UPSC CSE 2026 Essay Paper Discussion

Cybercrime and Cybersecurity in India: Attack Techniques, Critical Infrastructure and the Capacity Gap

The Kudankulam nuclear plant, AIIMS Delhi and India's UPI rails are all now attack surfaces. Cybersecurity stopped being an IT department problem the moment critical infrastructure went digital.

Code and a lock icon on a security console

The Kudankulam nuclear plant was targeted. AIIMS Delhi was taken down. India’s payments system now carries a large share of the country’s retail transactions on digital rails. Cybercrime and cybersecurity stopped being an IT department concern at the point where critical infrastructure, health records and money all moved online, which in India happened faster than almost anywhere.

Cybercrimes are criminal activities in which computers, communication devices, networks or the internet serve as the tool, the target or the medium.

The Attack Techniques

Malware. Malicious software built to damage systems, steal data or gain access.

TypeBehaviour
VirusAttaches to a host file and spreads when the file is executed
WormSelf-replicates and spreads without human intervention
TrojanDisguised as legitimate software, malicious after installation
SpywareSecretly collects user information
RansomwareEncrypts data or locks systems and demands payment, usually in cryptocurrency
BotnetNetwork of compromised machines controlled remotely

WannaCry and Locky are the standard ransomware references.

Denial of service. Flooding a website, server or network with traffic so legitimate users cannot reach it. When multiple compromised systems generate the traffic, it becomes distributed, which is far harder to filter.

Cryptojacking. Covertly using someone else’s computing resources to mine cryptocurrency. No data is stolen, which is why it goes unnoticed, and it still drains processing power, raises electricity consumption and damages hardware.

Social engineering. Manipulating human psychology rather than technical vulnerabilities, exploiting trust, fear, urgency, greed or curiosity. Phishing emails, fake bank messages, fake job offers, QR-code fraud, customer-care fraud, CEO impersonation and fake law-enforcement calls all belong here, and so do the digital arrest scams that have proliferated in India.

Advanced Persistent Threats. Long-term, stealthy intrusions, often state-backed, aimed at espionage, data theft or strategic mapping of critical systems rather than immediate disruption.

AI-enabled cybercrime. Generative AI makes phishing more convincing, clones voices, produces fake video, automates vulnerability discovery and enables impersonation at scale.

Why This Matters for India

Critical infrastructure. Power grids, nuclear plants, telecom networks, airports, hospitals and banks are digitised, and an attack disrupts essential services. The Kudankulam incident and the Mumbai blackout are the reference cases.

Financial security. With UPI, digital banking and fintech at India’s scale, cyber fraud threatens trust in the payments system itself. UPI fraud, fake investment apps, mule accounts, loan-app scams and digital arrest frauds are the operational forms.

Data protection and privacy. India’s digital ecosystem holds enormous volumes of personal, health, financial and biometric data. The AIIMS Delhi attack showed what a breach in a single large institution looks like.

National security. Cyber espionage against military, diplomatic and strategic institutions is now a standing component of hybrid warfare, alongside disinformation.

The Structural Problem

Two features of the Indian situation deserve to be named plainly.

Social engineering defeats technical controls. A country that has onboarded hundreds of millions of first-time digital users in a decade has a very large population with limited experience of distinguishing a genuine bank message from a fraudulent one. No firewall addresses that. Digital literacy is not a soft complement to cybersecurity here; it is the primary control for the most common attack class.

AI has inverted the cost asymmetry. Defence has always been more expensive than attack in cybersecurity. Generative AI makes convincing, personalised, multilingual attacks nearly free to produce, while detection still requires skilled analysts. The gap is widening, and it widens fastest in exactly the linguistic diversity that makes Indian content moderation hard.

The Way Forward

  • Treat digital literacy as core infrastructure, delivered in regional languages at the scale of the user base rather than as periodic campaigns.
  • Mandate security baselines for critical infrastructure operators, with audit and disclosure obligations rather than voluntary guidance.
  • Build detection capacity, not only prevention, since assuming breach is now the realistic operating posture.
  • Strengthen incident reporting, because under-reporting by institutions protects reputations and blinds policy.
  • Invest in the workforce. India’s cybersecurity personnel shortfall is the binding constraint, and it cannot be closed by procurement.

The reframe: cybersecurity in India is not primarily a technology problem. It is a literacy, reporting and workforce problem with a technology component.

Frequently Asked Questions

What are cybercrimes?

Criminal activities in which computers, communication devices, networks or the internet are used as the tool, the target or the medium of crime. Common forms include hacking and unauthorised access, online financial and UPI fraud, phishing and impersonation, malware and ransomware, cyberbullying, digital arrest scams, stalking and doxxing, and cyber espionage against critical infrastructure.

What is malware and what are its main types?

Malicious software designed to damage systems, steal data or gain unauthorised access. A virus attaches to a host file and spreads when executed. A worm self-replicates without human intervention. A trojan disguises itself as legitimate software. Spyware secretly collects user information. Ransomware encrypts data or locks systems and demands payment, usually in cryptocurrency, as with WannaCry and Locky.

What is the difference between DoS and DDoS?

A denial of service attack floods a website, server or network with excessive traffic so that legitimate users cannot reach it. When multiple compromised systems are used together to generate that traffic, it becomes a distributed denial of service attack, which is far harder to filter because the traffic comes from many sources.

What is cryptojacking?

Secretly using another person’s computer or server resources to mine cryptocurrency. It may steal no data at all, but it drains processing power, slows systems, raises electricity consumption and shortens hardware life, which makes it easy to miss and expensive to tolerate.

What is social engineering?

Manipulation of human psychology rather than technical vulnerabilities, exploiting trust, fear, urgency, greed or curiosity. Examples include phishing emails, fake bank messages, fake job offers, QR-code fraud, customer-care fraud, CEO impersonation and fake law-enforcement calls, which underpin the digital arrest scams now widespread in India.

What are Advanced Persistent Threats?

Long-term, stealthy intrusions, often linked to state-backed actors, aimed at espionage, data theft or strategic mapping of critical systems rather than immediate disruption. Their defining feature is patience: the objective is persistent access, not a visible incident.

How does artificial intelligence change cybercrime?

Generative AI makes phishing messages more convincing, clones voices, generates fake video, automates vulnerability discovery and enables large-scale impersonation. The effect is to make attacks cheaper, faster and harder to detect, which shifts the economics decisively towards the attacker.

Why does cybersecurity matter for India specifically?

Four reasons: critical infrastructure protection, since power grids, nuclear plants, telecom, airports, hospitals and banks are digitised; financial security, given the scale of UPI and digital banking; data protection, given the volume of personal, health, financial and biometric data held; and national security, since cyber espionage and disinformation are now components of hybrid warfare.

Practice Questions

Prelims MCQs

  1. A worm differs from a virus in that it
    (a) Requires a host file to spread
    (b) Self-replicates and spreads without human intervention
    (c) Only affects mobile devices
    (d) Encrypts data for ransom
    Answer: (b) A virus needs a host file executed by a user; a worm propagates autonomously.
  2. Cryptojacking involves
    (a) Stealing cryptocurrency wallets
    (b) Secretly using another's computing resources to mine cryptocurrency
    (c) Encrypting data for ransom
    (d) Flooding a server with traffic
    Answer: (b) It consumes processing power and electricity rather than stealing data directly.
  3. WannaCry is an example of
    (a) Spyware
    (b) Ransomware
    (c) A worm only
    (d) A denial of service tool
    Answer: (b) WannaCry encrypted data and demanded cryptocurrency payment, making it ransomware.
  4. Advanced Persistent Threats are characterised primarily by
    (a) Immediate visible disruption
    (b) Long-term stealthy access for espionage or mapping
    (c) High-volume traffic floods
    (d) Consumer financial fraud
    Answer: (b) APTs prioritise persistent undetected access, typically for espionage or strategic reconnaissance.
  5. Social engineering attacks exploit
    (a) Unpatched software
    (b) Weak encryption
    (c) Human psychology
    (d) Network topology
    Answer: (c) They target trust, fear, urgency, greed or curiosity rather than technical vulnerabilities.

Mains Questions

  1. Cybersecurity has become a national security issue rather than a technical one. Examine with reference to India's critical infrastructure. (250 words)
  2. Artificial intelligence has shifted the economics of cybercrime in favour of the attacker. Discuss the implications for defence. (250 words)
  3. Social engineering defeats technical controls. Evaluate the role of digital literacy in India's cybersecurity strategy. (150 words)
  4. Discuss the vulnerabilities created by rapid digitalisation of financial services in India. (250 words)
  5. Assess India's institutional framework for cybersecurity and identify the principal gaps. (150 words)

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Written by

Jwala Kumar Sir

Jwala Kumar teaches Science and Technology at Anantam IAS. He covers space, biotechnology, quantum computing, defence systems and cybersecurity, explaining the underlying science first so aspirants can read a new mission or policy announcement without waiting for a coaching handout.

Preparing for UPSC CSE 2026? Sit in a free demo class.

No sales call. No brochure. Watch a real Monday-morning GS session taught by ex-Rau's IAS faculty.