cheating;
  • cheating by personation;
  • criminal intimidation;
  • forgery;
  • and conspiracy.

The Information Technology Act, 2000 may also be relevant.

For example:

Section 66C

Identity theft involving fraudulent use of another person’s:

  • electronic signature;
  • password; or
  • unique identification feature.

Section 66D

Cheating by personation using a communication device or computer resource.

These provisions are frequently relevant to online impersonation and financial scams.

Should You File an FIR?

Where substantial money has been lost through cyber fraud, filing or seeking registration of an appropriate police complaint/FIR may be necessary depending on the facts.

The NCRP complaint is extremely useful, but it should not automatically be assumed to replace all criminal-procedure requirements in serious cases.

Victims should preserve the NCRP acknowledgement and provide it to police.

What Evidence Should You Preserve?

Do not delete anything.

Preserve:

  • bank statement;
  • transaction ID;
  • UPI reference number;
  • beneficiary UPI ID;
  • beneficiary name shown by the app;
  • QR code;
  • screenshots;
  • chat history;
  • WhatsApp number;
  • SMS messages;
  • email;
  • website URL;
  • call logs;
  • call recording where lawfully available;
  • advertisement;
  • fake identity documents;
  • bank complaint number;
  • 1930 acknowledgement;
  • NCRP reference;
  • and police complaint.

If the fraud involved a remote-access application, preserve the name of that application as well.

Should You Block Your Bank Account?

You do not necessarily need to close the entire account in every case.

But if credentials may have been compromised, immediately ask the bank to:

  • block UPI access;
  • reset credentials;
  • disable compromised devices;
  • change passwords;
  • block cards where necessary;
  • and secure mobile banking.

The goal is to stop the second transaction before it occurs.

Change Your UPI PIN

If there is any chance that your UPI credentials were exposed, change the UPI PIN immediately through the official banking or UPI application.

Do not follow links sent by unknown persons.

Can a Fraudster Withdraw Money Merely by Knowing Your UPI ID?

Normally, knowing a UPI ID alone should not allow a person to debit your account.

A UPI ID is designed to facilitate identification of a payment address.

The danger arises when the fraudster also obtains or manipulates:

  • UPI PIN;
  • device access;
  • OTP;
  • authentication;
  • SIM control;
  • remote screen access;
  • or approval of a collect request.

Consumers should not panic merely because someone knows their UPI ID.

But they should never share authentication credentials.

Do Banks Ever Ask for UPI PIN?

A legitimate bank employee should not need your UPI PIN to resolve a complaint.

UPI PINs should never be shared with:

  • customer-care agents;
  • police officers;
  • RBI representatives;
  • merchants;
  • courier companies;
  • or strangers.

A request for your PIN is a strong fraud warning.

Can the RBI Call You and Ask You to Transfer Money?

No legitimate RBI process requires a consumer to transfer money to a so-called verification or safe account to resolve fraud.

Fraudsters often misuse the names of:

  • RBI;
  • police;
  • CBI;
  • ED;
  • customs;
  • TRAI;
  • and banks.

Consumers should independently verify any such communication through official channels.

How Fast Should You Report?

Immediately.

Do not wait:

  • until tomorrow;
  • for the merchant to reply;
  • for the fraudster to promise a refund;
  • or for a family member to return home.

RBI’s liability framework itself makes reporting time highly relevant.

The cybercrime freezing system is also most effective while funds remain traceable within banking channels.

What If the Fraud Happened at Night?

The 1930 financial-cyber-fraud helpline is presented by the National Cyber Crime Reporting Portal as an immediate reporting channel, and the portal states that it operates 24×7 for financial cyber-fraud reporting.

Banks also maintain emergency fraud-reporting channels.

Use them immediately.

Bank Complaint vs Cybercrime Complaint

They serve different purposes.

Bank complaint

Focuses on:

  • disputed transaction;
  • account security;
  • customer liability;
  • reversal;
  • banking grievance; and
  • RBI compliance.

Cybercrime complaint

Focuses on:

  • identifying offenders;
  • tracing funds;
  • freezing beneficiary accounts;
  • investigating cheating or personation;
  • and criminal prosecution.

For many UPI fraud cases, both are necessary.

What If the Bank Says the Complaint Must Be Filed Through the UPI App?

You can use the UPI app’s dispute mechanism, but fraudulent or unauthorised transactions should also be reported directly to the bank.

NPCI itself directs complaints concerning fraudulent, unidentified or unauthorised transactions to the customer’s bank.

Do not rely solely on an in-app chatbot when substantial money has been lost.

Does the RBI Guarantee Refund of Every UPI Fraud?

No.

This is a major misconception.

RBI does not guarantee reimbursement of every fraud loss.

Refund entitlement depends on factors including:

  • whether the transaction was authorised;
  • whether the customer was negligent;
  • whether the bank was negligent;
  • whether a third-party breach occurred;
  • how quickly the customer reported it;
  • and the bank’s applicable policy.

For induced transfers personally authorised by the victim, recovery may depend heavily on tracing and freezing the money rather than automatic bank reimbursement.

Can the Bank Voluntarily Refund Even Where Customer Negligence Occurred?

Yes.

RBI’s framework permits banks, at their discretion, to waive customer liability even in cases involving customer negligence.

This does not create an automatic right, but it means banks may adopt more customer-friendly policies.

Common Myths About UPI Fraud

Myth 1: “Every UPI fraud must be refunded by the bank.”

Incorrect.

Bank liability depends on whether the transaction was unauthorised, responsibility for the breach and reporting time.

Myth 2: “If I entered the UPI PIN, nothing can be done.”

Incorrect.

Cybercrime recovery may still be possible, especially if the money is reported quickly and can be frozen.

Myth 3: “1930 only registers a complaint.”

Incomplete.

The financial cyber-fraud reporting system is also designed to facilitate coordination aimed at stopping movement of fraudulent funds. The Government reported more than ₹11,158 crore saved through CFCFRMS by June 2026.

Myth 4: “NPCI will directly refund any fraudulent UPI payment.”

Incorrect.

NPCI directs fraudulent and unauthorised transaction complaints to the customer’s bank for redressal.

Myth 5: “You need to enter your UPI PIN to receive money.”

Incorrect.

A PIN authorises transactions from your side; requests to enter it merely to receive a refund or payment are a common fraud warning.

Myth 6: “If the bank rejects the complaint, the matter is over.”

Incorrect.

The customer can escalate through the bank’s grievance mechanism and, where applicable, approach the RBI Ombudsman and other legal forums.

Practical Recovery Checklist

If you discover a fraudulent UPI transaction:

  1. Call your bank immediately.
  2. Block or secure UPI access if credentials may be compromised.
  3. Call 1930 immediately.
  4. File the complaint on the National Cyber Crime Reporting Portal.
  5. Preserve the acknowledgement/reference number.
  6. Approach the cybercrime police/local police where appropriate.
  7. Preserve all screenshots, messages and transaction records.
  8. Do not delete the fraudster’s phone number or chat.
  9. Ask the bank for a formal written decision.
  10. Escalate to the bank’s nodal/grievance officer if unresolved.
  11. Consider the RBI Ombudsman where the complaint concerns deficiency in banking service.
  12. Act quickly if you are informed that money has been frozen.

Frequently Asked Questions

Can I get my money back after UPI fraud?

Possibly.

Recovery depends on whether the payment was unauthorised, how the fraud occurred, how quickly it was reported, whether funds can be frozen and whether RBI’s zero- or limited-liability rules apply.

What number should I call after UPI fraud?

Call 1930 immediately for financial cyber fraud.

Should I contact my bank first?

Contact the bank immediately as well.

The best approach is not to treat these remedies as alternatives. Report to the bank and 1930 without delay.

How many days do I have to report an unauthorised transaction?

For third-party breaches where neither the bank nor customer is at fault, RBI’s zero-liability protection applies when the customer reports within three working days of receiving communication about the transaction.

What if I report within four to seven working days?

Customer liability may be limited according to RBI’s prescribed caps and the amount involved.

Does the bank have to credit the money back immediately?

Where the RBI unauthorised-transaction framework applies, the bank must provide the required shadow reversal within the prescribed period, including the 10-working-day timeline under the applicable directions.

Who has to prove that I was negligent?

Under RBI’s framework, the burden of proving customer liability in an unauthorised electronic banking transaction lies on the bank.

Can I complain to NPCI?

NPCI provides payment-system complaint mechanisms, but fraudulent, unidentified or unauthorised transactions should be raised with the customer’s bank.

Can I approach RBI if the bank refuses refund?

Where the complaint falls within the scope of the Reserve Bank – Integrated Ombudsman Scheme, 2026, the customer may approach the RBI Ombudsman after first following the required complaint process with the regulated entity.

What if I personally transferred the money because of a scam call?

That is still fraud.

However, automatic bank reimbursement may be more difficult because the transfer may have been technically authorised by you.

Immediate cybercrime reporting becomes especially important.

Can money frozen in a mule account be returned?

Potentially.

The Government’s 2026 CFCFRMS SOP includes procedures concerning restoration of defrauded funds to rightful claimants, but a freeze itself does not automatically mean immediate refund.

The Most Important Distinction for Victims

Most UPI fraud disputes can be better understood by asking one question:

Who actually authorised the payment?

If the payment occurred without your knowledge, the RBI unauthorised-transaction framework can provide powerful protection.

If you knowingly entered the UPI PIN and approved the transfer because a fraudster deceived you, the payment may still be criminal fraud, but the refund analysis becomes more complicated.

That distinction is often misunderstood.

A victim can be completely innocent from a criminal-law perspective while still facing a difficult bank-reimbursement claim because the bank technically executed the exact payment instruction the victim entered.

That is why fraud prevention and immediate fund freezing are so important.

Conclusion

Can you get your money back after UPI fraud in India?

Sometimes—but there is no universal automatic refund rule.

Where an electronic transaction was genuinely unauthorised and the customer was not responsible for the breach, RBI’s customer-protection framework can provide strong relief.

A customer may have zero liability where:

  • the loss occurred because of bank negligence or deficiency; or
  • a third-party breach occurred without fault of the bank or customer and the customer reported the transaction within three working days.

Where reporting is delayed, limited customer liability may apply.

Where the loss resulted from customer negligence such as sharing payment credentials, the customer may bear losses until the fraud is reported.

The more difficult cases involve transactions that the victim personally authorised after being deceived.

A digital-arrest victim, for example, may intentionally transfer money because they believe they are complying with law enforcement.

That transaction is still the product of fraud.

But from a banking-system perspective it may appear to be an authorised UPI payment.

In such cases, the chances of recovery often depend heavily on speed.

The victim should immediately:

contact the bank → call 1930 → lodge the NCRP complaint → approach the police/cybercrime unit.

The importance of rapid reporting is demonstrated by the Government’s own data. Through the national CFCFRMS mechanism, more than ₹11,158 crore had reportedly been prevented from being siphoned away across more than 32.80 lakh complaints by 30 June 2026.

Where a bank wrongfully rejects an eligible unauthorised-transaction complaint, the customer can escalate internally and may use the Reserve Bank – Integrated Ombudsman Scheme, 2026, which has been in force since 1 July 2026.

The practical rule is therefore simple:

Do not wait after discovering UPI fraud. Every hour can matter.

Do not negotiate with the fraudster.

Do not wait for a promised refund.

Do not delete the chats.

And do not assume either that the bank must always refund you or that recovery is impossible.

UPI fraud involves two separate battles:

recovering the money from the fraud chain and determining who legally bears the loss between the customer and the bank.

Understanding that distinction is the key to using India’s cybercrime and RBI remedies effectively.

This article reflects the legal and regulatory position publicly available up to September 2026. Refund entitlement depends on the particular transaction, customer conduct, bank systems, reporting time and applicable RBI directions. This article is intended for general legal information and academic discussion and does not constitute legal advice.