Most people lose money to cyber fraud because of three beliefs that are simply wrong: that the bank will refund them automatically, that the complaint can wait until office hours, and that online fraud cannot be traced anyway. In fact, whether you get your money back turns almost entirely on how fast you report, first to the national cybercrime helpline 1930 and then in writing to your bank. Report an unauthorised electronic transaction to the bank within three working days and the Reserve Bank's customer protection directions can put your liability at zero. Wait a week and the loss may be yours.
Part of the cyber crime and online fraud practice at S Jain & Attorneys, Bangalore.
This guide sets out the misconceptions that cost victims money, the provisions that actually apply now that the Bharatiya Nyaya Sanhita, 2023 has replaced the Indian Penal Code, the correct reporting sequence, and how far a bank's liability really goes.
The first hour decides how much you recover
A modern scam does not end when the money leaves your account. It moves. The amount is pushed through a chain of mule accounts and wallets, split into smaller sums, and cashed out. Every layer it passes through makes recovery harder, because the freeze has to be placed on an account that still holds the money. That is why the Indian Cyber Crime Coordination Centre (I4C) built the reporting system around speed. When you call 1930 or file on cybercrime.gov.in, a ticket is raised that reaches the banks and payment operators in the chain, and the balance lying in the destination account can be put on hold.
Practitioners and the helpline itself refer to the first hour as the golden hour. It is not a legal term and no rule guarantees a freeze. It simply reflects the reality that a hold placed in minutes catches money that a hold placed the next morning will not.
Deadline warning. Two clocks start the moment the money leaves. The first is the freeze clock, measured in minutes, which is why 1930 comes before everything else. The second is the liability clock under the Reserve Bank's directions, measured in working days, which is why a written complaint to the bank must follow the same day. Missing either one costs money independently of the other.
Why the very first report has to go to 1930 rather than anywhere else.
The money moves
The amount is pushed through a chain of mule accounts and wallets, split into smaller sums, and cashed out. Every layer it passes through makes recovery harder.
What the helpline does
Calling 1930 or filing on cybercrime.gov.in raises a ticket that reaches the banks and payment operators in the chain, so the balance in the destination account can be held.
The golden hour
Practitioners and the helpline call the first hour the golden hour. It is not a legal term and no rule guarantees a freeze, but the timing decides what is left to hold.
Eight misconceptions that cost victims money
| What people believe | What actually applies |
|---|---|
| It only happens to people who are not tech savvy. | Engineers, chartered accountants and senior bankers are routinely defrauded. Current scams attack trust and urgency, not technical ignorance. A convincing caller who already knows your last four digits does not need you to be naive. |
| The bank will automatically refund the money. | Nothing is automatic. Liability is decided under the Reserve Bank circular of 6 July 2017 on limiting customer liability in unauthorised electronic banking transactions, and it depends on who was at fault and how quickly you notified the bank in writing. |
| Cyber crime cannot be traced, so there is no point complaining. | Transactions leave a trail of account numbers, UPI handles, IP logs and device identifiers. Money-trail work by cyber cells is now routine, and BNS section 111 expressly treats cyber crimes as capable of amounting to organised crime where a syndicate is involved. |
| Filing a complaint is complicated and needs a lawyer. | The first report takes minutes. Call 1930 or file on cybercrime.gov.in yourself. Legal help matters later, for the FIR, for pushing an unresponsive bank and for recovery, not for the first report. |
| I must go to the police station in the area where the fraudster sits. | Section 173(1) of the Bharatiya Nagarik Suraksha Sanhita, 2023 requires information about a cognizable offence to be recorded irrespective of the area where the offence was committed. That is the zero FIR principle, now written into the statute. |
| Old sections such as IPC 420 still govern. | The IPC, the Criminal Procedure Code and the Evidence Act have been replaced. Cheating is now section 318 of the Bharatiya Nyaya Sanhita, 2023, procedure comes from the BNSS, and electronic evidence is governed by the Bharatiya Sakshya Adhiniyam, 2023. |
| If I keep talking to the caller I can get my money back. | Staying on the call is what the fraud depends on. Every extra minute is a minute the freeze is not in place, and the second call, offering to recover your loss for a fee, is usually the same group. |
| Once the police have it, there is nothing else to do. | The criminal case and the money are two separate tracks. Recovery normally comes from the bank liability route, the Reserve Bank Ombudsman, a consumer commission or an adjudication claim under the IT Act, not from the criminal court. |
Which law applies to which scam
Cyber fraud is not one offence. A single incident usually attracts a cheating provision from the Bharatiya Nyaya Sanhita, 2023 plus one or more computer specific offences from the Information Technology Act, 2000. Knowing which is which matters when the FIR is being drafted, because a badly framed FIR is one of the commonest reasons a matter stalls.
| Scam pattern | Principal offence | Commonly added provisions |
|---|---|---|
| OTP, UPI collect request or fake payment link, money debited | BNS s. 318 (cheating). Where property is delivered, s. 318(4) carries up to seven years | IT Act s. 66D (cheating by personation using a computer resource) |
| Fake customer care number or a caller posing as bank, courier or telecom staff | BNS s. 319 (cheating by personation), up to five years | IT Act s. 66D |
| Someone uses your password, e-signature or unique ID to transact | IT Act s. 66C (identity theft), up to three years and fine up to Rs. 1 lakh | BNS s. 318; IT Act s. 66 read with s. 43 where the account or device was accessed without authority |
| Fake investment, trading or task based earning app | BNS s. 318(4) | BNS s. 316 (criminal breach of trust) where funds were entrusted; BNS s. 111 where a syndicate is shown |
| Forged documents, cloned websites or fabricated electronic records | BNS s. 336 (forgery), which expressly covers a false electronic record | BNS s. 318; IT Act s. 66 |
| Sextortion, morphed images, threats to publish private content | BNS s. 308 (extortion); BNS s. 351 (criminal intimidation) | IT Act s. 66E (violation of privacy); IT Act s. 67 or 67A depending on the content |
| Digital arrest, a caller posing as police, CBI, ED or a court | BNS s. 319 and s. 318(4) | IT Act s. 66D; BNS s. 351 where threats are used |
| Company or service provider leaks your data and you suffer loss | IT Act s. 43A (compensation for failure to protect sensitive personal data) | IT Act s. 72A where disclosure was in breach of a lawful contract |
Common mistake. Reporting to the police station first and to the bank later. The police station will register your complaint, but the police cannot place the freeze. The freeze comes from the banking channel triggered by 1930 and cybercrime.gov.in, and the bank's own liability clock only starts when you notify the bank. Do those two first, then the station.
What to do in the first twenty four hours
- End the call. Do not confirm anything, do not install any application the caller asks you to install, and do not pay a further amount to release the first one.
- Call 1930 from any phone, or file at cybercrime.gov.in, and give the exact amount, time, transaction or UPI reference and the beneficiary details visible in your app. Note the acknowledgement number the system gives you.
- Notify your bank in writing on the same day. Use the bank's app or net banking grievance option, or email the branch and the nodal grievance officer, and keep the acknowledgement. A phone call alone leaves you with no proof of the date you reported.
- Ask the bank to block the card, freeze the account or disable UPI on the compromised handle, and to record the complaint as an unauthorised electronic transaction, not as a general query.
- Change the passwords and the UPI PIN on every account that shares an email address or mobile number with the compromised one, and remove any screen sharing or remote access application installed during the call.
- Preserve evidence before anything is deleted. Take full screenshots showing date, time and the whole screen, save the SMS and email alerts, note the caller number and UPI ID, and export the call log.
- File an FIR at a police station or cyber police station. Under BNSS s. 173(1) it must be recorded whichever station you approach, and under s. 173(2) you are entitled to a free copy of the FIR at once.
- If the FIR is refused, send the substance of the complaint in writing by post to the Superintendent of Police under BNSS s. 173(4), and if that fails, apply to the Magistrate under BNSS s. 175(3), the provision that replaces the old s. 156(3) CrPC.
- Diarise the ninety day mark. That is the outer limit within which the bank must resolve your complaint and establish your liability under the Reserve Bank directions.
How much of the loss the bank must bear
This is the part most victims never find out. The Reserve Bank circular DBR.No.Leg.BC.78/09.07.005/2017-18 dated 6 July 2017 fixes when a customer bears nothing, when the customer bears a capped amount, and when the loss falls back on the customer.
The customer's liability is zero in two situations: where the fraud, negligence or deficiency was contributed to by the bank, whether or not you reported it, and where the failure lay somewhere else in the system, neither with the bank nor with you, and you notified the bank within three working days of receiving the bank's communication about the transaction.
| Time taken to report to the bank after its communication | Customer's liability in a third party breach |
|---|---|
| Within 3 working days | Zero |
| Within 4 to 7 working days | The transaction value or the capped amount, whichever is lower. The cap is Rs. 5,000 for a basic savings account, Rs. 10,000 for other savings accounts, prepaid instruments, gift cards, MSME current accounts and credit cards with a limit up to Rs. 5 lakh, and Rs. 25,000 for other current accounts and credit cards with a limit above Rs. 5 lakh |
| Beyond 7 working days | As per the bank's board approved policy, which the bank must publish |
Three further points in the same circular are worth knowing. Working days are counted by the schedule of your home branch, excluding the day you received the bank's communication. Once you notify the bank, it must shadow credit the disputed amount within ten working days of notification, value dated to the date of the unauthorised transaction, without waiting for any insurance settlement. And the burden of proving customer liability in an unauthorised electronic banking transaction lies on the bank, not on you.
The one situation where the circular does not help is customer negligence, for example where you shared the credentials or the OTP. There, you bear the loss until the moment you report, and everything after the report is the bank's. That is another reason the timestamp on your written complaint matters so much.
Key takeaway. Complain to the bank in writing, on the same day, in words that say the transaction was unauthorised. A dated written complaint is what converts the Reserve Bank framework from a policy document into your entitlement, and it is the single document that decides which row of the table above you fall into.
If the bank says no: the escalation ladder
- Written complaint to the bank, with the transaction details, the 1930 acknowledgement number and the FIR copy if you have it. Insist on a complaint reference number.
- Escalate internally to the bank's nodal or principal nodal officer for grievance redressal if there is no meaningful response.
- Reserve Bank Ombudsman under the Reserve Bank Integrated Ombudsman Scheme, 2021, filed online through the Reserve Bank's complaint management system. Under clause 10(2) of the scheme a complaint lies only after you have made a written complaint to the bank and it was rejected wholly or partly, or you received no reply within 30 days, and it must be filed within one year of the bank's reply, or within one year and 30 days of your complaint if no reply came.
- Consumer commission under the Consumer Protection Act, 2019, on the footing of deficiency in service. Since the 2021 jurisdiction rules, the District Commission hears claims where the consideration does not exceed Rs. 50 lakh, the State Commission from above Rs. 50 lakh to Rs. 2 crore, and the National Commission above Rs. 2 crore.
- Adjudicating officer under section 46 of the IT Act for compensation, where the claim arises from a contravention of the Act. That officer has jurisdiction where the claim for damage does not exceed Rs. 5 crore, above which the competent court decides.
- Writ petition to the High Court in the narrow cases where a public authority has acted arbitrarily or a regulator has refused to act at all.
These routes are alternatives, not steps you must climb in order in every case, and the Ombudsman will not take a matter already pending before a court or commission. Choose one deliberately.
Evidence: why screenshots alone are not enough
Electronic evidence is now governed by the Bharatiya Sakshya Adhiniyam, 2023. Section 61 says a record cannot be rejected merely because it is electronic, section 62 says the contents of electronic records are proved in accordance with section 63, and section 63 sets the conditions on which a computer output is admissible. Critically, section 63(4) requires a certificate, submitted along with the electronic record at each instance where it is tendered, identifying the record, describing how it was produced, giving the particulars of the device, and signed both by the person in charge of the device or the relevant activity and by an expert.
In practical terms this means that the WhatsApp screenshot on your phone is the start of the evidence, not the end of it. Keep the original device if you can. Do not factory reset it, do not delete the chat because it upsets you, and do not forward the only copy and then clear the app. Bank statements and card statements should be obtained in the bank's own certified form. Where the recording of a call or a screen exists, keep the original file rather than a re-encoded copy shared over a messaging app.
Recognising the current scam patterns
The scripts change every few months but the levers do not. A caller manufactures authority, then urgency, then isolation. The digital arrest script is the clearest example: a caller claims to be from a police unit, customs, the narcotics wing or a central agency, says a parcel or a SIM in your name has been found with contraband, moves you to a video call with an apparent uniform and a fake courtroom backdrop, and tells you not to speak to anyone while the matter is verified. No Indian agency arrests, interrogates or takes custody over a video call, and no agency asks you to transfer money to a verification account. There is no such thing as a digital arrest.
Other recurring patterns are the investment or trading group that shows fabricated profits and then blocks withdrawal until a tax is paid, the part time task or rating job that pays small amounts and then demands a deposit, the fake customer care number that surfaces at the top of a search, the KYC expiry message that carries a link or an application file, and the loan application that harvests contacts and photos and then blackmails the borrower. If a stranger's instruction is that you install an application, share your screen, or move to a private chat, treat that as the end of the conversation.
What actually prevents this
- Never share an OTP, CVV, PIN, UPI PIN or password with anyone, including a person who says they are from your bank. No genuine bank employee needs any of them.
- Remember the direction of a UPI transaction. You never enter your UPI PIN to receive money. If someone asks you to approve a request or enter your PIN to collect a refund, it is a debit.
- Turn on two factor authentication on your bank accounts, primary email and any account that can reset the others. The email account is the master key, so protect it first.
- Never install a screen sharing, remote access or unknown APK file at the instruction of a caller, and never grant SMS or accessibility permissions to an application you did not go looking for.
- Set transaction limits low by default and raise them for the one transaction you need. Keep a separate low balance account for online payments.
- Read the SMS alert rather than dismissing it, and reconcile your bank and card statements monthly. The Reserve Bank framework runs off the date of the bank's communication, which means an unread alert is a running clock.
- Check your credit report periodically for loans and cards you never applied for.
- Do not transact on public wifi, and do not use a search engine result to find a bank or company helpline. Use the number printed on the card or the official application.
- Talk to the older members of the family about the digital arrest script and the fake refund call before they receive one, not after.
What we tell clients
The pattern in these matters is depressingly consistent. Recovery is decided in the first few hours, and it is lost in ordinary, understandable ways: the victim spends forty minutes trying to reach the bank on a customer care line instead of dialling 1930, or reports on the phone and never puts it in writing, so weeks later there is nothing to prove when the bank was told. Cases also weaken because the complaint is vague. A cyber complaint that says money was fraudulently withdrawn is worth much less than one that lists each debit with its time, amount, reference number and beneficiary handle, because the money trail is what the investigating officer can actually act on. The other frequent failure is the second scam: a caller who says he is from a recovery cell or a cyber unit and can return the money for a processing fee. No agency does that. Finally, be realistic about outcomes. A freeze secured in the first hour often produces a real refund, sometimes after an application to the Magistrate for release of the frozen amount. Once the money has been layered and withdrawn, the criminal case may still run, but the recovery conversation shifts to the bank's liability under the Reserve Bank framework, and that is a paper case built on your written complaint and the dates on it. Also worth saying plainly: if the loss is small and you are simply exhausted, still report on 1930 and cybercrime.gov.in, because the beneficiary account you name is very often the same account draining someone else.
If you want the reporting mechanics in more detail, our companion guide on how to report cyber crime in India walks through the portal category by category.
Frequently Asked Questions
How do I report cyber fraud in India?
Call the national cybercrime helpline 1930 as soon as possible and file a complaint at cybercrime.gov.in with your transaction details. Then notify your bank in writing the same day, and file an FIR at any police station.
Can I get my money back after an online fraud?
Often yes, if you act fast. Reporting within the first few hours lets banks and the helpline place a hold before the money is withdrawn, which greatly improves recovery. Separately, the Reserve Bank framework may put the loss on the bank depending on fault and on how quickly you reported.
How quickly must I report to my bank?
Immediately, and in writing. Under the Reserve Bank circular of 6 July 2017, a third party breach reported within three working days of the bank's communication carries zero customer liability, four to seven working days carries a capped liability, and beyond seven working days the bank's board approved policy governs.
Is a digital arrest call genuine?
No. No agency in India arrests, interrogates or takes custody of anyone over a phone or video call, and none demands money to clear your name or to a verification account. Disconnect and report it on 1930.
What evidence should I preserve?
Screenshots showing the full screen with date and time, transaction IDs and UPI references, the fraudster's number and UPI ID, emails, SMS alerts and call logs. Keep the original device and the original files, because under section 63 of the Bharatiya Sakshya Adhiniyam, 2023 the electronic record has to be tendered with a certificate under section 63(4).
Can the police refuse to register my FIR because the fraudster is in another state?
No. Section 173(1) BNSS requires information about a cognizable offence to be recorded irrespective of the area where the offence was committed, which is the zero FIR rule. If it is refused anyway, send the substance in writing by post to the Superintendent of Police under s. 173(4), and if necessary apply to the Magistrate under s. 175(3) BNSS.
Which sections will the FIR be registered under?
Typically section 318 of the Bharatiya Nyaya Sanhita, 2023 for cheating, with section 319 where the fraudster impersonated someone, together with sections 66C and 66D of the Information Technology Act, 2000 for identity theft and cheating by personation using a computer resource. Forgery of an electronic record falls under BNS section 336.
What if the bank rejects my claim?
Escalate to the bank's nodal grievance officer, then to the Reserve Bank Ombudsman under the Integrated Ombudsman Scheme, 2021, which you can approach if the bank rejected the complaint or did not reply within 30 days, within one year of the reply. A consumer commission under the Consumer Protection Act, 2019 and an adjudication claim under section 46 of the IT Act are the other routes.
Does the bank or the customer have to prove the transaction was unauthorised?
The Reserve Bank circular places the burden of proving customer liability in an unauthorised electronic banking transaction on the bank. In practice you should still document everything, because the bank will point to the credentials and the OTP.
Do I need a lawyer to report cyber fraud?
Not for the first report, and waiting for one wastes the hours that matter most. Legal help becomes useful for framing the FIR properly, for pushing an unresponsive bank or investigating officer, for an application to release frozen funds, and for the compensation claim.
If you have lost money or data, reporting quickly matters far more than anything else. Legal help can follow once the immediate report is in.
This article is for general informational purposes only and does not constitute legal advice. Please consult a qualified advocate about your specific matter.






