Digital Arrest Scams in India: How the Scam Works, Legal Remedies & What to Do

Digital Arrest Scams in India: Legal Remedies, Reporting Steps and Evidence Preservation

Contents

  1. What is a “Digital Arrest” Scam?
  2. How Scammers Create Fear and Force Quick Decisions
  3. How a Genuine Cybercrime Investigation Actually Works
  4. Practical Steps: What to Do If You Receive a Digital Arrest Call
  5. What to Do If You Have Already Paid Money or Shared Documents
  6. What Evidence Should a Victim Preserve?
  7. India’s Response to Cybercrime and Digital-Arrest Fraud
  8. The Supreme Court’s Intervention: Key Developments
  9. The Legal Framework: What the Law Actually Says
  10. Frequently Asked Questions
  11. Conclusion

What is a “Digital Arrest” Scam?

A digital-arrest scam is a cyber-fraud scheme in which criminals impersonate police officers, judges, or government officials and falsely claim that the victim is under investigation or arrest. Indian law does not recognise any procedure by which a person is arrested and held in custody through a video or WhatsApp call.

A “digital arrest” is a scam designed to extort money from victims using fear, deceit, and intimidation. Fraudsters impersonate law enforcement officials, using threats of arrest, frozen bank accounts, and passport cancellation to coerce victims into paying a “fine” or “security deposit” to avoid legal action.

The scam typically begins with a phone call — seemingly innocent at first, offering everything from a harmless parcel-delivery claim to a demand for KYC verification. As the conversation progresses, the scammer uses increasingly aggressive tactics to instil panic, often claiming the victim is involved in serious crimes like money laundering, cybercrime, or drug trafficking. Using fake documents, doctored videos, and spoofed phone numbers, scammers create an air of legitimacy that pushes the victim to comply. (On how Indian courts and forensics grapple with fabricated audio-video content more broadly, see our piece on deepfakes and digital evidence.)

If you have received a call saying your Aadhaar, SIM card, parcel, bank account, or PAN is linked to a crime, it is natural to panic. Many people freeze when the caller claims to be from the police, CBI, ED, Customs, RBI, or a cyber cell. Here is the direct answer: a “digital arrest” is not a recognised form of arrest under Indian law. No police officer, court, or government agency can lawfully take you into custody over a WhatsApp or video call, keep you under continuous video surveillance, or demand money to “stop” an arrest.

This article explains what a digital-arrest scam is, how a genuine cybercrime investigation actually proceeds under Indian law, the warning signs to watch for, immediate steps to take, and the legal remedies available if you have already paid money or shared personal details.


How Scammers Create Fear and Force Quick Decisions

These scams work by convincing victims that any delay will ruin their life, reputation, job, passport, or family peace. The pattern is now common: a call arrives, often from a spoofed number or a WhatsApp account carrying a police or government logo. The caller uses basic personal details to sound credible, then raises an allegation — an illegal parcel, money laundering, a drug case, a fake SIM, a suspicious bank account, obscene content, a tax issue, or terror funding.

The pressure then escalates. The caller may transfer the victim to a fake “senior officer,” display forged ID cards or fabricated court papers, insist the victim switch on video, and instruct them not to speak to anyone — sometimes claiming that talking to family, colleagues, or a lawyer would amount to “interfering with an investigation.”

Common red flags:

  • Threats of immediate arrest without any prior notice or written procedure
  • Repeated demands for secrecy
  • Pressure to remain on a continuous audio or video call
  • Fake documents, stamps, IDs, or “arrest warrants” sent over WhatsApp or email
  • Demands for money to “verify,” “settle,” “freeze,” or “clear” your name
  • Requests for Aadhaar, PAN, bank details, OTPs, or screen-sharing access

How a Genuine Cybercrime Investigation Actually Works

The best protection against panic is knowing what a real legal process looks like — and a digital-arrest call resembles none of it.

Where there is a genuine criminal inquiry, investigating authorities follow a defined procedure. Depending on the facts, a person may receive a notice, a summons, or a direction to appear before the investigating agency; the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) does permit summons and certain proceedings to be served or conducted in electronic mode. In some cases, police may arrest without a warrant, but even then the arrest must follow the statutory safeguards under the BNSS: the officer must identify himself, communicate the grounds of arrest, prepare the arrest documentation, and inform the arrested person of the right to inform a relative, friend, or nominated person, along with the right to legal counsel.

The key distinction: the law allows electronic communication — a summons or notice sent digitally — but it does not allow an “arrest” to be conducted or enforced entirely over a video call, nor does it allow custody to be substituted with a money payment. If a caller tells you a cybercrime arrest can happen entirely on video and can be avoided by paying, that is the warning sign. Real investigation is procedural, documented, and time-bound. Scam pressure is theatrical and designed to prevent you from verifying anything.


Practical Steps: What to Do If You Receive a Digital Arrest Call

The first few minutes matter most. Your goal is to break the scammer’s control before fear turns into compliance.

  1. End the call. Do not stay on the line to “clear your name” — the longer you remain engaged, the stronger the scam’s hold becomes.
  2. Do not transfer money. No fine, bond, “safe account,” verification deposit, or temporary “freeze” payment is part of any lawful arrest or investigation procedure.
  3. Do not share sensitive data. Never share OTPs, card details, CVV, UPI PIN, passwords, Aadhaar images, PAN copies, or screen-sharing access.
  4. Verify independently. Look up the official number of the police station, agency, or court from its own website and call it yourself — never use a number given by the caller.
  5. Preserve evidence. Save call logs, numbers, screenshots, WhatsApp chats, emails, fake notices, payment requests, and transaction details.
  6. Tell one trusted person immediately. Scammers isolate victims deliberately; breaking that secrecy often breaks the scam’s hold.
  7. Report the suspect. Use the National Cyber Crime Reporting Portal’s suspect-reporting facility, where available, especially if you have not yet lost money — see cybercrime.gov.in.
  8. If money is at risk, act within minutes. Contact your bank, block cards or UPI where needed, and call 1930 without delay.

What to Do If You Have Already Paid Money or Shared Documents

Even if you have made a transfer or sent a document, do not assume the situation is hopeless — fast action can still help.

  • Call 1930 and report the fraud
  • File a complaint on cybercrime.gov.in
  • Inform your bank or payment app in writing and through customer care
  • Ask the bank to block further debits, flag the beneficiary account, and note the complaint number
  • Change internet banking, email, and app passwords
  • Disable or reset UPI where necessary
  • Block cards and review standing mandates or linked apps
  • File a police complaint or FIR with all available evidence (see our guide on how to file a cybercrime complaint in India) — and where the scam was clearly run by a coordinated group rather than a lone caller, our guide on filing an FIR for conspiracy to commit fraud explains how to frame that alongside the cheating charge

If you shared Aadhaar, PAN, or account details but did not pay money, still report the incident. Identity data can be misused later for fake accounts, fraudulent SIM activation, loan applications, or further impersonation.

What Evidence Should a Victim Preserve?

Because evidence preservation is central to getting a complaint acted on quickly, keep the following — in original form wherever possible, not just as memory:

  • Caller phone numbers, including any spoofed numbers displayed
  • WhatsApp profile details (name, photo, “About” info) used by the scammer
  • Call recordings, where lawfully available to you as a party to the call
  • Screenshots of chats, threats, and fake documents
  • Screen recordings of any video call, if safely possible
  • Fake notices, “arrest warrants,” or court papers sent to you
  • Email headers and full email content, not just the visible text
  • UPI IDs, bank account numbers, and IFSC codes used by the fraudster
  • Transaction IDs / UTR numbers for any payment made
  • QR codes shared during the call
  • Payment receipts or bank debit confirmations
  • URLs of any fake websites or payment links
  • Basic device information (which phone/app you used to communicate)
  • Exact dates and times of every call, message, and payment

This list directly supports the immediate-response and reporting steps above — the more of this you have when you call 1930 or file on cybercrime.gov.in, the faster action can be taken.


India’s Response to Cybercrime and Digital-Arrest Fraud

Digital-arrest scams are one prominent strand within a much wider landscape of Indian cyber fraud — for the broader picture across UPI fraud, job scams, and AI-driven impersonation, see our overview on cyber frauds and online scams in India. The Indian government has expanded its response to digital fraud through several initiatives.

  • Indian Cyber Crime Coordination Centre (I4C): Set up by the Ministry of Home Affairs to coordinate national efforts against cybercrime and to issue public advisories, including on digital-arrest scams specifically.
  • National Cyber Crime Reporting Portal (NCRP): Allows the public to report cybercrime online, with a dedicated focus on offences against women and children.
  • Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS): The 1930 helpline/portal mechanism for immediately reporting and attempting to halt fraudulent transactions. As of 30 June 2026, CFCFRMS had helped save more than ₹11,158 crore across over 32.80 lakh complaints (source: I4C/MHA reporting, via Press Information Bureau). The government has also stood up a Suspect Registry, which has helped decline transactions worth roughly ₹25,698 crore, and a Cyber Commando programme for specialised response capability.
  • Cyber forensic infrastructure: Includes national and state-level cyber forensic labs supporting the collection and analysis of digital evidence.
  • CyTrain (I4C): An online training platform for law enforcement and judicial officers. More than 1.63 lakh police and judicial officers had registered on CyTrain as of mid-2026 (source: I4C/MHA reporting).
  • Public awareness campaigns: Including Cyber Dost, the Sanchar Saathi portal/app, SMS alerts, and public-space advisories on digital-arrest scams.

    The Supreme Court’s Intervention: Key Developments

    Alongside the executive measures above, the Supreme Court of India has taken direct, ongoing suo motu control of the issue since late 2025, in In Re: Victims of Digital Arrest Related to Forged Documents (Suo Motu Writ (Criminal) No. 3 of 2025). The case remains actively monitored, with the Court issuing successive rounds of directions as status reports come in from the Centre, RBI, states, and I4C.

    • October 2025 — Cognisance taken. The Court took suo motu cognisance after a senior-citizen couple from Ambala, Haryana, wrote to the Chief Justice alleging they had been defrauded of ₹1.05 crore by fraudsters who impersonated CBI, Intelligence Bureau, and judicial officials, and used forged Supreme Court and other court orders — complete with fabricated seals — to coerce payment under threat of arrest. The Court observed that the use of forged court orders strikes at the very foundation of public trust in the judiciary and required urgent, coordinated attention. It sought responses from the Centre and the CBI and later asked all states and Union Territories to furnish FIR data on digital-arrest cases.
    • December 2025 — Pan-India CBI probe ordered. Noting the pan-India, and often cross-border, character of these scams, the Court directed a coordinated CBI investigation and asked states that had withdrawn general consent for CBI jurisdiction — including Punjab, West Bengal, Tamil Nadu, Karnataka, and Telangana — to accord case-specific consent so the investigation could proceed nationally. The Court also flagged the alleged involvement of colluding bank officials as an area requiring investigation, given the role of mule accounts in moving defrauded funds.
    • July 2026 — Standalone offence suggested; deepfake risk flagged. The Court suggested that the Union government consider formally defining “digital arrest” as a standalone criminal offence, carrying stringent punishment and provision for freezing assets on the basis of prima facie evidence — going beyond relying solely on the existing extortion, cheating, and impersonation provisions discussed above. Chief Justice Surya Kant observed that the conduct already carries elements akin to extortion and robbery, while Justice Joymalya Bagchi flagged the growing use of deepfake-enabled impersonation (fabricated voices and video of officials) as a distinct problem needing legislative attention. The Centre informed the Court that a draft bill was under preparation.
    • August 2026 — Thirteen interim directions issued. The Court issued a detailed set of interim directions to the RBI, the Centre, and the states, including: RBI to formally adopt and circulate, within four weeks, an SOP for banks to place temporary debit holds on accounts linked to mule activity and cyber-enabled fraud; wider, faster adoption of e-Zero FIR mechanisms and of the Grievance Redressal and Money Restoration Modules under the MHA’s NCRP-CFCFRMS framework; and continued follow-up on victim compensation and fund-recovery mechanisms. The Court’s status report recorded that digital-arrest complaints on the NCRP had fallen sharply — from 1,23,672 in 2024, to 58,249 in 2025, to 16,377 in the period up to 30 June 2026 — and that ₹18.05 crore had been restored to victims across 36,290 cases through the Money Restoration Mechanism Portal, spanning 57 participating banks across all States and Union Territories.
    • Next hearing: 16 September 2026. The matter remains pending before the Court, with further status reports due on the feasibility of time-based restrictions on audio/video calling services (given their misuse in these scams) and on state-wise, bank-wise complaint and recovery data.

    Why this matters for the legal-framework discussion below: the Court’s July 2026 suggestion — that “digital arrest” be codified as a standalone offence with asset-freeze powers — is a live, judicially endorsed proposal, distinct from this article’s earlier point that existing extortion (Section 308), cheating (Section 318), and impersonation (Section 204) provisions already substantively cover the conduct. Both positions can be true at once: the existing provisions capture the conduct, while a standalone offence, if enacted, would primarily address procedural gaps — faster asset-freezing on prima facie evidence, and a single, clearly labelled offence for charging and sentencing purposes, rather than relying on prosecutors to assemble the correct combination of BNS and IT Act sections in every case.

    The Legal Framework: What the Law Actually Says

    The I4C has issued public advisories confirming that agencies such as the CBI, police, Customs, ED, or courts do not conduct arrests through video calls, and that there is no legal provision permitting an “arrest” to be carried out over video or online monitoring. The newly enacted criminal laws (BNS/BNSS) do not create any procedure for a “digital arrest.” What they do provide for is service of summons and certain proceedings in electronic mode — which is a narrower and different thing, and should not be conflated with the scam.

    Constitutional Protection

    Article 20(3) of the Constitution protects a person from being compelled to be a witness against themselves. This is relevant to concerns about being forced to hand over passwords or device access. However, this is not an absolute or automatic shield — whether a specific demand (for a password, biometric unlock, or device access) actually amounts to compelled self-incrimination in a given case depends on the facts and on evolving case law regarding digital evidence and self-incrimination. Readers should not rely on Article 20(3) alone to assume they can refuse every demand for digital access in every circumstance; independent legal advice is essential where this becomes a live issue in an actual investigation.

    Bharatiya Nyaya Sanhita, 2023 (BNS) — Substantive Offences

    • Section 308 (extortion): This is the most directly applicable BNS provision to a digital-arrest scam. Extortion is committed where a person intentionally puts someone in fear of injury and thereby dishonestly induces them to hand over property — and Section 308 expressly extends that fear to an accusation of having committed a serious offence. This maps precisely onto the scam’s core mechanic: the fraudster falsely accuses the victim of a crime (money laundering, drug trafficking, etc.) and uses the resulting fear to extract a “fine” or “security deposit.” Basic extortion carries imprisonment up to seven years; where the extortion is carried out by threatening an accusation of an offence punishable with death, life imprisonment, or imprisonment up to ten years — exactly the kind of accusation a “digital arrest” caller typically makes — the punishment under the relevant sub-section extends up to ten years, along with a fine.
    • Section 318 (cheating): Equally central to the scam’s legal character. Cheating is committed where a person deceives another and thereby fraudulently or dishonestly induces them to deliver property, or to do or omit to do something they would not otherwise have done, causing or likely to cause harm. A digital-arrest scam is, at its core, an act of deception (fake officials, fake warrants, fake case numbers) inducing the victim to transfer money. Punishment ranges from up to three years for cheating generally, up to five years where the offender was bound by law or contract to protect the victim’s interest in the transaction, and up to seven years where the cheating induces the victim to deliver property or alter a valuable security — the category most digital-arrest payments would fall into.
    • Section 111 (organised crime): This is not a general cybercrime provision. It applies only where a digital-arrest scam is run in a manner that satisfies the specific statutory conditions for “organised crime” — including the definitions of “continuing unlawful activity” and “organised crime syndicate” set out in the section itself. It is not automatically attracted merely because a scam occurred; it becomes relevant only where those statutory requirements are independently established on the facts (for example, a structured syndicate operating across multiple cases).
    • Section 204 (personating a public servant) (corresponds to former IPC Section 170): Punishes falsely posing as a public servant and acting as such. This provision is relevant where a scammer impersonates a police officer, CBI official, or judge — but its application depends on the facts of each case establishing the statutory ingredients of the offence, not on the mere fact that a scam occurred.
    • Section 351 (criminal intimidation), including Section 351(4) for anonymous communication: This provision should not be treated as the default charge for “demanding money through threats” in a digital-arrest scam. Criminal intimidation, as such, is threatening a person with injury in order to cause alarm or to compel them to do (or abstain from doing) an act they are not legally bound to do — it does not itself require that property actually change hands. Where the facts go further and the threat is used to dishonestly induce the victim to actually deliver money or property, the applicable provision is extortion under Section 308, not criminal intimidation — extortion is the more specific offence and the one that matches what actually happens in a digital-arrest scam once payment is demanded and made (or attempted). Section 351(4) has a narrower, distinct role: where the threat itself is communicated anonymously or the offender has taken care to conceal their identity or address, it adds an enhanced term of imprisonment on top of whichever intimidation offence is separately established on the facts. In practice, that means the correct sequence for a digital-arrest scam is: analyse whether the extortion ingredients under Section 308 are made out first (since a “fine” or “security deposit” was demanded and typically paid), and consider Section 351 only for conduct that involves threats and alarm without a completed or attempted extraction of property, with sub-section (4) layered on separately if the communication was anonymous.

    Quick-reference: conduct to provision

    Conduct Relevant Provision
    Cheating (deceiving the victim to induce payment) BNS Section 318
    Extortion (inducing payment through fear/threat) BNS Section 308
    Personating a public servant BNS Section 204
    Criminal intimidation BNS Section 351 (with Section 351(4) where anonymous)
    Cheating by personation using a computer resource IT Act Section 66D
    Identity theft IT Act Section 66C, where applicable
    Organised-crime syndicate operation BNS Section 111, where the statutory conditions are independently satisfied

    Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) — Procedure

    The BNSS (replacing the CrPC) governs arrest, search, and seizure procedure, including in cases involving digital offences. It does not create a standalone “digital arrest” procedure. Relevant powers include:

    • Section 105: Requires search and seizure to be recorded through audio-video electronic means (preferably mobile phone) and forwarded to a magistrate — a safeguard against misuse, not a general “monitoring” power.
    • Section 106: Allows a police officer to seize property suspected to be connected with an offence, subject to the conditions in that section.
    • Section 107: Governs attachment, forfeiture, or restoration of property connected with an offence, through a defined procedure — this is the closer analogue to “freezing” an asset, and it operates through specific statutory conditions, not as a general blanket power exercisable at will during any investigation.
    • Sections 35–60 (broadly): Govern the framework for arrest, including the requirement to state grounds of arrest and to inform a relative/friend/nominated person.

    Correction from the earlier draft: it is inaccurate to describe the BNSS as giving law enforcement a general, free-standing power to “freeze bank accounts or block social media accounts” in every investigation. Any such action is tied to specific provisions (such as seizure or attachment under Sections 106–107, or through other laws such as the IT Act or banking regulations) and specific statutory conditions — it is not a blanket investigative power. A genuine account freeze or attachment can occur, but only through these lawful, documented mechanisms — a caller demanding money to “unfreeze” an account is never itself a lawful step in that process.

    Information Technology Act, 2000 — Cyber Offences

    The IT Act is India’s principal cyber law statute. The provisions most relevant to digital-arrest scams, mapped to conduct rather than treated as interchangeable:

    Law Provision Relevance to Digital-Arrest Scams
    IT Act Section 66 Computer-related offences (e.g., unauthorised access/data theft) — punishable with imprisonment up to 3 years and/or fine up to ₹5 lakh
    IT Act Section 66C Identity theft — applies where scammers fraudulently or dishonestly use another person’s actual electronic signature, password, or other unique identification feature. It does not automatically cover every fabricated police seal or fake ID card used by a scammer — that conduct is better addressed under Section 204 BNS (personation) and Section 66D IT Act (below); Section 66C applies specifically where a real person’s electronic identifiers are misused.
    IT Act Section 66D Cheating by personation using a computer resource — directly relevant where a scammer poses as a CBI/ED/police official online to cheat a victim; imprisonment up to 3 years and fine up to ₹1 lakh
    IT Act Section 69 Empowers the government to direct interception, monitoring, or decryption of information through a computer resource — available on specified statutory grounds (sovereignty/integrity of India, security of the State, friendly relations with foreign States, public order, or preventing incitement to a cognizable offence, among the grounds set out in the section), not solely in national-security or cyber-terrorism cases
    IT Act Section 70B Designates the Indian Computer Emergency Response Team (CERT-In) as the national agency for specified cybersecurity incident-response functions, including collection, analysis, and dissemination of information on cyber incidents
    BNS Section 308 Extortion — inducing payment through fear of injury or a false accusation of a serious offence
    BNS Section 318 Cheating — deceiving the victim to dishonestly induce delivery of property
    BNS Section 204 Personating a public servant
    BNS Section 351(4) Criminal intimidation by anonymous communication

    Sections 67, 67A, and 67B (obscene or sexually explicit content) are also relevant in a specific variant of this scam, where fraudsters transmit obscene material to a victim and then falsely threaten prosecution for possessing, publishing, or transmitting it.

    The IT Act also has extraterritorial application to offences committed from outside India where the targeted computer resource is located in India — relevant given that many digital-arrest calls originate from abroad.


    Frequently Asked Questions

    Is digital arrest legal in India? No. Indian law does not recognise any procedure by which a person is arrested or kept in custody solely through a phone or video call. There is no such thing as a lawful “digital arrest” — the term describes a scam, not a legal process.

    Can police arrest someone through WhatsApp or a video call? No. A WhatsApp or video call cannot itself constitute a lawful arrest. Genuine criminal procedure under the BNSS may involve electronic service of a summons or notice, but an actual arrest requires the officer to identify himself, state the grounds of arrest, and follow the documented statutory process — none of which happens on a scam call.

    What should I do if I receive a digital-arrest call? Disconnect the call. Do not pay any money or share OTPs, PINs, passwords, or documents. Preserve whatever evidence you can (screenshots, call logs, messages). Then report it immediately — call 1930 if any money is at risk, and file a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in).

    Can I recover money lost in a digital-arrest scam? Immediate reporting improves the chances that banks and payment platforms can stop, hold, or trace a fraudulent transaction before it moves further through mule accounts — this window closes quickly, so speed matters. However, recovery is not guaranteed, and how much (if anything) is recovered depends on how fast the funds moved and where they ended up.

    What is 1930? 1930 is India’s national cybercrime helpline, run in connection with the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) under the I4C. It is the fastest route to report financial cyber fraud and seek immediate assistance, including requesting banks to hold or freeze a fraudulent transaction.

    Is there a specific law against “digital arrest” scams? Not as a single named offence at present, though the Supreme Court has suggested the Centre consider creating one (see “The Supreme Court’s Intervention” above). Currently, the conduct is prosecuted through a combination of existing provisions — extortion (Section 308 BNS), cheating (Section 318 BNS), personating a public servant (Section 204 BNS), and identity theft or cheating by personation under the IT Act (Sections 66C, 66D) — depending on the specific facts of the case.


    Conclusion

    A “digital arrest” is not a legitimate law-enforcement tool — it is a cyber-fraud tactic that exploits fear and unfamiliarity with real criminal procedure. India already has an interlocking framework of provisions — under the BNS, BNSS, and IT Act — that can address the impersonation, intimidation, identity theft, and cheating involved in these scams. The more urgent gaps are practical rather than purely legislative: faster cross-border cooperation to trace offshore call centres, faster account-freezing coordination between banks and cyber-cell units, and sustained public awareness so fewer people panic and pay in the first place.

    Any call for new legislation should identify precisely which conduct in this scam is not already covered by an existing provision, and what procedural gap — as opposed to an awareness gap — a new law would actually close, before recommending an entirely new statutory framework. The Supreme Court’s own July 2026 suggestion of a standalone “digital arrest” offence, discussed above, is instructive on this point: it is framed as addressing procedural gaps — asset-freezing on prima facie evidence and streamlined charging — rather than as a claim that the conduct is currently unpunishable.


    Internal Links Used in This Article

    All four links are placed inline in the body text above (not just listed here):

Musarraf Khan
Author: Musarraf Khan