New UPSC Foundation, Optional and TSPSC/APPSC batches are open — book a free demo class.Today's Daily QuizCall 98804 87071

Prelims GS-I · Threats · Security challenges

Cybercrime

Cybercrime — offences committed using computers and networks — is India's fastest-growing crime category, spanning financial fraud, identity theft, phishing, ransomware, online harassment and child exploitation. NCRB recorded over 65,000 cybercrime cases in 2022, but reported citizen complaints on the national portal run into millions annually, with financial fraud losses of tens of thousands of crores. India's response architecture includes the IT Act 2000, the Indian Cyber Crime Coordination Centre (I4C), the 1930 helpline and the National Cyber Crime Reporting Portal, alongside rising international cooperation.

The anatomy of cybercrime in India

Financial fraud dominates: UPI and card fraud, phishing links, fake investment and 'task' apps, loan-app extortion, QR-code scams and SIM-swap attacks. Social engineering — manipulating people rather than breaking systems — is the common thread. The 'digital arrest' scam epitomises this: victims are told on video calls by fake police or CBI officers that they are under investigation, and coerced into transferring money to 'clear' themselves.

Beyond fraud, India faces ransomware on hospitals and businesses, data breaches of government and private databases, online child sexual abuse material, cyberstalking and sextortion, and deepfake-driven disinformation. The attacker ecosystem is transnational: scam compounds in Myanmar, Cambodia and Laos, Chinese-linked loan apps, and domestic money-mule networks that launder proceeds within minutes.

  • Social engineering beats technical hacking in most Indian cases.
  • Digital arrest scams: fake police video calls extorting money.
  • Money mules move defrauded funds through layered accounts in minutes.
  • Deepfakes add a disinformation and extortion dimension.

Timeline

  1. 2000

    Information Technology Act enacted.

  2. 2004

    CERT-In established as national incident-response agency.

  3. 2020

    I4C becomes operational; cybercrime portal and helpline integrated.

  4. 2021

    IT Rules regulate intermediaries; traceability debate begins.

  5. 2023-24

    Digital arrest scams surge; national awareness campaign; UN cybercrime convention adopted.

Legal framework

The IT Act 2000 criminalises hacking (Section 66), identity theft (66C), cheating by personation (66D), cyber terrorism (66F) and privacy violation (66E); Section 69A empowers content blocking, and the 2021 IT Rules regulate intermediaries. The BNS 2023 covers cheating, criminal breach of trust, stalking and defamation regardless of medium. The Digital Personal Data Protection Act 2023 adds a data-protection layer, and the CERT-In directions (2022) mandate incident reporting within six hours.

Gaps remain: the IT Act predates smartphones and social media; jurisdiction is murky when offenders, servers and victims sit in different countries; and electronic evidence rules (Bharatiya Sakshya Adhiniyam Section 63, the successor to Section 65B of the Evidence Act) demand certification discipline that police stations often lack. A comprehensive new cyber law has been under discussion for years.

  • IT Act Sections 66, 66C, 66D, 66F are the workhorse provisions.
  • CERT-In requires cyber-incident reporting within six hours.
  • IT Rules 2021 impose due diligence on social-media intermediaries.
  • India has no comprehensive modern cybercrime statute yet.

What happens when you call 1930

  1. 1. Victim reports fraud to 1930 or cybercrime.gov.in
  2. 2. Ticket raised with transaction details
  3. 3. Banks and wallets alerted to freeze the money trail
  4. 4. Funds blocked across layered mule accounts
  5. 5. Case handed to state police for investigation

Institutional architecture

The I4C (2020) is the nodal framework with seven components: the National Cyber Crime Reporting Portal (cybercrime.gov.in), the 1930 helpline and Citizen Financial Cyber Fraud Reporting System, the National Cyber Forensic Laboratory, the Joint Cybercrime Coordination Team, cyber-threat analytics, training, and an ecosystem unit engaging banks and platforms. The 1930 system's ability to freeze defrauded money in transit — lakhs of calls, thousands of crores saved — is its biggest success.

CERT-In (2004) handles national incident response and threat advisories; the National Critical Information Infrastructure Protection Centre (NCIIPC) protects critical sectors; state cyber cells and cyber police stations investigate; and the National Cyber Security Coordinator advises at the apex. Capacity is the constraint: India has roughly one cyber police station per several districts, and forensic labs are overburdened.

  • I4C's seven pillars span reporting, forensics, analytics and coordination.
  • 1930 helpline freezes funds within the 'golden hour'.
  • CERT-In: incident response; NCIIPC: critical infrastructure.
  • Cyber police capacity lags far behind complaint volume.
Major cybercrime types and primary responses
CrimeModus operandiPrimary response
Financial fraudPhishing, UPI scams, fake apps1930 helpline, fund freezing, bank coordination
Digital arrestFake police video callsAwareness campaign, telecom blocking, I4C action
RansomwareEncrypted systems, extortionCERT-In advisories, backups, incident response
Data breachHacked databases sold on darknetDPDP Act, CERT-In reporting, forensics
Online harassmentStalking, sextortion, deepfakesIT Act/BNS provisions, platform takedowns

The international dimension and the road ahead

Cybercrime is borderless, but law is not. India declined to join the Budapest Convention, objecting to its drafting process and data-access provisions; it relies instead on MLATs (slow, often taking years), direct platform requests under US law (the CLOUD Act route), and G8 24/7 network cooperation. India signed the UN Convention against Cybercrime (adopted 2024) negotiations actively, seeking a more inclusive treaty.

The road ahead has three lanes: prevention (awareness campaigns, SIM/device binding for UPI, platform accountability), capacity (more cyber police stations, forensic labs, trained judges and prosecutors) and cooperation (faster MLATs, joint operations against scam compounds, data-sharing agreements). With digital payments at over 13,000 crore UPI transactions a year, the attack surface will only grow — cyber hygiene at population scale is now a national security imperative.

  • India is outside the Budapest Convention; relies on MLATs and bilateral channels.
  • UN Convention against Cybercrime (2024) is the new global framework.
  • UPI scale makes India the world's largest real-time payments target.
  • Prevention through awareness is the cheapest and most scalable defence.

Real-world case studies

The 1930 golden-hour system

Since its launch, the Citizen Financial Cyber Fraud Reporting System has handled lakhs of complaints and frozen thousands of crores in transit. Its success rests on speed: because fraudsters layer money through mule accounts within minutes, only real-time coordination between police, banks and payment platforms can intercept it.

AIIMS ransomware attack (2022)

A ransomware attack crippled AIIMS Delhi's servers for nearly two weeks, forcing a return to manual processes and exposing patient data. The attack underlined the vulnerability of critical health infrastructure and accelerated investment in cyber resilience across government hospitals.

Previous year questions

No UPSC question has been asked directly on this micro-topic yet. Use the practice questions below.

Practice questions

Practice MCQ 1

The helpline number for reporting financial cyber fraud in India is:

  • A. 112
  • B. 1930
  • C. 1091
  • D. 1553

Practice MCQ 2

CERT-In functions under which ministry?

  • A. Ministry of Home Affairs
  • B. Ministry of Electronics and Information Technology
  • C. Ministry of Defence
  • D. Ministry of Communications
Mains practice · 'In cybercrime, the victim's awareness is the first and cheapest line of defence.' Discuss with reference to India's recent fraud waves.
  • Social engineering dominates: phishing, digital arrest, investment scams.
  • 1930 golden-hour freezing; awareness campaigns.
  • Platform and telecom accountability.
  • Limits of enforcement against transnational syndicates.
Mains practice · Examine the jurisdictional and evidentiary challenges in prosecuting cybercrime in India and suggest reforms.
  • Borderless crime vs territorial law; servers and offenders abroad.
  • MLAT delays; India's stance on Budapest Convention.
  • Electronic evidence certification under BSA Section 63.
  • Reforms: modern cyber law, capacity, international data-sharing.

Further reading

  • IT Act 2000 — India Code
  • cybercrime.gov.in — National Cyber Crime Reporting Portal
  • NCRB Crime in India (cybercrime chapter)

Book a free demo class

Talk to a counsellor about the right batch, timings and preparation plan. No fee to attend a demo session.

Or call 98804 87071 · Mon–Sat 9 am–7 pm

Free UPSC daily current affairs quiz — 10 questions, new every day at 8 am IST.

Take the Daily Quiz
Call nowWhatsApp