Differences
This shows you the differences between two versions of the page.
| — | fake-pan-update-sms-scam-india [2026/07/22 17:47] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== Fake PAN Update SMS Scam India (2026) ====== | ||
| + | |||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** How to identify fake Income Tax PAN-update SMS scams, report phishing to CERT-In, file an FIR under BNS 2023, block fraudulent UPI links, and recover data shared. | ||
| + | </ | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | A typical fake PAN-update scam plays out like this. A taxpayer receives an SMS claiming their PAN card will be " | ||
| + | |||
| + | > **Citizen Crisis Response Network** \\ | ||
| + | > Suspect a PAN-update SMS? Do not click any link. Visit incometax.gov.in directly, screenshot the message, forward it to [email protected], | ||
| + | |||
| + | ===== Direct answer (featured snippet) ===== | ||
| + | |||
| + | **1** Fake PAN-update SMS scams use spoofed Income Tax Department sender IDs and urgent language to trick you into clicking phishing links. **2** The genuine Income Tax Department never sends unsolicited SMS with live links demanding immediate PAN or Aadhaar updates. **3** Scammers harvest PAN, Aadhaar, OTP, and banking credentials through cloned portals to drain accounts or sell identity documents on the dark web. **4** Report the SMS to CERT-In at [email protected], | ||
| + | |||
| + | ===== In this guide ===== | ||
| + | |||
| + | * [[#How the fake PAN SMS scam works in 2026|How the fake PAN SMS scam works in 2026]] | ||
| + | * [[#Red flags that expose phishing messages|Red flags that expose phishing messages]] | ||
| + | * [[# | ||
| + | * [[# | ||
| + | * [[# | ||
| + | * [[#Filing an FIR and sample complaint text|Filing an FIR and sample complaint text]] | ||
| + | * [[#Bank liability and zero-liability protection|Bank liability and zero-liability protection]] | ||
| + | * [[#Case law and enforcement touchpoints|Case law and enforcement touchpoints]] | ||
| + | * [[# | ||
| + | * [[#Sample legal notice to bank and NSDL|Sample legal notice to bank and NSDL]] | ||
| + | * [[# | ||
| + | * [[#Myth vs reality table|Myth vs reality table]] | ||
| + | |||
| + | ===== How the fake PAN SMS scam works in 2026 ===== | ||
| + | |||
| + | Cybercriminals purchase bulk SMS gateway credits and spoof sender IDs—common variations include " | ||
| + | |||
| + | When you tap the link, you land on a clone of the Income Tax e-filing portal or the NSDL PAN services page. The fake site requests PAN number, Aadhaar number, date of birth, mobile number, and email. On the next screen it prompts for a six-digit OTP "to authenticate your identity." | ||
| + | |||
| + | The scam scales because India' | ||
| + | |||
| + | > **Warning** — Even if the sender ID appears legitimate, cross-verify the domain in the URL. Official Income Tax and NSDL links always use incometax.gov.in or onlineservices.nsdl.com—never short URLs or third-party domains. | ||
| + | |||
| + | ===== Red flags that expose phishing messages ===== | ||
| + | |||
| + | **Urgency and threat language.** Genuine government communications never threaten immediate deactivation or legal action via SMS. The Income Tax Department publishes extended deadlines on its website and sends reminders through registered email on your e-filing account. | ||
| + | |||
| + | **Unsolicited links.** The department' | ||
| + | |||
| + | **Grammar and spelling errors.** Phishing messages often carry typos—" | ||
| + | |||
| + | **Generic greetings.** A real notice from the Income Tax Department uses your registered name and PAN. Scam texts open with "Dear User," "Dear Taxpayer," | ||
| + | |||
| + | **Request for OTP or CVV.** No government portal or bank ever asks you to share an OTP received on your phone. OTPs are auto-read by apps or manually entered by you on the *same* authenticated session—never disclosed to a third party. | ||
| + | |||
| + | **URL structure.** Hover over (on desktop) or long-press (on mobile) the link to reveal the full destination. Look for misspellings: | ||
| + | |||
| + | **SSL certificate mismatch.** If you do land on a phishing site, check the padlock icon. Fraudulent pages either lack HTTPS or display certificates issued to unrelated entities. Browsers flag these with "Not Secure" | ||
| + | |||
| + | > **Most citizens miss this** — Screenshot the SMS before deleting it. The metadata—sender ID, timestamp, and URL—form the evidential foundation of your FIR and CERT-In complaint. | ||
| + | |||
| + | ===== Statutory framework: BNS 2023, IT Act 2000, and RBI mandate ===== | ||
| + | |||
| + | **Bharatiya Nyaya Sanhita 2023 section 318(4)** corresponds to the erstwhile IPC section 420—cheating and dishonestly inducing delivery of property. A conviction carries imprisonment up to seven years and a fine. The offence is cognizable (police can arrest without warrant) and non-bailable. | ||
| + | |||
| + | **Bharatiya Nyaya Sanhita 2023 section 319** addresses cheating by personation—pretending to be another person (here, the Income Tax Department) to cheat the victim, corresponding to the erstwhile IPC section 419. It carries imprisonment up to five years and a fine, and is commonly charged alongside section 318(4) in PAN-impersonation cases. | ||
| + | |||
| + | **Information Technology Act 2000 section 66D** penalizes cheating by personation using a computer resource with imprisonment up to three years and a fine. Though BNS 2023 has replaced the IPC, the IT Act 2000 remains in force for cyber-specific offences, and prosecutors often invoke both statutes in the same charge-sheet. | ||
| + | |||
| + | **Information Technology Act 2000 section 43(a)** grants civil remedies: you can claim compensation from the intermediary (SMS gateway or hosting provider) if they failed to observe due diligence under Intermediary Guidelines 2021. The adjudicating officer under section 46 can award up to ₹5 crore, though typical awards range between ₹50,000 and ₹5 lakh. | ||
| + | |||
| + | **Reserve Bank of India circular on Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions (dated 6 July 2017)** sets out the customer-liability framework. Where an unauthorised transaction arises from a third-party breach (neither the bank's fault nor the customer' | ||
| + | |||
| + | > **Do this immediately** — Download the RBI circular on limiting customer liability in unauthorised electronic banking transactions from rbi.org.in and attach it to your bank complaint, stating clearly that you reported within three working days. | ||
| + | |||
| + | ===== Immediate actions if you clicked the link or shared data ===== | ||
| + | |||
| + | **Minute zero to five.** Do not close the phishing site yet; take screenshots showing the full URL, page content, and any form fields. On Android open Recent Apps and screenshot the browser window; on iOS capture the Safari address bar. Then disconnect your phone from Wi-Fi and mobile data to sever the attacker' | ||
| + | |||
| + | **Minute six to fifteen.** Call your bank's 24×7 customer care—Axis Bank: 1860-419-5555, | ||
| + | |||
| + | **Minute sixteen to thirty.** Dial the national cyber-crime helpline **1930**. Provide your registered mobile number, the phishing URL, and transaction details if any money left your account. The 1930 operator logs your complaint into the Citizen Financial Cyber Frauds Reporting and Management System (CFCFRMS) and issues a reference number. This number is mandatory for invoking RBI's zero-liability framework. | ||
| + | |||
| + | **Hour one.** Visit your bank branch with a written complaint on plain paper. Include the 1930 reference number, timeline, screenshots, | ||
| + | |||
| + | **Hour two to twenty-four.** Lodge an FIR at your local cyber-crime police station or through the National Cyber Crime Reporting Portal at cybercrime.gov.in. The police cannot refuse an FIR for a cognizable offence under BNS 2023 section 318(4); if they do, invoke Bharatiya Nagarik Suraksha Sanhita 2023 section 173(1), which codifies zero-FIR rights. | ||
| + | |||
| + | **Day two.** Change passwords for your Income Tax e-filing account, EPFO, DigiLocker, and any banking app. Enable two-factor authentication on email. Check your CIBIL report at cibil.com (one free report per year) and place a fraud alert with the credit bureau. | ||
| + | |||
| + | > **Citizen tip** — If you shared your Aadhaar OTP, visit uidai.gov.in and lock your biometrics under the " | ||
| + | |||
| + | ===== Reporting to CERT-In and Cyber Crime Portal ===== | ||
| + | |||
| + | **Indian Computer Emergency Response Team (CERT-In)** operates under the Ministry of Electronics and Information Technology and holds statutory authority under IT Act 2000 section 70B. Forward the phishing SMS as an email attachment to **[email protected]**. In the email body include: | ||
| + | |||
| + | * Your name and contact number | ||
| + | * Date and time you received the SMS | ||
| + | * Sender ID as displayed | ||
| + | * Full text of the message | ||
| + | * Expanded URL (use a URL-expander service like checkshorturl.com if you did not click) | ||
| + | * Screenshots of the fake website if accessed | ||
| + | |||
| + | CERT-In acknowledges reports with a ticket number and escalates malicious domains to registrars and hosting providers for takedown. | ||
| + | |||
| + | **National Cyber Crime Reporting Portal** at cybercrime.gov.in accepts complaints under " | ||
| + | |||
| + | If you do not receive a response within 15 days, file an RTI application with the Ministry of Home Affairs (Cyber Crime Coordination Centre) asking for the status of your complaint, name of the investigating officer, and steps taken. Use the **RTI Assistant** at https:// | ||
| + | |||
| + | > **Trust signal** — The Supreme Court in //Lalita Kumari v. Government of Uttar Pradesh// (2014) 2 SCC 1 held that police must register an FIR for cognizable offences without preliminary inquiry. Cite this judgment if your local station hesitates. | ||
| + | |||
| + | ===== Filing an FIR and sample complaint text ===== | ||
| + | |||
| + | An FIR under BNS 2023 transforms your complaint from a civil dispute into a criminal investigation. Police gain powers to summon telecom records, freeze mule accounts, and coordinate with international agencies via Interpol channels. Visit the cyber-crime police station in your district (larger cities have dedicated cyber-cells; | ||
| + | |||
| + | * Two printed copies of your written complaint | ||
| + | * Printouts of all screenshots | ||
| + | * Bank statement showing unauthorized debit | ||
| + | * 1930 reference number printout | ||
| + | * Photocopy of PAN card and Aadhaar card | ||
| + | * Photo ID proof | ||
| + | |||
| + | Below is a sample complaint text. Adapt names, dates, and amounts to your facts. | ||
| + | |||
| + | < | ||
| + | To, | ||
| + | The Station House Officer, | ||
| + | Cyber Crime Police Station, | ||
| + | [City Name], [State] | ||
| + | |||
| + | Subject: FIR under BNS 2023 Section 318(4) read with Section 319 and IT Act 2000 Section 66D for phishing and cheating | ||
| + | |||
| + | Respected Sir/Madam, | ||
| + | |||
| + | I, [Your Full Name], residing at [Full Address], [City, PIN], hereby lodge a complaint regarding a cyber fraud committed against me on [Date]. | ||
| + | |||
| + | 1. On [Date] at approximately [Time], I received an SMS on my mobile number [Your Mobile] from sender ID " | ||
| + | |||
| + | 2. The SMS contained a URL: [Full URL]. Believing it to be a genuine communication from the Income Tax Department, I clicked the link and was redirected to a website that closely resembled the official incometax.gov.in portal. | ||
| + | |||
| + | 3. I entered my PAN number, Aadhaar number, date of birth, mobile number, and subsequently a six-digit OTP received on my phone. | ||
| + | |||
| + | 4. Within minutes I received a bank debit alert: ₹[Amount] was withdrawn from my account [Account Number] at [Bank Name], [Branch]. | ||
| + | |||
| + | 5. I immediately called the bank's customer care and the 1930 helpline. I was issued reference number [1930 Reference Number] by the cyber-crime helpline. | ||
| + | |||
| + | 6. Screenshots of the SMS and phishing website are attached as Annexures A and B. Bank statement showing the unauthorized debit is attached as Annexure C. | ||
| + | |||
| + | 7. The act constitutes cheating and dishonestly inducing delivery of property under Bharatiya Nyaya Sanhita 2023 section 318(4) read with cheating by personation under section 319, and cheating by personation using a computer resource under Information Technology Act 2000 section 66D. | ||
| + | |||
| + | I request you to: | ||
| + | • Register an FIR under the above sections | ||
| + | • Investigate the SMS gateway and hosting provider of the phishing domain | ||
| + | • Coordinate with my bank and the National Payments Corporation of India (NPCI) to trace the recipient of the fraudulent transaction | ||
| + | • Take necessary action under Bharatiya Nagarik Suraksha Sanhita 2023 to preserve evidence | ||
| + | |||
| + | I am willing to cooperate fully with the investigation. | ||
| + | |||
| + | Place: [City] | ||
| + | Date: [Date] | ||
| + | |||
| + | Signature | ||
| + | [Your Name] | ||
| + | [Contact Number] | ||
| + | [Email Address] | ||
| + | |||
| + | Attachments: | ||
| + | Annexure A: Screenshot of SMS | ||
| + | Annexure B: Screenshots of phishing website | ||
| + | Annexure C: Bank statement extract | ||
| + | Annexure D: 1930 complaint reference printout | ||
| + | </ | ||
| + | |||
| + | The police will record your statement under BNSS 2023 section 183, assign a First Information Report number, and hand you a copy. If they refuse, invoke your right to approach the Superintendent of Police under BNSS 2023 section 173(3) or file a private complaint before the jurisdictional Magistrate under BNSS 2023 section 223. | ||
| + | |||
| + | > **Warning** — Some police stations ask you to register online first through cybercrime.gov.in and then visit for a " | ||
| + | |||
| + | ===== Bank liability and zero-liability protection ===== | ||
| + | |||
| + | Reserve Bank of India' | ||
| + | |||
| + | * **Zero liability: | ||
| + | * **Limited liability (up to ₹10, | ||
| + | * **Case-by-case assessment: | ||
| + | |||
| + | Under the RBI framework, a customer bears the **full loss** only where the loss is due to their own negligence—such as voluntarily sharing payment credentials—until they report the unauthorised transaction. Whether entering an OTP on a cloned government portal after being deliberately deceived amounts to such negligence is fact-specific and has been litigated both ways, so do not concede negligence in your complaint; set out plainly that you were deceived by a fraudulent site impersonating the Income Tax Department. | ||
| + | |||
| + | If your bank denies your claim citing " | ||
| + | |||
| + | **Step one:** Write to the bank's nodal officer (name and email listed on the bank's website under " | ||
| + | |||
| + | **Step two:** If no response within 30 days, lodge a complaint with the Banking Ombudsman. Visit rbi.org.in, navigate to " | ||
| + | |||
| + | **Step three:** Simultaneously approach the consumer forum under the Consumer Protection Act 2019, choosing the right tier by the value of your claim—District Commission up to ₹50 lakh, State Commission above ₹50 lakh and up to ₹2 crore, and the National Commission above ₹2 crore (pecuniary limits as revised in 2021). The Act recognizes digital-banking customers as " | ||
| + | |||
| + | > **Do this immediately** — Request certified copies of your bank statements and the SMS gateway logs from your telecom provider within 30 days. After 90 days, operators purge transactional SMS logs, and you lose crucial evidence. | ||
| + | |||
| + | ===== Case law and enforcement touchpoints ===== | ||
| + | |||
| + | Liability in OTP-based cyber-fraud disputes is decided on the facts of each case. Courts have, in some matters, directed banks to compensate victims where the bank failed in its duty of reasonable care or acted slowly after fraud was detected; in others, they have held that a customer' | ||
| + | |||
| + | Phishing attacks that exploit cloned government portals are commonly charged under BNS 2023 section 318(4) read with section 319, *and* IT Act 2000 section 66D concurrently. Where the proceeds are laundered, investigating agencies may also invoke the Prevention of Money Laundering Act 2002 to attach the assets. | ||
| + | |||
| + | **Enforcement agencies you may interact with:** | ||
| + | |||
| + | * **National Cyber Crime Coordination Centre (I4C):** Operates under Ministry of Home Affairs; handles interstate and international coordination. Contact via cybercrime.gov.in. | ||
| + | * **CERT-In: | ||
| + | * **Reserve Bank of India Banking Ombudsman: | ||
| + | * **Unique Identification Authority of India (UIDAI):** If your Aadhaar OTP was misused, file a complaint via uidai.gov.in/ | ||
| + | * **National Payments Corporation of India (NPCI):** For UPI fraud, email [email protected] with transaction ID and remitter/ | ||
| + | |||
| + | The Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs publishes periodic advisories and statistics on prevailing fraud trends; tax-themed phishing, including fake PAN-update scams, features consistently among the reported categories. | ||
| + | |||
| + | > **Most citizens miss this** — The PIO Reply Checker at https:// | ||
| + | |||
| + | ===== Long-term credit and identity monitoring ===== | ||
| + | |||
| + | Your PAN number is a master key to your financial identity. Scammers who harvest it can: | ||
| + | |||
| + | * File fraudulent income-tax returns to claim refunds | ||
| + | * Register shell companies in your name and use them for GST fraud or money laundering | ||
| + | * Apply for personal loans or credit cards | ||
| + | * Defraud EPFO provident-fund withdrawals | ||
| + | |||
| + | Mitigate these risks by: | ||
| + | |||
| + | **Quarterly CIBIL checks.** Use CIBIL' | ||
| + | |||
| + | **Income Tax account vigilance.** Log in to incometax.gov.in every month and review "My Profile" | ||
| + | |||
| + | **PAN inquiry freeze.** The Income Tax Department does not yet offer a formal PAN freeze, but you can request restriction on PAN changes by visiting your jurisdictional Assessing Officer with an affidavit and police FIR copy. They annotate your PAN record with "Fraud Alert." | ||
| + | |||
| + | **Aadhaar lock/ | ||
| + | |||
| + | **DigiLocker monitoring.** If you use DigiLocker for document storage, check the " | ||
| + | |||
| + | > **Citizen tip** — Set up Google Alerts for "[Your PAN number] company registration" | ||
| + | |||
| + | ===== Sample legal notice to bank and NSDL ===== | ||
| + | |||
| + | If your bank or the National Securities Depository Limited (NSDL, the authorized PAN service provider) failed to prevent unauthorized changes to your PAN details, issue a legal notice demanding reversal and compensation. Below is a sample. | ||
| + | |||
| + | < | ||
| + | LEGAL NOTICE | ||
| + | |||
| + | To, | ||
| + | The Branch Manager, | ||
| + | [Bank Name], | ||
| + | [Branch Address], | ||
| + | [City, PIN] | ||
| + | |||
| + | CC: Nodal Officer – Customer Grievances, [Bank Name], [Email] | ||
| + | CC: National Securities Depository Limited, 4th Floor, Trade World, Kamala Mills Compound, Mumbai – 400013 | ||
| + | |||
| + | Subject: Legal notice for unauthorized debit due to phishing fraud and failure to comply with RBI directions on limiting customer liability in unauthorised electronic banking transactions | ||
| + | |||
| + | Dear Sir/Madam, | ||
| + | |||
| + | 1. I, [Your Name], hold a savings account [Account Number] at your branch. On [Date], I was a victim of a phishing scam wherein fraudsters impersonating the Income Tax Department tricked me into disclosing my PAN, Aadhaar, and OTP details. | ||
| + | |||
| + | 2. On [Date and Time], ₹[Amount] was debited from my account without my authorization. I reported the fraud to your customer care on [Date and Time] and lodged a written complaint at your branch on [Date], receiving acknowledgment number [Acknowledgment Number]. | ||
| + | |||
| + | 3. Despite my reporting the unauthorised transaction within the three-working-day notification window prescribed by RBI's circular on Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, | ||
| + | |||
| + | 4. I also hold that NSDL, as the authorized PAN service provider, allowed a phishing domain to clone its interface without deploying adequate anti-phishing measures or consumer warnings. | ||
| + | |||
| + | DEMANDS: | ||
| + | |||
| + | a) Immediate reversal of ₹[Amount] to my account within seven days of receipt of this notice. | ||
| + | b) Certification that no adverse remark has been recorded against my account due to this incident. | ||
| + | c) Compensation of ₹[Amount, e.g., ₹25,000] for mental agony, time lost, and legal expenses. | ||
| + | d) A written assurance detailing the corrective measures adopted to prevent recurrence. | ||
| + | |||
| + | 5. If you fail to comply within seven days, I shall be constrained to: | ||
| + | • File a complaint with the Banking Ombudsman under the Reserve Bank – Integrated Ombudsman Scheme, 2021 | ||
| + | • Initiate a consumer complaint under Consumer Protection Act 2019 | ||
| + | • File a writ petition for mandamus in the jurisdictional High Court seeking directions to comply with RBI directives | ||
| + | |||
| + | This notice is issued without prejudice to my rights and remedies, all of which are expressly reserved. | ||
| + | |||
| + | Place: [City] | ||
| + | Date: [Date] | ||
| + | |||
| + | [Your Signature] | ||
| + | [Your Name] | ||
| + | [Contact Number] | ||
| + | [Email Address] | ||
| + | |||
| + | Enclosures: | ||
| + | 1. Copy of bank complaint acknowledgment | ||
| + | 2. FIR copy | ||
| + | 3. Screenshots of phishing SMS and website | ||
| + | 4. Bank statement extract showing unauthorized debit | ||
| + | 5. RBI circular extract (Limiting Liability of Customers in Unauthorised Electronic Banking Transactions) | ||
| + | </ | ||
| + | |||
| + | Send the notice via registered post with acknowledgment due and retain the receipt. If you do not receive a satisfactory reply within 15 days, proceed to the Banking Ombudsman and consumer forum simultaneously. | ||
| + | |||
| + | > **Trust signal** — A legal notice is not just a threat; it serves as admissible evidence in court that you took reasonable steps before litigation. Courts look favorably on parties who attempted pre-litigation settlement. | ||
| + | |||
| + | ===== Frequently asked questions ===== | ||
| + | |||
| + | ==== Can the Income Tax Department deactivate PAN without prior registered-email notice? ==== | ||
| + | |||
| + | No. The Central Board of Direct Taxes (CBDT) never deactivates a PAN without first sending a registered email to the address on file in your e-filing account and publishing a notice in at least two national newspapers. SMS is used only for reminders, not as the sole mode of final communication. | ||
| + | |||
| + | ==== If I shared only my PAN number and Aadhaar number but not the OTP, am I still at risk? ==== | ||
| + | |||
| + | Yes. Scammers aggregate such partial data from multiple breaches and combine them to open accounts, file fake returns, or sell the identity bundle on dark-web forums. Immediately report to CERT-In, lock your Aadhaar biometrics, and monitor your credit report. | ||
| + | |||
| + | ==== The phishing link is now dead—does that weaken my complaint? ==== | ||
| + | |||
| + | No. CERT-In and police cyber-forensic labs can often retrieve the original page from web archives, server logs, or DNS records. Your screenshots and 1930 reference remain valuable evidence. Still, act fast—the sooner the domain is reported, the better the chance of preserving a forensic trail before the fraudster takes the site down. | ||
| + | |||
| + | ==== My bank says they will refund only if the police recover the money. Is that lawful? ==== | ||
| + | |||
| + | Not as a blanket rule. Under RBI's customer-protection framework, where you are entitled to zero or limited liability the bank must shadow-credit the disputed amount within ten working days of your notification—its own recovery from the fraudster is a separate exercise that cannot be made a precondition for that credit. Inform your bank in writing, cite the RBI circular on limiting customer liability in unauthorised electronic banking transactions, | ||
| + | |||
| + | ==== Can I claim compensation for the time spent in filing FIR and visiting the bank? ==== | ||
| + | |||
| + | Yes, under the Consumer Protection Act 2019. The National Consumer Disputes Redressal Commission has awarded ₹5,000 to ₹50,000 for " | ||
| + | |||
| + | ==== Should I hire a lawyer immediately, | ||
| + | |||
| + | For amounts below ₹2 lakh, self-representation before the Banking Ombudsman and District Consumer Forum is straightforward—both bodies allow complaints without legal representation. For larger amounts or if the bank contests liability, consult a cyber-law advocate. Many bar associations offer free legal aid for cyber-fraud victims; inquire at your district legal services authority. | ||
| + | |||
| + | ==== What happens if the scammer used my PAN to register a fake company? ==== | ||
| + | |||
| + | The Ministry of Corporate Affairs allows you to file a strike-off application if a company is registered in your name without consent. Download Form STK-8 from mca.gov.in, attach your FIR and affidavit, and submit through the MCA portal. The Registrar of Companies will mark the company as "Under Fraud Investigation," | ||
| + | |||
| + | ==== Does cyber insurance cover phishing losses? ==== | ||
| + | |||
| + | Most standalone cyber-insurance policies cover social-engineering fraud, including phishing, up to the sum insured (commonly ₹1 lakh to ₹10 lakh). Check your policy document for the clause "Cyber Extortion and Social Engineering." | ||
| + | |||
| + | ==== How long does a typical investigation take before police file a charge-sheet? | ||
| + | |||
| + | Bharatiya Nagarik Suraksha Sanhita 2023 section 193 mandates that investigation should conclude within 90 days if the accused is in custody, or six months if at large. In practice, cyber-crime cases involving overseas servers take 12 to 18 months. You can request interim investigation status via RTI every 60 days. | ||
| + | |||
| + | ==== Can I prevent future scams by blocking my mobile number from receiving SMS from unknown senders? ==== | ||
| + | |||
| + | Partially. The Telecom Regulatory Authority of India' | ||
| + | |||
| + | > **Citizen tip** — Save the Citizen Crisis Response Network helpline (virtual support desk) in your phone contacts. When in panic, structured checklists reduce decision paralysis and accelerate the first-hour response. | ||
| + | |||
| + | ===== Myth vs reality table ===== | ||
| + | |||
| + | ^ Myth ^ Reality ^ | ||
| + | | The Income Tax Department sends PAN-update links via SMS. | The department never embeds live hyperlinks in SMS. All official communications direct you to incometax.gov.in and require login with existing credentials. | | ||
| + | | If the sender ID says " | ||
| + | | Once I enter my OTP, my money is gone for good. | Not necessarily. Report the unauthorised transaction to your bank within three working days and dial 1930 immediately—under RBI's customer-protection framework a third-party-breach transaction reported in time attracts zero liability, and the 1930 helpline can help freeze the money trail. | | ||
| + | | Filing an FIR is optional—I can just report to the bank. | An FIR under BNS 2023 section 318(4) is critical to invoke criminal investigation powers, freeze suspect accounts, and claim insurance. | | ||
| + | | CERT-In only helps government entities, not citizens. | CERT-In accepts complaints from all Indian residents at [email protected] and coordinates domain takedowns globally. | | ||
| + | | I need to hire a lawyer to approach the Banking Ombudsman. | The Reserve Bank – Integrated Ombudsman Scheme, 2021 lets you file a complaint yourself, free of cost, online at rbi.org.in or via the CMS portal—no lawyer is required. | | ||
| + | |||
| + | {{tag> | ||