Cyber Fraud Money Recovery in India: 1930 Helpline, Bank Hold, Refund, BNSS Section 107 & RBI Remedies
By Adv. Govind Bali, Fastrack Legal Solutions LLP | Reviewed on 20 August 2026
Cyber fraud money recovery is a race against movement of funds. Fraud proceeds may pass within minutes through a beneficiary account, several “layer” accounts, wallets, merchant accounts, cash withdrawals or virtual digital assets. Calling the bank or filing a complaint is essential, but neither step alone guarantees a refund. Recovery depends on speed, a traceable transaction trail, funds still available to hold, coordination between banks and police, and—where necessary—a lawful court order.
Quick legal answer: Immediately call 1930, report the fraud on cybercrime.gov.in, and notify the bank through its official 24×7 fraud channel. Preserve every transaction reference and acknowledgment. A portal complaint can help trigger tracing and a bank hold, but a hold is not the same as final recovery. Return of money may require police verification, a Magistrate’s order, action under Sections 106–107 or 497–498 of the Bharatiya Nagarik Suraksha Sanhita, 2023, or a separate RBI customer-liability remedy.
For the broader statutory framework, see our Cyber Crime Law in India 2026 guide. This article focuses specifically on recovering money after UPI, card, net-banking, wallet, impersonation, investment, task, loan-app, remote-access or other online fraud.
Key Takeaways
- Report financial cyber fraud to 1930 and the National Cybercrime Reporting Portal immediately; delay increases the risk that funds will leave the banking system.
- Separately notify the bank, block compromised channels and obtain a written complaint or dispute reference number.
- A “lien”, “hold”, “debit freeze” or CFCFRMS hold can preserve available funds, but does not automatically establish ownership or authorise refund.
- Section 106 BNSS concerns police seizure of property and requires prompt reporting to the jurisdictional Magistrate; Section 107 creates a court-supervised attachment and rateable-distribution mechanism for proceeds of crime.
- Sections 497 and 498 BNSS may support custody, delivery or disposal orders depending on whether the investigation/trial is pending or concluded.
- RBI’s zero- and limited-liability rules apply to qualifying unauthorised electronic banking transactions; they do not automatically cover every transfer induced by deception.
- Recovery is fact-sensitive. No lawyer, bank, police officer or private “recovery agent” can honestly guarantee return of cyber-fraud money.
The Three Distinct Recovery Tracks
| Track | Purpose | Typical result |
|---|---|---|
| 1930/NCRP and bank-network response | Rapid tracing and prevention of further dissipation | Hold or lien over funds still available in beneficiary/layer accounts |
| Police and criminal-court process | Investigation, seizure/attachment, proof of victim’s claim and lawful restoration | Release, delivery, restoration or rateable distribution under the applicable BNSS provision and court order |
| Bank-customer liability and RBI grievance process | Determine whether the bank or customer bears an unauthorised transaction loss | Shadow reversal, compensation or grievance relief where RBI directions apply |
These tracks may operate together, but they are not interchangeable. A criminal complaint may proceed even if the bank rejects customer liability. Conversely, an RBI complaint addresses deficiency in banking service; it does not convict the fraudster or replace the police investigation.
1. What to Do in the First Hour
- Call 1930 and provide the victim’s name, mobile number, bank or wallet, transaction date and time, amount, UTR/RRN/reference number, beneficiary details and the mode of fraud.
- Report the incident through the official National Cybercrime Reporting Portal. Save the acknowledgment number, submitted complaint and every uploaded document.
- Call the bank’s number shown on its official website, app or card—not a number sent by the fraudster. Report each transaction as fraudulent and request immediate beneficiary-bank recall/hold communication.
- Block or disable the compromised card, UPI handle, net-banking session, wallet, SIM or device access. Change passwords from a clean device and revoke unknown sessions.
- If a remote-access application was installed, disconnect the device, preserve it and obtain technical assistance before resetting it. A premature factory reset may destroy evidence.
- Prepare a one-page transaction chart and send a signed written complaint to the cyber police/police station with the NCRP acknowledgment and bank complaint numbers.
The Indian Cybercrime Coordination Centre (I4C) confirms that the National Cybercrime Reporting Portal and national helpline 1930 operate for cyber financial fraud reporting across States and Union Territories. I4C’s Citizen Financial Cyber Fraud Reporting and Management System enables complaints to be shared with banks and financial intermediaries for rapid action.
Do not send more money to “unlock” or “recover” the first payment
Fraudsters commonly demand tax, margin, verification, security deposit, court fee or “RBI clearance” after the first loss. A genuine police unit, court, RBI office or bank does not ask a victim to transfer money to a personal account or wallet to release frozen funds. Preserve the demand as evidence and stop further contact except under police advice.
2. Information Needed for a Useful 1930/NCRP Complaint
- Victim’s full name, address, mobile number and email.
- Name of remitting bank, masked account/card number and registered mobile number.
- Each transaction’s date, exact time, amount, UTR/RRN/reference number and payment channel.
- Beneficiary name, account number, IFSC, UPI ID, wallet, merchant ID or virtual-asset address, if visible.
- Fraudster’s phone numbers, usernames, URLs, email addresses, social-media profiles and device/application details.
- Screenshots and exports of chats, call logs, transaction messages, fake documents, QR codes and advertisements.
- A short chronology explaining the representation made, why it was false, how the victim relied on it and how money was transferred.
- The bank’s complaint number, blocking reference, chargeback/dispute reference and response, if any.
Do not upload altered screenshots or reconstructed chats as if they were originals. Keep original files and devices. For evidentiary treatment of electronic records, see our guide to the Bharatiya Sakshya Adhiniyam, 2023, including Section 63 requirements where applicable.
3. Is a 1930 or NCRP Complaint the Same as an FIR?
No. The NCRP acknowledgment records a cyber complaint and supports financial tracing, but it should not be assumed to be an FIR. The competent police unit examines the facts and takes action under the BNSS and applicable substantive offences. Where the information discloses a cognizable offence, FIR-registration principles apply.
If the police refuse to register or act on information disclosing a cognizable offence, Section 173(4) BNSS permits the aggrieved person to send the substance of the information in writing and by post to the Superintendent of Police. If relief is still not obtained, an application supported by an affidavit may be moved before the competent Magistrate under Section 175(3), subject to the statutory process. See our detailed guide: Police Refused FIR? Section 175(3) BNSS.
A private complaint before the Magistrate is another distinct route in appropriate cases; it should not be used mechanically where urgent inter-bank tracing requires police powers. Read more about a private criminal complaint under the BNSS.
4. Which Offences May Apply?
The sections depend on the modus operandi and evidence. Common provisions may include Section 318 of the Bharatiya Nyaya Sanhita, 2023 for cheating and dishonest inducement to deliver property, and Section 319 for cheating by personation. The official BNS text should be applied to the precise allegations.
Under the Information Technology Act, 2000, Section 66C addresses identity theft and Section 66D addresses cheating by personation using a communication device or computer resource. Sections 43 and 66 may be relevant to unauthorised access or computer-related acts when their ingredients are satisfied. The official Information Technology Act, 2000 remains a primary reference.
Labels such as “UPI fraud” or “investment scam” are not offences by themselves. The complaint should plead the deception, identity misuse, inducement, dishonest intention, unauthorised access, transaction trail and each participant’s role.
5. What Does a Bank Hold or Lien Mean?
Through the CFCFRMS/NCRP chain or direct police communication, a beneficiary bank may mark available money under hold, lien or debit restriction. The amount visible as “held” may be the whole reported sum or only the balance remaining when the alert reached that account. Different banks use different operational terminology.
A hold is protective and provisional. It does not by itself decide:
- whether the complainant is the lawful owner of the held amount;
- whether multiple victims have claims against the same balance;
- whether the account holder is an accused, a negligent recipient, a merchant, or an innocent downstream recipient;
- whether the money is the same property, traceable proceeds or unrelated funds; or
- which authority has power to order release.
The investigating officer and court may require bank statements, nodal-officer confirmations, the layer trail and claims of other victims. For the position from the account-holder’s side, see Bank Account Frozen Due to a UPI Transaction.
6. Police Seizure Under Section 106 BNSS
Section 106(1) BNSS authorises a police officer to seize property alleged or suspected to have been stolen or found under circumstances creating suspicion of the commission of an offence. Under Section 106(3), the seizure must be reported forthwith to the Magistrate having jurisdiction. The complete provision appears in the official Bharatiya Nagarik Suraksha Sanhita, 2023.
The Supreme Court held in State of Maharashtra v. Tapas D. Neogy, (1999) 7 SCC 685, that a bank account can constitute “property” for Section 102 CrPC, the predecessor of Section 106 BNSS. Teesta Atul Setalvad v. State of Gujarat, (2018) 2 SCC 372, also concerns freezing of accounts under that power. More recently, State of West Bengal v. Anil Kumar Dey, 2025 INSC 1413, reaffirmed the availability of the Section 102 seizure power in its statutory setting; the official Supreme Court judgment must be read for its facts and the interaction with special-law attachment.
Why Magistrate reporting matters
A victim seeking return should obtain, through lawful process, the FIR/complaint particulars, seizure or freeze communication, bank response, amount held and information showing whether the seizure was reported to the jurisdictional Magistrate. A mere bank email saying “cyber lien” may not reveal the legal foundation or the court competent to pass the next order.
7. Attachment and Restoration Under Section 107 BNSS
Section 107 provides a distinct court-supervised mechanism. Where an investigating police officer believes that property was derived or obtained directly or indirectly from criminal activity or an offence, the officer may—with approval of the Superintendent or Commissioner of Police—apply to the competent Court or Magistrate for attachment.
The provision ordinarily contemplates a show-cause notice and opportunity of hearing. An interim ex parte attachment or seizure may be ordered if notice would defeat the object. If the Court or Magistrate finds the property to be proceeds of crime, Section 107(6) directs the District Magistrate to distribute the proceeds rateably among affected persons. Under Section 107(7), distribution is to occur within sixty days of receipt of that order.
Important: Section 107 is not an automatic “60-day refund rule” from the date of cyber fraud. The sixty-day period concerns distribution by the District Magistrate after receipt of a qualifying court order under Section 107(6). The investigating officer must first invoke the statutory process, and the court must determine that the attached or seized property is proceeds of crime.
8. Applications Under Sections 497 and 498 BNSS
Section 497 empowers the Criminal Court or the Magistrate competent to take cognizance or commit the case for trial to make appropriate custody or disposal orders when property is produced during investigation, inquiry or trial. Section 498 governs disposal at the conclusion of the investigation, inquiry or trial and permits delivery to a person claiming entitlement, with or without a bond.
Which provision should be invoked depends on the procedural stage, how the funds were seized or produced, whether the investigating officer supports release, whether rival claims exist and how the local court treats electronic money or account balances. A carefully drafted application should not simply cite every property provision without explaining why that court has jurisdiction and how the specific funds are traceable to the applicant.
9. What a Victim’s Money-Release Application Should Contain
- Court, police station/cyber unit, FIR or complaint number, penal sections and present stage of investigation.
- A concise fraud chronology and itemised transaction table.
- Proof that the applicant owned and remitted the money.
- NCRP/1930 acknowledgment and the complaint supplied to police and banks.
- Beneficiary and layer-account trail available from the case record or bank nodal responses.
- Exact amount held in each account, avoiding a claim exceeding the traceable balance.
- The statutory basis for seizure/attachment and the provision under which release, restoration or distribution is sought.
- Disclosure of insurance, chargeback, bank credit, settlement or any other recovery to prevent double payment.
- Undertaking or bond to comply with further court directions, if required.
- A precise prayer identifying the bank, account, held amount and mode of remittance back to the verified victim account.
The bank and account holder may need notice depending on the provision and stage. The investigating officer’s status report is often decisive. Where several victims claim one balance, the court may decline first-come-first-served payment and require a rateable or otherwise legally structured distribution.
10. RBI Rules on Unauthorised Electronic Transactions
The RBI’s 6 July 2017 directions on limiting customer liability in unauthorised electronic banking transactions create a separate bank-customer remedy for covered accounts and transactions.
| Situation under RBI directions | Customer-liability principle |
|---|---|
| Bank’s contributory fraud, negligence or deficiency | Zero liability, regardless of when the customer reports, subject to the directions |
| Third-party breach with no fault attributable to bank or customer; reported within three working days of bank communication | Zero liability |
| Qualifying third-party breach reported in four to seven working days | Limited liability up to the lower of transaction value or the applicable RBI cap |
| Customer negligence, such as sharing payment credentials | Customer bears loss until reporting; loss after reporting is borne by the bank |
| Reporting after seven working days | Liability follows the bank’s board-approved policy |
For a qualifying zero- or limited-liability claim, the RBI directions require shadow reversal within ten working days of notification and resolution/customer-liability determination within the bank’s policy period, not exceeding ninety days. The bank bears the burden of proving customer liability under those directions.
Why every cyber scam does not produce a bank refund
A transaction may be “unauthorised” because the customer never initiated or approved it. In contrast, a victim may personally authorise a UPI transfer after being deceived by a fake investment platform, police impersonator or task scam. That remains potential cheating and cybercrime, but the bank may dispute whether the RBI unauthorised-transaction liability framework applies. The facts—particularly OTP/PIN sharing, device compromise, mandate approval and transaction authentication—must be analysed instead of assuming automatic zero liability.
11. RBI Ombudsman Route in 2026
Where the grievance concerns deficiency in service by an RBI-regulated entity, the customer must first complain to that entity. Under the Reserve Bank–Integrated Ombudsman Scheme, 2026, an Ombudsman complaint may be filed if the customer receives an unsatisfactory reply or no reply within thirty days, or within the longer timeline specified by RBI, NPCI or the card network where applicable.
The complaint must generally be filed within ninety days from expiry of the applicable response timeline or from the regulated entity’s last communication, whichever is later. Filing through RBI’s Complaint Management System is free. Maintainability exclusions apply, including where the same grievance is already pending or decided on merits before a court, tribunal, arbitrator or other judicial/quasi-judicial forum. A police investigation or criminal proceeding is not treated as the same grievance merely for that reason, according to the RBI’s official FAQ.
The Ombudsman route addresses service deficiency. It is not a substitute for reporting the fraud to 1930/police and cannot be treated as a universal recovery forum against an unknown fraudster.
12. Jurisdiction for Cyber-Cheating Cases
Sections 197 to 204 BNSS govern place of inquiry and trial. Section 202 specifically provides that an offence including cheating, where deception is practised through electronic communications, letters or telecommunication messages, may be inquired into or tried where the communication was sent or received. Cheating and dishonest inducement to deliver property may also be tried where the property was delivered by the person deceived or received by the accused.
This can create jurisdiction in more than one place, particularly where the victim, fraudster, remitting bank, beneficiary bank and devices are in different States. The police unit and court for a release application should be identified from the FIR, seizure report and investigation—not selected only for convenience.
13. Court Fee, Limitation and Delay
- Reporting on 1930/NCRP is free.
- A police complaint or FIR does not carry an ad valorem court fee.
- An application before a criminal court generally attracts only the filing requirements and any fixed court fee prescribed by the relevant State court-fees law/rules; there is no single nationwide fee for every cyber-recovery application.
- An RBI Ombudsman complaint is free.
- The criminal-law limitation provisions depend on the offences and punishment; serious cheating cases should not be delayed while limitation is calculated.
- Bank-liability and Ombudsman timelines are separate and may expire even while police investigation continues.
- Civil claims, contractual disputes, writ remedies and consumer proceedings have their own limitation, maintainability and court-fee rules.
The practical rule is to report immediately and obtain acknowledgments. Delay may not erase the offence, but it weakens real-time tracing, permits withdrawal or layering, and may adversely affect a bank-liability claim.
14. Evidence Checklist
| Evidence | Why it matters |
|---|---|
| Bank statement and transaction references | Proves debit, amount, time, channel and initial destination |
| 1930/NCRP acknowledgment | Shows reporting time and complaint identity |
| Bank complaint and nodal correspondence | Shows notice, requested recall/hold and bank response |
| Chats, emails, call logs and profile/URL captures | Proves representation, identity, inducement and communication route |
| Original device and application records | May show remote access, malware, session history or authentication |
| Police/FIR and seizure documents | Identifies investigation, legal power, accounts and Magistrate |
| Layer-account chart | Links the victim’s remittance to funds held downstream |
| Affidavit and Section 63 BSA certificate where required | Supports admissibility and authenticity of electronic records |
| Recovery/insurance/chargeback disclosure | Prevents duplication and supports an accurate balance claim |
15. Common Mistakes That Reduce Recovery Prospects
- Waiting for the branch to open instead of using 1930 and the bank’s 24×7 fraud channel.
- Reporting only the fraudster’s phone number without transaction references and beneficiary details.
- Assuming the NCRP complaint itself is an FIR or final refund order.
- Deleting chats, resetting the phone or uninstalling the remote-access app before preserving evidence.
- Paying a private agent who claims to have an “RBI portal”, “cyber cell contact” or guaranteed unfreeze code.
- Seeking release of the entire loss from an account holding only a smaller traceable balance.
- Ignoring notices to the account holder, bank or other claimants where the court requires them.
- Failing to disclose chargeback, provisional credit, insurance or recovery received elsewhere.
- Using unlawful access, threats or public doxxing to pursue a suspected mule-account holder.
Practical Recovery Workflow
- Stop further transactions and secure the banking channel/device.
- Report through 1930, NCRP and the remitting bank immediately.
- Give the cyber police a signed chronology and transaction table.
- Track the complaint by acknowledgment/FIR number and obtain the investigating officer’s details.
- Ask for the beneficiary/layer-account status and exact amount held through lawful channels.
- Determine whether the hold is administrative, under Section 106 seizure, Section 107 attachment or another law.
- Move the jurisdictional court with the correct statutory application and complete traceability documents when police verification and procedural stage permit.
- Pursue the bank-liability complaint separately where the transaction was unauthorised and RBI directions apply.
- Escalate service deficiency through the regulated entity’s grievance hierarchy and, when maintainable, RBI Ombudsman.
- Keep a recovery ledger showing every amount held, released, reversed, insured or still outstanding.
Frequently Asked Questions
Can money be recovered after reporting a cyber fraud to 1930?
Yes, recovery is possible when funds are traced and remain available, but 1930 does not guarantee a refund. It helps initiate rapid coordination and holds. Final return may require police verification, bank action or a court order.
How quickly should a cyber fraud be reported?
Immediately. Do not wait for a lawyer, branch visit or complete documentation before making the first 1930 and bank reports. Supplement the complaint with documents as soon as possible.
Is the NCRP acknowledgment an FIR number?
No. It is a cyber-complaint acknowledgment. Police must separately determine FIR registration and investigation under the BNSS.
What is the difference between a lien and a refund?
A lien or hold restricts use of available funds. A refund transfers money back to the victim after the bank or competent authority is legally satisfied. The first does not automatically create the second.
Can the police freeze a bank account under BNSS?
Section 106 BNSS authorises seizure of specified suspicious property and requires reporting to the jurisdictional Magistrate. Whether a particular full-account freeze or amount-specific lien is lawful depends on nexus, procedure and facts.
What does Section 107 BNSS provide for victims?
It permits court-supervised attachment of property believed to be proceeds of crime and, after the statutory finding, rateable distribution through the District Magistrate to affected persons.
Can a victim apply directly to the Magistrate for release?
A victim may move the competent court, but the correct provision and relief depend on how the money was held, the FIR and investigation stage, traceability, rival claims and whether the property is before the court. The investigating officer and bank are commonly called upon to report.
Will the bank reimburse a UPI payment made by the victim?
Not automatically. If the victim personally authorised the payment after deception, the bank may contend that it was not an “unauthorised transaction” under RBI customer-liability directions. Criminal tracing and recovery may still remain available.
Can RBI Ombudsman recover money from the fraudster?
The Ombudsman considers deficiency in service by a regulated entity. It does not investigate or prosecute the unknown fraudster. Police/NCRP action must continue separately.
Is a lawyer required to file the 1930 or NCRP complaint?
No. The victim can report directly and should not delay. Legal assistance may become useful for FIR escalation, complex multi-State tracing, bank disputes, Magistrate applications, writ proceedings or competing claims.
Conclusion
Cyber fraud money recovery requires parallel, disciplined action: rapid 1930/NCRP reporting, immediate bank notice, evidence preservation, police tracing, and the correct statutory application for held funds. Sections 106 and 107 BNSS now provide important seizure, attachment and restoration architecture, while Sections 497–498 address property during and after proceedings. RBI liability rules and the 2026 Ombudsman mechanism may offer additional relief where the dispute concerns an unauthorised electronic banking transaction or service deficiency.
The strongest case is not the longest complaint. It is the complaint that identifies every transaction, preserves the deception and authentication evidence, proves ownership, tracks the money through each layer and asks the competent authority for a precise, legally available order.
This article provides general legal information as of 20 August 2026. It is not legal advice, solicitation, or a guarantee of recovery. Cyber-fraud procedures, bank policies, court practice and statutory interpretation are fact-specific and may change. Urgent reporting should not be delayed while seeking advice.