By — Prisha Gakhar
Abstract
Digital banking has gained quick traction in India due to the development of technologies like internet banking, mobile banking and Unified Payments Interface (UPI), making financial transactions faster, more comfortable and increasingly ingrained in everyday life. The RBI statistics presented to the Ministry of Finance in the Lok Sabha session showed that UPI fraud instances almost doubled from 7.25 lakh in FY 2022-23 to 13.42 lakh in FY 2023-24. Industry estimates say UPI fraud in India is estimated to cause losses of ₹1,000 crore every quarter. The magnitude of such losses brings up a serious question of who should bear responsibility for digital payment fraud.
Introduction
UPI transactions rely on authentication: a consumer inputs their UPI PIN or otherwise authorises a transaction, which creates a record that purports to verify authorisation. But in many frauds, the clients are tricked into paying themselves. A victim might enter their PIN, scan a QR code or authorise a transaction thinking they are fulfilling a bank request, and receive money or secure their account. The transaction is technically allowed, but the customer has been fooled into giving consent.
This presents a severe gap in the existing system of electronic banking fraud in India. This article discusses the adequacy of the existing distribution of culpability in protecting UPI users and the need for banks and other financial institutions to be made more liable for transactions that are permitted in form but fraudulent in reality.
RBI Guidelines on Frauds in Digital Banking
The regulation of digital banking transactions in India is a mix of the Banking Regulation Act, 1949, Payment and Settlement Systems Act, 2007, Information Technology Act, 2000 and the broader legal framework of fraud and cybercrime. The circular on Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, issued by the RBI on 6 July 2017, which came into force this year, lays down an important framework to determine the level of customer liability in cases of electronic banking fraud. The framework makes a broad distinction between imprudence by the bank, breaches by third parties and negligence by the consumer.
(1) Zero liability of the customer. In the case of an unauthorised transaction due to negligence or deficiency on the side of the bank, a customer may have no culpability. However, the customer is required to inform the bank of the illegal transaction within the stipulated period.
(2) Restricted liability. Where the fraud arises from a third-party breach, and the bank and the customer have not been directly liable, the customer’s culpability may be reduced, depending on how quickly the transaction is reported.
(3) Negligence of customer. If the loss is due to negligence on the part of the client, such as sharing passwords, OTPs or banking credentials with unauthorised persons, the customer may have to absorb the loss until the fraud is notified to the bank. In these circumstances, the customer is regarded as if he has compromised the security mechanisms used to authenticate the transaction.
The RBI has also considered further measures to boost consumer protection, given the increasing sophistication of digital fraud. The suggested remedies include partial reimbursement to victims of some low-value digital crimes, especially those employing UPI, debit cards and mobile wallets, and higher evidential duties on banks when they deny fraud claims.
The Issue of Authorisation in UPI Fraud
The fundamental problem with UPI fraud is that the distinction between an “authorised” and “unauthorised” transaction does not necessarily translate into a distinction between legitimate and fraudulent transactions. Imagine a fraudster posing as a bank official and telling a customer that their bank account is in danger. The scammer tells the consumer to transfer money to an allegedly secure account. The customer opens their UPI app, enters the amount, selects the receiver and enters their UPI PIN. From a technical point of view alone, the payment has been allowed.
But the customer never intended to hand over money to a fraudster. In reality, the consumer has not consented to the fraudulent intent of the transaction and has thus allowed the mechanism of payment.
This is especially true in the case of social-engineering fraud. UPI fraud doesn’t always mean that the fraudster would get the customer’s password or OTP unknowingly. Instead, the fraudster may trick the customer into utilising the authentication technique for themselves.
Therefore, adopting authentication as definitive proof of permission may impose an undue burden on consumers. It risks turning sophisticated deceit into a customer negligence finding only because the customer clicked “pay”.
The issue, then, is not just whether the customer technically authorised the transaction. It should also be whether the customer was negligent and whether the bank or other payment intermediaries might reasonably have discovered or stopped the fraudulent transaction.
Case Law on Unauthorised Banking Fraud
Indian courts have been increasingly looking into the division of culpability between banks and clients in cases of electronic banking fraud.
In Suresh Chandra Singh Negi v. Bank of Baroda, the Allahabad High Court examined the issue of consumer negligence in contested illegal transactions. The judgment said the burden of proof of carelessness rests on the bank if a consumer disputes an illegal transaction. In contrast, the bank may not be liable where technical records reveal that the customer did genuinely authorise the transaction.
Similarly, in Hare Ram Singh v. Reserve Bank of India and Ors., the court highlighted the duty of the banks to take reasonable care and act with promptitude on the report of cyber fraud. Where the consumer discloses the fraud promptly, and the customer has not been grossly negligent, the concept of zero customer liability may force the bank to reimburse the loss.
Such incidents indicate that the protection of customers is not limited to the question of whether the customer’s credentials have been utilised. The actions of the bank, the circumstances of the transaction and the reaction of the consumer on discovering the fraud are all relevant to establish responsibility.
Do Banks Need to Be More Responsible?
In specific types of UPI fraud, there is a compelling rationale for enhanced accountability on the part of banks and financial institutions. Banks are not simply facilitators in digital payments. They have information and technology capabilities that the average customer does not have.
Banks can detect irregular transaction patterns, suspicious beneficiary accounts, repeated transfers and other signs that could indicate fraud. They are also better able to monitor accounts associated with suspicious or potentially fraudulent activity.
This sets out an important rule for the allocation of liability: the liability should follow the party best able to avoid the loss, when appropriate.
But this does not mean banks should be made absolutely liable for all fraudulent UPI transactions. Customers also have responsibilities to secure their UPI PINs, passwords and other authentication credentials and to respond in a timely manner when fraud is identified.
A more acceptable paradigm would be one of progressive liability. Where the customer has been misled despite reasonable care having been taken, reimbursement should be more readily attainable. In cases where a bank has not detected any evident signs of suspicious conduct, the bank should bear more responsibility.” In contrast, customer culpability may still be justified if the client has wilfully provided credentials or ignored obvious warnings.
Conclusions and Way Forward
India’s UPI fraud needs a regulatory framework that moves to a more complex approach, where the focus is on distinguishing between transactions that are actually unlawful and those that are legally authorised but induced through deception. Authentication should not be taken as inherently indicating informed permission, particularly when customers are being misled using sophisticated social engineering techniques.
When rejecting fraud claims, banks should be forced to provide relevant transaction records, including authentication logs, device information, and any available technical proof. This would allow culpability to be assessed based on the circumstances around the transaction rather than the use of the customer’s credentials.
A more suitable model would be one of proportionate liability. Where clients are defrauded despite taking reasonable care, they should be able to recover their money more easily; and banks should be held more accountable where they do not spot or respond to clear signs of fraud. At the same time, clients who wilfully expose passwords or ignore explicit warnings should also face some of the blame.
Ultimately, UPI fraud shows that technical approval is not the same as real consent. Therefore, greater accountability can be justified for banks, but not by way of absolute obligation. Instead, India’s system should allocate losses on the basis of negligence and the respective ability of clients and financial institutions to avoid the fraud. It would improve consumer safety, without affecting the efficiency and ease of use that have made UPI the backbone of India’s digital payments ecosystem.
About the Author: Prisha Gakhar is a third-year law student at Jindal Global Law School, with a keen interest in economics, IPR and corporate law.
Image Source: https://razorpay.com/blog/upi-frauds-types-tactics/

