Emergency Response Centre

You have been targeted. Here is exactly what to do.

Speed matters more than anything else on this page. Money that has left your account can often be frozen inside the first hour, and almost never after a day.

The golden hour โ€” first 60 minutes

Money lost

If funds have been debited

  1. Stop all further transactions. Do not send "one more payment" to fix it โ€” that instruction is part of the fraud.
  2. Call 1930. Have ready: your account number, the exact amounts, times, and every UTR / transaction reference.
  3. Call your bank's fraud line in parallel and ask for an immediate freeze on outward transactions and a beneficiary hold request.
  4. File at cybercrime.gov.in under "Report Financial Fraud". Save the acknowledgement number.
  5. Screenshot everything before anything is deleted: chats, caller numbers, UPI IDs, links, e-mails with headers.
  6. Give your bank a written complaint within 3 working days โ€” this preserves your rights under the RBI limited-liability framework.
Account or device compromised

If you were hacked, not robbed

  1. Put the phone in airplane mode if a remote-access app is running โ€” it cuts the session instantly.
  2. From a different, clean device: change passwords and revoke all active sessions.
  3. Remove any MFA method, forwarding rule, inbox rule or app permission you did not add.
  4. Uninstall AnyDesk / TeamViewer / QuickSupport / any sideloaded APK; revoke accessibility permissions.
  5. Check call forwarding: dial *#21#; cancel with ##21#.
  6. Factory-reset the device if malware is suspected, then change credentials again from the clean device.
Never do these three things Do not pay anyone who promises to recover your lost money for a fee โ€” that is the second scam. Do not delete evidence out of embarrassment. Do not keep it secret; isolation is what every one of these frauds depends on.

Where to report โ€” India

Use every applicable channel. They serve different purposes and do not replace each other.

ChannelUse it forHow
Helpline 1930Any financial cyber fraud โ€” fastest route to freezing fundsDial 1930
National Cyber Crime Reporting PortalAll cyber crimes; separate anonymous flow for women & child crimecybercrime.gov.in
Local cyber police stationFIR for significant loss, harassment, extortion, stalkingVisit in person with printed evidence
Your bank / wallet / PSPTransaction dispute, chargeback, account freeze, limited-liability claimOfficial app help section or the number on your card
CERT-InOrganisational incidents โ€” ransomware and specified incidents within 6 hoursincident@cert-in.org.in
Sanchar Saathi (Chakshu)Fraud calls and SMS, SIM swap, connections issued in your name (TAFCOP)sancharsaathi.gov.in
RBI SachetUnregulated lenders, illegal deposit schemes, loan-app harassmentsachet.rbi.org.in
RBI Ombudsman (CMS)Bank has not resolved your complaint within 30 dayscms.rbi.org.in
SEBI SCORESInvestment, advisory and securities fraudscores.sebi.gov.in
StopNCIIPreventing re-upload of intimate images across platformsstopncii.org
Childline 1098 / Tele-MANAS 14416Child safety; mental-health support for victims1098 ยท 14416

Evidence checklist

Investigators can only act on what you preserve. Capture this before blocking anyone.

Always capture

  • Screenshots of the full chat, including the sender's profile and number
  • Caller numbers, call times and call duration from your log
  • UPI IDs, bank account numbers, IFSC codes and UTR / reference numbers
  • The exact debit SMS and e-mail alerts, unedited
  • Links, shortened URLs and the domain they resolved to
  • Any APK, PDF or document you were sent (do not open it again)
  • E-mail with full headers (use "Show original" / "View source")
  • The app name, publisher and screenshots of any fake dashboard

How to preserve it properly

  • Do not delete the conversation โ€” block only after capturing
  • Export the chat (WhatsApp: Export chat โ†’ include media)
  • Store copies in two places: your device and a cloud folder or e-mail to yourself
  • Note a written timeline with dates and times while your memory is fresh
  • Print the key screenshots for the police station โ€” they are usually required on paper
  • Record your complaint acknowledgement numbers and the investigating officer's name
  • Keep bank statements covering the whole period, not just the disputed entries

Filing a complaint at cybercrime.gov.in โ€” step by step

  1. Go to cybercrime.gov.in โ€” type the address; do not use a search result.
  2. Choose the correct category: Report Financial Fraud for money loss, Report Women/Child Related Crime for sexual offences, harassment or child safety (this one allows anonymous reporting), or Report Other Cyber Crime.
  3. Register or log in with your mobile number and verify by OTP.
  4. Complete the incident details: date, time, amount, payment method, and the suspect details you have.
  5. Upload the evidence you preserved. Keep each file under the stated size limit; combine screenshots into a single PDF where needed.
  6. Submit and save the acknowledgement number. You will need it for every follow-up and for the bank.
  7. Track status under "Check Status" using the same login.
  8. Follow up with the assigned cyber police station; escalate to the Superintendent of Police if there is no movement.
Reporting is worth it even when the money is gone Complaints are what map mule networks, freeze downstream accounts and support prosecution. Every unreported case makes the next victim easier to reach.

Organisations โ€” CERT-In obligations

The 6-hour rule

Under the CERT-In Directions of 28 April 2022, entities in India must report specified cyber incidents to CERT-In within 6 hours of noticing them. Ransomware, data breaches, identity theft, and attacks on critical systems are all in scope.

Directions also require synchronised system clocks to NPL/NIC time and retention of ICT logs for 180 days within India.

CERT-In guidance โ†—

Also consider

  • DPDP Act 2023 personal-data breach obligations to the Data Protection Board and affected individuals
  • Sectoral regulators: RBI / CSIRT-Fin, SEBI, IRDAI, TRAI as applicable
  • NCIIPC where the entity operates Critical Information Infrastructure
  • Cyber insurance notification โ€” usually a strict policy condition with a short window
  • Foreign regulators where affected individuals are outside India (GDPR: 72 hours)
  • Law enforcement: local cyber police and, for large cases, state cyber cells
Reporting from outside India? The steps above stay the same โ€” act fast, preserve evidence, tell your bank โ€” but the authority you report to changes. Reporting routes for the USA, UK, UAE, Singapore, Australia, Canada and others are on the Countries page.