How to report cyber fraud in India
The golden hour is real: money reported within about an hour can often be held before it leaves the chain of accounts. Call 1930 first, then your bank, then file online. Plus the frauds actually running now, and the RBI rule limiting your liability.
Short answer
Call 1930 immediately — within the first hour if possible — then file at cybercrime.gov.in, then notify your bank in writing. Under RBI rules, a customer who reports an unauthorised electronic transaction within three working days generally has zero liability. Speed determines both recovery and liability.
Cyber financial fraud in India is fast, industrialised and largely reversible only in the first hour. Money moves through a chain of mule accounts within minutes, and the Citizen Financial Cyber Fraud Reporting and Management System exists precisely to interrupt that chain before it completes.
That system works through one number: 1930. It is free, it operates around the clock, and calling it before you call anyone else is the single most consequential decision in the whole sequence.
The first hour, in order
Call 1930. Do this before calling your bank, before searching online, before anything else. The operator takes the transaction details and raises a ticket that goes to the banks and payment intermediaries in the chain, who can place a hold on the funds if they have not already been withdrawn. The whole architecture is built around speed.
Have ready: your bank account or card number, the transaction date, time and amount, the beneficiary details if you have them, and the reference or UTR number.
Then call your bank's fraud line — the number on the back of the card or on your statement, never a number from a search result or a message. Block the card or freeze the account. Ask for a complaint reference number and the name of the person you spoke to.
Then file the complaint at cybercrime.gov.in. The online report is itself a formal complaint and generates an acknowledgement number. Upload screenshots, message threads, transaction records and anything else you have.
Then confirm to your bank in writing — email is fine — repeating what was reported and when. The written record of the date and time of your report is what establishes your liability position, and phone logs alone are weaker evidence.
Change passwords, starting with email, and enable two-factor authentication. If your phone stopped working around the time of the fraud, suspect a SIM swap and call your telecom operator immediately.
Do not delete anything. Messages, emails, call records and transaction confirmations are all evidence.
Your liability, and the rule banks do not volunteer
The RBI's limited liability framework for unauthorised electronic transactions is the most important consumer protection in this area and the least known.
Where the unauthorised transaction results from a deficiency in the bank's own systems, the customer has zero liability regardless of when it is reported.
Where it results from a third-party breach — where the fault is neither the bank's nor the customer's — the customer has zero liability if the transaction is reported within three working days of receiving the bank's communication about it. Reporting between four and seven working days limits liability to a prescribed amount; beyond that it is determined by the bank's own board-approved policy.
Where the loss results from the customer's own negligence — sharing a PIN, password or OTP — the customer bears the loss up to the point of reporting. After reporting, the bank bears it.
The bank must credit the amount to your account within ten working days of your notification where its liability is established, without waiting for the outcome of any investigation or insurance claim.
The bank bears the burden of proving customer liability. If a bank tells you the loss is yours because you shared an OTP, ask them to state that in writing with reference to the RBI circular — the requirement to justify it in writing changes many conversations.
If the bank does not resolve it within 30 days, escalate to the RBI Ombudsman through cms.rbi.org.in or by calling 14448. It is free, and the Ombudsman's award is binding on the bank.
The frauds actually running
The common structure across all of them is manufactured urgency plus a request for an OTP, a payment or an app installation. Any two of those three together is a fraud, essentially without exception.
The two rules that defeat almost all of it: no genuine institution ever asks for an OTP, PIN or password, and you never enter a UPI PIN to receive money.
| Fraud | How it works | The tell |
|---|---|---|
| Digital arrest | A caller claiming to be police, CBI, customs or TRAI says a parcel or SIM in your name is linked to a crime, then keeps you on video 'under arrest' until you transfer money | No Indian agency arrests anyone by video call or demands money to clear a case |
| UPI collect request | A 'buyer' sends a request to pay, framed as sending you money | You never enter a PIN to receive money — only to send it |
| KYC expiry | SMS or call saying your bank, wallet or SIM KYC has expired, with a link or an app to install | Banks do not send KYC links; they ask you to visit a branch or use their own app |
| Job and task scams | Small payments for simple online tasks build trust, then a large 'deposit' is required to withdraw earnings | Any job that requires you to pay to be paid |
| Loan app harassment | Instant loan apps harvest contacts and photos, then threaten and shame borrowers | Check the lender is RBI-registered before installing anything |
| Customer care number | A fake support number ranks in search results; the 'agent' asks you to install a screen-sharing app | Never install AnyDesk, TeamViewer or similar at anyone's phone instruction |
| Investment and trading groups | WhatsApp or Telegram groups showing fabricated profits, with a fake app for deposits | Check SEBI registration; guaranteed returns are always fictitious |
Patterns per MHA, RBI and I4C advisories; specific scripts change constantly.
After reporting, and preventing the next one
Track your complaint on cybercrime.gov.in with the acknowledgement number. Complaints are routed to the relevant state cyber cell, and you may be asked to visit or to file a formal FIR.
Follow up. Recovery, where it happens, generally comes from the funds being held early rather than from a later investigation — which is again why the first hour matters so much.
For fraudulent loans taken in your name, dispute them with the lender and with all four credit bureaus — CIBIL, Experian, Equifax and CRIF High Mark — enclosing the cyber crime acknowledgement. Credit report disputes are free and the bureau must investigate.
Check your credit report periodically. Each bureau must provide one free full report a year under RBI rules, and an unrecognised loan or enquiry is the earliest signal of identity misuse.
Lock your Aadhaar biometrics through myAadhaar, use a masked Aadhaar for photocopies, and use a Virtual ID where a service asks for an Aadhaar number.
Set transaction alerts and daily limits on your cards and UPI apps — the limits are adjustable, and lowering them costs nothing.
For frauds involving substantial sums, also report to IC3-equivalent national bodies where the counterparty is overseas, and consider a lawyer where the amount justifies it. Free legal aid through NALSA is available to those who qualify.
Key takeaways
- Call 1930 before you call your bank — it reaches the whole chain of intermediaries at once, which no single bank's fraud line can.
- Report an unauthorised transaction within three working days and RBI rules generally give you zero liability.
- The bank bears the burden of proving customer negligence — ask for any such claim in writing citing the RBI circular.
- No genuine institution asks for an OTP, and you never enter a UPI PIN to receive money.
- If unresolved after 30 days, the RBI Ombudsman is free and its award binds the bank — call 14448.
Who to contact
Call first, ideally within the hour. Reaches banks and payment intermediaries to hold funds.
National Cyber Crime Reporting Portal
Formal online complaint with an acknowledgement number; anonymous reporting for crimes against women and children.
Free, binding resolution of bank and payment disputes after 30 days with the institution.
Emergency police assistance.
Free legal representation for those who qualify.
At a glance
- First call
- 1930National cyber fraud helpline, 24/7
- Golden hour
- First ~60 minutesWhen funds can most often be held
- Online report
- cybercrime.gov.in
- Zero liability
- Report within 3 working daysRBI limited liability framework
- Bank response
- Credit within 10 working daysWhere the bank's liability is established
- If unresolved
- RBI OmbudsmanAfter 30 days with the bank; call 14448
- Anonymous reporting
- AvailableFor crimes against women and children
How to report cyber fraud in India — FAQ
What is the first thing to do if I am a victim of online fraud in India?
Call 1930 immediately, before calling your bank. The national helpline raises a ticket that reaches every bank and payment intermediary in the transaction chain at once, allowing funds to be held before they are withdrawn. Then call your bank's fraud line, file at cybercrime.gov.in, and confirm to your bank in writing.
Will I get my money back after cyber fraud?
It depends heavily on speed. Funds reported within the first hour can often be held before leaving the chain of mule accounts. Separately, RBI rules give you zero liability for unauthorised electronic transactions reported within three working days, with the bank required to credit your account within ten working days where its liability is established.
What is a digital arrest scam?
A caller impersonating police, CBI, customs or TRAI claims a parcel, SIM or bank account in your name is linked to a crime, then keeps you on a video call 'under arrest' while extracting transfers. No Indian agency arrests anyone by video call, holds anyone by phone, or takes money to clear a case. Hang up and call 1930.
Can someone take money from my account using a UPI request?
Only if you approve it. A collect request asks you to pay, and fraudsters frame it as receiving money. The rule that defeats it entirely: you never enter your UPI PIN to receive money, only to send it. If any transaction asks for your PIN, money is leaving your account.
What if my bank refuses to refund an unauthorised transaction?
Ask them to state in writing why, with reference to the RBI's limited liability circular — the bank bears the burden of proving customer negligence. If unresolved after 30 days, escalate free to the RBI Ombudsman at cms.rbi.org.in or on 14448. The Ombudsman's award is binding on the bank.
Read next
Sources & provenance
Facts verified
- 1.National Cyber Crime Reporting Portal OfficialMinistry of Home AffairsUsed for: 1930 helpline, online reporting and the financial fraud reporting system
- 2.Indian Cybercrime Coordination Centre OfficialMinistry of Home AffairsUsed for: Fraud patterns, advisories and the citizen reporting architecture
- 3.Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions RegulatorReserve Bank of IndiaUsed for: Zero liability window, reporting timelines and the ten-working-day credit requirement
- 4.RBI Ombudsman Scheme RegulatorReserve Bank of IndiaUsed for: Escalation after 30 days and binding awards
- 5.UPI safety OfficialNational Payments Corporation of IndiaUsed for: PIN is never required to receive money; collect request misuse
- 6.Credit report access RegulatorReserve Bank of IndiaUsed for: One free full credit report a year from each bureau
- 7.Digital lending guidelines RegulatorReserve Bank of IndiaUsed for: Requirements on lending apps and how to verify a registered lender
Not a source — AI-assisted analysis on this page
- AI-assisted analysis — call order, and the tells — The conclusion that calling 1930 before the bank materially changes recovery odds, and the 'tell' column identifying what gives each fraud pattern away, are our analysis. Fraud scripts change constantly; the underlying reporting architecture and liability rules are cited.
Reporting channels, the liability framework, ombudsman escalation, UPI mechanics and credit report rights come from the Ministry of Home Affairs, I4C, the RBI and NPCI as cited above. Liability amounts, timelines and ombudsman thresholds are set by RBI circulars that are periodically revised — check rbi.org.in for current terms. Fraud patterns change constantly; the structural tells are more durable than the specific scripts. One passage is marked as AI-assisted analysis. This is general information, not legal advice.
Facts on this page are taken from the sources listed above — Government of India ministries and departments, statutory authorities, regulators such as the RBI, SEBI, IRDAI and TRAI, state governments and official statistical releases. Comparisons, judgments and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Fees, slabs, limits and processing times change, often at the start of a financial year on 1 April; figures are current as of the review date shown and should be confirmed with the responsible department before you rely on them. A great deal of Indian administration is state administration — where a rule differs by state, this site says so.