Direct answer
At a glance
A practical guide to reporting fraudulent digital transactions, understanding customer liability, and preparing for RBI's expanded rules from 1 January 2027.
- Article type
- guide
- Last updated
- 20 July 2026 at 4:33 pm IST
- Sources listed
- 5
Report first, classify the transaction second
If money leaves your account through fraud, contact the bank immediately and report it through cybercrime.gov.in or helpline 1930. Do not wait to decide whether the payment was technically authorised. Save the bank complaint number, cybercrime acknowledgement, transaction reference, amount, date and time.
This matters because scams do not all look like a card or UPI transaction made without permission. A victim may be tricked into approving a collect request, sharing credentials, installing remote-access software or sending money to a fraudster. RBI's final June 2026 directions widen the customer-protection framework from only unauthorised electronic transactions to a broader group of fraudulent electronic banking transactions.
The revised framework comes into effect on 1 January 2027. Until then, banks must continue applying the rules currently in force. Do not quote a future benefit as if it is already available. The practical step is the same in both periods: report quickly through official channels and keep evidence of when the report was made.
What changes from 1 January 2027
The final directions apply across commercial banks, small finance banks, payments banks, local area banks, regional rural banks and urban and rural co-operative banks. The framework covers card-present and card-not-present transactions and expands beyond a narrow unauthorised-transaction test.
Key shopper-facing changes include:
- Broader fraud coverage: the framework can include transactions approved after credentials were obtained fraudulently, approval was coerced, or a customer was deceived into paying a scammer.
- A small-value compensation mechanism: eligible individual customers, including sole proprietors, may receive 85% of the net loss or ā¹25,000, whichever is lower, for a covered fraudulent transaction with a loss up to ā¹50,000.
- Two reports within five calendar days: eligibility for that compensation requires reporting to the bank and to the National Cyber Crime Reporting Portal or 1930 within five calendar days of the incident.
- Faster complaint outcomes: banks are expected to complete investigation and communicate the result within 45 calendar days for domestic transactions and 60 calendar days for cross-border transactions.
- Credit-card shadow reversal: for a reported fraudulent credit-card transaction, the disputed amount is to receive a shadow reversal within five days while the complaint is investigated.
These are general guideposts, not a promise that every loss will be reimbursed. Eligibility depends on the final directions, the facts of the incident, reporting evidence and the bank's assessment. Compensation is calculated on net loss, after deducting any amount already recovered.

CouponPe
Report to both systems immediately. The five-day condition shown is for the expanded framework effective 1 January 2027, not permission to wait five days.
Use this loss calculation
For the small-value mechanism, the stated calculation is:
Compensation = the lower of 85% of net loss and ā¹25,000
Here are labelled examples using hypothetical amounts:
| Net loss | 85% of net loss | ā¹25,000 cap | Indicative compensation |
|---|---|---|---|
| ā¹10,000 | ā¹8,500 | ā¹25,000 | ā¹8,500 |
| ā¹25,000 | ā¹21,250 | ā¹25,000 | ā¹21,250 |
| ā¹40,000 | ā¹34,000 | ā¹25,000 | ā¹25,000 |
| ā¹50,000 | ā¹42,500 | ā¹25,000 | ā¹25,000 |
The table demonstrates the formula only. It does not determine whether a reader's case is covered. A loss above ā¹50,000 falls outside this small-value mechanism, but the broader liability rules and complaint process may still be relevant.
Liability depends on how the fraud happened and when it was reported
RBI's existing 2017 framework gives zero customer liability when the bank is at fault. It also provides zero liability for a third-party breach, where neither the bank nor customer is at fault, when the customer reports within three working days of receiving the bank's transaction communication. A report made in four to seven working days can lead to limited liability, while later reports follow the bank's board-approved policy.
If the loss arose from customer negligence, such as sharing payment credentials, the existing framework says the customer bears the loss until the bank is informed; losses after reporting are borne by the bank. The bank carries the burden of proving customer liability.
Do not turn that into a simple "shared OTP means no refund" rule. The 2027 framework recognises a wider set of fraudulent situations, including deception and coercion. A bank still needs to examine the facts. Give a precise sequence rather than a conclusion: what message arrived, which screen was opened, what was entered or approved, when the debit appeared, and when each report was filed.
What to do in the first 30 minutes

CouponPe
Keep transaction and complaint evidence together, but never send a PIN, password or full card number as proof.
- Call the bank through its official number. Use the number on the card, statement or bank website. Block the affected card, account access or payment instrument if advised.
- Report through 1930 or cybercrime.gov.in. Keep the acknowledgement and exact submission time. A bank report does not replace the cybercrime report.
- Save transaction evidence. Record the UTR or transaction ID, amount, recipient or merchant identifier, date, time and bank alert.
- Preserve the fraud trail. Keep messages, numbers, URLs, email headers, app names and screenshots. Do not continue chatting merely to collect more evidence.
- Remove access safely. Disconnect remote-access apps or suspicious sessions and change credentials from a trusted device. Ask the bank before factory-resetting a device that may contain evidence.
- Track every complaint. Record the bank reference, cybercrime acknowledgement, promised response date and any written decision.
If a payment merely failed and no order was created, use the UPI failed-payment and refund timeline. That is a payment-status problem, not automatically fraud. If the fraud began with an unknown delivery, follow the unexpected COD parcel checklist and do not pay simply to inspect the package.
Shopping links cannot verify a payment request
CouponPe can help you reach canonical merchant pages such as Amazon coupons and store details, Flipkart coupons and store details, Myntra coupons and store details and AJIO coupons and store details. Those pages cannot confirm a bank call, refund QR, collect request or order-support message.
Open the merchant's official app or type its address yourself. Compare the order ID and amount with the account history. The genuine shopping website checklist helps before payment, while the return, replacement, refund and warranty guide applies to genuine orders with product or service problems.
Escalate after the bank's decision or delay
First give the bank a complete complaint and keep its acknowledgement. If the bank rejects the complaint, provides only a partial response, or does not resolve an eligible complaint within the applicable period, check the RBI Complaint Management System. RBI's Integrated Ombudsman route normally requires the customer to complain to the regulated entity first.
A cybercrime report, bank complaint and Ombudsman complaint serve different functions. Filing one does not automatically open the others. Use the same factual timeline and reference numbers across all of them, and update the net loss if any money is recovered.
How we checked the rules
CouponPe reviewed RBI's final 24 June 2026 announcement, the underlying customer-liability framework, RBI's financial-awareness material and the official National Cyber Crime Reporting Portal on 20 July 2026. The calculations above reproduce the stated 85% and ā¹25,000 limits with hypothetical values. We did not file a complaint, test a bank's handling, interview a victim or assess an individual case. The expanded directions become effective only on 1 January 2027, and bank-specific policies and factual findings can affect the outcome.
How this guide was prepared
CouponPe separates editorial explanation from merchant claims, records visible update dates, and lists the supplied sources below. Offer eligibility and final prices should always be confirmed on the merchant website or app.
Sources
- Reserve Bank of India: Final customer-liability amendment directions announcementAccessed
- Reserve Bank of India: Existing customer protection framework for unauthorised electronic transactionsAccessed
- Reserve Bank of India: Financial Awareness Messages on fraudulent digital transactionsAccessed
- National Cyber Crime Reporting Portal: Official reporting portalAccessed
- Reserve Bank of India: Complaint Management SystemAccessed
