Why in News?
- According to National Crime Records Bureau (NCRB) 2024 data, cybercrime cases in India rose sharply by 17.9% from 2023–2024, even as overall registered crime fell by 6%.
- The Status of Policing in India Report (SPIR) 2026 highlights citizens' vulnerability to cyber fraud and systemic challenges in securing justice for cyber fraud victims.
Scale and Nature of Cyber Frauds in India
Key Statistics
- NCRB 2024: Over 1.01 lakh cybercrime cases recorded; cybercrime rate escalated to 7.3 per lakh population.
- Conviction rate below 18% (NCRB 2022) due to challenges in digital evidence collection, procedural lapses and the transnational nature of cybercrimes.
- Over 80% of victims suffered financial losses; 23% lost upwards of ₹20,000.
- Primary motive: Financial gain through Forgery, Cheating and Fraud (FCF), followed by extortion and cyberstalking.
Changing Modus Operandi
- Social engineering over technical hacking: Fraud relies on psychological manipulation — exploiting institutional credibility (impersonating police/bank officials), aspirational greed (investment scams) and emotional distress.
- "Tax on Connectivity": Financial fraud is now a byproduct of deep digital integration; criminals systematically track digital footprints, making educated professionals and affluent groups highly vulnerable.
- Next-generation scams: AI-enabled deepfakes, spoofing, phishing, organised cyber syndicates and "Digital Arrest" scams.
- Concealment techniques: Use of Voice over Internet Protocol (VoIP) to mask locations and rapid routing of stolen funds through layered "mule accounts", making asset recovery difficult.
- Payment vulnerabilities: Unified Payments Interface (UPI) frequently targeted via compromised mobile numbers.
India's Legal Framework for Cyberspace
- Information Technology Act, 2000: Penalises identity theft, impersonation and harmful content; empowers blocking of malicious apps; Section 70A provides for protection of Critical Information Infrastructure (CII).
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: Ensures accountability of social media intermediaries; mandates swift removal of unlawful content.
- Digital Personal Data Protection (DPDP) Act, 2023: Imposes strict security obligations on data fiduciaries; mandates lawful data handling and explicit user consent.
- Promotion and Regulation of Online Gaming Act, 2025: Promotes e-sports while imposing a complete ban on online money gaming and related financial transactions.
- Bharatiya Sakshya Adhiniyam (BSA), 2023: Governs admissibility of electronic evidence — critical for securing cybercrime convictions.
Institutional Defence Mechanisms
- CERT-In (Indian Computer Emergency Response Team): Monitors cyber threats, identifies vulnerabilities, coordinates incident response.
- I4C (Indian Cybercrime Coordination Centre): Under Ministry of Home Affairs; facilitates real-time information sharing and coordination among law-enforcement agencies.
- NCIIPC (National Critical Information Infrastructure Protection Centre): Protects CII in banking, telecom, power and transportation.
- Financial Fraud Risk Indicator (FRI): Developed by the Department of Telecommunications; classifies suspicious mobile numbers into Medium, High and Very High-risk categories.
- CFCFRMS & 1930 Helpline: The Citizen Financial Cyber Fraud Reporting and Management System enables rapid reporting and freezing of fraudulent transactions.
- National Cyber Crime Reporting Portal and Sahyog Portal (for rapid removal of phishing links and malicious apps).
Challenges in Securing Cyber Justice
- Procedural attrition and under-reporting: A large plurality of victims never approach law enforcement; many abandon cases due to procedural hurdles and low trust in police.
- Institutionalised rent-seeking: Delays push vulnerable victims (poor, rural, women) to seek police action through bribes or personal networks, creating unequal access to justice.
- "Golden Hour" failure: Cyber syndicates siphon stolen funds rapidly through mule accounts; lack of automated, real-time coordination between police and banks means funds are withdrawn before freeze orders are executed.
- Jurisdictional fragmentation: Police bound by territorial jurisdictions, while criminals operate trans-nationally using VoIP and VPNs; inter-state coordination is slow.
- Forensic capacity deficit: Grassroots police stations lack digital forensics, blockchain tracking skills and electronic evidence preservation capabilities needed under BSA, 2023.
Way Forward: Accountable Cyber Justice
- Enforceable FIR registration: Make FIR registration for cyber fraud mandatory and time-bound to eliminate arbitrary police discretion.
- Proactive telecom intelligence: Expand FRI to flag high-risk numbers and block suspicious transactions pre-emptively.
- SOPs for asset freezing: Institutionalise real-time coordination between I4C, RBI, banks and telecom providers to freeze stolen funds within the "golden hour"; scale up the 1930 helpline and reporting portal.
- Targeted digital literacy: Shift from generic warnings to education on specific psychological manipulation tactics used by fraudsters.
- Scale the Sahyog Portal for rapid removal of phishing links and fraudulent content.
- Anti-corruption safeguards: Internal vigilance audits and automated tracking of recovered funds within cyber cells.
Significance for India
- With rapid digitalisation (UPI, Digital India), cybercrime threatens financial inclusion gains and citizen trust in digital public infrastructure.
- A shift from reactive investigation to proactive, technology-driven prevention is essential for cyber resilience.
- A victim-centric, corruption-free cyber justice system ensures digitalisation strengthens trust rather than creating new vulnerabilities.
Previous Year Questions (PYQ)
Prelims 2020: On cyber insurance for individuals — benefits covered include cost of system restoration, cost of hiring specialised consultants for cyber extortion, and cost of legal defence (Answer: 1, 3 and 4 only).
Prelims 2017: Service providers, data centres and body corporates are all legally mandated to report cyber security incidents in India.
Mains 2022: "What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy."
Conclusion
India's cybercrime challenge demands a paradigm shift from reactive investigation to proactive, technology-driven prevention and justice. Strengthening I4C coordination, FRI-based prevention, real-time fund freezing, digital literacy and accountable policing can build a cyber justice system worthy of a digital economy.