What to do about loan app harassment
Harassing your contacts, calling at night and threatening you are prohibited recovery practices whether the lender is registered or not. The first question to settle is whether a regulated entity is behind the app at all.
Short answer
Establish whether a regulated lender sits behind the app — lending can only be done by banks, RBI-registered NBFCs or entities permitted under state money lending laws. Regulated lenders are bound by rules prohibiting calls outside stated hours, contacting your relatives and threats. Report to the RBI where regulated, and to cybercrime.gov.in and 1930 where not.
Loan app harassment follows a script that is now well documented. A small amount is disbursed quickly, less than was agreed after undisclosed charges are deducted. The repayment period turns out to be days rather than weeks. When it is missed, the calls begin — first to you, then to your contact list, then messages to your colleagues and family, sometimes with morphed images, always with the implication that the debt is a disgrace to be broadcast. The harassment is the product, not a failure of process.
The first thing to establish is who is actually behind the app, because it determines every subsequent step. Lending in India can only lawfully be carried out by banks, by non-banking financial companies registered with the Reserve Bank of India, or by entities permitted under state money lending legislation. An app that is not connected to one of those is not a lender with a regulatory problem — it is an unauthorised operation, and the route is criminal rather than regulatory.
The second thing to establish is that the harassment is prohibited regardless. The rules on recovery agents that apply to banks and NBFCs are explicit and long-standing: no threatening language, no persistent calling outside stated hours, no harassing relatives, friends or co-workers, no publishing the borrower's name, no threats of violence, no misleading statements about the debt. The digital lending framework adds requirements about disclosure, the flow of funds and the handling of borrower data.
The third thing, and the one that matters most in the moment, is that having taken the loan does not make you liable to be treated this way. Owing money is a civil matter. Criminal intimidation, extortion, defamation and the misuse of your data are offences, and they are offences committed by the recoverer, not by the borrower. People submit to this because they feel they are in the wrong. On the harassment, they are not.
Establish who is behind the app
This is the diagnostic step and everything follows from it.
The Reserve Bank has stated the position directly: lending business can be carried out only by entities that are either regulated by it — banks and registered non-banking financial companies — or entities permitted to do so under other law, including state money lending legislation. It has also warned specifically about unauthorised digital lending platforms and mobile apps charging excessive rates and hidden charges, adopting unacceptable recovery methods, and misusing agreements to access borrower data.
Under the digital lending framework, a lending service provider or digital lending app operating on behalf of a regulated entity must disclose that entity. The app or its key fact statement should name the bank or NBFC on whose books the loan sits. If no regulated entity is named anywhere — not in the app, not in the loan agreement, not in the disbursal message — treat that as the answer.
Check the money trail as a cross-check. A regulated lending arrangement requires disbursal and repayment to flow between the borrower's bank account and the regulated entity's account, without pass-through accounts belonging to intermediaries. Money that arrived from, or must be repaid to, a personal account or an unnamed payment handle is a strong indicator.
Look at the loan documentation. A regulated lender must give you a key fact statement setting out the annual percentage rate, the recovery mechanism, the grievance redressal officer's details and the cooling-off arrangements. No documentation at all, or documentation that appears only after disbursal, is characteristic of unauthorised operations.
Note the deduction at source. Where a much smaller sum arrives than was agreed, with the difference described as a processing fee, that pattern combined with a very short tenure is the standard predatory structure and is inconsistent with the disclosure requirements a regulated lender operates under.
Do not rely on the app's own claims. Apps routinely display a plausible company name and an NBFC registration number that is either invented or belongs to an unconnected entity. Where a name is given, check it against the Reserve Bank's own published list of registered NBFCs rather than accepting the app's assertion.
What to do in the first twenty-four hours
Stop paying under pressure. Paying an inflated demand to make the calls stop is the most common response and it reliably produces more demands, because it identifies you as someone who pays under pressure. Where a genuine principal is owed to a genuine lender, that can be dealt with properly afterwards.
Preserve everything before you delete anything. Screenshot every message, every call log entry with the number and timestamp, every threat, every message sent to a contact of yours, and the app's own screens showing the terms, the disbursal amount and the demand. Save the loan agreement and the disbursal SMS. This evidence is what every subsequent route depends on and it disappears when you uninstall.
Revoke the app's permissions — contacts, storage, photos, SMS, call logs — in your phone settings, then uninstall it. Revoking before uninstalling matters, because uninstalling alone does not always withdraw permissions already granted, and the contact list is the mechanism of the harassment.
Tell your contacts before the messages reach them, or as soon as they do. This is unpleasant and it is the single most effective countermeasure available, because the entire business model depends on shame. A short message explaining that a predatory app has your contact list and may send them something removes almost all of the leverage.
If money has been debited fraudulently, or you have paid to an account you now believe to be fraudulent, call 1930 immediately and file on the national cybercrime reporting portal. For financial fraud the speed of that call matters more than anything else, because the chance of freezing funds falls sharply with time.
File on cybercrime.gov.in with the evidence attached. The portal is the formal route for cyber-enabled financial crime and the online report is itself a formal complaint.
File an FIR where there have been threats, intimidation, extortion, morphed images or defamatory messages to your contacts. These are offences in their own right. Registration is mandatory where the information discloses a cognisable offence, and a station cannot refuse on jurisdiction grounds.
Where a regulated entity is behind the app, complain to that entity's grievance redressal officer in writing, whose details it is required to give you, and keep the reference. That step is a precondition for the Ombudsman route.
The rules a regulated lender is bound by
Where a bank or a registered NBFC sits behind the app, you are not making a moral appeal — you are asserting compliance obligations that already bind them.
The Reserve Bank's guidelines on recovery agents are explicit about conduct. Recovery agents must not resort to harsh methods: no use of threatening or abusive language, no persistently calling the borrower outside the stated hours of the day, no harassing relatives, friends or co-workers, no publishing the borrower's name, no threats of violence or bodily harm, and no misleading representations about the nature or consequences of the debt.
The Fair Practices Code requires that lenders should not resort to undue harassment in recovery — persistently bothering borrowers at odd hours or using muscle power is specifically identified as impermissible.
The digital lending guidelines add a layer directed at exactly this business model: disclosure of the regulated entity behind a lending app, a key fact statement including the annual percentage rate, restrictions on the flow of funds through pass-through accounts, limits on the data an app may access from the borrower's device, and a requirement that borrower consent for data be explicit and revocable.
Every regulated entity must have a dedicated grievance redressal mechanism for recovery-related complaints, and the details of it must be given to the borrower at disbursal. If the app never gave you those details, that is itself a breach and is worth stating in the complaint.
The escalation, where the entity does not resolve the complaint, is the Reserve Bank's ombudsman scheme, which covers deficiency in service by regulated entities, is free to the complainant, and is designed to be used without representation.
None of this depends on whether you owe the money. The recovery conduct rules are about conduct, and a borrower in default is entitled to their protection in full.
When there is no regulated entity behind it
If no bank or registered NBFC can be identified, the framing changes completely: this is not a lending dispute with a compliance problem, it is a criminal operation, and the regulatory routes have nothing to bite on.
The conduct involved typically maps onto several offences under the criminal law — criminal intimidation, extortion, defamation where messages are sent to third parties, and offences relating to obscene or morphed images where those are used. Where borrower data has been taken and misused, the information technology framework is engaged as well.
The route is therefore the national cybercrime reporting portal and an FIR, in parallel, with the 1930 helpline where money has moved. The online report on the portal is a formal complaint in its own right and does not replace the FIR for the intimidation offences.
Do not attempt to negotiate or to trace the operators yourself. These operations are frequently run from outside the country through layers of intermediaries, and engagement produces more contact rather than less.
Recognise the debt question honestly. Money that was actually disbursed to you is money you received, and the fact that the operation is unlawful does not mean the sum vanishes as a matter of principle. But the amount demanded — inflated by undisclosed charges, penalties and rollovers — is generally not the amount received, and an unregistered operation is not in a position to enforce anything through a court. The practical answer is to stop paying, document everything, and report.
Protect the rest of your finances. Where the app had access to your device, assume other credentials may be compromised: change passwords for banking and email, enable two-factor authentication, and check your credit report for accounts you did not open, since data harvested in these operations is reused.
Where threats extend to your workplace or family, tell them yourself first, and consider informing your employer's HR function directly rather than letting a message from an unknown number be their first information.
Repairing the damage and avoiding the next one
Once the immediate pressure is off, there are three pieces of clearing up worth doing.
Check your credit record. A regulated lender will have reported the loan and any default to the credit information companies, and an unregulated one will not have — which is itself a useful diagnostic. Where a default has been reported that you dispute, or where an account appears that you did not open, the credit information framework provides a dispute process through the credit information company and the lender.
Deal with any genuine underlying debt properly. Where a regulated lender is owed a real principal, engaging with its formal grievance and settlement process, in writing, is far better than either paying under pressure or ignoring it. A documented settlement closes the matter; a payment made to stop calls does not.
Review the permissions on every financial app on your phone. The specific permission that makes this harassment possible is access to contacts, and almost no legitimate lending app has a genuine need for it. Treat a request for contact list access from a lending app as disqualifying.
On borrowing safely in future, the checks are short. Confirm the regulated entity behind the app and check the name against the Reserve Bank's published list. Read the key fact statement, and specifically the annual percentage rate rather than a monthly or daily figure. Confirm that disbursal and repayment run through the regulated entity's account rather than an intermediary's. Reject anything with a tenure of days, deductions at source, or contact list access.
If the borrowing need is genuine and small, the alternatives are worth listing precisely because the apps market themselves on the absence of them: a bank overdraft, a loan against an existing deposit or against gold, a co-operative or self-help group facility, an employer salary advance, or a small credit facility through an entity that is actually registered.
Finally, if the harassment has affected your mental health, treat that as a serious consequence rather than an embarrassment. The coercion in this model is designed to be psychologically effective, and the shame it produces is manufactured. Free legal aid through the district legal services authority is available for the criminal complaint side of this for those eligible.
Key takeaways
- Settle first whether a bank or RBI-registered NBFC sits behind the app — regulated means a compliance route, unregulated means a criminal one, and the steps differ completely.
- Prohibited recovery conduct includes threats, calls outside stated hours, contacting relatives, friends and co-workers, and publishing your name — and it is prohibited whether or not you are in default.
- Tell your own contacts on day one. The business model depends entirely on the fear of them being told, and pre-empting it removes the coercive asset.
- Revoke contacts, storage and SMS permissions before uninstalling, because uninstalling alone does not always withdraw permissions already granted.
- Screenshot everything before deleting anything — the evidence disappears with the app and every subsequent route depends on it.
Who to contact
National Cyber Crime Reporting Portal
Report cyber-enabled financial crime, extortion and misuse of data. Call 1930 first if money has moved.
The regulator behind the recovery agent, fair practices and digital lending requirements, and the ombudsman scheme.
Free representation for the criminal complaint side through District Legal Services Authorities.
At a glance
- Who may lawfully lend
- Banks, RBI-registered NBFCs, state-permitted money lendersAnything else is an unauthorised lending operation
- Prohibited recovery conduct
- Threats, odd-hour calls, contacting relatives and colleaguesUnder the RBI's recovery agent and fair practices requirements
- Grievance mechanism
- Required of every regulated entityWith details given to the borrower at disbursal
- If a regulated lender
- Complain to the lender, then the RBI OmbudsmanFree to the complainant
- If unregulated
- cybercrime.gov.in and 1930Plus an FIR — this is criminal, not a regulatory dispute
- Contact list access
- The mechanism of the harassmentRevoke permissions and uninstall; do not grant them in the first place
- Money already moved
- Call 1930 immediatelySpeed matters more than anything else for recovery
- Owing money
- Is a civil matterThe harassment is a separate, criminal matter against the recoverer
What to do about loan app harassment — FAQ
Is loan app harassment illegal even if I actually owe the money?
Yes. Owing money is a civil matter; the harassment is separate. For regulated lenders, the Reserve Bank's recovery agent requirements prohibit threatening language, persistent calls outside stated hours, harassing relatives, friends or co-workers, publishing the borrower's name and threats of violence. Where no regulated entity is involved, the conduct maps onto criminal offences such as intimidation, extortion and defamation.
How do I know if a loan app is legal?
Lending can only be done by banks, NBFCs registered with the Reserve Bank, or entities permitted under state money lending law. A compliant digital lending app must disclose the regulated entity behind it and give a key fact statement with the annual percentage rate and grievance officer details. Check any name claimed against the Reserve Bank's published list of registered NBFCs rather than trusting the app.
The app is messaging my contacts. What do I do?
Screenshot the messages, then revoke the app's contacts, storage and SMS permissions in your phone settings before uninstalling it. Then tell your contacts yourself, plainly, that a predatory app has your contact list. It is unpleasant and it is the most effective step available, because the whole model depends on the fear of exposure rather than on your ability to pay.
Where do I report a loan app?
If a regulated entity is behind it, complain in writing to that entity's grievance redressal officer, then escalate to the Reserve Bank's ombudsman scheme, which is free. If no regulated entity can be identified, report on the national cybercrime portal at cybercrime.gov.in and file an FIR for the intimidation offences. Where money has moved, call 1930 immediately — speed determines whether funds can be frozen.
Should I pay to make the calls stop?
No. Paying an inflated demand under pressure reliably produces further demands because it identifies you as someone who pays under pressure, and the amount demanded is generally not the amount you received once undisclosed charges, penalties and rollovers are stripped out. Where a genuine principal is owed to a genuine lender, deal with that through its formal process in writing afterwards.
Can the police refuse to register my complaint about a loan app?
Not where the information discloses a cognisable offence, and threats, extortion and use of morphed images are cognisable. A station cannot refuse on the ground that the offence happened elsewhere — that is what a zero FIR exists for. If refused, complain in writing to the Superintendent of Police and then approach a magistrate, with free legal aid if needed.
Will this damage my credit score?
A regulated lender will report the loan and any default to the credit information companies; an unregulated operation generally will not, which is itself a useful diagnostic. Check your credit report afterwards for disputed defaults and for accounts you never opened, since harvested data is reused. The credit information framework provides a dispute process through the credit information company and the lender.
Read next
Sources & provenance
Facts verified
- 1.Reserve Bank of India — guidelines on digital lending RegulatorReserve Bank of IndiaUsed for: That lending may be carried out only by banks, registered NBFCs and entities permitted under other law; the warning about unauthorised lending apps; disclosure of the regulated entity behind an app; the key fact statement; restrictions on fund flow through pass-through accounts; and limits on access to borrower data
- 2.Reserve Bank of India — recovery agents engaged by banks RegulatorReserve Bank of IndiaUsed for: Prohibited recovery conduct including threatening language, persistent calls outside stated hours, harassing relatives, friends and co-workers, publishing the borrower's name and threats of violence
- 3.Reserve Bank of India — guidelines on recovery agents RegulatorReserve Bank of IndiaUsed for: The obligations on regulated entities for the conduct of recovery agents and the requirement for a recovery-related grievance mechanism whose details are given to the borrower
- 4.Reserve Bank of India — Fair Practices Code RegulatorReserve Bank of IndiaUsed for: That lenders must not resort to undue harassment in recovery, including persistently bothering borrowers at odd hours or using muscle power
- 5.Master Circular on Customer Service in Banks RegulatorReserve Bank of IndiaUsed for: Consolidated customer service obligations including grievance redressal and the escalation route to the ombudsman scheme
- 6.Reserve Bank of India — customer service guidelines RegulatorReserve Bank of IndiaUsed for: Disclosure obligations, grievance redressal machinery and the consumer-facing statement of what regulated entities owe borrowers
- 7.National Cyber Crime Reporting Portal OfficialMinistry of Home AffairsUsed for: Online reporting of cyber-enabled financial crime and misuse of data, and the 1930 helpline for cases where money has already moved
- 8.India Code — Bharatiya Nyaya Sanhita, 2023 LawGovernment of IndiaUsed for: The offences engaged by recovery harassment, including criminal intimidation, extortion and defamation
- 9.India Code — Bharatiya Nagarik Suraksha Sanhita, 2023 LawGovernment of IndiaUsed for: Mandatory registration of information disclosing a cognisable offence, registration irrespective of jurisdiction, and the remedies where a station refuses
- 10.Reserve Bank of India RegulatorReserve Bank of IndiaUsed for: The published list of registered non-banking financial companies against which an app's claimed registration can be checked
- 11.National Legal Services Authority OfficialNALSAUsed for: Free legal aid eligibility covering the criminal complaint arising from recovery harassment
Not a source — AI-assisted analysis on this page
- AI-assisted analysis — removing the coercive asset — The assessment that the business model rests on fear of exposure to the borrower's contacts rather than on inability to pay, and the recommendation to message those contacts pre-emptively on day one before uninstalling, complaining or paying, are our conclusions and our characterisation of how the coercion operates. So is the guidance on the order of revoking permissions before uninstalling. These are not published regulatory guidance. The lending authorisation position, the prohibited recovery conduct, the digital lending requirements and the grievance and ombudsman routes are documented in the Reserve Bank material cited above.
The position that lending may be carried out only by banks, RBI-registered NBFCs and entities permitted under other law, the warning about unauthorised lending apps, the disclosure and key fact statement requirements, the restrictions on fund flow and on access to borrower data, the prohibited recovery conduct, the Fair Practices Code position on undue harassment and the requirement for a recovery-related grievance mechanism all come from the Reserve Bank of India material cited above. Online reporting and the 1930 helpline come from the National Cyber Crime Reporting Portal. The offences engaged, and the obligation to register information disclosing a cognisable offence irrespective of jurisdiction, come from the Bharatiya Nyaya Sanhita 2023 and the Bharatiya Nagarik Suraksha Sanhita 2023 on India Code; these replaced the earlier criminal codes from 1 July 2024 and section numbers in older material are superseded. Deliberately not quoted here: interest rate caps, the cooling-off period, the permitted hours for recovery contact, penalty amounts and the ombudsman scheme's monetary limits — these are set by regulation or notification and are revised, so take them from the current Reserve Bank guidelines. One passage is marked as AI-assisted analysis. This is general information, not legal or financial advice.
Facts on this page are taken from the sources listed above — Government of India ministries and departments, statutory authorities, regulators such as the RBI, SEBI, IRDAI and TRAI, state governments and official statistical releases. Comparisons, judgments and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Fees, slabs, limits and processing times change, often at the start of a financial year on 1 April; figures are current as of the review date shown and should be confirmed with the responsible department before you rely on them. A great deal of Indian administration is state administration — where a rule differs by state, this site says so.