Record preservation
Digital Arrest Evidence Checklist
This evidence checklist helps victims of digital arrest in India identify and preserve the evidence needed for legal action and record preservation. The first rule is preservation before interpretation. This checklist describes research records that can help a later review understand what happened.
Records to preserve
- call logs, caller IDs, chat handles, meeting links and timestamps;
- screenshots or recordings, where lawful and safely available;
- bank transfer references, UTRs, wallet addresses and complaint numbers;
- police, cyber portal, bank and platform acknowledgements;
- identity documents or KYC exposure records, with sensitive data redacted before publication.
How this archive labels them
A preserved record is not automatically proof of every allegation. It becomes a source item that can support a verified record, documented allegation, DISHA assessment or unresolved question.
Understanding the digital arrest method
Digital arrest is a fraud method in which criminals impersonate law-enforcement officers — CBI, narcotics bureau, customs, police — and contact their targets by video call, phone or messaging application. The impersonator claims that the target is implicated in a serious crime involving drug trafficking, money laundering, foreign currency violations or identity fraud, and insists that the target must remain on the video call — effectively under a form of surveillance — while the matter is "investigated." During this period, the fraudster instructs the victim to transfer money to specified accounts as bail, security deposit or penalty payments, to reveal sensitive personal information, or to send identity documents on the pretext of record verification. The entire interaction relies on the victim's fear of law enforcement and ignorance of the fact that no legitimate police or investigative body conducts arrests or investigations by video call in this manner.
Why evidence collection begins immediately
The moment a digital arrest interaction ends — whether through payment, escape or disconnection — the evidentiary clock starts running. Call logs and platform records may be purged on short retention cycles. Bank and payment records are available for dispute and reversal only within defined time windows. Fraudsters frequently operate through burner phone numbers, temporary virtual private networks and layered payment intermediaries that become progressively harder to trace as time passes. Evidence collection is therefore not a post-incident activity; it is a time-critical preservation task that begins while the incident is still fresh and continues until every available record has been secured and formally lodged with a complaint authority.
Filing records with the correct authorities
Each record preserved by the victim should be formally submitted to the appropriate complaint authority to create an official intake trail. India's National Cyber Crime Reporting Portal (cybercrime.gov.in) accepts digital arrest and online fraud complaints and assigns a complaint number. Bank complaints should be submitted with UTR references and timestamps to the bank's fraud team, the Reserve Bank of India's ombudsman process, and the cyber crime portal simultaneously. Where the DISHA archive holds case-file material on digital arrest incidents, the intake complaint number and the platform acknowledgement are treated as verified records under the claim-to-source system. The victim's own account of events is treated as a documented allegation pending corroboration from platform logs, bank records or law-enforcement findings.
Protecting sensitive data within the evidence file
The evidence checklist must be implemented with data-protection discipline. A victim's raw Aadhaar number, PAN, bank account details, passport scan or biometric data should never be published on a public platform, even as part of a complaint or research submission. Before any evidence item is shared with researchers, journalists, civil society organisations or this archive, sensitive identifying data should be redacted or replaced with a reference code that links back to a private file held securely by the victim or their legal representative. The archive's standard is to hold the complaint reference number, the platform name, the date and the outcome status in its public-facing records — not the raw identity documents themselves.