# How to file a cyber crime complaint in India

**TL;DR:** If money has just left your account through fraud, call the national cybercrime helpline number 1930 before doing anything else, then file a complaint on the National Cybercrime Reporting Portal at cybercrime.gov.in. Both routes exist to trigger a bank freeze on the fraudulent account while the money is still sitting there, and the window for that to work is measured in hours, not days.

---

## On this page

- [The first hour decides whether the money can be traced](#the-first-hour-decides-whether-the-money-can-be-traced)
- [The national helpline and the national cybercrime reporting portal](#the-national-helpline-and-the-national-cybercrime-reporting-portal)
- [What to have ready before you call or file](#what-to-have-ready-before-you-call-or-file)
- [How a portal complaint relates to an FIR](#how-a-portal-complaint-relates-to-an-fir)
- [The categories the portal uses, and why women and children route differently](#the-categories-the-portal-uses-and-why-women-and-children-route-differently)
- [What happens after you file, and how to track it](#what-happens-after-you-file-and-how-to-track-it)
- [Your bank's obligations and the RBI's liability rules](#your-banks-obligations-and-the-rbis-liability-rules)
- [Preserving evidence without destroying it](#preserving-evidence-without-destroying-it)
- [The offences that typically get invoked](#the-offences-that-typically-get-invoked)
- [Frequently asked questions](#frequently-asked-questions)

## The first hour decides whether the money can be traced

Money moved through a fraudulent UPI transaction, net banking transfer, or card payment does not sit still. It usually passes through one or more "mule" accounts within minutes, and from there it is withdrawn, split into smaller amounts, or moved to a wallet or exchange account before the victim has finished processing what happened. The single fact that governs everything else in this guide is that the odds of getting that money back fall sharply with every hour that passes before a bank is told to freeze the receiving account.

Nothing about this requires legal training. It requires speed, and it requires calling the right number before doing anything else, including calling your own bank's regular customer care line, which is often slower and not connected to the fraud-freeze mechanism the same way. The two channels that exist specifically for this are the national cybercrime helpline and the National Cybercrime Reporting Portal, both run by the [Indian Cybercrime Coordination Centre (I4C)](https://i4c.mha.gov.in) under the Ministry of Home Affairs. I4C states plainly on its own site that a cybercrime can be reported "on www.cybercrime.gov.in" or "on 1930," and treats these as the two front doors into the same reporting system.

The sequence below assumes the most common and time-sensitive scenario: money has already left your account. If nothing has been debited yet, for example if you clicked a phishing link but have not entered banking credentials, the urgency is lower but the same two channels are still the correct starting point.

```mermaid
flowchart TD
    A[Notice unauthorised transaction] --> B[Call 1930 immediately]
    B --> C[Give transaction details to the call handler]
    C --> D[Bank asked to flag and freeze the receiving account]
    D --> E[File complaint on cybercrime.gov.in]
    E --> F[Note the acknowledgment or complaint number]
    F --> G{Is it a cognizable offence with no FIR yet?}
    G -->|Yes| H[Go to the nearest police station or cyber cell]
    G -->|Portal complaint filed, evidence intact| I[Preserve screenshots, headers, UTR number]
    H --> I
    I --> J[Track status on the portal and with the cyber cell]
```

Every step in that sequence is designed to happen inside the first hour. The 1930 call starts the freeze process on the banking side. The portal complaint creates the formal record that the police and the bank's nodal officer both act on. Evidence preservation runs in parallel with both, not after them.

## The national helpline and the national cybercrime reporting portal

I4C, the agency behind both channels, is an initiative of the Ministry of Home Affairs whose scheme was approved on 5 October 2018 and which was formally dedicated to the nation on 10 January 2020. It was upgraded to an Attached Office of the Ministry with effect from 1 July 2024. Among its listed operational verticals is the National Cybercrime Reporting Portal (NCRP), which is the formal name for [cybercrime.gov.in](https://cybercrime.gov.in/).

The helpline number, 1930, is described on I4C's own website as a direct reporting channel, listed alongside the portal as the two ways to report a cybercrime. Calling it does two things at once. It gets a trained call handler to record the essential details of the fraud in real time, and it lets that handler push an alert into the system that flags the receiving bank account for a freeze, which is far faster than waiting for a written complaint to be processed and routed. The portal, by contrast, is where the complaint becomes a documented record with an acknowledgment number, uploaded evidence, and a status you can check later. In a financial fraud, do both. The call buys time on the freeze; the portal creates the paper trail the freeze and any later FIR will depend on.

Neither channel replaces the other, and neither replaces your bank's own fraud-reporting line, which you should also call separately, since the bank's internal timeline for reversing a transaction runs on rules set by the Reserve Bank of India that are independent of what I4C does. That RBI timeline is covered in detail further down this page, and it interacts directly with how fast you report.

If your advocate is verifying which provisions of the Bharatiya Nyaya Sanhita or the Information Technology Act, 2000 apply once the police begin drafting the FIR, a research tool built for [Indian statute and case law verification](https://niyam.ai) removes the guesswork of cross-checking section numbers against the enacted text rather than a summary that may be out of date.

## What to have ready before you call or file

A financial fraud complaint moves faster when the caller or the person filling in the portal form has the following ready, rather than reconstructing it under stress while on hold:

- Your registered mobile number and the mobile number the fraud was reported from, if different.
- The exact date and time of the fraudulent transaction, down to the minute if your bank SMS or app shows it.
- The transaction reference: a UPI transaction ID, a UTR number for a bank transfer, or the last four digits of a card along with the merchant name shown on the statement.
- The amount debited and the account or UPI handle it went to, if visible in your bank's transaction detail screen.
- A screenshot of the transaction confirmation or debit SMS, taken before you do anything else to the device.
- The phone number, email address, website URL, or app name involved in the fraud, if the money was induced by a call, message, or fake app rather than taken directly.
- Your bank account number and the name of the bank and branch, for the freeze request to be routed correctly.
- A copy of your identity document (Aadhaar, PAN, or passport) for the portal's mandatory identity verification step.

None of this needs to be perfectly organised. A photograph of your phone screen showing the debit SMS, taken in the first minute, is worth more than a tidy written account produced an hour later once the transaction detail has scrolled out of the SMS app or the merchant page has gone offline.

## How a portal complaint relates to an FIR

A complaint filed on cybercrime.gov.in is not automatically an FIR, and it does not by itself start a criminal investigation the way an FIR does. What it does is generate a formal, timestamped record that is forwarded to the concerned state or Union Territory law enforcement agency for action, and in financial fraud cases it is also what triggers the bank-side freeze mechanism through the reporting system I4C operates with banks and payment intermediaries.

Whether you additionally need to walk into a police station and register a formal FIR depends on the same threshold that governs every criminal complaint in India: whether the offence is cognizable. For a cognizable offence, which most financial cyber fraud is, since it typically involves cheating or forgery, the police have a duty to register an FIR once information disclosing that offence is placed before them, a principle the Supreme Court settled in [*Lalita Kumari v. Government of Uttar Pradesh*](https://indiankanoon.org/doc/10239019/), decided by a Constitution Bench on 12 November 2013. The distinction between offences the police must register on receipt of information and those that require a magistrate's order first is the [cognizable versus non-cognizable classification](/blog/cognizable-vs-non-cognizable), and it decides how firmly you can insist on registration if a station is reluctant to act.

In practice, for financial fraud you should not treat the portal complaint as a substitute for going to a police station if the fraud amount is significant, if the freeze has not held the money, or if you need a formal FIR copy for insurance, employer, or civil recovery purposes. A portal complaint gives law enforcement the digital trail; an FIR gives you a document with legal standing that a court, an insurer, or a civil recovery suit will recognise. The underlying duty to register an FIR once a cognizable offence is disclosed is not discretionary, and the [statutory basis for mandatory FIR registration under Section 173 of the BNSS](/blog/bnss-section-173-fir-registration) applies to a cyber fraud report the same way it applies to any other cognizable complaint. If a station is reluctant to register the FIR because the fraud "happened online" or the accused's location is unclear, the same [zero FIR rule that applies to any cognizable offence](/blog/zero-fir-e-fir-bnss-guide) applies here too: Section 173(1) of the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) lets you give that information at any police station "irrespective of the area where it is committed," and the station has no discretion to turn you away purely because the offence is not local to it. Where a station still refuses, [the remedies against a police station that will not register an FIR](/blog/police-not-registering-fir-remedy) apply without modification for a cyber fraud case.

Where the loss is small and speed is the priority, filing on the portal, getting the acknowledgment number, and following up with the bank is often enough for the freeze mechanism to work without a parallel station visit on day one. Where the loss is substantial, filing at the police station in parallel, not instead of the portal, is the safer course.

## The categories the portal uses, and why women and children route differently

The National Cybercrime Reporting Portal exists because financial fraud is only one category of cybercrime it handles. I4C's website describes a distinct workstream for what it calls "online crimes against women and children," including dedicated officer training separate from general cybercrime handling; in one instance the agency reported training 175 Uttar Pradesh police officers specifically on identifying and handling online crimes against women and children in June 2026. This is not a formality. Complaints in that category, covering online sexual harassment, child sexual abuse material, cyberstalking, and similar offences, are routed to units and personnel trained to handle the sensitivity of the underlying offence and, where the complainant chooses, can be filed with an option to keep the complaint anonymous, which is not available for a standard financial fraud complaint since the fraud investigation depends on the complainant's bank and transaction details.

For a financial fraud complaint, none of that special routing applies. Your complaint goes through the standard cybercrime workflow, which is built around getting the transaction and account details to the bank and the investigating agency as fast as possible, not around protecting complainant anonymity. If your situation involves both a financial loss and elements of harassment, stalking, or exploitation, for instance a fraud that began with a fake dating profile or a blackmail demand, disclose that fully when filing. It affects which unit within the portal's workflow picks up the complaint and what protections apply to how your identity is handled in the file.

## What happens after you file, and how to track it

Once a complaint is submitted on the portal, you receive an acknowledgment number. Keep it. That number is what you use to check status later and what you should quote in every follow-up call to your bank, the cyber cell, or I4C. The complaint is then routed to the law enforcement agency with jurisdiction, generally the cybercrime cell of the state or Union Territory where you filed, based on your reported location, and for financial fraud complaints it also flows into I4C's mechanism for coordinating with banks and payment system providers to act on the receiving account.

What "acting on the receiving account" means in practice depends on how quickly the money moved on from that account. If the freeze request reaches the bank while the funds are still sitting in the destination account, the bank can place a hold on that amount pending investigation. If the money has already been withdrawn or moved further downstream, freezing the immediate receiving account accomplishes less, which circles back to why the first hour matters more than any other part of this process.

Tracking status is done through the portal itself using your acknowledgment number, and separately through the police station or cyber cell if you also filed an FIR, since the FIR and the portal complaint are tracked in different systems even when they concern the same fraud. If your case reaches the stage of a chargesheet or a court filing, tracking then shifts to the case management systems the courts use, and the same complaint or FIR number carried through onto a case can later be looked up on the [eCourts and NJDG case status system](/blog/check-case-status-ecourts-njdg) once a case number is assigned. Where a cyber cell goes silent on a complaint for weeks with no update, filing a formal information request under the [Right to Information Act](/blog/how-to-file-rti) to the concerned police department is a legitimate way to force a written status update, since RTI applies to investigation-status records the same way it applies to any other government record, subject to the usual exemptions for material that would harm an ongoing investigation.

Investigations under the BNSS also run against statutory clocks the investigating agency itself has to observe, from timelines for filing a chargesheet to timelines for forensic examination in specified offences; the [full checklist of BNSS statutory timelines](/blog/bnss-statutory-timelines-checklist) is a useful reference if your fraud complaint has become a formal case and you want to know what the investigating officer is actually bound to do by when.

## Your bank's obligations and the RBI's liability rules

Separately from the criminal complaint, your bank has independent obligations toward you as a customer once you report an unauthorised electronic transaction. These are set out in the [Reserve Bank of India's circular](https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11040) *Customer Protection: Limiting Liability of Customers in Unauthorised Electronic Banking Transactions*, RBI/2017-18/15, DBR.No.Leg.BC.78/09.07.005/2017-18, dated 6 July 2017, addressed to all scheduled commercial banks. The circular requires banks to give customers 24x7 access through multiple channels, including a dedicated toll-free helpline and a direct link on the bank's website, for reporting unauthorised transactions, and to send an immediate acknowledgment with a registered complaint number the moment a report is made.

The circular sets three outcomes depending on how the loss occurred and how quickly it was reported:

- Zero liability applies where the unauthorised transaction results from a contributory fraud, negligence, or deficiency on the bank's part, regardless of whether the customer reported it, or where a third-party breach occurred (fault lying neither with the bank nor the customer) and the customer notifies the bank within three working days of receiving the bank's communication about the transaction.
- Limited liability applies where a third-party breach occurred and the customer notifies the bank within four to seven working days of that communication. In that window, the customer's liability is capped at the transaction value or the ceiling set out in the circular's Table 1, whichever is lower, ranging from Rs 5,000 for basic savings accounts to Rs 25,000 for larger current, cash credit, or high-limit credit card accounts.
- Beyond seven working days, liability is determined by the bank's own board-approved policy, which the bank must disclose to customers and publish.

Where the customer was negligent, for example by sharing an OTP or banking password, the customer bears the loss until the moment the transaction is reported to the bank; any loss occurring after that report is the bank's responsibility. Once a customer has notified the bank of an unauthorised transaction that qualifies for zero or limited liability, the circular requires the bank to credit the disputed amount back to the customer's account, on a shadow reversal basis, within 10 working days of the notification, without waiting for any insurance claim to first settle.

| Scenario | Liability outcome |
| --- | --- |
| Bank's own fraud, negligence, or system deficiency | ✓ Zero liability, regardless of when reported |
| Third-party breach, reported within 3 working days | ✓ Zero liability |
| Third-party breach, reported in 4 to 7 working days | Capped per Table 1 (Rs 5,000 to Rs 25,000 depending on account type) |
| Third-party breach, reported beyond 7 working days | As per the bank's board-approved policy |
| Loss from customer sharing OTP or password | ✗ Customer bears loss up to the point of reporting; bank liable after |
| Reversal timeline once liability is zero or limited | Bank must shadow-reverse the amount within 10 working days of notification |

The practical takeaway is that the clock the RBI circular runs on, working days from the date the bank's communication about the transaction reaches you, is separate from and can be shorter than the clock a criminal investigation runs on. Report to your bank the same day you report to 1930 and the portal. Waiting even two or three days can shift you from the zero-liability bracket into the capped-liability bracket for no reason connected to whether the money is actually recoverable.

## Preserving evidence without destroying it

Everything gathered in the first hour has evidentiary value only if it is preserved correctly from that point on. The habits that destroy it are common and usually well-intentioned.

Take full-page screenshots, not cropped ones, of every SMS, app notification, email, or chat message connected to the fraud, including the sender's number or address and the timestamp visible in the screenshot itself, not just the message text. For a phishing email or a fraudulent message, preserve the full email header, not just the visible sender name, since the header contains the routing information (originating IP address, mail server path) that establishes where the message actually came from; most email clients have a "view original" or "show source" option that displays this. For a fraudulent website, save the full URL, not just the domain, and where possible use your browser's save-page or print-to-PDF function to capture the page as it appeared rather than relying on a screenshot alone.

Keep every transaction reference exactly as issued: the UPI transaction ID, the UTR number, and the bank's own reference number for the debit, all of which appear on your passbook, app transaction history, or the SMS confirmation. If the fraud traces back to your personal data being leaked from a company you had an account with, for example a fraudster who already knew your policy number or loan details before calling, that company has its own breach-notification obligations under the [Digital Personal Data Protection Rules, 2025](/blog/dpdp-rules-2025), and a complaint to that entity's grievance officer runs alongside, not instead of, your cybercrime complaint. Do not paraphrase these into your own notes as the only record; keep the original source alongside any summary you make. If the fraud involved a call, note the number it came from, even if it displayed as a masked or spoofed number, since that detail still has investigative value.

What destroys evidentiary value is usually procedural, not deliberate. Factory-resetting the phone or device used in the transaction before it has been examined, deleting the fraudulent app or message thread once you believe you have "captured what's needed," or restoring from a backup that overwrites the device's current state, can all erase metadata an investigator needs and that a screenshot alone does not preserve. If a device is central to how the fraud happened, for example malware installed through a fake app, keep that device switched on and untouched until the cyber cell has had a chance to advise on imaging it, rather than continuing to use it normally. Under the Bharatiya Sakshya Adhiniyam, 2023, electronic records are admissible when accompanied by the certificate the statute requires, and the chain of custody from the moment of capture matters to whether that record holds up; the certification requirement for [electronic evidence under Section 63 of the BSA](/blog/bsa-section-63-electronic-evidence) is worth understanding before evidence is handed over, since a certificate obtained after the fact is harder to get right than one prepared as evidence is gathered.

If your bank refuses to acknowledge a properly reported unauthorised transaction within the RBI's timelines, or disputes your entitlement to zero liability despite meeting the conditions above, the next step is usually a formal written demand before escalating to the Banking Ombudsman or a consumer forum. The structure for [drafting a legal notice that puts the other side on formal notice](/blog/how-to-draft-legal-notice) applies to a bank's failure to reverse a fraudulent debit the same way it applies to any other contractual breach, and where the bank sends back a defensive or dismissive reply, [responding to that legal notice correctly](/blog/reply-to-legal-notice-india) keeps the record straight for whichever forum you escalate to next. A bank's failure to follow the RBI's own binding circular is a deficiency in service that the [Consumer Protection Act, 2019](/blog/consumer-protection-act-2019) squarely covers, and the complaint itself can be filed online through the [e-Daakhil portal](/blog/file-consumer-complaint-edaakhil) without needing to appear in person at the first stage.

## The offences that typically get invoked

Financial cyber fraud in India is rarely charged under a single statute. Two sets of provisions usually apply together: the [Information Technology Act, 2000](https://indiankanoon.org/doc/1965344/), whose criminal sections were not touched by the 2023 replacement of the IPC, CrPC, and Evidence Act, and the [Bharatiya Nyaya Sanhita, 2023 (BNS)](https://indiankanoon.org/doc/149679501/), which replaced the Indian Penal Code with effect from 1 July 2024.

Under the IT Act, Section 66C punishes identity theft: fraudulently or dishonestly using another person's electronic signature, password, or any other unique identifying feature, punishable with imprisonment up to three years and a fine up to Rs 1 lakh. Section 66D punishes cheating by personation using a computer resource or communication device, carrying the same punishment. Section 43 sets out civil compensation for unauthorised access to or damage of a computer or computer system, and Section 66 makes the same conduct a criminal offence, punishable with imprisonment up to three years or a fine up to Rs 5 lakh or both, where it is done dishonestly or fraudulently.

Under the BNS, the offence most commonly invoked alongside the IT Act sections is cheating. Section 318(1) defines cheating, and Section 318(4), corresponding to Section 420 of the old IPC, specifically punishes cheating that dishonestly induces the victim to deliver property, with imprisonment up to seven years and a fine, which is the provision that fits most UPI, net banking, and card fraud fact patterns. Where the fraud involved impersonating a bank official, a relative, or an authority figure, Section 319, corresponding to old IPC Section 419, covers cheating by personation specifically. Where a fabricated document, such as a forged KYC form or fake bank letter, was part of the scheme, Section 336 covers forgery, with the punishment rising to up to seven years under Section 336(3) where the forgery was intended to support cheating. Where the fraud involved someone entrusted with your funds or account access misusing that position, such as a relationship manager or an agent, Section 316 covers criminal breach of trust.

Which combination applies is a question of fact specific to how the fraud was carried out, and it is the investigating officer's call at the FIR stage, refined further once a chargesheet is filed. The [overview of what changed when the BNS, BNSS, and BSA replaced the older codes](/blog/new-criminal-laws-bns-bnss-bsa) and the [BNS-to-IPC section mapping](/blog/bns-ipc-section-mapping) are useful references if you are trying to match a provision your FIR cites back to the older numbering you may be more familiar with, and the separate question of [whether IPC-era case law still applies to the equivalent BNS provision](/blog/do-ipc-precedents-apply-under-bns) matters once your case reaches the stage of arguing bail or quashing, since a precedent decided under old Section 420 does not automatically transfer to new Section 318(4) without confirming the language carried over unchanged. Confirming that a cited precedent is still good law under the renumbered provision, rather than relying on a citation that predates the recodification, is exactly the kind of check a [dedicated legal research and citation tool](https://niyam.ai) is built to make fast rather than a manual cross-reference exercise done under deadline pressure.

## Frequently asked questions

### What number do I call if money has just been fraudulently debited from my account?

Call 1930, the national cybercrime helpline listed by the Indian Cybercrime Coordination Centre (I4C) under the Ministry of Home Affairs, alongside filing a complaint at cybercrime.gov.in. Call your bank's own fraud-reporting line at the same time, since the bank's internal freeze and liability timeline runs independently of the helpline. Do this within minutes of noticing the transaction, not after collecting every document first.

### Is filing a complaint on cybercrime.gov.in the same as filing an FIR?

No. A portal complaint creates a formal record that is forwarded to the relevant law enforcement agency and, for financial fraud, feeds into the bank-freeze mechanism, but it is not itself an FIR. For a cognizable offence like most financial fraud, you retain the right to have an FIR registered at a police station, and for significant losses that is worth doing in parallel rather than relying on the portal complaint alone.

### Can any police station register my cyber fraud FIR, or only one where I live?

Any police station must register an FIR for a cognizable offence regardless of territorial jurisdiction, then transfer it to the station where the offence occurred; this is the [zero FIR rule](/blog/zero-fir-e-fir-bnss-guide) under Section 173(1) of the BNSS. Since online fraud often has no clear physical location, this matters more for cybercrime than for most other offences, and a station cannot refuse you solely on jurisdiction grounds. If a station still refuses, [the specific remedies against non-registration](/blog/police-not-registering-fir-remedy) apply.

### How long do I have to report an unauthorised transaction to get zero liability from my bank?

Under the RBI's July 2017 circular on unauthorised electronic banking transactions, you get zero liability if the loss was due to a third-party breach and you notify the bank within three working days of the bank's communication about the transaction. Reporting within four to seven working days caps your liability at a fixed amount instead of eliminating it; reporting beyond seven days leaves you subject to the bank's own policy.

### What if I shared my OTP or UPI PIN before realising it was a scam?

Where the loss results from your own negligence, such as sharing an OTP, password, or UPI PIN, you bear the loss up to the point you report it to the bank. Any loss that occurs after you report the unauthorised transaction becomes the bank's responsibility. This makes the timing of your report to the bank significant even in cases where you contributed to the fraud.

### Once I report, how quickly must the bank return my money?

Where your loss qualifies for zero or limited liability under the RBI's circular, the bank must credit the disputed amount back to your account on a shadow reversal basis within 10 working days of your notification, without waiting for an insurance claim to be settled first. This is a regulatory timeline the bank is bound by, separate from how long the criminal investigation into the fraud takes.

### What is the difference in how the portal handles a financial fraud complaint versus a complaint involving a woman or child victim?

Financial fraud complaints go through the portal's standard workflow, built around routing transaction and account details to your bank and the investigating agency quickly. Complaints involving online crimes against women and children are handled by units given dedicated training for that category and, where the complainant chooses, allow the complaint to be filed with an anonymity option that is not built into the standard financial fraud workflow.

### What information should I gather before I even open the portal or dial the helpline?

Have your registered mobile number, the exact date and time of the fraudulent transaction, the UPI transaction ID or UTR number, the amount and destination account or handle, a screenshot of the debit confirmation, and any phone number, email, or website connected to the fraud. Also keep your bank account number, branch name, and a copy of a government identity document, since the portal requires identity verification to submit a complaint.

### Does a screenshot count as valid evidence in a cyber fraud case?

A screenshot is useful evidence but is strengthened significantly when it captures the full page, including the timestamp and sender details visible on screen, rather than a cropped image of just the message text. Under the Bharatiya Sakshya Adhiniyam, 2023, electronic records generally require an accompanying certificate to be admissible, so a screenshot alone should be supplemented with the underlying message, email header, or transaction log wherever you can preserve it.

### Should I turn off or reset my phone after discovering the fraud?

No. If the fraud involved malware, a fake app, or unauthorised access to the device itself, keep it switched on and avoid resetting, deleting the suspicious app, or restoring from a backup until the cyber cell has had a chance to advise on it. Resetting or overwriting the device can erase metadata that supports the investigation, even though a screenshot of what you saw on screen still has value on its own.

### What offences are typically cited in a cyber financial fraud FIR?

Most FIRs combine provisions from the Information Technology Act, 2000, commonly Sections 66C (identity theft) and 66D (cheating by personation using a computer resource), with provisions from the Bharatiya Nyaya Sanhita, 2023, most often Section 318(4) for cheating that induces delivery of property, corresponding to the old IPC Section 420. Section 319 (cheating by personation) or Section 336 (forgery) may be added depending on how the fraud was carried out.

### Has the replacement of the IPC by the BNS changed the IT Act sections used in cyber fraud cases?

No. The Information Technology Act, 2000's criminal provisions, including Sections 66, 66C, and 66D, were not amended when the Bharatiya Nyaya Sanhita, 2023 replaced the Indian Penal Code on 1 July 2024. What changed is the numbering of the general criminal law provisions, such as cheating and forgery, that are typically charged alongside the unchanged IT Act sections.

### What is I4C, and how is it different from a state police cybercrime cell?

The Indian Cybercrime Coordination Centre (I4C) is a Ministry of Home Affairs body that coordinates the national reporting infrastructure, including the helpline and the reporting portal, and works with banks and payment intermediaries on the freeze mechanism. State and Union Territory cybercrime cells are the investigating agencies that actually pursue individual FIRs and cases; a portal complaint is routed to the relevant state or UT cell for that stage of the work.

### Can I track my complaint after I file it on the portal?

Yes. The portal issues an acknowledgment number when you submit a complaint, and that number is used to check the complaint's status on the portal directly. If your matter also becomes an FIR at a police station, that is tracked separately through the police or the eCourts system once a case is registered, using the FIR or case number assigned at that stage.

### If the bank refuses to reverse a fraudulent transaction despite the RBI's rules, what can I do?

Put the bank on formal written notice citing the RBI circular and the timeline it missed, since a properly drafted demand often resolves the matter before escalation is needed. If the bank still does not act, you can escalate to the Banking Ombudsman under the RBI's grievance redressal scheme or file a consumer complaint, since a bank's failure to follow its own regulator's binding circular is a service deficiency a consumer forum can examine.

### Is there a deadline for filing a cyber fraud complaint on the portal, or can I file it weeks later?

The portal accepts complaints regardless of how much time has passed since the fraud, but the practical value of speed is entirely about recovery, not eligibility. A complaint filed weeks later can still lead to an FIR and an investigation, but the receiving account has almost certainly already been emptied by then, so the freeze mechanism that depends on fast reporting will no longer help.

### Does reporting to 1930 or the portal cost anything?

No. Reporting through the national cybercrime helpline and the National Cybercrime Reporting Portal is free. There is no fee for filing a complaint, and any call, message, or agent asking for payment to "process" your cybercrime complaint or "release" frozen funds is itself a fraud attempt and should be reported the same way.
