A Threat at 2 AM From a Number You Don't Know

Your phone lights up at two in the morning. The message is short and ugly. Sometimes it is a voice note. Sometimes a photograph of your home. Sometimes a single line warning you to back off from a court case, a job, a relationship, or a piece of land. The number is one you have never seen. You stare at the ceiling for the rest of the night wondering whether to ignore it, to reply, or to do something. By morning, the message has been deleted from the other end. Or it has been followed by ten more.

This is one of the most distressing experiences a person can have, especially when there is no obvious reason behind it. The first instinct is often to keep it private. That is exactly the wrong instinct. Indian law treats anonymous threats as a serious offence and the police have real tools to trace the speaker. The problem is most people don't know what those tools are, what to ask the police to do, or what the realistic limits are. So they suffer in silence and the offender gets bolder.

What the Law Counts as a Threat

Not every angry message is a criminal threat. The law has a specific test. Section 503 of the Indian Penal Code defines criminal intimidation as threatening another person with injury to body, reputation or property — or to the body or reputation of someone the victim is interested in — with the intent to cause alarm, or to compel the victim to do something they are not legally bound to do, or to abstain from doing something they are legally entitled to do.

The Supreme Court has clarified that the threat must be real and the speaker must mean what they say, but the offence is complete the moment the words are spoken with intent to cause alarm; the victim does not have to wait for the threat to be carried out. In Chander Kala v Ram Kishan (1985) the Court found criminal intimidation made out where a head master threatened a lady-teacher that until she signed certain papers in blank he would spoil her modesty. In Romesh Chandra Arora (1960) a person who took indecent photographs of a girl and threatened the father with publication unless paid was held guilty of criminal intimidation rather than mere extortion. The point of these rulings is that words plus intent equals offence; physical follow-up is not required.

Vague abusive talk, mere bluster, or a single rude message without any "or else" element will not always amount to criminal intimidation. Manik Taneja v State of Karnataka (2015) and Tammineedi Bhaskara Rao v State of AP (2007) stress that mere expression of words without any intention to cause alarm is not enough. So the practical test is — does the message threaten harm and does it carry an "or else" element designed to scare you into action or inaction? If yes, it is criminal intimidation in law.

The Sections That Apply

Three groups of sections are relevant.

IPC Section 503 and Section 506. Section 503 defines the offence; Section 506 prescribes the punishment. Simple criminal intimidation carries imprisonment up to two years, fine, or both. The aggravated form — threatening death, grievous hurt, destruction of property by fire, or imputation of unchastity to a woman — carries imprisonment up to seven years. Note an important practical wrinkle: in Uttar Pradesh, Section 506 has been made cognizable and non-bailable by state notification, which changes the enforcement equation considerably. Other states may have similar local notifications, so always check.

IPC Section 507 covers criminal intimidation by anonymous communication. The very fact that the threat is anonymous makes the offence a more serious one, with additional punishment.

Information Technology Act provisions. Where the threat is delivered through a communication device or computer resource, the IT Act adds offences. Section 66 of the IT Act dealing with computer-related offences applies in tandem with the relevant IPC section. Where the threat involves obscene electronic content, Section 67 also comes into play. Where the threat involves stalking, posting personal pictures, or intimidating a woman online, the gender-specific IPC provisions and special legislation are added.

The investigating officer will pick the right combination based on the precise language and method. As a complainant, you do not have to draft this perfectly. You only have to set out the facts clearly.

How Police Actually Trace an Unknown Number

Most people imagine tracing as something instant and dramatic. The reality is paperwork, and quite a lot of it. Indian telecom service providers maintain detailed subscriber records under licence conditions. Every Indian SIM is registered against an Aadhaar or other KYC document. Every call and SMS leaves a trace in the call detail record, or CDR.

The investigating officer issues a written notice to the telecom service provider, typically under the production-of-document provisions of the criminal procedure law (Section 91 in the CrPC framework, the equivalent BNSS provision in the new code). The notice asks for two things. First, the subscriber details for the number — the registered name, address, KYC documents, the date of activation. Second, the call detail record for a defined period — usually the last seven to thirty days — showing every call and SMS made or received, the duration, the cell tower used, and the other party's number.

Once these come back, the investigation often unblocks itself. The KYC may directly identify the person. If the SIM was issued on fake documents, the cell tower locations show where the threats originated, and a small radius search using nearby CCTV and known suspects narrows the field. The CDR also shows who else the threatener has been speaking to, which often connects the threat to a specific dispute the victim is involved in. Trained investigating officers do this every week.

The same machinery can be used for an Indian operator's mobile data records to find the IP address that a particular subscriber's phone was using at a particular time. From the IP address the police can request the platform records to trace the social-media account that was logged in.

Tracing Threats on WhatsApp, Telegram and Social Apps

If the threat came over a messaging or social platform, the chain is slightly different but the logic is the same. The police request platform cooperation through the law-enforcement channel that every major platform must publish in India under the Information Technology Rules 2021. The platform typically provides four kinds of data: the registered phone number or email of the account holder, the IP address logs at the time of registration and at the time of the threatening messages, the device fingerprint, and basic subscriber information.

The platform cannot hand over the content of end-to-end encrypted messages because it does not have access to that content on its servers. This is a real and well-known limit. What the platform can hand over is the metadata — the trail that points to a specific phone number, email or device. Once the police have that, the chain goes back to the telecom operator: which SIM was logged into the account at the relevant time, where was that SIM physically located, and who is the registered subscriber.

End-to-end encryption blocks server-side content recovery, but the threat itself sits on your phone. Your screenshots are direct evidence of the content. So you do not need the platform to hand over the message; you only need the platform to hand over the identifier of the speaker. That is something every major platform is required to provide on a properly framed law-enforcement request.

Threats From Abroad or Through a VPN

This is where you need an honest conversation about limits. If the threatener is using a foreign-issued SIM, an OTT calling app registered with a foreign phone number, or a VPN that masks the source IP, tracing slows dramatically.

The legal route in cross-border cases is the Mutual Legal Assistance Treaty, or MLAT. India has MLAT arrangements with several countries. The CBI's Interpol-MLAT cell, in coordination with the Ministry of Home Affairs and the Ministry of External Affairs, transmits formal requests to the requested country for evidence and identification. MLAT requests are real, but they are not fast. Even cooperative countries take three to six months on average. Some take longer or never respond. Where the foreign country does not have an active MLAT or the offence does not meet dual-criminality, the request may simply fail.

This is not a reason to do nothing. It is a reason to set your expectations correctly. In foreign-server cases, the realistic short-term outcome is usually a takedown of the offending account by the platform on the strength of your FIR, plus a documented investigation file that may bear fruit later. If the threats are localised and ongoing, a parallel application for protective orders before the magistrate or the High Court can address your immediate safety while the long-form investigation proceeds.

The BNSS / Criminal Procedure Investigation Framework

The criminal procedure law lays down the architecture inside which all of this happens. Once the FIR is registered, the investigation officer derives powers from the chapter on police investigation. Three powers matter most for cyber threat cases.

One, the production order (Section 91 in the CrPC framework, equivalent to Section 94 of BNSS). Any officer-in-charge of a police station, as well as any court, can require the production of any document or thing necessary for an investigation. The Supreme Court in Om Prakash Sharma v Central Bureau of Investigation (2000) emphasised that production must be necessary or desirable for the investigation. The provision is the legal foundation for issuing a notice to the telecom operator or the social platform demanding records.

Two, search and seizure (Sections 93, 94, 100 and 102 of the criminal procedure law and equivalent BNSS provisions). Once a suspect is identified, the police can apply for a search warrant from the magistrate, recover the device used to send the threats, and seize it as material evidence. Section 102 allows seizure of property suspected of being involved in an offence.

Three, the chain from FIR to chargesheet (Sections 154, 156, 161, 173 of the criminal procedure law and the equivalent BNSS provisions). The leading commentary on Chapter XII of the criminal procedure law lays out the architecture: information is received, the FIR is recorded, investigation begins, witnesses are examined, the suspect is identified, a chargesheet is filed, and the magistrate takes cognizance. Every step is paper-trailed. None of it should be a mystery to you as the complainant; you are entitled to know your investigating officer's name, the FIR number, and the broad status of the file.

Filing the FIR: A Practical Checklist

Most criminal intimidation cases die at the FIR stage because the complaint is too vague. A good FIR is short, sharp and chronological.

  • Name, address, age and contact of the complainant.
  • The threatening number, handle or platform with screenshots attached.
  • Dates and times of every threat in chronological order. Be precise.
  • The exact words of the threat, copy-pasted or reproduced verbatim.
  • The "or else" element — what does the threat ask you to do or not do?
  • Any context that points to a possible suspect — a dispute, a court case, a workplace incident.
  • Any witnesses who saw or heard about the threats.
  • The legal sections — IPC 503/506 (and 507 if anonymous), IT Act 66 if electronic.
  • A request for urgent action — CDR analysis, IP trace, platform notice.

If the local police hesitate to register the FIR, you have remedies. A zero-FIR can be registered at any police station and transferred to the station with proper jurisdiction. If even that fails, an application under Section 156(3) of the criminal procedure law (and the equivalent BNSS provision) can be moved before the magistrate to direct the police to register and investigate. These are real, well-trodden routes.

Realistic Timelines and Why They Matter

Here are honest expectations.

FIR registration: same day if your papers are clean. Production notice to the telecom operator: issued within a week of FIR. Telecom response with subscriber details and CDR: typically 7 to 30 days, sometimes faster on serious cases. Platform response on social media accounts: 15 to 30 days through the standard law-enforcement channel. Identification of suspect, where everything is domestic: 4 to 12 weeks. Arrest: 1 to 4 weeks after identification. Chargesheet: within 60 to 90 days of arrest under the standard rules.

Where the speaker is abroad or behind a VPN: 6 months to never. Where the threat is intermittent and not life-threatening, the realistic outcome may be takedown plus a record on file rather than identification.

The reason to know these timelines is to be a useful complainant. Police files move when complainants follow up steadily without panicking. Note your IO's name and number. Visit or call once a week initially, then once a fortnight. Keep a written log of every interaction. If progress stalls beyond 30 days without a clear technical reason, escalate in writing to the SHO and then to the DCP.

If the threats relate to a wider pattern of online harm including stalking, doxxing or sustained harassment, the case overlaps with the topic of online harm and digital safety, which can change the strategy and the protective relief available.

What Should I Actually Do Now?

  1. Do not reply to the threatener. Do not call back. Engagement encourages escalation and contaminates evidence.
  2. Screenshot everything. Capture the message, the sender's number or handle, and the visible date/time. If the message is a voice note, save the audio file.
  3. Write down a chronology. One line per incident — date, time, what was said, what platform. This becomes the spine of your FIR.
  4. Note the context. Is there a dispute, a court case, a workplace incident, or a relationship that may have triggered the threats? Mention it in your complaint to help narrow suspects.
  5. File the FIR at your nearest police station. Mention IPC Sections 503 and 506, Section 507 if anonymous, IT Act Section 66 if electronic. Carry printed screenshots and your photo ID.
  6. Lodge a parallel complaint at cybercrime.gov.in. The portal complaint creates a permanent digital record and is useful for follow-up.
  7. Ask for a CDR notice in writing. Politely request the IO to issue a production notice to the telecom service provider for the threatening number.
  8. Tell the platform. If the threat came through a social media platform or messenger, file an in-app report and email the grievance officer with your FIR copy.
  9. If the threat is severe, ask for protection. Where the threat names your home, your family or a date, your lawyer can move the magistrate or the High Court for protective orders or police protection.
  10. Follow up methodically. Note the FIR number, the IO's contact, and visit every 7 to 10 days for the first month. Keep a written log.

If the police are slow, the platform is unresponsive, or the threats continue while the file lies dormant, that is a moment when an experienced lawyer can speed things up materially. At Pinaka Legal we routinely move 91/94 production-notice follow-ups, magistrate applications under Section 156(3) of the procedure code, and parallel writ-style protections where the threat involves a vulnerable victim. The aim is straightforward — identify the speaker, stop the threats, and put the file on a track that ends in a chargesheet.

Frequently Asked Questions

Can police really trace a threatening unknown number?

Usually yes if the number is an Indian SIM. The investigating officer issues a written notice to the telecom service provider asking for subscriber details and the call detail record. The provider replies with the registered name, address, KYC documents and the cell tower locations from where the threats originated. This is routine work for police, and turnaround is generally a week to a month. The exception is when the caller used a foreign SIM, an OTT calling app over a VPN, or a stolen SIM, in which case tracing slows down considerably.

What law makes online threats a crime?

Section 503 of the Indian Penal Code defines criminal intimidation as threatening another person with injury to body, reputation or property with the intent to cause alarm or to force the victim to do or not do something. Section 506 prescribes the punishment, which can extend to two years' imprisonment, fine, or both. Where the threat is made through any electronic means or computer resource, Section 66 of the Information Technology Act and the related provisions on offensive electronic communication can be added depending on the precise content of the threat.

What is a CDR and how does it help trace the caller?

A call detail record is a log maintained by every telecom operator showing each call and SMS made or received from a number — including time, duration, the cell tower used, and the other party's number. The investigating officer issues a production notice to the operator under the criminal procedure law. The CDR places the suspect at a specific tower at a specific time and links the threatening number to other accounts, devices and people. CDR analysis is usually the single most important step in tracing telephone-based threats.

Can WhatsApp messages or Telegram threats be traced?

Up to a point. Police can ask the platform for the registration number, IP address logs, account creation device, and basic subscriber information through the platform's law enforcement channel. The actual content of end-to-end encrypted messages cannot be retrieved from the platform's servers, only from a phone seized during arrest. So the chain typically goes: registered number, then telecom operator KYC, then physical address, then arrest and seizure. The encryption is a real limit, but the metadata trail is usually enough to identify the sender.

What if the threats are from a foreign number or VPN?

This is where investigation becomes harder and slower. If the server or registration is in another country, Indian police can request information through the Mutual Legal Assistance Treaty route, which involves the Ministry of Home Affairs and the Ministry of External Affairs. MLAT requests are real but they take months and depend on the cooperation of the foreign country. Be honest with yourself about timelines. Where threats are localised, intermittent, and not life-threatening, the realistic outcome may be takedown of the account rather than identification and prosecution of the speaker.

Should I file an FIR or just complain to the cyber cell?

File the FIR. Cyber cells assist with technical investigation but the FIR is the formal foundation under Section 154 of the criminal procedure law that authorises every subsequent step — production notices, search warrants, arrests. A cyber-cell complaint without a registered FIR often results in slow or informal action. If the local police hesitate, register a zero-FIR at any police station. The cybercrime portal at cybercrime.gov.in runs in parallel and is excellent for documentation, but it does not replace an FIR.

What do I need to bring to the police station?

Bring three things. One, a written one-page complaint setting out the facts, the dates and times, the threatening number or handle, and the sections (IPC 503/506, IT Act 66 if electronic). Two, printed screenshots and any chat exports, with the URL or sender visible. Three, your photo ID. If a colleague, neighbour or family member witnessed the threats, mention them by name. Do not over-script the complaint; the FIR does not need to be exhaustive, only clear.

How fast will police actually act?

It depends on the threat level. If the threat is clearly serious — names a date, mentions a weapon, refers to your home or family — most police respond within hours and can request urgent CDRs. If the threats are anonymous trolling, response time is days to weeks. Persistent follow-up matters. Note your investigating officer's name and direct number, and check status every 7 to 10 days. If progress stalls, escalate to the SHO and then to the DCP in writing.

Is criminal intimidation a serious offence?

Yes, especially in its aggravated form. Section 506 of the IPC punishes simple criminal intimidation with imprisonment up to two years, fine, or both. The aggravated form — threats of death, grievous hurt, destruction of property by fire, or imputation of unchastity to a woman — carries up to seven years. In states like Uttar Pradesh, Section 506 has been made cognizable and non-bailable by state notification, which means immediate arrest and no automatic bail. Always check the local position with your lawyer.

Can I get an interim protection order while the police investigate?

Where the threat is severe and ongoing, your lawyer can move the magistrate or the High Court for protective orders. The magistrate has powers to direct police protection, restraining orders and even bind-down proceedings against a suspect once identified. Where the threat is from a known person — neighbour, ex-spouse, business adversary — a parallel application under domestic violence law or a restraining suit may be filed. Where the speaker is anonymous, the police investigation must produce identification before any restraining order can be enforced against a named person.

What happens if police identify the threatener but they are in another state?

Once the suspect is identified, the local police can travel to make the arrest, or request the police of the other state to assist. The criminal procedure law allows transit warrants. The accused will be brought before the magistrate who has jurisdiction over the offence. In practice this is bureaucratic but routine. Cases occasionally get stuck because of inter-state coordination delays; a written follow-up from your lawyer to the SP or DCP often unblocks the file.

Should I respond to the unknown number to gather more information?

No. Engaging with the threatener can encourage escalation and contaminate the evidence. Save everything, do not reply, do not call back, and do not send screenshots to mutual contacts before the FIR is filed. If the threat references something only an insider would know, mention that in your complaint so the investigating officer narrows down likely suspects. Let the police do the contact, not you.

For more articles on Indian law, visit the Pinaka Legal Blog. For queries, call +91 8595704798 or email info@pinakalegal.com.