Legal Cyber Crime

Cyber Crime Complaint

Cyber fraud moves faster than any legal process. Funds are routed through layered accounts within minutes, devices are discarded, and content is deleted before anyone reads a complaint. What determines the outcome is usually what happened in the first few hours. Estabizz assists individuals, families, professionals, businesses, directors and regulated entities with online fraud reporting, 1930 helpline and cyber portal guidance, digital evidence preservation, police complaint drafting, FIR strategy, bank coordination and account-freeze representation, platform takedown support, CERT-In reporting review and defence where a cyber notice has been received — under the current framework of the IT Act, BNS, BNSS and BSA.

📅 2026
|
⏱️ 15 min read
|
👁️ Regulatory Guide
Focus: Cyber Crime Complaint
Financial fraud helpline
1930
Bank reporting window
3 working days
Evidence law
BSA, 2023
Matters most
Speed

Overview

In simple terms… a Cyber Crime Complaint is what you file when someone uses a phone, computer, payment app, social media account, email or website to cheat, threaten, harass, impersonate, steal from or otherwise act unlawfully against you.

These matters are unusual in how time-sensitive they are. In financial fraud, early reporting is what gives banks and law enforcement any chance of tracing and blocking funds before they are layered beyond reach. In harassment and reputation matters, early preservation is what stops the evidence disappearing when a profile is deleted or a post is taken down.

This page covers both sides — filing a complaint, and responding when a complaint, notice or account freeze lands on you.

The First Few Hours

If money has just left your account, do these things now and read the rest of this page afterwards. Call 1930. Inform your bank and get a written acknowledgement with a reference number. File on the National Cyber Crime Reporting Portal and keep the acknowledgement number. Do not delete anything — not the chats, not the call logs, not the transaction alerts, however embarrassing they feel. Do not format or factory-reset the device.

StepAction
1Call 1930 immediately in any cyber financial fraud
2Inform the bank, wallet or payment app and obtain a written reference
3File on the National Cyber Crime Reporting Portal and note the acknowledgement
4Preserve transaction IDs, UTR numbers, beneficiary details and screenshots
5Do not delete chats, emails, call logs or app notifications
6Change passwords and secure the affected accounts, without wiping the device
7Preserve the device itself and avoid formatting or resetting it
8Take legal support for complaint drafting and FIR strategy
9Track the acknowledgement number and complaint status
10Keep a single dated file of every bank, police and portal interaction

Quick Answer

A Cyber Crime Complaint is not a licence or a registration. It is a reporting and enforcement process for cyber offences, online fraud and digital misconduct.

You do not need to file one for every online annoyance. But where there is financial loss, identity misuse, harassment, blackmail, data theft, unauthorised access or a credible digital threat, immediate reporting is strongly advisable — and the value of reporting decays by the hour.

Regulatory Framework

ParticularApplicable framework
Main cyber lawInformation Technology Act, 2000
Criminal offencesBharatiya Nyaya Sanhita, 2023
Criminal procedureBharatiya Nagarik Suraksha Sanhita, 2023
EvidenceBharatiya Sakshya Adhiniyam, 2023
Cognizable offence reportingBNSS Section 173
Non-cognizable informationBNSS Section 174
Police investigation powersBNSS Section 175
Electronic recordsBSA Sections 61, 62 and 63
National reporting platformNational Cyber Crime Reporting Portal
Financial fraud helpline1930
Organisational incident reportingCERT-In Directions under Section 70B of the IT Act
Banking customer protectionRBI framework on limiting customer liability in unauthorised electronic banking transactions

Key Provisions

Section numbering changed on 1 July 2024 when the BNS, BNSS and BSA replaced the IPC, CrPC and Evidence Act. Complaints drafted from older templates frequently still cite repealed provisions, which helps nobody.

ProvisionPractical relevance
IT Act Section 43Unauthorised access, downloading, damage and disruption of computer systems
IT Act Section 66Computer-related offences involving dishonest or fraudulent intention
IT Act Section 66CIdentity theft — misuse of password, electronic signature or unique identification feature
IT Act Section 66DCheating by personation using a computer resource or communication device
IT Act Section 66EViolation of privacy
IT Act Sections 67, 67A and 67BObscene material, sexually explicit material and child sexual abuse material in electronic form
IT Act Sections 72 and 72ABreach of confidentiality, and disclosure in breach of lawful contract
BNS Section 316Criminal breach of trust, where entrustment and dishonest misappropriation are disclosed
BNS Section 318Cheating, including deception-based financial fraud
BNS Section 319Cheating by personation, for fake identity and impersonation matters
BNS Sections 336 and 340Forgery, and using a forged document or electronic record as genuine
BNS Section 351Criminal intimidation, for online threats
BNS Section 356Defamation, for reputation-damaging digital publication
BNSS Section 173Information relating to a cognizable offence, including by electronic communication
BNSS Section 193Investigation report framework, including chain of custody for devices
BSA Sections 61 to 63Admissibility of electronic and digital records

Types of Matter We Handle

TypeTypical examples
Cyber financial fraudUPI fraud, bank fraud, card fraud, wallet fraud, fake payment links
Phishing and vishingFake bank calls, fake KYC updates, OTP scams, spoofed websites
Investment scamsFake trading apps, crypto scams, stock tip fraud, predatory loan apps
Identity theftMisuse of Aadhaar, PAN, mobile number, email, photographs or credentials
Social media impersonationFake Instagram, Facebook, LinkedIn, Telegram or WhatsApp profiles
Cyber harassmentThreats, stalking, abusive messaging and sustained intimidation
Sextortion and blackmailThreats to publish private or manipulated images
Data theftUnauthorised access to, copying or misuse of business or personal data
Email fraudBusiness email compromise, fake invoices and email spoofing
Online defamationFalse posts, fake reviews and viral allegations
Bank account freezeAccounts frozen due to a cyber complaint or a suspicious transaction trail
Defence of the accusedEvidence mapping and response where you have been named

When to File

SituationWhy it is urgent
Money has been transferred fraudulentlyEarly reporting is the only realistic path to tracing or blocking
A UPI or bank account is compromisedBoth the bank and the cyber complaint must be started at once
OTP, PIN or credentials were misusedThe reporting timeline directly affects your liability position
A fake profile has been createdIdentity misuse spreads quickly and evidence vanishes on takedown
Private images are being used as leverageUrgent takedown and protection strategy, and do not pay
Online harassment is continuingEvidence preservation and safety planning together
A business email has been hackedClient payments and data may already be exposed
Company data has been stolenInternal incident response and complaint may both be needed
A bank account has been frozenSource-of-funds documentation should begin immediately
A cyber police notice has arrivedA considered response is needed before anything goes on record

Where to Report

RouteBest used for
1930 helplineImmediate reporting of cyber financial fraud
National Cyber Crime Reporting PortalOnline reporting of cybercrime, with a dedicated route for offences against women and children
Cyber police stationComplex cyber offences, investigation follow-up and FIR support
Local police stationFIR, including a Zero FIR where jurisdiction is unclear
Bank, wallet or payment appTransaction hold, dispute, chargeback and the customer protection route
Platform reportingProfile takedown and content preservation
CERT-InSpecified cyber incidents affecting covered organisations

These routes are complementary rather than alternatives. In a typical financial fraud, the helpline, the bank and the portal should all be engaged the same day, and the police complaint follows with the acknowledgements attached.

Bank Liability and the Three-Day Rule

The RBI framework on unauthorised electronic banking transactions links customer liability to two things: whose fault the loss was, and how quickly it was reported. This is the part victims most often do not know, and it is worth real money.

ScenarioCustomer liability position
Bank’s own negligence or deficiencyZero liability, regardless of whether the customer reported it
Third-party breach, no fault of bank or customer, reported within 3 working daysZero liability
Third-party breach, reported within 4 to 7 working daysLimited liability, subject to the prescribed caps
Reported beyond 7 working daysDetermined by the bank’s board-approved policy
Loss due to customer negligence, such as sharing credentialsCustomer bears the loss until the transaction is reported; liability stops on reporting

The three working days run from when the bank communicates the transaction to you, not from when you noticed it. That distinction matters if alerts went to an old number, a spam folder or a phone you were not carrying. Keep the acknowledgement of your report, in writing, with a timestamp — the reporting date is the fact the whole liability analysis turns on.

Digital Evidence That Holds Up

Cyber cases are built almost entirely on electronic records, and their admissibility is governed by Sections 61 to 63 of the Bharatiya Sakshya Adhiniyam, 2023. Evidence gathered carelessly in the panic of the first day is the most common weakness in an otherwise good complaint.

DoInstead of
Preserve the whole conversation with dates and identifiers visibleCropped screenshots of individual messages
Keep the original device unformattedResetting the phone to remove the intrusion
Record the full profile URL and account handleA screenshot with no link, taken after takedown
Save transaction IDs, UTRs and beneficiary account detailsA description of the amount from memory
Export email with full headersA forwarded copy that loses the routing information
Keep call logs and the numbers usedDeleting the numbers after blocking them
Note a dated chronology as events happenReconstructing the sequence weeks later
Keep every bank and portal acknowledgementRelying on a verbal assurance from a call centre

Documents Required

DocumentPurpose
Identity proof of the complainantComplaint verification
Mobile number and email usedMapping the affected digital accounts
Incident chronologyDate-wise clarity on what happened
Screenshots of chats, calls and messagesPrimary digital evidence
Bank statementTransaction trail
UPI ID, UTR and transaction referencesFund movement tracking
Beneficiary account detailsTrace and freeze requests
Fake website, app or profile linksPlatform and investigation support
Email headers, where availableEmail fraud analysis
Call logs and numbers usedIdentifying the contact channel
Device detailsTechnical investigation support
Police or portal acknowledgementFollow-up and escalation
Bank complaint referenceLiability and refund strategy
Company authorisation, for a business complaintAuthority to complain on behalf of the entity

How We Run the Matter

StepActivityOutput
1Initial consultationIncident and urgency assessment
2Evidence preservationScreenshots, bank trail, URLs, chats and device details secured
3Legal mappingIT Act, BNS, BNSS and BSA provisions identified
4Reporting guidance1930 and portal route, with acknowledgement tracking
5Bank and platform coordinationFreeze, dispute or takedown requests
6Complaint draftingA structured complaint for the cyber cell or police station
7FIR or Zero FIR supportRegistration strategy aligned to BNSS Section 173
8Follow-up and escalationSP representation or Magistrate route where required
9Recovery or resolution strategyRefund, de-freeze or further legal action
10Ongoing trackingTicket-based updates on complaint, police and bank status

Who Does What

Cyber fraud investigation depends on fast coordination between parties who do not share a system. Knowing which one to press, and for what, saves days.

StakeholderRole
Police and cyber cellRegistration, investigation, notices, tracing and FIR action
Your bankDispute handling, customer liability assessment and beneficiary follow-up
Beneficiary bankHolding or freezing the receiving account on a valid request
Payment app or walletTransaction, merchant and wallet trail details
Telecom operatorSIM, KYC and call record support through legal process
Platform or social media companyTakedown, content preservation and user data through legal process
CERT-InIncident reporting framework for covered organisations

Cyber Crime Against Businesses

For a business, cybercrime rarely arrives as a single fraudulent debit. It arrives as a compromised mailbox that redirected a customer payment, an employee who left with the customer database, or a vendor account that turned out to be fake.

SituationWhat the response needs
Business email compromiseEmail header review, bank trail and police complaint
Vendor payment fraudInvoice, purchase order, bank and email verification
Employee data theftAccess logs, device records and legal notice
Fake company profile or listingPlatform complaint and legal escalation
Customer data breachIncident response and a reporting obligation assessment
Operating account frozenSource-of-funds and transaction explanation, urgently
Online defamationNotice, takedown and reputation strategy
Ransom or extortion demandComplaint, evidence preservation and a decision not taken alone

CERT-In Reporting for Organisations

Where the victim is an organisation rather than an individual, a second obligation may run alongside the complaint. The CERT-In Directions of 28 April 2022 require covered entities — service providers, intermediaries, data centres, body corporates and government organisations — to report specified cyber incidents to CERT-In within six hours of noticing them or being made aware of them.

This is a separate track from the police complaint, with its own timeline and recipient, and it is easy to miss while the business is focused on containment. For the full readiness picture, including log retention and escalation design, see Cyber Security Advisory.

Frozen Bank Accounts

A growing share of the cyber matters we see involve people whose accounts were frozen because funds connected to someone else’s fraud passed through them — sometimes several transfers downstream, and often where the account holder did nothing wrong. Merchants receiving customer payments are particularly exposed.

What to assembleWhy
Source-of-funds documentationShows where the credited amount legitimately came from
Complete transaction trailPlaces the disputed credit in normal business context
Invoices, orders and customer recordsEstablishes the commercial reason for the receipt
KYC and onboarding recordsShows the counterparty was properly identified
Correspondence with the bankCreates a record of prompt and cooperative conduct
A written representation to the investigating officerThe freeze is usually lifted through the investigation, not the branch

Act quickly. For a business, a frozen operating account stops payroll and vendor payments within days, and the practical damage often exceeds the disputed amount many times over.

Defence Side Support

Not everyone named in a cyber complaint is a fraudster. Accounts get caught in layered transaction trails, employees get accused during acrimonious exits, and business disputes get recast as cyber offences.

SituationWhat the review covers
Bank account frozenSource of funds and transaction trail
Cyber police notice receivedResponse strategy and supporting documents
False online fraud allegationEvidence and communication review
Business account received disputed fundsMerchant and transaction documentation
Employee accused of data theftDevice and access log review
Social media complaint receivedContent and platform policy review
Cyber FIR registeredBail, quashing and defence route mapping
Company named in a complaintAuthorised response and internal investigation

Handle this carefully. A casual reply can create admissions that are difficult to walk back, and a delayed response tends to harden the investigation’s working assumption. Where an FIR has been registered, see Bail Application and Court Proceedings.

Why Complaints Fail

ProblemConsequenceHow we address it
Reported lateFunds have already been layeredImmediate 1930, portal and bank reporting
Incomplete screenshotsEvidence lacks context and continuityDigital evidence checklist
Missing UTR or transaction IDTracing becomes impracticalBank statement and transaction mapping
Complaint written emotionallyThe offence is not identifiable from the narrativeStructured, fact-led drafting
Fake profile deleted before captureThe evidence disappears with the takedownURL, screenshot and archive guidance before reporting
Repealed section references usedMismatch with the current criminal law frameworkDrafting aligned to IT Act, BNS, BNSS and BSA
Account frozen without explanationBusiness operations stopTransaction trail and de-freeze representation
Organisational breach not reportedA separate CERT-In obligation missedIncident documentation and reporting review
No follow-up after the portal complaintThe matter goes quiet and stays quietTicket-based tracking and escalation

Our Services

ServiceWhat we do
Urgent reporting support1930, portal and bank reporting in the first hours
Digital evidence reviewPreservation and organisation under BSA requirements
Complaint draftingStructured complaints for the cyber cell or police station
FIR strategyRegistration, Zero FIR and escalation under the BNSS
Bank representationCustomer liability position and dispute follow-up
Account freeze supportSource-of-funds documentation and representations
Platform coordinationTakedown requests and content preservation
CERT-In reporting reviewFor covered organisations, alongside the complaint
Notice reply and defenceConsidered responses to cyber police notices
Settlement and recovery strategyWhere a civil route runs alongside the complaint
Advocate coordinationBriefing, chronology and evidence file
Ticket-based trackingStatus across bank, portal, police and platform

FAQs

1. What is a Cyber Crime Complaint?

A formal complaint reporting an online or technology-enabled offence — financial fraud, identity theft, harassment, unauthorised access, data theft, impersonation or digital extortion.

2. Where do I file one?

Through the National Cyber Crime Reporting Portal, by calling 1930 for cyber financial fraud, or at a cyber police station or local police station. In financial fraud the helpline and the portal come first, because they are the fastest route to the banking channel.

3. What should I do in the first hour after online fraud?

Call 1930, inform your bank, file on the cyber portal and preserve everything — transaction IDs, UTR numbers, screenshots, messages and call logs. Speed matters more here than in almost any other area of law.

4. Can the money be recovered?

Sometimes. Recovery depends on how fast the report reaches the banking channel, whether the funds are still traceable, how the beneficiary banks respond and whether the trail can be frozen before the money is layered further. Nobody can promise recovery, and you should be wary of anyone who does.

5. What is the 1930 helpline?

The national helpline for reporting cyber financial fraud in India. It exists to get a suspicious transaction into the banking system quickly.

6. Does reporting within three days guarantee a refund?

No, but it materially protects your position. Under the RBI framework on unauthorised electronic banking transactions, a customer generally bears zero liability where the loss arises from a third-party breach with no customer fault and the transaction is reported within three working days of receiving the bank’s communication. Reporting between four and seven working days attracts limited liability subject to prescribed caps.

7. What happens if I report late?

Beyond seven working days, liability is determined by the bank’s board-approved policy. The practical position weakens with every day of delay, both for liability and for tracing.

8. What if I shared my OTP or PIN?

Where the loss arises from customer negligence, such as sharing payment credentials, the customer generally bears the loss until the transaction is reported. Report it anyway and immediately, because liability stops accruing from the point of reporting.

9. Which laws apply to cybercrime in India?

Principally the Information Technology Act, 2000 for cyber offences, the Bharatiya Nyaya Sanhita, 2023 for the underlying criminal offences, the Bharatiya Nagarik Suraksha Sanhita, 2023 for procedure, and the Bharatiya Sakshya Adhiniyam, 2023 for electronic evidence.

10. Why does the new criminal law framework matter to my complaint?

Because section numbering changed entirely on 1 July 2024. A complaint drafted from an old template citing IPC and CrPC sections signals carelessness and can cause avoidable confusion at the registration stage.

11. Is BSA relevant to a cyber complaint?

Very. Cyber cases are built almost entirely on electronic records — screenshots, chats, emails, logs, URLs and statements. Sections 61 to 63 of the Bharatiya Sakshya Adhiniyam govern their admissibility, and evidence collected carelessly is harder to rely on later.

12. Can WhatsApp chats be used as evidence?

Yes, subject to the electronic evidence requirements. Preserve the original device and the full conversation rather than isolated cropped screenshots, because context and continuity are what give the record weight.

13. Can I file against an unknown person?

Yes. Most cyber complaints begin against unknown accused. What matters is that the facts, digital traces, account numbers and timeline are set out clearly enough for investigation to start.

14. Can a fake social media profile be reported?

Yes, both to the platform for takedown and through the cyber complaint route where identity misuse, harassment or fraud is involved. Preserve the profile URL and screenshots before reporting, because takedown removes the evidence too.

15. Can a complaint be filed for online harassment?

Yes. Threats, stalking, abusive messaging, blackmail and sustained harassment can be reported through the portal and police channels, and the National Cyber Crime Reporting Portal has a dedicated route for offences against women and children.

16. I am being blackmailed with private images. What should I do?

Report immediately and do not pay. Preserve the messages and profile details, avoid further engagement, and use the portal’s dedicated reporting category. These matters are handled confidentially and urgency genuinely helps.

17. What if the police do not register an FIR?

Where the information discloses a cognizable offence, escalation is available — a written representation to the Superintendent of Police, and thereafter the Magistrate route under the BNSS. A Zero FIR can also be registered at any police station irrespective of territorial jurisdiction.

18. What is a Zero FIR?

An FIR registered at a police station that does not have territorial jurisdiction, later transferred to the station that does. It exists so that jurisdiction arguments do not delay urgent registration.

19. Can my bank account be frozen because of someone else’s complaint?

Yes. Accounts that receive funds connected to a reported fraud can be frozen, sometimes several transfers removed from the original fraud and without any wrongdoing by the account holder.

20. What do I do if my account is wrongly frozen?

Assemble the source-of-funds documentation and transaction trail, and make a documented representation to the investigating officer and the bank. For businesses this is urgent, because a frozen operating account stops payroll and vendor payments within days.

21. Can a company file a Cyber Crime Complaint?

Yes, through an authorised signatory with board or management authorisation, supported by internal records such as access logs, email headers and accounting entries.

22. Is CERT-In reporting required for every cybercrime?

No. CERT-In reporting applies to specified cyber incidents affecting covered entities, within six hours. An individual fraud victim uses 1930, the portal and the police route instead.

23. I have received a cyber police notice. What now?

Take it seriously and answer it properly. A casual reply can create admissions, and ignoring it worsens your position. Have the notice reviewed and a considered response prepared before you say anything on record.

24. What is the biggest mistake victims make?

Two, usually together: waiting before reporting, and deleting the evidence. Chats get cleared out of embarrassment, devices get formatted, and the record that would have supported the complaint disappears.

25. Can Estabizz appear before police or court?

We handle evidence review, complaint drafting, reporting strategy, bank and platform coordination, notice replies and case preparation. Appearance is through enrolled advocates.

Expert Insight

“The strongest cyber complaint is not the longest one. It is the one filed the same day, supported by a clean chronology, a complete transaction trail, evidence preserved in the form the law expects, and the correct provision named. Everything that makes a complaint work is decided in the first few hours.”
— CS Devyani Khambhati, Compliance Expert

Disclaimer

This guide is general information, not matter-specific legal advice. Offence classification, applicable provisions, liability outcomes and available remedies depend entirely on the facts, and recovery in cyber fraud can never be assured. Bank liability outcomes depend on the RBI framework as applied by the bank’s board-approved policy and on the facts of the individual transaction. Statutory positions stated here are as at September 2026 and parts of this guide remain under professional review. Estabizz provides complaint drafting, evidence review, documentation, reporting strategy and coordination support; appearance is through enrolled advocates. Confirm the position with your advocate before acting.

In Cyber Fraud, Hours Decide Outcomes

Money moves through layered accounts, SIM cards are discarded and posts are deleted. Report first, preserve everything, and let the complaint be drafted properly around what you managed to keep.