Cybercrime is any crime committed through computers, phones or the internet. It ranges from phishing and online payment fraud to identity theft, hacking, ransomware, extortion and the sharing of child sexual abuse material. If it happens to you, speed matters most: call your bank, report the crime (in India, on 1930 or cybercrime.gov.in), secure your accounts and keep the evidence.
This guide explains cybercrime from zero: what it is, the forms you are most likely to meet, why it is so common, and a step-by-step plan for the first hours after an incident, for individuals and for organisations.
What cybercrime means
Cybercrime covers two broad groups of offences:
- Crimes against computers. The computer or network is the target: hacking into systems, spreading malware, ransomware, denial-of-service attacks and data theft.
- Crimes using computers. The internet is the tool for an old crime: fraud, theft, extortion, harassment, stalking and the abuse of children.
Most people meet the second group. A fake bank message, a marketplace buyer who “overpays” by UPI, an investment group on a messaging app, a caller claiming to be from customs: these are classic frauds moved online, where they reach thousands of people at almost no cost to the criminal.
The scale is large. The FBI’s Internet Crime Complaint Center received 1,008,597 complaints in 2025, with reported losses of $20.877 billion, according to its 2025 Internet Crime Report. Phishing and spoofing led by number of complaints, while investment fraud caused the largest losses.
The most common types of cybercrime
| Type | How it usually works | Who it hits |
|---|---|---|
| Phishing, smishing and vishing | Fake emails, texts or calls that steal logins, OTPs or card details | Everyone |
| Online payment and UPI fraud | Fake buyers, refund scams, “collect requests” sent as if they were payments | Individuals and small sellers |
| Investment and trading scams | Fake apps or groups that show invented profits, then block withdrawals | Individuals |
| Identity theft | Stolen personal data used to open accounts, take loans or SIM-swap a number | Individuals |
| Business email compromise | A spoofed or hijacked executive or supplier account asks for a payment | Companies |
| Hacking and data breaches | Break-ins to steal or sell databases and access | Companies and institutions |
| Ransomware | Data is stolen and systems are encrypted until a ransom is paid | Companies, hospitals, governments |
| Extortion and harassment | Sextortion threats, cyberstalking, abuse on social media | Individuals |
| Child sexual abuse material | Producing, sharing or viewing it online is a serious crime almost everywhere | Children |
Most of these start with deception rather than technical skill. We explain the main variants of the most common one in 10 types of phishing attacks.
Why people commit cybercrime, and why it works
The motive is usually money. Others act for revenge, ideology, espionage or notoriety. Cybercrime works for criminals for three plain reasons: it is cheap to attempt at scale, it is easy to do from another country, and much of it is never reported. Stolen passwords, card details and access to company networks are traded on criminal forums, so a breach at one company often feeds fraud against its customers months later.
What to do if you are a victim: the first hour
Time matters most with financial fraud. The sooner a transaction is reported, the better the chance that the receiving account can be frozen.
- Call your bank or wallet provider immediately and ask them to block the card, account or UPI ID involved. Use the number on the back of your card or in the official app, never one from the message.
- Report the crime. In India, call the national cyber crime helpline 1930, or file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in. Elsewhere, use your national reporting service; in the US that is the FBI’s IC3.
- Change your passwords, starting with email, banking and any account that used the same password. Turn on two-step verification.
- Keep the evidence. Take screenshots of messages, profiles, payment confirmations and transaction IDs. Don’t delete the chat or email.
- Check for further damage. Look for new devices signed into your accounts, forwarding rules in your email, and messages sent in your name.
- Warn people who might be targeted next, such as your contacts if your messaging or social account was taken over.
Speed also affects who carries the loss. Under the Reserve Bank of India’s 2017 circular on limiting customer liability for unauthorised electronic banking transactions, a customer has zero liability for a third-party breach reported within three working days of the bank’s alert. Where the loss came from the customer sharing payment credentials, the customer bears it until the transaction is reported.
What organisations should do
A cyber incident at a company is both a technical problem and a legal one.
- Contain first. Isolate affected machines, reset exposed credentials and preserve logs before anyone wipes and rebuilds.
- Report on time. In India, the CERT-In Directions of April 28, 2022 require service providers, data centres, companies and government organisations to report listed cyber incidents to CERT-In within 6 hours of noticing them.
- Find out what leaked. Stolen data and access often appear for sale. Dark web monitoring shows whether your credentials, databases or network access are being traded.
- Remove the scam infrastructure. Phishing sites, fake apps and impersonation accounts using your brand can be taken down at the registrar, host or platform.
If you suspect one of your accounts is already in someone else’s hands, our checklist of compromised account signals will help you confirm it.
How to protect yourself from cybercrime
- Use a password manager and a different password for every account.
- Turn on two-step verification, and prefer an authenticator app or passkey over SMS where you can.
- Never share an OTP, PIN or card CVV with anyone, whoever they claim to be.
- Treat urgency as a warning sign: “your account will be blocked today” is a pressure tactic.
- Keep your phone, browser and operating system updated.
- Install apps only from official stores, and never install a remote access app because a caller asked you to.
FAQ
What is the difference between cybercrime and cyber fraud?
Cyber fraud is one kind of cybercrime: deceiving someone online to take their money or data. Cybercrime is the wider term and also covers hacking, malware, ransomware, harassment, stalking and child abuse material, where the goal isn’t always financial. Most cybercrime that ordinary people meet, though, is some form of fraud.
Where do I report cybercrime in India?
Call the national cyber crime helpline 1930 as soon as possible if money has been lost, or file a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in. Keep screenshots, transaction IDs and the phone numbers or links involved. Organisations must also report listed incidents to CERT-In within 6 hours.
Can I get my money back after online fraud?
Sometimes. Your chances are best if you report within hours, because the bank and police can try to freeze the receiving account before the money moves on. Under RBI rules, how much of the loss you carry depends on how the fraud happened and how quickly you reported it. Reporting late rarely helps.
Is it worth reporting a scam attempt if I didn’t lose money?
Yes. Reports of attempted fraud help block numbers, links and accounts before they reach others. In India, suspicious calls, SMS and WhatsApp messages can be reported through the Chakshu facility on the Sanchar Saathi portal, and phishing emails through your mail provider’s report button.
