UPI Fraud: What to Do in the First 30 Minutes
Speed matters in an unauthorised UPI transaction because funds can move through several accounts quickly. The first objective is containment and traceability: alert the bank and payment app, call 1930, report through the cybercrime portal and preserve transaction evidence.
\nFor broader context, see the RBI Banking — Master Directions, Prudential Rules and Operations Hub.
Current position in plain English
Use the Debt-to-Income and FOIR Calculator to work through the related inputs before acting.
\nDecision table
| Time window | Priority action | Record to save |
|---|---|---|
| 0–5 minutes | Call bank and block affected channels | Complaint number and call time |
| 5–15 minutes | Call 1930 and provide transaction details | Helpline acknowledgement |
| 15–30 minutes | Submit cybercrime report and app/bank dispute | Portal acknowledgement |
| Same day | Secure SIM, email and device; file police report if advised | Screenshots, device/app details |
| Following days | Track bank investigation and escalate service deficiency | Written replies and timeline |
For the connected rule, example or next step, see Senior Citizen Cyber Fraud Response: First 60 Minutes Checklist.
\nHow to apply the rule
Use two tracks at the same time: containment and complaint. Containment blocks further access; the complaint creates a traceable record for banks, payment operators and investigators.
Never rely on a phone number supplied inside the suspicious message. Open the official app or type the institution’s website address independently.
A fast, accurate complaint is better than a dramatic allegation. State what was authorised, what was not, when the alert arrived, when the bank was informed and which credentials or devices may have been compromised.
For UPI fraud immediate steps, first identify the legal or contractual relationship, then separate the amount, event and deadline. Use one chronology across the portal, institution and supporting records. This prevents a correct fact from being submitted under the wrong year, account, policy clause or complaint route.
For the connected rule, example or next step, see UPI Fraud Safety Checklist: 10 Red Flags Before You Scan or Pay.
\nPractical example
Priya approves a collect request that falsely appears to be a refund. She immediately calls her bank, reports the UPI transaction to 1930 and uploads the UTR, payee VPA, chat and screenshots. Because she authorised the payment, a refund is not automatic, but early reporting may help freeze downstream funds and preserves her complaint rights.
Action checklist
- Call the bank’s official fraud number and block UPI/mobile banking as needed.
- Call 1930 with UTR, amount, time, payer bank and beneficiary details.
- File at cybercrime.gov.in and retain acknowledgement.
- Report inside the UPI app and to the relevant bank.
- Remove remote-access or suspicious apps and scan the device.
- Change email, banking and UPI credentials from a clean device.
- Monitor all linked accounts and credit reports for further misuse.
Evidence and document checklist
- UPI transaction page and UTR
- Bank debit SMS/email and statement
- Scammer phone, VPA, QR code and account details
- Chat, call logs, advertisements and screen recordings
- 1930 and cybercrime acknowledgements
- Bank and app complaint numbers
- Device, SIM-change and remote-access evidence
Common mistakes
- Waiting for the recipient to reply before reporting
- Deleting the chat in embarrassment
- Calling a number supplied by the scammer
- Sharing OTP or UPI PIN to receive a refund
- Assuming app support alone is a police complaint
- Posting full account details publicly
Red flags
- Multiple debits or device-control indicators
- SIM stops working or email password changes
- The bank refuses to register a complaint
- A loan or new beneficiary appears
- Scammer threatens arrest or asks for a safe-account transfer
- Requests for further payment to unlock or recover money
Escalation route
After immediate bank, 1930 and cybercrime reporting, escalate unresolved bank-service issues through the bank’s grievance hierarchy and, when maintainable, the RBI Complaint Management System. Criminal investigation remains with law enforcement.
When escalating, include the original complaint, acknowledgement, concise chronology, disputed amount, rule or clause relied upon and the exact relief requested. Do not send passwords, PINs, OTPs or unrelated identity documents.
Frequently Asked Questions
Additional practical controls
The following points consolidate distinct practical guidance from overlapping Finin2min coverage into this definitive page.
- An emergency UPI-fraud workflow covering account protection, bank reporting, 1930, the cybercrime portal, evidence preservation and unauthorised-transaction liability.
- The first thirty minutes are for stopping further loss and creating traceable reports—not debating the scammer.
- Contact the bank and UPI app immediately to block affected channels and report unauthorised transactions.
- Call 1930 and complete the National Cyber Crime Reporting Portal process for financial cyber fraud as quickly as possible.
- RBI’s unauthorised-transaction framework makes reporting time and the cause of loss important to customer liability.
Source and review trail
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
- Primary category
- Income Tax
- Official starting point
- www.incometax.gov.in