Credit Card Fraud: Types, Cardholder Protections and Disputes
Stolen and copied cards are only half of it. A card can be issued in your name, or your account quietly redirected.
Credit card fraud is any use of a credit card, or a credit card account, that the genuine cardholder did not authorise. It differs from debit card fraud in one practical way: the money spent is the bank's credit line, not the customer's savings, so the loss lands on the issuer's books first and the customer's dispute is about a bill rather than an empty account.
The syllabus lists credit cards separately under Electronic Card Frauds because the frauds are partly different too. Besides stolen and copied cards, a credit card can be obtained in someone else's name, or an existing account can be quietly redirected to the fraudster.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
Types of Credit Card Fraud
Lost or stolen card
How it happens
A physical card is used before the holder reports it
Typical warning sign
Spends far from the holder's usual places, soon after a theft
Counterfeit card
How it happens
Data skimmed at a terminal or ATM is written onto a cloned card
Typical warning sign
Card-present spends while the real card is with the holder
Card not present
How it happens
Card number, expiry and CVV stolen online and used for e-commerce
Typical warning sign
Online spends at merchants the holder has never used
Application fraud
How it happens
A card is issued on stolen or forged KYC documents
Typical warning sign
New account maxed out quickly, then no payments at all
Account takeover
How it happens
Fraudster changes the mobile number or address, then asks for a replacement card or limit increase
Typical warning sign
Contact details changed shortly before a card reissue request
Vishing pretexts
How it happens
Calls offering a limit increase, reward point redemption or annual fee waiver, asking for the OTP
Typical warning sign
An OTP the customer did not request, read out to a caller
| Type | How it happens | Typical warning sign |
|---|---|---|
| Lost or stolen card | A physical card is used before the holder reports it | Spends far from the holder's usual places, soon after a theft |
| Counterfeit card | Data skimmed at a terminal or ATM is written onto a cloned card | Card-present spends while the real card is with the holder |
| Card not present | Card number, expiry and CVV stolen online and used for e-commerce | Online spends at merchants the holder has never used |
| Application fraud | A card is issued on stolen or forged KYC documents | New account maxed out quickly, then no payments at all |
| Account takeover | Fraudster changes the mobile number or address, then asks for a replacement card or limit increase | Contact details changed shortly before a card reissue request |
| Vishing pretexts | Calls offering a limit increase, reward point redemption or annual fee waiver, asking for the OTP | An OTP the customer did not request, read out to a caller |
RBI Rules That Protect the Cardholder
From RBI's card issuance and conduct directions (the 2022 Master Direction, now consolidated into 2025 directions for each type of bank):
- check_circleNo unsolicited cards. A card issued without the customer's explicit consent is prohibited.
- check_circleA card not activated within 30 days of issue needs the customer's OTP-based consent to activate. If no consent comes, the issuer must close the account free of cost within seven working days of seeking confirmation.
- check_circleNo charges may be levied on transactions the cardholder disputes as fraud until the dispute is resolved.
- check_circleIssuers must offer 24x7 channels to report an unauthorised transaction and block the card (helpline, SMS, email, IVR, website link, app), and must send immediate confirmation once the card is blocked.
- check_circleA replacement for a blocked card is issued only with the cardholder's explicit consent.
- check_circleAny fraud insurance cover offered with a card needs the cardholder's explicit consent.
How a Credit Card Fraud Dispute Runs
- 1
Cardholder reports and the card is blocked
Every transaction after the report is the bank's loss under RBI's liability rules.
- 2
Shadow reversal
The disputed amount is credited provisionally so the customer is not billed for it while the bank investigates. Under the 2017 rules this is within 10 working days of the report. From 1 January 2027 the credit card shadow reversal must be within five calendar days.
- 3
Investigation and chargeback
The issuer examines the transaction and, where the merchant side is at fault, can raise a dispute with the acquirer through the card network's rules.
- 4
Liability decided and communicated
The bank carries the burden of proving the customer liable. A rejected claim must state reasons.
Quick practice on banking operations. No signup.
What the Issuer Watches For
RBI's Digital Payment Security Controls Directions, 2026 list the signals a bank's fraud system should be tuned to: bursts of transactions in a short period, high-risk merchant categories, strings of invalid CVVs or PINs that suggest counterfeit cards or an account generation attack, unusual locations and time zones, and spends traced back to a known point of compromise. Card limits must be enforced at the network switch, with separate domestic and international limits.
How the IIBF Exam Tests This
Expect classification questions (application fraud versus account takeover versus counterfeit) and rule questions on the cardholder's protections. The trap is mixing debit and credit timelines: the shadow reversal rule talks about crediting the account, but for credit cards the 2026 amendment sets its own, shorter window from 2027. Both can appear: the amendment (24 June 2026) falls before the 30 June 2026 cut-off for sittings from September 2026 to February 2027.
FAQs
What should I do if my credit card is used fraudulently?expand_more
Block the card immediately through the issuer's 24x7 helpline, app or SMS, raise a dispute for each fraudulent transaction, and report on 1930 or cybercrime.gov.in. The issuer cannot charge you on those transactions while the dispute is open.
Do I have to pay a credit card bill for a fraudulent transaction?expand_more
Not while you dispute it as fraud: RBI's rules bar charges on disputed transactions until the dispute is resolved. Whether you finally bear any loss depends on whose fault it was and how fast you reported it.
Someone got a credit card in my name. What now?expand_more
That is application fraud using your identity. Tell the issuer in writing that you never applied, report it on cybercrime.gov.in, and check your credit report so the account can be removed from it.
Is it safe to share an OTP to increase my credit limit?expand_more
No. Banks do not ask for OTPs on calls. A caller offering a limit increase, reward redemption or fee waiver in exchange for an OTP is a fraudster using the OTP to authorise a transaction.
Next steps
- Card Not Present Fraudarrow_forward
- ATM Card Fraudarrow_forward
- Identity Theftarrow_forward
- Customer Liabilityarrow_forward
120 questions, 2 hours, scored instantly.
