Skip to main content

Online impersonation and account hacking in India: protect women’s identity, evidence and safety

A practical response guide for fake profiles, hacked accounts, stolen OTPs, doxxing, intimate-image threats and coordinated online abuse targeting women.

In this guide

Recognise impersonation and account takeover

A fake profile, changed recovery email, unknown login, cloned voice, stolen photo, doxxing post or message sent from a woman’s account can affect work, family, money and physical safety. The screen does not make the harm unreal.

Impersonation is not a joke

Someone may copy a name, photo, bio, voice or workplace to contact friends, solicit money, sexualise the woman or damage her reputation. Save the link and exact wording without forwarding it widely.

Look for takeover signals

Unexpected password resets, new devices, changed recovery details, deleted messages, sent emails, payment alerts or a device that logs out can indicate unauthorised access.

Treat intimate-image threats as urgent

Threats to publish an intimate image, sexual extortion, stalking or doxxing can connect online and offline danger. Do not negotiate alone or pay under pressure.

Do not blame the woman for trusting someone

A public photo, a relationship, an old password or a shared device does not give another person permission to impersonate, expose or control her.

Check physical risk too

Ask whether the person knows the home, work, school, route, children, passwords or account recovery contact. Build a safety plan across devices and places.

The first safe hours

Act from a device and place the other person cannot monitor. A rushed reset can alert an abuser, erase evidence or lock the woman out of her own account.

Use a safer device and account

If possible, change the email password first, sign out unknown sessions, update recovery details and enable multi-factor authentication. Avoid doing this on a monitored device without a plan.

Contact the service through its official channel

Use the platform’s account-recovery and impersonation process. Check the address yourself; do not click a recovery link sent by the person who is threatening you.

Protect bank and payment access

If money or OTPs are involved, contact the bank or payment provider immediately. For cyber financial fraud, call 1930 and keep the transaction reference.

Preserve evidence privately

Record URLs, usernames, timestamps, login alerts, messages, payment details and screenshots. Store them in a safe place and do not re-upload intimate material.

Tell one safe person what is happening

A supporter can help monitor alerts, call a provider, accompany a complaint or watch the door. They should not take the account password or impersonate the woman.

Account takeover and impersonation response map
Risk or accountSafe actionReport number or review date
Email, phone or social account
Bank, wallet or payment
Fake profile, threat or image
Home, work, school or family risk

Reporting without spreading the harm

Different conduct can need different channels. Use the smallest amount of personal or intimate material that lets an official service understand the complaint.

Use the National Cyber Crime Reporting Portal

The portal accepts cybercrime complaints and has routes for cybercrime related to women or children. Read the form, keep the acknowledgement and ask what information is required.

Call 1930 for cyber financial fraud

The official portal identifies 1930 as the immediate helpline for cyber financial fraud. It does not replace a report for stalking, impersonation, image abuse or physical threats.

Use the platform’s impersonation process

Report the fake account, copied image, unauthorised access, sexual exploitation or threat under the closest category. Ask whether records can be preserved and re-uploads limited.

Keep every tracking number

Save the cybercrime, platform, bank and police reference numbers, date, contact and next step. A report is a request for action, not a guarantee of arrest or removal.

Privacy, consent and account ownership

The safest response protects the woman’s identity while preserving enough evidence to act. A helper should never become a second person with unrestricted access.

Consent is specific

A partner, parent, friend or employer should not read messages, reset passwords, submit a complaint or publish a warning in the woman’s name without her permission, except for a defined urgent safeguarding duty.

Keep recovery methods independent

Use a phone number, email, authenticator or backup code the abuser cannot access. Change shared passwords and check connected apps, forwarding rules and cloud sessions.

Do not doxx the impersonator

Publishing a suspected person’s address, phone, workplace or family details can create retaliation, legal and safety risks. Send evidence to the official route instead.

Plan for a monitored device

A sudden password change, deleted history or new safety app can be visible. Use a safer device, private browsing plan or support service where changing settings could increase danger.

When digital abuse becomes a safety emergency

Online abuse can be used to force contact, punish a woman for leaving, control money or expose her at work and home. Coordinate digital, physical and emotional support.

Call 112 for immediate physical danger

A weapon, forced entry, confinement, assault or credible imminent threat needs emergency help when safe. Do not meet the impersonator to prove identity.

Use Women Helpline 181 or a One Stop Centre

These services may help connect safety, counselling, legal, police, medical or shelter support. Ask what can remain private and how the service will contact you.

Sources for this point: Women Helpline 181One Stop Centre scheme

Protect work and education

Tell only the necessary manager, teacher or safety contact, ask for a private plan and keep the fake profile away from a public confrontation. Request interim protection from harassment.

Review the plan after each change

A takedown, new account, police call, court notice or family reaction can change the risk. Keep a back-up contact and do not let the abuser choose the pace.

Questions people ask

Should I call 1930 for every hacked account?

1930 is the official immediate helpline for cyber financial fraud. For account takeover without financial fraud, use the platform recovery process and the cybercrime or police route that fits the conduct.

Can I delete the fake account myself?

Report it, but preserve the URL, username, timestamps and messages first when safe. Removal may limit future harm, while evidence can help a complaint.

What can a supporter say?

‘You did not cause this. We can use a safer device, secure the account, keep evidence private and choose the platform, bank, cybercrime, police or support route you want.’

Sources and publication record

Draft prepared 16 September 2026; project-team editorial review pending · Sources checked .