Skip to content
Close

Search

Gold scales of justice enclosed within a laurel wreath beside the text “The Law School Hub” and the tagline “Learn Law. Understand Justice.” on a professional grey background. Gold scales of justice enclosed within a laurel wreath beside the text “The Law School Hub” and the tagline “Learn Law. Understand Justice.” on a professional grey background. The Law School Hub

Learn Law. Understand Justice.

Gold scales of justice enclosed within a laurel wreath beside the text “The Law School Hub” and the tagline “Learn Law. Understand Justice.” on a professional grey background. Gold scales of justice enclosed within a laurel wreath beside the text “The Law School Hub” and the tagline “Learn Law. Understand Justice.” on a professional grey background. The Law School Hub

Learn Law. Understand Justice.

  • Home
  • All Blog Categories
    • Administrative Law
    • Banking and Finance Law
    • Case Summaries
    • Constitutional Law
    • Corporate and Commercial Law
    • Criminal Law
    • Environmental Law
    • Family Law
    • International Law
    • Intellectual Property Law
    • Judiciary Examination Preparation
    • Labour and Employment Law
    • Law Entrance Examination Guidance
    • Legal News Analysis
    • Legal Research and Writing
    • Taxation Law
    • Technology and Cyber Law
  • Case Summaries
    • Technology and Cyber Law Case Summaries
    • Taxation Law Case Summaries
    • Labour and Employment Law Case Summaries
    • International Law Case Summaries
    • Intellectual Property Law Case Summaries
    • Family Law Case Summaries
    • Environmental Law Case Summaries
    • Criminal Law Case Summaries
    • Corporate and Commercial Law Case Summaries
    • Constitutional Law Case Summaries
    • Banking and Finance Law Case Summaries
    • Administrative Law Case Summaries
  • Contributor’s Page
  • About Us
  • Join Our Community
  • Contact Us
  • Terms of Service
  • Privacy Policy

Main Menu

  • Home
  • All Blog Categories
    • Administrative Law
    • Banking and Finance Law
    • Case Summaries
    • Constitutional Law
    • Corporate and Commercial Law
    • Criminal Law
    • Environmental Law
    • Family Law
    • International Law
    • Intellectual Property Law
    • Judiciary Examination Preparation
    • Labour and Employment Law
    • Law Entrance Examination Guidance
    • Legal News Analysis
    • Legal Research and Writing
    • Taxation Law
    • Technology and Cyber Law
  • Case Summaries
    • Technology and Cyber Law Case Summaries
    • Taxation Law Case Summaries
    • Labour and Employment Law Case Summaries
    • International Law Case Summaries
    • Intellectual Property Law Case Summaries
    • Family Law Case Summaries
    • Environmental Law Case Summaries
    • Criminal Law Case Summaries
    • Corporate and Commercial Law Case Summaries
    • Constitutional Law Case Summaries
    • Banking and Finance Law Case Summaries
    • Administrative Law Case Summaries
  • Contributor’s Page
  • About Us
  • Join Our Community
  • Contact Us
  • Terms of Service
  • Privacy Policy
  • Home
  • All Blog Categories
    • Administrative Law
    • Banking and Finance Law
    • Case Summaries
    • Constitutional Law
    • Corporate and Commercial Law
    • Criminal Law
    • Environmental Law
    • Family Law
    • International Law
    • Intellectual Property Law
    • Judiciary Examination Preparation
    • Labour and Employment Law
    • Law Entrance Examination Guidance
    • Legal News Analysis
    • Legal Research and Writing
    • Taxation Law
    • Technology and Cyber Law
  • Case Summaries
    • Technology and Cyber Law Case Summaries
    • Taxation Law Case Summaries
    • Labour and Employment Law Case Summaries
    • International Law Case Summaries
    • Intellectual Property Law Case Summaries
    • Family Law Case Summaries
    • Environmental Law Case Summaries
    • Criminal Law Case Summaries
    • Corporate and Commercial Law Case Summaries
    • Constitutional Law Case Summaries
    • Banking and Finance Law Case Summaries
    • Administrative Law Case Summaries
  • Contributor’s Page
  • About Us
  • Join Our Community
  • Contact Us
  • Terms of Service
  • Privacy Policy
Close

Search

Home/Technology and Cyber Law/Master the Crucial Do’s and Don’ts of Cybercrime Reporting to Safely Crush Devastating Online Hackers
Technology and Cyber LawAll Blog Categories

Master the Crucial Do’s and Don’ts of Cybercrime Reporting to Safely Crush Devastating Online Hackers

By Yash Yogitta Joshi
June 29, 2026 18 Min Read
0
Updated on July 6, 2026
Do's and don'ts of cybercrime reporting cover image showing green checklist, red warning list, cybercrime complaint form, Information Technology Act 2000, reporting portal, and cyber fraud alert phone.
A smart legal guide explaining the do’s and don’ts of cybercrime reporting for victims and complainants.

Legal Note: This article is intended for educational and informational purposes only and does not constitute formal legal advice. While every effort has been made to ensure legal accuracy, readers must verify provisions with official sources or consult a practicing advocate. Laws such as the IPC, IEA, and CrPC have transitioned to the Bharatiya Nyaya Sanhita (BNS), Bharatiya Sakshya Adhiniyam (BSA), and Bharatiya Nagarik Suraksha Sanhita (BNSS) frameworks; kindly verify current applications based on the date of the offense.

Table of Contents

  • Introduction
  • Overview
  • Detailed Explanation
    • The Critical “Do’s” of Cybercrime Reporting
    • The Fatal “Don’ts” of Cybercrime Reporting
  • Key Legal Provisions
    • The Information Technology Act, 2000
    • The Bharatiya Sakshya Adhiniyam, 2023 (BSA)
    • The Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS)
  • Important Case Laws
    • 1. The Absolute “Do” of Evidence Certification: Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal
    • 2. The Mandate to Register an FIR: Lalita Kumari v. Govt. of U.P.
    • 3. Virtual Presence and Legal Jurisdiction: State of Maharashtra v. Dr. Praful B. Desai
    • 4. Intermediary Guidelines and Takedowns: Shreya Singhal v. Union of India
  • Practical Examples and Illustrations
    • Illustration 1: The Remote Access Banking Fraud
    • Illustration 2: Corporate Ransomware and Data Extortion
    • Illustration 3: Cyber Defamation and Image Morphing
  • Listicles: Vital Summaries for Your Protection
    • 10 Absolute “Do’s” You Must Execute Immediately
    • 10 Absolute “Don’ts” You Must Avoid at All Costs
  • Tables: Tactical Organization for Cybercrime Rules
  • Key Takeaways
  • Conclusion
  • FAQs
  • Legal References

Introduction

When a devastating cyberattack occurs—whether it involves a rapidly draining bank account, a hijacked social media profile, or a corporate data breach—the sheer panic that follows frequently paralyzes the victim. In these critical first moments, victims constantly ask a desperate question: “What exactly must I do right now, and what must I absolutely avoid doing?” Directly answering this urgent query, your very first step must be to call the 1930 National Cybercrime Helpline to freeze stolen funds, while simultaneously avoiding the fatal mistake of deleting the original digital evidence out of fear. Because the internet is a highly volatile environment, the line between successfully prosecuting a scammer and losing your legal case entirely depends on your immediate actions. Therefore, mastering the specific Dos and Donts of Cybercrime Reporting is not merely an administrative formality; it is the ultimate legal shield that separates empowered victims from permanent financial loss. This comprehensive, beginner-friendly guide will equip law students, young advocates, and everyday netizens with the exact procedural knowledge required to navigate a digital crisis safely.

Overview

The legal framework governing cyberspace in India operates at the intricate intersection of technology and procedural criminal law. Primarily, the Information Technology Act, 2000 establishes the substantive offenses, defining what constitutes a digital crime. Concurrently, the newly implemented Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) dictates exactly how the police must investigate these crimes, while the Bharatiya Sakshya Adhiniyam, 2023 (BSA) strictly governs how digital evidence must be presented in a court of law. Because electronic data is incredibly fragile and easily manipulated, Indian courts demand strict adherence to procedural protocols. Ultimately, failing to follow the correct Dos and Donts of Cybercrime Reporting frequently leads to catastrophic procedural blunders, resulting in the rejection of evidence and the acquittal of guilty hackers. This detailed blog meticulously breaks down these binary rules, providing a clear roadmap to secure absolute legal justice.

Detailed Explanation

Navigating a cyber investigation requires cold, calculated legal precision. Victims and their legal representatives must view the compromised device not merely as a piece of technology, but as an active crime scene that requires immediate, careful securing. To ensure absolute compliance with Indian cyber jurisprudence, we must dissect the Dos and Donts of Cybercrime Reporting into distinct, actionable categories.

The Critical “Do’s” of Cybercrime Reporting

Understanding what proactive steps you must take is the foundation of a strong legal defense. These are the non-negotiable actions that empower law enforcement to assist you.

  • DO Sever the Internet Connection Immediately: If you suspect your computer or smartphone is actively compromised by malware or a remote-access application, you must disconnect it from the internet instantly. Turn off the Wi-Fi router or unplug the ethernet cable. This action prevents the hacker from exfiltrating more data or sending further malicious commands to your device.
  • DO Call the 1930 Helpline for Financial Frauds: If the cybercrime involves unauthorized UPI transfers, credit card scams, or bank fraud, your most urgent “Do” is dialing 1930. The Citizen Financial Cyber Fraud Reporting and Management System uses this helpline to trigger a real-time alert across the banking network. This rapid response attempts to freeze the stolen funds in the scammer’s destination account before they can successfully withdraw the cash.
  • DO Preserve the Original Electronic Evidence: Courts rely entirely on primary data. You must meticulously preserve the original emails, SMS messages, WhatsApp chats, and server logs. If you received a phishing email, you must save the complete “Email Header” (which contains the originating IP address), rather than just taking a surface-level screenshot. The original data on the physical device forms the corpus delicti—the physical body of the digital crime.
  • DO File a Formal Complaint on the National Portal: Do not rely merely on verbal complaints to your local beat officer. You must log on to the centralized National Cyber Crime Reporting Portal (NCRP). This platform allows you to create a chronological, legally documented incident report, which subsequently generates a unique, trackable acknowledgment number.
  • DO Draft a Section 63 BSA Certificate: Under the new Indian evidence laws, a printed screenshot is legally useless on its own. You must draft and sign a statutory certificate under Section 63 of the BSA. This vital document legally guarantees that the computer or smartphone you used to capture the evidence was functioning correctly and was under your lawful control.
  • DO Notify Your Bank Within 72 Hours: If you suffer a banking fraud, relying solely on a police complaint is a severe mistake. You must formally submit a written dispute to your home bank branch within three working days. Complying with this specific Reserve Bank of India (RBI) mandate is crucial because it often shifts the financial liability away from you, legally forcing the bank to refund your stolen money.

The Fatal “Don’ts” of Cybercrime Reporting

Equally important to knowing what to do is knowing exactly what actions will permanently destroy your case. Avoiding these common blunders is a core component of mastering the Dos and Donts of Cybercrime Reporting.

  • DON’T Delete the Abusive Messages or Malicious Files: Out of sheer anger, disgust, or embarrassment, victims frequently delete threatening WhatsApp messages or the fake banking apps that scammed them. This is a fatal legal error. Deleting these items permanently destroys the primary electronic evidence that forensic experts desperately need to trace the perpetrator.
  • DON’T Power Off or Format the Device: While you must disconnect the internet, you absolutely must not turn the device off or perform a “Factory Reset.” Powering down a device immediately erases the volatile memory (RAM), which often contains the cryptographic keys or temporary IP addresses used by the hacker. Formatting the device destroys all digital footprints, rendering a police investigation impossible.
  • DON’T Engage in Vigilantism or “Hack Back”: Out of frustration, victims sometimes attempt to retaliate against the scammer by sending viruses back or hiring unethical private hackers. You must never do this. “Hacking back” is strictly illegal in India. By engaging in active digital retaliation, you instantly transform your legal status from an innocent victim into a criminal suspect under the IT Act.
  • DON’T Confront the Attacker Directly: If you discover a fake social media profile impersonating you, do not message the creator threatening them with police action. Confronting the scammer prematurely simply alerts them to your awareness. They will immediately delete the profile, erase their server logs, and disappear before law enforcement can issue a legal preservation order to the social media platform.
  • DON’T Accept Police Refusal to File an FIR: Local police stations sometimes hesitate to register complex cybercrime cases, citing a lack of territorial jurisdiction. You must not accept this refusal. The law empowers you with specific rights. By walking away defeated, you allow the criminal to escape justice simply due to administrative friction.
  • DON’T Delay the Reporting Process: Cybercriminals rely entirely on your confusion and shame. If you wait days or weeks to report a financial scam because you feel embarrassed, the hackers will route your stolen funds through multiple international shell accounts or convert them into untraceable cryptocurrency. Speed is your only true defense in cyberspace.

Key Legal Provisions

To execute the Dos and Donts of Cybercrime Reporting effectively, legal professionals and victims must deeply understand the statutory backbone of Indian cyber law. Relying on these exact sections in your legal drafts ensures that law enforcement takes your complaint seriously. You can explore these acts and legal concepts in greater detail through comprehensive study materials at The Law School Hub.

The Information Technology Act, 2000

  • Section 43 (Penalty and Compensation for damage to computer, computer system, etc.): This is a foundational civil provision that allows a victim to seek financial compensation if someone accesses their computer without permission. Crucially, this section highlights a major “Don’t.” If you attempt to “hack back” against your attacker, you directly violate Section 43, making you liable to pay massive compensation.
  • Section 66 (Computer Related Offences): This vital provision translates the civil wrongs of Section 43 into criminal offenses. It prescribes imprisonment for up to three years and hefty fines for anyone who dishonestly or fraudulently commits data theft or hacking. When you fulfill the “Do” of filing an FIR, you must ensure the police invoke this section.
  • Section 66C (Punishment for identity theft): This crucial section protects your digital identity. It specifically targets scammers who fraudulently make use of your electronic signatures, passwords, or unique identification features.
  • Section 66D (Punishment for cheating by personation by using computer resource): This is the core legal provision invoked for modern phishing scams, fake social media profiles, and matrimonial frauds. When someone pretends to be a legitimate bank official online to extract money, they violate Section 66D.
  • Section 70B (Indian Computer Emergency Response Team to serve as national agency for incident response): This section dictates the mandatory corporate Dos and Donts of Cybercrime Reporting. It imposes a massive legal duty on corporate entities and data centers to report severe cyber incidents (such as ransomware attacks) to CERT-In within exceptionally tight timeframes, typically within 6 hours of discovery. Hiding a breach is a major corporate “Don’t.”
  • Section 75 (Act to apply for offence or contravention committed outside India): This highly important section protects your rights against international attackers. It clearly states that the IT Act applies to an offense committed outside India by any person, provided the act involves a computer resource located physically in India. This nullifies the “Don’t” of assuming you cannot catch a foreign hacker.

The Bharatiya Sakshya Adhiniyam, 2023 (BSA)

  • Section 63 (Admissibility of electronic records): Formerly known as the infamous Section 65B of the Indian Evidence Act, this new provision is the most critical evidentiary step in your legal journey. It strictly mandates that any electronic record (such as printed emails, WhatsApp chats, or server logs) must be accompanied by a specific, signed certificate to be deemed legally admissible as evidence in a court of law. Submitting uncertified digital evidence is a massive legal mistake.

The Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS)

  • Section 173 (Information in cognizable cases): Formerly Section 154 of the CrPC, this section legally obligates police officers to register a First Information Report (FIR) for cognizable offenses. More importantly, it statutorily solidifies the concept of the “Zero FIR.” This means the police must register the case regardless of where the crime occurred and then transfer it. This provision empowers you to completely ignore the “Don’t” of accepting a police refusal based on jurisdiction.
  • Section 175(3) (Power of Magistrate to direct investigation): Formerly Section 156(3) CrPC, this provision is your ultimate legal remedy. If the police stubbornly fail in their duty to register your cybercrime FIR, you have the statutory right to approach a Judicial Magistrate. The Magistrate can subsequently order the police to launch an immediate, binding criminal investigation.

Important Case Laws

Judicial precedents from the Supreme Court and various High Courts continuously shape how the Dos and Donts of Cybercrime Reporting are executed in practical scenarios. Referencing these exact cases in your legal representations significantly boosts your authoritativeness and legal standing.

1. The Absolute “Do” of Evidence Certification: Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal

Citation: Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1. Relevance: In this monumental and clarifying judgment, the Supreme Court of India definitively settled decades of confusion surrounding electronic evidence. The Court ruled that the statutory certificate (formerly under Section 65B of the Evidence Act, now Section 63 of the BSA) is a strict, mandatory condition precedent for the admissibility of electronic records. The Court held that victims simply cannot bypass this requirement. Therefore, drafting this certificate is a non-negotiable, mandatory “Do” when gathering your digital evidence.

2. The Mandate to Register an FIR: Lalita Kumari v. Govt. of U.P.

Citation: Lalita Kumari v. Govt. of U.P., (2014) 2 SCC 1. Relevance: A Constitution Bench of the Supreme Court unequivocally mandated that the police must register an FIR if the information provided by the victim discloses the commission of a cognizable offense. The police have absolutely no discretion to conduct a preliminary inquiry to check the veracity of the complaint before registering the FIR if a serious crime is clear on its face. This judgment empowers victims and explicitly proves that accepting police refusal is a major “Don’t” in cybercrime reporting.

3. Virtual Presence and Legal Jurisdiction: State of Maharashtra v. Dr. Praful B. Desai

Citation: State of Maharashtra v. Dr. Praful B. Desai, (2003) 4 SCC 601. Relevance: Although primarily dealing with video conferencing in criminal trials, this landmark case established the foundational legal principle that “virtual presence” is entirely equivalent to “physical presence” in the eyes of Indian criminal law. This judgment reinforces the concept that jurisdiction in cyberspace extends far beyond physical boundaries, supporting a victim’s right to file a cybercrime report from their own physical location regardless of where the hacker legally resides.

4. Intermediary Guidelines and Takedowns: Shreya Singhal v. Union of India

Citation: Shreya Singhal v. Union of India, AIR 2015 SC 1523. Relevance: While most famous for striking down the unconstitutional Section 66A of the IT Act to protect free speech, this case also laid down crucial guidelines regarding the duties of internet intermediaries (like Facebook or YouTube). The Court clarified that platforms are only obligated to take down unlawful content upon receiving a valid court order or a notification from an appropriate government agency. Therefore, your “Do” involves obtaining a formal police order to force a platform to remove defamatory content, rather than just endlessly clicking the platform’s internal “report” button.

Practical Examples and Illustrations

To truly master this protocol, let us examine how the Do’s and Don’ts of Cybercrime Reporting apply directly to highly realistic, real-world illustrations that citizens face daily.

Illustration 1: The Remote Access Banking Fraud

The Scenario: Vikram receives a call from someone claiming to be a telecom executive offering a free 5G network upgrade. The caller smoothly convinces Vikram to download a screen-sharing application (like AnyDesk) and make a ₹10 test payment. Suddenly, the scammer takes remote control of Vikram’s phone, reads his incoming OTPs, and instantly transfers ₹3,00,000 from his savings account. Applying the Rules:

  • The Critical Do: Vikram’s immediate action must be to disconnect his phone from the internet to sever the screen-sharing connection. Next, he must instantly dial 1930 to trigger a financial freeze on the stolen ₹3,00,000. Furthermore, he does need to submit a written dispute to his bank branch within the RBI’s 72-hour window.
  • The Fatal Don’t: Vikram must not format his phone in a panic. Doing so would erase the digital footprint of the remote access application, making it impossible for the cyber cell to trace the IP address of the attacker.

Illustration 2: Corporate Ransomware and Data Extortion

The Scenario: A mid-sized healthcare tech company in Bangalore discovers that all their patient servers are completely encrypted. A digital note on the main server demands 5 Bitcoin to release the decryption key. Furthermore, the hackers threaten to leak highly sensitive patient health records on the dark web if the ransom is not paid within 24 hours. Applying the Rules:

  • The Critical Do: The company’s IT team must do the right thing by immediately disconnecting the infected servers from the main network to prevent the lateral movement of the malware. Crucially, they must report this severe breach to CERT-In within 6 hours to comply with Section 70B of the IT Act.
  • The Fatal Don’t: The company must not pay the ransom. Paying the ransom funds criminal syndicates, violates corporate governance rules, and provides zero legal guarantee that the hackers will actually return the decrypted data. Furthermore, they must not try to hide the breach from the government to save their public reputation.

Illustration 3: Cyber Defamation and Image Morphing

The Scenario: Priya, a university student, discovers that heavily morphed, defamatory images of her are being circulated on a newly created, fake Instagram account, causing her immense psychological distress. Applying the Rules:

  • The Critical Do: Priya does execute the evidence preservation steps flawlessly. She copies the exact profile URL (not just the display name), takes time-stamped screenshots, and drafts her Section 63 BSA certificate. She then utilizes the anonymous reporting feature on cybercrime.gov.in specifically designed for crimes against women.
  • The Fatal Don’t: Priya must not confront the fake account directly by sending them angry messages, as that would alert the perpetrator to delete the account and hide their tracks.

Listicles: Vital Summaries for Your Protection

To ensure rapid recall during high-stress situations, meticulously memorize these core components of the Do’s and Don’ts of Cybercrime Reporting:

10 Absolute “Do’s” You Must Execute Immediately

  1. DO sever internet access to the compromised device immediately to stop ongoing data theft.
  2. DO dial 1930 instantly to report financial fraud and initiate a banking fund freeze.
  3. DO permanently block compromised debit cards, credit cards, and UPI IDs via your banking app.
  4. DO change all your critical passwords using an entirely separate, clean, and secure device.
  5. DO enable Two-Factor Authentication (2FA) across all your primary social media and email accounts.
  6. DO extract the exact URL or the full Email Header for precise digital identification of the attacker.
  7. DO take clear, time-stamped screenshots of all fraudulent communications and fake websites.
  8. DO register a formal, chronological complaint online at the national portal (cybercrime.gov.in).
  9. DO submit a formal, written fraud dispute to your home bank branch within 3 working days.
  10. DO strictly draft a Section 63 BSA Certificate to legally authenticate your printed electronic evidence.

10 Absolute “Don’ts” You Must Avoid at All Costs

  1. DON’T wait days to report the crime; cybercriminals launder money incredibly fast.
  2. DON’T delete any original data, including abusive text messages, emails, or malicious apps.
  3. DON’T factory reset or format your device before a police forensic team has fully inspected it.
  4. DON’T attempt vigilantism or “hack back” against the scammer; this violates Section 43 of the IT Act.
  5. DON’T confront the scammer online, as this alerts them to destroy their digital tracks.
  6. DON’T accept a local police station’s refusal to register an FIR based on “territorial jurisdiction.”
  7. DON’T submit raw, printed screenshots to a judge without the mandatory statutory certificate.
  8. DON’T pay extortion demands during a ransomware attack; it never guarantees data recovery.
  9. DON’T hide a corporate data breach to save reputation; CERT-In mandates reporting within 6 hours.
  10. DON’T panic and freeze; follow the structured legal checklist to regain control of the situation.

Tables: Tactical Organization for Cybercrime Rules

For a rapid, visual legal assessment, use this comparison matrix to perfectly align your required actions with the specific type of cybercrime you are handling.

Category of CybercrimeThe Critical “Do” ActionThe Fatal “Don’t” ActionApplicable Legal Provision
Financial / UPI FraudDO dial 1930 and inform your bank within 72 hours.DON’T delete the fraudulent SMS or transaction alert.Section 66D IT Act & RBI Circulars.
Phishing / Email ScamDO extract the full email header to find the IP address.DON’T click on any links or reply to the email.Section 66C & 66D of the IT Act.
Social Media HackingDO secure the exact profile URL and report via the portal.DON’T message the hacker threatening them with police.Section 66 & 43 of the IT Act.
Ransomware AttackDO disconnect infected servers and report to CERT-In (6 hours).DON’T pay the demanded cryptocurrency ransom.Section 43 IT Act & CERT-In Guidelines.
Police Refuse ActionDO draft an escalation letter to the Magistrate.DON’T walk away and accept the refusal silently.Section 173 & 175(3) of the BNSS, 2023.

Key Takeaways

  • Implementing the strict Dos and Donts of Cybercrime Reporting transforms a victim’s panicked, emotional reaction into a highly effective, legally sound strategy.
  • The absolute most critical factor in financial cybercrimes is speed. Utilizing the 1930 helpline and formally notifying the bank within 72 hours dictates whether you recover your stolen funds.
  • Electronic evidence is remarkably fragile and procedurally demanding. Submitting screenshots without a Section 63 BSA certificate is a massive “Don’t” that renders your evidence legally inadmissible in an Indian court.
  • You are not bound by physical borders. The concept of the Zero FIR under the BNSS mandates that law enforcement must record your cyber complaint regardless of where the scammer resides.
  • The law highly empowers you with legal escalation tools. If the police fail in their duty, approaching a Judicial Magistrate under Section 175(3) BNSS is your ultimate, powerful legal remedy.

Conclusion

In conclusion, successfully battling modern digital crime requires significantly more than just basic technical knowledge; it requires absolute procedural discipline. The internet is a fast-moving, inherently volatile landscape, and cybercriminals rely heavily on your confusion and delay to successfully launder money and erase their tracks. However, by strictly adhering to these comprehensive Dos and Donts of Cybercrime Reporting, you effectively neutralize their advantage. You secure your financial perimeter, perfectly preserve the fragile digital evidence in accordance with strict evidentiary laws, and force the legal machinery to act swiftly on your behalf. Technology law in India is robust and heavily favors a highly organized victim. Therefore, internalize these binary rules, maintain your absolute composure during a crisis, assert your statutory rights confidently, and never allow a simple procedural error to give a cybercriminal an avenue for escape.

FAQs

1. What is the absolute most urgent “Do” in the Dos and Don’ts of Cybercrime Reporting? If the crime involves money, the most urgent action is calling the 1930 National Cybercrime Helpline to freeze the fraudulent transaction, followed immediately by blocking your bank accounts. If it is a data breach, the most urgent step is disconnecting the device from the internet without turning it off.

2. I took screenshots of the WhatsApp scam. Is that enough evidence? No. While taking screenshots is a good “Do,” they are considered secondary evidence. To make them legally admissible in court, you must follow the rule of drafting and signing a mandatory statutory certificate under Section 63 of the Bharatiya Sakshya Adhiniyam (BSA).

3. The police station refused my complaint because the hacker is in another state. What do I do? You must not accept this refusal. You must assert your right to a Zero FIR. Under Section 173 of the BNSS, police are legally obligated to register a cognizable cybercrime complaint regardless of territorial jurisdiction. If they still refuse, you can escalate the complaint to the Superintendent of Police.

4. How quickly must I report an unauthorized bank transfer to get my money back? According to strict Reserve Bank of India (RBI) guidelines, you do need to formally report the unauthorized transaction to your bank within three (3) working days. Meeting this exact deadline is a critical action that often ensures zero financial liability for the victim.

5. Can I file a cybercrime report without physically going to a police station? Yes, you absolutely can. You can initiate the entire legal process online through the National Cyber Crime Reporting Portal (cybercrime.gov.in). The portal securely generates an acknowledgment number and routes the complaint to your local nodal officer for investigation.

6. Do companies have a different set of Dos and Donts than private individuals? Yes. Corporate entities have much stricter statutory duties. Under Section 70B of the IT Act, companies and data centers must execute their incident response rapidly, as they are legally mandated to report severe cyber breaches to CERT-In within 6 hours. Hiding a breach is a major corporate “Don’t.”

7. I accidentally clicked a phishing link, but I don’t think any money was stolen. Should I still act? Yes. You should do a thorough check. Disconnect the device, change your passwords from a completely different machine, and run a thorough antivirus scan. You should also report the malicious URL to the cybercrime portal to help authorities take down the phishing server.

8. What should I do if a hacker is demanding money to unlock my computer? You must not pay the ransom. Paying funds criminal syndicates and provides zero legal guarantee that they will return your data. You do need to disconnect the network, preserve the digital ransom note, and report the extortion to the authorities immediately.

9. Can I hire a private hacker to aggressively trace the person who scammed me? Absolutely not. “Hacking back” or engaging in active defense is strictly illegal in India under Section 43 of the Information Technology Act. Doing so will immediately transition your legal status from a victim into a criminal suspect.

10. What if the police completely ignore my online cybercrime complaint for months? If your online complaint remains pending without an FIR registration, you must escalate it. A critical “Do” in your legal strategy is to hire an advocate to file a formal application before a Judicial Magistrate under Section 175(3) of the BNSS, who can then legally order the police to investigate.

Legal References

  1. The Information Technology Act, 2000 (India Code Repository).
  2. The Bharatiya Sakshya Adhiniyam, 2023 (Official e-Gazette of India).
  3. The Bharatiya Nagarik Suraksha Sanhita, 2023 (Ministry of Home Affairs).
  4. The Bharatiya Nyaya Sanhita, 2023.
  5. Reserve Bank of India (RBI) Master Circular on Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions.
  6. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1 (Supreme Court Landmark Judgment on Electronic Evidence Certification).
  7. Lalita Kumari v. Govt. of U.P., (2014) 2 SCC 1 (Supreme Court Constitution Bench Judgment on Mandatory FIR Registration).
  8. State of Maharashtra v. Dr. Praful B. Desai, (2003) 4 SCC 601 (Supreme Court Judgment on Virtual Presence and Jurisdiction).
  9. Shreya Singhal v. Union of India, AIR 2015 SC 1523 (Supreme Court Judgment on Intermediary Liability and Free Speech).
  10. National Cyber Crime Reporting Portal (cybercrime.gov.in).
  11. Ministry of Electronics and Information Technology (MeitY) Official Notifications regarding Cyber Security.
  12. Supreme Court of India Official Judgments Portal.
  13. Indian Computer Emergency Response Team (CERT-In) Guidelines and Directives under Section 70B.
  14. High Court of Delhi Rules on Electronic Evidence Presentation and Preservation.
  15. SCC Online Legal Database (For comprehensive case law research).
  16. Indian Kanoon (Open Access Legal Database for preliminary research).
  17. Please note: Case citations must be carefully verified against current SCC/AIR volumes before any formal court submission.

At The Law School Hub, we simplify case laws, legal acts, and legal concepts for law students and legal readers. Want to read more useful legal blogs? Visit The Law School Hub.

Tags:

1930 helplineBNSS 2023CERT-In Rules.Cyber Fraud PreventionCyber Jurisdiction Indiacyber law IndiaCyber Security Notesdigital evidenceDos and Donts of Cybercrime ReportingFinancial CybercrimeIT Act 2000law student guideLegal AwarenessNational Cyber Crime Portalphishing scamsRBI Fraud Guidelinesreporting online harassmentSection 63 BSAThe Law School HubZero FIR
Author

Yash Yogitta Joshi

Hi, I am Yash Yogitta Joshi, the creator and author behind The Law School Hub, a legal education platform created to make Indian law simple, clear, and accessible for everyone.My interest in law began with a curiosity to understand how rights, justice, and legal systems work in everyday life. Over time, I realised that many students, aspirants, and citizens find legal concepts difficult because they are often explained in complex language. This inspired me to build The Law School Hub as a beginner-friendly space for learning law in a practical and easy-to-understand way.My goal is to create content that is accurate, useful, and easy to follow. I believe that legal education should not be limited to textbooks or courtrooms. Everyone should have access to basic legal knowledge so they can understand their rights, duties, and responsibilities.

Follow Me
Other Articles
Cybercrime reporting checklist cover image showing reporting checklist clipboard, cybercrime report form, digital evidence file, National Cyber Crime Reporting Portal, Information Technology Act 2000, and cyber police icons.
Previous

The Ultimate Checklist for Handling Cybercrime Reporting to Quickly Stop Devastating Online Scammers

Cybercrime reporting FAQ cover image showing FAQ board, cyber help support card, National Cyber Crime Reporting Portal, complaint tracking phone, Information Technology Act 2000, and legal symbols.
Next

Master the Most Urgent Frequently Asked Questions on Cybercrime Reporting to Safely Stop Devastating Scams

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    Recent Posts

    • The Definitive Guide to Intellectual Property Rights: Why Every Common Person Must Deeply Care
    • Suhas Katti Case: How India Got Its First Cybercrime Conviction to Protect Women Online
    • Cadila Healthcare Case: Why Trademark Rules for Medicines Are Stricter in India
    • Supreme Court Takes Crucial Step: Extends Consultation Deadline on Draft AI Rules for Courts
    • Frustrated by Repeated Document Demands in Aadhaar Card Correction? 7 Powerful Legal Steps to Instantly Stop Government Harassment

    Recent Comments

    No comments to show.

    Archives

    • July 2026
    • June 2026

    Categories

    • Administrative Law
    • All Blog Categories
    • Banking and Finance Law
    • Case Summaries
    • Constitutional Law
    • Constitutional Law Case Summaries
    • Corporate and Commercial Law
    • Corporate and Commercial Law Case Summaries
    • Criminal Law
    • Family Law
    • Intellectual Property Law
    • Intellectual Property Law Case Summaries
    • Legal News Analysis
    • Technology and Cyber Law
    • Technology and Cyber Law Case Summaries
    Gold scales of justice enclosed within a laurel wreath beside the text “The Law School Hub” and the tagline “Learn Law. Understand Justice.” on a professional grey background.

    Page Lists
    • About Us
    • Contact Us
    • Contributor's Page
    • Home page | The Law School Hub
    • Join Our Community
    • Learn Law Through Our Blogs
    • Privacy Policy
    • Terms of Service
    Latest Posts
    • The Definitive Guide to Intellectual Property Rights: Why Every Common Person Must Deeply Care
    • Suhas Katti Case: How India Got Its First Cybercrime Conviction to Protect Women Online
    • Cadila Healthcare Case: Why Trademark Rules for Medicines Are Stricter in India
    • Supreme Court Takes Crucial Step: Extends Consultation Deadline on Draft AI Rules for Courts
    • Frustrated by Repeated Document Demands in Aadhaar Card Correction? 7 Powerful Legal Steps to Instantly Stop Government Harassment
    All Blog Categories
    • Administrative Law
    • All Blog Categories
    • Banking and Finance Law
    • Case Summaries
    • Constitutional Law
    • Constitutional Law Case Summaries
    • Corporate and Commercial Law
    • Corporate and Commercial Law Case Summaries
    • Criminal Law
    • Family Law
    • Intellectual Property Law
    • Intellectual Property Law Case Summaries
    • Legal News Analysis
    • Technology and Cyber Law
    • Technology and Cyber Law Case Summaries

    Let's Connect on Social Media

    • Instagram
    • LinkedIn
    • Facebook
    • Telegram
    • X
    • WhatsApp

    © 2026 The Law School Hub. All Rights Reserved.

    The content on this website is created for legal education, awareness, and academic purposes only. It does not constitute legal advice.