Golden hour — first 1 to 2 hours matter most

Lost money online? Call 1930 right now.

The National Cyber Crime Helpline (1930) and cybercrime.gov.in can freeze the receiver bank account before the fraudster withdraws. Every minute counts.

1930

Free • 24×7 • Operates in all major Indian languages

A closed silver-grey laptop, a small green snake plant in a terracotta pot and a coiled white earphone wire on a warm grey concrete surface — emergency cyber fraud hero

Golden-hour checklist — do these in order

The first 60 minutes after the fraud are the only window in which banks can usually reverse the transaction. Once the money leaves the receiver account, recovery becomes extremely hard.

1

Dial 1930 — file the financial fraud complaint

The operator will note the transaction ID, sender bank, receiver bank, and amount. They route the freeze request to the receiver bank within minutes.

Tap to call 1930
2

Call your bank — freeze cards, change UPI PIN

Use the number printed on the back of your debit/credit card (not the one in a suspicious SMS). Block all cards, change UPI PIN, change internet-banking password, and disable any auto-debits you do not recognise.

Never share OTPs, CVV, or PIN — even with someone claiming to be from your bank or the police.

3

Preserve evidence — screenshot everything

Save these before the apps auto-delete them: bank SMS / email confirmation, UPI app transaction page, fraudster's phone number / WhatsApp profile / email, any chat screenshots, the website URL or app name where it happened, your call log showing time of the fraud call.

  • Bank debit SMS / email (timestamp visible)
  • UPI / wallet transaction reference (UTR or RRN number)
  • Fraudster's mobile number, UPI ID, or bank account number
  • WhatsApp / SMS chat screenshots (do not delete the chat)
  • Phishing website URL or fake app name
4

File the formal complaint at cybercrime.gov.in

The 1930 phone call alone is not enough — within 24 hours you must also lodge a written complaint at the National Cyber Crime Reporting Portal. This is what triggers actual investigation by the local cyber-cell.

Open cybercrime.gov.in
5

Get a written FIR from your local police station

Carry your evidence pack + the 1930 acknowledgement number + the cybercrime.gov.in complaint reference. Police are legally required to register a 'Zero FIR' even if the fraudster is in another state — insist on it.

6

Inform the credit bureaus + apps + RBI

If KYC documents (Aadhaar / PAN) were shared with the fraudster: lock your Aadhaar biometrics at uidai.gov.in, raise a credit-freeze with CIBIL / Experian / Equifax, and report to the RBI Sachet portal (sachet.rbi.org.in) for any unlicensed lending or investment scam.

What kind of scam was it?

Knowing the category helps the cyber-cell investigator. Select the closest match when filing at cybercrime.gov.in.

  • UPI / wallet fraudsomeone tricked you into a UPI request, fake QR scan, or 'collect' request
  • OTP phishingcaller posed as bank / KYC officer / electricity board and got the OTP
  • Investment / trading scamWhatsApp / Telegram group promised guaranteed returns
  • Loan-app fraudunauthorised loan app harassed you with morphed photos / contact list threats
  • Job / task fraudpaid 'registration fee' for a job, or did rating tasks for advance commissions
  • Digital arrest / fake CBIvideo call from 'CBI / RBI / Customs' threatening arrest unless you transfer money
  • Romance / matrimony scamonline partner asked for money, gifts, or customs duty
  • Sextortion / blackmailthreats to release morphed or intimate content unless you pay

Watch out for the SECOND scam

After the first scam, fraudsters often call back posing as 'police / cyber-cell / RBI recovery agent' offering to recover the lost money for a fee. This is a second scam. The real 1930 / cybercrime.gov.in / police will NEVER:

  • Ask for a 'processing fee' or 'recovery commission'
  • Ask you to install AnyDesk, TeamViewer, or any remote-access app
  • Ask for your OTP, debit card PIN, CVV, or UPI PIN
  • Send you a payment link to 'verify' refunds

The legal sections that apply

  • IT Act 2000, §66CIdentity theft (fraudulent use of password / electronic signature / unique identifier). Up to 3 years jail + ₹1L fine.
  • IT Act 2000, §66DCheating by personation using a computer resource. Up to 3 years jail + ₹1L fine. This is the main section for OTP / phishing fraud.
  • BNS 2023, §318(4)Cheating (replaces old IPC §420). Up to 7 years jail + fine.
  • BNS 2023, §319Cheating by personation (replaces old IPC §416/419).
  • BNS 2023, §336(3)Forgery with intent to cheat (covers fake KYC / fake screenshots).
Disclaimer: This page is informational guidance, not legal advice. Cyber-fraud investigations are time-sensitive — the steps above maximise your chance of recovery but do not guarantee it. Consider engaging an advocate experienced in IT Act §66 and BNS §318 cases for follow-up.
Back to Emergency Talk to a lawyer