Phishing and OTP fraud — what to do in the first 24 hoursA phishing-page debit or an OTP-induced UPI transfer sets off three statutory clocks at once — the Reserve Bank of India's three-working-day notification window under the 6 July 2017 customer-protection circular, the Section 173 BNSS / Section 154 CrPC FIR clock, and the Section 67C IT Act preservation clock against the intermediary. This article maps the procedural architecture that governs the first 24 hours of recovery — the IT Act offences (Sections 43, 66, 66C, 66D, 72A Three statutory clocks in twenty-four hours
[ Everyday Law ]

Phishing and OTP fraud — what to do in the first 24 hours

A phishing-page debit or an OTP-induced UPI transfer sets off three statutory clocks at once — the Reserve Bank of India's three-working-day notification window under the 6 July 2017 customer-protection circular, the Section 173 BNSS [Section 154 CrPC] FIR clock, and the Section 67C IT Act log-preservation clock against the intermediary. This article maps the procedural architecture that governs the first twenty-four hours of recovery and the statutes that sit behind it.

Phishing and OTP fraud in India is not a single offence but a stack of three intersecting legal regimes — a banking-regulation regime that allocates the financial loss between the customer and the bank under the RBI's 6 July 2017 circular, an Information Technology Act offence regime that punishes the impersonation, unauthorised access and disclosure that produced the debit, and a Bharatiya Nyaya Sanhita cheating regime that catches the underlying deception. The first twenty-four hours after a fraudulent debit are the operational hinge for all three: a customer who triggers the RBI three-working-day window, an FIR under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 [Section 154 CrPC], and a Section 67C preservation request against the intermediary in that window protects the recovery position across every track. A customer who misses that window finds each regime degraded in turn. This article is a doctrinal map of that architecture, not a leaflet.

The offence-side overlay — IT Act Sections 43, 66, 66C, 66D and 72A

The Information Technology Act, 2000 supplies the punitive scaffolding for every phishing and OTP-fraud charge. Five sections do most of the doctrinal work.

Section 43 of the IT Act, 2000 is the civil-penalty provision. It attaches liability for damages where any person, without permission of the owner of a computer, computer system or computer network, accesses or secures access to such computer resource, downloads or copies data, or causes the disruption of any computer service. Phishing — a fraudulent web page designed to harvest credentials — is squarely Section 43 conduct on the perpetrator's side; the cap of one crore that existed in the pre-2008 text was removed by the Information Technology (Amendment) Act, 2008, and damages are recoverable before the Adjudicating Officer under Section 46 of the Act. Section 43 is the civil track that runs alongside the FIR, not a substitute for it.

Section 66 of the IT Act, 2000 makes Section 43 conduct an offence where it is committed dishonestly or fraudulently within the meaning of Sections 23 and 24 of the IPC (now Sections 2(7) and 2(8) of the Bharatiya Nyaya Sanhita, 2023). Punishment extends to three years' imprisonment and a fine up to five lakh rupees. The Supreme Court in Shreya Singhal v Union of India, (2015) 5 SCC 1, while striking down the vague Section 66A, expressly preserved Section 66 on the ground that its ingredients are defined with sufficient specificity to survive a void-for-vagueness analysis. Section 66 is the offence-side workhorse in the FIR of every credentials-harvesting phishing case.

Section 66C of the IT Act, 2000 — identity theft — punishes fraudulent or dishonest use of an electronic signature, password or any other unique identification feature of another person, with imprisonment up to three years and a fine up to one lakh rupees. The provision is drafted in deliberately broad terms; the phrase "any other unique identification feature" has been read to cover Aadhaar numbers, banking PINs, UPI PINs, OTPs, biometric authentication tokens and device-identification markers. Where a fraudster has used a captured OTP or PIN to debit the customer's account, Section 66C is made out on the face of the transaction record; the further question is whether the conduct was dishonest or fraudulent within the meaning of the BNS provisions.

Section 66D of the IT Act, 2000 — cheating by personation by computer resource — is the linchpin of the typical phishing or vishing prosecution. The provision punishes "whoever, by means of any communication device or computer resource cheats by personating" with imprisonment up to three years and a fine up to one lakh rupees. The substantive content of "cheats by personation" is drawn from Section 416 IPC (now Section 319 of the Bharatiya Nyaya Sanhita, 2023): cheating by pretending to be some other person, or by knowingly substituting one person for another, or by representing that he is a person other than he really is. A fake banking call-centre, an impersonated payment-app helpline, a spoofed merchant page, a counterfeit KYC-verification notification — each is paradigm Section 66D conduct, and is routinely charged together with the Section 319 BNS cheating-by-personation count.

Section 72A of the IT Act, 2000 punishes the disclosure of information in breach of a lawful contract — relevant where a bank employee, a call-centre agent, a third-party payment processor or a KYC-data handler has leaked customer authentication data that was subsequently used in the fraud. Punishment extends to three years' imprisonment or a fine up to five lakh rupees, or both. Section 72A is the insider-leak overlay; it operates alongside the body-corporate civil liability under Section 43A for failure to maintain reasonable security practices over sensitive personal data.

Two further provisions complete the offence-side picture. Section 75 of the IT Act, 2000, the extraterritoriality clause, extends the Act's reach to "any offence or contravention committed outside India by any person" if the act involves a computer, computer system or computer network located in India. Phishing infrastructure — domain registrars, hosting providers, mule-account chains — routinely sits outside Indian territory; Section 75 is what makes the Indian charge sustainable irrespective of where the perpetrator dialled in from. Section 67C, the preservation provision, requires intermediaries to preserve and retain such information as may be specified in the Rules; non-compliance is punishable up to three years' imprisonment. Section 67C is the basis for the formal preservation notice that goes out to the bank, the payment-system operator, the telecom service provider and the relevant social-media or messaging intermediary in the first twenty-four hours.

The BNS cheating provisions — Sections 318, 319, 336 and 61

The Bharatiya Nyaya Sanhita, 2023 carries the cheating offences forward from the IPC with consolidated numbering. Four sections are operative.

Section 318 of the BNS [Section 420 IPC] is the general cheating offence — fraudulent or dishonest inducement of a person to deliver any property, or to consent to the retention of property, or to do or omit anything which causes damage in body, mind, reputation or property. Phishing transfers the customer's funds because the customer or an authenticator was induced by deception; the inducement is the gravamen of Section 318. Cheating in the form addressed by Section 318(4) — cheating with dishonest inducement to deliver property — carries imprisonment up to seven years and a fine.

Section 319 of the BNS [Section 416 IPC; punishment formerly under Section 419 IPC] punishes cheating by personation specifically; the Explanation makes the offence good whether the personated individual is real or imaginary. Section 319 is the BNS twin of Section 66D IT Act. The two are routinely charged together because the gravamen differs — Section 319 captures the impersonation; Section 66D captures the computer-resource medium. The charges are not duplicative.

Section 336 of the BNS [Section 463 IPC] is the forgery framework, picking up the fabrication of false electronic documents — spoofed transaction confirmations, fabricated KYC stamps, counterfeit merchant invoices used to extract the OTP. Where the phishing case involves a fabricated electronic record (not merely a phishing form), Section 336 is the natural addition.

Section 61 of the BNS [Sections 120A and 120B IPC] is the criminal-conspiracy provision and is routinely added where the phishing operation is plainly a network — call-centre, mule-account custodians, drop-mobile suppliers, account-takeover operators. The conspiracy charge changes both the substantive exposure and the procedural position (jurisdiction extends to any place where any overt act was committed) and is often what justifies the inter-state coordination that these cases require.

The RBI customer-protection circular — three liability tiers and the bank's burden

Allocation of the financial loss between bank and customer is governed by Reserve Bank of India Circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017, issued under Section 35A of the Banking Regulation Act, 1949. The circular applies to all scheduled commercial banks, regional rural banks, small finance banks, payments banks, foreign banks operating in India and cooperative banks regulated by the Reserve Bank. Its operative scheme rests on three tiers that turn on the speed of the customer's notification after the bank's communication.

The notification clock runs from the bank's alert — SMS or email — not from the date of debit. Where the unauthorised transaction occurred because of bank-side fraud, negligence or deficiency, the customer's liability is zero irrespective of when the customer reports. Where the loss is caused by a third-party breach with no fault on either side, the customer's liability is zero if notification is within three working days; capped at the Annex-II amount (Rs 5,000 for a Basic Savings Bank Deposit account, Rs 10,000 for ordinary savings and MSME current accounts and small credit-card accounts, Rs 25,000 for larger current and credit-card accounts) if notification is within four to seven working days; and as per the bank's Board-approved policy — in practice, full — beyond seven working days. Where the loss is due to customer negligence — shared password, voluntarily disclosed OTP, credentials cached on an unsecured device — the customer bears the entire loss until the bank is notified, and the loss passes to the bank thereafter.

Paragraph 6 of the circular places the burden of proving customer negligence squarely on the bank. The customer's threshold burden is only to establish that the transaction was not authorised by the customer; the bank must then come forward with contemporaneous evidence — transaction-trail records, device fingerprints, call recordings, location data — to discharge the negligence burden. Paragraph 9 requires the bank to shadow-reverse the disputed amount into the customer's account within ten working days of notification, regardless of the eventual liability finding; the credit is provisional but not discretionary.

The Payment and Settlement Systems Act, 2007 — Section 4 (RBI authorisation as a precondition to operating a payment system), Section 7 (grant of authorisation) and Section 18 (directive power over payment systems) — supplies the architectural backbone on which the circular sits. The PSS Act is silent on customer-side liability; the 2017 circular fills that gap.

The roadmap — what the first twenty-four hours must produce

The procedural architecture of the first twenty-four hours is a parallel-track sequence, not a linear one. Five steps run together; the order is logical, not strictly temporal.

Step one — notify the bank in writing within three working days. The clock under the 2017 circular runs from the bank's communication of the transaction (the SMS or email alert), not from the date of debit. The notification must be in writing to the bank's branch, the bank's customer-service channel and, where the customer has registered access, the bank's internet-banking grievance portal. Verbal notification is insufficient under the circular's text. The notification triggers paragraph 6's burden allocation and paragraph 9's ten-working-day shadow-reversal obligation. Where the bank disputes the notification timestamp, the burden of proving timely notification falls on the customer; the screenshot, the email timestamp and the in-app grievance number are therefore the customer's first evidentiary artefact.

Step two — file the complaint on the National Cybercrime Reporting Portal and the 1930 helpline within the same window. The Citizen Financial Cyber Fraud Reporting and Management System, operated by the Indian Cybercrime Coordination Centre under the Ministry of Home Affairs, is the inter-bank coordination mechanism through which a fraudulent debit can be frozen at the beneficiary end before the funds are layered out of the regulated system. The portal is accessible at cybercrime.gov.in and the helpline at 1930. The CFCFRMS complaint is not itself an FIR; it is a preservation-and-freeze mechanism that runs parallel to the FIR and is, in practice, the front-line operational lever against onward layering. The freeze is not statutory in the strict sense — it operates under the RBI–MHA inter-bank coordination framework — but is the most effective real-time recovery instrument available to the customer.

Step three — register an FIR under Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 [Section 154 CrPC]. Phishing and OTP-fraud offences under Sections 66, 66C and 66D of the IT Act, 2000, read with Sections 318 and 319 of the Bharatiya Nyaya Sanhita, 2023, are cognizable. The Constitution Bench in Lalita Kumari v Govt of Uttar Pradesh, (2014) 2 SCC 1, held that registration of an FIR is mandatory under Section 154 CrPC (now Section 173 BNSS) where the information discloses a cognizable offence; preliminary inquiry is permissible only in the narrow categories the judgment identifies, and a financial-fraud FIR is not one of them. A refusal to register attracts the remedies under Section 173(4) BNSS (escalation to the Superintendent of Police) and Section 175 BNSS [Section 156(3) CrPC] (a Magistrate's order directing investigation). The FIR may be filed at the local police station, at the cyber police station for the district, or — where the offence has inter-state elements — at the National Cybercrime Reporting Portal, which routes the complaint to the jurisdictional unit.

Step four — issue Section 67C preservation requests against every relevant intermediary. Section 67C of the IT Act, 2000 requires intermediaries to preserve and retain such information as the Rules specify; the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 set the retention floor at 180 days for user information after withdrawal or cancellation of registration. The preservation request — sent by the investigating officer, but in practice initiated through the FIR and the CFCFRMS complaint — covers the bank's transaction logs, the payment-system operator's switch logs, the telecom service provider's call detail records, the mule account's KYC and onboarding records, and the device-fingerprint logs of the originating session. The preservation window is the principal evidentiary asset of the prosecution; once the 180 days have run, the data is gone.

Step five — preserve the customer-side evidence. The customer's own evidentiary record is the second pillar of the case. Screenshots of the phishing page or message, SMS-alert timestamps, call recordings or call logs of vishing calls, transaction confirmations, the bank's auto-response acknowledgments and the device's session logs are all admissible electronic records under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 [Section 65B of the Indian Evidence Act, 1872], subject to the certificate the section requires. The Supreme Court has clarified the certificate requirement in Arjun Panditrao Khotkar v Kailash Kushanrao Gorantyal (2020) 7 SCC 1 — the certificate is mandatory where the original device is not produced in court. Customer-side preservation is what permits the certificate to be issued when the matter reaches trial.

Where the four tracks converge — the position in 2026

Each of the four tracks — the bank's restitution liability under the 2017 circular, the IT Act offence track, the BNS cheating track, and the inter-bank freeze track under CFCFRMS — produces a different output and proceeds on a different timeline. Their convergence depends on disciplined documentation in the first window.

The restitution track is the fastest. Where the customer has notified within three working days and the bank cannot discharge its paragraph-6 burden, the loss passes back to the bank under bucket one; shadow-reversal under paragraph 9 occurs within ten working days; the consumer-fora line in the Punjab National Bank v Leader Valves Ltd series and the National Consumer Disputes Redressal Commission's State Bank of India v K K Misra jurisprudence has been consistent in characterising bank inaction beyond the ten-working-day window as a freestanding deficiency in service. The RBI Integrated Ombudsman Scheme, 2021 supplies the parallel escalation route — Rs 20 lakh compensation ceiling, plus Rs 1 lakh for mental anguish, with appeal to a Deputy Governor of the Reserve Bank.

The criminal track is the slowest and is principally a deterrence and information-recovery instrument rather than a restitution route. The civil-penalty track under Section 43 IT Act, recoverable before the Adjudicating Officer under Section 46 of the Act, is the middle path — uncapped damages, but a forum that has been chronically thin on the ground; only a handful of states have appointed adjudicators with a record of disposing of such matters.

The Supreme Court in Sharat Babu Digumarti v Govt of NCT of Delhi, (2017) 2 SCC 18, clarified that where the Information Technology Act and the Indian Penal Code apply to the same conduct, the IT Act being the special and later enactment must prevail to the extent of inconsistency; the Court applied that principle to a Section 67 (obscene electronic content) charge over Section 292 IPC. The principle has been extended in High Court jurisprudence to Section 66D over Section 419 IPC and to Section 66C over Section 419/420 IPC for the specific aspects covered by the IT Act provisions. In practice, the prosecution charges both — the IT Act count for the medium-specific aspect, the BNS count for the underlying deception — and the question of which prevails is addressed at the framing-of-charge stage.

The unresolved doctrinal questions

Three doctrinal questions sit unresolved at the intersection of the four tracks and continue to determine outcomes at the margin.

The first is the application of the 2017 circular to customer-authenticated-but-fraud-induced transactions — collect-request scams in which the customer has approved the UPI request, OTP-sharing scams in which the customer has read the code into the phone of a vishing caller, screen-sharing fraud in which the customer has installed remote-access software at the fraudster's prompting. Banks treat these as authorised transactions and therefore outside the circular's three-tier scheme; consumer fora have split — some treating the deceptive inducement as defeating the consent at the threshold; others treating the authentication as conclusive and the customer's recovery as confined to the offence track against the perpetrator. The RBI has not issued a clarificatory direction on this fact pattern; the question is genuinely open.

The second is the position of non-bank payment-system participants — third-party application providers, payment aggregators, prepaid-instrument issuers — under the 2017 framework. The circular addresses banks; analogous customer-protection texts for non-bank operators are thinner. Where the fraudulent debit has been routed through a non-bank operator, the customer's recovery against the operator depends on contract and on the operator's own grievance-redressal architecture; the paragraph-6 burden allocation does not apply by its terms.

The third is the cross-border dimension. The Mutual Legal Assistance Treaty route and the Section 75 extraterritoriality of the IT Act are formally available, but the operational recovery of funds that have left the regulated system through a cross-border layering chain is, in candour, rare. The residual loss in those cases sits on the customer regardless of how the liability allocation reads on paper. The MHA's coordination with foreign financial-intelligence units through the Indian Cybercrime Coordination Centre has improved the prevention picture but has not yet shifted the recovery picture.

For the customer who has notified within three working days, filed the CFCFRMS complaint, registered the FIR under Section 173 of the BNSS, and pressed the bank, the Ombudsman and the consumer commission in sequence on the strength of paragraph 6 and paragraph 9, the legal architecture is genuinely effective. For the customer who has missed the three-working-day window, who has authenticated the transaction under deception, or whose funds have left the regulated system, the architecture is real but partial. The doctrine, in either case, runs through the same statutes — the Information Technology Act, 2000 as the offence-side overlay; the Bharatiya Nyaya Sanhita, 2023 as the cheating framework; the Banking Regulation Act, 1949 and the Payment and Settlement Systems Act, 2007 as the source of authority for the RBI's customer-protection circular; and the Bharatiya Nagarik Suraksha Sanhita, 2023 as the procedural code that governs the FIR.