Credit Card Fraud and OTP Scam – I lost INR INR1,49,225 and got back

Credit Card Fraud and OTP Scam - I lost INR INR1,49,225 and got back
Recommend LetsFintech.com to your network!
Forty-six seconds: how a ghee advertisement on Facebook took INR 1,49,225 from my credit card

Card-not-present fraud · India · 30 May – 13 August 2026

Forty-six seconds to lose INR 1,49,225. Seventy-five days to get it back.

I work in fraud management. I know what a chargeback is. I still clicked an advertisement for ghee on Facebook, typed two OTPs into a fake checkout, and watched my credit card get emptied twice in under a minute. This is the whole thing — the machinery of the scam, the hour that saved me, the dispute process nobody explains, and what happened when I reported the advertisement to Meta.

What the card statement eventually looked like
DateDescriptionDebitCredit
30 May 2026
11:04:19
Card-not-present transaction. Merchant descriptor: a hair salon. I was buying ghee.INR 49,999.00
30 May 2026
11:05:05
Second transaction, 46 seconds later, on the second OTP.INR 99,226.00
02 Jun 2026Dispute registered with the bank for both transactions. FIR already filed.
~1 week laterInterim credit, so that I was not paying interest on money I never spent.interim
13 Aug 2026Dispute resolved in my favour. Credit confirmed.INR 1,49,225.00
The ending, first

This message arrived seventy-five days after the money left

I am starting at the end, because if you are reading this at 2 a.m. with your card blocked and your stomach in knots, you need to know the ending is possible before you can bear the middle.

Two and a half months after the fraud, the bank confirmed the disputed amount had been credited back to my card. Nothing about that outcome was automatic. It happened because of a sequence of specific, boring, time-bound actions taken in a specific order — most of them in the first sixty minutes.

Grey pixelated blocks in every screenshot below are my redactions: card digits, available limits, service-request numbers, the merchant name and unrelated third parties. Nothing else has been edited. Tap any screenshot to enlarge it.

Exhibit 0113 Aug 2026
Email from the bank stating that INR 149225 has been credited to the credit card towards the disputed transaction.
The resolution email. INR 1,49,225 credited back to the card against the disputed transactions — exactly the sum of INR 49,999 and INR 99,226.
Part 01 · The set-up

The advertisement did not find me at random

For about two weeks before 30 May, I had been shopping for ghee. Not casually — properly. Comparing brands on Amazon, on Flipkart, on a card-issuer’s shopping platform, on the brands’ own websites. In advertising language, I had become an in-market audience: a person whose recent behaviour marks them as ready to buy a specific thing.

That signal is a product. It is bought, sold, inferred from pixels on shopping sites, and used to retarget people who have shown intent. Whoever ran this advertisement did not need to guess that a middle-class man in India might want A2 desi ghee. The machine already knew, and the machine served me an offer for exactly the thing I had been researching.

So when the advertisement appeared in my Facebook feed, it did not feel like an intrusion. It felt like a coincidence in my favour. That is the first mechanism of this scam, and it is not built by the scammer — it is built by the advertising system and rented to the scammer by the hour.

Why it appeared credible to a fraud professional

It was an advertisement, not a random link — and somewhere in my head sat the lazy assumption that an advertiser must have been verified, that money had changed hands, that a platform this large must check who it takes money from. Every part of that assumption deserves scrutiny. I gave it none.

Part 02 · The shop

A survey, a discount, a countdown clock

The advertisement led to a short questionnaire. Answer a few questions about your household, your cooking, how much ghee you use — and unlock a first-order price. This is not a survey. It is a compliance ladder: each small “yes” makes the next “yes” easier, and by the time your card is out, you have already invested effort and feel owed a reward.

The reward was half a litre of premium A2 ghee for INR 10. The product page carried a “-99%” flash, a “HOT” tag, 2,565 reviews, five stars — and a timer counting down from ten minutes.

Exhibit 02Product page
Fake shop product page for A2 Desi Ghee showing a 99 percent discount badge, a HOT tag, 2565 reviews and a countdown timer at nine minutes forty-two seconds.
INR 10.00 – INR 8,312.00, a “-99%” badge, and a clock at 00:09:42. The timer is the entire product.
Exhibit 03Checkout
Checkout page of the fake shop showing two units of A2 Desi Ghee first order at ten rupees, subtotal twenty rupees, with a countdown timer.
The checkout I believed I was completing: two half-litre jars, subtotal INR 20.00. Hold that number against what actually left the card.
Exhibit 04Variants
Product page showing net weight options: first order 10 rupees half litre, half litre, 1 litre, 2, 3, 4 and 6 litre.
A full size ladder — half litre to six litres — so the shop reads as a real business with real inventory.

The storefront was well built. Product photography, an Arabic subtitle on the product name, a detailed FAQ about fermentation and cultured butter, a “Why A2?” explainer. All of it lifted, as far as I can tell, from a genuine food brand that had nothing to do with this. That company is a victim here too: its label, its photographs and its copy were used as the costume.

Exhibit 05The domain
Browser address bar showing a lookalike .shop domain for the fake ghee storefront.
The tell I did not read: a throwaway .shop domain with a country tag bolted onto a real brand’s name. Do not visit it. It is reproduced only so you recognise the shape of these addresses.
Exhibit 06Borrowed copy
Product description text about making ghee from fermented milk, yogurt and butter, plus an FAQ about additives.
Paragraphs of confident, specific, brand-quality copy. Effort here is cheap; it is copy-paste. Polish is not proof.

The four pressure devices on one page

  • Scarcity — a countdown timer that resets for every visitor.
  • Reciprocity — you “earned” the discount by completing the survey.
  • Social proof — thousands of reviews, unverifiable and unlinked.
  • Absurd value — 99% off, which should have been the loudest alarm and instead read as the prize.
Part 03 · Ninety seconds

The first card was declined. I should have stopped there.

I was suspicious. Genuinely. So I did something half-sensible: I used a card on which I had already reduced both the international and the domestic transaction limits to a minimum, reasoning that if this went wrong, the damage was capped.

It failed. An error message, no transaction.

That decline was the system doing exactly what I had configured it to do, and it was the last exit before the crash. Instead of reading it as evidence, I read it as friction. I wanted the deal. I picked up a second card.

And here is the belief that cost me INR 1,49,225: I thought card fraud happened through international transactions. I had locked down the international limit on that second card and left the domestic limit untouched, because domestic transactions need an OTP, and an OTP is something only I receive.

The two OTPs

An OTP arrived. I read the notification preview on my lock screen, saw the code, and typed it in. The page returned an error. A second OTP arrived immediately. I typed that in too.

What I did not do was open the message and read it to the end. In the bank’s SMS format, the amount sits at the front of a long sentence, and the fragment that surfaces in a lock-screen preview is not reliably the part that tells you what you are approving. I authenticated twice without ever seeing the number I was authorising.

11:04:19

INR 49,999 authorised on the first OTP. Just under the INR 50,000 threshold at which reporting and escalation obligations tighten — a deliberately chosen number.

11:05:05

INR 99,226 authorised on the second OTP. Forty-six seconds later. Nearly double the first.

11:05:0x

Two SMS alerts land, one on top of the other. I read the second one properly. My hands went cold.

Exhibit 07SMS · debit 2
Bank SMS alert showing Rs 99,226.00 spent on the credit card with the merchant name and available limit redacted.
INR 99,226.00. Note the merchant descriptor, redacted here: it named a hair salon, not a ghee shop.
Exhibit 08SMS thread
SMS thread showing a normal small food-delivery transaction the previous day, then the fraudulent Rs 49,999 transaction.
The same thread, one day apart: an ordinary INR 320 food order, then INR 49,999 to a salon. The alerts look identical. Only the numbers scream.
Exhibit 09Email · 11:05:05
Bank email alert for a transaction of INR 99,226.00 with merchant information and credit limits redacted.
The bank’s email for the second debit, timestamped to the second.
Exhibit 10Email · 11:04:19
Bank email alert for a transaction of INR 49,999.00 at the same merchant, 46 seconds earlier.
And the first. Same merchant, 46 seconds earlier. This pair of timestamps is the clearest evidence in the whole file.

What actually happened, mechanically

Nobody “hacked” my bank. The fake storefront was a collection point. The card details I typed were relayed, in real time, to a payment page at a different merchant — one with a live acquiring relationship — where a much larger amount was charged. The OTP my bank sent was for that real transaction; I supplied it, believing it belonged to a INR 20 order.

Three fingerprints of this pattern, all of which I could have caught:

  • Descriptor mismatch. The merchant name in the alert had nothing to do with the goods. That mismatch alone is enough to abandon a purchase.
  • The “wrong OTP” error. There was no error. The first charge had gone through. The error message exists to harvest a second authentication. A failed OTP is never a reason to enter another one.
  • The escalating ladder. A smaller amount first to test that the card and the victim both cooperate, then a much larger one before the victim can react.

The gap between my two protective instincts is the entire lesson. I had understood that limits matter. I had not understood that an OTP is not a shield — it is a signature. The bank was never fooled. It asked me, twice, whether I authorised a payment, and twice I said yes.

Part 04 · The first hour

What I did in the next sixty minutes, in order

Everything I recovered, I recovered because of this hour. In cyber-fraud recovery, speed beats sophistication: money moves through mule accounts and merchant settlement cycles fast, and each hour of delay reduces the chance that anything can still be frozen or reversed.

If it is happening to you right now

The sequence

  1. Block the card. Immediately. App, IVR, or the SMS block code printed in every transaction alert. Do it before you do anything else, including crying, googling, or telling anyone.
  2. Call the bank’s fraud line and report each transaction verbally. Get a complaint or service-request number. Write down the time of the call.
  3. Call 1930 — the national cyber-crime financial-fraud helpline, staffed round the clock. This pushes your case into the system that talks directly to banks and payment intermediaries. The first sixty minutes are commonly called the golden hour for a reason.
  4. File on cybercrime.gov.in (the National Cyber Crime Reporting Portal), category: financial fraud. Save the acknowledgement number.
  5. Email the bank in writing, listing every disputed transaction with date, time, amount and reference. Written notice is what starts your regulatory clock, not the phone call.
  6. Go to the police / cyber cell and file an FIR. Take printouts of everything. An FIR is not a formality — it changes how seriously your dispute is treated at every later stage.
  7. Send the bank the signed dispute form when it arrives, within the deadline it states. Miss this and the investigation may not even begin.

My bank’s card-blocking team, for what it is worth, was excellent. They blocked the card, and because the amount exceeded INR 50,000, they told me plainly to go to the cyber-crime police as well. The next three days went to the police station — cooperative officers, a mountain of paperwork, and a feeling of helplessness that no amount of professional knowledge touched.

Exhibit 1102 Jun 2026
Bank email acknowledging a dispute raised for two transactions, promising interim credit and requiring a signed Transaction Dispute Form within seven working days.
The dispute acknowledgement: two transactions, interim credit promised so that finance charges do not accrue during the investigation, and a signed Transaction Dispute Form required within seven working days — a card-network requirement, not bank bureaucracy.
Part 05 · The machinery

What a chargeback actually is, and why it takes months

Most people hear “chargeback” and imagine a refund button. It is not that. It is a formal, rule-bound reversal pushed by your issuing bank, through the card network, against the merchant’s acquiring bank. There is a schedule, and there are adversaries.

Authorisation is not settlement

When the OTP goes through, the money is not yet gone. The transaction is authorised — a hold against your limit. The merchant then captures it, and funds settle to the merchant’s account typically a day or so later, sometimes in batches. This is why reporting within the hour matters so much: it is occasionally possible to stop or claw back a transaction before settlement completes, and it is always better evidence of good faith.

Interim credit

Once you dispute, the issuer usually posts a provisional credit for the disputed amount while it investigates. This is not the bank agreeing you are right. It exists so that you are not paying interest and late fees on a charge under investigation. Under the Reserve Bank’s customer-protection framework for unauthorised electronic banking transactions, banks are expected to credit the disputed amount within ten working days of your notification and to resolve the complaint within ninety days.

Liability, and the three-day clock

The RBI’s July 2017 circular on limiting customer liability sets the ground rules: if the loss is due to the bank’s negligence or a third-party breach where the customer is not at fault and reports within three working days of receiving the bank’s communication, customer liability is zero. Report on days four to seven and liability is capped — up to INR 25,000 for higher-limit credit cards. Beyond that, it falls to the bank’s board-approved policy.

The uncomfortable part of my own case

I entered the OTP. Under a strict reading, sharing an authentication credential is customer negligence, and negligence can mean bearing the loss until the moment of reporting. I did not get my money back because a rule automatically guaranteed it. I got it back because the case was documented within the hour, supported by an FIR, filed as a merchant dispute, and ultimately not successfully defended by the other side. Anyone telling you a refund is guaranteed is selling something.

Why 45 to 90 days of silence

Once the dispute is filed, the network gives the merchant’s side a window to defend the charge — broadly 30 days on Visa, 45 on Mastercard, shorter on some others — with the cardholder’s own filing window generally running to 120 days from the transaction. If the merchant responds with evidence, the issuer can escalate to pre-arbitration and then to the network for a binding decision. Each stage has its own clock. This is why my money sat in limbo from June to mid-August while nothing appeared to happen. Something was happening; it was simply happening in a queue.

What to do during the wait

  • Pay the rest of your bill on time. Do not let a genuine balance go delinquent because a disputed amount is sitting on the same statement.
  • Keep every acknowledgement number in one file: bank SR, 1930 reference, NCRP number, FIR copy, dispute form receipt.
  • Follow up in writing every two to three weeks. Politely, with reference numbers.
  • If the bank misses its own timelines, escalate to the banking ombudsman through the RBI’s complaint management system. That threat is real and banks respond to it.
Part 06 · The instrument

Use a credit card online. Not a debit card. Not UPI.

This is the single most useful practical thing I can give you, and it is the reason my story has an ending rather than just a wound.

  • It is not your money yet. A fraudulent credit-card charge takes the bank’s money and leaves you with a disputed line on a statement. A fraudulent debit or UPI transaction takes food-money out of your account today, and you spend the recovery period without it.
  • Chargeback rights are real and structured. Card networks have a defined dispute mechanism with reason codes, deadlines and an appeal path. UPI has grievance redressal, but a completed push payment is designed to be final.
  • Interim credit exists. You are usually made whole during the investigation, not after it.
  • Exposure is capped by a limit you control. You can set that limit low. You can set separate domestic, international, online and contactless limits. You can freeze the card in the app in one tap.
  • Fraud monitoring is more aggressive on credit portfolios, because the issuer, not you, carries much of the loss.

The corollary matters just as much: a credit card is only a good shield if you keep the limit sane, read every alert, and clear the statement in full. It is a risk-transfer instrument, not permission to be careless. I was careless with the instrument and it still saved me.

Part 07 · Cross-border

If that merchant had been overseas, I would probably still be writing complaints

My transactions were domestic. That single fact is doing enormous work in this story. Here is what changes when the merchant sits outside India.

  • The authentication gap. India has long mandated an additional factor — the OTP — for domestic online card payments. Many jurisdictions do not. A card compromised here can be charged abroad with no OTP at all, which is exactly why my old assumption (“fraud is an international problem”) existed in the first place. The RBI’s 2025 authentication directions extend two-factor requirements to domestic payments from April 2026, with a validation mechanism for non-recurring cross-border card-not-present transactions required from October 2026 — but that only bites where the overseas merchant or acquirer actually asks for it.
  • Your FIR stops at the border. An Indian police complaint gives Indian police jurisdiction over Indian entities. A shell company registered elsewhere, with an acquirer elsewhere and a hosting provider elsewhere, is reached only through mutual legal assistance — a process measured in months and years, and rarely deployed for one victim’s INR 1.5 lakh.
  • The freeze machinery does not extend. The 1930 helpline and the financial-fraud reporting system work because Indian banks, wallets and payment intermediaries are wired into them. A foreign acquirer is not, and nobody can freeze the beneficiary account for you.
  • You are left with exactly one lever: the network dispute. No police pressure, no regulator with authority over the merchant, no local ombudsman. Just Visa’s or Mastercard’s rulebook, and evidence.
  • Currency, conversion and timing muddy everything. The amount reversed may differ from the amount debited once forex and markup are unwound; dynamic currency conversion, refund rates and cross-border fees all become arguing points.
  • Layering is faster. Overseas proceeds are moved through payment aggregators, gift-card rails and crypto conversion within hours, so even a successful investigation finds nothing to recover.

So: keep your international limit at zero or near it unless you are actively travelling or subscribing, and turn it back off afterwards. That control is free, takes ten seconds, and is the difference between a dispute you can win and a loss you can only mourn.

Part 08 · Honesty

Why I got my money back — and why that was partly luck

  • The merchant was domestic. Reachable by an Indian acquirer, an Indian regulator and an Indian police force.
  • I reported inside the hour, and in writing well within three working days.
  • I filed an FIR. A dispute backed by a police report is qualitatively different from one that is not.
  • The bank behaved well. Fast blocking, correct advice, interim credit, and a dispute pushed through the network properly.
  • The other side did not, or could not, successfully defend the charge within its representment window. This part was not in my control at all.
  • My paperwork was boring and complete. Timestamps, reference numbers, screenshots, a consistent account. Nothing exaggerated.
  • Half the exposure never happened, because a limit I had set months earlier on the first card blocked that attempt.

Take out any one of the first four and the outcome could have been different. Take out the domestic part and I think it would have been.

Part 09 · The part nobody prepares you for

Shame is the scam’s second payload

My heart rate went through the roof. Then came a physical sensation I can only describe as falling. For a middle-class salaried person, INR 1,49,225 is not an inconvenience — it is more than a year of disciplined saving, gone between two messages. Within a minute I was doing the arithmetic of the rest of the year.

And then, immediately behind the fear, the thing that hurt more: shame. I am educated. My work is literally in fraud management. I am the person friends and family call for advice. I knew about chargebacks — that is why I use credit cards online. And I still walked in through the front door.

Expertise does not immunise you. It gives you a story to tell yourself.

The reason knowledge failed me is that the scam did not attack my knowledge. It attacked my state. Time pressure narrows attention. Desire for a deal creates motivated reasoning. A partial success (“I was careful with the first card”) manufactures a feeling of control. Under that load, an expert’s expertise becomes an argument for why it is fine to proceed. The failure was not intelligence. It was context.

If you have been scammed, please hear this without the caveats: being deceived by a system engineered by full-time professionals to defeat attention is not a character flaw. These operations are staffed, funded, iterated and A/B tested. They run on millions of people until they find the ten thousand who are tired, hopeful, hurried or simply in-market. You were not stupid. You were targeted.

What actually helped, in the days after

  • Doing the next concrete task. Block, call, file, print, sign. Action is the only thing that competes with rumination.
  • Telling one person the same day. Secrecy is what turns a financial event into a private wound. I told one person; that conversation kept me functional.
  • Separating the loss from the identity. “I lost money to a professional crew” is true. “I am an idiot” is a story. Notice which one you are rehearsing at 3 a.m.
  • Accepting the wait. Once the paperwork is in, refreshing your statement does not move the queue. Set a follow-up reminder every fortnight and put the phone down.
  • Not letting it eat the household. Fear leaks into everything — sleep, appetite, temper, the way you talk to people who did nothing wrong.

Guard against the second scam

Victims are resold. Within days you may be contacted by “recovery agents”, “cyber lawyers” or fake officials promising to retrieve your money for an upfront fee, or asking for card and account details to “verify” your case. No legitimate agency asks a victim for money or credentials to process a fraud complaint. Grief and urgency are exactly the conditions the first scam used; the second one uses them again.

If the distress does not settle — if you cannot sleep for weeks, if the shame is turning into something heavier, if you find yourself hiding it from everyone — please treat that as seriously as you treated the transaction. Talk to someone you trust, and to a mental-health professional if it persists. Financial trauma is real trauma, and the size of the number has nothing to do with whether you are allowed to be shaken by it.

Part 10 · The platform

I reported the advertisement that robbed me. Facebook left it up.

This is the part of the story I am angriest about, and it is the part that is not about me at all. My money came back. The advertisement stayed up. Somebody else was next.

After the fraud, I used Meta’s own scam-reporting flow. I described precisely what had happened: an advertised link, a fake ghee purchase, card details entered, a “wrong OTP” prompt, two transactions, INR 49,999 and INR 99,226 lost. I identified the advertisement. I submitted the report. I was told it would be reviewed against Community Standards.

Exhibit 12Report filed
Meta AI support assistant chat where the user reports the advertised link, entering card details, a wrong OTP prompt and losing two amounts.
The report, in my own words, with the amounts stated. The two unrelated brands Meta’s search surfaced below the scam advertisement are redacted here — they have nothing to do with this.
Exhibit 13The outcome
Meta support assistant confirming the report was submitted and then stating that the reported content was not removed.
The verdict, verbatim in substance: reviewed by a combination of technology and human reviewers — and in this case the reported content was not removed.

Read that sequence again. A user reports, with specifics, that an advertisement on the platform led directly to the theft of INR 1.49 lakh from his credit card. The platform reviews it. The platform concludes that nothing needs to come down.

This is not one bad decision. It is a business model with a tolerance setting.

In November 2025, Reuters published an investigation based on internal Meta documents from 2021–2025. The numbers it reported are not fringe allegations; they were the company’s own estimates, and they have since been cited in litigation and by regulators.

≈10%

Share of Meta’s 2024 revenue — roughly $16 billion — that internal projections attributed to advertisements for scams and banned goods, per the Reuters report. Meta called the figure a rough, overly inclusive estimate.

15bn/day

Estimated number of “higher-risk” scam advertisements shown to users daily, per an internal document, generating around $7 billion a year.

95%

The certainty threshold reportedly required before automated systems ban a suspected scam advertiser. Below it, some advertisers were charged higher rates instead — a “penalty bid” that monetises suspicion rather than removing it.

1 in 3

Share of successful scams in the United States that Meta’s own safety staff estimated the company’s platforms were involved in, according to a May 2025 internal presentation cited in the reporting.

Guardrails

Internal documents reportedly described limits on how much revenue the company was willing to lose to enforcement, and prioritised markets where regulatory penalties would be steepest.

Since then: securities and financial-conduct regulators have opened enquiries into the company’s role in financial scams, and at least one attorney general has sued Meta over profiting from scam advertising. The company says it fights fraud aggressively and that the leaked material presents a selective view.

Set that against what I experienced

  • An advertiser paid Meta to reach me. That is a commercial relationship with a payment instrument attached — the one place where identity can actually be verified.
  • I was targeted with precision, because ad-tech knew I was shopping for exactly this product. Precision that good is not available to the honest and unavailable to the fraudulent.
  • I reported a completed financial crime, with amounts, in the platform’s own flow. The content stayed up.
  • Nobody at Meta contacted me. No follow-up, no request for the transaction evidence, no notification to other users who had clicked the same advertisement.

Five things Meta could do this quarter, if it wanted to

  1. Verify identity for commerce advertisers, with real KYC — bank-grade, tied to the payment instrument and a legal entity, before a single rupee of e-commerce advertising is served. Payment platforms manage this for merchants handling far less money.
  2. Route reports that allege financial loss to human review with a service-level agreement, and let victims attach evidence: bank alerts, transaction references, the FIR. A closed-loop “not removed” with no evidence path is not review, it is dismissal.
  3. Notify exposed users. When an advertisement is confirmed fraudulent, tell everyone who clicked it. Breach-notification norms exist in every other industry that handles this much harm.
  4. Publish enforcement data by country — scam advertisements reported, removed, median time to removal, advertiser bans, appeals. India is one of Meta’s largest markets and one of its largest scam-loss markets; both numbers should be public.
  5. Fund restitution and a fast law-enforcement channel. Revenue earned from a fraudulent advertisement should be forfeited to victims, and there should be a direct, hours-not-weeks channel to India’s cyber-crime coordination system.

There is a defence that platforms deploy here: scale, volume, impossibility. It is not persuasive coming from a company that can identify a man who has been comparison-shopping ghee for two weeks and put a jar in front of him within the hour. The targeting is exquisite. The gatekeeping is not. That is a choice about where the engineering goes.

Part 11 · Prevention

The rules I now follow, written by someone who learned them expensively

  • Set domestic limits, not just international onesEvery issuer lets you cap online, contactless, ATM, domestic and international usage separately. Cap all of them. Fraud does not respect your mental model of where it comes from.
  • Keep one low-limit card for unfamiliar merchantsA card with a INR 10,000–INR 25,000 limit is a firewall. Use it for anything you have not bought from before, and never enable international usage on it.
  • Use virtual or single-use card numbers where your bank offers themMerchant-locked or one-time numbers make the stolen data worthless.
  • Open the SMS. Read the whole thing. Every time.Never authenticate from a lock-screen preview. The amount and the merchant are the only two things that matter, and a preview may show you neither.
  • A failed OTP means stop, not retryIf a checkout says the OTP was wrong and immediately sends another, close the tab and check your statement. This is the signature of a relay attack.
  • Check the merchant descriptor before you type the codeIf the alert names a business that has nothing to do with what you are buying, you are funding someone else’s transaction.
  • Treat a countdown timer as an exit signLegitimate retailers do not need to stop you from thinking. If the offer dies while you verify it, it was never an offer.
  • Verify the offer at the sourceOpen a new tab, go to the brand’s official site or app, and see whether the promotion exists. Ninety-nine per cent off is not a promotion; it is bait.
  • Read the domain like an address, not a decorationBrand names bolted onto throwaway extensions, hyphens, country tags and unfamiliar suffixes are how impersonation is done at scale.
  • Never fill a “survey” to unlock a priceIt is a compliance ladder and a data-harvest, and it has no legitimate retail purpose.
  • Turn on every alert channelSMS and email and app push. Redundancy is what let me see the second debit in seconds rather than at the month’s end.
  • Do not shop from advertisementsThis is the rule I actually live by now. If an advertisement interests me, I search for the brand independently and buy from a source I chose. A paid placement is a purchased position in your attention, not a credential.
Part 12 · Emergency card

If this is happening to you right now, in India

Save this before you need it
  1. Block the card — issuer app, IVR, or the SMS block code in your transaction alert.
  2. 1930 — national cyber-crime financial-fraud helpline, 24×7. Call within the first hour.
  3. cybercrime.gov.in — file under financial fraud; keep the acknowledgement number.
  4. Bank fraud line + written email — list every disputed transaction with date, time, amount, reference. Ask for the dispute to be raised and for interim credit.
  5. Police / cyber cell — FIR, with printouts of alerts, emails and screenshots.
  6. Signed Transaction Dispute Form — return it inside the stated deadline, usually seven working days.
  7. If the bank misses its timelines — escalate to the RBI’s ombudsman scheme through its complaint-management portal.

Keep everything. Screenshot everything. Timestamp everything. The dullest folder you ever assemble may be the reason you get made whole.

Closing

Why I am publishing a story that embarrasses me

Because the shame is the reason these crews operate at this scale. Most victims never tell anyone. The scam is engineered to be humiliating precisely so that it stays quiet — and silence is what lets the same advertisement, the same fake storefront and the same “wrong OTP” screen run for the next person.

So: I am educated, I work in fraud management, I was the person in my circle people asked for advice, and on a Saturday morning in May I lost INR 1,49,225 to a jar of ghee that did not exist. I got it back, through speed, paperwork and a fair amount of luck. If you have lost money this way, you are not alone and you are not a fool. Block the card, make the calls, file the papers, tell one person — and then be as kind to yourself as you would be to a friend telling you the same story.

And if you take one line from all of this, take the one that cost me the most to learn: an OTP is not protection. It is your signature.

Sources and further reading

  • RBI, Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, 6 July 2017 (zero-liability on reporting within three working days; provisional credit within ten working days; resolution within ninety days).
  • RBI’s 2025 directions on authentication mechanisms for digital payment transactions — two-factor authentication for domestic digital payments from 1 April 2026, and a validation mechanism for non-recurring cross-border card-not-present transactions from 1 October 2026.
  • Indian Cyber Crime Coordination Centre (I4C), Ministry of Home Affairs — national helpline 1930 and the National Cyber Crime Reporting Portal, cybercrime.gov.in.
  • Card-network dispute rules: cardholder filing windows of roughly 120 days; merchant representment windows of roughly 30 days (Visa) and 45 days (Mastercard), followed by pre-arbitration and arbitration.
  • Reuters investigation into Meta’s internal documents on scam advertising, November 2025, and subsequent regulatory and legal action reported thereafter.

This is a personal account written to help others avoid the same trap. It is not legal, financial or tax advice, and procedures, timelines and platform policies change — verify current rules with your bank, with the RBI, and with the official cyber-crime portal before relying on them. All screenshots are from my own devices and accounts; card digits, credit limits, service-request numbers, the fraudulent merchant’s name and unrelated third parties have been redacted. The legitimate food brand whose product photographs and packaging were used by the fake storefront had no involvement in this fraud and is itself a victim of impersonation.

Did you lost money to a Credit Card Scam? How to get your money back from scamsters?
I clicked a INR10 ghee ad on Facebook. It cost me INR1,49,225 in 46 seconds.
Two OTPs, 46 seconds: how a fake ghee shop emptied my credit card I work in fraud management.
A Facebook ad still scammed me.
INR1,49,225 gone in 46 seconds — and 75 days to get every rupee back Your OTP is not your protection.
It is your signature. If the OTP “fails” and a second one arrives, stop. That is the trap.
The first 60 minutes decide whether your money comes back
I reported the scam ad to Facebook. They left it running.
Card blocked, FIR, chargeback: the exact steps that got my INR1.49 lakh back
Why I will never buy anything from an advertisement again

फेसबुक पर INR10 वाले घी के विज्ञापन पर क्लिक किया — 46 सेकंड में INR1,49,225 उड़ गए
दो OTP और 46 सेकंड: नकली घी की वेबसाइट ने मेरा क्रेडिट कार्ड खाली कर दिया
मैं खुद फ्रॉड मैनेजमेंट में काम करता हूँ, फिर भी फेसबुक के विज्ञापन ने ठग लिया
46 सेकंड में INR1,49,225 गए, 75 दिन में पूरा पैसा वापस आया — पूरी कहानी
OTP आपकी सुरक्षा नहीं, आपका हस्ताक्षर है
OTP “गलत” बताकर दूसरा OTP आए तो रुक जाइए — असली जाल यहीं है
ठगी के बाद के पहले 60 मिनट तय करते हैं कि पैसा वापस मिलेगा या नहीं
मैंने स्कैम विज्ञापन की शिकायत की, फेसबुक ने उसे हटाया तक नहीं
कार्ड ब्लॉक, FIR और चार्जबैक: वो कदम जिनसे मेरे INR1.49 लाख वापस मिले अब मैं किसी विज्ञापन से खरीदारी नहीं करता — वजह यह है

A fraud professional’s own case file: anatomy of a CNP relay attack that cleared two OTPs
INR1.49 lakh in 46 seconds: the controls that worked, and the one belief that didn’t
Descriptor mismatch was the only real-time signal — and no customer is trained to read it
The second OTP is the highest-value fraud signal issuers still under-weight
When ad-tech precision becomes fraud infrastructure: in-market targeting as an attack surface
Zero liability, interim credit, representment: a chargeback timeline from the claimant’s side
What a fraud manager learned about his own bank’s dispute process by becoming a victim
Domestic vs cross-border CNP fraud: why recovery odds collapse at the border
The awareness gap is not knowledge, it is context — a case study in expert failure
One victim, one detailed report, zero takedown: the platform accountability problem in scam advertising

Note: This happened with a real person and they reached out to us to write this article.

Write to us at [email protected], if you need more info.