Skip to Content

Cyber Fraud and Online Scams

How to Stay Safe in the Digital Age
26 August 2026 by
Himanshi Jangra, Ballb ,3 year, Maharaja Surajmal Institute, Delhi
​

Abstract

Cyber fraud and online scams have emerged as one of the most pressing challenges of the digital age, affecting individuals, institutions, and the economy at large. This paper examines the meaning and scope of cybercrime, distinguishes it from the narrower category of online scams, and analyses the principal causes driving its rapid growth in India, namely lack of awareness, exploitation of human emotion, and technological vulnerability. It surveys the most prevalent forms of online fraud in the country, including phishing, banking fraud, investment and cryptocurrency scams, deepfake-enabled fraud, and job or work-from-home scams, before assessing their financial, legal, and psychological impact on victims. The paper further reviews the Indian legal framework governing cybercrime, comprising the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023, and allied policy measures, and outlines practical safety measures and victim-response protocols. Finally, it identifies persistent challenges in combating cybercrime and offers suggestions, including digital literacy campaigns, stronger cybersecurity measures, faster prosecution, and the responsible use of artificial intelligence, to build a safer digital ecosystem.

Keywords: cybercrime, online scams, phishing, deepfake, cyber fraud, digital safety, Information Technology Act, Bharatiya Nyaya Sanhita

1. Introduction

Imagine a situation in which a person uses Google Maps to find a helpline number, only to have their bank account hacked and money deducted instead of receiving help. This is no longer a hypothetical scenario but an evolving reality that is rapidly affecting people across the country. This particular field of crime is known as cybercrime. In lay terms, cybercrime is a type of crime that takes place online, an illegal activity in which an electronic device is used as a medium to deceive people and gain financial advantage. Attackers increasingly rely on digital channels to commit traditional crimes such as theft, fraud, and harassment.[1]

According to The Hindu, cyber fraud cases have risen sharply in recent years. [2] This growth is not attributable solely to a lack of awareness; it is also fuelled by distinctly human factors such as greed and susceptibility to manipulation. Cybercrime is not a single, standalone offence but an umbrella term that encompasses a range of other crimes, including deepfakes, phishing, investment fraud, and impersonation. No single explanation accounts for the rise of these crimes, but the growth is largely linked to the increased use of digital networks over time. India, in particular, is rapidly moving online, whether through digital transactions or the widespread use of social media platforms. [3] These trends have not gone unnoticed by the government, which has introduced a range of measures aimed at deterring cybercrime and online fraud, discussed in detail later in this paper.

2. Understanding Cyber Fraud

Cybercrime is a blanket term describing all crimes committed via the internet, typically aimed at acquiring financial gain or damaging an individual's social reputation. India witnesses thousands of online fraud cases daily, driven largely by the shift of traditional activities, from financial transactions to record-keeping, onto digital platforms. While this shift has substantially reduced administrative workload, it has simultaneously increased exposure to cyber fraud. According to a 2023 report by the U.S. Federal Trade Commission (FTC), since 2021 one in four people who reported being defrauded of money said the scam began on social media. [4] Behind all such crimes lies a common link: the use of technology.

Although the terms "cybercrime" and "online scam" are often used interchangeably, a meaningful distinction exists between them. Cybercrime is a broad category encompassing all illegal acts involving computers or networks, whereas an online scam refers specifically to a deceptive scheme used to steal money or data. In short, all online scams are cybercrimes, but not all cybercrimes are online scams. While no single rule fully explains the daily rise of such crimes, three major contributing factors can be identified.

2.1 Lack of Awareness

A significant proportion of the population lacks the knowledge necessary to prevent online scams and cybercrime. Young people, in particular, are often unaware of how to secure their digital credentials and frequently fail to use strong passwords, making it easier for attackers to compromise their accounts quickly. [5] Raising awareness about online account security is therefore essential to reducing the cyber threat.

2.2 Human Emotion

Human emotion plays a critical role in making individuals easy targets for cybercrime. People are often drawn in by promises of online lottery winnings or alarmed by fake police-arrest calls, both of which serve as common entry points for fraud. When receiving such calls, it is important to remain composed and avoid falling for these tactics; a formal complaint should then be filed to help curb this menace. [6]

2.3 Technological Vulnerability

Technological vulnerability, or the absence of efficient systems to manage cyber threats, is a further root cause of cybercrime. As technology advances, so too do the methods used by cybercriminals to exploit existing weaknesses. Gaps in regulatory oversight compound this problem, giving attackers greater confidence and posing a broader social threat.[7] Addressing all three factors awareness, emotional vulnerability, and technological weakness is essential to developing a robust response to cybercrime.

3. Most Common Online Scams in India

India is currently confronting several recurring categories of cybercrime, outlined below.

3.1 Phishing (Emails and PDFs)

Phishing is the most widespread form of cybercrime. It involves the deceptive impersonation of trusted entities, such as banks or government agencies, in order to trick individuals into revealing sensitive data, ranging from passwords to credit card details. Victims are often asked to share a One-Time Password (OTP) or induced to click malicious links. [8] Individuals are therefore advised to verify the authenticity of any website or PDF before interacting with it and to never share OTPs with anyone.

3.2 Banking Fraud

Fraudulent calls from individuals posing as bank employees are frequently used to extract personal information. These calls are often made from untraceable, unauthorised numbers. Scammers request card details under the pretext of a routine banking formality, when in fact they are attempting to obtain the victim's UPI PIN. Such calls should be terminated immediately without disclosing any personal details, and the incident should be reported to assist law-enforcement tracking. [9]

3.3 Investment and Cryptocurrency Scams

Fraudsters distribute malicious Android and iOS applications through third-party links or clone legitimate platforms such as CoinGDX or Binance. These fraudulent apps display highly realistic dashboards showing simulated profits. When the user attempts to withdraw funds, the app blocks the transaction and demands arbitrary "customs clearance fees," continuing to extract payments until the victim stops. [10]

3.4 Deepfakes and AI-Enabled Scams

Scammers use manipulated videos of trusted business figures, government officials, or celebrities to promote fraudulent cryptocurrency tokens. Victims who trust these videos click embedded links leading to malicious pages designed to compromise their accounts. Deepfakes AI-generated videos produced using advanced machine-learning models have become an increasingly active tool for financial fraud and misinformation in India.[11] Verifying the source of any video or news item before trusting it is therefore essential.

3.5 Job and Work-from-Home Scams

Part-time job and work-from-home scams represent one of the fastest-growing categories of cybercrime in India. Scammers offer victims simple tasks such as typing, proofreading, or data entry; once the work is completed, they claim a "formatting error" occurred and demand fees for software activation or tax clearance, or threaten legal action. A related variant involves fake online shopping platforms that ask victims to "rate products" by depositing their own money into a wallet, promising the return of capital plus a 15% commission. While the wallet balance appears to grow rapidly, any attempt at withdrawal is permanently blocked.[12]

These represent only some of the many methods used by attackers to defraud individuals. Vigilance and adherence to government guidelines remain essential to countering these threats.

4. Impact of Cyber Fraud

Cyber fraud inflicts harm on both individual victims and society at large. Its principal effects are outlined below.

4.1 Financial Loss

Victims face immediate financial loss through drained bank accounts, stolen cryptocurrency assets, and fraudulent loan liabilities, resulting in significant mental and social distress. As monetary gain is the primary motive behind most cyber fraud, individuals are strongly advised never to share OTPs, Aadhaar numbers, PAN numbers, or bank details with unknown callers or via email; such credentials should be shared only with trusted, authorised government agencies. [13]

4.2 Identity Theft

Identity theft occurs when personal identifiable information is stolen to commit financial fraud. Unlike a stolen credit card or UPI PIN, which can be blocked and replaced, core identity markers such as PAN, Aadhaar number, and biometric data cannot be easily changed. Once compromised, this information may remain permanently exposed on the dark web, stripping the victim of legal autonomy and potentially barring access to future loans or credit facilities. [14]

4.3 Emotional and Psychological Effects

Victims frequently develop a persistent fear of technology, with emotional and psychological effects that can last a lifetime. Beyond financial loss, victims often struggle to resume normal digital interaction, experiencing feelings of helplessness and isolation. For many, this emotional trauma proves more difficult to overcome than the monetary loss itself, underscoring the need for greater support structures for victims of cybercrime. [15]

5. Legal Framework Governing Cybercrime in India

India has a well-defined legal framework to address cyber fraud and online scams, consisting of statutory provisions, regulatory bodies, and procedural mechanisms.

5.1 Information Technology Act, 2000

The Information Technology Act, 2000 (IT Act) is the primary legislation governing cybercrime in India. It was enacted to provide legal recognition to electronic transactions and to penalise offences committed through digital means. [16] Key provisions relevant to online scams include:

  • Section 66C: Punishes identity theft by using another person's electronic signature, password, or other unique identification feature.

  • Section 66D: Penalises cheating by personation using computer resources, which directly covers phishing and impersonation scams.

  • Section 66B: Deals with dishonestly receiving stolen computer resources or communication devices.

  • Section 43: Provides for compensation for unauthorised access to computer systems and data theft.

The IT Act also establishes the Indian Computer Emergency Response Team (CERT-In) as the national agency for coordinating cyber-security responses and issuing safety advisories.[17]

5.2 Allied Policy Measures and Reporting Mechanisms

The National Cybercrime Reporting Portal (cybercrime.gov.in) allows citizens to report online fraud instantly. The government has also established the 1930 national helpline for immediate assistance in blocking financial transactions.[18] Additionally, the Reserve Bank of India (RBI) regularly issues circulars on safe digital banking practices, and the Ministry of Electronics and Information Technology (MeitY) has issued advisories against deepfakes and misleading AI-generated content.[19]

6. How to Stay Safe Digitally

Prevention remains the most effective safeguard against cyber fraud. Vigilance at the individual level, if widely practised, can meaningfully reduce the national incidence of cybercrime. Recommended measures include:

  • Use strong, unique passwords  avoid simple sequences such as "123456" and instead use passwords with special characters.

  • Enable two-factor authentication  layered security measures make it significantly harder for scammers to access a device.

  • Never share OTPs or passwords  such credentials should never be disclosed to unknown callers, including anyone claiming to represent a bank or government agency; suspicious numbers should be reported.

  • Verify links before clicking unknown or suspicious links should never be opened; always check a URL before visiting a site.

  • Download apps only from trusted sources avoid installing applications from unverified websites.

  • Keep software updated regular updates help prevent malware and virus attacks.

  • Avoid public Wi-Fi for banking public networks at stations or shopping areas can expose devices to security risks; use trusted networks instead.

  • Monitor bank statements regularly routine checks help detect unauthorised deductions promptly.

Taking these simple precautions can make a substantial difference in preventing cyber fraud.

7. What to Do If You Become a Victim

Adherence to the safety measures outlined above remains the first line of defence. However, should an individual fall victim to cyber fraud, remaining calm and following the steps below can help mitigate the damage.

  • Immediately contact your bank request that the payment or transaction be stopped without delay to prevent further financial loss.

  • Report the fraud on the National Cybercrime Reporting Portal, or by calling the national helpline number 1930, which operates across all States and Union Territories.

  • Preserve screenshots and transaction details such records serve as crucial evidence during investigation.[20]

8. Challenges in Combating Cybercrime

8.1 Lack of Public Awareness

Many people remain digitally illiterate about the risks of cyber fraud and unfamiliar with the evolving tactics used by scammers. This gap in knowledge benefits attackers, who exploit public unfamiliarity with technology. Expanding digital literacy is therefore essential to reducing cybercrime.

8.2 Cross-Border Cybercriminals

A substantial share of cybercrime in India involves international criminal networks, which are difficult for domestic law-enforcement agencies to trace. Strengthened international cooperation and regulation are needed to address this cross-border dimension effectively.

8.3 Rapidly Evolving Technology

The continual advancement of technology poses an ongoing challenge for law enforcement. Cybercriminals regularly develop new methods of deception, and gaps in India's technological capacity make it difficult for authorities to keep pace.

8.4 Low Reporting Rates

The true scale of cybercrime remains unknown, as only a small fraction of incidents are formally reported, reflecting public fear and a lack of trust in government agencies. Without accurate data on the scope of the problem, it becomes considerably more difficult for investigative agencies to respond effectively. Encouraging greater reporting through accessible portals is therefore a critical policy priority.

9. Conclusion

Cybercrime represents an evolving and increasingly urgent reality that demands coordinated regulatory attention. Sustained action, comprising stronger legal enforcement, expanded public awareness, and responsible technological innovation, can substantially reduce the incidence and impact of cyber fraud. Taken together, the right combination of individual vigilance and institutional reform offers a realistic path toward a safer digital society.

No single stakeholder can address this challenge alone. Government bodies, financial institutions, technology companies, and citizens must work in tandem, sharing responsibility for prevention, detection, and response. As digital adoption continues to deepen across India, cybersecurity can no longer be treated as an afterthought but must be embedded into the design of every digital product and public service from the outset.

Ultimately, the fight against cyber fraud is not a one-time effort but a continuous process that must evolve alongside the very technologies it seeks to safeguard. With sustained commitment, timely policy reform, and an informed citizenry, India can steadily move toward a digital environment where trust, rather than fear, defines the everyday online experience.

REFERENCE

[1]: *Black’s Law Dictionary*, 11th ed. (2019) defines cybercrime broadly as criminal activity carried out using computers or the internet.

[2]: *The Hindu*, "Cyber Fraud Cases in India: Trends and Analysis," 2024 (reporting a sharp year-on-year increase in digital fraud complaints).

[3]: Ministry of Electronics and Information Technology (MeitY), *Annual Report 2023-24*, noting India’s rapid digital adoption and rising cyber threats.

[4]: U.S. Federal Trade Commission (FTC), *Consumer Protection Data Spotlight: Social Media Fraud Report* (2023), finding that 1 in 4 fraud victims identified social media as the scam’s starting point.

[5]: CERT-In, *Security Guidelines for Users* (2023), highlighting weak password practices among young internet users.

[6]: National Crime Records Bureau (NCRB), *Crime in India – 2022*, Chapter on Cybercrimes, noting emotional exploitation as a primary modus operandi.

[7]: UNODC, *Cybercrime and the Digital Economy Report* (2023), discussing technological vulnerabilities and regulatory gaps in developing economies.

[8]: Section 66D, Information Technology Act, 2000 (punishing cheating by personation using computer resources).

[9]: Reserve Bank of India (RBI), *Master Circular on Digital Payment Security*, 2023, advising customers to never share UPI PINs or OTPs.

[10]: RBI, *Public Alert on Unauthorised Investment Apps*, 2024, warning against fraudulent cryptocurrency platforms.

[11]: MeitY, *Advisory on Deepfakes and Misinformation*, November 2023, calling for verification of AI-generated content.

[12]: National Cybercrime Reporting Portal, *Common Scam Patterns* (2024), listing job fraud and task-based scams as major categories.

[13]: Section 66C, Information Technology Act, 2000 (identity theft), read with the Aadhaar (Targeted Delivery of Financial and Other Subsidies) Act, 2016.

[14]: Data Security Council of India (DSCI), *Cyber Fraud Impact Study* (2023), on the irreversibility of compromised biometric and PAN data.

[15]: World Health Organization, *Mental Health and Digital Crime* (2022), discussing long-term psychological trauma among cybercrime victims.

[16]: Information Technology Act, 2000, Preamble and Section 1.

[17]: Section 70B, Information Technology Act, 2000 (establishment of CERT-In).

[18]: Ministry of Home Affairs, *National Cybercrime Reporting Portal User Guide*, 2024, detailing the 1930 helpline.

[19]: MeitY, *Advisory on Responsible AI and Deepfake Detection*, 2024.

[20]: Standard operating procedure prescribed by the National Cybercrime Reporting Portal for victims.

Himanshi Jangra, Ballb ,3 year, Maharaja Surajmal Institute, Delhi 26 August 2026
Share this post
Category
Sign in to leave a comment