FAQ's on Cyber Attacks

There are two ways in which you can file a complaint regarding and cyber crime/ online fraud.

  1. Registering online Complaint
  2. Registering a complaint at the nearest cyber crime police station.

At present, the Ministry of Home Affairs has launched a centralized webportal for online registration of the cybercrime related complaints accross India :

www.cybercrime.gov.in  

There are two options for reporting cybercrimes on this webportal:

  1. Report Crime related to Women/ Child– Under this section, you can report complaints pertaining to online Child Pornography (CP), Child Sexual Abuse Material (CSAM) or sexually explicit content such as Rape/Gang Rape (CP/RGR) content. These types of crimes can be reported anonymously also. Once complaint is given under this section, then one cannot withdraw back the complaint.
  2. Report Other Cybercrimes– Under this option, you can report complaints pertaining to cybercrimes such as mobile crimes, online frauds, social media crimes, online financial frauds, ransomware, hacking, cryptocurrency crimes and online cyber trafficking.

The process will enable a person to register a complaint online without visiting the police station.  

Once the complaint is registered then a reference ID will be generated which can be tracked latter. This registered complaint along with ID is sent  to respective police station for further enquiry.

For further Queries/ Questions regarding filing cyber crime related complaint on the webportal refer to https://www.cybercrime.gov.in/Webform/FAQ.aspx

In the current scenario it is essential that every individual is aware of the steps involved in successfully filing a complaint against a cyber crime

Step 1: Register a written complaint with the cyber crime cell of the city, you are currently residing in.

According to the IT Act, a cyber crime comes under the purview of global jurisdiction. This means that a cyber crime complaint can be registered with any of the cyber cells in India, irrespective of the place where it was originally committed.

You may refer the following link for State/Nodal grievance officer contact details: https://cybercrime.gov.in/Webform/Crime_NodalGrivanceList.aspx

Step 2: Remember that when filing the cyber crime complaint, you need to provide your name, contact details, and address for mailing. You need to address the written complaint to the Head of the Cyber Crime Cell of the city where you are filing the cyber crime complaint.

In case of online harassment, a legal counsel can be approached to assist you with reporting it to the Police Station.

Additionally, you may be asked to provide certain documents with the complaint. This would, however, depend on the nature of the crime.

Step 3: Register a Cyber Crime FIR-If you do not have access to any of the cyber cells in India, you can file a First Information Report (FIR) at the local police station. In case your complaint is not accepted there, you can approach the Commissioner or the city’s Judicial Magistrate.

Step 4: Certain cyber crime offenses come under the Indian Penal Code. You can register a cyber crime FIR at the nearest local police station to report them.

It is mandatory under Section 154, Code of Criminal Procedure, for every police officer to record the information/complaint of an offense, irrespective of the jurisdiction in which the crime was committed.

Step 5: Most of the cyber crimes that are covered under the Indian Penal Code are classified as cognizable offenses. A cognizable offense is the one in which a warrant is not required for an arrest or investigation.

In this case, a police officer is bound to record a Zero FIR from the complainant. He must then forward it to the police station under the jurisdiction of the place where the offense was committed.

Step 6: Zero FIR offers some solace to victims of cases that require immediate attention/investigation as it avoids wasting time in enlisting the offense on police records.

FACT : A Zero FIR means that an FIR can be filed in any police station, irrespective of the jurisdictional limitations and location of the incident, and latter transferring it to concerned jurisdiction.

  • A written Complaint explaining the complete incidence
  • Copy of the alleged Email
  • Email should be taken from the original receiver. Copy of the forwarded email should be avoided
  • Full Header of the alleged Email
  • Copy of email and header should be in both hard & soft forms
  • Soft copy should be given in a CD-R only.
  • How to view Full Header of Email -   refer to http://www.cybercelldelhi.in/header.html

  • screenshot of the malicious app and the location from where it downloaded.
  • Bank statement from the victim’s account if any transactions made.
  • soft copy of all above mentioned documents in soft form.

Brief description of the incident, and consider providing the following financial information:

  1. Originating Name
  2. Originating Location
  3. Originating Bank Name
  4. Originating Bank Account Number
  5. Recipient Name
  6. Recipient Bank Name
  7. Recipient Bank Account Number
  8. Recipient Bank Location (if available)
  9. Intermediary Bank Name (if available)
  10. SWIFT Number
  11. Date
  12. Amount of Transaction
  13. Additional Information (if available) - including “FFC”- For Further Credit; “FAV” – In Favor Of

  • Copy of data which has been stolen
  • Copyright certificate for the data in question.
  • Details of suspected employee who took the data from company.
  • Following documents related to suspected employee:
  • Appointment letter
  • Non-disclosure agreement if any
  • List of duty assigned.
  • List of gadgets assigned to the suspected.
  • List of clients with whom the suspect is in touch.
  • Proof of selling of your copyright data to any client.
  • Devices used by the suspect while working with the company, if any.

  • EMail id /phone number or any other means of communication through which ransom has been demanded.
  • If malware was sent in the attachment of the mail. Screen shots of the mail with full header of first receiver should be provided

  • Bank statement from the concerned bank of last six months.
  • Copy of SMSs received related to the alleged transactions.
  • Copy of your ID proof and address proof as shown in the bank records.

  • Bank statement from the concerned bank of last six months.
  • Make a copy of SMSs received related to the alleged transactions.
  • Copy of your ID proof and address proof as shown in the bank records.

  • Bank statement from the concerned bank of last six months.
  • Make a copy of SMSs received related to the alleged transactions.
  • Copy of your ID proof and address proof as shown in the bank records.

  • Complete facts in brief about the incident.
  • Address of Bitcoin.
  • Amount of Bitcoin involved.
  • Address from/to whom purchase/sale of Bitcoins is done.

  • Print out of the alleged email along with its full header of the email
  • Email should be taken from the original receiver. Copy of the forwarded email should be avoided
  • Bank statement from the victim’s account.
  • Details of the alleged transaction made.
  • Soft copy of all above mentioned documents.

  • Bank statement from the concerned bank of last six months.
  • Make a copy of SMSs received related to the alleged transactions.
  • Copy of your ID proof and address proof as shown in the bank records.

Source : http://www.cybercelldelhi.in/compdocument.html

  • Copy/screenshot of alleged contents/profile
  • Screenshot copy of URL of alleged contents
  • Contents should be in both hard & soft forms
  • Soft copy should be given in CD-R only
  • How to view URL - refer to http://www.cybercelldelhi.in/url.html

Additionally for Social Media related crime/fraud, you should report it on specific social Media platform:

  1. Apart from the above steps, one must also register a complaint on the corresponding platform where the offense was committed. The steps for the same are clearly stated on every social media platform.
  2. Most of the social media platforms have a clear procedure in place for reporting any abuse or other nasty offenses. You must make sure that you report such activities in the very initial stages of its occurrence. This shall enable the concerned social media platform to take immediate steps for blocking further activities and protecting the privacy of your personal information.
  3. Facebook, Twitter, Instagram, Snapchat, and YouTube have a strict and clear redressal mechanismto protect its users from online abuse and cyber crimes. Make sure that you do your groundwork on their guidelines for reporting an abuse without waiting for an abuse to actually happen!

You may refer to the following link for state wise for State/ Nodal grievance officer contact details: https://cybercrime.gov.in/Webform/Crime_NodalGrivanceList.aspx

You may register an online complaint on the portal cybercrime.gov.in or in your nearest cyber crime police station.

  • Ensure that you keep the mobile number and all the conversation records, email records and payment transaction records taken place for registering an online or off line complaint.

For detailed list of documents required for registering a complaint refer to list of documents mentioned above.

You may refer to the following link for state wise for State/ Nodal grievance officer contact details: https://cybercrime.gov.in/Webform/Crime_NodalGrivanceList.aspx

  • Never believe in zero percent interest loans, online loans or financial help from an unidentified person or non-reliable source.
  • Never disclose any personal information however convincing the caller may sound.
  • Find out details of the organisation, bank, company, dealer, chit fund Co. Etc.,  team in organisation, ID card/Employee no. of the employee, that the caller claims to be from.
  • Ask the caller to send you a mail to registered mail id regarding the matter.
  • Take time to verify the details given by the caller, call the organization, bank, company ..etc., on the verified authentic number you have from reliable source (random google search for contact numbers can be misleading)  and cross verify the matter.
  • You may take the mail id of the caller and try sending mail and verify its ISP provider to trace location and also check company domain name in mail id.
  • Never call back a phone number that was associated with the text that concerns you.If you find out its a fake call block the number and register an online complaint on cybercrime.gov.in

For more information on social engineering techniques and tips to prevent, pl. Visit:

https://www.infosecawareness.in/concept/social-engineering?lang=en

  • Never believe a message or call, that claims that you have won a cash prize or lottery etc., asking you to register or click on a link.
  • Never disclose any personal information however convincing the caller may sound.
  • Find out details of the company, address, registration number and ID card/Employee no. of the employee, that the caller claims to be from.
  • Ask the caller to send you a mail to registered mail id regarding the matter.
  • Take time to verify the details given by the caller, call the company on the verified authentic number you have from reliable source (random google search for contact numbers can be misleading)  and cross verify the matter.
  • You may take the mail id of the caller and try sending mail and verify its ISP provider to trace location and also check company domain name in mail id.
  • Youmay check the website provided and ensure that the URL has ‘https’ (s stands for secured) and a lock icon, with correct spelling.
  • To verify and check the domain ID/name of the website log in to https://registry. in/whois which is a searchable list of every domain currently registered in the world.
  • Check for the online ratings or reviews for the company, website etc.,
  • Do not reply to text messages that have asked you about any of your personal finances.
  • If the text messages (along with the unknown number) urges for a quick reply then that is a clear sign of SmiShing! Don’t Respond!

If you find out its a fake offer, block the number and register an online complaint on cybercrime.gov.in

  • Report it to the concerned bank and immediately block the cards by calling the toll free number of the respective bank.
  • It is advisable to keep a copy of all your financial documents for retrieving the related information like card number etc., in case of theft.
  • File a complaint with your local police station. Keep a copy of the compliant for proof of the fraud. It can help you deal with bank
  • Lodge a written compliant with the home branch and collect the acknowledgement & keep it safe. It may help to resolve the issue It is advisable to get a new card issued and not to use the old card in case you get back the same after losing / theft.

Refer to the below link for information on tips to protect against Credit and Debit card frauds:

- https://www.infosecawareness.in/concept/credit-and-debit-cards?lang=en

- https://www.infosecawareness.in/concept/women/atm-risks-tips

Tips for selling safely :

  • Always try to use only simple payment methods that you trust and are familiar with.Always remember not to send copies of your documents, personal data and most importantly financial or banking information however convincing the buyer might seem.
  • Don’t deal with buyers who keep on constantly changing the meeting place or calling from different mobile numbers.
  • If you see the buyer waiting for you in his car and he wants to check the item, ask him kindly to get out of the car to check it outside; it is always better in a public place you have both chosen.
  • Always remember transaction PIN or scanning QR code is required for sending money, never for receiving money.  

Tips for buying safely :

  • Avoid items that have suspiciously lower prices than what is offered in the market.
  • Do not deal with buyers who insist on asking for your personal information such as your full name, age, aadhar card, pan cad, bank account details  etc.
  • Never send an advance partial or full payment, or use a debit card to pay someone you do not know before collecting your item
  • Remember, it is recommended to purchase items directly from the seller.
  • Always inspect the item before purchasing. Following this one rule will help you avoid most scams.
  • Insist on meeting the seller at a safe location such as Metro stations, shopping malls or any famous public point.
  • Be careful and alert if the price of the product is clearly undervalued. Pay extra attention if the seller avoids personal collection of the product or avoids Cash on Delivery.
  • Pay attention and be extra careful if the persons account was found very recently on the online selling application site or when it is written in a way that seems like template or automatically translated.

Also

  • If you suspect someone to be either acting fraudulently (buying or selling) report in the online application or call the authentic number of specific company’s customer care department.
  • Always ensure that you do online shopping from secured websites, ensure that the url of website has ‘https’ ( S is for secured) and lock icon. Check the spelling of the website, also to find out the real owner of the domain name and its credibility log into the https://registry.in/whois.

Never respond to any messages or click  link directly without confirming the authenticity of the sender and purpose, as it may automatically download some malicious content/virus while loading the link.

  • Never install any unknown E-wallet/money transaction application from any store or any websites for mobile funds transaction.
  • Also never install any third party applications from any unknown portal because they have the capability of collecting key logs, user names and passwords and records of your device if given accessibility/ granted permissions during installation.
  • Always download mobile banking apps from Google play store/ apple store or any reputed store for mobiles.
  • In case of internet banking, always ensure that that the respective website is genuine by checking in the address tab, if you find anything suspicious do not provide any banking details and exit from it.
  • Never save your card details on the payment application portal.
  • Add only minimum amount in payment wallets.
  • If possible use normal phone instead of smart phone for  receiving all the OTPs  related to all financial transactions.
  • Always ensure that you are using a genuine application for booking online tickets like movie tickets, air tickets, bus tickets etc., through mobile.

Pl. Refer to the following links for information and security tips on  online shopping:

https://www.infosecawareness.in/concept/student/online-shopping?lang=en

https://www.infosecawareness.in/concept/women/online-shopping?lang=en

  • Firstly register a complaint for that application under its complaint/ report section.
  • Inform all the friends and family members about your account being hacked and being misused on socially and in person, as the hackers can misuse the account in any way.
  • Refer to answer given in question no. 2 for registering complaint in cybercrime.gov.in, and refer to answer given in Question no. 15 for complaining in social media and cyber crime cell.

Refer to the below link for information on tips on social networking: https://www.infosecawareness.in/concept/student/social-networking

  • Never give any personal information to a stranger or a person you do not know.
  • Never give away your contact number to the caller instead ask him what number have they dialed.
  • Children should be instructed to never reveal any personal information to unknown callers. They should be taught to record callers name and phone number.
  • Do not include your telephone number on outgoing message of your voice mail service.
  • Never engage in conversation with person trying to harass you, typically crank callers are seeking attention, they generally want the receiver to express shock or anger, frustration.
  • You might also try putting recorded message instead which says “ you cannot answer the call and a message can be left”.
  • Hang up the call   do not respond, block the callers number and lodge a complaint
  • If the calls are frequent and threatening you may also contact the service provider and with the assistance lodge a complaint in nearest cybercrime cell or cybercrime.gov.in

Pl. refer to the following link for further information on cyberstalking and tips on the same.

https://www.infosecawareness.in/concept/children/online-predators 

https://www.infosecawareness.in/concept/women/safety-on-cyberstalking

  • Never to create multiple accounts  with weak passwords, as it may be used by hackers for any crime.
  • Always use strong passwords that are difficult to guess with combination of characters, numbers & alphabets for your mobile, computer, and all other digital devices or applications.
  • Keep changing your password and ensure that you use different passwords for different accounts
  • Avoid posting personal pictures, or pictures of your family of friends or any personal details online publicly.
  • Never add or accept unknown persons friend request nor respond to any of them.
  • Never comment/ post on any unknown persons comment page,  as you will be open to many unknown members.
  • Avoid browsing websites that are not trust worthy, also avoid clicking suspicious links, text messages as they can be a trap for Identity theft.
  • Never give away your personal & confidential information like passwords, account numbers, PIN numbers, etc., over the phone or through email.
  • Carry duplicate copies of important documents like Identity Cards, License,  to minimize the damage in case of physical theft.
  • To protect your digital assets ensure the following:
    • Strong Firewalls
    • VPN for outside access
    • Scheduled malware and virus scans
    • Automatic windows and other software updates
    • Secured wireless networks
    • Protecting/limiting the physical access to your computer

Pl. Refer to the following url on further information and tips regarding identity theft:

https://www.infosecawareness.in/concept/children/identity-theft

  • Never give any personal information to a stranger or a person you do not know.
  • If he is using abusive language, hang up the call   do not respond, block the callers number and lodge a complaint.
  • Be calm and firm with the caller in denying the information and hang up the phone and block the number.
  • You may also contact the service provider and with the assistance lodge a complaint in nearest cyber crime cell or cybercrime.gov.in

Pl. Refer to the following url on further information and tips regarding identity theft:

https://www.infosecawareness.in/concept/children/identity-theft

  • Never disclose any personal information however convincing the caller may sound.
  • Find out details of the organization, bank, company, dealer, chit fund Co. Etc.,  team in organisation, ID card/Employee no. of the employee, that the caller claims to be from. (pl. remember that random google search for contact numbers can be misleading)
  • Ask the caller to send you a mail to registered mail id regarding the matter.
  • Take time to verify the details given by the caller, call the organization on the verified authentic number you have and cross verify the matter.
  • You may take the mail id of the caller and try sending mail and verify its ISP provider to trace location and also check company domain name in mail id.
  • If you find out its a fake call block the number and register an online complaint on cybercrime.gov.in

For more information on social engineering techniques and tips to prevent, pl. Visit:

https://www.infosecawareness.in/concept/social-engineering?lang=en

  • Never accept any requests sent through email or mobile SMS from strangers,check the genuineness of  the message or mail. Some times even fake mails may  seem genuine with logo of bank etc.,
  • Always remember transaction PIN or scanning QR code is required for sending money, never for receiving money.  
  • Never disclose any personal or sensitive banking information however convincing the email may be.
  • Take time to verify the details of organisation, bank, company, dealer, chit fund Co. Etc., mentioned in the mail  and call the organization on the verified authentic number and cross verify the matter (pl. remember that random google search for contact numbers can be misleading)
  • You may try sending mail and verify its ISP provider to trace location and also check company domain name in mail id.
  • If you find out its a fake call/ message, block the number and register an online complaint on portal cybercrime.gov.in

Pl. Refer to the following link for information on phishing attacks and tips for

https://www.infosecawareness.in/concept/phishing-attacks?lang=en

  • Never click the link directly without confirming the authenticity of the sender and purpose, as it may automatically download some malicious content/virus while loading the link.
  • Never accept any requests sent through email or mobile SMS from strangers however genuine the message may  seem with logo etc.,
  • Always remember transaction PIN or scanning QR code is required for sending money, never for receiving money.  
  • Never disclose any personal or sensitive banking information however convincing the email may be.
  • Take time to verify the details of organisation, bank, company, dealer, chit fund Co. Etc., mentioned in the mail  and call the organization on the verified authentic number and cross verify the matter.( remember that random google search for contact numbers can be misleading)
  • You may try sending mail and verify its ISP provider to trace location and also check company domain name in mail id.
  • If you find out its a fake call/ message, block the number and register an online complaint on portal www.cybercrime.gov.in
  • To trace the email from which it is originating you can just copy the entire email headers of the mail and trace it by the same with online email id tracing tools like email tracer etc.

Pl. Refer to the following link for information on phishing attacks and tips for

https://www.infosecawareness.in/concept/phishing-attacks?lang=en

isea-loading.gif