With the rapid growth of UPI, net banking, and mobile wallet transactions, digital financial fraud has become an increasingly common threat. Scammers use sophisticated social engineering tactics, fake customer care calls, and phishing links to trick people into revealing sensitive details.
A major concern for banking customers is determining responsibility when money is stolen online. According to Reserve Bank of India (RBI) guidelines, customer liability depends directly on where the security failure occurred and how quickly the fraud is reported.
Here is a breakdown of the RBI’s digital fraud compensation rules, how liability is determined, and what happens if you inadvertently share an OTP with a scammer.
Understanding Customer Liability Under RBI Guidelines
The RBI categorizes unauthorized electronic banking transactions into three distinct liability levels based on negligence and reporting speed.
1. Zero Liability (Full Refund from the Bank)
A customer faces zero financial liability and is entitled to a 100% refund under two conditions:
- Bank System Failure: The fraud or security breach occurred due to a fault, negligence, or loophole in the bank’s system (regardless of whether the customer reported it).
- Third-Party Breach: A security leak occurred elsewhere in the payment network, and the customer reported the unauthorized transaction to the bank within 3 working days of receiving the transaction alert.
2. Limited Liability (Capped Financial Loss)
If the delay in reporting an unauthorized transaction is due to customer oversight (and not negligence), liability is capped based on the account type:
- Reporting within 4 to 7 working days: The customer’s maximum liability is capped according to RBI limits (ranging from ₹5,000 for basic savings accounts up to ₹25,000 for commercial accounts/credit cards with high limits). The bank must refund the remaining balance.
- Reporting after 7 working days: The customer’s liability is determined entirely according to the individual bank’s board-approved policy.
3. 100% Customer Liability (Gross Negligence)
If a customer exhibits gross negligence by voluntarily sharing confidential credentials—such as passwords, PINs, UPI PINs, or One-Time Passwords (OTPs)—the customer bears the entire loss until the unauthorized transaction is reported to the bank. Any fraudulent transactions taking place after reporting the breach remain the bank’s responsibility.
What Happens If You Share an OTP After Being Tricked?
Social engineering frauds often involve impersonation, where scammers pose as bank officials, delivery agents, or utility service workers to trick victims into sharing OTPs.
- Negligence Classification: Under strict regulatory definitions, sharing an OTP is classified as customer-side negligence because banks continuously advise customers never to share OTPs or PINs.
- Bank Refund Denial: In most cases where an OTP was shared, banks deny primary liability for the loss, as the transaction was completed using valid two-factor authentication (2FA).
- Exceptions & Cyber Recovery: If you immediately notify the bank to freeze your account/cards and report the incident on the national cybercrime portal (1930 or cybercrime.gov.in), law enforcement may freeze the fraudulent recipient account before the funds are withdrawn. If the stolen funds are successfully blocked in the destination bank account, courts or banking ombudsmen can order a recovery refund.
Step-by-Step Action Plan
What to Do Immediately After a Digital Fraud
If you fall victim to a digital financial scam, follow these steps immediately to limit your liability:
- Notify Your Bank Instantly: Block your debit/credit card, UPI access, and net banking via your banking app or customer care hotline.
- Report Within 3 Days: Ensure your official complaint is logged with the bank within 3 working days to protect your eligibility under the RBI’s zero/limited liability framework.
- Call the National Cyber Crime Helpline (1930): Report the transaction immediately to enable police and banking networks to trace and freeze the funds in the scammer’s destination account.
- Obtain an Incident Ticket/FIR: File a formal complaint on the official government cybercrime portal (cybercrime.gov.in) or at your local police station, and retain a copy of the acknowledgment ticket.
- Escalate to the Banking Ombudsman: If your bank fails to resolve your grievance or rejects a valid claim within 30 days, file an official complaint with the RBI Integrated Ombudsman.
While RBI guidelines offer robust protection against system glitches and third-party security breaches, user caution remains the primary line of defense. Remember that no legitimate bank, payment platform, or government agency will ever ask for your UPI PIN, password, or OTP.
Keeping your financial credentials private and reporting suspicious transactions immediately remain essential for digital financial safety.

