A phishing or UPI fraud is rarely one wrong. Someone impersonates a bank executive, sends a phishing SMS or places a vishing call, extracts credentials and one-time passwords, and moves money out through UPI or IMPS before the account holder realises what has happened. For the victim, the legal position sits across three systems at once: the criminal law that punishes the fraudster, the reporting machinery that can freeze the money in transit, and the banking-regulation rules that decide who ultimately bears the loss. This explainer sets out what each of those offers a defrauded customer, drawing on the substantive offences under the Bharatiya Nyaya Sanhita and the Information Technology Act, the procedure under the Bharatiya Nagarik Suraksha Sanhita, the evidence rules under the Bharatiya Sakshya Adhiniyam, and the Reserve Bank of India's 2017 circular on customer liability.
What the Fraudster Has Done, in Law
The conduct in a typical UPI phishing case is not a single offence but a cluster of them, prosecuted together. The two frameworks that matter are the general criminal law under the Bharatiya Nyaya Sanhita, 2023 (BNS) and the specific cyber offences under the Information Technology Act, 2000.
Cheating and cheating by personation
Section 318(1) of the BNS defines cheating as deceiving a person and thereby fraudulently or dishonestly inducing that person to deliver property, or doing an act that causes or is likely to cause wrongful loss or wrongful gain. The Explanation makes clear that dishonest concealment of facts is itself a deception. In a phishing case the deception is the false pretence of being a bank official, and the inducement is obtaining credentials and OTPs under that pretence. Cheating is punishable with imprisonment up to three years, or fine, or both, and is a cognizable and bailable offence.
The more serious variant is Section 319, cheating by personation, which applies where a person cheats by pretending to be someone else, or by representing that he is a person other than he really is. Pretending to be a bank executive falls squarely within it. It carries a higher maximum, imprisonment up to five years, or fine, or both, and is likewise cognizable and bailable. Where more than one person is involved, Section 61 (criminal conspiracy) and Section 3(5) (acts done by several persons in furtherance of common intention) allow each participant to be held liable for the whole of the criminal act, even one who executed only a part of it. These provisions replace the old IPC Sections 419, 420, 120B and 34.
The cyber offences
The IT Act adds offences aimed specifically at conduct carried out through computer resources. Three are central to a phishing or UPI fraud.
Section 66C: "Whoever, fraudulently or dishonestly make use of the electronic signature, password or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh."
Section 66C is the identity-theft offence. Using a victim's OTP or password to access the account and move funds is the core violation, and the offence is complete on such use, without proof of actual loss. Section 66D punishes cheating by personation "by means of any communication device or computer resource", again with imprisonment up to three years and fine up to one lakh rupees. A phishing SMS and a vishing call are both communication devices within its meaning, so the section applies directly. Section 66 covers computer-related offences done dishonestly or fraudulently, drawing on the prohibited acts listed in Section 43 (including securing access to a computer or account without permission), and carries imprisonment up to three years or fine up to five lakh rupees. All three are cognizable and bailable.
Two further IT Act provisions matter to a victim seeking redress rather than to the prosecution. Section 43A makes a body corporate that handles sensitive personal data liable to pay compensation where it is negligent in maintaining reasonable security practices and thereby causes wrongful loss, a civil rather than criminal liability. Section 75 extends the Act to offences committed outside India where the conduct involves a computer, computer system or computer network located in India, which is what allows Indian law to reach an offshore fraudster who targets an Indian account.