If you discover an unauthorised transaction, don't spend the first 30 minutes arguing with the person who contacted you. Your priority is to reduce further loss and create an evidence trail.
Executive Summary
A card transaction appears that you don't recognise. Then another one appears. You panic โ and perhaps call the number included in the SMS.
The person answering says: โDon't worry. We will reverse the transaction. Just share the OTP.โ
That may be the second stage of the attack. A genuine bank representative should not require you to disclose your OTP, PIN or password.
The first objective is not to investigate the scammer. It is to contain the incident, report it through official channels and preserve the information investigators may need.
๐จ The First 30-Minute Emergency Plan
0โ5 Minutes: STOP THE BLEEDING
1. Block the card immediately
Use your bank's official app, website or card-issuer helpline. Where the bank provides separate controls, disable the affected payment channels.
Do not call a number supplied by the suspicious SMS. Use the number printed on the back of your card or the bank's official website/app.
2. Check whether more transactions are happening
Don't look only at the transaction that alerted you. Review the wider payment surface:
Payment accounts
Bank account, debit card, credit card, UPI, wallets and linked accounts.
Red flags
Small test transactions, multiple merchants, recurring payments, ATM withdrawals, international transactions and new beneficiaries.
Fraudsters may use a small transaction to test a compromised payment instrument before attempting larger transactions.
5โ10 Minutes: CONTACT YOUR BANK
Call the bank's official fraud/customer-service channel and clearly state that you are reporting an unauthorised transaction.
Ask for:
RBI guidance requires banks offering e-banking services to provide 24ร7 reporting channels for unauthorised transactions and to take immediate steps to prevent further unauthorised transactions after a report.
10โ15 Minutes: CALL 1930
For cyber financial fraud in India, the official National Cyber Crime Reporting Portal directs victims to report immediately through 1930 or the online portal. The helpline is listed as 24ร7 on the government portal.
The reason speed matters is simple: stolen funds may move through multiple accounts or channels before they are withdrawn or converted.
The government portal currently identifies 1930 as the immediate-reporting channel for cyber financial fraud.
Have these details ready
The National Cyber Crime Reporting Portal provides financial-fraud reporting and asks complainants to provide transaction and supporting information.
15โ20 Minutes: FILE THE CYBERCRIME COMPLAINT
Do not rely only on the phone call. Use the official National Cyber Crime Reporting Portal and select the appropriate financial-fraud reporting option.
After submitting the complaint, save the acknowledgement/complaint number. It becomes part of your evidence trail.
20โ25 Minutes: PRESERVE THE EVIDENCE
This is where many victims make a mistake. They delete the SMS, delete WhatsApp conversations, block the scammer, uninstall the suspicious app โ and later realise that useful evidence has disappeared.
Preserve the suspicious messages, transaction alerts, screenshots, phone numbers, UPI IDs, URLs, emails, app details, bank complaint number, 1930 reference and NCRP acknowledgement.
Keep the original information intact where possible. If you need to block a number or account, capture the relevant evidence first.
25โ30 Minutes: SECURE YOUR DIGITAL ENVIRONMENT
If only card details were compromised, blocking the card may address the immediate payment risk. But if you also entered other credentials, assume the incident may be broader.
If you installed a remote-access application at the scammer's request, treat the device as potentially compromised and seek appropriate technical assistance.
๐ด One of the Biggest Mistakes: Calling the Scammer Back
Imagine seeing:
You call the number in the SMS. Someone answers:
Then: โPlease tell me the OTP you just received.โ
STOP. That OTP may be the authorisation required for another fraudulent transaction.
A genuine bank representative should not require you to disclose your OTP, PIN or password.
โ ๏ธ What If I Accidentally Shared My OTP?
Don't wait and don't assume the damage is already done.
The fact that an OTP was shared does not mean you should stop reporting. However, customer liability can depend on the circumstances, including whether payment credentials were shared. RBI's framework specifically distinguishes customer negligence from third-party/system breaches.
๐ก๏ธ Understanding Your RBI Protection
This is one of the most misunderstood parts of a financial-fraud incident.
| Situation | What the RBI framework says |
|---|---|
| Bank negligence / deficiency | Customer liability is zero, subject to the framework. |
| Third-party breach; no customer negligence; report within 3 working days | Zero liability. |
| Third-party breach; report in 4โ7 working days | Liability is limited according to the applicable framework and account/card category. |
| Report beyond 7 working days | Handled according to the bank's Board-approved policy. |
| Customer negligence, such as sharing payment credentials | Customer bears the loss until the transaction is reported; losses after reporting are treated differently under the framework. |
RBI's customer-protection framework also states that banks should provide an acknowledgement for the complaint and take immediate steps after receiving a report.
๐ฐ Does Reporting Guarantee a Refund?
No. Calling 1930 does not automatically guarantee that the money will be returned.
The outcome can depend on:
The purpose of rapid reporting is to increase the opportunity to stop or trace the money โ not to promise automatic recovery.
๐จ Beware of the SECOND SCAM
After you report a fraud, someone may contact you claiming:
โPay โน5,000 processing charges.โ
โInstall this application to receive your refund.โ
โShare your OTP to release the frozen amount.โ
This can be another scam. Use only official government and bank channels.
๐งช A Realistic 30-Minute Example
| Time | Action |
|---|---|
| 10:02 | SMS shows โน48,000 spent on your card. |
| 10:04 | Open the bank's official app and block the card. |
| 10:06 | Call the bank and register an unauthorised-transaction complaint. |
| 10:10 | Call 1930. |
| 10:15 | Provide transaction ID, amount, date/time, bank and merchant information. |
| 10:20 | Submit the NCRP complaint. |
| 10:25 | Save SMS, screenshots, complaint number, 1930 reference and NCRP acknowledgement. |
| 10:30 | Secure banking/email accounts and review other payment channels. |
That's a much stronger response than spending the first 30 minutes arguing with the scammer.
๐ What SOC & Fraud Teams Should Learn
For organisations, the lesson is bigger than individual card fraud. Financial-fraud detection should look for combinations of payment, identity and device anomalies.
Transaction anomalies
Unusual merchant, location, amount, velocity, sudden transaction spikes and new payment instruments.
Account takeover signals
New device, SIM change, password reset, new beneficiary, unusual login and impossible-travel indicators.
Behavioural anomalies
Multiple failed authentication attempts, sudden changes in user behaviour and unusual authentication patterns.
Fraud infrastructure
Known malicious phone numbers, suspicious domains, fake support pages and phishing infrastructure.
๐ฎ๐ณ India's Cyber-Fraud Response Ecosystem
The response is no longer simply Victim โ Bank. Rapid reporting can involve several coordinated points in the response chain.
The practical objective is to shorten the time between Fraud โ Detection โ Reporting โ Fund Interception.
๐จ CyberRakshakLabs 30-Minute Checklist
๐ Block card/payment channel
๐ธ Screenshot transaction
๐ฆ Contact bank
๐ Get complaint number
๐ Call 1930
๐ป File complaint on cybercrime.gov.in
๐ Preserve evidence
๐ Secure accounts ยท ๐ฑ Check device ยท ๐ Change compromised credentials
Official References
National Cyber Crime Reporting Portal: cybercrime.gov.in
RBI โ Customer Protection / Unauthorised Electronic Banking Transactions: RBI notification
This research is an awareness and incident-response guide, not legal or financial advice. RBI customer-liability rules can depend on the transaction type, customer conduct and the applicable framework.
Your first job is containment.
BLOCK โ BANK โ 1930 โ REPORT โ PRESERVE โ SECURE
Every minute matters because digital money can move much faster than a traditional investigation. The best time to stop a cyber fraud is before the money moves. The second-best time is immediately after you discover it.
Think Before You Click. Stay Aware. Stay Secure.
CyberRakshakLabs โ Threat Intelligence for a Safer Tomorrow.