Cyber fraud in India no longer looks like a lone hacker breaking into a server. Most of it today is social engineering — a fraudster convincing a victim to hand over an OTP, install an app, click a link, or wire money to a “trustworthy” stranger. The National Cyber Crime Reporting Portal received over 22.6 lakh complaints in 2024 alone, with reported losses crossing ₹22,845 crore. This guide covers the broader landscape of cyber fraud in India — phishing and identity theft, job and investment scams, sextortion, SIM-swap fraud, and social-media impersonation — the statutory framework under the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023, and exactly how to report it. For fraud specific to UPI and digital payment transactions — fake customer-care calls, malicious QR codes, and bank liability rules — see our dedicated guide on UPI and Digital Payment Fraud in India, which this article does not repeat.
- Legal Purpose and Background
- Common Types of Cyber Fraud Beyond Digital Payments
- Key Statutory Provisions: IT Act and BNS
- Reporting a Cyber Crime — Step by Step
- Jurisdiction and the Zero FIR Route
- What Happens After You Report
- Important Judgments
- Practical Implications and Common Mistakes
- Preventive Practices That Also Strengthen a Legal Claim
- Frequently Asked Questions
- Conclusion
The shift from opportunistic hacking to organised, socially-engineered fraud has been driven by a simple economic reality: it is far cheaper and lower-risk for a criminal enterprise to persuade a hundred people to voluntarily transfer money than it is to breach a bank’s systems directly. Call centres running scripted scam operations, often staffed by trafficked or coerced workers, now account for a significant share of reported cyber fraud — a pattern Indian investigators increasingly describe using the language of organised crime rather than individual hacking. Understanding this shift matters for victims and for anyone drafting a complaint, because it changes what evidence is useful: the exact script used, the platform the fraudster operated on, and any identifying detail about the account or number used to contact you are often more valuable to investigators than technical detail about how a payment was processed.
Legal Purpose and Background
Cyber fraud in India is prosecuted under a dual framework. The Information Technology Act, 2000 supplies the “electronic means” element — provisions like identity theft (Section 66C) and cheating by personation using a computer resource (Section 66D) were written specifically for offences committed through a computer, network, or communication device. The Bharatiya Nyaya Sanhita, 2023, which replaced the Indian Penal Code from 1 July 2024, supplies the general offence — cheating (Section 318), cheating by personation (Section 319), and forgery (Section 336) apply whether the deception happened online or off. In practice, a cyber fraud FIR is almost always registered under both statutes together: the BNS section supplies the “cheating” or “forgery” charge, and the IT Act section supplies the “using a computer resource” aggravation.
A newer addition matters for organised cyber fraud specifically. Section 111 of the BNS, which defines “organised crime,” explicitly lists “cyber-crimes” among the categories of “continuing unlawful activity” that can trigger the section — alongside extortion, economic offences, and trafficking. This is a direct legislative response to the scale of India’s scam-call-centre operations, which increasingly resemble organised syndicates rather than lone fraudsters. Where investigators can show a pattern of cyber fraud committed by an organised group, Section 111 allows a materially harsher charge than a standalone cheating case under Section 318.
It’s worth noting what got removed. Section 66A of the IT Act — which criminalised sending “offensive” messages online — was struck down as unconstitutional in 2015. That repeal is sometimes wrongly cited as evidence that India’s cyber-fraud law generally weakened. It didn’t: 66A was about offensive speech, not fraud, and the identity-theft and cheating-by-personation provisions that actually govern fraud cases were untouched.
Common Types of Cyber Fraud Beyond Digital Payments
Recognising the mechanism matters because it usually determines which provision applies and which agency is the right first point of contact.
Phishing, smishing, and vishing. A fraudster sends a fake email (phishing), SMS (smishing), or places a call (vishing) impersonating a bank, employer, courier company, or government department, aiming to extract personal data, login credentials, or a one-time payment “to release a stuck parcel” or “clear a pending fine.” This is the broad category that Section 66D IT Act (cheating by personation using a computer resource) and Section 319 BNS (cheating by personation) are built for.
Identity theft and account takeover. A fraudster obtains enough personal information — often from a data breach, a phishing attempt, or social media oversharing — to impersonate the victim: opening a credit line, taking over a social media or email account, or filing fraudulent claims in the victim’s name. Section 66C of the IT Act criminalises the fraudulent or dishonest use of another person’s electronic signature, password, or any other unique identification feature.
SIM-swap fraud. A fraudster convinces (or bribes) a telecom outlet into issuing a duplicate SIM card for the victim’s number, using forged or socially-engineered documentation. Once the duplicate SIM is active, the victim’s original SIM stops working and the fraudster starts receiving OTPs and bank alerts meant for the victim. Recent Karnataka High Court litigation has held telecom providers vicariously liable for negligent duplicate-SIM issuance that enabled such fraud (see Important Judgments below).
Online job, investment, and trading scams. Fake job offers demanding an upfront “registration fee,” fraudulent stock-tip or crypto “trading academies” promising guaranteed returns, and Ponzi-style investment apps are consistently among the highest-value categories of cyber fraud reported to the NCRP portal. These are charged principally under Section 318 BNS (cheating and dishonestly inducing delivery of property), often alongside IT Act provisions if the scam was run through a fake website, app, or messaging platform.
Sextortion and blackmail. A fraudster, often posing as a romantic interest, records or fabricates an intimate video call and then threatens to circulate it unless paid. Delhi High Court has described sextortion as “a profound violation of privacy” warranting custodial investigation rather than anticipatory bail (see Important Judgments). This typically attracts Section 66E IT Act (violation of privacy) and Section 67 IT Act (publishing obscene material), alongside extortion provisions under the BNS.
Matrimonial and romance scams. Fake profiles on matrimonial or dating platforms are used to build trust over weeks or months before requesting money for a fabricated emergency, customs duty on a “gift,” or a joint investment. These squarely engage Section 66D IT Act and Section 319 BNS.
Social media and account impersonation. Creating a fake profile using a real person’s photographs to harass, defame, or extract money from their contacts. Where the impersonation includes morphed or obscene images, Sections 66C, 66D, 66E, and 67 of the IT Act can all apply together, alongside BNS provisions on criminal intimidation and stalking where relevant.
Business email compromise and ransomware. Corporate-targeted fraud — a spoofed vendor or CEO email diverting a payment, or ransomware locking a company’s systems until a ransom is paid — is a growing category, though (as flagged in our research for this article) reported Indian court judgments squarely on ransomware or business email compromise remain scarce; these matters are more often handled through CERT-In coordination and civil recovery than through reported criminal appeals. A typical business email compromise begins with a compromised or closely spoofed vendor email address requesting a change of bank account for an upcoming payment; because the request often arrives mid-negotiation on a genuine invoice, finance teams frequently act on it without a verification call. Ransomware, by contrast, usually reaches a company through a phishing attachment or an unpatched remote-access vulnerability, and Indian companies are increasingly required to report significant incidents to CERT-In within six hours under the 2022 CERT-In directions — a compliance obligation distinct from, and in addition to, any criminal complaint.
Loan-app and recovery-agent harassment. Fraudulent instant-loan apps, often operating outside RBI’s regulatory perimeter, extract excessive processing fees, charge usurious interest, and — when a borrower falls behind — use the broad permissions granted at installation to access the borrower’s contact list and photos for coercive “recovery” tactics, including morphed images sent to the borrower’s contacts. This pattern typically engages Section 66E and Section 67 of the IT Act (privacy violation and obscene material) alongside extortion and criminal intimidation provisions under the BNS, and — where the app itself is unlicensed — potential action under the RBI’s digital lending guidelines.
Fake e-commerce and classifieds fraud. Fraudulent listings on classifieds and marketplace platforms, or entirely fake e-commerce storefronts, collect advance payment for goods that are never delivered, or deliver counterfeit or empty packages. Because the transaction often looks like an ordinary consumer dispute at first, victims sometimes delay reporting it as fraud — but where the seller’s identity, address, or product claims were deliberately falsified, this is Section 318 BNS cheating, not merely a failed transaction, and should be reported as such.
These categories overlap in practice more often than they stay neatly separated — a single fraud operation might begin as a fake job offer, escalate into a demand for a “security deposit” transferred by UPI, and end with the fraudster threatening to leak personal photos shared during onboarding “verification.” Investigators and victims alike should resist trying to force a single incident into exactly one category; report the full sequence of events, and let the investigating officer determine the applicable charges.
Key Statutory Provisions: IT Act and BNS
The table below summarises the provisions most commonly invoked in cyber fraud cases. It is not exhaustive, and the specific charges in any FIR depend on the facts.
| Provision | What It Covers | Punishment (max) |
|---|---|---|
| Section 43, IT Act | Civil wrong — unauthorised access, data theft, introducing viruses, damaging a system | Compensation to the affected person (civil, not criminal) |
| Section 66, IT Act | Fraudulent or dishonest acts under Section 43 — the general hacking/cyber fraud offence | 3 years and/or fine up to ₹5 lakh |
| Section 66C, IT Act | Identity theft — fraudulent use of another’s password, signature, or unique ID | 3 years and fine up to ₹1 lakh |
| Section 66D, IT Act | Cheating by personation using a computer resource | 3 years and fine up to ₹1 lakh |
| Section 66E, IT Act | Violation of privacy — capturing or publishing private images without consent | 3 years and/or fine up to ₹2 lakh |
| Section 67, IT Act | Publishing or transmitting obscene material electronically | 3 years and fine up to ₹5 lakh (first conviction) |
| Section 318, BNS | Cheating and dishonestly inducing delivery of property | Varies by sub-section, up to 7 years |
| Section 319, BNS | Cheating by personation | Up to 3 years, or up to 5 years for specified aggravated forms |
| Section 336, BNS | Forgery, including forgery for the purpose of cheating | Up to 7 years depending on sub-section |
| Section 111, BNS | Organised crime, expressly including cyber-crimes as a category of continuing unlawful activity | Up to life imprisonment or death for the most severe offences under the section |
Two provisions govern where a cyber fraud case can be pursued. Section 75 of the IT Act gives Indian courts extraterritorial jurisdiction over an offence involving a computer or network located in India, even where the accused or the server is physically outside the country — relevant because a large share of job scams, investment scams, and sextortion operations run from abroad. Section 79 of the IT Act separately provides a conditional “safe harbour” for intermediaries — platforms hosting third-party content — exempting them from liability provided they meet due-diligence and takedown obligations; this is the provision at the centre of several of the judgments discussed below.
Reporting a Cyber Crime — Step by Step
Step 1 — Preserve evidence immediately. Screenshot the fraudulent messages, emails, profiles, transaction confirmations, and call logs before the fraudster can delete or block you. Note exact timestamps, phone numbers, UPI IDs, account numbers, and website URLs involved.
Step 2 — Call 1930 if money is involved. Where the fraud involved a financial transaction, call the national cyber fraud helpline 1930 immediately. It feeds into the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), which can flag banks and payment intermediaries to freeze or hold funds before withdrawal. There is no fixed statutory “golden hour,” but every hour of delay reduces the chance of recovery — report as soon as the fraud is discovered.
Step 3 — File on the National Cyber Crime Reporting Portal. Go to cybercrime.gov.in, register with a mobile number and email, and choose the correct category — financial fraud, crime against women and children (which also permits anonymous reporting), or other cyber crimes. The portal explicitly asks for accurate, complete details for prompt action; incomplete complaints slow down every subsequent step.
Step 4 — Follow up with a formal FIR where needed. For non-financial cyber crimes, or where the portal complaint needs to be converted into a formal police FIR, approach the local police station or a dedicated cyber crime cell. Under Section 173(1) BNSS, you may file at any police station regardless of territorial jurisdiction — the Zero FIR mechanism discussed below.
Step 5 — Notify your bank or platform in parallel. If a bank account, wallet, or card was compromised, report it to the issuing bank or platform directly and in writing, in addition to the police/portal complaint — this triggers the bank’s own fraud-liability process and creates a paper trail independent of the criminal investigation.
Jurisdiction and the Zero FIR Route
Cyber fraud rarely respects state boundaries — a victim in Mumbai may be defrauded by a syndicate operating from another state or another country entirely. Indian procedure accounts for this in two ways. First, Section 173(1) of the BNSS lets a victim register an FIR — including a cyber fraud FIR — at any police station, “irrespective of the area where the offence is committed.” That FIR is registered as a Zero FIR and then transferred to the police station with actual territorial jurisdiction, which re-registers it as a regular, numbered FIR. Refusing to accept a Zero FIR on jurisdictional grounds is not permitted.
Second, a newer mechanism specifically for cyber-financial fraud — the e-Zero FIR — auto-converts certain complaints registered on the 1930/cybercrime.gov.in system into a Zero FIR without the complainant needing to separately visit a police station. As of a Supreme Court hearing in August 2026, the government reported this mechanism operational in 19 states, with dedicated Cyber Crime Coordination Centres notified in 14 states — figures worth checking for your specific state before relying on the online-only route, since coverage is still expanding and not yet universal.
What Happens After You Report
Filing a complaint is the start of a process, not the end of one, and knowing what to expect helps set realistic expectations. Once a complaint is registered on the National Cyber Crime Reporting Portal or converted to a Zero FIR, it is typically assigned to a cyber crime cell or the investigating station’s designated officer. For financial fraud reported promptly through 1930, the CFCFRMS system can trigger a hold request to the banks or wallets that received the funds within hours — this hold is provisional, not a final recovery, and the victim’s money remains subject to the bank’s own dispute-resolution process and, ultimately, any court order distributing frozen funds among multiple claimants where several victims’ money passed through the same mule account.
Where the fraud involved a regulated bank or NBFC and the response is unsatisfactory, victims retain a separate escalation route through the Reserve Bank of India’s Banking Ombudsman scheme (now consolidated under the RBI Integrated Ombudsman Scheme, 2021), which can be pursued independently of, and in parallel with, the criminal complaint. This matters because criminal investigations can take months or years to conclude, while an ombudsman complaint about a bank’s specific handling of a fraud-liability claim can often be resolved faster and does not require proving criminal guilt — only that the bank’s own zero-liability or limited-liability framework was not correctly applied.
Investigators working a cyber fraud case typically proceed by tracing the money trail — the receiving account, the accounts it was subsequently split across (frequently called “mule accounts,” often opened using someone else’s identity documents for a fee), and eventually a withdrawal point, whether an ATM, a cash-out agent, or a cryptocurrency exchange. This is why acting fast matters disproportionately in cyber fraud compared to many other offences: money that has already been withdrawn or converted to cryptocurrency is exponentially harder to recover than money still sitting in the first receiving account.
Important Judgments
| Case | Core Issue | Holding | Practical Significance |
|---|---|---|---|
| NASSCOM v. Ajay Sood & Ors., 119 (2005) DLT 596 | Phishing recognised as actionable fraud | Delhi High Court granted injunction and damages against operators sending fake recruitment emails to harvest personal data, even absent a bespoke statute at the time | India’s first judicial recognition of phishing as a distinct wrong |
| Sharat Babu Digumarti v. Govt. of NCT of Delhi, (2017) 2 SCC 18 | IT Act vs IPC overlap; intermediary liability | Where conduct is squarely covered by the IT Act as a special law, IPC provisions for the same conduct cannot be separately invoked; clarified intermediary safe-harbour under Section 79 | Governs how prosecutors must choose between overlapping IT Act and BNS charges |
| Shreya Singhal v. Union of India, (2015) 5 SCC 1 | Constitutionality of Section 66A | Struck down Section 66A as unconstitutionally vague; left identity-theft and fraud provisions (66C, 66D) fully intact | Frequently misunderstood as weakening cyber-fraud law generally — it did not |
| Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473 | Admissibility of electronic evidence | A Section 65B Evidence Act certificate is mandatory for admitting electronic records such as emails, call logs, and transaction data | Governs how cyber fraud evidence must be proved at trial |
| Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1 | Clarifying Section 65B certification | Reaffirmed Anvar P.V. as controlling law and clarified when a certificate can be obtained or dispensed with | The current controlling precedent on electronic evidence in cyber fraud trials |
| Syed Asifuddin v. State of Andhra Pradesh, 2005 CriLJ 4314 | Whether a mobile handset is a “computer” | Tampering with a handset’s ESN/source code to defeat network locking attracted Sections 65 and 66 IT Act; rejected the “not a computer” defence | Established the broad scope of what counts as a computer resource |
| Kalandi Charan Lenka v. State of Odisha, 2017 SCC OnLine Ori 52 | Fake profile with morphed images | Creating a fake profile with morphed obscene images and circulating it attracted Sections 66C, 66D, 66E, and 67 IT Act; bail refused | A leading authority on impersonation-based harassment |
| Basaveshwara Pattana Sahakara Bank v. Canara Bank & Ors., 2026 LiveLaw (Kar) 198 | Telecom liability for SIM-swap fraud | Karnataka High Court held a telecom provider vicariously liable for its employee’s negligent issuance of a duplicate SIM enabling a SIM-swap fraud; enhanced compensation to ~₹50.5 lakh with interest | Recent authority extending liability beyond the bank to the telecom provider |
| PNP Polytex Pvt. Ltd. v. RBI & Bank of Baroda, Bombay HC, 28 Apr 2026 | RBI zero-liability circular in SIM-swap fraud | Held the RBI’s zero-liability protection applies where a SIM-swap-enabled unauthorised transfer was promptly reported and the customer was not negligent; ordered refund of ₹1.24 crore with interest | Reinforces prompt reporting as central to recovering funds |
| Nirmaljit Singh Narula v. Indijobs at Hubpages.com, CS(OS) 871/2012 | Disclosure duties of hosting intermediaries | Directed a hosting platform to disclose, in a sealed cover, the identity and login data of an anonymous user behind an impersonating profile | An early authority on unmasking anonymous online impersonators |
| Soukin v. State (NCT of Delhi), 2024 SCC OnLine Del 2986 | Sextortion and anticipatory bail | Denied anticipatory bail, holding sextortion “a profound violation of privacy” and “a significant social menace” warranting custodial investigation | Signals courts’ current seriousness toward sextortion cases |
| Avnish Bajaj v. State (NCT of Delhi), 116 (2005) DLT 427 | Individual director liability vs platform liability | Distinguished a platform’s liability from an individual director’s personal liability for third-party content listed on it | Early marker in what became today’s intermediary safe-harbour litigation |
The 2026 SIM-swap rulings above are recent and, as with any recent judgment, may still be subject to appeal — they are cited here as evidence of a clear and current judicial trend toward extending liability to telecom providers and reinforcing bank zero-liability protections, not as settled, final law.
Practical Implications and Common Mistakes
Most cyber fraud complaints fail not because the law is inadequate but because the complaint itself is thin — vague on dates, missing transaction references, or filed weeks after the fact once memory of exact details has faded. Treat the first hour after discovering fraud as an evidence-gathering window, not just a reporting window: write down everything you remember, in order, before making any calls, so that the formal complaint reflects a complete and accurate account rather than a rushed summary.
A recurring pattern in cyber fraud investigations is the gap between what a victim assumes the law requires and what it actually requires. Many victims believe they must have a suspect’s real name or exact location before police can register an FIR — they don’t; the offence is registrable on the strength of the fraudulent conduct itself, and identifying the accused is part of the investigation, not a precondition for it. Others believe that because a scam was run through a foreign number or a foreign-hosted website, Indian police have no jurisdiction — as covered above, Section 75 of the IT Act specifically addresses this, and most large-scale scam operations are investigated as much through international coordination (via INTERPOL notices and mutual legal assistance requests) as through domestic policing alone.
The single most common mistake is delay. Whether the loss is financial or reputational, every hour spent deciding whether to report reduces the odds of a usable remedy — banks can freeze funds only if alerted quickly, and platforms are far more responsive to takedown requests filed within days of the harm than weeks later.
The second common mistake is under-documenting. A screenshot without a timestamp, a call log without the number, or a vague description of “some fraud happened online” makes it harder for police to register a specific, chargeable offence — and harder for a bank or platform to act. Capture the exact UPI ID, account number, phone number, URL, or username involved, and preserve the original message rather than only a paraphrase.
The third is assuming a Zero FIR or online complaint is the end of the process. Both are a starting point — the complaint or Zero FIR still needs to be followed through with the investigating station, and complainants who file and then disengage often find their case loses momentum. Following up in writing, and keeping copies of every acknowledgment number, materially improves outcomes.
Finally, victims sometimes hesitate to report sextortion or matrimonial-scam fraud out of embarrassment. Courts have been explicit — as in Soukin above — that these are treated as serious offences, not private matters to be resolved informally with the perpetrator. Informal negotiation with a blackmailer routinely leads to repeated demands, not resolution.
Preventive Practices That Also Strengthen a Legal Claim
Preventive habits are not just about avoiding fraud — they also produce the evidence that makes a later legal claim stronger. Enable two-factor authentication wherever available, since it independently corroborates that an account was not simply carelessly secured. Avoid searching for customer-care numbers on open search engines; use only the number printed on an official card, statement, or app, since fraudulent listings are a leading vector for phishing calls. Never share an OTP, and treat any request to do so — regardless of who is asking — as conclusive evidence of fraud, not a legitimate verification step. Keep a habit of periodically checking your telecom account for any unauthorised duplicate-SIM request, since SIM-swap fraud typically begins with a period of “no signal” that many victims initially dismiss as a network issue. And retain transaction alerts, emails, and app notifications rather than deleting them promptly — they are frequently the only evidence available once a dispute reaches a bank’s grievance process or a court.
For businesses, the equivalent discipline is a written verification protocol for any request to change vendor payment details, regardless of how urgent or how senior the requester appears to be — a short call to a known, previously-verified number before releasing payment defeats the overwhelming majority of business email compromise attempts. For anyone using instant-loan apps, checking whether the app or its NBFC partner is listed on the RBI’s registered-entity database before installing it, and refusing to grant contact-list or photo-gallery permissions unless strictly necessary for the app’s stated function, closes off the exact leverage that loan-recovery harassment depends on.
A note on scope. This article deliberately does not repeat the mechanics of UPI or digital-payment-specific fraud — fake customer-care calls, malicious QR codes, “collect” request scams, and bank/RBI liability rules for payment transactions are covered in full in our dedicated guide, linked at the top of this article.
Frequently Asked Questions
What is the first thing I should do after discovering I’ve been a victim of cyber fraud?
Preserve evidence immediately — screenshots, transaction IDs, phone numbers, and timestamps — then call the 1930 helpline if money was involved, and file a complaint on cybercrime.gov.in. Speed matters more than any other single factor in whether funds can be recovered.
Can I file a cyber crime complaint anonymously?
The National Cyber Crime Reporting Portal permits anonymous reporting specifically for the “crime against women and children” category. Financial fraud and other cyber crime categories require the complainant’s identity for the complaint to be actioned.
Do I need to file the FIR at the police station nearest to where the fraud happened?
No. Under Section 173(1) of the BNSS, you can file at any police station, and it will be registered as a Zero FIR and transferred to the station with actual jurisdiction. A station cannot refuse to register your complaint purely on jurisdictional grounds.
What is the difference between the IT Act and BNS charges in a cyber fraud FIR?
The IT Act supplies provisions specific to offences committed through a computer or network — identity theft (Section 66C), cheating by personation online (Section 66D). The BNS supplies the general cheating, personation, and forgery offences (Sections 318, 319, 336) that apply regardless of medium. Cyber fraud FIRs typically cite both together.
Is it too late to report if the fraud happened weeks or months ago?
No — you can still file a complaint, though the odds of freezing or recovering funds fall sharply the longer the delay, since money moves through multiple accounts quickly. A delayed report can still support prosecution, evidence preservation, and civil recovery even where fund recovery is unlikely.
Can a fraud committed by someone outside India still be prosecuted here?
Yes. Section 75 of the IT Act gives Indian courts extraterritorial jurisdiction over an offence involving a computer or network located in India, even where the accused or server is abroad — relevant since many scam operations are run from outside the victim’s state or country.
What should I do if a fraudster is blackmailing me over an intimate photo or video?
Do not pay, and do not negotiate directly with the person — this typically leads to repeated demands rather than resolution. Preserve every message and payment demand, and report immediately through the 1930 helpline and cybercrime.gov.in’s crime-against-women-and-children category, which permits anonymous reporting.
My social media account was hacked and is being used to scam my contacts — what should I do?
Report it to the platform immediately through its account-compromise reporting flow, warn your contacts through another channel that the account is compromised, and file a complaint on cybercrime.gov.in under the identity-theft/impersonation category. If any contact has already lost money to a message sent from your hacked account, they should file their own separate complaint as the financial victim.
Can a company be held responsible if my SIM was fraudulently duplicated?
Recent Karnataka High Court authority has held a telecom provider vicariously liable where its own employee’s negligence enabled a fraudulent duplicate SIM issuance that led to financial loss. Liability depends on the specific facts of how the duplicate SIM was obtained, but the door to holding telecom providers accountable, not just banks, is now open.
Should I report a fake job offer or investment scam even if I didn’t lose money?
Yes. Reporting a scam you identified before losing money still helps investigators map an active fraud operation and can prevent the same scheme from reaching other victims. The National Cyber Crime Reporting Portal accepts reports of attempted, not only completed, fraud.
Conclusion
Cyber fraud in India now spans a wide range of mechanisms — phishing, identity theft, SIM-swap fraud, job and investment scams, sextortion, and impersonation — and the law has kept pace, if unevenly, through a combination of the IT Act’s technology-specific provisions and the BNS’s general cheating and forgery offences. The single biggest determinant of outcome is speed: reporting through the 1930 helpline and the National Cyber Crime Reporting Portal within hours, not days, materially changes whether funds can be frozen and whether an investigation gains traction. Recent case law — extending telecom liability for SIM-swap fraud, treating sextortion with judicial seriousness, and reinforcing bank zero-liability rules — shows courts adapting the law’s application even where fresh legislation has not. None of this removes the burden from individuals and businesses to build basic defensive habits — verifying unfamiliar requests, protecting OTPs and passwords, and treating urgency itself as a warning sign — since prevention remains faster and more reliable than any recovery process, however well the recovery process itself continues to improve.
This article is intended as general statutory information and does not constitute legal advice. Lexovia is not a law firm and does not provide legal advice, legal consultation, or legal representation under the Advocates Act, 1961. Statutory provisions, procedural requirements, and case law may vary and are subject to ongoing change. Customers are advised to consult a qualified enrolled advocate or the relevant authorities before acting on any specific cyber fraud matter.
Need a document drafted or a legal question researched? Lexovia provides statute-backed legal drafting and research, delivered to your inbox — no office visits.
See Services & Pricing →This document type is also available with a native-language companion — see Services for details.