The call comes from a number that looks official. A man in what appears to be a police uniform tells you a parcel in your name contained contraband, that a warrant has been issued, and that you must stay on video until the matter is "cleared". Four hours later your savings are gone. This is a scripted fraud with a name β digital arrest β and the law has answers for it, but only if you move in the first hour.
India has no single cyber crime statute: the offences sit across the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023, and the data protection rules, and the reporting machinery that actually recovers money is the 1930 helpline and the cybercrime.gov.in portal.
The bottom line
What to do first: call 1930 and file on cybercrime.gov.in, ideally within the hour. That is what freezes the receiving account before the money is layered away.
What the law covers: hacking, identity theft, impersonation fraud, privacy violations, obscene content, cyber terrorism, and attacks on critical infrastructure, with punishments from a fine to life imprisonment.
What it does not fix: money already withdrawn. Recovery odds fall sharply after 24 hours, and a report filed a week later is a prosecution record rather than a refund.
What counts as a cyber crime
A cyber crime is any unlawful act committed with a computer, network or digital device β either as the tool, as in phishing and online fraud, or as the target, as in data theft and system damage. No statute defines the phrase. It describes a cluster of offences spread across several laws, running from financial fraud and identity theft through cyberstalking, sextortion and obscene content to attacks on power grids and banking systems.
The practical consequence of that scatter is that a single incident usually attracts several provisions at once. A fake bank-officer call that empties an account is impersonation under the IT Act and cheating under the BNS, charged together.
The Information Technology Act, 2000
This is the principal cyber law, and its sections are worth knowing by number because they are what an FIR will cite.
- Section 43 β civil liability, with compensation up to βΉ1 crore, for damaging a computer, introducing a virus or accessing a system without authorisation.
- Section 66 β hacking and computer-related offences, up to 3 years and a fine.
- Section 66C β identity theft, up to 3 years and a βΉ1 lakh fine.
- Section 66D β cheating by personation using a computer resource, up to 3 years and a βΉ1 lakh fine. This is the section most digital arrest and fake-officer cases run on.
- Section 66E β violation of privacy by capturing or publishing private images, up to 3 years and a βΉ2 lakh fine.
- Section 66F β cyber terrorism, punishable with imprisonment for life.
- Sections 67, 67A and 67B β publishing or transmitting obscene material, sexually explicit material, and child sexual abuse material respectively.
- Section 70 β offences against protected systems and critical information infrastructure, up to 10 years.
One section is missing from that list on purpose. Section 66A criminalised sending "offensive" messages online, and the Supreme Court struck it down as unconstitutional in Shreya Singhal v. Union of India in 2015. Cases still get registered under it occasionally by police who have not caught up. They cannot stand.
The Bharatiya Nyaya Sanhita, and why both laws get used
The BNS replaced the Indian Penal Code on 1 July 2024. It says nothing about hacking, and that is not an oversight β it supplies the ordinary crimes that sit underneath the digital method. Cheating is Section 318, the old IPC 420. Cheating by personation is Section 319, formerly IPC 419. Theft is Section 303, extortion is Section 308, and defamation is Section 356.
Investigators charge the IT Act and the BNS together because each covers what the other does not. The IT Act describes the digital conduct; the BNS carries the dishonesty and the sentence for the underlying crime. The three new criminal laws changed the section numbers for almost everything, so an older complaint citing IPC 420 is describing what is now BNS 318.
Data protection and the deepfake rules
The Digital Personal Data Protection Act, 2023 governs how organisations handle personal data, and its Rules were notified in November 2025. It matters here in a specific way: when a breach at a company exposes the data later used to defraud you, the DPDP obligations are what that company answers for.
The IT Rules, 2021 require platforms to remove unlawful content and report incidents to CERT-In, the national cyber-incident response agency. In October 2025 those rules were amended to deal with deepfakes and synthetically generated information, including labelling requirements β the first direct legislative response to AI-generated impersonation.
How to report, in the order that matters
Speed is the whole game in financial fraud, because stolen money moves through a chain of mule accounts within minutes.
- Call 1930, the 24Γ7 national helpline, and file on the National Cyber Crime Reporting Portal at cybercrime.gov.in. Do this first, before anything else. The Citizen Financial Cyber Fraud Reporting and Management System behind it links more than 85 banks and intermediaries, and a report in the first hour can freeze the receiving account while the money is still sitting in it.
- Tell your bank to block the card or account, and lodge a written dispute. A phone call alone leaves you nothing to point at later.
- Preserve everything β screenshots, transaction IDs, URLs, email headers, call logs, the entire chat with the fraudster. Delete nothing, however embarrassing.
- Save the NCRP complaint ID. Every follow-up will ask for it.
- Escalate to an FIR at the local police station or cyber cell, which is necessary for larger frauds.
- Track the complaint on the portal and chase both the police and the bank. Persistence recovers money that patience does not.
Where you can report, and who can
Any victim can report, individual or organisation. Cyber crime carries pan-India jurisdiction, so a complaint can be registered with any cyber cell regardless of where the offence happened β the Zero FIR principle behind Section 154 of the CrPC, now the BNSS. Police who tell you to go back to the city where the fraud originated are wrong, and it is worth saying so politely at the desk.
The portal also allows anonymous reporting for offences against women and children, which exists because the alternative for many victims is not reporting at all. The wider protections for women apply alongside.
What the courts have done
Shreya Singhal in 2015 is the landmark on speech, striking down Section 66A for criminalising online expression in terms too vague to be constitutional.
The newer problem is AI. In Sadhguru Jagadish Vasudev v. Igor Isakov (2025) the Delhi High Court granted a sweeping "dynamic+" injunction protecting a person's name, image and voice from deepfake misuse, with orders for rapid takedowns. The reasoning is worth noting even if you never litigate: an ordinary injunction names specific URLs, which is useless when a thousand copies appear overnight. The court built an order that extends to material not yet posted.
Where the system still fails
Enforcement is the weak link, not the statute book. Fraud rings operate across state and national borders, behind anonymity tools and on infrastructure outside Indian jurisdiction. Digital evidence runs into admissibility problems. Trained cyber investigators are in short supply, and a district cyber cell holding hundreds of open complaints will not chase a small loss with any urgency.
The recovery window is the harder truth. Once funds pass through two or three mule accounts and out through a cash withdrawal, freezing achieves nothing. This is why the first hour matters more than the quality of your eventual complaint.
Common mistakes
- Waiting to report until you have "all the details". Call 1930 with what you know now.
- Deleting the chat or the messages out of embarrassment. That is the evidence.
- Continuing to talk to the fraudster, or paying something to make a fabricated case go away.
- Telling the bank but not the police, or the police but not the bank. Both, immediately.
- Sharing an OTP, PIN or CVV under pressure. No genuine official asks for these, in any circumstance, ever.
- Assuming nothing can be done once the window has closed. Reporting still builds the case that catches the ring, and partial recovery does happen.
Frequently asked questions
Where do I report a cyber crime? Call 1930 for financial fraud and file at cybercrime.gov.in. For an FIR, go to your local police station or cyber cell.
Was Section 66A really removed? Yes. The Supreme Court struck it down as unconstitutional in 2015 in Shreya Singhal. No case can validly be registered under it.
Can I report from a different city or state? Yes. Cyber crime has pan-India jurisdiction and you can file a Zero FIR anywhere, whatever the local station tells you.
Are deepfakes illegal? Misusing someone's likeness can attract the IT Act, the BNS and the DPDP provisions together, and the IT Rules were amended in October 2025 to deal specifically with synthetic media and labelling.
How long do I have to get my money back? Realistically, hours. The freeze mechanism works while the funds are still in the receiving account, and the chance of recovery drops sharply after the first 24 hours.
What is a digital arrest? A fraud, and not a legal procedure of any kind. No Indian agency conducts arrests over video call or asks for money to settle an investigation. Disconnect, verify through a number you look up yourself, and call 1930.