HomeNews ReportsFrom CyberTip to courtroom: How India tracks CSEAM suspects, identifies victims and where investigations...

From CyberTip to courtroom: How India tracks CSEAM suspects, identifies victims and where investigations fall short

CyberTips can lead Indian police to suspects and victims, but court records show how gaps in attribution, digital evidence and prosecution can derail cases before conviction.

In July 2021, the office of the Senior Superintendent of Police in Rupnagar, Punjab, received 19 CyberTipline reports from the Ministry of Home Affairs for necessary action. One of them carried the number 72122374. The matter had not reached police through a complaint from the child. Instead, it arrived as a digital lead that had travelled through an international and national reporting system.

The Rupnagar Cyber Cell examined the material associated with the Tipline report. According to the prosecution case later recorded by the Punjab and Haryana High Court, investigators followed a Facebook link mentioned in the material, connected the account with a mobile number and sought subscriber details from the service provider. The trail ultimately pointed towards a person in Punjab.

On 8th July 2021, City Rupnagar police registered an FIR. The sequence appears straightforward when reduced to a few steps: CyberTip, account, mobile number, subscriber and FIR. But identifying the subscriber was not the same as establishing who had committed the alleged offence.

Police still had to determine whether the person whose details emerged from the subscriber information had actually controlled the Facebook account when the reported activity occurred. They had to connect the material with a device and its user and establish facts about the material itself, including whether the person depicted was a child.

The same problem appears repeatedly across Indian court records. A CyberTip may point investigators towards an account, mobile number, IP-related information or other digital identifiers. But a mobile number registered in someone’s name does not automatically prove that the person uploaded a file. An internet connection may be used by several people and an online account can be accessed from different devices.

The investigation therefore has to move through several links: digital identifier, subscriber, device, user and alleged criminal act. Each has to be supported by evidence.

The technology company that first detects suspected child sexual abuse material may be outside India. The reporting mechanism may operate from the United States and the information can pass through India’s central cybercrime infrastructure. Eventually, however, an Indian police unit has to determine where the alleged activity occurred, who may have been behind it and whether there is sufficient material to proceed with a criminal investigation.

Cases examined by OpIndia from Chennai, Punjab, Karnataka, Chhattisgarh and Delhi show how differently that process can end. Some reached chargesheets and higher courts. Some ended in acquittal because crucial digital links could not be proved. In other cases, digital evidence allegedly led investigators beyond the person circulating the material and towards children whose abuse had never been reported to police.

How India entered the CyberTip system

India formally entered the NCMEC CyberTipline information-sharing mechanism in 2019, as discussed in the first article of this series. According to the Ministry of Home Affairs, the National Crime Records Bureau signed a memorandum of understanding with the US-based National Center for Missing and Exploited Children, or NCMEC, on 26th April 2019 for receiving Tipline reports concerning online child sexual exploitation material.

How a CyberTip becomes a case

By 11th March 2025, more than 69 lakh CyberTipline reports had been shared with concerned States and Union Territories, the Home Ministry told the Lok Sabha. This does not mean India had identified 69 lakh offenders. NCMEC describes the CyberTipline as a reporting mechanism through which electronic service providers and members of the public report suspected child sexual exploitation. One of its functions is to make such reports available to law-enforcement agencies that can act on the information.

The Home Ministry says I4C has been established as an attached office to deal with cybercrime in a coordinated manner. It also says the conversion of cybercrime reports into FIRs and subsequent action are handled by the concerned State and UT law-enforcement agencies. Police and public order are State subjects.

This means an alert entering India through a central system can ultimately become a case at a local police station hundreds or thousands of kilometres away.

What does a CyberTip give investigators?

The information accompanying a CyberTip varies from case to case. NCMEC has documented reports containing details such as email addresses, screen names, reported images and IP addresses. Indian court records examined by OpIndia contain cases involving Facebook accounts, mobile numbers, IP-related information and other digital identifiers.

These details can provide a starting point, but they cannot by themselves establish who carried out the reported activity. A connection may serve an entire household, office or shared network. A mobile number can be registered in one person’s name while somebody else uses the handset. The cases that followed show how police attempted to bridge that gap.

How the investigation moves

How the Chennai case travelled from CyberTip to the Supreme Court

One of the strongest documented examples comes from Chennai. An FIR was registered at the All-Women Police Station, Ambattur, in 2020 based on CyberTipline Report number 49303278.

Acting on the complaint, police traced the accused and seized his mobile phone, which was sent for forensic examination. According to court documents, the forensic examination found material involving children along with other pornographic files on the device.

The final report was filed before the Special Court and the matter proceeded under the POCSO Act and IT Act. The accused approached the Madras High Court seeking to quash the case.

The High Court quashed the proceedings in January 2024 after taking the view that mere possession or private viewing of the material, without evidence of transmission or publication, did not attract the POCSO Act or Section 67B of the IT Act.

The Supreme Court reversed that decision in September 2024. It held that the High Court had adopted an unduly narrow interpretation of Section 15 of POCSO and Section 67B of the IT Act. The Supreme Court clarified that the amended Section 15 creates separate offences relating to possession and storage and that criminal liability does not in every case depend upon proof that the material was actually transmitted.

For understanding the investigation, the journey itself is significant. A numbered CyberTip entered the Indian system, reached police in Chennai, led to an FIR, seizure and forensic examination of a device, a chargesheet and eventually proceedings before the Supreme Court.

The case also highlights a wider issue in the judicial process. Where loopholes or differing interpretations of the law delay proceedings, there is a need to ensure that the legal framework is sufficiently clear so that cases can move forward without avoidable delays.

Punjab – CyberTip led to FIR, but electronic evidence could not be proved

The Rupnagar case mentioned at the beginning did not end with the FIR. The accused was arrested in May 2022 and police seized an Oppo mobile phone.

When he sought bail, he argued that his Facebook account had been misused. The Punjab and Haryana High Court noted that the investigation had been completed, but the State could not point to any document showing how the age of the person seen in the video had been determined. He was granted regular bail on 25th July 2022.

The case eventually went to trial, where seven prosecution witnesses were examined. On 19th March 2026, the Special Court in Rupnagar acquitted the accused.

The court found that the prosecution’s case was based on the CyberTip CD, but the CD itself had not been exhibited. The person who prepared it was not examined and the required Section 65B certificate relating to the electronic record was not produced. The court held that the prosecution had failed to prove beyond reasonable doubt that the accused had uploaded the material.

The case illustrates how a CyberTip can successfully lead police to an account and subscriber, but the prosecution can still fail if the electronic evidence on which the case is built is not properly proved.

How CyberTips led to police cases and bail proceedings in Karnataka

Karnataka court records show how CyberTips were passed to specialised Crime, Economic Offences and Narcotics, or CEN, police stations.

In Uttara Kannada, CyberTip 75331606 led to FIR at the UK CEN Police Station. According to the prosecution, material involving children had been uploaded to social media using a mobile phone linked to the accused.

The question before the Karnataka High Court was whether the accused himself had uploaded the material or someone else had used his phone. The court said this required investigation and granted him anticipatory bail on 23rd May 2022, directing him to cooperate with investigators. A later final judgment could not be traced.

In Ballari, CEN police received CyberTip 74110154 through the CID. According to the prosecution, examination of the Tip revealed images and videos involving children, along with an IP address and other information linked to the accused.

The Sessions Court initially rejected his request for anticipatory bail. However, on 20th July 2021, the Karnataka High Court granted anticipatory bail, noting that investigators still had to establish whether the material could actually be attributed to him.

A similar case arose in Kalaburagi from CyberTip 85243917. Police received the report along with digital material and conducted a preliminary inquiry. According to the prosecution, investigators linked the alleged upload to an IP address associated with the accused and registered an FIR at the Kalaburagi CEN Crime Police Station.

When the accused approached the High Court for anticipatory bail, the investigation was still underway. On 30th May 2022, the court rejected his plea.

The three cases demonstrate the same investigative difficulty. An IP address, account or handset can help police identify a suspect, but investigators still have to establish who actually carried out the reported activity.

Bilaspur – How an IP address led police to a local FIR

A 2026 Chhattisgarh High Court order shows how technical information from a CyberTip can also help police identify the appropriate jurisdiction.

According to the prosecution, CyberTip 127954701 was received from NCRB and related to an alleged upload from June 2022. Police conducted a preliminary inquiry and examined the technical information attached to the report.

Investigators said the IP information pointed to network activity in Bilaspur. They then obtained details of the mobile number linked to that connection and found that it was registered in the name of accused. Since the alleged activity fell within the area of City Kotwali police station, an FIR was registered there under Section 67B of the Information Technology Act.

The accused argued that an IP address and subscriber details did not prove that he himself had uploaded the material. On 29th April 2026, the Chhattisgarh High Court rejected his anticipatory bail plea. The court did not decide whether he was guilty.

The case shows the basic investigative chain: IP address -> location -> mobile number -> subscriber -> local police station -> FIR. Establishing who actually used that connection remains a separate part of the criminal investigation.

Delhi – Finding the account holder was not enough

A Delhi case shows how an investigation can continue even after police identify the people linked to online accounts.

In FIR registered at Lodhi Colony police station, investigators were acting on a CyberTipline report concerning a file allegedly shared through Facebook Messenger. According to the prosecution before the Delhi High Court, one Facebook account was linked to a mobile number registered in the name of the accused. Police also traced another Facebook account and another mobile number connected with the alleged exchange.

During the investigation, another man told police that he had created the second Facebook account. The accused accepted that the mobile number linked to his own Facebook account belonged to him, but denied knowing the other person. Police also sought the device allegedly used to access his account at the relevant time.

Investigators were not only trying to identify the account holders. Police told the High Court that they also wanted to establish where the video had originally come from and identify the people responsible for creating it.

On 16th January 2026, the Delhi High Court rejected accused’s anticipatory bail plea. The court was deciding only the bail application and did not determine whether he was guilty.

The case shows that identifying a mobile number or account can be only one stage of the investigation. Police may still have to determine who operated the account, where the material originated and who created or circulated it.

From phone seizure to evidence that can survive in court

Once police identify a possible device, phones, computers or storage devices may be seized and examined. Investigators can compare the recovered material and account activity with the CyberTip and seek supporting evidence from telecom companies, platforms, witnesses and other sources.

India has expanded its cyber-forensic infrastructure for such investigations. By March 2025, cyber forensic-cum-training laboratories had been commissioned in 33 States and Union Territories under the Cyber Crime Prevention against Women and Children scheme. More than 24,600 law-enforcement personnel, public prosecutors and judicial officers had received training in cybercrime awareness, investigation and forensics.

The National Cyber Forensic Laboratory (Investigation) in New Delhi had also provided early-stage forensic assistance to State and UT law-enforcement agencies in around 11,835 cybercrime cases. These are broader cybercrime figures and are not specific to CSAM cases.

The presence of forensic material, however, does not automatically result in conviction. Two Bengaluru cases show why.

Bengaluru – Two CyberTip cases ended in acquittal

In one Bengaluru case, CyberTip 74377485/2020 reached police through NCRB and the CID. Police said that the accused had used a WhatsApp number and mobile phone to browse and upload material involving a child. The case went through investigation, device examination and trial.

During the trial, the court found gaps in the evidence. There were problems in proving that the seized phone was properly connected to the alleged activity and in establishing what the forensic evidence showed.

On 29th July 2024, the court acquitted the accused under Sections 67 and 67B of the Information Technology Act, holding that the prosecution had failed to prove the charges beyond reasonable doubt.

Another Bengaluru case based on CyberTip 49294906/2020 ended in acquittal on the same day. Police alleged that material involving a child had been uploaded through a Facebook account.

During the trial, the police officer who had received the CyberTip admitted that he had registered the case without independently checking the CD at that stage. The person who was allegedly sent the material did not support the prosecution’s claim and police had not seized his phone.

Forensic examination found case-related material on the accused’s handset, but the court said the prosecution still had to prove who had downloaded or transmitted it. The phone was also not password-protected, raising the possibility that somebody else could have used it.

The court acquitted the accused after finding that the prosecution had failed to prove the case beyond reasonable doubt.

The two cases show why the quality of the investigation after a CyberTip becomes crucial. The prosecution still has to connect the account, device and alleged activity with the accused through admissible evidence.

When investigators have to find the child

CSAM investigations are not only about identifying the person who uploaded or shared the material. Images and videos can also be evidence that a child was physically abused.

Sometimes the child is already known to police. In other cases, investigators may not know who the child is, where the child lives or where the material was created. The investigation then works in reverse. Instead of a child reporting the abuse to police, investigators use the digital material to try to identify and locate the child.

When the investigation works backwards to find the child.

The CBI cases from Hisar and Aizawl in 2025 show how this can happen.

Hisar – Digital evidence allegedly led CBI to multiple children

On 4th June 2025, CBI announced a case involving the alleged rape and sexual assault of multiple minor victims in Hisar, Haryana. The agency said the CSAM was linked with CyberTipline reports generated by Google and submitted to I4C. It also referred to material available through INTERPOL’s International Child Sexual Exploitation database.

CBI said it analysed the material using cyber-forensic tools and traced the investigation to Hisar. Searches were conducted, electronic devices were seized and the accused was arrested.

During the investigation, CBI said it identified multiple minor victims who had allegedly been sexually assaulted and exploited for the creation of CSAM. According to the agency, neither the children nor their families had previously reported the alleged abuse to police.

The latest public CBI update traced for the case is from June 2025, when the accused had been arrested and the investigation was continuing.

In this case, according to CBI, the digital material helped investigators find the children rather than the children first leading police to the material.

Aizawl – Digital evidence allegedly led investigators to an unreported assault

A similar case emerged in Aizawl, Mizoram. CBI registered the case on 30th May 2025 and carried out searches on 4th June. Electronic devices were seized. The agency said the CSAM was linked with CyberTipline reports generated by Google and submitted to I4C.

According to CBI, forensic examination of the material revealed evidence of the alleged sexual assault of a minor child. Investigators identified and located the child, who was then rescued.

Cybertrails across India

The accused was arrested on 9th June 2025. CBI said neither the child nor the family had previously reported the alleged assault to police. The investigation was continuing when the agency issued its update.

The Hisar and Aizawl cases show why CSAM investigations cannot be viewed only as cases involving illegal files online. Where the material records real abuse, identifying and protecting the child can become as important as finding the person who created, possessed or circulated it.

What happened to more than 69 lakh CyberTips?

As of 11th March 2025, the Home Ministry said more than 69 lakh CyberTipline reports had been shared with States and Union Territories. However, there is no consolidated national data showing how many resulted in FIRs, arrests, chargesheets, convictions, acquittals or the identification and rescue of children.

This leaves an important gap in understanding how effectively the system works after an alert reaches India. The 69 lakh figure shows the scale of information flowing into the law-enforcement system, but does not show how many reports eventually became successful investigations or prosecutions.

The same problem exists with State-wise performance. National figures show that forensic infrastructure and training have expanded, but publicly available data does not provide a comparable State-wise count of CyberTips received, FIRs registered, prosecutions completed, convictions obtained or children identified.

From an online alert to a conviction remains the challenge

A technology company may detect suspected CSAM and a CyberTip may eventually reach the appropriate police unit in India. From there, investigators may trace an account, IP address, mobile number or device. But none of those steps alone establishes guilt.

The cases examined here show what happens after the alert. Chennai reached the Supreme Court. Rupnagar and the two Bengaluru prosecutions ended with important questions over the electronic evidence, with all three accused ultimately acquitted in the trial-court cases discussed. Karnataka, Bilaspur and Delhi show the difficulty of connecting digital identifiers with the person who actually carried out the activity. Hisar and Aizawl show how the same digital trail can allegedly help investigators find children whose abuse had never been reported.

India has come a long way in building systems to receive CyberTips, expanding cyber-forensic capacity and training investigators. However, the real challenge often begins after the alert reaches a State or district police unit. Stronger digital evidence collection, better attribution, timely forensic examination and legally sound investigation are essential if CyberTip-based cases are to move beyond FIRs and arrests and ultimately result in convictions where the evidence supports them.

Some of these investigations also cross India’s borders, involving foreign agencies and international databases. How those international leads reach Indian investigators and how the CBI, INTERPOL and foreign law-enforcement agencies work together will be examined in the next part of this series.

Join OpIndia's official WhatsApp channel

  Support Us  

For likes of 'The Wire' who consider 'nationalism' a bad word, there is never paucity of funds. They have a well-oiled international ecosystem that keeps their business running. We need your support to fight them. Please contribute whatever you can afford

Anurag
Anurag
Anurag is a Chief Sub Editor at OpIndia with over 22 years of professional experience, including more than six years in journalism. He is known for deep dive, research driven reporting on national security, terrorism cases, judiciary and governance, backed by RTIs, court records and on-ground evidence. He also writes hard hitting op-eds that challenge distorted narratives. Beyond investigations, he explores history, fiction and visual storytelling. Email: [email protected]

Related Articles

Trending now

- Advertisement -