In India, the fastest way to report cyber fraud is through the 1930 Cyber Fraud Helpline and the National Cyber Crime Reporting Portal (cybercrime.gov.in). These government-backed systems operate under the Indian Cyber Crime Coordination Centre (I4C) and help banks, payment service providers, and law enforcement agencies respond quickly to suspicious transactions before stolen money is moved through multiple accounts.
Whether it is a UPI scam, phishing attack, fake investment scheme, digital arrest scam, or another form of online fraud, if money has been transferred without authorisation, taking immediate action can significantly improve the chances of stopping the transaction and recovering funds.
If you are wondering how to report cyber crime, this guide explains:
-
how to file a cybercrime online complaint
-
the crucial evidence you need to lodge a complaint
-
how complaint tracking works
-
what happens after you report the incident
Key Takeaways
-
Call 1930 within the first hour; this window matters more than any other factor.
-
File a formal NCRP complaint on cybercrime.gov.in even after calling 1930.
-
Save transaction IDs, screenshots, and UTR numbers before you report.
-
Notify your bank within three working days to protect your liability under RBI rules.
-
Track your case using the acknowledgement number generated at reporting.
-
Early reporting sharply raises the odds of a fund freeze; late reporting rarely recovers money.
Why the First Hour Matters More Than the First Week ( Golden Hour)
Cybercrime investigators call the first hour after a fraud the golden hour, and it decides more about recovery than anything you do afterwards. Stolen money does not vanish instantly; it usually lands first in a mule account, a holding account used to break the trail before withdrawal or further transfer. For a short window, those funds can still be located and frozen.
Report within that window, and a bank can place a lien on the receiving account. The Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) supports both the 1930 helpline and the online reporting portal, helping authorities trace and freeze fraudulent transactions quickly.
As of June 30, 2026, it had helped save more than ₹11,158 crore across over 32.8 lakh complaints since its 2021 launch. So, speed decides the outcome far more than the amount involved.
What Counts As Cyber Fraud
Cyber fraud covers any financial loss through a digital channel: UPI scams, phishing links, fake investment apps, OTP fraud, SIM swaps, loan app harassment, “digital arrest” calls, fake customer care numbers, remote-access app misuse, and card or net-banking fraud, resulting in unauthorised financial loss to the victim. If money was moved, or an attempt was made without your genuine consent, it is considered cyber fraud.
This differs from non-financial cybercrime like hacking or harassment, which the same portal accepts but routes differently.
| Aspect | Cyber Fraud | Other Cybercrime |
|---|---|---|
| Definition | Your money is stolen, or someone attempts to steal it through a digital channel | A digital crime occurs, but there may be no direct financial loss |
| How It Happens | Someone tricks you into sending money through UPI, bank transfer, card, wallet, or net banking | Someone hacks an account, threatens, harasses, impersonates, or misuses personal information without necessarily taking money |
| Examples | UPI scams, phishing links, fake investment apps, OTP fraud, SIM swaps, fake customer-care numbers, remote-access apps, digital-arrest scams, and loan-app fraud | Account hacking, cyberstalking, online harassment, identity misuse, threatening messages, or unauthorised access |
| Financial Impact | Money has moved, or someone has attempted to move money without the user's genuine consent | The harm is digital, but money has not necessarily been stolen or transferred |
| Reporting | Report immediately through the financial cyber-fraud reporting process | Report through the appropriate cybercrime reporting channel |
The simplest way to remember it
-
Cyber fraud = “Someone took or tried to take my money digitally.”
-
Other cybercrime = “Someone harmed, threatened, hacked, or misused something digitally, but it isn't necessarily about money.”
When unsure, file a complaint anyway; under-reporting costs victims far more than reporting something minor.
Cyber Fraud in India: Key Numbers
| Metric | Value |
|---|---|
| Money Saved Through CFCFRMS (Since 2021) | ₹11,158+ crore |
| Complaints Processed | 32.8 lakh+ |
| Mule Accounts Flagged by the Suspect Registry | 32 lakh+ |
| Fraudulent Transactions Blocked | ₹25,698+ crore |
Source: Ministry of Home Affairs / I4C figures, as of June 30, 2026.
Cyber Crime: How to Report Fraud Through the 1930 Helpline
1930 is India’s dedicated cyber fraud helpline number, run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs. It replaced an earlier number, 155260, in 2021, and operates toll-free, 24x7.
One of the most common questions victims ask is "cyber crime how to report after losing money online?" The answer depends on how quickly you act and whether the fraud involved a bank account, UPI transaction, card payment, or digital wallet. Here are the steps to follow.
Step 1: Call 1930 immediately, before confronting the fraudster or attempting recovery yourself. If a remote-access app is installed, switch to aeroplane mode first, then dial from another line.
Step 2: Give the operator your transaction details such as name, mobile number, amount, transaction ID or UTR number, date and time, and the bank, UPI app, or online wallet involved.
Step 3: Let the operator register and route the complaint. It gets logged into CFCFRMS, and an alert goes to the receiving bank’s nodal officer requesting a hold on funds. Save the SMS acknowledgement number, and if directed, complete additional details on cybercrime.gov.in the same day.
The helpline has no minimum transaction threshold, so it is worth calling for smaller amounts too. City cyber cell data consistently shows higher recovery when victims call within the first hour.
What Is a Mule Account and Why It Matters for Amount Recovery
A mule account is a bank or wallet account used to receive and quickly move stolen money. Fraud rings chain several mule accounts together: funds enter one, split across more within minutes, then get withdrawn as cash or moved cross-border.
This is why the golden hour matters. Once money clears a mule account and moves to the next hop, freezing it gets harder with every step. I4C’s Suspect Registry has already helped flag more than 32 lakh mule accounts, leading banks to decline transactions worth over ₹25,698 crore before those accounts could be used again, the Ministry of Home Affairs told the Lok Sabha in August 2026. Stopping a transaction before it reaches a mule account is far more effective than tracing it afterwards.
Read more: Money Mules 101: Recruited, Coerced, or Complicit
How to File a Cybercrime Online Complaint on cybercrime.gov.in (NCRP)
The National Cyber Crime Reporting Portal, or NCRP, is where you file a formal cybercrime online complaint, and it is the written record that police, banks, and the RBI's grievance process all refer back to later. File here even if you have already called the cyber fraud helpline number 1930, since the phone call and the portal complaint serve different purposes in the same case.
Step 1: Go to cybercrime.gov.in and choose your category
On the homepage, select “Register a Complaint,” then choose between “Report Women/Child Related Crime”, Financial Fraud, or “Report Other Cyber Crime.”




Step 2: Register or log in
First-time users select their state, enter an email address and mobile number, and verify both with an OTP. Returning users can log in directly. Keep your phone accessible, since the portal will send a one-time password to confirm your identity at more than one stage.

Step 3: Fill in the complaint form carefully
This is the section where detail matters most. You will describe the incident (the portal requires a minimum of 200 characters), enter the date, time, and mode of the transaction, add the suspect's phone number, UPI ID, bank account, or website if known, and avoid special characters like @, #, or % in text fields, since these can break the submission. Upload supporting evidence at this stage: screenshots, transaction slips, and chat records. There are 4 tabs to fill:
-
Incident details
-
Suspect details
-
Complainant details
-
Preview and submit
Fill each of the tabs very carefully to get the best possible resolution. Review every field carefully, since corrections after submission are harder to make than getting it right the first time; then click submit. You will receive an acknowledgement number by SMS and email. This number is what banks, the police, and you will use to track the case going forward, so treat it the way you would a case file number.
Evidence Checklist: What to Gather Before You Start
Gather the following records before you call 1930 or start your cyber fraud complaint on the portal, since both channels move faster once the details are already on hand.
-
Transaction ID or UTR number, with exact date, time, and amount
-
Bank or wallet statement showing the debit
-
Screenshots of the fraudulent app, website, or payment page
-
Phone numbers, email addresses, or UPI IDs used by the fraudster
-
Chat, SMS, or call logs connected to the fraud
-
A government ID for portal verification, and your acknowledgement number if you already called 1930
Do not delete the fraudster’s messages, block the number, or uninstall a suspicious app until this evidence is captured.
What Happens After You Report: The Recovery Timeline
Once your complaint is logged, several processes run in parallel, as discussed below.
1. Within the golden hour
The nodal officer at the receiving bank is alerted and can place a temporary lien on the account holding your funds, provided the money has not already been withdrawn or moved further along the chain.
2. Within 3 working days
Under the Reserve Bank of India's 2017 circular on customer liability, if you report an unauthorised transaction to your own bank within 3 working days of receiving its alert. If the fraud happened because of a third-party security breach and you did not cause it through your own negligence, you may have zero liability, meaning you may not have to bear the loss.
In such cases, RBI rules protect you from bearing the financial loss yourself. This protection applies regardless of whether the bank has already recovered the stolen funds from the fraudster. The bank may still pursue recovery separately, but you should not be held responsible for the loss if you meet the eligibility conditions.
3. 4 to 7 working days
Reporting in this window still limits your liability, typically to a capped amount depending on your account or card type, rather than the full transaction value.
4. Within 10 working days
Once you have notified your bank, RBI rules require it to credit the disputed amount back to your account within 10 working days, without waiting for its own investigation or insurance claim to conclude, provided the case falls under zero or limited liability.
5. For amounts above ₹10 lakh
Since May 2025, cyber fraud complaints involving amounts above ₹10 lakh that are reported through the National Cyber Crime Reporting Portal (NCRP) or the 1930 helpline automatically trigger registration of a Zero FIR with the e-Crime Police Station. This converts the complaint into a formal criminal case without requiring you to visit a police station separately.
6. Your report helps prevent future fraud
Your complaint helps enrich the I4C's Suspect Registry, a shared database of mobile numbers, UPI IDs, and bank accounts linked to prior fraud. As of June 30, 2026, I4C's Suspect Registry had shared more than 32.08 lakh Layer-1 mule accounts and over 30.48 lakh suspect identifiers with participating financial institutions, helping decline suspicious transactions worth ₹25,698 crore.
However, none of these guarantees your money comes back. Recovery depends heavily on how quickly you acted and how far the funds had already travelled. But every step above is a real, enforceable process, not a formality.
Here’s the typical cyber fraud timeline:
| Stage | What Typically Happens |
|---|---|
| Victim Transfers Money | Funds reach the fraudster's receiving account |
| Initial Laundering | Money is routed into one or more mule accounts |
| Rapid Layering | Funds are split and transferred across multiple accounts |
| Further Movement | Money may be converted to cash, crypto, or purchases |
| Delayed Reporting | Banks and law enforcement have fewer opportunities to freeze the funds |
| Recovery Becomes Increasingly Difficult | The chances of recovering the money decrease |
Other Ways to Report Cyber Fraud in India
The 1930 helpline and NCRP portal are the primary channels, but a few others matter depending on your situation.
-
Your bank or wallet directly: Most banks and UPI apps have a dedicated fraud-reporting number or an in-app “report transaction” option. Calling your bank alongside 1930 is not redundant; it starts your bank's own internal freeze process in parallel.
-
RBI Ombudsman: If your bank fails to resolve your cyber fraud complaint, or does not respond within 30 days, escalate it to the RBI Ombudsman through the Complaint Management System at cms.rbi.org.in, or by calling 14448. Under the Reserve Bank Integrated Ombudsman Scheme, 2026, effective July 1, 2026, the Ombudsman can award compensation of up to ₹30 lakh for financial loss caused by a regulated entity's deficiency in service.
-
Chakshu, on the Sanchar Saathi portal: Run by the Department of Telecommunications, Chakshu is for reporting a suspicious call, SMS, or WhatsApp message before you have lost money, things like fake KYC update requests or impersonation of a bank or government official. It is not meant for cases involving actual financial loss; those still go to 1930 or NCRP, but it helps get fraudulent numbers blocked at the network level.
-
Your local police station You can walk into any police station and report cyber fraud in person. Under the Zero FIR provision, an officer must register your complaint and forward it to the relevant cyber cell, regardless of jurisdiction.
Common Mistakes That Cost Victims Their Money
Once you are aware of how to report cybercrime, it’s time to know certain errors that quietly cost victims money they could otherwise have recovered:
-
Waiting to “figure out what happened” before reporting: every hour of delay lowers the odds of a fund freeze.
-
Deleting evidence out of panic, when screenshots and messages are often the only link investigators have.
-
Calling 1930 but never completing the NCRP complaint, which is the durable record police act on.
-
Continuing to engage with the fraudster, especially sharing another OTP to “verify” a refund. Banks and police never ask for OTPs.
-
Assuming that a small amount is not worth reporting, since complaint patterns help trace larger fraud rings.
Why Reporting Alone Cannot Stop Cyber Fraud
Reporting is inherently reactive. By the time a victim realises they have been defrauded and files a complaint, the fraud has already occurred. In many cases, stolen funds have been transferred through one or more mule accounts, fragmented across multiple transactions, or withdrawn before intervention can take place.
Modern cybercriminals operate at machine speed. They use fake identities, synthetic profiles, device farms, and coordinated mule-account networks to move money rapidly and evade detection. As fraud schemes become more sophisticated, relying solely on victim reports means organisations are always responding after the damage has begun.
Effective cyber-fraud prevention requires identifying risk before a transaction is completed or an account is approved. This is where real-time fraud intelligence becomes critical.
How Modern Fraud Detection Systems Stop Fraud Before Reporting Is Needed
By evaluating device details, transaction patterns, and account history, fraud can be detected before a transaction completes. This is exactly where Sign3 comes in.
-
Device intelligence flags multiple devices linked to prior fraud, emulators, or signs of tampering before a transaction is approved.
-
Behavioural biometrics reads how a genuine user types, taps, and navigates, flagging sessions that behave like a script rather than the account owner.
-
Digital footprint analysis cross-checks a user or device against patterns seen across other apps to detect fraud rings operating at scale.
-
Risk scoring combines these signals into a real-time score, letting banks block or step up verification instantly.
-
Mule account detection flags accounts showing mule-like inflow and outflow patterns before they can be used to launder stolen funds.
When used together, these components detect fraud at the point of transaction instead of relying entirely on a victim’s call to 1930 after the damage is done.
Read more: Fraud Detection Rules Every Fintech Should Implement
Conclusion
Fraud reported in time can sometimes be recovered. As cybercriminals are performing prompt and more sophisticated fraudulent activities, banks and fintechs are shifting from reactive recovery to proactive detection of cyber fraud cases.
By combining device intelligence, behavioural signals, digital footprints, and risk scoring, the fraud intelligence platform like Sign3 helps identify suspicious activity before money moves, reducing fraud exposure before victims ever need to call 1930 or file a complaint.
Frequently Asked Questions
How do I report cybercrime in India?
Call 1930 immediately if money has moved, then file a written cyber fraud complaint on cybercrime.gov.in using the acknowledgement number the system generates. Doing both gives you an urgent fund freeze request and a formal case record that your local police cyber cell can act on.
What is the cyber fraud helpline number, and is it free?
The cyber fraud helpline number is 1930. It is toll-free from any mobile or landline network in India, operated by I4C under the Ministry of Home Affairs, and available 24x7, including weekends and holidays.
How do I file a cybercrime online complaint on NCRP?
Visit cybercrime.gov.in, select “Report Other Cyber Crime,” register with your state, email, and mobile number, fill in the incident details and transaction information, upload your ID proof and evidence, then submit to receive an acknowledgement number for tracking.
Can I report cyber fraud anonymously?
For crimes against women and children, the portal allows anonymous reporting. For a financial cyber fraud complaint, your identity and ID proof are required, since banks need verified details from you to act on a freeze request. Your information is handled by law enforcement and is not made public.
Will I definitely get my money back?
No system can assure that. Recovery odds are highest when you report within the golden hour, and RBI's liability rules protect you from bearing the loss yourself in many cases, but funds already withdrawn or moved through several accounts become genuinely hard to trace.
What is an acknowledgement number, and why does it matter?
It is the reference number generated when you file on NCRP or call 1930. You will need it to track your complaint status on the portal, to follow up with your local cyber cell, and to correspond with your bank about the fraud.
What if my complaint status has not changed in weeks?
Track it anytime using your acknowledgement number under “Track Your Complaint” on cybercrime.gov.in. If there is no movement, follow up with your state or district cyber cell directly, citing the acknowledgement number.
Does filing a cyber fraud complaint cost anything?
No. The 1930 helpline, the NCRP portal, and the RBI Ombudsman are all free government services. Anyone asking for a “registration fee” or “processing charge” to act on your complaint is running a separate scam.
About The Author
Arvinder Singla is the Co-founder & CEO of Sign3. With extensive experience in the gaming and fintech industries, he has been at the forefront of innovating fraud prevention solutions. His expertise drives Sign3's mission to deliver cutting-edge technology that safeguards businesses from evolving fraud threats.
