
Cyber law India 2026 victim rights are useful only when you know the conditions, deadlines, and correct complaint route. A bank dispute, police complaint, consumer case, and regulator grievance are different processes. One does not automatically replace another.
That distinction matters now. On 28 July 2026, the Ministry of Home Affairs said the national financial cyber fraud system had helped save more than ₹11,158 crore across over 32.80 lakh complaints by 30 June 2026. The same update confirmed that 1930 helps citizens lodge financial cyber fraud complaints and that a Money Restoration Module became functional in April 2026. Saved or blocked money is not the same as an automatic refund, but fast reporting can materially improve the chance of stopping its movement.
This guide explains five practical rights, the IT Act India cyber fraud provisions, BNS cyber fraud India 2026 charges, the accurate RBI zero liability rule India, and how to file FIR cyber fraud India without relying on viral legal claims. It is general information, not advice for a specific case.
If money moved today
Call 1930 immediately, report the transaction through your bank's official fraud channel, obtain both acknowledgement numbers, then complete the complaint at cybercrime.gov.in. Do not wait to finish reading.
Why Knowing Your Legal Rights Changes Everything
Fraud victims are often told one of two wrong extremes: that every authorised transfer is unrecoverable, or that every unauthorised transaction must be refunded in three days. The real position is evidence-based. Who initiated the transaction, whether a payment credential was shared, when the bank alert arrived, when the customer reported, and what the bank's systems recorded can determine liability.
Knowing your rights changes the conversation. Instead of asking a branch for sympathy, you can submit a dated dispute referring to the RBI circular, request the complaint number and system evidence, and escalate a service failure through RBI CMS or a consumer commission. Instead of accepting a jurisdiction objection at a police station, you can refer to BNSS Section 173 and submit information about a cognizable offence irrespective of where it occurred.
Keep one evidence file. Include the bank statement, disputed transaction IDs, bank alerts, complaint timestamps, 1930 and portal acknowledgement numbers, FIR or diary entry, emails with full headers, chat exports, phone numbers, URLs, beneficiary details, device logs, and every bank response. A recent NCDRC case turned on the absence of bank evidence proving that the customer shared an OTP. Evidence is how a general protection becomes usable in your case.
Your 5 Key Rights as a Cyber Fraud Victim in India
Right 1: Zero or Limited Liability for Unauthorised Bank Transactions
The RBI zero liability rule India is set out in the RBI circular dated 6 July 2017. Zero liability applies when the unauthorised electronic transaction resulted from bank fraud, negligence, or deficiency, regardless of when the customer reports it. It also applies to a third-party breach where neither the bank nor customer is at fault if the customer notifies the bank within three working days of receiving the transaction communication.
If that third-party breach is reported in four to seven working days, liability is limited to the transaction value or the applicable RBI cap, whichever is lower. After seven working days, the bank's board-approved policy applies. If the loss arose from customer negligence, such as sharing a payment credential, the customer bears loss up to the time of reporting, but the bank bears any later unauthorised loss.
The RBI circular also requires a shadow credit within 10 working days after notification for a qualifying unauthorised transaction, resolution within 90 days, and places the burden of proving customer liability on the bank. Report first, argue classification second. Ask for the exact reason, evidence, and policy clause if the claim is rejected.
Right 2: Give Information About a Cognizable Offence at Any Police Station
For an online fraud FIR India complaint, BNSS Section 173 says information relating to a cognizable offence may be given orally or electronically to the officer in charge of a police station, irrespective of where the offence occurred. Electronic information must be signed within three days. This supports the practical Zero FIR route when the place of occurrence is uncertain or outside the station's area.
The careful legal point is that not every online dispute automatically discloses a cognizable offence. The alleged conduct and sections determine classification. If your facts disclose cognizable identity theft, personation, cheating that induced delivery of property, extortion, or a connected offence, provide the facts and evidence rather than insisting on a guessed section.
If the station refuses to record information disclosing a cognizable offence, BNSS Section 173(4) allows you to send the substance in writing by post to the Superintendent of Police. If satisfied, the SP must investigate or direct an investigation. If that still fails, apply to the Magistrate. File the cybercrime portal complaint in parallel, but understand that a portal acknowledgement is not itself an FIR.
Right 3: Seek Consumer Redress for Deficiency in Service
The Consumer Protection Act 2019 can help when the dispute concerns deficiency in service or an unfair trade practice by a bank, payment provider, insurer, platform, or business. It is not a universal recovery case against an unidentified scammer. Name the service provider whose failure you can prove, describe the duty and breach, and attach the financial loss and complaint trail.
Start with the company's grievance process. The National Consumer Helpline offers pre-litigation support, and the government's e-Jagriti portal supports consumer commission filings. A lawyer is not mandatory, but complex evidence or a large claim may justify legal advice.
Right 4: Escalate to the Financial Regulator for Service Failures
Use the regulator that supervises the service provider. For a bank, eligible NBFC, or covered payment participant, first complain to the regulated entity. If it rejects the complaint, partly rejects it, gives an unsatisfactory answer, or does not respond within 30 days, the RBI Integrated Ombudsman Scheme offers cost-free redress through RBI CMS.
For a grievance involving a SEBI-regulated entity, first approach the entity and then use SEBI SCORES. For an insurer, use the insurer's grievance channel and IRDAI Bima Bharosa. Regulators address failures by regulated entities. They do not replace a 1930 report or police investigation against the scammer.
Right 5: Use Current Data-Security Remedies and Track the DPDP Transition
The DPDP Act India 2026 position needs special care. The DPDP Act 2023 and DPDP Rules 2025 have phased commencement. As of 5 August 2026, core duties involving reasonable security safeguards, breach intimation, and Data Principal rights are scheduled for the later phase after the 18-month transition in May 2027. A victim should not claim that the future breach-notification framework already guarantees compensation today.
During this transition, IT Act Section 43A remains relevant where a body corporate handling sensitive personal data is negligent in maintaining reasonable security practices and that negligence causes wrongful loss or gain. The facts, type of data, applicable rules, causation, and forum still need proof. Contract, consumer, sectoral, and tort remedies may also matter. Preserve the breach notice, the organization's privacy policy, consent records, support replies, and evidence connecting the exposure to later fraud.

Accuracy note for the visual: the RBI protection is conditional, an FIR depends on facts disclosing a cognizable offence, and the DPDP security and breach duties are in phased commencement. The detailed text above states the position as verified on 5 August 2026.
The Laws That Protect You: IT Act, BNS, RBI Rules, and Consumer Law
Key laws protecting cyber fraud victims in India in 2026:
- IT Act Section 43A: a current compensation provision for qualifying loss caused by a body corporate's negligent protection of sensitive personal data.
- IT Act Sections 66C and 66D: identity theft and cheating by online personation are offences punishable by up to three years and a fine up to ₹1 lakh.
- RBI Customer Protection Circular: zero or limited liability can apply to unauthorised electronic banking transactions based on fault and reporting time.
- BNS Sections 318 and 319: cheating and cheating by personation apply based on the facts. Dishonest inducement to deliver property under Section 318(4) can carry up to seven years and a fine.
- Consumer Protection Act 2019: a victim can seek redress for proven deficiency in service or unfair trade practice by a service provider or business.
- DPDP Act 2023 and Rules 2025: India's new data protection regime is rolling out in phases, with the principal security, breach, and individual-rights duties scheduled for May 2027.
You usually do not need a lawyer to call 1930, report at cybercrime.gov.in, dispute a bank transaction, complain through RBI CMS, or approach the National Consumer Helpline. Legal help can be valuable when liability is contested, evidence is technical, an FIR route stalls, or the amount is substantial.

Transition note: the DPDP row in the visual is a high-level summary, not a present automatic compensation promise. See Right 5 for the August 2026 commencement position.
How to File a Cyber Fraud FIR in India
Use this file FIR cyber fraud India sequence while continuing the bank and 1930 process:
- Gather evidence. Save statements, transaction IDs, screenshots, chat exports, caller numbers, email headers, URLs, device details, and the exact timeline.
- Report financial loss immediately. Call 1930 and complete the complaint at cybercrime.gov.in. Save the acknowledgement number.
- Notify the bank separately. Use its official 24-hour fraud channel. Block compromised payment instruments and request written acknowledgement.
- Give the police a factual complaint. State how the deception, personation, identity misuse, threats, or unauthorised access occurred and what property was delivered or removed.
- Ask for the recorded reference. Obtain the FIR number when registered, or the diary, CSR, NCR, or acknowledgement details used in your state.
- Escalate a refusal correctly. For facts disclosing a cognizable offence, write to the SP under BNSS Section 173(4), then approach the Magistrate if necessary.
Do not surrender your only phone or original records without documenting what was handed over and receiving an acknowledgement. Preserve the original evidence and provide copies or exports when appropriate. Do not contact money mules or attempt a private recovery that may alert the network.

What Scammers Are Charged Under and Why It Matters
Victims do not have to draft a charge sheet. Still, knowing the structure helps you describe the facts:
- IT Act Section 66C: dishonest or fraudulent use of another person's electronic signature, password, or unique identification feature.
- IT Act Section 66D: cheating by personation using a communication device or computer resource. The maximum is three years plus a fine up to ₹1 lakh.
- BNS Section 318: cheating. The penalty varies by subsection. Section 318(4), dishonest inducement to deliver property or alter valuable security, can reach seven years and a fine.
- BNS Section 319: cheating by personation, relevant where a scammer pretends to be a police officer, bank employee, relative, executive, or regulator.
- BNS Section 308: extortion, potentially relevant where threats are used to obtain money.
- BNS Section 351: criminal intimidation, potentially relevant to threats in digital arrest, sextortion, and loan app harassment.
BNS Section 317 concerns stolen property, not a special digital arrest offence. The commonly shared claim that every digital arrest scam is charged under Section 317 is therefore incorrect. Police may add forgery, organized crime, conspiracy, money laundering, or other provisions if the evidence supports them.
The distinction also affects FIR procedure. Under the BNSS classification schedule, cheating that dishonestly induces delivery of property under BNS Section 318(4) is cognizable and non-bailable, while simple cheating under Section 318(2) is non-cognizable and bailable. Describe the money transfer and deception clearly so the facts are not reduced to a vague online dispute.
Real 2026 Victim Cases: Rights Worked When Evidence Was Preserved
Same-day report after a fake electricity bill app
In April 2026, The Indian Express reported that the NCDRC upheld an order directing SBI to refund ₹1.99 lakh and pay ₹25,000 compensation. The customer had downloaded a fake electricity app, but the commission found no proof that he shared an OTP and noted that he reported the fraud to the bank and cybercrime police the same day. This is a reported commission order based on its evidence, not a rule that downloading any malicious app always produces a refund.
Retired professor's ₹12.93 lakh unauthorised withdrawals
In May 2026, The Indian Express reported that the NCDRC dismissed SBI's appeal and upheld refund, interest, compensation, and costs for a retired professor. The commission said the bank had not produced technical logs proving that the customer shared payment credentials and applied paragraph 6(ii) of the RBI circular. This shows why victims should ask a bank to state and prove its negligence allegation.
Gurgaon consumer case after a fake renewal email
In June 2026, The Indian Express reported that a Gurgaon District Consumer Commission directed Axis Bank to refund ₹2.34 lakh and awarded additional relief after a business owner followed a fraudulent website-renewal email. The report says the commission relied on unrebutted evidence, including emails, transactions, the bank complaint, and cybercrime complaint. Consumer outcomes remain fact-specific and may be appealed.
National reporting system data
The strongest national evidence for acting quickly is operational, not anecdotal. A 28 July 2026 MHA response said CFCFRMS had saved more than ₹11,158 crore across more than 32.80 lakh complaints by 30 June 2026. It also said complaint-to-FIR conversion and investigation are handled by State and Union Territory law-enforcement agencies. A portal complaint therefore starts a process; it does not promise an FIR, court order, or refund by itself.
If you have already paid, follow the full online fraud money recovery guide. For the first emergency actions, use Got scammed online in India: what to do. If someone asks to rent your account or route recovered money, read the mule account legal risk guide.
Source Credits and Legal References
- RBI circular dated 6 July 2017 on customer liability for unauthorised electronic banking transactions.
- Ministry of Finance update dated 24 March 2026 confirming that revised RBI instructions were still issued for public consultation.
- India Code, Information Technology Act 2000, including Sections 43A, 66C, and 66D.
- India Code, Bharatiya Nyaya Sanhita 2023, including Sections 308, 318, 319, and 351.
- India Code, Bharatiya Nagarik Suraksha Sanhita 2023, including Section 173 and the offence classification schedule.
- MeitY, DPDP Rules 2025 and enforcement timeline.
- Ministry of Home Affairs update dated 28 July 2026 on CFCFRMS 2.0, 1930, saved funds, and restoration modules.
- The three case studies above are credited and linked individually to their reporting by The Indian Express.
Frequently Asked Questions
What is the RBI zero liability rule for online fraud in India?
Under RBI’s 6 July 2017 circular, zero customer liability applies when the bank caused the unauthorised electronic transaction, or when a third-party breach occurred without customer or bank fault and the customer notified the bank within three working days of receiving the transaction communication. If customer negligence such as sharing a payment credential caused the loss, the customer bears loss until reporting, while later loss is borne by the bank. The bank has the burden of proving customer liability.
Can police refuse to file an FIR for cyber fraud in India?
BNSS Section 173 lets a person give information about a cognizable offence to any police station regardless of where it occurred. Not every cyber complaint is automatically cognizable, so the facts and alleged sections matter. If an officer refuses to record information that discloses a cognizable offence, send it in writing to the Superintendent of Police under BNSS Section 173(4), then apply to the Magistrate if needed. You can also report at cybercrime.gov.in.
What are scammers charged under in India?
Common provisions include IT Act Sections 66C and 66D for identity theft and online personation, BNS Section 318 for cheating, BNS Section 319 for cheating by personation, BNS Section 308 for extortion, and BNS Section 351 for criminal intimidation. The exact charge and penalty depend on the facts. BNS Section 318(4), involving dishonest inducement to deliver property, can carry up to seven years and a fine.
What does the DPDP Act mean for fraud victims in August 2026?
The DPDP Act and 2025 Rules have a phased commencement. As of 5 August 2026, the core duties on security safeguards, breach notification, and Data Principal rights are scheduled for the later phase in May 2027. Victims should not present those future duties as an already available compensation guarantee. IT Act Section 43A remains relevant to negligent data security claims during the transition, and other consumer, contract, banking, and criminal remedies may also apply.
How do I file a consumer complaint for online fraud in India?
A consumer complaint can be relevant when a bank, payment provider, insurer, platform, or business allegedly caused deficiency in service or used an unfair trade practice. First complain to the provider and preserve the response. Use the National Consumer Helpline for pre-litigation support and the official e-Jagriti system for a consumer commission filing. An unknown scammer alone is generally a police matter, not a substitute for a service-deficiency case.
Use your rights while the evidence is fresh
Call 1930, notify your bank, preserve every acknowledgement, and use the correct police, regulator, or consumer route. Share this guide with someone who may otherwise accept a rejection without asking for the evidence.
Open RakshaAIMore from RakshaAI Blog
Stay Protected Online
Use RakshaAI to check websites, phone numbers, and UPI IDs for scams free, instant, no sign-up required.
RakshaAI is a private platform by Ehatech Services Pvt. Ltd. Not affiliated with any government body. Editorial policy


