September 26, 2026
What to Do After Cyber Fraud in India
What to Do in the First 60 Minutes After a Cyber Fraud ?
By Drivesyncinfotechpvtltd
5 min read
The first hour decides whether your money comes back or vanishes forever. A DriveSync Infotech guide for anyone who uses UPI, net banking, or a debit card. The story usually starts the same way. A message pops up. A link is clicked. An OTP is shared, or an app is installed. And within seconds, money starts leaving the account. Rs. 40,000 gone. Then Rs. 2,00,000. Then the balance reads zero. Most people freeze. They panic, call a family member, and stare at the screen wondering if the money is gone for good. Here is the part almost nobody knows. The first 60 minutes after a cyber fraud matter more than everything that happens later. In cybercrime, this window even has a name. Investigators call it the Golden Hour. What you do inside this hour often decides whether the money is frozen and returned, or whether it disappears through a chain of accounts you will never see again
Why the First Hour Decides Everything ?
Cybercriminals are fast. They know that the moment a victim realises what happened, the clock starts. So they do not sit on the money. They move it. Quickly. Stolen funds are pushed through what are called mule accounts, one after another, sometimes five or ten accounts within a few minutes. From there the money is pulled out as cash, turned into gift cards, or converted into cryptocurrency. Once the money leaves that first receiving account, tracing it becomes far harder. But while it is still sitting in that first account, it can be frozen. That is the whole game. Speed against speed. This is why acting in the first hour beats almost every fancy tool used later in an investigation.
Step 1 : Stop the Bleeding (First 5 to 10 Minutes)
Before you do anything else, cut off access. If your phone, card, or account has been compromised, the attacker may still have a way in. Close every door you can.
- Block your debit and credit cards.
- Freeze or lock UPI and net banking through your bank app or by calling customer care.
- If a fraud app was installed, put the phone in airplane mode and remove the app.
- If you shared banking login details, change the passwords from a different, trusted device.
Use a second phone or a family member's phone if you suspect your own device is infected.
The goal here is simple. Stop any further transfers from going out before you even start reporting.
Step 2 : Save the Evidence Before You Delete Anything
When people panic, they often delete the fraud message or the suspicious app out of fear. Do not do this. Everything on your screen right now is evidence. The bank, the cyber police, and the courts may need it
Take screenshots and note down:
- The transaction ID or UTR number
- The amount and exact time of each transfer
- The UPI ID, phone number, or bank account the money went to
- SMS alerts from your bank
- Any chats, emails, or call records with the fraudster
A single transaction ID can become the first thread that investigators pull to unravel an entire network. So save it before you touch anything.
Step 3 : Call 1930 and File on the NCRP
This is the most important step, and the one most people delay. India has a dedicated cyber fraud helpline. The number is 1930. Call it as soon as you have your basic details ready. This is the fastest way to get the wheels turning, because the helpline can start the process of alerting banks to hold the money. Right after the call, or at the same time, file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in.
When you file, include:
- The exact transaction time
- The transaction ID or UTR number
- The amount lost
- Your bank and the receiving bank or app
- The fraudster's number, UPI ID, or account details if you have them
You will get a complaint reference number. Keep it safe. You will need it for every follow up after this.
Step 4 : What Happens the Moment You Report ?
Many victims think reporting is just paperwork. It is not.
The moment your complaint is registered, it enters a system built to move fast. Behind the scenes, the portal connects with the Citizen Financial Cyber Fraud Reporting and Management System, or CFCFRMS.
This system can send alerts straight to the banks involved. The alert carries your details, the transaction information, the amount, and the beneficiary account.
The aim is one thing only. Freeze the money before the fraudster can pull it out. If you reported fast enough, and the money is still sitting in that first account, the bank can put it on hold.
This is exactly how victims in some cases have recovered lakhs and even crores that everyone assumed were already gone. The faster you report, the more of the trail is still frozen in place.
Step 5 : Inform Your Bank in Writing
A phone call is not enough.Visit your branch or use the official complaint channel and submit:
- A copy of your cybercrime complaint acknowledgement
- The full transaction details
- A written request to investigate and reverse the transaction
There is a strong reason to do this quickly.
Under Reserve Bank of India rules on unauthorized electronic transactions, if you report a fraud to your bank promptly, your liability can be reduced to zero or kept very limited. Delay it, and you may be held responsible for a larger share of the loss.
In short, reporting fast does not only help recover the money. It also protects you legally.
Step 6 : If the Bank Does Not Help, Escalate
Sometimes the bank is slow, or the response is not satisfactory.
Do not stop there.
If your complaint is not resolved within the time the bank is supposed to take, you can escalate through the RBI Complaint Management System at cms.rbi.org.in.
This is a free grievance channel, and it puts formal pressure on the bank to act. Keep every reference number, email, and acknowledgement from the start, because a clean paper trail makes escalation much stronger.
The Mistakes That Cost People Their Money
Most lost cases are not lost because of clever criminals.
They are lost because of simple, human mistakes in the first hour.
- Waiting till morning : People often decide to report the next day. By then the money is gone through ten accounts.
- Deleting the evidence : Removing the app or message in panic destroys the trail.
- Feeling ashamed : Many victims stay silent because they feel embarrassed. Silence is exactly what the fraudster is counting on.
- Only calling the bank : The bank alone cannot trigger the national freezing system. You need 1930 and the NCRP.
Every one of these mistakes costs time. And in the Golden Hour, time is money in the most literal sense.
A Simple Golden Hour Checklist
Save this. Share it with your parents and anyone who is not comfortable with technology, because they are the most common targets.
- Block cards, UPI, and net banking.
- Screenshot every transaction,message, and alert.
- Call 1930 immediately.
- File a complaint on cybercrime.gov.in and note the reference number.
- Submit a written complaint to your bank with the acknowledgement.
- Escalate to the RBI CMS if the bank does not act.
The Bottom Line_ : Cyber fraud is scary because it feels final._
One tap, and the money is gone.
But it is far less final than most people believe. Every fraud leaves a trail, and for a short while that trail is still frozen in place, waiting to be followed.
The difference between getting your money back and losing it forever often comes down to a single decision made in the first hour.
So if it ever happens to you, or to someone you love, remember the one rule that matters most.
Do not wait. Report it immediately. Because in cyber fraud, the Golden Hour is not a figure of speech. It is the difference between recovery and regret.
Written by_ Drivesync Infotech Private Limited. If this helped, share it with someone who needs to read it before they ever need it._