An unexpected IMPS debit needs a controlled response. First protect access to the bank account and connected credentials. Then report the transaction to the bank or payment provider through its official complaint channel. If the event may involve financial cyber fraud, consider the National Cyber Crime Reporting Portal and 1930 as a separate route. RBI complaint escalation is not a substitute for the first report to the regulated entity.
This guide is for a suspected unauthorised IMPS transaction or account compromise. It keeps four questions separate: what the IMPS rail shows, whether the account holder authorised the transfer, what the recipient or merchant claims, and which institution should receive each complaint. An authorised payment that is later disputed is not automatically the same as an unauthorised electronic-banking transaction.
What IMPS does—and what it does not establish
IMPS is a transfer rail. An official bank description identifies IMPS as a method for transferring funds, not as the party that decides whether a particular debit was authorised or whether a merchant’s service was supplied. The transaction record may help identify the date, amount, reference and account involved, but the rail alone does not determine the full dispute outcome.
Keep the following roles distinct:
- Provider or bank: receives the transaction report, secures access, investigates the account event and records the complaint.
- IMPS rail: describes the transfer mechanism used for the debit.
- Recipient: may be the account or institution shown in the transaction details. Its identity should be taken from the bank record, not guessed from a description.
- Merchant or service claim: may concern a purchase, account credit or other authorised activity. It does not by itself prove or disprove account compromise.
- RBI route: provides an escalation framework for eligible complaints after the provider-first process.
- NCRP and 1930: provide a separate official route for financial cyber-fraud reporting.
Do not describe the debit as a merchant dispute merely because a merchant name appears in the narration. Do not describe it as cyber fraud merely because the payment was unexpected. Record what is known, what is disputed and what remains unknown.
Secure access before investigating the payment
If credentials may have been exposed, security comes before a detailed reconstruction. Use a trusted route to contact the bank, rather than responding to a message, call or link that may be connected with the incident. Avoid sharing passwords, one-time passwords, card details, PINs or remote-access permissions with anyone claiming to arrange a refund.
- Contact the bank or payment provider through its official channel and state that an IMPS transaction is suspected to be unauthorised.
- Ask for the account, digital-banking access and relevant payment instruments to be secured in accordance with the provider’s process.
- Change affected credentials using the provider’s trusted access route. If the same password was reused elsewhere, change it on those services as well.
- Preserve the original transaction notification, account statement entry and relevant security alerts before deleting messages or resetting devices.
- Check whether any unfamiliar beneficiary, device, login, mandate or profile change appears in the account records.
The aim at this stage is to reduce further exposure and create a clear first report. Do not wait for a merchant response before notifying the bank where an unauthorised debit or compromised credentials are suspected.
Separate an unauthorised transaction from an authorised dispute
The key question is whether the account holder authorised the electronic-banking transaction, not simply whether the result was disappointing. An unauthorised transaction report concerns a payment the account holder says they did not approve. An authorised dispute may concern a payment the account holder made or approved but later questions, such as the recipient, value, service, crediting or cancellation.
| Issue | First description to use | Evidence to preserve |
|---|---|---|
| Account holder did not approve the IMPS debit | Suspected unauthorised electronic-banking transaction | Statement entry, alert, time, amount, reference and access-security details |
| Account holder approved the transfer but disputes the recipient or service | Authorised transaction dispute | Order or account records, correspondence, promised service details and payment reference |
| Credentials or device may have been compromised | Suspected account compromise | Unfamiliar login or beneficiary information, security alerts and device observations |
| Possible financial cyber fraud | Potential cyber-fraud report | Transaction data, communications, identifiers and a chronological account |
These categories can overlap in an investigation, but the first report should not combine them carelessly. Explain the facts in plain language: what you recognise, what you do not recognise, what you authorised, and what you cannot yet confirm.
What to include in the first bank report
A useful IMPS official complaint is specific enough for the provider to locate the transaction and understand the security concern. Use the provider’s official complaint channel and keep the acknowledgement, reference number and submission time.
- Account or payment relationship details requested by the provider, without sending unnecessary credentials.
- The exact debit amount and currency shown in the record.
- The date and time displayed by the bank.
- The IMPS reference or transaction identifier.
- The recipient or beneficiary details exactly as displayed.
- A direct statement of whether you authorised the payment.
- The date you noticed the debit and the date you first reported it.
- Any suspected credential, device, beneficiary or access change.
- Copies or secure records of alerts, statements, messages and relevant communications.
- A request for written acknowledgement and the next step in the provider’s complaint process.
Do not alter screenshots or rewrite transaction records in a way that removes context. If an image is needed, retain the original file and note when it was captured. The bank’s own records remain important even when a notification is incomplete.
Map each issue to the correct remit
One report may need more than one route, but each route should carry the question it is equipped to address. A recipient or merchant may be relevant to an authorised dispute; it is not a replacement for reporting an unauthorised debit to the bank. The bank or provider should receive the first account-security and transaction complaint.
| Question | Primary route | What to submit |
|---|---|---|
| Was an IMPS debit made from the account and was it authorised? | Bank or payment provider | Transaction identifiers, authorisation position, account-security facts and evidence |
| What does the recipient or merchant say about an authorised payment? | Recipient or merchant, while keeping the provider complaint open | Payment reference, order or account context and the specific disputed outcome |
| Has the provider handled the complaint through its process? | Provider complaint or grievance channel | Original complaint reference, correspondence, dates and unresolved points |
| Is escalation to the RBI Ombudsman framework being considered? | RBI route after the provider-first process | Provider complaint details, response or lack of response and supporting records |
| Could the event be financial cyber fraud? | NCRP or 1930 | Transaction data, chronology, suspected communications and identifiers |
Keep the reference numbers from each route separate. A cybercrime report does not replace a bank complaint. An RBI escalation does not replace immediate account-security action. A merchant response does not close an unauthorised-transaction report unless you decide, based on the facts, that the dispute has changed.
When the cybercrime route is relevant
The National Cyber Crime Reporting Portal is an official route for cybercrime reporting, and 1930 is identified for financial fraud. Consider this route where the facts indicate possible online financial fraud, credential theft, social engineering, unauthorised access or related digital activity. Use the factual record available at the time; do not wait for a complete theory of the incident.
A cybercrime report should be chronological and precise. State when you noticed the debit, what the account record shows, what access or communication appeared unusual, when the bank was contacted and which reference numbers were issued. Attach or preserve relevant records as requested by the official process. Avoid naming a person or organisation as responsible unless your evidence supports that description. “Unknown recipient” or “suspected compromise” may be more accurate than an unsupported accusation.
Where there is no indication of cyber-enabled fraud, the bank’s complaint process may still be the relevant first route for an unauthorised electronic-banking report. The two routes are not mutually exclusive when the facts support both.
How RBI escalation fits after the provider complaint
The RBI Ombudsman framework is an escalation route for eligible complaints involving regulated entities after the provider-first process. It should be considered only after the relevant bank or provider has received the complaint and its response, or the applicable provider process has otherwise been followed. The RBI material should be checked for the framework and conditions that apply to the complaint.
Prepare a clean escalation file:
- Record the provider’s name and the official complaint reference.
- Set out the transaction facts without mixing an unauthorised claim with an authorised service dispute.
- Include the dates of the first report, follow-ups and any response.
- Explain the unresolved issue in one or two precise sentences.
- Attach relevant records in an ordered sequence and keep the originals.
- Check the RBI route for eligibility and process requirements before submitting.
RBI escalation does not guarantee a particular result, reversal or recovery. It is a distinct complaint path that follows the provider-first stage.
Build an evidence file without exposing yourself further
Create a simple chronology with four columns: date and time, event, source of the information and action taken. Include the bank notification, statement entry, complaint reference, contact channel and any suspected security event. Preserve email headers or message details where relevant, but do not forward sensitive credentials or one-time passwords.
Separate evidence into three folders or clearly labelled groups:
- Transaction evidence: statement entries, IMPS references, amounts, times and recipient details.
- Access evidence: login or security alerts, unfamiliar beneficiary changes, device observations and credential-compromise indicators.
- Complaint evidence: bank acknowledgements, provider replies, NCRP or 1930 details and any RBI submission records.
Write down uncertainty. For example, distinguish “I did not authorise this debit” from “I do not recognise the recipient name”. The first is an authorisation statement; the second is an identification issue. This distinction helps the receiving institution investigate without assuming facts that have not been established.
Follow-up without making unsupported promises
Monitor the account through a trusted channel and keep a record of new alerts or debits. Follow the bank’s instructions for replacing credentials, securing access and responding to its questions. If the provider asks for clarification, answer the specific question and retain the submission.
Do not promise yourself or anyone else that a debit will be reversed, that funds will be recovered, that an account will be frozen, or that a complaint is eligible for a particular escalation. Those outcomes depend on the facts, the provider’s process and the applicable framework. A careful report is useful even when the final outcome is not yet known.
For related routes, use UPI and recovery guidance, RBI CMS gaming payment complaint guidance or financial cyber-fraud and 1930 guidance. These links should supplement, not replace, the first bank or provider report.
Frequently asked questions
What should be secured first?
Secure access to the bank account and connected payment credentials first through the provider’s official channel. Report the suspected unauthorised IMPS debit at the same time, preserve the transaction record and avoid sharing passwords, one-time passwords or remote access with anyone offering help.
How is an unauthorised transaction separated from an authorised dispute?
An unauthorised transaction is one the account holder says they did not approve. An authorised dispute concerns a payment the account holder approved but later questions, such as the recipient, amount, service or account credit. State which position applies and do not treat an unfamiliar merchant name as proof of unauthorised access.
Which evidence belongs in the first report?
Include the amount, date, time, IMPS reference, recipient details as displayed, authorisation position, date noticed, suspected security facts and any relevant alerts or statements. Add the provider complaint reference after submission and preserve original records without exposing passwords or one-time passwords.
When is the cybercrime route relevant?
Consider the National Cyber Crime Reporting Portal or 1930 when the facts may involve financial cyber fraud, credential theft, social engineering, unauthorised access or related digital activity. This is separate from the bank complaint, which remains the first route for securing the account and reporting the transaction.
When can the RBI Ombudsman route be considered?
It can be considered for an eligible complaint after the relevant regulated entity has received and handled the provider-first complaint. Keep the original reference, dates, response or lack of response and supporting records, then check the RBI framework and conditions before escalating.