Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
If you’ve been locked out of Google Pay, see unfamiliar transactions, or got an alert for a device you don’t recognize, your account may be compromised — and every minute matters, since UPI transfers are near-instant and hard to reverse once completed. Here’s exactly what to do, in order.
Google Pay itself doesn’t store your money — it’s a UPI interface to your bank account, so “hacking” almost always means someone obtained your UPI PIN, OTP, or got you to approve a collect request or screen-sharing session, not a direct breach of Google’s servers. Common routes: phishing links imitating Google Pay or your bank, fake customer-care numbers found via a Google search, screen-sharing apps like AnyDesk installed after a “support” call, and SIM swap fraud that lets someone receive your OTPs.
Call your bank’s 24×7 helpline (the number on your card or passbook, never one found via a random Google search) and ask them to block UPI transactions on your account right away — this stops further damage faster than anything you can do inside the Google Pay app itself.
Follow up the call with a written complaint (email or the bank’s app) listing every unauthorized transaction with date, time, and amount — this written record is what starts your formal dispute and liability-protection timeline.
Report the fraud at cybercrime.gov.in or call the 1930 helpline — this can trigger a fund freeze at the receiving end if you act quickly, and generates the acknowledgment number banks often ask for.
Go to myaccount.google.com/security, change your password, review “Your devices” for anything unfamiliar and sign it out, and enable 2-step verification if it isn’t already on.
Once your bank confirms the account is safe and you’ve secured your Google account and phone number, set up a new UPI PIN — never reuse the old one.
Don’t assume Google Pay’s own “support” can freeze a transaction — UPI is bank-rail infrastructure, and only your bank (or the receiving bank, prompted by NPCI/your cybercrime complaint) can actually intervene on a completed transfer. The app is the front door; your bank is where the actual recovery process happens.
| Situation | What to Do |
|---|---|
| Someone accessed your Google account/device without your knowledge | Secure the Google account first, then check if UPI/bank access was also affected |
| You were tricked into approving a payment or screen-sharing session yourself | Report as unauthorized/fraudulently induced — RBI liability rules can still apply depending on how fast you report |
| You see a debit but never touched the app or shared anything | Report immediately as a fully unauthorized transaction — strongest liability protection |
No. Reporting to your bank, filing on cybercrime.gov.in, and calling 1930 are all free.
Yes, for the immediate blocking and reporting steps — this is designed for direct self-service. A lawyer becomes relevant if your bank denies liability for a genuinely unauthorized transaction or delays resolution well beyond RBI’s prescribed timelines.
Need professional legal help with this?
Find a Lawyer on VidyodayThe same immediate steps apply whether the hacked app is Google Pay or another UPI app — see our guide on PhonePe account hacked for the app-specific equivalent, and our general guide on bank account hacked for the underlying banking-side process.
No — Google Pay is a UPI interface, not the holder of your funds. Only your bank, or NPCI/the receiving bank in response to a timely complaint, can freeze or reverse a transaction.
Calling your bank’s official helpline to block UPI on your account is faster than any in-app action, since it acts at the bank-rail level directly.
Not necessarily — the app itself usually isn’t the vulnerability. Secure your Google account and bank access first; you can safely re-register UPI on the same app afterward.
Go to myaccount.google.com/security and review “Your devices” — sign out of anything you don’t recognize immediately.
It depends on how the fraud happened and how quickly you reported it — a genuinely unauthorized transaction reported within 3 working days carries the strongest liability protection under RBI’s current rules. Note that RBI has already notified a revised framework (effective January 1, 2027) that changes this reporting window to 5 calendar days, so check the current rule in force at the time you’re reading this.
Filing on cybercrime.gov.in generates an official complaint and acknowledgment number that serves this purpose — a separate physical FIR is usually only needed if your bank or the portal specifically requires one for your case.
This is extremely common — report the fake number itself in your cybercrime.gov.in complaint, and never call a number found via search instead of your bank’s printed/official helpline going forward.
This article is for general information only and does not constitute legal or financial advice. Bank policies, RBI rules, and app security features can change — verify current guidance with your bank or on rbi.org.in before relying on this for a real dispute.