Digital Evidence Preparation Guide

How to Preserve Digital Evidence After a Cybercrime
Digital evidence can be crucial in cybercrime investigations. It may help establish what happened, when it happened, how the fraud was carried out, and potentially assist in identifying the person or entity responsible.
However, digital evidence can be fragile. Messages may be deleted, accounts may be deactivated, websites may disappear, and data may be overwritten.
The golden rule: Preserve first. Report quickly. Do not alter or destroy potential evidence.
1. Act Quickly—but Don’t Panic
If you have been the victim of a cybercrime:
🚨 If money has been lost:
Call 1930 immediately and contact your bank or financial institution.
Do not wait until you have collected every piece of evidence.
You can preserve additional evidence while the complaint is being processed.
2. Preserve the Original Evidence
Whenever possible, retain the original source of the evidence.
For example:
- Keep the original WhatsApp conversation.
- Do not delete the original email after taking a screenshot.
- Preserve the original bank statement or transaction record.
- Keep the original files received from the suspected offender.
- Preserve relevant social media messages.
Screenshots are useful, but a screenshot should generally be treated as an additional copy rather than a replacement for the original evidence.
3. Take Screenshots Carefully
Screenshots can help document information that may later disappear.
When taking screenshots, try to capture:
☐ Date and time
☐ Phone number
☐ Username
☐ Email address
☐ Profile name
☐ Transaction ID
☐ UPI ID
☐ Website URL
☐ Relevant message
☐ Account/profile information
☐ Any warning or notification
Where possible, take a screenshot that includes the entire screen and relevant context.
Avoid:
❌ Cropping out important information.
❌ Editing screenshots.
❌ Adding text or annotations to the original screenshot.
❌ Using filters or image-editing tools.
If you need to highlight something for your own understanding, retain the original unedited screenshot separately.
4. Preserve WhatsApp and Messaging Evidence
If the fraud occurred through WhatsApp, Telegram, SMS, or another messaging platform:
☐ Preserve the complete conversation.
☐ Take screenshots of relevant messages.
☐ Record the sender’s phone number or username.
☐ Save relevant profile information.
☐ Preserve photographs or documents sent by the offender.
☐ Record links shared in the conversation.
☐ Preserve voice notes.
☐ Preserve relevant call logs.
☐ Use the platform’s available export or download functions where appropriate.
Do not delete the conversation simply because you have taken screenshots.
5. Preserve Email Evidence
If email was involved:
☐ Keep the original email.
☐ Take screenshots where useful.
☐ Record the sender’s email address.
☐ Preserve attachments.
☐ Save suspicious links.
☐ Preserve relevant replies and forwards.
☐ Keep the email’s original metadata or headers where available.
Important
Avoid forwarding suspicious emails unnecessarily. If you need to provide them to investigators, banks, or legal professionals, preserve the original email and provide a copy where appropriate.
6. Preserve Website Evidence
Fraudulent websites may disappear quickly.
If you encounter a suspicious website:
☐ Record the complete URL.
☐ Take screenshots of relevant pages.
☐ Record the date and time you accessed the website.
☐ Preserve screenshots of payment instructions.
☐ Save invoices or receipts.
☐ Record contact details displayed on the website.
☐ Save relevant terms and conditions, if applicable.
☐ Preserve advertisements or promotional material that led you to the website.
Do not continue interacting with a suspicious website merely to collect evidence.
7. Preserve Social Media Evidence
If the fraud occurred through Instagram, Facebook, X, Telegram, LinkedIn, or another platform:
☐ Screenshot the profile.
☐ Record the username.
☐ Save the complete profile URL.
☐ Screenshot relevant posts.
☐ Preserve direct messages.
☐ Record the date and time.
☐ Save advertisements or sponsored posts, where relevant.
☐ Preserve payment requests.
☐ Record any changes to the account, if observed.
Social media accounts can be renamed, deleted, or made private. Preserve relevant information as soon as possible.
8. Preserve Financial Evidence
For financial cyber fraud, preserve:
☐ Bank statements
☐ UPI transaction records
☐ UPI IDs
☐ Transaction IDs
☐ UTR numbers
☐ IMPS/NEFT/RTGS details
☐ Debit card transaction records
☐ Credit card transaction records
☐ Wallet transaction records
☐ SMS alerts
☐ Email alerts
☐ Beneficiary account details
☐ Bank account numbers
☐ IFSC codes
☐ Cryptocurrency wallet addresses
☐ Blockchain transaction hashes
Create a Transaction Log
| Date | Time | Amount | Transaction ID/UTR | Payment Method | Beneficiary |
|---|---|---|---|---|---|
| ₹ | UPI | ||||
| ₹ | IMPS | ||||
| ₹ | Card |
This can make it easier to present the financial trail to the bank and investigating authorities.
9. Preserve Phone and Call Evidence
If the fraudster contacted you by phone:
☐ Preserve the phone number.
☐ Take a screenshot of the call log.
☐ Record the date and time of the call.
☐ Record the duration of the call.
☐ Preserve SMS messages.
☐ Preserve WhatsApp call details.
☐ Preserve call recordings, where lawfully available.
☐ Write down what the caller claimed and what instructions they gave.
If you do not have a recording, write down your recollection as soon as possible while the conversation is still fresh in your memory.
10. Preserve Evidence of Account Hacking
If your email, WhatsApp, social media, or banking account has been compromised, preserve:
☐ Login alerts
☐ “New device” notifications
☐ Password reset emails
☐ OTP messages
☐ Unauthorised login notifications
☐ Emails about changes to account information
☐ Screenshots of the compromised account
☐ Evidence of unauthorised transactions
☐ Details of unfamiliar devices or sessions
☐ Evidence of unauthorised messages sent from your account
11. Do Not Factory Reset Your Device Unnecessarily
If your phone or computer may contain relevant evidence:
Avoid immediately:
❌ Factory resetting the device.
❌ Deleting suspicious applications.
❌ Wiping the device.
❌ Deleting files.
❌ Clearing browser history.
❌ Uninstalling applications that may contain relevant information.
If the device itself is important to the investigation, seek appropriate technical or professional guidance before making significant changes.
However:
If your device is actively compromised or poses a security risk, protect your accounts and personal information first. Security and evidence preservation should be balanced carefully.
12. Preserve Suspicious Files Safely
If you receive a suspicious document, APK, executable file, or other potentially malicious file:
☐ Do not open it unnecessarily.
☐ Do not install it.
☐ Do not execute it merely to investigate.
☐ Preserve the file safely if it is relevant.
☐ Record where and when you received it.
☐ Note the sender and associated communication.
If you believe your device is infected, prioritise securing the device and your accounts.
13. Create a Digital Evidence Folder
Create a dedicated folder:
📁 CYBERCRIME EVIDENCE
01 – Incident Summary
02 – Chronological Timeline
03 – Bank Transactions
04 – UPI/Payment Records
05 – WhatsApp & Chats
06 – Emails
07 – Screenshots
08 – Call Records
09 – Social Media
10 – Website Evidence
11 – Device Evidence
12 – Bank Complaint
13 – 1930 Complaint
14 – Cybercrime Portal Complaint
15 – Police/FIR Documents
14. Maintain a Chain of Custody Record
For important evidence, maintain a simple record of:
- What the evidence is.
- When you obtained it.
- Where it came from.
- Who had access to it.
- Whether it was copied or transferred.
- Where it is currently stored.
Example:
| Evidence | Date Obtained | Source | Stored At |
|---|---|---|---|
| WhatsApp Chat | 15/07/2026 | Fraudster’s number | Secure Drive |
| Bank Statement | 15/07/2026 | Bank | Evidence Folder |
| Screenshot | 15/07/2026 | Fraudulent Website | Secure Drive |
This can help maintain an organised record of your evidence.
15. Keep Original and Working Copies Separate
Where possible, maintain:
📂 ORIGINAL EVIDENCE
The original, unedited files.
📂 WORKING COPIES
Copies used for organising, highlighting, or sharing.
This helps ensure that the original evidence remains preserved.
16. Back Up Your Evidence Securely
Keep at least one secure backup of important evidence.
Possible options include:
- An encrypted external drive.
- Secure cloud storage.
- Another trusted storage location.
Protect sensitive evidence with strong passwords and appropriate access controls.
Avoid sharing sensitive evidence publicly on social media.
17. Create a Chronological Timeline
Write down:
When did the offender first contact you?
What did they say?
What did you do?
What information did you provide?
When was the payment made?
When did you discover the fraud?
When did you contact your bank?
When did you call 1930?
When did you file the cybercrime complaint?
A simple timeline can be extremely useful when explaining the incident.
18. Preserve Evidence Before Blocking the Offender
If you are dealing with a scammer, impersonator, or harasser:
- Record the phone number or username.
- Save the profile URL.
- Take relevant screenshots.
- Preserve important messages.
- Record transaction information.
- Then consider blocking the account.
Do not continue communicating with the offender solely to obtain more evidence.
19. Report the Cybercrime
After preserving the essential evidence:
Financial Fraud
📞 Call 1930 immediately.
Banking Fraud
🏦 Contact your bank or financial institution immediately.
Cybercrime
💻 File a complaint through the official National Cyber Crime Reporting Portal.
Serious or Complex Cases
👮 Consider approaching the appropriate police/cybercrime authorities.
Legal Issues
⚖️ Consider consulting a qualified legal professional where appropriate.
20. Keep All Complaint Records
Maintain copies of:
☐ 1930 complaint/reference number
☐ Cybercrime Portal acknowledgement
☐ Bank complaint number
☐ Transaction dispute number
☐ Police complaint/FIR, if applicable
☐ Investigating officer’s details, if provided
☐ Emails sent to authorities
☐ Responses received
☐ Follow-up correspondence
🚫 What NOT to Do
❌ Don’t delete evidence.
❌ Don’t alter original files.
❌ Don’t factory reset a relevant device unnecessarily.
❌ Don’t open suspicious files merely to investigate.
❌ Don’t continue communicating with a scammer unnecessarily.
❌ Don’t pay a “recovery agent” promising guaranteed recovery.
❌ Don’t publicly upload sensitive evidence containing personal or financial information.
❌ Don’t wait to report financial fraud while trying to create a perfect evidence file.
🛡️ The Digital Evidence Golden Rules
1. Preserve
Keep original evidence intact.
2. Document
Record dates, times, URLs, phone numbers, and transaction details.
3. Organise
Create a clear evidence folder and timeline.
4. Secure
Keep evidence backed up and protected from unauthorised access.
5. Report
Notify your bank and the appropriate cybercrime authorities promptly.
6. Don’t Alter
Avoid modifying, deleting, or overwriting potential evidence.
🚨 REMEMBER
Digital evidence can disappear—but your actions can preserve it.
If you are a victim of cybercrime, do not panic and do not delete anything in haste. Preserve relevant evidence, secure your accounts, report financial fraud immediately, and seek appropriate professional assistance where necessary.
Preserve. Protect. Report.
Disclaimer: This guide is intended for general awareness and informational purposes and does not constitute legal or forensic advice. The appropriate method of preserving and presenting digital evidence may depend on the nature of the case and the applicable legal and technical requirements.
