Overview
In simple terms… a Cyber Crime Complaint is what you file when someone uses a phone, computer, payment app, social media account, email or website to cheat, threaten, harass, impersonate, steal from or otherwise act unlawfully against you.
These matters are unusual in how time-sensitive they are. In financial fraud, early reporting is what gives banks and law enforcement any chance of tracing and blocking funds before they are layered beyond reach. In harassment and reputation matters, early preservation is what stops the evidence disappearing when a profile is deleted or a post is taken down.
This page covers both sides — filing a complaint, and responding when a complaint, notice or account freeze lands on you.
The First Few Hours
If money has just left your account, do these things now and read the rest of this page afterwards. Call 1930. Inform your bank and get a written acknowledgement with a reference number. File on the National Cyber Crime Reporting Portal and keep the acknowledgement number. Do not delete anything — not the chats, not the call logs, not the transaction alerts, however embarrassing they feel. Do not format or factory-reset the device.
| Step | Action |
|---|---|
| 1 | Call 1930 immediately in any cyber financial fraud |
| 2 | Inform the bank, wallet or payment app and obtain a written reference |
| 3 | File on the National Cyber Crime Reporting Portal and note the acknowledgement |
| 4 | Preserve transaction IDs, UTR numbers, beneficiary details and screenshots |
| 5 | Do not delete chats, emails, call logs or app notifications |
| 6 | Change passwords and secure the affected accounts, without wiping the device |
| 7 | Preserve the device itself and avoid formatting or resetting it |
| 8 | Take legal support for complaint drafting and FIR strategy |
| 9 | Track the acknowledgement number and complaint status |
| 10 | Keep a single dated file of every bank, police and portal interaction |
Quick Answer
A Cyber Crime Complaint is not a licence or a registration. It is a reporting and enforcement process for cyber offences, online fraud and digital misconduct.
You do not need to file one for every online annoyance. But where there is financial loss, identity misuse, harassment, blackmail, data theft, unauthorised access or a credible digital threat, immediate reporting is strongly advisable — and the value of reporting decays by the hour.
Regulatory Framework
| Particular | Applicable framework |
|---|---|
| Main cyber law | Information Technology Act, 2000 |
| Criminal offences | Bharatiya Nyaya Sanhita, 2023 |
| Criminal procedure | Bharatiya Nagarik Suraksha Sanhita, 2023 |
| Evidence | Bharatiya Sakshya Adhiniyam, 2023 |
| Cognizable offence reporting | BNSS Section 173 |
| Non-cognizable information | BNSS Section 174 |
| Police investigation powers | BNSS Section 175 |
| Electronic records | BSA Sections 61, 62 and 63 |
| National reporting platform | National Cyber Crime Reporting Portal |
| Financial fraud helpline | 1930 |
| Organisational incident reporting | CERT-In Directions under Section 70B of the IT Act |
| Banking customer protection | RBI framework on limiting customer liability in unauthorised electronic banking transactions |
Key Provisions
Section numbering changed on 1 July 2024 when the BNS, BNSS and BSA replaced the IPC, CrPC and Evidence Act. Complaints drafted from older templates frequently still cite repealed provisions, which helps nobody.
| Provision | Practical relevance |
|---|---|
| IT Act Section 43 | Unauthorised access, downloading, damage and disruption of computer systems |
| IT Act Section 66 | Computer-related offences involving dishonest or fraudulent intention |
| IT Act Section 66C | Identity theft — misuse of password, electronic signature or unique identification feature |
| IT Act Section 66D | Cheating by personation using a computer resource or communication device |
| IT Act Section 66E | Violation of privacy |
| IT Act Sections 67, 67A and 67B | Obscene material, sexually explicit material and child sexual abuse material in electronic form |
| IT Act Sections 72 and 72A | Breach of confidentiality, and disclosure in breach of lawful contract |
| BNS Section 316 | Criminal breach of trust, where entrustment and dishonest misappropriation are disclosed |
| BNS Section 318 | Cheating, including deception-based financial fraud |
| BNS Section 319 | Cheating by personation, for fake identity and impersonation matters |
| BNS Sections 336 and 340 | Forgery, and using a forged document or electronic record as genuine |
| BNS Section 351 | Criminal intimidation, for online threats |
| BNS Section 356 | Defamation, for reputation-damaging digital publication |
| BNSS Section 173 | Information relating to a cognizable offence, including by electronic communication |
| BNSS Section 193 | Investigation report framework, including chain of custody for devices |
| BSA Sections 61 to 63 | Admissibility of electronic and digital records |
Types of Matter We Handle
| Type | Typical examples |
|---|---|
| Cyber financial fraud | UPI fraud, bank fraud, card fraud, wallet fraud, fake payment links |
| Phishing and vishing | Fake bank calls, fake KYC updates, OTP scams, spoofed websites |
| Investment scams | Fake trading apps, crypto scams, stock tip fraud, predatory loan apps |
| Identity theft | Misuse of Aadhaar, PAN, mobile number, email, photographs or credentials |
| Social media impersonation | Fake Instagram, Facebook, LinkedIn, Telegram or WhatsApp profiles |
| Cyber harassment | Threats, stalking, abusive messaging and sustained intimidation |
| Sextortion and blackmail | Threats to publish private or manipulated images |
| Data theft | Unauthorised access to, copying or misuse of business or personal data |
| Email fraud | Business email compromise, fake invoices and email spoofing |
| Online defamation | False posts, fake reviews and viral allegations |
| Bank account freeze | Accounts frozen due to a cyber complaint or a suspicious transaction trail |
| Defence of the accused | Evidence mapping and response where you have been named |
When to File
| Situation | Why it is urgent |
|---|---|
| Money has been transferred fraudulently | Early reporting is the only realistic path to tracing or blocking |
| A UPI or bank account is compromised | Both the bank and the cyber complaint must be started at once |
| OTP, PIN or credentials were misused | The reporting timeline directly affects your liability position |
| A fake profile has been created | Identity misuse spreads quickly and evidence vanishes on takedown |
| Private images are being used as leverage | Urgent takedown and protection strategy, and do not pay |
| Online harassment is continuing | Evidence preservation and safety planning together |
| A business email has been hacked | Client payments and data may already be exposed |
| Company data has been stolen | Internal incident response and complaint may both be needed |
| A bank account has been frozen | Source-of-funds documentation should begin immediately |
| A cyber police notice has arrived | A considered response is needed before anything goes on record |
Where to Report
| Route | Best used for |
|---|---|
| 1930 helpline | Immediate reporting of cyber financial fraud |
| National Cyber Crime Reporting Portal | Online reporting of cybercrime, with a dedicated route for offences against women and children |
| Cyber police station | Complex cyber offences, investigation follow-up and FIR support |
| Local police station | FIR, including a Zero FIR where jurisdiction is unclear |
| Bank, wallet or payment app | Transaction hold, dispute, chargeback and the customer protection route |
| Platform reporting | Profile takedown and content preservation |
| CERT-In | Specified cyber incidents affecting covered organisations |
These routes are complementary rather than alternatives. In a typical financial fraud, the helpline, the bank and the portal should all be engaged the same day, and the police complaint follows with the acknowledgements attached.
Bank Liability and the Three-Day Rule
The RBI framework on unauthorised electronic banking transactions links customer liability to two things: whose fault the loss was, and how quickly it was reported. This is the part victims most often do not know, and it is worth real money.
| Scenario | Customer liability position |
|---|---|
| Bank’s own negligence or deficiency | Zero liability, regardless of whether the customer reported it |
| Third-party breach, no fault of bank or customer, reported within 3 working days | Zero liability |
| Third-party breach, reported within 4 to 7 working days | Limited liability, subject to the prescribed caps |
| Reported beyond 7 working days | Determined by the bank’s board-approved policy |
| Loss due to customer negligence, such as sharing credentials | Customer bears the loss until the transaction is reported; liability stops on reporting |
The three working days run from when the bank communicates the transaction to you, not from when you noticed it. That distinction matters if alerts went to an old number, a spam folder or a phone you were not carrying. Keep the acknowledgement of your report, in writing, with a timestamp — the reporting date is the fact the whole liability analysis turns on.
Digital Evidence That Holds Up
Cyber cases are built almost entirely on electronic records, and their admissibility is governed by Sections 61 to 63 of the Bharatiya Sakshya Adhiniyam, 2023. Evidence gathered carelessly in the panic of the first day is the most common weakness in an otherwise good complaint.
| Do | Instead of |
|---|---|
| Preserve the whole conversation with dates and identifiers visible | Cropped screenshots of individual messages |
| Keep the original device unformatted | Resetting the phone to remove the intrusion |
| Record the full profile URL and account handle | A screenshot with no link, taken after takedown |
| Save transaction IDs, UTRs and beneficiary account details | A description of the amount from memory |
| Export email with full headers | A forwarded copy that loses the routing information |
| Keep call logs and the numbers used | Deleting the numbers after blocking them |
| Note a dated chronology as events happen | Reconstructing the sequence weeks later |
| Keep every bank and portal acknowledgement | Relying on a verbal assurance from a call centre |
Documents Required
| Document | Purpose |
|---|---|
| Identity proof of the complainant | Complaint verification |
| Mobile number and email used | Mapping the affected digital accounts |
| Incident chronology | Date-wise clarity on what happened |
| Screenshots of chats, calls and messages | Primary digital evidence |
| Bank statement | Transaction trail |
| UPI ID, UTR and transaction references | Fund movement tracking |
| Beneficiary account details | Trace and freeze requests |
| Fake website, app or profile links | Platform and investigation support |
| Email headers, where available | Email fraud analysis |
| Call logs and numbers used | Identifying the contact channel |
| Device details | Technical investigation support |
| Police or portal acknowledgement | Follow-up and escalation |
| Bank complaint reference | Liability and refund strategy |
| Company authorisation, for a business complaint | Authority to complain on behalf of the entity |
How We Run the Matter
| Step | Activity | Output |
|---|---|---|
| 1 | Initial consultation | Incident and urgency assessment |
| 2 | Evidence preservation | Screenshots, bank trail, URLs, chats and device details secured |
| 3 | Legal mapping | IT Act, BNS, BNSS and BSA provisions identified |
| 4 | Reporting guidance | 1930 and portal route, with acknowledgement tracking |
| 5 | Bank and platform coordination | Freeze, dispute or takedown requests |
| 6 | Complaint drafting | A structured complaint for the cyber cell or police station |
| 7 | FIR or Zero FIR support | Registration strategy aligned to BNSS Section 173 |
| 8 | Follow-up and escalation | SP representation or Magistrate route where required |
| 9 | Recovery or resolution strategy | Refund, de-freeze or further legal action |
| 10 | Ongoing tracking | Ticket-based updates on complaint, police and bank status |
Who Does What
Cyber fraud investigation depends on fast coordination between parties who do not share a system. Knowing which one to press, and for what, saves days.
| Stakeholder | Role |
|---|---|
| Police and cyber cell | Registration, investigation, notices, tracing and FIR action |
| Your bank | Dispute handling, customer liability assessment and beneficiary follow-up |
| Beneficiary bank | Holding or freezing the receiving account on a valid request |
| Payment app or wallet | Transaction, merchant and wallet trail details |
| Telecom operator | SIM, KYC and call record support through legal process |
| Platform or social media company | Takedown, content preservation and user data through legal process |
| CERT-In | Incident reporting framework for covered organisations |
Cyber Crime Against Businesses
For a business, cybercrime rarely arrives as a single fraudulent debit. It arrives as a compromised mailbox that redirected a customer payment, an employee who left with the customer database, or a vendor account that turned out to be fake.
| Situation | What the response needs |
|---|---|
| Business email compromise | Email header review, bank trail and police complaint |
| Vendor payment fraud | Invoice, purchase order, bank and email verification |
| Employee data theft | Access logs, device records and legal notice |
| Fake company profile or listing | Platform complaint and legal escalation |
| Customer data breach | Incident response and a reporting obligation assessment |
| Operating account frozen | Source-of-funds and transaction explanation, urgently |
| Online defamation | Notice, takedown and reputation strategy |
| Ransom or extortion demand | Complaint, evidence preservation and a decision not taken alone |
CERT-In Reporting for Organisations
Where the victim is an organisation rather than an individual, a second obligation may run alongside the complaint. The CERT-In Directions of 28 April 2022 require covered entities — service providers, intermediaries, data centres, body corporates and government organisations — to report specified cyber incidents to CERT-In within six hours of noticing them or being made aware of them.
This is a separate track from the police complaint, with its own timeline and recipient, and it is easy to miss while the business is focused on containment. For the full readiness picture, including log retention and escalation design, see Cyber Security Advisory.
Frozen Bank Accounts
A growing share of the cyber matters we see involve people whose accounts were frozen because funds connected to someone else’s fraud passed through them — sometimes several transfers downstream, and often where the account holder did nothing wrong. Merchants receiving customer payments are particularly exposed.
| What to assemble | Why |
|---|---|
| Source-of-funds documentation | Shows where the credited amount legitimately came from |
| Complete transaction trail | Places the disputed credit in normal business context |
| Invoices, orders and customer records | Establishes the commercial reason for the receipt |
| KYC and onboarding records | Shows the counterparty was properly identified |
| Correspondence with the bank | Creates a record of prompt and cooperative conduct |
| A written representation to the investigating officer | The freeze is usually lifted through the investigation, not the branch |
Act quickly. For a business, a frozen operating account stops payroll and vendor payments within days, and the practical damage often exceeds the disputed amount many times over.
Defence Side Support
Not everyone named in a cyber complaint is a fraudster. Accounts get caught in layered transaction trails, employees get accused during acrimonious exits, and business disputes get recast as cyber offences.
| Situation | What the review covers |
|---|---|
| Bank account frozen | Source of funds and transaction trail |
| Cyber police notice received | Response strategy and supporting documents |
| False online fraud allegation | Evidence and communication review |
| Business account received disputed funds | Merchant and transaction documentation |
| Employee accused of data theft | Device and access log review |
| Social media complaint received | Content and platform policy review |
| Cyber FIR registered | Bail, quashing and defence route mapping |
| Company named in a complaint | Authorised response and internal investigation |
Handle this carefully. A casual reply can create admissions that are difficult to walk back, and a delayed response tends to harden the investigation’s working assumption. Where an FIR has been registered, see Bail Application and Court Proceedings.
Why Complaints Fail
| Problem | Consequence | How we address it |
|---|---|---|
| Reported late | Funds have already been layered | Immediate 1930, portal and bank reporting |
| Incomplete screenshots | Evidence lacks context and continuity | Digital evidence checklist |
| Missing UTR or transaction ID | Tracing becomes impractical | Bank statement and transaction mapping |
| Complaint written emotionally | The offence is not identifiable from the narrative | Structured, fact-led drafting |
| Fake profile deleted before capture | The evidence disappears with the takedown | URL, screenshot and archive guidance before reporting |
| Repealed section references used | Mismatch with the current criminal law framework | Drafting aligned to IT Act, BNS, BNSS and BSA |
| Account frozen without explanation | Business operations stop | Transaction trail and de-freeze representation |
| Organisational breach not reported | A separate CERT-In obligation missed | Incident documentation and reporting review |
| No follow-up after the portal complaint | The matter goes quiet and stays quiet | Ticket-based tracking and escalation |
Our Services
| Service | What we do |
|---|---|
| Urgent reporting support | 1930, portal and bank reporting in the first hours |
| Digital evidence review | Preservation and organisation under BSA requirements |
| Complaint drafting | Structured complaints for the cyber cell or police station |
| FIR strategy | Registration, Zero FIR and escalation under the BNSS |
| Bank representation | Customer liability position and dispute follow-up |
| Account freeze support | Source-of-funds documentation and representations |
| Platform coordination | Takedown requests and content preservation |
| CERT-In reporting review | For covered organisations, alongside the complaint |
| Notice reply and defence | Considered responses to cyber police notices |
| Settlement and recovery strategy | Where a civil route runs alongside the complaint |
| Advocate coordination | Briefing, chronology and evidence file |
| Ticket-based tracking | Status across bank, portal, police and platform |
FAQs
1. What is a Cyber Crime Complaint?
A formal complaint reporting an online or technology-enabled offence — financial fraud, identity theft, harassment, unauthorised access, data theft, impersonation or digital extortion.
2. Where do I file one?
Through the National Cyber Crime Reporting Portal, by calling 1930 for cyber financial fraud, or at a cyber police station or local police station. In financial fraud the helpline and the portal come first, because they are the fastest route to the banking channel.
3. What should I do in the first hour after online fraud?
Call 1930, inform your bank, file on the cyber portal and preserve everything — transaction IDs, UTR numbers, screenshots, messages and call logs. Speed matters more here than in almost any other area of law.
4. Can the money be recovered?
Sometimes. Recovery depends on how fast the report reaches the banking channel, whether the funds are still traceable, how the beneficiary banks respond and whether the trail can be frozen before the money is layered further. Nobody can promise recovery, and you should be wary of anyone who does.
5. What is the 1930 helpline?
The national helpline for reporting cyber financial fraud in India. It exists to get a suspicious transaction into the banking system quickly.
6. Does reporting within three days guarantee a refund?
No, but it materially protects your position. Under the RBI framework on unauthorised electronic banking transactions, a customer generally bears zero liability where the loss arises from a third-party breach with no customer fault and the transaction is reported within three working days of receiving the bank’s communication. Reporting between four and seven working days attracts limited liability subject to prescribed caps.
7. What happens if I report late?
Beyond seven working days, liability is determined by the bank’s board-approved policy. The practical position weakens with every day of delay, both for liability and for tracing.
8. What if I shared my OTP or PIN?
Where the loss arises from customer negligence, such as sharing payment credentials, the customer generally bears the loss until the transaction is reported. Report it anyway and immediately, because liability stops accruing from the point of reporting.
9. Which laws apply to cybercrime in India?
Principally the Information Technology Act, 2000 for cyber offences, the Bharatiya Nyaya Sanhita, 2023 for the underlying criminal offences, the Bharatiya Nagarik Suraksha Sanhita, 2023 for procedure, and the Bharatiya Sakshya Adhiniyam, 2023 for electronic evidence.
10. Why does the new criminal law framework matter to my complaint?
Because section numbering changed entirely on 1 July 2024. A complaint drafted from an old template citing IPC and CrPC sections signals carelessness and can cause avoidable confusion at the registration stage.
11. Is BSA relevant to a cyber complaint?
Very. Cyber cases are built almost entirely on electronic records — screenshots, chats, emails, logs, URLs and statements. Sections 61 to 63 of the Bharatiya Sakshya Adhiniyam govern their admissibility, and evidence collected carelessly is harder to rely on later.
12. Can WhatsApp chats be used as evidence?
Yes, subject to the electronic evidence requirements. Preserve the original device and the full conversation rather than isolated cropped screenshots, because context and continuity are what give the record weight.
13. Can I file against an unknown person?
Yes. Most cyber complaints begin against unknown accused. What matters is that the facts, digital traces, account numbers and timeline are set out clearly enough for investigation to start.
14. Can a fake social media profile be reported?
Yes, both to the platform for takedown and through the cyber complaint route where identity misuse, harassment or fraud is involved. Preserve the profile URL and screenshots before reporting, because takedown removes the evidence too.
15. Can a complaint be filed for online harassment?
Yes. Threats, stalking, abusive messaging, blackmail and sustained harassment can be reported through the portal and police channels, and the National Cyber Crime Reporting Portal has a dedicated route for offences against women and children.
16. I am being blackmailed with private images. What should I do?
Report immediately and do not pay. Preserve the messages and profile details, avoid further engagement, and use the portal’s dedicated reporting category. These matters are handled confidentially and urgency genuinely helps.
17. What if the police do not register an FIR?
Where the information discloses a cognizable offence, escalation is available — a written representation to the Superintendent of Police, and thereafter the Magistrate route under the BNSS. A Zero FIR can also be registered at any police station irrespective of territorial jurisdiction.
18. What is a Zero FIR?
An FIR registered at a police station that does not have territorial jurisdiction, later transferred to the station that does. It exists so that jurisdiction arguments do not delay urgent registration.
19. Can my bank account be frozen because of someone else’s complaint?
Yes. Accounts that receive funds connected to a reported fraud can be frozen, sometimes several transfers removed from the original fraud and without any wrongdoing by the account holder.
20. What do I do if my account is wrongly frozen?
Assemble the source-of-funds documentation and transaction trail, and make a documented representation to the investigating officer and the bank. For businesses this is urgent, because a frozen operating account stops payroll and vendor payments within days.
21. Can a company file a Cyber Crime Complaint?
Yes, through an authorised signatory with board or management authorisation, supported by internal records such as access logs, email headers and accounting entries.
22. Is CERT-In reporting required for every cybercrime?
No. CERT-In reporting applies to specified cyber incidents affecting covered entities, within six hours. An individual fraud victim uses 1930, the portal and the police route instead.
23. I have received a cyber police notice. What now?
Take it seriously and answer it properly. A casual reply can create admissions, and ignoring it worsens your position. Have the notice reviewed and a considered response prepared before you say anything on record.
24. What is the biggest mistake victims make?
Two, usually together: waiting before reporting, and deleting the evidence. Chats get cleared out of embarrassment, devices get formatted, and the record that would have supported the complaint disappears.
25. Can Estabizz appear before police or court?
We handle evidence review, complaint drafting, reporting strategy, bank and platform coordination, notice replies and case preparation. Appearance is through enrolled advocates.
Expert Insight
“The strongest cyber complaint is not the longest one. It is the one filed the same day, supported by a clean chronology, a complete transaction trail, evidence preserved in the form the law expects, and the correct provision named. Everything that makes a complaint work is decided in the first few hours.”
— CS Devyani Khambhati, Compliance Expert
Disclaimer
This guide is general information, not matter-specific legal advice. Offence classification, applicable provisions, liability outcomes and available remedies depend entirely on the facts, and recovery in cyber fraud can never be assured. Bank liability outcomes depend on the RBI framework as applied by the bank’s board-approved policy and on the facts of the individual transaction. Statutory positions stated here are as at September 2026 and parts of this guide remain under professional review. Estabizz provides complaint drafting, evidence review, documentation, reporting strategy and coordination support; appearance is through enrolled advocates. Confirm the position with your advocate before acting.