Delhi-focused information on PMLA, ED and economic-offence proceedings+91 82944 31232ankitsingh.legum@gmail.com

PMLA / ED

Fake Customer-Care Number Found on Google: Who Is Liable, How Can the Listing Be Traced and How Can Money Be Recovered?

India 2026 guide to Search/Maps manipulation, fake support pages, remote-access fraud, payment tracing and digital evidence The person operating the fraudulent customer-care number and the persons knowingly participating in the deception or movement of the fra

By Advocate Ankit Kumar Singh

India 2026 guide to Search/Maps manipulation, fake support pages, remote-access fraud, payment tracing and digital evidence

By Advocate Ankit Kumar Singh

Last verified: 12 August 2026

Direct Answer: Who Is Liable If I Called a Fake Customer-Care Number Found on Google?

The person operating the fraudulent customer-care number and the persons knowingly participating in the deception or movement of the fraud proceeds are the primary subjects of investigation.

But the fact that the victim found the number through Google Search, Google Maps or an advertisement does not automatically make Google liable for the entire loss.

Likewise, if fraudsters copied the name of a bank, airline, e-commerce company, wallet provider, courier company, electronics manufacturer or another genuine business, that genuine business is not automatically the fraud operator.

Liability must be separated by role:

  1. Who created or controlled the fake listing/page?
  2. Who operated the phone number?
  3. Who induced the victim to act?
  4. Who obtained remote access or credentials?
  5. Who received the payment?
  6. Who withdrew or layered the proceeds?
  7. Was the genuine brand involved at all?
  8. What did the search/intermediary platform host or display?
  9. Was the platform placed on sufficiently specific notice?
  10. What records are available to connect the infrastructure to the operator?

The strongest case is built from the complete digital and financial trail rather than from the single proposition:

“I saw the number on Google.”

1. What Is a Fake Customer-Care / Search-Poisoning Scam?

Search poisoning in this context means creating, manipulating or promoting online content so that a fraudulent support number or support webpage becomes visible when a user searches for urgent customer assistance.

Typical searches include:

  • “[bank name] customer care number”;
  • “[airline] refund helpline”;
  • “[wallet] payment failed customer care”;
  • “[e-commerce company] refund phone number”;
  • “[courier company] complaint number”;
  • “[AC/TV/refrigerator company] service centre near me”;
  • “FASTag refund customer care”;
  • “gas booking complaint number”;
  • “hotel booking refund number”; or
  • “loan app customer support”.

The victim is already seeking assistance and therefore expects to speak to someone who knows the brand’s processes.

The fraudster exploits that pre-existing trust.

2. Four Different Ways the Fake Number May Appear

Discovery Surface What the Victim Sees Evidence to Preserve
Organic Search Result Fake support webpage ranking for the customer-care query Search query, result title, URL, snippet, position, timestamp
Google Maps / Business Profile Business name, phone, address, website or service centre entry Profile URL, phone, website, map location, reviews, screenshots
Sponsored Advertisement Paid search result or promoted listing Ad disclosure, advertiser details shown, destination URL, screenshots
Fake Support Website Independent webpage containing numbers for multiple brands Full URL, domain, page copy, number, RDAP data, screenshots

These pathways should not be mixed together in the complaint. Investigators need to know whether the victim clicked an advertisement, Maps listing or ordinary webpage.

3. First Rule: Preserve the Search Result Before It Disappears

Fraudulent listings and pages can change rapidly.

A number may be replaced, the webpage removed, the profile suspended, the business name altered or the advertisement stopped.

Before repeatedly reporting the listing, preserve the visible evidence if it is still accessible.

Search-result evidence checklist

  1. Exact words typed into Google.
  2. Date and exact time.
  3. Device used.
  4. Browser/app used.
  5. Search-result screenshot showing surrounding context.
  6. Whether the result said “Sponsored”.
  7. Result title.
  8. Displayed domain.
  9. Full destination URL.
  10. Displayed customer-care number.
  11. Maps/Business Profile URL if applicable.
  12. Business name.
  13. Address shown.
  14. Website linked from the profile.
  15. Ratings/reviews visible at that time.
  16. Any “call” button or click-to-call interface used.

Where appropriate, make a screen recording showing the route from the search result to the listing/page without logging into sensitive accounts or interacting further with the fraudster.

4. Google Maps / Business Profile Manipulation

Google’s official Business Profile rules require the phone number and website associated with a profile to represent the actual business and be under appropriate business control.

Google also provides a specific reporting route for misleading business names, phone numbers or business URLs that suggest fraudulent activity.

What to preserve from a suspected fake Business Profile

  • profile URL;
  • exact business name;
  • category;
  • telephone number;
  • website;
  • address/location;
  • opening hours;
  • photographs;
  • reviews;
  • date/time viewed; and
  • comparison with the genuine brand’s official contact page.

Reporting route

Google Maps allows misleading business information to be reported from the profile and directs users to its Business Redressal Complaint process where misleading names, phone numbers or URLs raise suspected fraud.

5. What If the Scam Came Through a Sponsored Google Ad?

Preserve the fact that the result was an advertisement.

Do not crop away the “Sponsored” or advertising disclosure.

Capture:

  • search query;
  • advertisement headline;
  • display URL;
  • actual landing-page URL;
  • telephone number;
  • advertiser information visible through the interface, if available;
  • screenshots; and
  • date/time.

Google provides a formal “Report an ad or listing” complaint route for inappropriate or policy-violating advertisements.

The complaint to the advertising platform is separate from the police/NCRP complaint.

6. Fake Organic Support Pages and “Customer Care Number” Websites

A fraudulent result may be an ordinary webpage rather than a Maps listing or ad.

Such a website may contain hundreds of brand names and telephone numbers in order to attract high-intent searches.

Preserve:

  • full page URL;
  • domain name;
  • page title;
  • support number;
  • brand logos/names copied;
  • contact form;
  • email addresses;
  • payment links;
  • other brands impersonated;
  • page-source or forensic capture where professionally necessary; and
  • search-query result that led to the page.

A phishing or social-engineering page may also be reported through the appropriate Google Search/Safe Browsing reporting channel.

7. How Can the Fake Website Be Traced?

Public domain-registration information is only one starting point.

ICANN’s Registration Data Access Protocol, or RDAP, provides access to current domain-registration data and has replaced the older WHOIS protocol for relevant registration-data access.

RDAP may help identify information such as:

  • sponsoring registrar;
  • registration dates;
  • domain status;
  • nameservers;
  • registry information; and
  • certain registration contacts where not redacted or otherwise restricted.

Public RDAP data may not identify the actual scammer because privacy/redaction, proxy services or false registration information may intervene.

Therefore the investigation may require lawful requests to:

  • domain registrar;
  • hosting provider;
  • CDN/reverse-proxy provider where relevant;
  • email provider;
  • advertising platform;
  • search/business-profile platform; and
  • payment provider.

Depending upon what is retained and lawfully obtainable, useful records may include account-registration data, billing records, verification information, login/access data and infrastructure records.

8. Preservation Notice vs Disclosure Request: They Are Not the Same

A victim or genuine brand may send a complaint requesting that a fraudulent page/listing be disabled and relevant records be preserved.

But asking a private platform to preserve data is different from compelling it to disclose private account records to the victim.

Google states that government requests for user information are reviewed for compliance with applicable law and legal process.

Under the current IT Rules, an intermediary receiving a lawful written order from an authorised government agency for investigative, protective or cyber-security purposes is required, within the applicable framework, to provide information or assistance under its control or possession.

Therefore a practical case strategy can involve:

  1. victim preserves public evidence;
  2. victim reports the fraud to the platform;
  3. victim requests preservation of relevant platform records where appropriate;
  4. Cyber Police identifies the records required; and
  5. lawful disclosure requests/orders are sent through the appropriate official channel.

9. What Platform Records Might Matter?

The exact data available varies by product and retention policy. Do not assume every item exists.

Potentially relevant categories may include:

  • Business Profile creation/account information;
  • profile verification data;
  • account manager/owner identifiers;
  • phone-number changes;
  • website-URL changes;
  • business-name changes;
  • profile suspension history;
  • associated email/account identifiers;
  • advertising-account information;
  • billing/payment data;
  • ad creative and destination URLs;
  • access/login records where retained;
  • associated accounts or campaigns;
  • content/report history; and
  • other records identified through lawful investigation.

A complaint should identify the precise profile URL, ad, webpage or account rather than asking generally for “all Google data”.

10. How Can the Fake Phone Number Be Investigated?

Preserve the number exactly as displayed, including country code.

Also preserve:

  • call log;
  • date/time;
  • call duration;
  • callback numbers;
  • SMS messages;
  • WhatsApp account if used;
  • caller-ID label;
  • recording, where lawfully available;
  • exact words used by the caller;
  • name/designation claimed; and
  • numbers used after the first call.

During investigation, telecom subscriber/account records and call-related records may be sought through lawful process, subject to provider availability and retention.

The displayed number should not automatically be treated as conclusive proof of the physical person who spoke to the victim.

11. The Remote-Access Stage: Why “Customer Care” Wants Your Screen

Fake support callers may ask the victim to install or open remote-access or screen-sharing software under the pretext of:

  • processing a refund;
  • checking a failed transaction;
  • completing KYC;
  • resolving a wallet problem;
  • fixing mobile banking;
  • activating an account;
  • cancelling an order; or
  • demonstrating a refund form.

Remote-access software itself may be legitimate technology. The fraud arises when the caller dishonestly uses access to view or manipulate sensitive activity.

If remote access was granted, preserve:

  • application name;
  • installation time;
  • session ID/code;
  • screenshots;
  • permissions granted;
  • downloads;
  • browser activity;
  • SMS/notification events;
  • banking activity during the session; and
  • approximate time remote control ended.

Disconnect unauthorised remote access and secure exposed accounts from a trusted device.

12. The Payment Trail Is Often Stronger Than the Search Result

The fake listing explains how the victim entered the fraud.

The payment trail can identify where the proceeds went.

UPI payment evidence

  • VPA/UPI ID;
  • beneficiary display name;
  • UTR/RRN/reference;
  • amount;
  • date/time;
  • QR code;
  • payment app;
  • transaction screenshot; and
  • bank statement.

Bank-transfer evidence

  • account number;
  • beneficiary name;
  • IFSC;
  • UTR;
  • transaction mode;
  • amount;
  • date/time; and
  • bank confirmation.

Card / merchant-payment evidence

  • merchant name displayed;
  • transaction reference;
  • amount;
  • date/time;
  • card issuer;
  • merchant/acquirer information later supplied by the bank; and
  • dispute/chargeback reference, if initiated.

Do not assume that the first beneficiary account is the final beneficiary. Cyber-fraud proceeds may be moved onward through intermediary accounts.

13. If Money Was Lost: Immediate 1930 / Bank / NCRP Sequence

  1. Notify the bank/payment provider immediately.
  2. Call National Cybercrime Helpline 1930 promptly.
  3. Record the 1930 acknowledgement/reference.
  4. Complete the complaint through cybercrime.gov.in.
  5. Preserve the UTR/RRN/VPA/account/merchant details.
  6. Preserve the fake listing, page, number and call evidence.
  7. Do not send additional money for “refund processing”.

I4C’s CFCFRMS framework allows verified financial-cyber-fraud complaints to be shared with participating financial institutions for tracing/freezing intervention.

Prompt reporting may improve the possibility of intercepting available funds, but no freezing or recovery can be guaranteed.

14. Does RBI Require the Bank to Refund Me?

Do not assume that every fake-customer-care loss automatically receives a full refund.

RBI’s customer-protection framework concerning unauthorised electronic banking transactions distinguishes different factual situations.

RBI provides zero-liability protection in specified cases, including qualifying third-party breaches where the deficiency lies neither with the bank nor customer and the customer reports within the prescribed period.

Conversely, where the loss is due to customer negligence such as sharing payment credentials, RBI’s directions provide a different allocation of liability until reporting occurs.

A further practical complication is that some social-engineering cases involve the victim personally initiating or authenticating the transfer because of deception.

Whether such a transaction fits the bank’s “unauthorised transaction” liability framework requires analysis of:

  • who technically initiated the transaction;
  • whether remote access was used;
  • whether credentials were taken;
  • whether an OTP/PIN was voluntarily shared;
  • whether the victim was deceived into authenticating;
  • bank/system security evidence;
  • time of reporting; and
  • the applicable bank/payment instrument rules.

Therefore, always lodge the bank dispute promptly, but do not promise automatic reimbursement.

15. Who Is Potentially Liable? Role-by-Role Matrix

Actor Possible Role Liability Position
Fake customer-care operator Deception, personation, payment inducement Primary criminal investigation target where evidence establishes involvement
Account / UPI / merchant recipient Receives or transfers proceeds Depends on knowledge, participation, commission, withdrawals and surrounding evidence
Fake website operator Creates impersonating support page Potentially connected to deception/personation if attribution is proved
Telephone account operator Receives victim calls Requires subscriber, device and actual-user attribution
Genuine brand Identity being impersonated Not automatically liable merely because its name/logo was copied
Search/Maps intermediary Hosts/displays third-party information Not automatically liable; Section 79 and due-diligence framework require fact-specific analysis
Hosting provider / registrar Infrastructure layer Infrastructure relationship alone does not prove participation in fraud
Bank/payment provider Processes disputed transaction Customer-protection and dispute obligations depend on transaction facts and applicable regulation

16. When Could the Genuine Brand Become Relevant?

The genuine brand should normally be contacted immediately to confirm that:

  • the number is not its official helpline;
  • the website is not authorised;
  • the claimed employee/agent does not belong to it, where verifiable;
  • the payment destination is not its authorised collection channel; and
  • the relevant official contact information.

This verification can be valuable evidence because it separates impersonation from genuine support activity.

The genuine company’s liability should be considered separately only where facts indicate something more, for example:

  • the disputed listing was actually controlled by the company;
  • the caller was an authorised employee/agent;
  • the payment reached an authorised account;
  • the company’s own account/system was compromised in a causally relevant manner; or
  • another independent legal basis for liability exists.

Do not join the genuine brand as the fraud operator merely because the fraudster pronounced its name.

17. Google / Search Platform Liability: Why It Is Not Automatic

Section 79 of the Information Technology Act provides an exemption from intermediary liability for qualifying third-party information subject to the statutory conditions.

The protection is conditional upon matters including the nature of the intermediary function and observance of due diligence.

Section 79 also contains exceptions where, among other things, the intermediary has conspired, abetted, aided or induced the unlawful act, or fails to act within the applicable statutory framework after the legally relevant knowledge/notification described in the Act.

The current IT Rules separately impose grievance-redressal and due-diligence obligations.

Therefore, the legal enquiry should be evidence-based:

  • what exact product/surface displayed the content;
  • whether it was third-party information;
  • what complaint was sent;
  • whether the offending URL/profile/number was specifically identified;
  • when notice was received;
  • what action followed;
  • whether the platform otherwise participated in the unlawful act; and
  • which statutory duties actually apply.

A blog should not promise that a victim can recover fraud loss directly from Google merely by showing a screenshot of a search result.

18. Current Intermediary Grievance Timelines Matter

Under the IT Rules updated as on 10 February 2026, an intermediary’s grievance mechanism generally requires acknowledgement of a complaint within twenty-four hours and resolution within seven days.

Certain removal complaints falling within the relevant rule are subject to more expedited treatment.

The grievance complaint should therefore be specific.

Include:

  • exact URL/profile;
  • fake phone number;
  • genuine business identification;
  • screenshots;
  • why the listing is fraudulent;
  • cybercrime acknowledgement where available;
  • request for disabling/removal as applicable; and
  • request that relevant account/listing records be preserved pending lawful investigation.

19. Sample Platform Fraud / Preservation Notice

SUBJECT: FRAUDULENT CUSTOMER-CARE LISTING / IMPERSONATION —
REQUEST FOR REVIEW, DISABLING AND PRESERVATION OF RECORDS

I am reporting a listing / advertisement / webpage appearing through
[GOOGLE SEARCH / GOOGLE MAPS / GOOGLE ADS / OTHER SERVICE].

Exact URL / Profile URL:
Search query used:
Date and time observed:
Displayed business name:
Displayed phone number:
Displayed website:

The above content appears to impersonate:

[Genuine Business Name]

Official website/contact reference:
[DETAIL]

I contacted the displayed number on [DATE/TIME] believing it to be genuine.

Thereafter the following occurred:
[BRIEF FACTUAL CHRONOLOGY]

Financial loss, if any:
Amount:
Payment mode:
Transaction reference:

Cybercrime / police reference:
1930 acknowledgement:
NCRP acknowledgement:

I request:

1. urgent review under the applicable fraud/misrepresentation policies;
2. disabling/removal where warranted;
3. preservation, to the extent permitted by law and applicable retention
   systems, of relevant account/profile/advertising records pending lawful
   investigation; and
4. retention of the complaint/reference number.

This request does not seek disclosure of private user information directly
to me where lawful process is required. Relevant investigating authorities
may separately issue appropriate legal requests.
  

20. Sample Genuine-Brand Verification Request

SUBJECT: REQUEST TO VERIFY SUSPECTED FAKE CUSTOMER-CARE NUMBER

On [DATE] I searched for customer support relating to [ISSUE].

I found the following telephone number / webpage / listing:

Phone:
URL:
Displayed name:
Search/Maps location:

I contacted the number and the caller represented himself/herself as being
associated with your organisation.

The caller instructed me to:
[REMOTE ACCESS / UPI / CARD / OTP / OTHER]

Please confirm, to the extent you are able:

1. whether the above telephone number is an authorised customer-care number;
2. whether the website/listing is operated or authorised by your organisation;
3. whether the payment account/UPI ID supplied is an authorised collection
   channel; and
4. the correct official customer-support channel.

The information is required for a cybercrime complaint concerning suspected
impersonation of your organisation.

Cybercrime acknowledgement, if available:
[NUMBER]
  

21. Sample Bank Fraud / Transaction Dispute Narrative

On [DATE/TIME], after searching online for the customer-care number of
[GENUINE BRAND], I contacted [PHONE NUMBER] believing it to be an authorised
support number.

The caller represented himself/herself as [CLAIMED ROLE].

I was instructed to [DESCRIBE EXACT STEPS].

The disputed transaction is:

Amount:
Date/time:
Mode:
UPI ID / beneficiary account / merchant:
UTR / RRN / reference:

I subsequently independently verified that the customer-care number /
website was not authorised by the genuine brand and suspect that I was
deceived through a fraudulent customer-care impersonation.

I request:

• immediate fraud marking / restriction as applicable;
• investigation of the disputed transaction;
• preservation of relevant transaction and authentication records;
• communication to the beneficiary/acquiring/payment institution where
  permitted;
• registration of my dispute under the applicable customer-protection /
  transaction-dispute framework; and
• a written complaint/reference number.

1930 acknowledgement:
NCRP acknowledgement:
Police complaint/FIR, if any:
  

22. Criminal-Law Matrix

Conduct Potential Provision Accuracy Note
Deception induces delivery of money/property BNS Section 318 Cheating; exact ingredients must be proved
Fraudster pretends to be genuine customer-care executive/company representative BNS Section 319 Cheating by personation where ingredients exist
False electronic support document/payment document created BNS Section 336 Forgery analysis depends on the particular electronic record and intent
Known forged electronic document used as genuine BNS Section 340 Apply only where statutory requirements are established
Electronic/computer-resource personation IT Act Section 66D Highly relevant where cheating by personation occurs through communication/computer resource
Password/unique electronic identification feature fraudulently used IT Act Section 66C Identity-theft ingredients must be established
Unauthorised computer access through remote-access misuse IT Act Sections 43/66 Depends on authorisation, conduct and dishonest/fraudulent intent

A complaint should describe the conduct first. The investigating agency can apply appropriate provisions from the proved facts.

23. Can I Complain at My Local Police Station If the Fraudster Is in Another State?

Cyber-fraud infrastructure may span several States.

Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 provides that information relating to a cognizable offence may be given irrespective of the area where the offence was committed.

That is important where:

  • victim is in another Indian jurisdiction;
  • fake support webpage is hosted elsewhere;
  • phone SIM is registered in another State;
  • beneficiary account is elsewhere;
  • advertiser/account infrastructure is outside the State; or
  • fraud proceeds pass through multiple jurisdictions.

24. Digital Evidence: Do Not Submit Only a Cropped Screenshot

A screenshot of the fake number is useful, but the evidentiary package should be broader.

Preserve:

  • search-result screenshots;
  • full URL;
  • Maps Business Profile URL;
  • advertisement evidence;
  • original browser history;
  • call logs;
  • call recordings where lawfully available;
  • WhatsApp/SMS communications;
  • remote-access application information;
  • UPI/card/bank records;
  • 1930/NCRP acknowledgements;
  • brand verification email;
  • platform complaint acknowledgement;
  • RDAP result;
  • original PDFs/images/files; and
  • a complete chronology.

Sections 61 to 63 of the Bharatiya Sakshya Adhiniyam, 2023 govern electronic/digital records and their proof.

The statutory Section 63 certificate schedule expressly includes source/device information and hash-value fields.

Therefore, where litigation is likely, preserve original electronic sources rather than repeatedly editing, cropping or resaving every item.

25. Recommended Evidence Chronology

10:04 AM — Searched “[BRAND] customer care number”
10:05 AM — Search/Maps result opened
10:06 AM — Number +91XXXXXXXXXX displayed
10:07 AM — Call initiated
10:09 AM — Caller claimed to be customer-care executive
10:13 AM — Remote-access app requested
10:16 AM — Screen-sharing/remote session started
10:21 AM — Caller requested UPI/card/bank action
10:24 AM — First disputed transaction
10:29 AM — Second disputed transaction
10:36 AM — Call ended
10:44 AM — Genuine brand contacted independently
10:51 AM — Number confirmed unauthorised
10:55 AM — Bank fraud complaint registered
11:01 AM — 1930 called
11:18 AM — NCRP complaint completed
11:27 AM — Fake Maps/Search result preserved/reported
11:42 AM — Platform complaint/reference recorded
  

Use actual times from devices, bank records and acknowledgements. Do not reconstruct exact times from memory where they can be verified objectively.

26. How the Fake Listing Can Be Traced — Investigation Map

SEARCH / MAPS / AD
        ↓
PRESERVE RESULT + URL + NUMBER
        ↓
       ┌────────────┬─────────────┬─────────────┐
       ↓            ↓             ↓
   PHONE TRACE   DOMAIN/PROFILE  PAYMENT TRACE
       ↓            ↓             ↓
CALL / SUBSCRIBER  RDAP / HOST   VPA / UTR /
                    PLATFORM      BANK / MERCHANT
       └────────────┴─────────────┴─────────────┘
                       ↓
             CORRELATE TIMESTAMPS
                       ↓
          BANK + 1930 + NCRP + POLICE
                       ↓
     LAWFUL REQUESTS FOR PRIVATE RECORDS
                       ↓
        IDENTIFY ACTUAL ROLE / KNOWLEDGE
  

27. Common Mistakes That Weaken the Case

  • Reporting the fake Maps listing before taking any screenshot.
  • Saving only the phone number but not the profile URL.
  • Failing to note whether the result was Sponsored.
  • Cropping out the search query and surrounding result.
  • Deleting browser history immediately.
  • Uninstalling remote-access software before documenting what was used.
  • Failing to obtain UTR/RRN/payment references.
  • Calling the fraudster repeatedly after discovering the scam.
  • Waiting several days before notifying the bank and 1930.
  • Accusing the genuine brand without first verifying the number.
  • Assuming the beneficiary account holder must necessarily be the mastermind.
  • Assuming a SIM subscriber necessarily made the call personally.
  • Assuming the web-domain registrant is necessarily the actual offender.
  • Demanding private platform account data directly from customer support rather than obtaining lawful investigative process.
  • Assuming appearance in Google Search automatically establishes Google’s liability.

28. Frequently Asked Questions

Q1. I called a number shown on Google. Is Google responsible for my loss?

Not automatically. The role of the particular Google surface, third-party information, Section 79 intermediary protection, due-diligence obligations, notice received and other facts must be examined. The fake operator remains the immediate fraud target.

Q2. Can a fake number really appear on Google Maps?

Misleading phone numbers, business names and URLs can be reported through Google’s Maps and Business Redressal mechanisms. Preserve the profile before reporting it.

Q3. How do I prove the number was on Google?

Preserve the search query, screenshot, profile/result URL, number, date/time and browser/device context. Where possible, preserve the entire route rather than one cropped image.

Q4. Can Google reveal who created the fake listing to me?

Private user/account information is generally subject to applicable privacy law and legal process. Police or other authorised agencies may seek relevant records through lawful requests.

Q5. Can the domain owner be identified?

RDAP can provide current registration information such as registrar and technical/domain data, but registrant identity may be redacted. Further registrar/hosting data may require lawful process.

Q6. Should I report the fake listing first or call 1930 first?

If money has been transferred, bank and 1930 reporting should be immediate. Preserve the visible listing quickly if possible, but do not delay the financial-fraud response.

Q7. Is the genuine company liable because the fraudster used its logo?

Mere impersonation does not automatically make the genuine brand the fraud operator. Its role must be assessed from actual control, agency, payment and system evidence.

Q8. The scammer made me install AnyDesk or another remote-access app. What should I preserve?

Preserve the app name, session information, installation time, call chronology, screenshots and banking events during the remote session. Secure affected accounts from a trusted device.

Q9. I personally entered my UPI PIN because the caller deceived me. Will the bank refund automatically?

No automatic result should be promised. Notify the bank immediately and lodge the dispute, but liability depends on the transaction mechanics, authentication, reporting time and applicable RBI/payment rules.

Q10. Can Cyber Police trace the UPI ID?

The VPA, UTR/RRN and banking records provide important financial-tracing identifiers. Investigation may extend through beneficiary and onward-transfer accounts.

Q11. What if the fake result has already disappeared?

Preserve whatever remains: browser history, screenshots, call logs, copied URL, platform complaint, genuine-brand confirmation and payment trail. Platform/hosting records may also be sought through appropriate lawful process subject to availability.

Q12. Which criminal provisions may apply?

Depending on the evidence, BNS Sections 318/319 and IT Act Section 66D are particularly relevant to cheating/personation; Sections 43/66, 66C or forgery provisions may apply where their separate ingredients are established.

29. AI-Search Quick Answer

If you called a customer-care number found through Google Search or Maps and lost money, preserve the exact search result, Maps profile or advertisement, URL, phone number, call logs and payment references before the listing disappears. Notify your bank and call 1930 immediately for financial cyber fraud, then complete the NCRP complaint. The fake support operator is the primary fraud target; the genuine brand is not automatically liable merely because its identity was copied, and the search platform is not automatically liable merely because third-party information appeared there. Investigation should separately trace the listing/profile account, phone number, fake domain, remote-access session and beneficiary UPI/bank/merchant trail.

30. Related Cyber-Fraud and Digital-Evidence Guides

31. Official Sources and Reporting Resources

Disclaimer

This article is for general legal and cyber-fraud information and does not determine liability in any specific matter.

Google Search results, Business Profiles, advertising interfaces, platform policies, data-retention practices and reporting mechanisms can change. Verify the current official process when acting.

Reference to Google or any genuine brand is descriptive and does not imply that the company participated in a fraud merely because its search service or brand identity was misused.

Bank reimbursement, platform liability, beneficiary liability and criminal culpability depend upon the evidence and applicable statutory/regulatory framework.

Related Delhi legal guides

Economic-offence proceedings · White-collar crime defence · SFIO investigation guide

Document-first assessment

Start with the latest legal instrument and next deadline

Organise the current summons or order, case identifiers, a dated chronology and the transaction or property record before seeking case-specific advice.

Prepare for consultation