Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteIf you suspect a UPI or banking scam, contact your bank immediately through its official app, website, or verified phone number and report any unauthorized debit. Ask it to secure the affected account or payment access and give you a complaint reference. Then report the cybercrime through 1930 or the National Cyber Crime Reporting Portal, raise a transaction dispute with your bank, and save your evidence. These steps are urgent, but they do not guarantee that money will be recovered.
What to do first after a UPI or banking scam
- Report it to your bank. Use the bank’s official app, website, or a phone number you verify independently. Identify the transaction and say clearly that it was unauthorized. Ask the bank to take steps to prevent further unauthorized transactions, secure affected digital access or payment instruments as appropriate, and provide a complaint reference. Do not call a number supplied by the suspected scammer. RBI’s directions require banks to provide 24×7 reporting channels and take immediate preventive steps after notification. Read the RBI directions.
- Report cyber fraud through 1930 or the government portal. Call 1930 or file a report through the National Cyber Crime Reporting Portal as soon as possible. Keep the acknowledgement. A cybercrime report does not replace telling your bank: contact both. The government portal’s notice advises victims to report immediately. The detailed reporting instructions available here are labelled “For Delhi Only”, so their additional instructions should not be treated as a national rule.
- Open a dispute through the bank and, where available, your UPI app. Report the specific unauthorized or fraudulent transaction to the bank. Use the transaction’s in-app complaint option as an additional route if available. NPCI facilitates complaints but says the member bank or institution is responsible for resolving them. NPCI’s complaint page and its UPI FAQ explain the routes.
- Preserve records before changing or removing anything. Save the transaction ID or RRN, date and amount, bank or wallet involved, relevant UPI ID or account identifiers, screenshots, messages, and every complaint acknowledgement or reference number. Do not delete the app or messages before preserving relevant evidence. The Delhi-labelled instruction sheet lists transaction details and screenshots among the information to provide.
How to secure your UPI and banking access
Protect your PIN, password and OTP
Never share your UPI PIN, OTP, banking password, card details, or remote-access control with someone who contacts you. NPCI says not to share the UPI PIN and that bank customer support will never ask for it. A caller’s claim that they need your PIN to cancel or reverse a payment is not a reason to disclose it. If you think a PIN or other credential has been exposed, contact the bank through an official channel and follow its instructions to secure or change the affected access.
Use a trusted device and official recovery instructions
Make account changes only through your bank’s official app, website, or verified support channel. Recovery and reset steps vary by bank and app; do not follow links or instructions sent by a suspected scammer. NPCI says that if your SIM, phone, or PSP app has changed, UPI re-registration is required. Follow your bank or app’s current official instructions for that process. See the NPCI UPI FAQ.
Check linked accounts and recent activity
Review recent transactions and linked bank accounts in your bank and UPI apps. If your app offers controls to change a UPI PIN, switch linked accounts, or block and report a user sending illicit collect requests, use the current in-app help guidance. NPCI lists these among BHIM features, but labels and flows may change between app versions. See NPCI’s BHIM feature reference.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What if money was debited from your account?
Tell the bank that the debit was unauthorized and ask it to register a dispute. Provide the transaction identifier, date, amount, and any relevant account or UPI details, then keep the complaint reference. Also report promptly through 1930 or the National Cyber Crime Reporting Portal and retain that acknowledgement. These routes serve different purposes: the bank handles account protection and the transaction dispute; the government channel handles cybercrime reporting; a UPI app or NPCI complaint can help route a payment grievance, but does not replace the bank’s process.
Ask the bank how it will assess your liability and what further records it needs. RBI’s 6 July 2017 directions set out liability rules for scheduled commercial banks, including regional rural banks, small finance banks, and payments banks. Under that framework, liability depends on how the transaction occurred and how quickly it was reported:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- If a loss resulted from bank negligence or deficiency, the circular provides for zero customer liability.
- For a third-party breach where neither the bank nor customer is at fault, a report within three working days of the bank’s transaction communication qualifies for zero liability under the circular. A report after four to seven working days has capped liability; beyond seven working days, the bank’s board-approved policy applies.
- If customer negligence, such as sharing payment credentials, caused the loss, the customer bears the loss until the bank is notified; the circular assigns later loss to the bank.
These are RBI framework rules, not a guarantee about an individual claim. The bank must assess the facts and applicable rules. The circular also provides for shadow reversal in qualifying zero- or limited-liability cases and requires liability determination or resolution within the bank’s policy timeline, capped at 90 days; that does not mean every reported amount is guaranteed or immediately recovered. Read the RBI circular.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If the scam involved a “jumped deposit” claim
NPCI’s clarification dated 13 January 2025 says that simply opening a UPI or bank app does not automatically approve a payment, and an outside party cannot directly request or withdraw funds from your account. Do not rely on a scammer’s claim that opening an app itself authorized a debit. Check your account activity; if an actual unauthorized transaction appears, report it to your bank and through the cybercrime channel. Read NPCI’s clarification.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

