Credit Card Fraud in India 2026: Common Scams and the RBI Rule That Decides Who Pays
By Nitish Bharadwaj · Published Aug 24, 2026 · 7 min
Most Indian credit card fraud succeeds through social engineering — fake bank calls, phishing links, and QR scams — not technical hacking. RBI's liability framework ties your exposure directly to reporting speed: zero liability if you report within 3 working days of the bank's alert, a capped liability if you report in 4–7 days, and your bank's own policy deciding everything after that. This guide covers the scams to watch for, the exact reporting window that protects you, and what to do in the first 60 minutes after you spot an unauthorised transaction.
A phone call from someone claiming to be your bank's "fraud prevention team," warning that a suspicious transaction just hit your card and asking you to read out the OTP to "block" it, works more often than any technically sophisticated hack. It succeeds by manufacturing panic in the ninety seconds before your caution kicks in. Knowing exactly which scams work on Indian cardholders, and how RBI's liability rules split the loss between you and your bank, matters far more than a generic "never share your OTP" warning.
The Scams That Actually Work on Indian Cardholders
Card fraud in India rarely involves breaking encryption — it almost always involves convincing you to hand over what encryption is supposed to protect. Here are the five patterns that account for most cardholder complaints in 2026.
| Scam | How It Works | The Giveaway |
|---|---|---|
| Fake bank call (vishing) | Caller claims to be from your bank's fraud desk, says a transaction was flagged, and asks you to read out the OTP that just arrived to "cancel" or "verify" it. | No bank employee ever needs your OTP, PIN, or CVV on a call. A request to share one of these IS the fraud, not protection against it. |
| Phishing links (SMS/WhatsApp) | A message with a link to a fake bank-branded page — "KYC update pending," "card blocked, click to reactivate" — captures your card number and CVV when you fill the form. | The domain never matches the bank exactly. Look for lookalikes such as "hdfcbank-verify.in" instead of hdfcbank.com. |
| QR code / "quishing" scams | A QR code pasted over a legitimate one at a shop, taped to a parking meter, or sent as a fake "refund" redirects to a payment or data-capture page. | Scanning a QR code to receive money should never ask for your card PIN — a PIN authorises outgoing payments, never incoming ones. |
| Card skimming at ATMs/POS | A hidden device fitted over a card reader copies your card's stripe data during a routine swipe, later cloned onto a blank card. | A loose, wobbly, or add-on-feeling card slot is the giveaway most people never bother to check before inserting. |
| Cloned shopping sites | A lookalike e-commerce site advertising a heavily discounted product exists solely to capture card details at checkout. | A padlock icon no longer proves legitimacy — scammers buy SSL certificates too. Check the exact domain spelling, not just HTTPS. |
RBI's Liability Rule: Who Actually Pays
RBI's limited liability framework for unauthorised electronic transactions applies to credit cards, debit cards, and prepaid instruments alike. Your liability is decided almost entirely by how fast you report the fraud after your bank alerts you to it — not by how the fraud happened.
| Reporting Window | Your Liability |
|---|---|
| Within 3 working days of the bank's alert | Zero — full reversal, as long as you weren't negligent (for instance, you didn't voluntarily share your OTP with a caller). |
| 4–7 working days | Capped by your bank's board-approved policy — commonly up to ₹25,000 on credit card accounts, though the exact figure varies by issuer. |
| After 7 working days | Decided entirely by your bank's internal policy. This is the window with the least protection, which is why reporting speed matters more than anything else. |
What to Do in the First 60 Minutes
- Call your bank's 24x7 fraud helpline immediately to block the card — use the number on the back of your card or the bank's official app, never a number from the suspicious SMS itself.
- Follow up the call with a written complaint through net banking, the bank's app, or email. RBI's 3-day zero-liability clock counts from when the bank informed you of the transaction, not from when you called.
- File a parallel complaint on the National Cybercrime Reporting Portal (cybercrime.gov.in) or call 1930 — this creates an official record independent of the bank's own process.
- Get a written acknowledgment number for your complaint. You will need it if you have to escalate to the RBI Banking Ombudsman after 30 days without resolution.
- Request a fresh card and PIN rather than continuing to use the compromised number, even once the disputed transaction is reversed.
Everyday Habits That Close Most of These Gaps
- Set a low default transaction limit and raise it only when you actually need to — most banking apps let you do this in seconds; see our guide on lowering your contactless transaction limit for exactly how.
- Turn on SMS or app alerts for every transaction, including failed attempts — a failed attempt is often the first sign someone already has your card details.
- Avoid saving full card details on unfamiliar shopping sites. RBI-mandated tokenisation means your actual card number no longer sits on a major platform's servers once you use "save card" there.
- If you hold more than one card, keep a separate, lower-limit card set aside specifically for online spending — it caps your worst-case exposure if that card alone is compromised.
When the Bank Still Says No
If your bank rejects a genuinely unauthorised claim or drags the resolution past 30 days, you have two formal routes: a chargeback dispute through the card network for the specific transaction (our credit card chargeback guide covers the exact process and documentation banks expect), or an escalation to the RBI Banking Ombudsman citing the unresolved complaint. Keep every complaint reference number and written communication — banks that back down usually do so once a customer shows they know the actual RBI timeline rather than just being upset.
It's also worth knowing what RBI has tightened on the sales side of card fraud: banks can no longer push you into an unsolicited card upgrade or a fresh card sale over a single unsolicited call, under the one-click credit card sales ban — a rule introduced for the same reason phishing works, because a rushed decision on a call is exactly when mistakes happen.
Frequently Asked Questions
Does the RBI zero-liability rule apply to debit cards and UPI too?
Yes. The same limited-liability framework covers debit cards and prepaid instruments. UPI fraud follows a similar dispute process but runs through NPCI in coordination with your bank.
Can a bank deny my claim just because I read out an OTP?
Not automatically. If the transaction was genuinely unauthorised and you reported it within the protected window, OTP-sharing alone isn't legally sufficient proof of negligence — though banks will often argue otherwise, so be ready to escalate.
How long does a bank take to reverse a fraudulent transaction?
Banks typically issue a provisional "shadow reversal" within about 10 working days of a valid complaint, pending their internal investigation, with final resolution to follow.