INDEPENDENT RESEARCH

Dated evidence · commercial links labelled · 18+ · no winning or recovery promise

CASINOCHECKINDIA / भारतहिन्दीCASINO DIRECTORY

Net Banking Unauthorised Debit in India: What to Do

Respond to a suspected Net Banking unauthorised debit in India. Secure access, contact your bank, preserve evidence and separate RBI and NCRP routes.

PUBLISHED: 30 August 2026REVIEWED: 30 August 2026INDIA · en-IN

A Net Banking unauthorised transaction needs a fast, orderly response. The first objective is to protect access to the bank account and stop further use of compromised credentials. The next is to report the disputed debit to the bank or other regulated provider through its official complaint channel. If the incident appears to involve financial cyber fraud, the National Cyber Crime Reporting Portal and 1930 are separate reporting routes. The RBI Ombudsman framework is a further escalation route for eligible complaints after the provider-first process; it is not a substitute for the first report to the bank.

This guide is for a suspected debit that you say you did not authorise. It does not decide whether a transaction was fraudulent, whether a bank will reverse it, or whether any particular complaint is eligible for escalation. Keep the facts precise, avoid guessing how the credentials were obtained, and use only official channels. Review date: 30 August 2026.

Secure the account before investigating the debit

Use a device and connection you consider safe. Contact the bank using the official website, mobile application, card or account documentation, or another channel independently verified as belonging to the provider. Do not rely on a message, telephone number, payment request or link contained in a suspicious communication.

Tell the provider that you suspect a Net Banking account compromise and an unauthorised electronic-banking transaction. Ask what immediate protective action is available for the account and online-banking access. Follow the provider’s security instructions, including any applicable credential or access changes. If you suspect that a device, email account or mobile number connected with banking access is compromised, secure those services through their legitimate providers as well.

  1. Stop engaging with the suspected scammer or sender.
  2. Do not approve a new sign-in, beneficiary, payment or authentication request merely because someone claims it is needed for a refund.
  3. Record the time at which you first noticed the issue and the time at which you contacted the bank.
  4. Keep confirmation numbers, complaint references and copies of communications.

Report the transaction to the bank or regulated provider

The bank or relevant regulated provider is the primary place to report a disputed account debit. State that the transaction is unauthorised, if that is your position, and ask for the complaint to be recorded. Include the account identifier in a suitably masked form where possible, the transaction date and time, amount, reference or narration, and the channel shown in the account record.

Ask the provider to distinguish the transaction report from any general request for information. If the provider uses a dedicated unauthorised-transaction or electronic-banking reporting process, follow that process and retain the acknowledgement. If you are reporting by telephone, ask how to submit supporting material and how to obtain a written complaint reference.

The RBI framework on unauthorised electronic-banking transactions addresses reporting and liability principles. It does not mean that every transaction described as disputed will automatically be reversed. The provider must examine the account record, authentication details, alerts, reporting information and other relevant circumstances.

Read the RBI material on unauthorised electronic-banking transactions alongside the provider’s complaint instructions.

Separate an unauthorised transaction from an authorised dispute

Use accurate language. An unauthorised transaction means you state that you did not initiate, approve or permit the payment or access in question. An authorised dispute is different: you may have made or approved the payment but dispute the recipient, amount, service, delivery, cancellation, refund or description. These categories can lead to different investigation paths and evidence requirements.

IssueWhat to stateWhat not to assume
Suspected unauthorised debitYou did not authorise the transaction and want the provider to record and investigate it.Do not assume that reporting alone establishes fraud or guarantees a reversal.
Authorised merchant or recipient disputeYou authorised the payment but dispute the recipient, amount, service, refund or other performance issue.Do not describe an authorised payment as unauthorised simply because the outcome is unsatisfactory.
Unknown transaction descriptionThe narration or recipient is unfamiliar and you need the provider to identify the transaction.An unfamiliar description alone does not prove that the debit was unauthorised.
Credential compromise without a confirmed debitYou suspect access credentials may have been exposed and request security guidance.Do not wait for a debit before securing access if the risk is immediate.

If you are unsure which category applies, describe exactly what you remember: whether you entered credentials, approved an authentication request, shared information, or noticed the transaction only after it appeared. The bank can record the account of events and explain its process. Do not alter the facts to fit a preferred complaint category.

Prepare the first evidence packet

The first report should be usable without unnecessary speculation. Preserve original records where possible and create a simple chronology. Evidence should show what happened, when you noticed it, what appears in the account record, and when you notified the provider.

Do not send complete passwords, one-time authentication secrets, security answers or recovery codes in a complaint. If a screenshot is necessary, redact unrelated account numbers, balances, personal identifiers and other information not needed for the investigation. Keep the unredacted original securely, but share it only through a verified provider or official reporting channel when requested.

Keep the remits separate

Several organisations may appear relevant, but they perform different functions. The bank or regulated provider handles the account-level complaint and its investigation. The recipient or merchant may be relevant to an authorised dispute or factual clarification, but contacting a recipient does not replace the bank report. RBI escalation is a complaint route concerning the regulated provider after the provider-first process. NCRP and 1930 are cybercrime reporting routes for suspected financial fraud.

RoutePrimary purposeWhat to includeWhat it does not replace
Bank or regulated providerRecord and investigate the disputed debit and account-security issue.Transaction details, chronology, security concerns and provider complaint reference.It does not become an RBI Ombudsman complaint merely because it was reported to the bank.
Recipient or merchantClarify an authorised payment, recipient identity, service issue or refund position where relevant.Payment reference and the narrow factual issue.It does not replace a suspected unauthorised-transaction report to the bank.
RBI Ombudsman frameworkProvide an escalation framework for eligible complaints against regulated entities after the provider-first process.Provider complaint details, response or status, chronology and supporting records.It does not replace the initial bank report or determine every private dispute.
NCRP and 1930Report suspected financial cyber fraud through the official cybercrime route.Transaction information, contact details requested by the portal or helpline, chronology and available evidence.It does not replace the bank’s account complaint or an RBI provider complaint.

When the cybercrime route is relevant

Use the official National Cyber Crime Reporting Portal and consider the 1930 financial-fraud helpline when the facts indicate suspected online financial fraud, such as a deceptive request, compromised online access or a payment made through a cyber-enabled incident. Report the matter to the bank as well. These routes have different purposes, so a cybercrime report should not be treated as a replacement for the bank’s unauthorised-transaction complaint.

Give the cybercrime report the same factual chronology used for the bank, updated with any new reference numbers. Do not present an unverified identity, motive or recovery claim as fact. If you do not know how access was obtained, say so. If the debit is only an unfamiliar merchant entry and there is no indication of cyber fraud, first clarify the transaction with the bank and assess whether it is an authorised dispute.

Escalate through the provider-first process

Keep the provider’s complaint reference and monitor the response through an official channel. If the provider asks for further information, answer the specific questions and retain proof of submission. If the response does not resolve the complaint, or if the provider process has otherwise reached the point at which escalation may be considered, review the RBI Ombudsman framework.

Eligibility, timing and the information required for an RBI Ombudsman complaint depend on the applicable framework and circumstances. Do not assume that a bank complaint is automatically eligible for Ombudsman escalation, or that an Ombudsman route will produce a particular result. Present the provider complaint, response or lack of resolution, dates, transaction details and relevant evidence in a consistent order.

For a practical distinction between the RBI route and cybercrime reporting, see RBI complaint escalation and financial cyber fraud reporting.

Follow-up without weakening the record

Use one chronology and update it rather than creating conflicting versions. Note every provider contact, including date, channel, reference number, request made and response received. If you receive a call claiming to represent the bank, independently verify it before sharing information or approving an action. A genuine complaint process should not require you to disclose a password or an authentication secret.

Do not close a complaint merely because an unfamiliar party promises a recovery, asks for an advance payment, or requests remote access. Do not make additional payments to obtain a supposed refund. If new facts emerge, send them through the existing official complaint reference and, where relevant, update the cybercrime report.

Questions to ask before submitting

For related account-payment recovery information, use payment recovery guidance. The correct route depends on the facts recorded by you and the relevant provider; no route guarantees reversal, recovery, freezing of funds or a particular legal or regulatory outcome.

FAQ

What should be secured first?

Secure the affected banking access and report the suspected compromise to the bank through a verified official channel. Follow the provider’s security instructions, avoid sharing passwords or authentication secrets, and record when you noticed the issue and when you reported it.

How is an unauthorised transaction separated from an authorised dispute?

An unauthorised transaction is one you state that you did not initiate, approve or permit. An authorised dispute involves a payment you made or approved but whose recipient, amount, service, refund or other aspect you challenge. State the facts accurately rather than choosing the category that seems more likely to succeed.

Which evidence belongs in the first report?

Include the transaction date, time, amount, reference or narration, the affected account or profile, when you noticed the debit, a factual chronology, and any relevant alerts or communications. Add the bank complaint reference after reporting. Mask unnecessary personal or account information and never send passwords or authentication secrets.

When is the cybercrime route relevant?

The NCRP and 1930 route is relevant when the facts indicate suspected financial cyber fraud, such as deceptive online activity or compromised online access. Report to the bank as well, because cybercrime reporting is separate from the provider’s account complaint and any RBI escalation.

Can an RBI complaint replace the first bank report?

No. The bank or relevant regulated provider is the first complaint route for the disputed debit. The RBI Ombudsman framework is an escalation route for eligible complaints after the provider-first process. Review the applicable framework and keep the provider complaint record before considering escalation.