Get the RTI Wiki appFree on iPhone and Android.

1930 cyber fraud helpline: what to say and do next

Information to give the 1930 cyber financial fraud helpline

Call 1930 promptly after a cyber financial fraud, but do not spend the call telling a long story or quoting legal sections. The operator needs a clear identity, payment and incident record that can be routed. Keep the bank involved separately and complete the National Cyber Crime Reporting Portal record with evidence. An acknowledgement is important, but it is not a recovery guarantee.

Quick answer: Say who you are, the mobile number involved, the exact amount and time, the bank or wallet, the payment channel, transaction ID or UTR, beneficiary details and a one-sentence description of how the fraud occurred. Ask the operator to repeat the acknowledgement number. Then notify the bank, preserve evidence and complete the report at cybercrime.gov.in. Never call a number from a search advertisement or pay someone to “activate” the 1930 complaint.

Before calling: collect the minimum facts

Open the transaction detail and write down:

  1. your name and a safe callback number (a second phone if the primary SIM has gone dead);
  2. bank, wallet or payment provider;
  3. account number in masked form unless the official operator requests the required details;
  4. transaction amount, date and exact time (read it off the debit SMS, not from memory);
  5. transaction ID, UTR, UPI reference or card reference;
  6. beneficiary VPA, account, merchant, wallet or phone number shown;
  7. how the fraud started: fake support, phishing, remote access, UPI collect request, QR code, SIM swap, shopping scam or account takeover;
  8. whether more transactions are still happening;
  9. bank complaint number, if already available.

If you are missing the UTR, open the bank or UPI app and screenshot the transaction page. The same string is sometimes labelled RRN. On Google Pay it sits under “UPI transaction ID”. On PhonePe it is the long string on the receipt. For several debits, list each UTR in time order rather than only the total.

Do not delay the first report while trying to create perfect screenshots. Make the call with the core transaction facts, then complete the evidence record.

A clear 1930 call script

Use your own facts in this order. Read them; do not improvise a five-minute story. The operator needs facts in a usable sequence.

I am reporting a cyber financial fraud.

My name is [name] and my callback mobile number is [number].
The affected bank or wallet is [provider].

The disputed transaction is ₹[amount] at [date and time].
The transaction ID or UTR is [reference].
The beneficiary shown is [VPA, account, merchant or wallet].

This happened when [one factual sentence: for example, a caller impersonated
merchant support and induced me to approve a UPI collect request].

I have [blocked the card or account channel / contacted the bank / not yet
reached the bank]. Please register the report and tell me the acknowledgement
number and the next portal step.

Work through the call in this order:

  1. Open: identity, callback number, request to register a cyber financial-fraud report. Do not start with the backstory.
  2. Transaction facts: bank or wallet, exact time, exact amount, UTR or UPI reference, beneficiary VPA or account shown.
  3. What happened: two factual sentences. “I clicked a link in an SMS and entered my UPI PIN on a fake page.” Or “A caller claiming to be courier support asked me to confirm delivery with an OTP.” Keep it dry.
  4. Ask for the next step: request the acknowledgement number, whether a lien or freeze request will be raised to the beneficiary bank, and what you must complete on cybercrime.gov.in. If the operator only says “we have noted it”, ask them to repeat the acknowledgement and the portal step.
  5. Close: read the number back. Say you will complete the portal report. Do not call 1930 again on the same facts to “add more details”; that can create a duplicate. Add documents on the portal.

If there are several transactions, give them in time order. Do not combine the total while hiding individual references; each UTR can matter for tracing.

What not to say

Avoid unsupported labels such as “the bank hacked me” when a fake merchant persuaded you to authorise a payment. State exactly what you clicked, shared or approved. This helps the bank and police classify the incident.

Do not:

  • invent a transaction time or beneficiary;
  • claim the payment was unauthorised if you knowingly entered the PIN, even if deception induced you;
  • conceal that remote-access software was installed;
  • omit a shared OTP or credential out of embarrassment;
  • accuse an unrelated person based only on a recycled phone number;
  • demand a guaranteed refund from the helpline operator.

Truthful details protect the later complaint even when they do not produce an immediate answer.

Is 1930 available 24 hours, and what if the line is busy?

1930 is promoted as a national cyber financial-fraud helpline. Call volumes are high in the late evening and on weekends, which is why people search for 1930 helpline number timing and whether 1930 is 24 hours. Treat the line as a first report, not as a queue that must succeed before you do anything else.

If the line is busy:

  1. redial; do not wait an hour between attempts;
  2. on a second device, open cybercrime.gov.in and start the financial-fraud report with the same facts;
  3. block further outgoing payments through the official bank app, the number printed on the card, or the in-app “block card / freeze UPI” control — not a number from a search advertisement;
  4. screenshot every debit SMS and the transaction screen before the phone is switched or the SIM is replaced.

When you do get through, mention the time of the first attempt. That timestamp belongs in your later bank dispute and portal statement. The busy tone is not a reason to skip the portal.

Do not dial a 10-digit mobile that claims to be “1930 callback”, “I4C refund cell” or “cybercrime officer”. Genuine follow-up is through the portal status, the bank’s published channels, or a police unit you verify independently. 1930 will not ask for an OTP, UPI PIN, CVV, remote-access app, or a processing fee.

What the acknowledgement means

The acknowledgement proves a report was registered or routed in the reporting system. It does not guarantee a freeze or refund, and it does not prove that:

  1. the beneficiary account contains the money;
  2. a bank has frozen funds;
  3. the suspect has been identified;
  4. an FIR has been registered;
  5. a refund has been approved;
  6. recovery will occur within a fixed number of hours.

The cybercrime system routes complaints to the relevant State or Union Territory law-enforcement agency. I4C's public notice says that I4C itself is not an investigating agency. Keep the acknowledgement safe and follow the authority identified in the portal record.

Complete the portal report

Use cybercrime.gov.in directly. The portal's published one-page instruction for financial-fraud reporting lists details such as mobile number, bank or wallet, transaction ID, date, card information where relevant and screenshots. It also describes completing formal portal details after a helpline acknowledgement within 24 hours, but that particular instruction is labelled For Delhi Only. Follow the acknowledgement and State-specific instructions in your case, and in every case complete the portal record promptly rather than treating the call as the end of the process.

Choose the financial fraud category, not a generic “other” or bullying category. Wrong routing delays the file. Use the same registered mobile you quoted on the call.

Upload clear copies of:

  • transaction detail and bank statement;
  • messages, email, website or app identity;
  • call log and suspect contact;
  • remote-access app evidence, if used;
  • shopping order, invoice or fake support chat;
  • bank complaint and blocking confirmation;
  • a short chronological statement.

Keep original files. Redact copies used outside the official complaint so card, Aadhaar and account data are not exposed. Download the acknowledgement PDF and store it in three places: device, email draft, and a printed copy for the branch.

How to check 1930 cyber crime complaint status

People searching 1930 cyber crime complaint status need the portal record, not a third-party “track 1930” site. Log in at cybercrime.gov.in with the mobile used on the call. Use the acknowledgement or complaint number the operator repeated. Status text on the portal is a routing record; it is not a freeze confirmation and not an FIR copy.

Also keep:

  1. the bank’s own dispute or blocking reference;
  2. any SMS or email the portal actually sent to the registered mobile;
  3. the State or Union Territory unit named in the portal, if shown.

Do not post the full acknowledgement, account number or victim statement in a public comment asking “what is the status”. If the portal shows a local police or cyber unit, use the cybercrime complaint-status guide for the follow-up path without exposing the file. A second scammer will often quote a real-looking acknowledgement; verify through the portal, not through a callback.

Notify the bank even after calling 1930

The 1930 report and bank complaint are separate records. Call the bank through its official website, card or app. Ask it to block further activity and register the dispute with a timestamp.

Give the bank:

  1. transaction reference and amount;
  2. fraud method;
  3. time you first discovered it;
  4. time you reported it to the bank;
  5. 1930 or NCRP acknowledgement;
  6. request for the applicable recall, lien, chargeback or dispute procedure;
  7. request for a written liability decision.

Walk into the home branch with a printed portal acknowledgement when you can. Email-only disputes are easier to bury. Get a stamped inward number. If the branch refuses an acknowledgement, escalate the same day to the bank’s published nodal officer, not to a number from a search ad.

Use the online-payment fraud guide for the RBI customer-liability conditions. Reporting within three days does not automatically refund every scam; the transaction type, cause and negligence findings matter. For UPI that shows a debit with no merchant, read UPI deducted but not received before treating a glitch as a completed fraud.

Secure connected accounts

After reporting the payment:

  • change bank and email passwords from a trusted device;
  • remove unknown UPI devices or mandates through the official app;
  • block affected cards and check tokenised cards;
  • contact the telecom operator if the SIM stopped or a port request appeared;
  • review email forwarding rules and recovery numbers;
  • uninstall remote-access software after preserving evidence;
  • watch for a second scammer posing as police, bank staff or a recovery agent.

If your SIM stopped unexpectedly, use the SIM-swap recovery checklist and the SIM-swap fraud recovery guide. If unknown numbers appear on your name, check TAFCOP / Sanchar Saathi on the official route, not a paid “SIM check” site. If the bank later restricts an account because of a complaint, use the bank-freeze response guide.

Special cases: UPI, AEPS and SIM swap

The same 1930 facts still apply. The extra step changes.

UPI deduction with no merchant

If the SMS shows a debit but no merchant name, the case may be a UPI Lite issue, a failed collect request, or a mandate auto-debit rather than a completed fraud. Still call 1930 if money has left the account. In parallel, use the bank’s official UPI dispute and read the UPI deducted-not-received plan. Some failed credits reverse through the payment system without a police freeze.

AEPS or Aadhaar fingerprint debit

AEPS frauds can drain an account at a business-correspondent micro-ATM using biometric impersonation. Give 1930 the AEPS / RRN reference and the correspondent or merchant location if shown. After preserving evidence, lock Aadhaar biometrics through the official UIDAI route at myaadhaar.uidai.gov.in and follow AEPS Aadhaar fraud recovery.

SIM swap or port-out

If the phone showed “No service” before the debit, treat it as SIM-swap until proved otherwise. Tell 1930 that the registered mobile was dead or ported. Visit the telecom store for a restoration record before you replace the SIM if you still need the debit SMS as evidence; export or screenshot SMS first. Then use the SIM-swap guides above. Do not share a fresh OTP with anyone who calls claiming they can “restore 1930 access”.

QR, cashback and shopping-support scams

If the debit followed a shop QR, temple or parking scan, or a fake cashback page, keep the original QR photo, invoice and chat. See QR-code scam checks and fake cashback and shopping-support scams. The 1930 script stays the same: UTR, merchant shown, one-sentence method.

Track without exposing yourself

Use the official cybercrime portal to view the complaint status. Do not post the full acknowledgement, account number, phone number or victim statement in a public comment asking for help.

If a person calls claiming they can release money or close the complaint:

  1. ask for name, rank, unit and official contact;
  2. verify through the police station or agency independently;
  3. do not pay a fee or send crypto;
  4. do not share an OTP or UPI PIN;
  5. record the new impersonation attempt in the complaint.

No genuine refund requires you to approve a debit request.

Sample written complaint to your bank

A typed copy on a plain sheet, given at the branch counter with a stamped acknowledgement, is the paper trail that sits beside the 1930 number.

To,
The Branch Manager,
[Bank name], [Branch name and address]
Date: [DD MMM 2026]

Subject: Unauthorised electronic banking transaction — request to
block further activity, register a dispute, and confirm any
recall / lien / chargeback steps. Account [last 4 digits].

Sir/Madam,

I hold savings account [last 4 digits] at your branch. On [date]
at [time] I noticed an unauthorised debit of ₹[amount] via
[UPI/IMPS/card/AEPS]. Transaction references:

1. UTR [number] for ₹[amount] at [time]
2. UTR [number] for ₹[amount] at [time]

I reported the fraud to:

1. National Cyber Crime Helpline 1930 at [time] on [date].
   Acknowledgement: [number].
2. The National Cyber Crime Reporting Portal
   (https://cybercrime.gov.in/) on [date].
   Acknowledgement: [number]. PDF enclosed.

Please:

(a) block further activity on the affected channel and confirm
    in writing the time of blocking;
(b) register this dispute under the bank’s unauthorised electronic
    banking transaction process and give a complaint number;
(c) start the applicable recall, chargeback or beneficiary-lien
    request and tell me the reference;
(d) issue a written liability decision, including any provisional
    credit, with reasons.

Enclosures: NCRP acknowledgement, debit SMS / app screenshots,
identity proof.

Yours faithfully,
[Name]
[Signature]
[Mobile]
[Email]

Cite the RBI customer-liability circular by the number on the RBI page rather than from memory. After 30 days of no satisfactory bank reply, the RBI Integrated Ombudsman route in the banking Ombudsman guide is for bank service failure, not for ordering the police to freeze a third-party account.

Collect These Details Before You File

Have these ready before you open the portal or call 1930. The more accurate your information, the faster the action.

  • Your full name, registered mobile number, and email address
  • Your bank account number and IFSC code
  • The exact amount and date-time of the fraudulent debit
  • The transaction reference number (UTR / transaction ID) from your bank alert SMS or passbook
  • The fraudster's phone number, UPI ID, bank account number, or wallet ID if you know it
  • Screenshots of any suspicious SMS, WhatsApp message, email, or website
  • Your bank statement showing the debit
  • Any money transfer receipt or online payment confirmation

Save all of these to a folder. Do not delete any message or notification, even if it looks like junk.

If the fraudster contacted you through a phone call or SMS, also report the number to Sanchar Saathi at sancharsaathi.gov.in/sfc. Select the fraud category, enter the number, attach a screenshot, and submit. This triggers telecom action and can disconnect the number used to cheat you. Reporting here does not replace the cybercrime.gov.in complaint - file both.

For UPI-specific fraud, also raise a dispute directly in your UPI app (Google Pay, PhonePe, BHIM, or your bank app) under the relevant transaction. See our guide on how to file a UPI fraud complaint for the in-app steps.

What Happens After You Report

* Your bank is required to acknowledge your complaint immediately and give you a complaint number.

  • The bank must provisionally credit the disputed amount to your account within 10 working days while the investigation runs. The full resolution must happen within 90 days.
  • Law enforcement agencies and the police access complaints filed on cybercrime.gov.in and may contact you for a statement or additional details.
  • In financial fraud cases, the I4C (Indian Cyber Crime Coordination Centre) under MHA coordinates across banks and payment networks to flag the fraudster's account.
  • Keep checking your complaint on the portal using the reference number. If there is no action within a reasonable period, escalate (see below).

If the fraud involved an OTP that was given unknowingly or obtained by impersonation, also read our page on OTP bank scam complaints and how to claim a cyber fraud money refund once your complaint is registered.

File an RTI if the Complaint Goes Unanswered

File an RTI to: the State Cyber Cell / Nodal Cyber Crime officer and your bank

If your complaint on 1930 or cybercrime.gov.in has received no update after a reasonable period, you can file an RTI application to the relevant public authority for information on the action taken. Suggested questions:

  • What action was taken on my complaint number [reference] filed on [date]?
  • Has an FIR been registered? If yes, provide the FIR number and police station.
  • Which bank or payment network was contacted, and what was their response?
  • Has any amount been frozen or recovered in connection with the complaint?
  • What is the name and designation of the officer assigned to my complaint?

Use our free AI RTI Drafter to generate a complete Section 6(1) application.

What if I already fell for a fraud call from someone claiming to be police or CBI?

This is called “digital arrest” scam or police impersonation fraud. Report it on 1930 and on cybercrime.gov.in under the “Other Cyber Crime” category. Also note: no genuine police officer, CBI official, ED officer, or court will ever demand money by phone or video call, or threaten to arrest you remotely.

Frequently asked questions

What is 1930 used for?

It is the national reporting helpline promoted by the official cybercrime portal for cyber financial fraud.

Is the 1930 helpline 24 hours?

It is staffed as a national helpline, including outside ordinary office hours, but call volume can mean a busy tone. File on cybercrime.gov.in in parallel and block the card through official bank channels.

How quickly should I call?

Call promptly after discovering the transaction. Earlier reporting can improve the chance of timely routing, but there is no guaranteed “golden hour” percentage or recovery promise.

What if I do not know the beneficiary account?

Give the transaction ID, UTR, payment channel, amount and the beneficiary information visible in the statement. Do not guess missing details.

Must I also contact the bank?

Yes. Ask the bank to block further activity and register its own complaint or dispute record even after calling 1930.

Is the 1930 acknowledgement an FIR?

No. It is a reporting-system acknowledgement. The competent State or Union Territory law-enforcement agency handles investigation and further legal process.

Does 1930 guarantee a freeze or refund?

No. Action depends on the transaction trail, time, remaining funds, bank response and investigation. I4C’s public notice is that I4C itself does not freeze accounts.

Should I complete the cybercrime portal report?

Yes. Follow the acknowledgement instructions and complete the official portal record promptly with transaction and supporting evidence.

What is the difference between 1930 and 100?

100 is the police emergency line for any crime in progress or a safety threat. 1930 is the specialised cyber financial-fraud reporting helpline that feeds the NCRP system. For an online money fraud, dial 1930 and complete the portal. If there is a parallel physical threat, kidnapping or extortion in person, dial 100 as well.

Can I call 1930 from outside India?

The 1930 short code is for Indian networks. From abroad, use cybercrime.gov.in with the same facts. Keep an Indian mobile available for verification SMS if the portal or bank requires one.

What if someone asks for money to process my 1930 complaint?

Do not pay. Verify through the official portal, bank or police unit. Treat the demand as a possible recovery scam.

Official sources

Was this useful?
- views