Speed matters in an unauthorised UPI transaction because funds can move through several accounts quickly. The first objective is containment and traceability: alert the bank and payment app, call 1930, report through the cybercrime portal and preserve transaction evidence.
Finin2min takeaway: Act from primary records, use the official channel and keep a dated evidence trail. A portal message, screenshot, dashboard or verbal assurance is not a substitute for the governing rule and underlying documents.
Current position in plain English
Report to the bank immediatelyUse the official fraud channel, not only an in-app chatbot. Ask for a complaint number, beneficiary freeze request and confirmation of the reported time.
Call 1930The national cyber financial-fraud helpline can help route an urgent report for fund interception. Follow it with the required portal complaint.
Secure the payment environmentBlock or reset affected UPI access, cards and mobile banking. Change credentials from a trusted device and check for screen-sharing or malicious apps.
Distinguish unauthorised fraud from an authorised scam paymentRBI customer-liability rules are strongest where the transaction was unauthorised. If the victim personally authorised the transfer under deception, recovery still requires urgent bank and police action but liability analysis can differ.
Do not pay a 'recovery agent'Anyone asking for another transfer, remote access or OTP to recover funds is likely extending the fraud.
Decision table
| Time window | Priority action | Record to save |
|---|
| 0–5 minutes | Call bank and block affected channels | Complaint number and call time |
| 5–15 minutes | Call 1930 and provide transaction details | Helpline acknowledgement |
| 15–30 minutes | Submit cybercrime report and app/bank dispute | Portal acknowledgement |
| Same day | Secure SIM, email and device; file police report if advised | Screenshots, device/app details |
| Following days | Track bank investigation and escalate service deficiency | Written replies and timeline |
How to apply the rule
Use two tracks at the same time: containment and complaint. Containment blocks further access; the complaint creates a traceable record for banks, payment operators and investigators.
Never rely on a phone number supplied inside the suspicious message. Open the official app or type the institution’s website address independently.
A fast, accurate complaint is better than a dramatic allegation. State what was authorised, what was not, when the alert arrived, when the bank was informed and which credentials or devices may have been compromised.
For UPI fraud immediate steps, first identify the legal or contractual relationship, then separate the amount, event and deadline. Use one chronology across the portal, institution and supporting records. This prevents a correct fact from being submitted under the wrong year, account, policy clause or complaint route.
Practical example
Priya approves a collect request that falsely appears to be a refund. She immediately calls her bank, reports the UPI transaction to 1930 and uploads the UTR, payee VPA, chat and screenshots. Because she authorised the payment, a refund is not automatic, but early reporting may help freeze downstream funds and preserves her complaint rights.
Action checklist
- Call the bank’s official fraud number and block UPI/mobile banking as needed.
- Call 1930 with UTR, amount, time, payer bank and beneficiary details.
- File at cybercrime.gov.in and retain acknowledgement.
- Report inside the UPI app and to the relevant bank.
- Remove remote-access or suspicious apps and scan the device.
- Change email, banking and UPI credentials from a clean device.
- Monitor all linked accounts and credit reports for further misuse.
Evidence and document checklist
- UPI transaction page and UTR
- Bank debit SMS/email and statement
- Scammer phone, VPA, QR code and account details
- Chat, call logs, advertisements and screen recordings
- 1930 and cybercrime acknowledgements
- Bank and app complaint numbers
- Device, SIM-change and remote-access evidence
Common mistakes
- Waiting for the recipient to reply before reporting
- Deleting the chat in embarrassment
- Calling a number supplied by the scammer
- Sharing OTP or UPI PIN to receive a refund
- Assuming app support alone is a police complaint
- Posting full account details publicly
Red flags
- Multiple debits or device-control indicators
- SIM stops working or email password changes
- The bank refuses to register a complaint
- A loan or new beneficiary appears
- Scammer threatens arrest or asks for a safe-account transfer
- Requests for further payment to unlock or recover money
Escalation route
After immediate bank, 1930 and cybercrime reporting, escalate unresolved bank-service issues through the bank’s grievance hierarchy and, when maintainable, the RBI Complaint Management System. Criminal investigation remains with law enforcement.
When escalating, include the original complaint, acknowledgement, concise chronology, disputed amount, rule or clause relied upon and the exact relief requested. Do not send passwords, PINs, OTPs or unrelated identity documents.
Frequently Asked Questions
Should I call 1930 before the bank? ▼
Do both immediately. The bank can block channels and 1930 can support rapid fund-tracing.
Will the bank always refund UPI fraud? ▼
No. Outcome depends on whether the transaction was unauthorised, reporting time, customer conduct, bank controls and investigation.
Can a UPI PIN receive money? ▼
No. Entering a UPI PIN normally authorises a debit, not receipt.
What is the UTR used for? ▼
It helps identify and trace the specific transaction.
Should I uninstall the payment app? ▼
First preserve evidence and secure access; follow bank or cybercrime instructions and remove malicious apps.