Before sending money to an unfamiliar UPI ID, phone number or bank account, there is now an official Indian government database worth checking: the I4C Suspect Repository on the National Cyber Crime Reporting Portal (NCRP).
The facility lets citizens search certain digital identifiers—including mobile numbers, email IDs, bank account numbers, UPI IDs and social-media identifiers—for possible links to cybercrime complaints. But there is a critical limitation: a match does not legally establish that the owner is a cybercriminal, and a clean search does not prove that an identifier is safe. I4C itself says the repository is based on complaints, is incomplete and is subject to errors.
That distinction matters before you decide whether to pay someone.
How to Check a UPI ID for Cybercrime
The quickest official check is through the Suspect Repository on cybercrime.gov.in.
Step 1: Open the official NCRP website
Go to the National Cyber Crime Reporting Portal at cybercrime.gov.in.
On the portal, look for:
Report & Check Suspect → Suspect Repository → Check Suspect
The current NCRP homepage lists separate facilities for checking suspects by mobile/email and for checking websites or apps.
Do not rely on a website sent to you by the person whose details you are checking. Type the official NCRP address yourself.
Step 2: Select the identifier
The public repository currently provides search categories including:
- Mobile number
- Bank Account Number
- Social Media
- UPI ID
For a UPI payment request, select UPI ID and enter the complete identifier. For a phone-based scam, search the mobile number. For a bank transfer, use the bank-account search option.
For mobile searches, the portal specifically instructs users not to add +91 before the number.
Step 3: Complete the captcha and search
The repository uses a captcha before displaying the search result.
If the identifier appears in the database, read the result carefully. Do not immediately conclude that the person or account holder is a criminal.
I4C’s own disclaimer says the database is created from cybercrime complaints received from the public and that I4C does not certify the authenticity of those complaints. Investigation is the responsibility of the relevant police authorities.
What Does an I4C Suspect Search Result Mean?
This is the part many online guides get wrong.
A result in the repository means the identifier has appeared in information associated with cybercrime complaints submitted through the NCRP system. It is a risk indicator, not a court finding.
The repository itself warns that:
- It is not complete.
- Cybercriminals can rapidly create, change or dispose of identifiers.
- Errors are possible.
- Users should exercise discretion.
- The authenticity of individual complaints is not certified by I4C.
So if a UPI ID appears in the database, treat it as a serious reason to stop and verify independently.
It should not be reported as proof that the person who currently controls that identifier is a criminal.
The reverse is equally important.
A “No Match Found” result does not mean “Safe”
This is an inference from I4C’s own warning that the repository is incomplete and that identifiers can be created or changed quickly.
A fraudster can use a newly created UPI ID, phone number or bank account that has never appeared in a complaint.
Therefore:
No match = no matching record found in that repository.
It does not mean:
No match = government-verified genuine person.
How to Check a Phone Number for Cybercrime
Use the same NCRP Suspect Repository and select Mobile.
This can be useful when you receive:
- A suspicious bank call
- A fake KYC call
- A digital-arrest call
- An investment offer
- A fake customer-care call
- A suspicious WhatsApp message
- A job or loan offer
- A payment request from an unknown number
I4C also provides a separate Report Suspect facility through which citizens can report suspicious phone numbers, WhatsApp numbers, Telegram handles, email IDs, URLs, SMS headers and social-media URLs.
If a number is not found in the repository but has clearly been used for fraud, reporting it can help add information to the wider cybercrime response system.
Do not use a phone-number search to identify a private person
The NCRP facility is a cybercrime-risk check. It is not a public reverse-KYC database.
A phone number being registered in somebody’s name, appearing on a caller-ID app or being associated with a social-media profile does not establish that the person committed a crime.
Avoid publishing or circulating a private person’s number simply because you suspect them of fraud.
How to Check a Bank Account for Fraud
The NCRP Suspect Repository also provides a Bank Account Number search.
This is particularly relevant when somebody sends you account details for:
- A large payment
- An advance payment
- An investment
- A loan
- A job-related fee
- A marketplace transaction
- A supposed government refund
- A donation or fundraising request
Search the account number before transferring money if the circumstances are suspicious.
But again, the result needs context.
A bank account may appear in a cybercrime complaint because it was allegedly used to receive or move fraudulent funds. That does not, by itself, establish who controlled the account or what the account holder knew.
This matters because cybercrime investigations increasingly encounter mule accounts—accounts used to receive or move money for criminal networks. The government says the I4C Suspect Registry had shared details of 32.08 lakh Layer-1 mule accounts with participating entities by June 30, 2026.
The distinction between an account being flagged and a person being convicted should never be lost in reporting.
What Is the Difference Between the Public Repository and I4C’s Suspect Registry?
They are related, but they are not the same thing.
The public NCRP Suspect Repository lets citizens search identifiers such as mobile numbers, email IDs, bank accounts and UPI IDs.
The broader Suspect Registry, launched by I4C in collaboration with banks and financial institutions in September 2024, is part of the financial-sector fraud-risk system.
MHA said that by June 30, 2026, more than 30.48 lakh suspect identifier records received from banks and financial institutions and 32.08 lakh Layer-1 mule accounts had been shared with participating entities. It also reported declined transactions worth ₹25,698 crore associated with the system.
In May 2026, I4C and RBIH also announced an agreement to use suspect-registry intelligence to strengthen AI-driven detection of mule accounts in the banking ecosystem.
The practical takeaway is simple:
Banks may have access to fraud-risk intelligence that an ordinary citizen cannot see through the public search page.
So a consumer’s search should be treated as one layer of verification—not a complete background check.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Check the Beneficiary Name Before Paying
There is another check you should make even when the I4C repository shows no result.
When making a UPI payment, inspect the beneficiary name shown by your payment application before authorising the transaction.
NPCI has required UPI applications to display the ultimate beneficiary’s banking name, fetched through the relevant validation mechanism, rather than relying on user-defined payee names or names extracted from QR codes.
The name should make sense in the context of the payment.
For example, if somebody claims to be collecting a payment for a company but the beneficiary information points to an unrelated individual, stop and verify through the company’s official contact channel.
A matching name is useful—but it still does not prove that the payment request is legitimate.
What About SEBI Check?
There is a separate official tool for securities-market payments.
SEBI Check allows investors to verify UPI IDs and bank-account details of eligible SEBI-registered intermediaries. SEBI’s live verification pages provide fields for UPI ID, account number and IFSC.
This is useful if someone is asking you to transfer money for:
- Stock-market investments
- Mutual funds
- Investment advisory services
- Other securities-market transactions involving a SEBI-regulated intermediary
But SEBI Check is not a general cybercrime blacklist.
A UPI ID passing SEBI’s verification means the relevant intermediary/payment details match SEBI’s verification framework. It does not mean every person using a similarly named UPI ID is legitimate.
What If the UPI ID Is Not in I4C’s Database?
Use additional checks before paying.
1. Verify the beneficiary
Check the beneficiary name displayed by your UPI application.
2. Verify independently
If someone claims to represent a company, bank, broker or government department, contact that organisation through its official website or known customer-service channel.
Do not use the phone number provided by the suspected caller to “confirm” their identity.
3. Check the payment purpose
Ask yourself whether the requested payment actually makes sense.
A legitimate UPI ID can still be used in a fraudulent transaction.
4. Never enter your UPI PIN just to “verify” an ID
A UPI PIN is used to authorise a payment. It is not a general-purpose identity-verification password.
NPCI’s UPI safety guidance advises users to exercise caution around payment requests and protect their authentication credentials.
What If the Identifier Appears in the Suspect Repository?
Do not send the money.
Save a screenshot of the search result and preserve the original UPI ID, phone number or account number.
If you believe an identifier is being used for cybercrime, use the NCRP’s Report Suspect facility. I4C specifically provides a mechanism for reporting suspicious identifiers and uploading supporting evidence.
If money has already been transferred, do not wait for the database search to resolve the situation.
Call 1930 and report the financial cyber fraud through the National Cyber Crime Reporting Portal. CERT-In’s citizen guidance also directs people to cybercrime.gov.in and 1930 for cyber fraud and crime reporting.
A Note About the NCRP Repository’s Date
There is a detail users should know before treating the public database as a live blacklist.
The current public Suspect Repository page displays “Last Updated: 02/02/2024”, even though the broader I4C Suspect Registry has continued to receive and share substantially larger volumes of data through the banking ecosystem in 2025–26.
That does not mean the NCRP facility is useless. It means its public-facing result should not be interpreted as a comprehensive, real-time clearance certificate.
This is one of the biggest gaps in simplified online guides about “checking a scammer”.
The Safest 60-Second Check Before You Pay
If you are about to send money to someone unfamiliar, use this sequence:
1. Copy the UPI ID/account number/phone number.
2. Search it in the I4C NCRP Suspect Repository.
3. Check the beneficiary name shown in your UPI app.
4. Independently verify the person or organisation.
5. For securities-market payments, use SEBI Check where applicable.
6. If anything conflicts, stop the payment.
7. If money has already been lost, call 1930 immediately.
No single database can prove that a payment is safe. The strongest check is a combination of an official cybercrime search, beneficiary verification and independent confirmation of who is actually requesting the money.
FAQ
Can I check a UPI ID for cybercrime in India?
Yes. The I4C National Cyber Crime Reporting Portal provides a public Suspect Repository where citizens can search UPI IDs, mobile numbers, bank account numbers, email IDs and other identifiers.
Does a “No Match Found” result mean the UPI ID is safe?
No. I4C explicitly says the repository is incomplete and that cybercriminals can rapidly create or change identifiers. A no-match result only means the identifier was not found in that database at the time of the search.
Does an I4C match prove someone is a cybercriminal?
No. The repository is based on complaints, and I4C says it does not certify their authenticity. The relevant police authorities investigate the allegations.
Can I check a phone number for cybercrime?
Yes. Select Mobile in the NCRP Suspect Repository. I4C also provides a separate facility to report suspicious phone numbers, WhatsApp numbers, Telegram handles and other identifiers.
Can I check a bank account for fraud?
Yes. Bank Account Number is one of the identifier categories available in the public I4C Suspect Repository. A result should be treated as a warning requiring further verification, not as proof of criminal liability.
Is SEBI Check the same as I4C Suspect Search?
No. SEBI Check is designed to verify payment details associated with eligible SEBI-registered intermediaries. I4C’s Suspect Repository is the broader cybercrime-related identifier search facility.
What should I do if I have already paid a suspicious UPI ID?
Call 1930 immediately, notify your bank/payment provider through its official channel and file or complete the complaint on cybercrime.gov.in. Preserve the UPI ID, transaction reference, screenshots, messages and other evidence.
Can I report a suspicious number even if it is not in the database?
Yes. The NCRP provides a Report Suspect facility for suspicious phone numbers, WhatsApp/Telegram identifiers, email IDs, URLs and other digital identifiers.
Useful next step: Save the official NCRP Suspect Repository page in your browser. If you regularly make online payments to unfamiliar people or businesses, check the identifier before paying not after the money has left your account.
About the author — Ananya Aradhya writes on cybercrime, fraud, scams, cybersecurity, digital safety, and emerging threats. Her work also covers major criminal cases, financial frauds, consumer scams, and stories that highlight risks affecting people in the real and digital world.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics