Digital evidence can vanish when a scammer deletes a group, changes a username, withdraws an advertisement or blocks the victim. Preserve the original context quickly, but do not delay bank blocking or the 1930 report while creating a perfect evidence file.
Finin2min takeaway: Act from primary records, use the official channel and keep a dated evidence trail. A portal message, screenshot, dashboard or verbal assurance is not a substitute for the governing rule and underlying documents.
Current position in plain English
Containment comes before documentationBlock the affected account, card, UPI, SIM or device and report the money trail immediately.
Capture identifiers, not only screenshotsSave UTRs, phone numbers, usernames, URLs, bank accounts, wallet addresses, email headers, app IDs and timestamps.
Preserve originalsKeep exported chats, original emails, files and screen recordings. Editing or annotating the only copy can weaken provenance.
Create a chronologyA one-page timeline helps banks and investigators understand how contact, payment and discovery occurred.
Protect your own sensitive dataDo not share full credentials publicly or with unofficial recovery agents.
Decision table
| Evidence category | Examples | Why useful |
|---|
| Transaction | UTR, bank statement, VPA, beneficiary account | Fund tracing |
| Identity | Phone, email, username, KYC claim, profile URL | Actor linkage |
| Communication | Exported chat, email header, call log, recording | Method and representation |
| Technical | App/APK, domain, device alert, remote-access log | Infrastructure |
| Reporting | Bank, 1930, portal and police acknowledgements | Timeline and escalation |
How to apply the rule
Use two tracks at the same time: containment and complaint. Containment blocks further access; the complaint creates a traceable record for banks, payment operators and investigators.
Never rely on a phone number supplied inside the suspicious message. Open the official app or type the institution’s website address independently.
A fast, accurate complaint is better than a dramatic allegation. State what was authorised, what was not, when the alert arrived, when the bank was informed and which credentials or devices may have been compromised.
For cybercrime evidence checklist, first identify the legal or contractual relationship, then separate the amount, event and deadline. Use one chronology across the portal, institution and supporting records. This prevents a correct fact from being submitted under the wrong year, account, policy clause or complaint route.
Practical example
A victim screenshots only the final 'account blocked' message but deletes the investment group. A better file includes the group link, admin usernames, payment instructions, beneficiary accounts, UTRs, app download URL, call logs and a chronology of each transfer.
Action checklist
- Block and report the financial channel immediately.
- Export chats and save original emails with headers.
- Capture full-page screenshots showing URL, time and username.
- Download statements and UTR details.
- Record device, SIM and remote-access changes.
- Write a chronological incident note while memory is fresh.
- Back up evidence in two secure locations.
- Submit only relevant copies to official channels.
Evidence and document checklist
- Bank and wallet statements
- UTRs and payment receipts
- Phone and call logs
- Email headers and original .eml files
- Chat export and media
- Website/app links and installation files
- Identity documents sent to scammer
- Bank, 1930, cybercrime and police reports
Common mistakes
- Cropping out usernames or timestamps
- Forwarding evidence repeatedly and losing originals
- Editing the only screenshot
- Delaying the bank call to prepare a document
- Publishing personal data on social media
- Giving a recovery agent remote access
Red flags
- Scammer deletes accounts or group
- Remote-access app remains installed
- SIM/email compromise
- Multiple beneficiary accounts
- Crypto transfer or offshore platform
- Threats involving intimate images or physical safety
Escalation route
Submit financial fraud promptly to the bank, 1930 and cybercrime.gov.in. Follow police instructions for device examination. Escalate service complaints separately to the relevant regulator; do not mix criminal allegations and consumer-service issues without explaining both.
When escalating, include the original complaint, acknowledgement, concise chronology, disputed amount, rule or clause relied upon and the exact relief requested. Do not send passwords, PINs, OTPs or unrelated identity documents.
Frequently Asked Questions
Are screenshots enough? ▼
They help, but transaction identifiers, original files, URLs, exports and timestamps are stronger.
Should I record a scammer’s call? ▼
Follow applicable law and personal-safety considerations; preserve existing call logs and recordings without provoking further contact.
Can I delete a malicious app? ▼
First contain risk and preserve relevant details; follow bank or police guidance, then remove it from a secured device.
Where should I store evidence? ▼
Use secure offline or encrypted storage and keep a second backup.
Should I post the scammer’s bank account online? ▼
No. Provide it to banks and authorities; public posting can expose personal data and complicate investigation.