............................. Cyber Crime Law, Seizure Rules & Account Freeze in India
A practical legal overview of the Information Technology Act 2000, Bharatiya Nyaya Sanhita (BNS), Bharatiya Nagarik Suraksha Sanhita (BNSS), MHA CFCFRMS system, MRM/GRP bank portals, and Section 35(3) BNSS protections.
1. Legal Definition & Meaning of Cyber Crime
In Indian law, Cyber Crime is not defined by a single specific definition under the Information Technology Act, 2000. In practical terms, it covers any unlawful or criminal activity where a computer, mobile phone, internet network, or digital data system is used as the tool to commit the offense, or is itself the victim of unauthorized access, damage, or financial theft. These offenses are investigated under the IT Act 2000, the Bharatiya Nyaya Sanhita (BNS 2023), and relevant banking regulations.
2. Common Categories of Cyber Offenses
The following are the primary digital fraud and commercial cyber complaints registered with state cyber units:
P2P & Crypto Liens Banking
Selling cryptocurrency on exchange platforms (Binance, Bybit) where payments are received from compromised third-party bank accounts, resulting in multi-state bank liens on genuine sellers.
Task & Investment Scams Fraud
Fake stock trading applications, rating task scams, and part-time job groups run via Telegram/WhatsApp to divert victim money into mule current accounts.
Email Compromise & Spoofing Corporate
Business Email Compromise (BEC) and fake invoice modifications where business payments are redirected to unauthorized beneficiary accounts.
Digital Arrest Coercion Extortion
Impersonating Police, Customs, CBI, or ED officials on video calls with forged official letters to force victims into making fund transfers.
Data Theft & Ransomware Security
Unauthorized server access, data exfiltration, or encryption of corporate databases with demands for cryptocurrency ransom.
Mule Account Operations Financial
Operating or providing third-party bank accounts to transfer and withdraw defrauded funds across Layer 1, Layer 2, and Layer 3 stages.
3. How Bank Accounts Get Frozen: MHA I4C, MRM & GRP Portals
Understanding the inter-linked systems used by police, MHA, and banks to trace and hold disputed money.
A. MHA I4C & The Citizen Financial Cyber Fraud Reporting System (CFCFRMS)
Operated under the Ministry of Home Affairs (MHA), the CFCFRMS platform connects the 1930 emergency helpline directly with bank systems. The process works as follows:
Victim files a complaint on 1930 / cybercrime.gov.in. A unique Acknowledgement Number (Ack No) is created.
The CFCFRMS dashboard sends real-time system alerts to the Nodal Officers of all destination banks.
The system tracks how the funds moved: Layer 1 (direct recipient), Layer 2 (next transfer), Layer 3 (subsequent accounts).
Downstream banks mark an immediate debit freeze or lien on the recipient accounts to prevent cash withdrawals.
B. MRM Portal (Merchant Risk Management)
Used by payment gateways (Razorpay, Cashfree, PayU, PhonePe) and banks to monitor merchant accounts (MIDs). If money from a cyber complaint enters an online checkout or UPI VPA, the MRM system holds the merchant's settlement balance until documentation is cleared.
C. GRP Portal & Bank Cyber Desks
The Grievance Redressal Portal (GRP) is the internal desk where Bank Nodal Officers process police freeze notices. Under RBI rules, banks must provide the customer with the Ack Number, Police Station Name, State LEA Code, and IO Email ID on request.
4. Key Sections: IT Act 2000 vs Bharatiya Nyaya Sanhita (BNS)
The main statutory sections under which FIRs and notices are issued by cyber units:
| Offense Type | IT Act, 2000 | BNS 2023 (Old IPC) | Punishment / Bail Nature |
|---|---|---|---|
| Hacking & Unauthorized Data Access | Section 43 / 66 | Sec 303 BNS (Sec 379 IPC) | Up to 3 Years or Fine (Bailable) |
| Cheating by Personation via Digital Device | Section 66D | Sec 318(4) BNS (Sec 420 IPC) | Up to 3-7 Years + Fine (Cognizable) |
| Identity Theft (Fake KYC, Phishing) | Section 66C | Sec 336 BNS (Sec 468 IPC) | Up to 3 Years + Fine (Bailable) |
| Publishing Sexually Explicit Content | Section 67 / 67A | POCSO / Sec 79 BNS | 5 to 7 Years (Non-Bailable) |
| Cyber Terrorism | Section 66F | Sec 113 BNS / UAPA | Life Imprisonment (Non-Bailable) |
5. Notice Before Arrest: Section 35(3) BNSS & Arnesh Kumar Ruling
Mandatory Procedure Under Section 35(3) BNSS (Old Section 41A CrPC)
Under Section 35(3) of the Bharatiya Nagarik Suraksha Sanhita (BNSS, 2023), for offenses punishable with imprisonment of up to 7 years (such as Sec 66C, 66D IT Act and Sec 318(4) BNS), police officers cannot make an immediate routine arrest. They are required to serve a formal Notice of Appearance directing the individual to join the inquiry.
Supreme Court Directives in Arnesh Kumar v. State of Bihar:
- Arrest is not mandatory: Mere registration of a cyber crime FIR does not give police the authority to make automatic arrests.
- Written reasons are compulsory: If an officer decides to arrest, they must record clear reasons in writing explaining why custody is necessary (e.g., flight risk, evidence tampering).
- Protection for the Noticee: As long as the noticee joins the investigation, attends scheduled calls, and submits relevant transaction records, they cannot be arrested without prior written justification.
- Judicial oversight: Magistrates cannot mechanically approve judicial remand without checking whether the Section 35(3) BNSS notice procedure was followed.
6. Common Notices Issued by Cyber Crime Units
Sec 94 BNSS Notice Old Sec 91 CrPC
Issued by the Investigating Officer (IO) directing an individual or bank to submit transaction statements, trade chat logs, tax receipts, or identity documents.
Sec 106 BNSS Order Old Sec 102 CrPC
Sent directly to Bank Nodal Officers ordering debit freeze or lien marking on suspected accounts. The officer must report this freeze to the local Magistrate.
Sec 79(3)(b) IT Act Notice Takedown
Sent to websites, domain hosts, or online platforms to remove fraudulent pages, unlawful links, or infringing content within 36 hours.
7. Device Seizure Powers & Electronic Evidence Rules
| Legal Procedure | Requirements & Statutory Safeguards |
|---|---|
| Digital Hardware Seizure | When mobile devices, laptops, or servers are seized under Section 106 BNSS, the officer must generate a Cryptographic Hash Value (SHA-256) on the spot in front of independent witnesses to ensure the digital data cannot be altered later. |
| Certificate under Section 63 BSA | To use electronic records (WhatsApp chats, call records, server logs, bank spreadsheets) in court, a certificate under Section 63 of the Bharatiya Sakshya Adhiniyam (BSA, old Sec 65B) must be submitted by the person in lawful control of the device. |
8. Difference Between Cyber Cell and Cyber Police Station
Cyber Crime Cell (Inquiry Wing)
- • Not a notified Police Station under Section 2(r) BNSS.
- • Handles initial verification of 1930 / NCRP portal complaints.
- • Collects bank statements and IP logs; cannot register statutory FIRs directly.
- • Forwards the file to a local police station if a cognizable offense is confirmed.
Cyber Police Station (Designated PS)
- • Formally notified as a Police Station via State Government Gazette.
- • Holds direct authority to register FIRs under IT Act and BNS sections.
- • Has complete statutory powers to issue Section 35(3) notices, execute arrests, and conduct search operations.
- • Files formal chargesheets (Section 193 BNSS) before the designated Cyber Magistrate.
9. Who is LEA and Who is a Bank Nodal Officer?
Law Enforcement Agency (LEA)
Refers to government investigative departments including State Cyber Police, CID, CBI, and Enforcement Directorate (ED).
- • Traces money trails and sends freeze requisitions to banks.
- • Evaluates transaction proofs provided by account holders.
- • Issues formal No Objection Certificates (NOCs) to banks to lift account holds.
Bank Cyber Nodal Officer
Senior banking compliance officials appointed under RBI mandates to handle law enforcement correspondence.
- • Receives freeze alerts through the MHA CFCFRMS / GRP systems.
- • Marks liens or total debit restrictions on specific account numbers.
- • Required by law to share the Police Station name, Notice ID, and Officer email with the affected customer.
10. Step-by-Step Procedure to Unfreeze a Bank Account
The standard legal procedure for resolving lien marks and debit freezes on bank accounts:
| Step | Action Required | Practical Procedure |
|---|---|---|
| Step 1 | Collect Case Details from Bank | Visit your home branch and submit a written letter requesting the Cyber Notice Copy, Acknowledgement Number, Disputed Amount, Police Station Name, and IO Email ID. |
| Step 2 | Prepare Legitimate Fund Records | Compile your bank statements, invoices, trade logs (crypto/P2P receipts), GST returns, and identity proofs to establish that the funds were received legitimately. |
| Step 3 | Send Legal Representation to the IO | Submit a written legal reply under Section 94 BNSS / 91 CrPC to the Investigating Officer explaining the transaction and requesting removal of the lien or restriction of the hold only to the disputed amount. |
| Step 4 | Apply Before the Magistrate (Sec 503 BNSS) | If the cyber police station does not respond within a reasonable time, file an application under Section 503 BNSS (Old Sec 457 CrPC) before the jurisdictional Judicial Magistrate for orders to release the account. |
| Step 5 | Writ Petition Before High Court (Art. 226) | If an entire account with substantial funds is frozen arbitrarily by an out-of-state police unit over a minor disputed amount, file a Writ Petition before the High Court to set aside the arbitrary freeze. |
Need Assistance with a Cyber Cell Notice or Frozen Account?
We assist in drafting legal representations for police authorities and filing court applications to remove debit restrictions.
