All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Cybercrime Investigation and Procedure in India: FIR to Foreign Evidence

Substantive cyber law decides what was a crime; whether anyone answers for it is decided by procedure: how fast the money was frozen, whether the IP resolved to a subscriber, whether the phone was hashed at seizure, and whether the platform abroad ever produced the account data. The pieces have appeared across earlier notes, s.78 and s.80, preservation, the Examiner; this note assembles the working sequence of a cyber investigation from complaint to charge sheet, including the machinery no section of the Act names: the national portal, the 1930 helpline, and the cooperation routes for foreign evidence.

1. Reporting: Portal, Helpline, FIR

From complaint to case

Figure 1: From complaint to case

  • The National Cyber Crime Reporting Portal. cybercrime.gov.in, run under the Indian Cyber Crime Coordination Centre (I4C) of the MHA, receives complaints of every cybercrime, with anonymous reporting for content concerning women and children; complaints route to the State police for registration and investigation.
  • The 1930 helpline. The national cyber fraud helpline feeding the Citizen Financial Cyber Fraud Reporting and Management System: reported in the first hours, a fraudulent transfer is chased through the chain of banks, wallets and merchants, each institution alerting the next and lien-marking the amount as it lands, the single most effective remedy in financial cybercrime.
  • FIR, Zero FIR and the electronic complaint. Cognizable cyber offences are registered like any other; the BNSS puts Zero FIR on statutory footing, any police station registering irrespective of jurisdiction and transferring to the competent one, and permits electronic FIRs and complaints, signed within the statutory window. Portal complaints are not themselves FIRs until registered.
  • Cyber police stations and the Inspector rule. States have notified dedicated cyber police stations and cyber cells; whoever holds the file, s.78 requires an officer not below Inspector to investigate offences under the Act (Topic 66)

The freeze chain on the money

Figure 2: The freeze chain on the money

2. Jurisdiction

Place in a placeless crime

Figure 3: Place in a placeless crime

  • Territorial jurisdiction. A cyber act is committed in several places at once, where the accused sat, where the server processed, where the victim received the consequence, and the BNSS local jurisdiction rules for offences committed partly in one area and partly in another, or continuing offences, let courts at any of these take cognizance; in fraud, the place where the victim parted with money grounds jurisdiction.
  • Cross-border crime. s.1(2) with s.75 extends the Act to offences committed outside India by any person, if the conduct involves a computer, system or network located in India (Topic 66); the assertion is straightforward, enforcement against a foreign accused runs through the cooperation routes below.

3. The Data and Money Trail

Link by link to the accused

Figure 4: Link by link to the accused

  • Tracing the IP address. The platform discloses the IP addresses and timestamps behind the offending account or transaction; the internet or telecom provider then resolves IP, time and port to a subscriber, the step where carrier-grade NAT, VPNs and proxies complicate attribution, met in part by the CERT-In directions requiring VPN and cloud providers to keep subscriber records for five years (Topic 64)
  • Subscriber information and CDRs. Subscriber detail records and call detail records from telecom providers map identities, associations and movement; tower dumps and IMEI trails locate devices. The compulsion instrument is the BNSS production order, s.94, the successor of s.91 CrPC, with the interception and monitoring powers of ss.69 and 69B reserved for their own sanctioned channels (Topics 69, 72)
  • The bank and UPI trail. Account opening records, transaction statements and UPI logs trace proceeds hop by hop through mule accounts, the recruited or rented accounts that layer the money; banks respond to s.94 orders, and seizure or freezing of the credited amounts proceeds under the BNSS property seizure provisions with magisterial reporting.
  • Cryptocurrency and wallet investigation. Where proceeds convert into crypto assets, exchange KYC records, blockchain analysis of wallet flows and seizure of private keys become the trail; Indian exchanges answer production orders and FIU reporting duties, while offshore exchanges require the cooperation routes.
  • Preservation while process runs. Because logs and content are perishable, investigators send immediate preservation requests: s.67C obliges intermediaries to preserve prescribed information, Rule 3(1)(g) keeps removed-content records for 180 days, Rule 3(1)(h) retains registration information after cancellation, and the CERT-In directions fix 180-day logs, so the data survives until an order or MLAT arrives (Topics 61, 64, 74)
  • CERT-In assistance. In incident-driven cases, breaches, ransomware, defacements, CERT-In's incident reports, technical analysis and directions support the police investigation, its s.70B(6) power to call for information carrying its own sanction (Topic 64)

4. Devices and Forensics

  • Search and seizure. Public place searches and arrests travel under s.80; homes and offices need the BNSS warrant or emergency search route, with audio-video recording of searches and seizure witnessed by memo (Topic 83)
  • Imaging, hashing, custody. Seized computers and phones are forensically imaged through write blockers, hash values fixing integrity from seizure memo to courtroom, and the chain of custody documented at every transfer, the disciplines on which admissibility and weight survive (Topics 24, 82)
  • Forensic examination. Examination by an Examiner of Electronic Evidence notified under s.79A, computer, mobile and storage media forensics recovering files, chats, artefacts and metadata, ending in a reasoned report proved under s.39(2) BSA (Topic 82)
  • Cloud evidence. Accounts and data held with cloud and platform providers are reached by orders on the provider rather than device seizure, with the s.63 BSA certificate from the provider's records officer proving the output; data held on foreign servers pushes the case into the cooperation routes.

5. Foreign Evidence and International Cooperation

The routes to data abroad

Figure 5: The routes to data abroad

  • Direct platform channels. Global intermediaries maintain law enforcement request systems and disclose basic subscriber information on valid Indian legal process at their discretion; the 2021 Rules add hard edges within India's jurisdiction, information within 72 hours of a lawful order under Rule 3(1)(j), resident officers of SSMIs, and preservation duties (Topics 74, 76)
  • MLAT. For content and evidence needed at trial, the Mutual Legal Assistance Treaty route, requests through the Ministry of Home Affairs as central authority to the partner State, the India-US treaty carrying most platform traffic since the major providers are US-based; slow, but the product arrives as formally transmitted evidence.
  • Letters rogatory. Where no treaty serves, a competent court issues letters rogatory under the BNSS to the foreign court through the diplomatic channel, the older and slower cousin of the MLAT request.
  • The conventions. India is not a party to the Budapest Convention on Cybercrime, preferring a UN process; the UN convention against cybercrime, adopted by the General Assembly in December 2024 and opened for signature in 2025, may in time supply a broader cooperation framework, its entry into force and India's ratification to be watched.
  • Interpol and informal channels. Red and blue notices, I4C's international liaison and provider emergency disclosure procedures for imminent harm round out the toolkit, informal product then regularised through formal process.

⚠ Exam trap

Keep the instruments attached to their sources: the 1930 helpline and the reporting portal are administrative machinery of the MHA's I4C, created by no section of the IT Act; Zero FIR and electronic FIRs come from the BNSS; preservation flows from s.67C, the intermediary rules and the CERT-In directions; and compulsion of records is the s.94 BNSS production order, never the s.69 interception power, which has its own competent authority route. On foreign evidence, remember the pairing: MLAT through the MHA where a treaty exists, letters rogatory through the court where none does, and India stands outside the Budapest Convention.

6. Frequently Asked Questions

How is a cybercrime reported and investigated in India?

The victim may complain at any police station, on the National Cyber Crime Reporting Portal, or through the 1930 helpline for financial frauds, where the Citizen Financial Cyber Fraud Reporting and Management System alerts the banks in the transfer chain to freeze the money in flight. A cognizable offence is registered as an FIR, at any station as a Zero FIR if need be, and investigated by an officer not below Inspector under Section 78, through production orders for platform, telecom and bank records, preservation requests to intermediaries, seizure and forensic imaging of devices, and examination by a Section 79A Examiner.

How do investigators obtain data held by foreign platforms?

In layers: direct law enforcement request channels of the platforms for basic subscriber information, preservation requests to stop deletion, the 72-hour information duty and resident officers under the 2021 Rules for platforms operating in India, and for evidence needed at trial the MLAT route through the Ministry of Home Affairs or letters rogatory issued by a court where no treaty applies. India is not a party to the Budapest Convention; the UN cybercrime convention adopted in 2024 may eventually broaden the treaty framework.

7. Related Topics

  • Topic 24: Digital Evidence in Investigation. Collection and proof, the evidentiary side of this note.
  • Topic 83: Section 80. The search, seizure and arrest power in the field.