After a UPI or OTP scam, act quickly. Notify the bank through its official fraud channel, call 1930, preserve transaction and device records, and assess the bank's response. A UPI and OTP scam lawyer in India can help when the loss is serious, the bank disputes liability, or the complaint and evidence need a coordinated legal strategy.
Use the first minutes for bank and 1930 reporting
Call the bank, card issuer, wallet, or payment provider using a number from its official website, app, or statement. Ask the team to block further access, mark the disputed transactions, secure the account, and issue a complaint reference. If a remote-access application was installed, stop using the affected device for banking until it has been checked. Change credentials from a clean device and remove access that you do not recognise.
For a financial cyber fraud, the official reporting instructions identify helpline 1930 and the National Cyber Crime Reporting Portal. They also list bank or wallet information, transaction identifiers, dates, and screenshots as useful details. Keep the acknowledgement and complete the portal registration or follow-up requested after the helpline call. Reporting does not promise a refund, but delay can make the transaction trail harder to act on.
Understand what the RBI liability framework actually asks
Victims often ask whether a bank must return the money immediately. RBI directions distinguish situations involving bank deficiency, a third-party breach, and customer negligence. They also connect the customer's position to how quickly the unauthorised transaction is reported. The RBI customer-protection directions describe zero-liability and limited-liability situations, reporting periods, and the bank's shadow-reversal process, but the result still depends on the account, transaction, facts, and applicable bank policy.
If an OTP, UPI PIN, password, or screen-sharing permission was disclosed, do not hide that fact. Explain what the caller said, what the customer believed was happening, what was entered or approved, and when the customer realised the debit was unauthorised. A careful complaint is stronger than a technical conclusion that the records cannot support. Losses after the bank was notified may also need to be separated from the first disputed debit.
Build an evidence file that matches each debit
Do not send one long screenshot folder with no index. Match every transaction to the event that produced it:
- Payment records: UTR, UPI ID, beneficiary account, amount, date, time, card or wallet entry, and bank statement.
- Contact records: caller number, email, WhatsApp profile, fake customer-care page, SMS, social post, and the exact request made.
- Device records: app installed, screen-sharing session, permission prompt, login alert, SIM event, password reset, and device used.
- Bank response: complaint number, email, call reference, nodal escalation, reversal decision, and the reason for any rejection.
- Impact: salary loss, business interruption, blocked account, failed EMI, customer payment, or exposure of identity material.
Keep original messages, emails, and statements untouched. Use copies for highlighting. Do not send Aadhaar, full account numbers, or OTPs to online recovery agents. Do not abuse the beneficiary account holder or publish their details before the transaction chain has been checked.
Make the bank complaint audit-ready
The written complaint should state the first unauthorised debit, the alert time, the time and channel of bank notice, the 1930 reference, the portal acknowledgement, and the relief requested. Ask for reversal or freeze action where appropriate, preservation of relevant records, and a written decision. If the bank says the transaction was authorised, ask what record supports that conclusion and identify the event that the customer disputes.
A branch visit may not reach the fraud team or nodal officer. Send the complaint through the prescribed channel and keep proof of delivery. If the response is incomplete, escalation may involve the bank's nodal process, an ombudsman route, police follow-up, or court advice. The right step depends on the complaint and the documents, not simply on the amount shown in the SMS.
Check for device and business causes
An OTP scam may involve a fake customer-care number, a malicious application, a SIM event, a collect request, a QR-code instruction, or a customer who misunderstood a payment approval. Do not state that the bank system was hacked unless the evidence supports it. Record the screen, message, and action in sequence. The site's Cybersecurity service may help review access and device controls, while its Cyber Forensics service may fit a matter that needs a technical record of calls, devices, or electronic transactions.
For a company account, identify the employee or vendor who received the message, the approval chain, the device used, and the controls that could prevent another debit. A founder can also consult the site's startup lawyer in Bangalore resource when the loss affects company approvals, contracts, payroll, or investor reporting. The site's Indian Evidence Act reference is related reading for organising electronic records, subject to advice on the current law and facts.
Know when legal escalation is useful
Direct bank reporting may be enough for a small, clearly documented loss. Legal help becomes useful when the bank denies liability, the fraud crossed several banks, the victim is elderly, a business account was affected, the complaint was rejected for missing facts, the beneficiary account is frozen, or the money has not been traced. A lawyer can separate the bank dispute from the cybercrime complaint and prepare the records each recipient needs.
Do not promise yourself a refund because an online adviser says a case is easy. Do not pay a person who offers to reach a police officer through a private channel. A documented timeline, bank acknowledgement, portal number, and accurate explanation of any shared credential are more useful than an aggressive message.
Turn the first report into a refund strategy
If you lost money through an OTP request, UPI collect approval, QR-code trick, fake customer-care call, or reward-points message, contact ExpertCyberLawyer.com with the transaction schedule, bank complaint, 1930 reference, portal acknowledgement, and device details. A UPI and OTP scam lawyer in India can then assess the bank liability question, evidence, police follow-up, and legal escalation supported by the record.
