CYBERRAKSHAK LABS ยท RESEARCH #026

๐Ÿšจ Spotted Card Fraud in India? Hereโ€™s Exactly What to Do in the First 30 Minutes

Your first 30 minutes can be more important than the next 30 days. This practical response plan focuses on containment, reporting, evidence preservation and account security after suspected card or online financial fraud.

By Vivek Kumar ยท Published 9 September 2026
RESEARCH#026
CATEGORYCyber Fraud / Cyber Awareness
CRL ASSESSMENTHIGH
RESEARCH LEVELThreat Analysis
PUBLISHED2026-09-09
Source & social links:
LinkedIn Post โ†— WhatsApp โ†— YouTube โ†—
How CyberRakshakLabs researches threats โ†’
STOP THE MONEY. SECURE THE ACCOUNT. REPORT THE FRAUD. PRESERVE THE EVIDENCE.
If you discover an unauthorised transaction, don't spend the first 30 minutes arguing with the person who contacted you. Your priority is to reduce further loss and create an evidence trail.
0โ€“5Block & contain
5โ€“10Contact the bank
10โ€“15Call 1930

Executive Summary

A card transaction appears that you don't recognise. Then another one appears. You panic โ€” and perhaps call the number included in the SMS.

The person answering says: โ€œDon't worry. We will reverse the transaction. Just share the OTP.โ€

STOP.
That may be the second stage of the attack. A genuine bank representative should not require you to disclose your OTP, PIN or password.

The first objective is not to investigate the scammer. It is to contain the incident, report it through official channels and preserve the information investigators may need.

๐Ÿšจ The First 30-Minute Emergency Plan

0โ€“5 MIN ยท STOPโ†’ 5โ€“10 MIN ยท BANKโ†’ 10โ€“15 MIN ยท 1930โ†’ 15โ€“20 MIN ยท REPORTโ†’ 20โ€“25 MIN ยท EVIDENCEโ†’ 25โ€“30 MIN ยท SECURE
0โ€“5 Minutes: STOP THE BLEEDING

1. Block the card immediately

Use your bank's official app, website or card-issuer helpline. Where the bank provides separate controls, disable the affected payment channels.

๐Ÿ›‘ Debit card
๐Ÿ›‘ Credit card
๐Ÿ›‘ International transactions
๐Ÿ›‘ Online/card-not-present transactions
๐Ÿ›‘ ATM/POS channels where appropriate
๐Ÿ›‘ Other affected payment controls

Do not call a number supplied by the suspicious SMS. Use the number printed on the back of your card or the bank's official website/app.

2. Check whether more transactions are happening

Don't look only at the transaction that alerted you. Review the wider payment surface:

Payment accounts

Bank account, debit card, credit card, UPI, wallets and linked accounts.

Red flags

Small test transactions, multiple merchants, recurring payments, ATM withdrawals, international transactions and new beneficiaries.

Fraudsters may use a small transaction to test a compromised payment instrument before attempting larger transactions.

5โ€“10 Minutes: CONTACT YOUR BANK

Call the bank's official fraud/customer-service channel and clearly state that you are reporting an unauthorised transaction.

โ€œI am reporting an unauthorised transaction. Please block the affected card/payment channel and register a fraud/dispute complaint.โ€

Ask for:

โœ… Complaint/reference number
โœ… Exact complaint registration time
โœ… Confirmation that the affected channel is blocked
โœ… Dispute/chargeback process, where applicable
โœ… Any additional security action required
โœ… Written acknowledgement, if available

RBI guidance requires banks offering e-banking services to provide 24ร—7 reporting channels for unauthorised transactions and to take immediate steps to prevent further unauthorised transactions after a report.

10โ€“15 Minutes: CALL 1930
๐Ÿ“ž 1930 โ€” National Cyber Crime Helpline
For cyber financial fraud in India, the official National Cyber Crime Reporting Portal directs victims to report immediately through 1930 or the online portal. The helpline is listed as 24ร—7 on the government portal.

The reason speed matters is simple: stolen funds may move through multiple accounts or channels before they are withdrawn or converted.

Victim Accountโ†’Fraudster Accountโ†’Mule Accountโ†’Another Muleโ†’Cash / Crypto / Other Channel

The government portal currently identifies 1930 as the immediate-reporting channel for cyber financial fraud.

Have these details ready

๐Ÿ“ฑ Mobile number
๐Ÿฆ Bank name
๐Ÿ’ณ Account/card details
๐Ÿ’ฐ Transaction amount
๐Ÿ•’ Transaction date/time
๐Ÿ”ข Transaction ID / UTR / RRN
๐Ÿช Merchant/beneficiary information
๐Ÿ“ž Fraudster's phone number
๐Ÿ”— UPI ID, if applicable
๐Ÿ“ธ Screenshots and supporting evidence

The National Cyber Crime Reporting Portal provides financial-fraud reporting and asks complainants to provide transaction and supporting information.

15โ€“20 Minutes: FILE THE CYBERCRIME COMPLAINT

Do not rely only on the phone call. Use the official National Cyber Crime Reporting Portal and select the appropriate financial-fraud reporting option.

After submitting the complaint, save the acknowledgement/complaint number. It becomes part of your evidence trail.

Official route: cybercrime.gov.in ยท Immediate financial-fraud helpline: 1930

20โ€“25 Minutes: PRESERVE THE EVIDENCE

This is where many victims make a mistake. They delete the SMS, delete WhatsApp conversations, block the scammer, uninstall the suspicious app โ€” and later realise that useful evidence has disappeared.

Don't delete anything yet.
Preserve the suspicious messages, transaction alerts, screenshots, phone numbers, UPI IDs, URLs, emails, app details, bank complaint number, 1930 reference and NCRP acknowledgement.

Keep the original information intact where possible. If you need to block a number or account, capture the relevant evidence first.

25โ€“30 Minutes: SECURE YOUR DIGITAL ENVIRONMENT

If only card details were compromised, blocking the card may address the immediate payment risk. But if you also entered other credentials, assume the incident may be broader.

๐Ÿ”‘ Change banking password
๐Ÿ”‘ Change email password
๐Ÿ›ก๏ธ Enable MFA
๐Ÿ“ฑ Review active sessions/devices
๐Ÿšซ Remove unknown devices
๐Ÿ‘ค Check newly added beneficiaries
๐Ÿ”„ Review UPI mandates/autopay
๐Ÿ“ฒ Check for suspicious apps

If you installed a remote-access application at the scammer's request, treat the device as potentially compromised and seek appropriate technical assistance.

๐Ÿ”ด One of the Biggest Mistakes: Calling the Scammer Back

Imagine seeing:

โ€œโ‚น25,000 debited from your account.โ€

You call the number in the SMS. Someone answers:

โ€œSir, don't worry. We are from the bank's fraud department.โ€

Then: โ€œPlease tell me the OTP you just received.โ€

STOP. That OTP may be the authorisation required for another fraudulent transaction.

A genuine bank representative should not require you to disclose your OTP, PIN or password.

โš ๏ธ What If I Accidentally Shared My OTP?

Don't wait and don't assume the damage is already done.

BLOCK CARDโ†’CONTACT BANKโ†’CHANGE COMPROMISED CREDENTIALSโ†’1930โ†’NCRPโ†’PRESERVE EVIDENCE

The fact that an OTP was shared does not mean you should stop reporting. However, customer liability can depend on the circumstances, including whether payment credentials were shared. RBI's framework specifically distinguishes customer negligence from third-party/system breaches.

๐Ÿ›ก๏ธ Understanding Your RBI Protection

This is one of the most misunderstood parts of a financial-fraud incident.

SituationWhat the RBI framework says
Bank negligence / deficiencyCustomer liability is zero, subject to the framework.
Third-party breach; no customer negligence; report within 3 working daysZero liability.
Third-party breach; report in 4โ€“7 working daysLiability is limited according to the applicable framework and account/card category.
Report beyond 7 working daysHandled according to the bank's Board-approved policy.
Customer negligence, such as sharing payment credentialsCustomer bears the loss until the transaction is reported; losses after reporting are treated differently under the framework.

RBI's customer-protection framework also states that banks should provide an acknowledgement for the complaint and take immediate steps after receiving a report.

CyberRakshakLabs takeaway: Don't wait to debate liability. Report immediately. The bank and the investigation can determine the applicable circumstances.
๐Ÿ’ฐ Does Reporting Guarantee a Refund?

No. Calling 1930 does not automatically guarantee that the money will be returned.

The outcome can depend on:

โฑ๏ธ How quickly the fraud was reported
๐Ÿ”Ž Whether funds can still be traced
๐Ÿ’ธ Whether money has been withdrawn
๐Ÿ” Whether it moved through multiple accounts
๐Ÿ’ณ Type of transaction
๐Ÿงพ Whether it was genuinely unauthorised
๐Ÿ‘ค Customer conduct
๐Ÿฆ Bank/payment-system investigation
โš–๏ธ Law-enforcement action
๐Ÿงฉ Other case-specific factors

The purpose of rapid reporting is to increase the opportunity to stop or trace the money โ€” not to promise automatic recovery.

๐Ÿšจ Beware of the SECOND SCAM

After you report a fraud, someone may contact you claiming:

โ€œYour money has been recovered.โ€
โ€œPay โ‚น5,000 processing charges.โ€
โ€œInstall this application to receive your refund.โ€
โ€œShare your OTP to release the frozen amount.โ€

This can be another scam. Use only official government and bank channels.

โŒ OTP
โŒ UPI PIN
โŒ Card PIN
โŒ Banking password
โŒ Remote-access control
โŒ Recovery fee to an unknown person
๐Ÿงช A Realistic 30-Minute Example
TimeAction
10:02SMS shows โ‚น48,000 spent on your card.
10:04Open the bank's official app and block the card.
10:06Call the bank and register an unauthorised-transaction complaint.
10:10Call 1930.
10:15Provide transaction ID, amount, date/time, bank and merchant information.
10:20Submit the NCRP complaint.
10:25Save SMS, screenshots, complaint number, 1930 reference and NCRP acknowledgement.
10:30Secure banking/email accounts and review other payment channels.

That's a much stronger response than spending the first 30 minutes arguing with the scammer.

๐Ÿ”Ž What SOC & Fraud Teams Should Learn

For organisations, the lesson is bigger than individual card fraud. Financial-fraud detection should look for combinations of payment, identity and device anomalies.

Transaction anomalies

Unusual merchant, location, amount, velocity, sudden transaction spikes and new payment instruments.

Account takeover signals

New device, SIM change, password reset, new beneficiary, unusual login and impossible-travel indicators.

Behavioural anomalies

Multiple failed authentication attempts, sudden changes in user behaviour and unusual authentication patterns.

Fraud infrastructure

Known malicious phone numbers, suspicious domains, fake support pages and phishing infrastructure.

๐Ÿ‡ฎ๐Ÿ‡ณ India's Cyber-Fraud Response Ecosystem

The response is no longer simply Victim โ†’ Bank. Rapid reporting can involve several coordinated points in the response chain.

Victimโ†’ Bank / Card Issuerโ†’ 1930โ†’ I4C / CFCFRMSโ†’ Cybercrime Authoritiesโ†’ Financial Institutions / Payment Networks

The practical objective is to shorten the time between Fraud โ†’ Detection โ†’ Reporting โ†’ Fund Interception.

๐Ÿšจ CyberRakshakLabs 30-Minute Checklist

MINUTES 0โ€“5
๐Ÿ›‘ Block card/payment channel
๐Ÿ“ธ Screenshot transaction
MINUTES 5โ€“10
๐Ÿฆ Contact bank
๐Ÿ“ Get complaint number
MINUTES 10โ€“15
๐Ÿ“ž Call 1930
MINUTES 15โ€“20
๐Ÿ’ป File complaint on cybercrime.gov.in
MINUTES 20โ€“25
๐Ÿ“ Preserve evidence
MINUTES 25โ€“30
๐Ÿ” Secure accounts ยท ๐Ÿ“ฑ Check device ยท ๐Ÿ”‘ Change compromised credentials

Official References

National Cyber Crime Reporting Portal: cybercrime.gov.in

RBI โ€” Customer Protection / Unauthorised Electronic Banking Transactions: RBI notification

This research is an awareness and incident-response guide, not legal or financial advice. RBI customer-liability rules can depend on the transaction type, customer conduct and the applicable framework.

When you discover card fraud, don't spend the first 30 minutes trying to understand how the scammer did it.

Your first job is containment.

BLOCK โ†’ BANK โ†’ 1930 โ†’ REPORT โ†’ PRESERVE โ†’ SECURE
Final Takeaway
Every minute matters because digital money can move much faster than a traditional investigation. The best time to stop a cyber fraud is before the money moves. The second-best time is immediately after you discover it.

Think Before You Click. Stay Aware. Stay Secure.

CyberRakshakLabs โ€” Threat Intelligence for a Safer Tomorrow.