UPI has made everyday payments in India fast, simple and available at any hour. But that same convenience has opened the door to a growing wave of fraud — fake customer-care calls, phishing links, bogus QR codes, "collect request" scams, remote-access apps, SIM-swap attacks and straightforward impersonation.
When money disappears from an account through a fraudulent UPI transaction, the question that follows is rarely simple: who actually bears the loss — the customer, the bank, the payment app, or the fraudster?
There is no single answer. It depends on whether the transaction was genuinely unauthorised, whether the customer did anything negligent, and — critically — how fast the fraud was reported.
This article is written for general awareness and educational purposes only. It is not legal advice. Every dispute turns on its own facts, the bank's specific terms, RBI directions, available evidence and how a court or ombudsman ultimately reads the situation.
UPI fraud isn't one single thing — it covers a range of scenarios, including:
A transaction the account holder never authorised or even knew about
A fraudster tricking someone into revealing their UPI PIN, OTP or banking password
A fake "collect request" that the victim mistakenly accepts
A QR-code scam where scanning is falsely presented as a way to receive money
Screen-sharing or remote-access apps installed at a scammer's request
A spoofed customer-care number or phishing link
A SIM-swap or compromised device
A failure that originates from the bank's or the payment system's own security
The line that matters most legally is the difference between a transaction the customer never approved, and one the customer did approve — but only because they were deceived. That distinction shapes almost everything that follows.
The Reserve Bank of India's 2017 framework on limiting customer liability in unauthorised electronic banking transactions is the backbone of nearly every UPI fraud dispute. It sets out when a customer owes nothing, when liability is capped, and when the customer may end up bearing the loss.
One feature of the framework matters more than almost any other: the burden of proving customer liability sits with the bank, not the customer. A bank cannot simply assume a customer was careless just because a PIN or OTP was used — it has to establish that.
1. The bank was negligent or at fault. If the unauthorised transaction happened because of the bank's own negligence, deficiency, or contributory fraud, the customer owes nothing — and this applies regardless of how quickly the customer reported it.
2. A third party was at fault, and the customer reported fast. Sometimes neither the bank nor the customer is to blame — the failure sits somewhere else in the system. In these cases, the customer can still have zero liability, provided the fraud is reported within three working days of receiving the bank's notification of the transaction.
This is why speed matters so much: the three-day window is one of the strongest protections a customer has.
If the report falls in this window (for a third-party breach where the customer isn't at fault), liability isn't zero, but it's capped — limited to either the transaction amount or a fixed ceiling, whichever is lower. The commonly cited caps, depending on account type, are:
Account type Liability cap
Basic savings accounts ₹5,000
Accounts with daily transaction limits up to ₹25,000 ₹10,000
Accounts with higher transaction limits ₹25,000
At that point, the RBI framework hands the decision over to the bank's own Board-approved policy. There's no fixed protection anymore — which is exactly why customers shouldn't sit on a suspicious transaction while they try to figure out what happened. Report first, investigate afterward.
This is where most real disputes get complicated.
Picture a common scam: someone calls pretending to be from the bank, and convinces the victim to share a UPI PIN or OTP. That information is then used to drain the account.
Under the RBI framework, if the loss happened because of the customer's own negligence — such as sharing credentials — the customer bears the loss up until the moment they report it. Anything that happens after the report is generally the bank's responsibility.
But "the customer shared a PIN" doesn't automatically settle the matter. What actually gets examined includes:
What exactly was disclosed, and how
Whether the customer genuinely authorised the payment, or was manipulated into it
How quickly the fraud was discovered and reported
Whether the bank had adequate warnings and fraud controls in place
Whether the transaction looked unusual compared to the customer's normal activity
Whether the bank acted appropriately once notified
Whether further unauthorised transactions were allowed to go through after the report
In other words, calling something a "UPI scam" doesn't by itself decide who pays. The specific facts do.
No — this is a common misconception. Because UPI sits inside a regulated digital payment system, people often assume the bank must reimburse every fraudulent transaction. That isn't the legal position.
The RBI's framework distinguishes between categories of unauthorised transactions, and a customer's own conduct — plus how quickly they reported the issue — can materially affect the outcome.
That said, banks aren't off the hook either. Under RBI's Digital Payment Security Controls framework, regulated entities are required to maintain fraud-risk management systems and customer-protection mechanisms. A bank can't simply reject a complaint without properly investigating the circumstances.
Not directly. The National Payments Corporation of India (NPCI) operates the UPI network, but it isn't the entity that resolves fraud claims. NPCI's own complaint process routes fraud-related and unauthorised-transaction complaints to the customer's respective bank for resolution — the bank is the one responsible for investigating and deciding the outcome.
So a UPI fraud complaint should generally start with the bank, not the payment app or NPCI.
It's tempting to assume the app is responsible simply because the transaction happened inside it. In reality, a single UPI transaction can involve several different parties:
The customer's bank
The recipient's bank
The UPI app or payment service provider
NPCI, as the network operator
The merchant or recipient
Telecom or device infrastructure providers
The fraudster
Where the fault actually lies depends on what went wrong — a security failure, a technical glitch, a mistaken transfer, or a deceived customer are all treated differently. The app's customer support acknowledging a complaint is not the same as a legal determination of liability; that responsibility runs through the bank.
This is the toughest category of all. Imagine a fraudster says: "I'm sending you ₹20,000 — just enter your PIN to receive it." The victim complies and unknowingly authorises a payment to the fraudster.
Technically, the transaction was authenticated with the customer's own credentials. But that doesn't end the analysis — the circumstances surrounding it still matter, including whether the transaction should be treated as "unauthorised" in substance, and whether the customer's conduct amounted to negligence.
This is why victims should give the bank a detailed, honest account of exactly what happened, rather than describing it vaguely as "a payment I made by mistake." Useful evidence includes:
Call records and phone numbers used by the fraudster
SMS and app alerts
Screenshots of the interaction
WhatsApp or other chat messages
Transaction IDs / UPI reference numbers (UTR)
Bank statements
Recipient account details
Any complaint reference numbers
Separately from the bank dispute, the fraudster themselves may be pursued under India's criminal and cyber laws for offences such as cheating, impersonation, identity theft, unauthorised computer access, or operating through mule accounts. Criminal proceedings run on their own track — even if the police identify and charge the fraudster, that doesn't guarantee the victim recovers their money, and a delay in catching the fraudster doesn't prevent the customer from pursuing a claim against the bank.
1. Report to the bank right away. Use the bank's official fraud-reporting channel — RBI requires banks to provide round-the-clock reporting mechanisms and to act to prevent further unauthorised transactions once notified.
2. Call the national cybercrime helpline (1930) or use the cybercrime portal. Fast reporting can help authorities freeze funds before they move further down a chain of accounts.
3. Preserve every piece of evidence. Don't delete anything — messages, call logs, screenshots, alerts, transaction IDs.
4. Raise a complaint with the UPI app too, but treat this as supplementary — NPCI directs fraud complaints back to the bank for actual resolution.
5. Secure your accounts. Change passwords, block compromised cards, and contact your telecom provider if a SIM-swap is suspected.
6. File a police/cybercrime complaint, citing the bank complaint number and full transaction details.
7. Escalate within the bank if the response is inadequate. Ask for a written explanation, not just a verbal rejection.
If the bank doesn't resolve the complaint satisfactorily, or doesn't respond within 30 days, the customer can escalate to the RBI's Integrated Ombudsman Scheme — a free grievance-redressal mechanism for deficiencies in service by regulated entities. Complaints can be filed through RBI's Complaint Management System (cms.rbi.org.in). This route is a second step, not a first one — the bank has to be approached first.
This mechanism is particularly useful where:
The bank rejected the claim without proper investigation
The bank wrongly attributed negligence to the customer
The bank missed its own grievance-handling timelines
There was no adequate or timely response at all
Under the framework, a bank must resolve the complaint and determine any customer liability within the period set out in its own Board-approved policy — but that period cannot exceed 90 days from the complaint being received. If the bank fails to resolve it or determine liability within that window, the applicable compensation must be paid to the customer regardless.
For cases that qualify for zero or limited liability, banks are also expected to credit ("shadow reverse") the disputed amount to the customer's account within 10 working days of notification — without waiting for any insurance claim to be settled first.
Suppose ₹40,000 is debited from an account through a UPI transaction the customer never made. The customer notices it immediately and reports it the same day, to both the bank and the 1930 helpline.
If a system-level security failure caused it, and the customer shared no credentials → the customer can likely claim zero liability.
If the bank's own security lapse contributed → zero liability again, regardless of reporting speed.
If the customer had voluntarily entered their PIN after being deceived → the bank will examine whether that amounts to negligence.
If the customer had instead waited several days before reporting → the strongest protections (the 3-day zero-liability window) may no longer apply.
The result isn't decided just because "UPI was involved." It comes down to what happened, and how quickly it was reported.
The customer is not automatically liable for UPI fraud — nor is the bank automatically responsible for every loss.
Bank negligence, or a third-party breach reported within three working days, can mean zero liability for the customer.
Reporting within 4–7 working days (for qualifying third-party breaches) caps liability at a fixed amount.
Reporting after 7 working days leaves the outcome to the bank's own policy.
Sharing a UPI PIN, OTP or password is treated as negligence — liability rests with the customer until they report it; losses after that point generally shift to the bank.
The burden of proof for customer liability lies with the bank, not the other way around.
NPCI's complaint system exists, but fraud complaints are routed to — and resolved by — the customer's bank.
If the bank's response is unsatisfactory or absent, the RBI Integrated Ombudsman Scheme is the next avenue.
Above all: never share your UPI PIN, OTP or password with anyone — including someone claiming to be from your bank, the police, or a government office.
Speed, documentation and an accurate account of events are usually what decide these disputes — far more than the label "UPI fraud" itself. Where a bank has rejected a substantial claim or attributed negligence to a customer without adequate justification, seeking professional legal advice is generally worthwhile.