Updated: September 19, 2026
Pooja Pal cyber fraud case: Uttar Pradesh’s Chayal Assembly constituency MLA Pooja Pal has reported unauthorized transactions from her Union Bank account. According to her complaint, around ₹1.55 lakh was withdrawn through PhonePe between August 22 and September 13, 2026. The matter was reported to Dhoomanganj police, and a technical investigation is underway to determine how the transactions occurred.
The case has drawn attention because the reported transactions continued over several days before they were noticed. Pal has also raised concerns about possible unauthorized access to her mobile device and personal data.
What Happened to Pooja Pal’s Bank Account?
In short: Pooja Pal reported that approximately ₹1.55 lakh was withdrawn without authorization from her Union Bank account through PhonePe transactions between August 22 and September 13. She noticed the issue on September 14 and subsequently approached the police. The exact mechanism behind the unauthorized transactions has not yet been established publicly.
According to the complaint details reported by multiple news outlets:
- The affected account was reportedly held with Union Bank of India.
- Unauthorized transactions allegedly took place between August 22 and September 13, 2026.
- The total amount involved was approximately ₹1.55 lakh.
- The transactions were reportedly carried out through PhonePe/UPI.
- The transactions came to light on September 14.
- A complaint was filed at Dhoomanganj police station.
- Pooja Pal requested investigation of the relevant UPI transactions, UTR numbers and transaction IDs.
- She also expressed concern that personal information stored on her phone could have been accessed or leaked.
Pooja Pal Cyber Fraud: What Did Her Complaint Say?
The complaint reportedly seeks technical examination of the mobile phone, PhonePe account, UPI transactions and banking system to establish how the unauthorized withdrawals occurred.
HNN 24×7 reported that Pal suspected her iPhone may have been compromised. However, this remains an allegation or suspicion in the complaint, not an established finding of the investigation. Police and cyber investigators are expected to determine the actual source and method of the unauthorized transactions.
This distinction is important because an unauthorized UPI transaction does not, by itself, establish that a phone was hacked. Digital fraud can involve different attack vectors, including compromised credentials, social engineering, malicious applications, account access, SIM-related issues or other forms of unauthorized access.
Pooja Pal Cyber Fraud Case: Transaction Timeline
| Date | Reported development |
| August 22, 2026 | Period of reported unauthorized transactions begins |
| August 22–September 13 | Multiple PhonePe/UPI transactions were allegedly made |
| September 13 | Reported transaction period ends |
| September 14 | Pooja Pal reportedly noticed the unauthorized withdrawals |
| September 2026 | Complaint/FIR process initiated and investigation begins |
| September 19 | Reports published with the cyber investigation continuing |
The dates above reflect information reported in the complaint and news coverage available as of September 19, 2026.
How Much Money Was Lost in the Pooja Pal Cyber Fraud?
Approximately ₹1.55 lakh was reportedly withdrawn from Pooja Pal’s bank account through unauthorized PhonePe/UPI transactions. Reports state that the transactions occurred over a period from August 22 to September 13, rather than as one single withdrawal.
The exact transaction-by-transaction details are part of the investigation, and authorities have been asked to examine the relevant transaction IDs and UTR numbers.
Was Pooja Pal’s Phone Hacked?
There is currently no publicly established finding that confirms her phone was hacked. Pooja Pal reportedly expressed suspicion that her iPhone may have been compromised and that private information could have been accessed. The cyber investigation is intended to establish how the unauthorized transactions occurred.
This is an important distinction for readers: a person’s suspicion about a device compromise should not be presented as a confirmed technical finding unless investigators establish it.
What Is the Police Investigation Looking Into?
The reported investigation involves examining the digital and financial trail connected with the disputed transactions.
Investigators may examine:
- PhonePe transaction records.
- UPI transaction IDs and UTR numbers.
- Bank transaction logs.
- Device and application activity.
- Relevant authentication records.
- Mobile-device evidence.
- Possible access to personal data.
- The destination accounts or transaction recipients.
HNN 24×7 reported that the cyber team was examining the mobile, PhonePe, UPI and banking systems to determine how the money was withdrawn and who may have been involved.
Why This Cyber Fraud Case Matters
The incident highlights a broader digital-security issue: unauthorized electronic transactions can happen even when an account holder does not knowingly initiate a payment.
For users, the most important lesson is speed of reporting. The Reserve Bank of India has established customer-protection rules for unauthorized electronic banking transactions, with liability depending on factors including the nature of the breach, customer negligence and how quickly the transaction is reported.
Therefore, anyone noticing an unfamiliar bank or UPI transaction should avoid waiting to see whether another transaction occurs.
What Should You Do If Money Is Withdrawn Without Permission?
Immediately report the unauthorized transaction to your bank and use India’s official cyber-fraud reporting system. For financial cyber fraud, the National Cyber Crime Reporting Portal directs victims to the 1930 helpline for immediate reporting.
1. Call 1930
The Government of India’s National Cyber Crime Reporting Portal provides 1930 as the helpline for reporting financial cyber fraud.
2. Report the Incident Online
You can also report cybercrime through the official National Cyber Crime Reporting Portal.
National Cyber Crime Reporting Portal
3. Inform Your Bank Immediately
Contact the bank through its official customer-care channel and report the unauthorized transaction.
RBI directions require banks offering electronic banking services to provide channels for reporting unauthorized transactions and to take steps to prevent further unauthorized transactions after receiving a report.
4. Secure Your UPI and Banking Access
Depending on the circumstances, consider:
- Changing relevant banking passwords or PINs.
- Reviewing UPI applications and linked accounts.
- Checking whether unfamiliar devices or sessions are connected.
- Contacting the bank to block or secure affected services.
- Preserving SMS, email and app notifications.
- Keeping transaction IDs and UTR numbers for the investigation.
5. Preserve Digital Evidence
Do not delete potentially relevant messages, transaction notifications, emails or other records before reporting the incident.
Keep:
- Transaction screenshots
- Bank statements
- UTR numbers
- Transaction IDs
- SMS alerts
- PhonePe transaction records
- Relevant emails
- Complaint/reference numbers
These records can help investigators trace the transaction trail.
RBI Rules on Unauthorized Electronic Transactions
RBI’s customer-protection framework distinguishes between different circumstances surrounding unauthorized electronic banking transactions.
For example, where a third-party breach occurs and neither the bank nor customer is responsible, reporting within the prescribed period can affect the customer’s liability. Where the customer has shared payment credentials, different liability rules can apply.
Because liability depends on the specific facts, consumers should report suspicious transactions as quickly as possible rather than assuming that the money cannot be recovered.
RBI — Customer Protection on Unauthorised Electronic Banking Transactions
Pooja Pal Cyber Fraud: What Happens Next?
The next stage is expected to focus on tracing the disputed transactions and determining how the account was accessed.
At present, publicly available reporting establishes that:
- A complaint was made regarding unauthorized withdrawals.
- Approximately ₹1.55 lakh was reportedly involved.
- The transactions were linked to PhonePe/UPI.
- The reported transaction period was August 22 to September 13.
- A police/cyber investigation is underway.
- The suspected method of access has not yet been conclusively established.
Any further identification of suspects, recovery of funds or confirmation of a device compromise should therefore be based on subsequent police or investigative findings rather than assumptions.
Frequently Asked Questions
Who is Pooja Pal?
Pooja Pal is an MLA from the Chayal Assembly constituency in Uttar Pradesh’s Kaushambi district. The current report concerns unauthorized transactions from a bank account associated with her.
How much money was withdrawn from Pooja Pal’s account?
Approximately ₹1.55 lakh was reportedly withdrawn through unauthorized PhonePe/UPI transactions.
When did the alleged cyber fraud happen?
According to the reported complaint, unauthorized transactions took place between August 22 and September 13, 2026. The issue was reportedly noticed on September 14.
Was Pooja Pal’s iPhone hacked?
Pooja Pal reportedly suspected that her iPhone may have been compromised, but publicly available reports do not establish this as a confirmed technical finding. The matter is part of the investigation.
Where was the cyber fraud complaint filed?
Reports state that a complaint was filed at Dhoomanganj police station in Prayagraj.
What should I do if an unauthorized UPI transaction happens to me?
Immediately contact your bank, report the financial cyber fraud through 1930, and submit a complaint through the National Cyber Crime Reporting Portal. Preserve transaction IDs, UTR numbers, screenshots and bank alerts.
Can unauthorized money be recovered?
Recovery depends on the circumstances, transaction trail, reporting time and investigation. Reporting quickly can help authorities and banks take action, but recovery should not be presented as guaranteed.
Is this case still under investigation?
Yes. As of September 19, 2026, reports indicate that technical and cyber investigation into the transactions is continuing.
Final Takeaway
The Pooja Pal cyber fraud case involves reported unauthorized withdrawals of approximately ₹1.55 lakh through PhonePe/UPI between August 22 and September 13, 2026. A complaint was filed after the transactions were discovered, while investigators examine the banking, UPI, PhonePe and mobile-device aspects of the case.
For ordinary UPI and online-banking users, the key takeaway is simple: check transaction alerts regularly and report any unauthorized financial transaction immediately. India’s cyber-fraud reporting system can be reached through 1930, while complaints can also be submitted through the National Cyber Crime Reporting Portal.

