Doctrine deep-dive? Trace it across statutes and judgments with LITT.
Size
0%
Lex-O-Pedia

What Are Your Rights If You Are a Victim of UPI or Phishing Fraud?

Phishing and UPI fraud engage criminal law, cyber law and banking regulation at once. A map of the offences a fraudster commits, how to report the fraud, and the RBI rules that decide whether the victim or the bank bears the loss.

0 / 0 · 0 min left
300 wpm

A phishing or UPI fraud is rarely one wrong. Someone impersonates a bank executive, sends a phishing SMS or places a vishing call, extracts credentials and one-time passwords, and moves money out through UPI or IMPS before the account holder realises what has happened. For the victim, the legal position sits across three systems at once: the criminal law that punishes the fraudster, the reporting machinery that can freeze the money in transit, and the banking-regulation rules that decide who ultimately bears the loss. This explainer sets out what each of those offers a defrauded customer, drawing on the substantive offences under the Bharatiya Nyaya Sanhita and the Information Technology Act, the procedure under the Bharatiya Nagarik Suraksha Sanhita, the evidence rules under the Bharatiya Sakshya Adhiniyam, and the Reserve Bank of India's 2017 circular on customer liability.

What the Fraudster Has Done, in Law

The conduct in a typical UPI phishing case is not a single offence but a cluster of them, prosecuted together. The two frameworks that matter are the general criminal law under the Bharatiya Nyaya Sanhita, 2023 (BNS) and the specific cyber offences under the Information Technology Act, 2000.

Cheating and cheating by personation

Section 318(1) of the BNS defines cheating as deceiving a person and thereby fraudulently or dishonestly inducing that person to deliver property, or doing an act that causes or is likely to cause wrongful loss or wrongful gain. The Explanation makes clear that dishonest concealment of facts is itself a deception. In a phishing case the deception is the false pretence of being a bank official, and the inducement is obtaining credentials and OTPs under that pretence. Cheating is punishable with imprisonment up to three years, or fine, or both, and is a cognizable and bailable offence.

The more serious variant is Section 319, cheating by personation, which applies where a person cheats by pretending to be someone else, or by representing that he is a person other than he really is. Pretending to be a bank executive falls squarely within it. It carries a higher maximum, imprisonment up to five years, or fine, or both, and is likewise cognizable and bailable. Where more than one person is involved, Section 61 (criminal conspiracy) and Section 3(5) (acts done by several persons in furtherance of common intention) allow each participant to be held liable for the whole of the criminal act, even one who executed only a part of it. These provisions replace the old IPC Sections 419, 420, 120B and 34.

The cyber offences

The IT Act adds offences aimed specifically at conduct carried out through computer resources. Three are central to a phishing or UPI fraud.

Section 66C: "Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh."

Section 66C is the identity-theft offence. Using a victim's OTP or password to access the account and move funds is the core violation, and the offence is complete on such use, without proof of actual loss. Section 66D punishes cheating by personation "by means of any communication device or computer resource", again with imprisonment up to three years and fine up to one lakh rupees. A phishing SMS and a vishing call are both communication devices within its meaning, so the section applies directly. Section 66 covers computer-related offences done dishonestly or fraudulently, drawing on the prohibited acts listed in Section 43 (including securing access to a computer or account without permission), and carries imprisonment up to three years or fine up to five lakh rupees. All three are cognizable and bailable.

Two further IT Act provisions matter to a victim seeking redress rather than to the prosecution. Section 43A makes a body corporate that handles sensitive personal data liable to pay compensation where it is negligent in maintaining reasonable security practices and thereby causes wrongful loss, a civil rather than criminal liability. Section 75 extends the Act to offences committed outside India where the conduct involves a computer, computer system or computer network located in India, which is what allows Indian law to reach an offshore fraudster who targets an Indian account.

Legal Wires Pro

Read the full explainer

This is a members' explainer. Pro opens the complete breakdown, section by section, plus ad-free reading across the site.

Get ProAlready a member? Sign in
Written by Sushant Shukla
Follow the thread

Questions about this piece

AI-powered, citation-anchored. Pick a question to see the answer.

  1. 01
  2. 02
  3. 03
Powered by LITT AI · Educational explainer, not legal advice. Verify before relying.
1.5×

More in

Legal Wires

Legal Wires

Stay ahead of the legal curve. Get expert analysis and regulatory updates natively delivered to your inbox.

Success! Please check your inbox and click the link to confirm your subscription.