A practical guide to responding to cyber fraud in India: call 1930, alert your bank, secure compromised accounts, preserve digital evidence and complete the cybercrime complaint.

Cyber Fraud in India: What to Do in the First 30 Minutes After Losing Money

The420.in Staff
14 Min Read

The first 30 minutes after a cyber fraud are not the time to argue with the scammer, investigate their identity or panic about how the fraud happened. They are the time to report the transaction, alert the financial institution, secure any compromised account and preserve evidence.

In India, the national cyber-fraud helpline is 1930. The National Cyber Crime Reporting Portal at cybercrime.gov.in is the official online reporting channel, and the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) is designed to help authorities and financial institutions act while fraudulent funds may still be traceable.

The government says CFCFRMS had saved more than ₹11,158 crore across more than 32.80 lakh complaints by June 30, 2026. That does not mean every amount reported is automatically refunded; “saved” money and money ultimately restored to a victim are different stages.

Here is what to do, minute by minute.

First 5 minutes: Stop the money from moving further

1. Stop communicating with the fraudster

Do not negotiate. Do not threaten the caller. Do not click another link they send you.

If the fraudster is still on a call, end it.

If you have been told to transfer another amount for a “refund”, “verification”, “account unfreezing” or “recovery”, do not pay it.

A second payment can make the financial trail more complicated and increase the loss.

2. Do not delete anything

Take screenshots of:

  • The fraudulent transaction
  • Bank SMS or email alerts
  • UPI transaction details
  • UTR or transaction reference number
  • Recipient account or UPI ID
  • Phone numbers
  • WhatsApp, Telegram or social-media conversations
  • Emails and suspicious URLs
  • QR codes
  • Fake invoices, notices or identity documents
  • Any remote-access or APK application involved

The official NCRP checklist specifically asks financial-fraud complainants to keep the bank, wallet or merchant name, 12-digit transaction ID/UTR, transaction date, fraud amount and supporting evidence ready.

3. If your credentials were exposed, secure the account

If you disclosed your internet-banking password, card information, OTP, UPI credentials or other authentication information, use your bank’s official app, website or helpline to secure the account.

If a suspicious remote-access application was installed, avoid continuing sensitive banking activity on that compromised device until it has been secured.

Minutes 5–10: Call 1930

4. Report the financial fraud immediately

Call 1930, India’s national cybercrime helpline for financial cyber fraud.

The National Cyber Crime Reporting Portal specifically directs victims of cyber financial fraud to call 1930 for immediate reporting. The service is intended to help stop fraudulent funds from being siphoned away.

Have these details ready:

  • Your name and mobile number
  • Bank/wallet/payment service involved
  • Transaction date and time
  • Fraud amount
  • UTR/transaction ID
  • Recipient account or UPI ID, if visible
  • Fraudster’s phone number or email
  • Website, app or social-media account involved

Do not wait until you have every detail. Give the information you have and follow the instructions from the helpline.

The reason for urgency is practical, not symbolic: stolen funds can move from one account to another, be withdrawn or be transferred through multiple intermediary accounts.

5. Save the acknowledgement number

Keep the complaint acknowledgement SMS or reference number.

The 1930 report is not the same thing as an FIR, and calling 1930 does not automatically reverse a transaction. It starts the financial-fraud reporting and response process connected with the NCRP/CFCFRMS system.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Minutes 10–20: Alert your bank separately

6. Report the fraud to your bank or payment provider

Do this even after calling 1930.

Use only the bank’s official fraud helpline, official app or official website. Do not use a number sent by the suspected fraudster.

Tell the bank clearly:

“This is a cyber-fraud/unauthorised transaction. Please register the complaint and provide the complaint reference number.”

Ask what immediate controls are available for the affected channel—such as blocking a card, disabling internet banking or securing the relevant payment facility.

RBI’s customer-protection framework requires banks providing electronic banking services to provide round-the-clock mechanisms through multiple channels for reporting unauthorised transactions and loss or theft of payment instruments. Banks are also required to take immediate steps to prevent further unauthorised transactions after receiving such a report.

7. Understand the RBI liability rule

Reporting quickly can also matter for customer liability.

Under RBI’s framework, where an unauthorised transaction results from a third-party breach and neither the bank nor customer is at fault, reporting within three working days of receiving the bank’s communication about the transaction can result in zero customer liability.

Different rules apply where the customer has contributed through negligence—for example, by sharing payment credentials.

That is why a victim should report the transaction to the bank even if they have already contacted 1930.

Do not assume that a fraud victim automatically has zero liability. The facts and applicable RBI rules matter.

Minutes 20–30: Complete the paper trail

8. File or complete the NCRP complaint

Go to the official National Cyber Crime Reporting Portal and follow the instructions associated with your 1930 complaint.

The portal asks financial-fraud complainants for transaction details and supporting evidence.

Write the incident chronologically:

  1. How the fraudster contacted you
  2. What they claimed
  3. What link, app, QR code or account was used
  4. What you were asked to do
  5. What transaction took place
  6. When you discovered the fraud
  7. When you called 1930
  8. When you informed your bank

Keep the description factual. Do not guess the identity of the perpetrator or invent details that are not visible in your records.

9. Preserve the original evidence

Do not edit screenshots or crop away transaction information unnecessarily.

Keep the original:

  • SMS messages
  • Emails
  • Call records
  • Chats
  • Transaction receipts
  • Bank statements
  • URLs
  • Application files, where safely possible
  • Screenshots
  • Documents supplied by the fraudster

If police or the bank later request additional material, you should be able to provide the original records.

What happens after you report?

The current system is more than a complaint-number generator.

CFCFRMS is designed to allow police and financial institutions to coordinate around the reported transaction. Where the money is still traceable, the relevant financial institution may place the reported amount on hold under the applicable process.

The MHA said in July 2026 that the Money Restoration Module and Grievance Redressal Module became functional from April 2026. The first is intended to expedite restoration of defrauded money, while the second handles grievances involving frozen bank accounts and lien-marked amounts.

But there is a crucial distinction:

A hold is not the same as a refund.

The fact that ₹50,000, ₹5 lakh or ₹50 lakh has been placed on hold does not mean the victim can immediately spend that money again. Restoration depends on the investigation, transaction trail, procedural requirements and circumstances of the case.

The420.in has separately examined the current Money Restoration Module and the newer procedures for cyber-fraud victims.

Does the “30-minute rule” guarantee recovery?

No.

There is no government rule saying that a complaint made within 30 minutes guarantees recovery, or that a complaint after 30 minutes cannot succeed.

The practical principle is simpler:

The earlier the financial system is alerted, the greater the opportunity to intervene before the money moves further.

Current government data show the scale of the intervention system, but they should not be interpreted as a guarantee of recovery for an individual complaint.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

What if the fraud happened days ago?

Report it anyway.

A delayed complaint can still create an investigative record and may help authorities trace the transaction or identify linked accounts, phone numbers, URLs or other identifiers.

But do not delay simply because you believe the “golden hour” has already passed.

The correct response after a day, week or month is still to report the incident—not to abandon it.

What laws can apply to cyber fraud?

There is no single offence called a “1930 fraud”.

The applicable provisions depend on what the accused allegedly did.

Under the Bharatiya Nyaya Sanhita, 2023, which came into force on July 1, 2024, Section 318 deals with cheating and Section 319 with cheating by personation.

The Information Technology Act, 2000 also contains cyber-specific provisions. Section 66C deals with identity theft involving another person’s electronic signature, password or unique identification feature, while Section 66D covers cheating by personation using a communication device or computer resource.

The exact provisions used in a case are determined by investigators and prosecutors based on the evidence. A victim does not need to identify the correct criminal-law section before calling 1930.

Three things you should never do after a cyber fraud

Don’t pay a “recovery agent”

Anyone promising guaranteed recovery in exchange for an upfront payment should be treated with extreme caution.

A second fraud often targets people who have already lost money.

Don’t delete the scammer’s messages

Those messages may contain phone numbers, payment details, URLs, account information or other evidence useful to investigators.

Don’t wait for the bank to “sort it out”

Report to the bank and 1930.

They serve different parts of the response process.

FAQ: What to Do After Cyber Fraud in India

1. What is the first thing to do after a cyber fraud?

If money has been lost or an unauthorised financial transaction has occurred, call 1930 immediately, then notify the bank or payment provider through its official fraud-reporting channel.

2. Is 1930 available 24/7?

The official National Cyber Crime Reporting Portal directs victims of financial cyber fraud to the national helpline 1930for immediate reporting.

3. Should I call 1930 or my bank first?

Do both immediately. Calling 1930 connects the incident to the national cyber-fraud response system, while notifying the bank creates a direct fraud report with the financial institution.

4. Can 1930 guarantee that my money will come back?

No. A complaint can trigger efforts to trace and hold funds, but recovery depends on whether the money is still traceable, investigation, verification and the applicable restoration procedure.

5. What documents are needed to report cyber fraud?

Keep the transaction ID/UTR, bank or wallet details, transaction date and amount, your identification details and relevant evidence such as screenshots, messages, URLs and other records.

6. Does a 1930 complaint automatically become an FIR?

No. A cybercrime complaint, financial-fraud response and FIR are separate stages. Conversion into an FIR and subsequent investigation are handled by the relevant State or Union Territory law-enforcement agency.

7. What if I reported the fraud late?

Report it anyway. Delay can reduce the opportunity for rapid intervention, but it does not mean the incident should go unreported.

8. What should I do next?

Keep your 1930 acknowledgement, bank complaint number and evidence in one folder. Follow up through the NCRP and respond promptly to requests from your bank or investigating agency.

The most useful rule is simple: report first, reconstruct the story second.

About the author — Ananya Aradhya writes on cybercrime, fraud, scams, cybersecurity, digital safety, and emerging threats. Her work also covers major criminal cases, financial frauds, consumer scams, and stories that highlight risks affecting people in the real and digital world.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected