Opens in a new tab
Join Anantam IAS Channel on Telegram

Cybercrimes in India: Vulnerability and Access to Justice

Why in News?

The Status of Policing in India Report (SPIR), 2026, prepared by Common Cause and Lokniti-CSDS, examines cybercrime through a survey of 8306 respondents across 16 States. It highlights both growing exposure to online fraud and unequal access to redress. 

Meanwhile, NCRB data show that registered cybercrime cases increased from 86,420 in 2023 to 1,01,928 in 2024, a rise of 17.9%. These represent registered cases, rather than the entire extent of cybercrime. 

UPSC Relevance: GS-2: Polity and Governance: Governance; GS-3 Internal Security; GS-3 Science and Technology: Cybersecurity

Prelims: IT Act, I4C, CERT-In, NCRP, Sanchar Saathi etc. 
Mains: Cybercrimes and Cybersecurity

Understanding Cybercrime and Cyber Fraud:

  • Cybercrime refers broadly to criminal activities in which computers, communication devices or networks are the target or the means of committing an offence.
  • Cyber fraud is a subset involving digital deception to obtain money, credentials or other benefits.

Major forms of cybercrime include:

  • Financial fraud: Fake investment platforms, fraudulent loan apps, payment scams and bank impersonation.
  • Identity and data theft: Stealing passwords, personal information or account credentials.
  • Attacks on computer systems: Hacking, malware and ransomware that locks data and demands payment.
  • Online abuse and exploitation: Cyberstalking, bullying, sextortion and non-consensual sharing of intimate images.
  • Attacks on essential services: Disruption of digital systems supporting hospitals, banks, electricity and other infrastructure.

A crucial feature of many frauds is social engineering: manipulating people into trusting a fraudulent identity or request. Criminals exploit fear of authority, financial aspirations, urgency and trust in familiar relationships.

What does the Survey reveal?

Four findings capture its significance:

  • Exposure grows with digital participation: Frequent internet and digital-payment users encounter more fraudulent communications. Younger and less-educated respondents faced greater overall victimisation.
  • Financial fraud is prominent: Around 13% of respondents reported experiencing cybercrime in the preceding two to three years; financial fraud accounted for more than half of reported victim experiences. Financial fraud is more prominent among better-educated and affluent respondents. 
  • Reporting remains difficult: Around half of victims of cybercrime approached the police, while 42% of complainants found complaint registration difficult.
  • Justice can depend on informal influence: 27% of those who registered police complaints reported paying a bribe, with poorer complainants disproportionately affected. Personal contacts were also used to secure police attention. 

Who is more Vulnerable and Why?

Vulnerability has three dimensions: exposure to crime, severity of harm and ability to obtain justice.

  • Highly connected and financially active users: Frequent online shopping, investing and digital payments create more opportunities for fraudulent contact. Publicly available or leaked information can make impersonation more convincing. 
  • New digital users and people with limited digital literacy: Difficulty distinguishing genuine applications, customer-care numbers and payment requests can expose users to deception. Language barriers and dependence on intermediaries can compound the problem. Formal education does not necessarily provide the skills to recognise a sophisticated scam.
  • Elderly people and socially isolated individuals: Impersonation of relatives, banks or officials can exploit trust, fear and limited access to immediate assistance. Loss of retirement savings can be particularly damaging.
  • Women, children and adolescents: Cyberstalking, sexual harassment, grooming and image-based abuse create risks beyond financial loss. Fear of stigma or restrictions on internet access can discourage reporting.
  • Poor and rural households: Even a modest loss can disrupt essential expenditure. Travel costs, repeated police visits, lost wages, and limited legal assistance may make pursuing a complaint unaffordable.

Why is tackling Cybercrime difficult?

  • Rapid movement of money: Funds can move through several mule accounts (accounts used to receive and transfer criminal proceeds) before withdrawal or further concealment. Delayed reporting reduces opportunities to intercept them.
  • Interstate and international networks: Victims, offenders, bank accounts and servers may be located in different jurisdictions. Investigations require coordinated access to evidence across police forces, financial institutions and countries.
  • Evolving methods of deception: AI-generated voices, deepfake videos, fake websites and impersonation make fraudulent requests more persuasive. Technical safeguards alone cannot prevent a victim from being manipulated into making a payment.
  • Under-reporting and victim-blaming: Embarrassment, fear of reputational damage and low expectations of recovery discourage complaints. Treating victims as merely careless can deepen distrust.
  • Uneven investigative capacity: Effective investigation requires digital forensics, financial tracing, timely preservation of electronic evidence and trained prosecutors. Capacity varies across jurisdictions.
  • Fragmented responsibility and unequal treatment: Victims may have to approach banks, payment platforms, police and helplines separately. Demands for bribes or dependence on personal influence undermine equal access to justice.
  • Blocking money does not ensure its return: Complaint registration, FIR registration, freezing funds, refund and conviction are different stages. A successful intervention to block funds must be followed by lawful and timely restoration to the victim.

Why Cybersecurity Matters for India?

  • Critical Infrastructure Protection: India’s power grids, nuclear plants, telecom networks, airports, hospitals and banks are increasingly digitised. A cyberattack can disrupt essential services. E.g., Kudankulam Nuclear Powerplant attack, Mumbai blackout 
  • Financial Security: With UPI, digital banking and fintech growth, cyber fraud threatens trust in the financial system. E.g., UPI fraud, fake investment apps, mule accounts, loan-app scams and digital arrest frauds.
  • Data Protection and Privacy: India’s digital ecosystem stores large volumes of personal, health, financial and biometric data. Breaches in hospitals, insurers, banks or fintech firms can compromise privacy and institutional credibility. E.g., the AIIMS Delhi cyberattack.
  • National Security: Cyber espionage against military, diplomatic and strategic institutions can weaken India’s security. Cyberattacks are now part of hybrid warfare, along with disinformation, infrastructure disruption and psychological operations. 
  • Trust in Digital Governance: Digital India, DBT, Aadhaar-linked services, CoWIN, DigiLocker and other DPIs depend on public trust. If citizens fear data theft, identity fraud or service disruption, adoption of e-governance may suffer. 
  • Protection of Vulnerable Groups: Women, children, elderly citizens and digitally inexperienced users face higher risks of cyberstalking, sextortion, online grooming, doxxing, financial fraud and digital arrest scams. 

Government Laws, Institutions and Initiatives:

(i) Legal and procedural framework:

  • Information Technology Act, 2000: Section 66C addresses identity theft, while Section 66D addresses cheating by personation using computer resources. Other provisions deal with computer-related offences and unlawful electronic content. 
  • National Cyber Security Policy 2013: India’s first cybersecurity policy aims to build a secure and resilient cyberspace.
  • BNSS, 2023- Section 173: Information about a cognizable offence may be given irrespective of where it occurred, supporting Zero FIR. Information communicated electronically must be signed within three days to be taken on record. 
  • RBI’s customer-protection framework: Provides zero or limited customer liability for specified unauthorised electronic transactions, depending on responsibility and reporting time. It does not guarantee reimbursement for every scam-induced payment.

(ii) Reporting and coordinated action:

Indian Cyber Crime Coordination Centre (I4C): An attached office of the Ministry of Home Affairs, supporting coordinated action against cybercrime.

Its principal mechanisms include:

  • National Cyber Crime Reporting Portal (NCRP): Enables reporting of cybercrimes, with special attention to offences against women and children.
  • 1930 helpline and Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS): Facilitate immediate reporting of financial fraud and coordination to stop further movement of stolen funds.
  • Cyber Fraud Mitigation Centre: Brings banks, payment intermediaries, telecom providers, technology intermediaries and law-enforcement agencies together.
  • Samanvaya platform: Supports interstate information sharing and analysis of linked crimes.
  • Suspect Registry: Shares suspect identifiers with participating financial institutions to help prevent fraudulent transactions. 

(iii) Telecom-based fraud prevention:

  • Sanchar Saathi- Chakshu: Allows citizens to report suspected fraudulent communications. Actual financial fraud should be reported through 1930/NCRP.
  • Financial Fraud Risk Indicator (FRI): A Department of Telecommunications tool that classifies mobile numbers by financial-fraud risk and shares intelligence with banks and payment providers for preventive checks.

(iv) Capacity building and awareness:

  • Cybercrime Prevention against Women and Children (CCPWC) Scheme: Supports forensic-cum-training laboratories and investigative capacity.
  • CyTrain: Provides online training in cybercrime investigation, forensics and prosecution.
  • CyberDost: Spreads awareness about scams and safe digital practices.

(v) Wider cybersecurity institutions:

  • CERT-In, under MeitY, is the national agency for responding to cybersecurity incidents under Section 70B of the IT Act.
  • NCIIPC, designated under Section 70A, focuses on protecting critical information infrastructure.

These roles complement police investigation of individual cybercrimes. 

Key Challenges:

  • Shortage of trained cyber police, prosecutors and judges
  • Low FIR conversion and conviction rates
  • Cross-border nature of cybercrime
  • Use of mule accounts, fake SIM cards and crypto channels
  • Weak cyber hygiene among citizens
  • Inadequate cybersecurity budgets among MSMEs and local bodies
  • Fragmented institutional coordination
  • Shortage of digital forensic capacity
  • Outdated National Cyber Security Policy of 2013
  • Risks from AI, deepfakes and quantum computing
  • Poor security in Internet of Things and operational technology systems.

Way Forward: 

  • Update the National Cyber Security Policy and release a comprehensive National Cyber Security Strategy.
  • Strengthen CERT-In, I4C, NCIIPC and state cyber cells through manpower and technology.
  • Create specialised cyber courts and trained cyber prosecutors.
  • Expand cyber forensic labs at district and state levels.
  • Enforce secure-by-design standards for digital public infrastructure.
  • Make reporting accessible: Provide multilingual assistance, acknowledgement numbers, case tracking and effective implementation of Zero FIR.
  • Improve cyber hygiene through school curricula, workplace training and citizen campaigns.
  • Protect vulnerable groups through faster takedown, victim support and gender-sensitive policing.
  • Regulate mule accounts, fake SIMs and illegal loan apps more strictly.

As cybercrime becomes more organised, AI-driven and transnational, India must move from a reactive policing model to a proactive cyber-resilience model. 

Practice Prelims MCQ: 

Q. Consider the following statements:

  1. I4C functions under the Ministry of Home Affairs.
  2. CERT-In is the national agency for responding to cybersecurity incidents.
  3. Reporting a financial loss through Chakshu automatically initiates reimbursement.

Which statements are correct?

(a) 1 and 2 only
(b) 2 and 3 only
(c) 1 and 3 only
(d) 1, 2 and 3

Answer: (a) Chakshu concerns suspected fraudulent communications; it does not automatically reimburse losses.

UPSC PYQ 2018

Q. The terms ‘WannaCry, Petya and EternalBlue’ sometimes mentioned in the news are related to:

(a)    Exoplanets

(b)    Cryptocurrency

(c)    Cyber attacks

(d)    Mini satellites

Answer: (c)

UPSC PYQ 2017

Q. In India, it is legally mandatory for which of the following to report on cyber security incidents?

1. Service providers

2. Data centres

3. Body corporate

Select the correct answer using the code given below:

(a) 1 only

(b) 1 and 2 only

(c) 3 only

(d) 1, 2 and 3

Answer: (d)

Mains Practice Question: 

Q. In the context of the increasing frequency of cybercrimes, explain the importance of cybersecurity for India. Discuss the steps taken by the government to strengthen prevention and victim redress.

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Written by

Pooja Bhatt Ma'am

Editor — UPSC Content · Anantam IAS

Pooja Bhatt is part of the editorial team at Anantam IAS, writing and editing UPSC prep content across Prelims, Mains and current affairs.

Specialises in · UPSC syllabus content, editing and publishing Experience · 6+ years

Want tomorrow's brief in your inbox before coffee?

We edit — we don't scrape. Every morning, one lean briefing written for UPSC Prelims + Mains relevance.