Three working days to cap your liability.
Under the Reserve Bank of India circular of 6 July 2017 on customer liability, an unauthorised electronic banking transaction arising from a third-party breach and reported to the bank within three working days leaves the customer with zero liability, and the bank is to credit the amount within ten working days. Separately, the first hour decides whether the money can be frozen at all. Both of those steps ask what you were shown, and the site that showed it to you has a lifespan of days.
Works on Chrome and Edge. From $4.99 (about ₹480) as a one-off, or a 7-day trial that requires a payment card.
secure-kyc-update-portal.in
Landing page · served over HTTPS
“Your account will be suspended in 24 hours. Complete KYC verification now to continue banking.”
Domain suspended four days later. Nothing left to show the bank.
Captured & sealed
SHA-256 · URL and UTC capture time
Illustrative example. Fictional account, not a real post.
In India, reporting cyber fraud on 1930 or cybercrime.gov.in can get the money held, and telling your bank within three working days caps your liability at zero under the RBI circular of 6 July 2017 where a third party breached your account. ProofSnap preserves the fraudulent page before the site disappears.
India has no scheme that refunds a defrauded customer automatically, but it does have a deadline that decides who bears the loss. Under the Reserve Bank of India framework on customer liability in unauthorised electronic banking transactions, a customer who notifies the bank within three working days of receiving the communication about the transaction bears zero liability, and the bank is to credit the amount to the account within ten working days. Before that, there is the practical window everyone calls the golden hour: report on the national helpline 1930, operated round the clock by the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs, and the money can sometimes be held at the beneficiary account before it moves on. The written complaint goes to the National Cyber Crime Reporting Portal at cybercrime.gov.in, and a police complaint follows. All three routes work from documents, and the documents are the pages that persuaded you: the fake store, the cloned bank page, the KYC update form, the investment dashboard showing your balance. They exist for days. ProofSnap captures each of them as a package with the full page, the saved source, the URL, the capture time in UTC, an SHA-256 hash of every file and an RSA-4096 signature, which is also the hash a section 63 certificate has to state. From $4.99 (about ₹480) as a one-off.
Radim Motycka, Founder and Lead Engineer, ProofSnap · · Independently verifiable via Trust Verifier
Why claims fail later
The site is gone before anyone asks to see it
Fraud infrastructure is disposable. By the time a bank, a portal or a court looks at the matter, the thing that convinced you has been taken down.
Domains live for days
A fake store, a cloned bank page or a KYC form exists for days, sometimes hours. Once the domain is suspended, the page you entered your details on cannot be produced by you, by the bank or by the investigating officer.
The account deletes itself
Investment, task-based and romance frauds run through profiles and groups that are wound up the moment the money moves. The pitch, the promises and the payment instructions go with them.
The bank decides on the basis of what you can show
A bank assessing customer liability looks at what was shown to you and what warnings you were given. If the page cannot be produced, the assessment is made without it, and an escalation to the banking ombudsman starts from the same gap.
The order of operations, and why it is this order
Each step depends on the one before it. Getting the order wrong costs you either the money or the proof.
The first hour is about the money
Call 1930 or file on cybercrime.gov.in immediately. Reporting inside the golden hour is what allows the funds to be held at the beneficiary account before they are layered away. This is measured in minutes, not days.
Three working days is about the liability
Under the RBI circular of 6 July 2017 on customer liability, notifying the bank within three working days of receiving the communication about an unauthorised electronic transaction leaves the customer with zero liability where the loss arose from a third party breach, and the bank is to credit the amount within ten working days. Where you shared the payment credentials yourself, for example on a phishing page, you bear the loss until you report the transaction, which is why the page you were tricked on is worth preserving. Delay shifts the loss towards you.
Capture what you were shown
Before the domain is suspended, capture the store, the payment page, the cloned portal, the profile and the message thread. This is the step nobody prompts you to take and the only one that cannot be recovered afterwards.
Then the written complaint and the FIR
File the complaint on the National Cyber Crime Reporting Portal and follow it with a police complaint. Keep the acknowledgement number. A same-day report is treated very differently from one made three weeks later.
Investment and task frauds: capture the dashboard too
In an investment or task-based fraud, the most revealing document is not the pitch but the fake dashboard showing your balance growing. It is what explains why you kept paying, and it is the clearest demonstration of how the deception worked. The dashboard disappears with the account, so capture it alongside the offer and the chat with the handler.
How do I capture a page in 41 seconds?
No forensic training required. The proof is in the package, not in your account of how careful you were.
Freeze first, then capture
Call 1930 and your bank. Then open the store, the payment page, the profile or the thread in Chrome or Edge and capture each one from the side panel while the money is being stopped.
The package seals itself
Every file receives an SHA-256 hash, the manifest is signed with an RSA-4096 key, and the manifest hash is anchored to Bitcoin. The capture time is recorded in UTC, independent of your device clock.
Report and attach the file
File on cybercrime.gov.in and with the police, and submit the package to the bank with the claim. If the bank rejects it, the same file goes to the banking ombudsman without rebuilding anything.
What is in the evidence package?
Between 11 and 15 files depending on your plan, delivered as one ZIP that anyone can check without installing anything.
Full-page screenshot
The whole page, not just the visible window, stitched and hashed.
Saved page source
The document as rendered at capture time, including the head, meta tags and structured data.
Extracted page text
Searchable plain text, so a quote can be found and cited without retyping.
Technical metadata
URL, page title, HTTP response headers, browser, operating system and the capture time in UTC.
Signed manifest
SHA-256 for every file, signed with an RSA-4096 key whose public key ships in the package.
Blockchain timestamp
The manifest hash anchored to Bitcoin via OpenTimestamps, so the capture time cannot be backdated.
Chain of custody and forensic log
A record of what happened during the capture, in the order it happened.
Evidence report as PDF
A readable summary you can attach to an application, a notice or a report.
Verification instructions
Written steps plus scripts, so the other side can re-check the hashes offline.
Anyone can verify it, including the other side. Drop the ZIP onto the public Trust Verifier, and the hashes, the signature and the timestamp are checked in the browser. Nothing is uploaded and nothing depends on ProofSnap still existing.
Three ways to get the evidence
Prices are charged in USD. Approximate rupee figures are for orientation only, converted at about ₹96 to US$1, and your card issuer sets the actual rate.
One matter
$4.99 once
about ₹480
A SnapPack is a single up-front purchase for a set number of captures. No subscription, no auto-renewal, no trial. Best when you have one matter and you want it documented today.
Get a SnapPackOngoing matters
$8.99/month
about ₹860
For anyone who captures regularly: advocates, compliance teams, investigators, brand protection. The 7-day free trial requires a payment card. Cancel any time during the trial and you are not charged.
Start the 7-day trialWe do it for you
$44.99 per URL
about ₹4,300
Send us the link and our team captures the package for you, with nothing to install. Useful when the capture should not come from a party to the dispute.
See the capture serviceProofSnap is not a law firm and does not give legal advice. India has no equivalent of an EU qualified timestamp, so the eIDAS option carries no presumption before an Indian court and is offered on Enterprise plans for cross-border matters. What section 63 of the Bharatiya Sakshya Adhiniyam asks for is the hash value of the record, which every package contains.
Official sources
Every figure and deadline on this page comes from the following primary sources. Check them yourself rather than taking our word for it.
- National Cyber Crime Reporting Portal the official portal for filing a cyber crime complaint, with the 1930 helpline.
- RBI: customer protection, limiting liability in unauthorised electronic banking transactions the three-working-day rule and the ten-working-day credit.
- Section 63, Bharatiya Sakshya Adhiniyam 2023 the certificate requirement, including the hash value.
ProofSnap does not recover money and does not replace a report. What it does is make sure the page that convinced you still exists in a checkable form when the bank, the ombudsman or the court asks what exactly you were shown.
Questions people actually ask
The site will be gone this week
Freeze the money, capture the page, file the complaint. In that order.