By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
A Telegram or WhatsApp message offering daily income for simple tasks — rate products, like YouTube videos, “prepay to unlock higher commission” — pays small amounts at first, then asks for larger deposits to “complete the set” or “release the balance,” and finally blocks your wallet. This is the prepaid / rating / online job task scam, one of the most frequently reported cyber fraud patterns in Kerala in 2024-25, and legally it is not a failed business — it is cheating by personation using a computer resource under Section 66D IT Act and Section 318(4) BNS, with the same 1930/CFCFRMS hold, bank-lien and Magistrate refund (Sections 497-505 BNSS) logic as any other UPI fraud. The task narrative is the social engineering; the legal response is the same money-trail response.
How does the task scam actually operate?
| Stage | What you see | What is legally happening |
|---|---|---|
| Hook | Message on Telegram/WhatsApp/Instagram: “Part-time job, earn ₹2,000/day, no investment, train from home” — asks you to join a group with a “receptionist” and a “mentor” | Personation — the “receptionist” is not an HR officer; the brand logos and trade marks are misused — 66D/319 |
| Trust building | You complete 2-3 simple tasks (rate a hotel, like a video) and a small commission is credited to a wallet or UPI — you withdraw once | Inducement — the small credit is the consideration that induces the later delivery under Sec 318(4) BNS |
| Escalation | “Prepay ₹10,000 to unlock Level 2; pay ₹47,000 more to complete the set and withdraw — your balance will then double” | Dishonest inducement to deliver property — the core cheating charge; each UPI you send is a separate delivery |
| Trap | Balance shows growing in the fake dashboard, but withdrawal is blocked — “pay GST / verification / withdrawal fee / risk fund” | Further cheating under the same sections; later demands under Sec 308 BNS (extortion) where threats or reputational harm are added |
| Silence | Mentor stops responding; group is cleared; Telegram handle disappears | Layering — your UPI has already been layered through mules; CFCFRMS may show the amount split and moved within hours |
A Kerala variant adds crypto P2P: “withdraw in USDT to avoid TDS” — the tainted INR is routed to a crypto P2P hop, making the trail harder but not impossible.
Why does paying “one more level” make your case weaker, not stronger?
Two reasons:
- Each payment is a new delivery procured by cheating. It does not buy release of the earlier delivery — the earlier delivery is already the offence. The scammer’s wallet balance screen is not a bank balance and has no legal significance; it is an image generated to induce the next delivery.
- It can be used to argue you were a witting participant in layering. A person who sends successive amounts despite a growing withdrawal block is harder to distinguish, on paper, from a money mule who is knowingly passing funds for commission. Stopping payments and preserving the record is therefore legally protective.
Which sections apply — and do you need an FIR or is NCRP enough?
NCRP/1930 is not an FIR — it is the hold/routing step. An FIR under Section 173 BNSS (old 154 CrPC) is what commences investigation and grounds later holds and refund orders:
| Provision | When it is common in task scams | Cognizable? |
|---|---|---|
| BNS Sec 318(4) (cheating inducing delivery) | Every prepaid task deposit you sent | Yes (up to 7 years) |
| BNS Sec 319 (cheating by personation) | Fake HR / brand impersonation | Yes |
| IT Act Sec 66D (personation using computer resource) | Fake job/brand via Telegram/website | Yes (Inspector+) |
| IT Act Sec 66C (identity theft) | OTP / credential misuse where account taken over | Yes |
| BNS Sec 308 / 351 | Threats to release data or demand further payment | Yes for s. 308; s. 351 is non-cognizable |
File a written, signed complaint at the district Cyber Police Station citing these sections, with the full payment list below. Request FIR under Sec 173 BNSS; ask for Section 94 BNSS production to the receiving banks and platforms, and — where your own account is now frozen as a mule layer by an earlier victim’s 1930 — shift to the bank-freeze guide and the 35-vs-94 guide simultaneously.
How does recovery actually work — the same money trail as UPI fraud?
Recovery follows the same UPI fraud recovery escalator already detailed step-by-step in the UPI fraud guide:
- 1930/NCRP immediately — 1930 call + cybercrime.gov.in filing with every UTR/RRN, beneficiary UPI ID, wallet screenshot and amount; CFCFRMS attempts hop-by-hop holds while the money is still inside the banking system.
- Write to your bank the same day — for any leg that was genuinely unauthorised, cite the RBI circular on limiting customer liability in unauthorised electronic banking transactions (06 Jul 2017); for the payments you were induced to authorise (the usual task-scam pattern), the operative remedy is a recall request and the CFCFRMS hold, not a liability reversal. Request recall and preservation of the remittance trail. For task scams the victim’s bank is the remitting side; the lien is sought on the receiving mules, not your own account.
- FIR + investigation — the cyber cell traces the INR hops; Section 94 BNSS to banks/payment intermediaries, Section 106 BNSS lien on amounts found, Section 193 BNSS progress intimation to you.
- Magistrate refund — victim application for release of lien-marked amounts traceable to your UTRs under Sections 497-505 BNSS before the jurisdictional Magistrate of the receiving account’s bank / the FIR — not the bank-freeze writ track, which fits the opposite posture (your account frozen as recipient).
Why timing dominates: In task-scam matters, the INR is often split across several mule accounts within hours and then withdrawn as cash or routed via P2P USDT. A 1930 call in minute 30 seeks holds on real balances; a complaint on day 10 seeks recovery of what is left.
What bundle should you prepare — the file that moves first?
Bring one PDF that every forum asks for:
- Every UPI transaction with UTR/RRN, beneficiary UPI ID / account, amount and timestamp — highlight the UTRs in your bank statement.
- The task-group screenshots with URLs and timestamps (preserve original device for Section 63 BSA hash).
- The wallet / dashboard balance screen showing blocked withdrawal — label it as a platform-side image, not a bank balance.
- Your 1930 / NCRP numbers and your bank’s written acknowledgement of the recall request.
- A one-page chronology — first message date, each payment date, the date withdrawal was blocked, and the date of complaint.
Primary sources
- IT Act, 2000 — Sections 66C, 66D, 66, 78; BNS, 2023 — Sections 308, 318, 319, 351, 78
- BNSS, 2023 — Sections 35, 94, 106, 173, 497-505; BSA — Section 63
- I4C / NCRP at cybercrime.gov.in and 1930; RBI circular 06 Jul 2017 on limited liability for unauthorised electronic banking transactions
- Kerala State Police Cyberdom / district Cyber Cells (2024-25 task-scam advisories)
FAQ
