💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • How safe is India’s critical national infrastructure

    Why in the News?

    India’s critical infrastructure security has come into focus amid rising concerns over cyber threats targeting IoT-enabled systems used in energy, transport, communications and industrial networks. Recently, there were warnings from India’s National Cyber Security Coordinator that highlight that traditional cyber defences are no longer adequate against increasingly sophisticated attacks on critical systems.

    What Constitutes Critical Infrastructure in India?

    Critical Information Infrastructure (CII): Systems whose incapacitation can severely impact national security, economy, public health or safety.

    Major Sectors

    1. Energy: Power grids, oil and gas networks.
    2. Transport: Railways, airports, ports and highways.
    3. Telecommunications: Internet backbone and communication networks.
    4. Banking & Finance: Payment systems and financial infrastructure.
    5. Healthcare: Hospital networks and medical databases.
    6. Strategic Systems: Defence, satellites and emergency services

    Why has digital transformation increased vulnerabilities in critical infrastructure?

    1. Digital Integration: Connects traditionally isolated infrastructure systems with internet-enabled networks, increasing exposure to cyber risks. Earlier, local control systems operated independently; today they function through networked environments.
    2. Automation Expansion: Enables predictive maintenance, remote monitoring and optimisation across power plants, chemical industries, transport systems and refineries. Greater connectivity, however, increases the possibility of remote compromise.
    3. IoT Proliferation: Expands attack surfaces through connected devices such as cameras, GPS systems, industrial controllers, water-level sensors and smart monitors that continuously exchange data.
    4. Systemic Dependence: Creates cascading risks because disruption in one sector may trigger failures across supply chains, communication networks and essential services.
    5. National Security Exposure: Converts technical vulnerabilities into strategic risks as attacks on infrastructure can disrupt economic stability and public order.

    How has the convergence of IT, OT and IoT transformed security risks?

    1. Information Technology (IT): Processes and stores digital data through servers, cloud systems and computational networks.
    2. Operational Technology (OT): Controls physical systems such as industrial machinery, transport systems and manufacturing plants.
    3. IoT Connectivity: Integrates physical infrastructure with digital control systems using sensors, controllers and automated devices.
    4. Control Vulnerability: Allows compromised IoT systems to manipulate physical operations. Breached devices may alter industrial controls or operational parameters.
    5. Invisible Threats: Creates hidden security risks through malicious firmware, embedded control pathways or hardware-level vulnerabilities.
    6. Trojan Risks: Enables insertion of concealed vulnerabilities that remain dormant but can later disrupt systems or facilitate surveillance.

    Why are conventional cybersecurity measures insufficient for critical infrastructure?

    1. Limited Scope: Cybersecurity measures such as server protection, anti-virus systems and breach prevention primarily secure digital layers but may not protect embedded physical systems.
    2. Physical-Digital Interdependence: Requires security frameworks that protect not only software but also hardware, sensors and communication pathways.
    3. Critical Infrastructure Sensitivity: Demands higher scrutiny because disruption may directly affect public safety and strategic operations.
    4. Procurement Gaps: Weak tender conditions often fail to prioritise trusted products or deep security evaluation.
    5. Compliance Weakness: Eligibility assessments frequently focus on paperwork rather than hardware authenticity, origin verification and operational vulnerability.
    6. Institutional Enforcement Deficit: Existing IT and IoT guidelines remain inadequately enforced for national-level infrastructure.

    Examples 

    1. SCADA Systems: Earlier local process control systems managed industrial operations through Supervisory Control and Data Acquisition systems; today many are internet-connected.
    2. CERT-In: Strengthens cyber response capacity through incident monitoring and emergency response protocols but does not fully secure infrastructure hardware.

    How do procurement and certification weaknesses create national security risks?

    1. Trusted Procurement Deficit: Allows deployment of imported systems without rigorous security verification.
    2. Security Evaluation Gaps: Weak scrutiny of design origin, manufacturing authenticity and operational vulnerabilities increases risk of embedded backdoors.
    3. Certification Challenges: Existing testing procedures remain lengthy and unevenly enforced across infrastructure sectors.
    4. Imported Device Risk: Raises concern over GPS-enabled electronic locks and communication systems manufactured abroad but deployed in sensitive supply chains.
    5. False Certification Concerns: Creates risks when imported products receive domestic certification despite unresolved security questions.

    Example 

    1. STQC Certification: Recent certification of cameras by Standardisation Testing and Quality Certification (STQC) ensures devices do not perform unintended control or data-sharing functions. However, certification remains time-consuming and inconsistently applied across IoT devices.

    Why is fuel transportation emerging as a major infrastructure vulnerability?

    1. Fuel Supply Digitisation: Integrates tankers with GPS tracking, digital monitoring and IoT-enabled electronic locking systems.
    2. Operational Dependence: Makes petroleum logistics increasingly dependent on remote communication technologies.
    3. Remote Disruption Risk: Creates vulnerability if vehicle tracking systems or e-locks are imported, compromised or improperly certified.
    4. Supply Chain Exposure: Enables interference with fuel distribution systems, affecting energy security and economic continuity.

    Example 

    1. Petroleum Tankers: Earlier protected through seals, locks and keys; now increasingly dependent on IoT-based keyless systems and GPS-enabled monitoring.
    2. Recent U.S. Case: A cyberattack on fuel storage systems reported by CNN demonstrates how attacks on energy systems can disrupt supply chains.

    How can India strengthen critical infrastructure resilience?

    1. Trusted Technology Ecosystem: Prioritises secure and trusted domestic technologies for sensitive sectors.
    2. Certification Enforcement: Ensures rigorous security testing for IoT devices deployed in national infrastructure.
    3. Supply Chain Security: Strengthens scrutiny of hardware origin, firmware integrity and manufacturing authenticity.
    4. Cyber-Physical Security Framework: Integrates IT, OT and IoT protection rather than treating cybersecurity as a software issue alone.
    5. Awareness Generation: Encourages industrial users, utilities and government agencies to recognise cyber risks in connected systems.
    6. Continuous Vigilance: Supports real-time monitoring and regular security audits of infrastructure networks.

    Conclusion

    India’s critical infrastructure is undergoing rapid digital transformation through automation, IoT and AI, improving efficiency and service delivery across sectors. However, increasing interconnection between digital and physical systems has also expanded vulnerabilities to cyberattacks, supply-chain risks and remote disruptions. In an era of connected systems, infrastructure resilience has become inseparable from national security and economic stability.

    PYQ Relevance

    [UPSC 2022] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

    Linkage: The PYQ tests understanding of cyber security architecture, vulnerabilities and institutional preparedness in India’s digital ecosystem. The article expands the cyber security debate beyond data protection to critical infrastructure protection.

  • [23rd May 2026] The Hindu OpED: Cyber warfare is outpacing gloabl legal accountability

    PYQ Relevance[UPSC 2023] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.Linkage: The PYQ directly connects with the article’s themes of cyber threats, legal gaps, attribution challenges, and cyber governance. It helps in linking cyber warfare with India’s preparedness, cyber norms, and accountability mechanisms in internal and international security.

    Mentor’s Comment

    The recent Israel-Iran conflict showed that wars are no longer fought only with missiles and soldiers. Along with military attacks, cyberattacks were reportedly used to disrupt websites, communication systems, and digital networks. This has highlighted a growing problem: while cyber warfare is becoming faster and more dangerous, international laws are struggling to hold countries or groups accountable. This is mainly because it is difficult to identify who carried out the attack and prove responsibility.

    Why is cyber warfare increasingly becoming an instrument of modern conflict?

    1. Hybrid Warfare: Combines cyber operations with conventional military action to weaken communication systems, influence public narratives, and disrupt defence preparedness. Recent Israel-Iran tensions reflected simultaneous cyber disruptions alongside kinetic strikes.
    2. Strategic Disruption: Enables attacks on websites, digital services, and information ecosystems without immediate physical confrontation, reducing costs of escalation.
    3. Military Utility: Supports conventional military campaigns through disruption of command-and-control systems, logistics, and surveillance capabilities before physical attacks.
    4. Non-State Participation: Expands battlefield actors beyond states. The pro-Iranian Handala Hack Team reportedly claimed cyberattacks on entities, including a U.S.-based medical technology company.
    5. Low-Cost Asymmetry: Allows weaker actors to impose disproportionate costs on technologically advanced states through malware, ransomware, or infrastructure sabotage.

    Why is establishing legal accountability in cyber warfare so difficult?

    1. Threshold Ambiguity: International law prohibits the use of force under Article 2(4) of the UN Charter, but determining when cyber operations amount to “use of force” remains contested.
    2. Classification Problem: Distinguishing between cyber espionage, cybercrime, sabotage, and armed attack remains legally unclear, complicating state responsibility.
    3. Attribution Challenge: Cyber operations are covert by nature. Attackers frequently conceal origins through proxy servers, spoofing, and third-party infrastructure, making definitive attribution difficult.
    4. State Responsibility Gap: International law requires attribution of conduct to a state for legal responsibility. Technical suspicion often fails to meet evidentiary thresholds admissible before courts.
    5. Uncertain Harm Assessment: Difficulty in proving direct causation between cyber operations and measurable physical or economic harm weakens accountability.
    6. Example: Cyberattacks targeting critical infrastructure may create large-scale disruption, yet legal consequences remain limited if attribution cannot be conclusively established.

    How do limitations of international law weaken cyber accountability?

    1. Legal Applicability: Existing principles of sovereignty, non-intervention, and prohibition of force theoretically apply to cyberspace.
    2. Enforcement Deficit: International legal frameworks rarely produce prosecutions or compensation despite growing cyber incidents.
    3. Doctrinal Mismatch: Traditional legal frameworks were developed for geographically identifiable and physically attributable conflict, unlike decentralized cyber operations.
    4. Absence of Consensus: States disagree on what constitutes armed attack, proportionality, and lawful retaliation in cyberspace.
    5. Normative Fragmentation: Different national interpretations prevent development of universally accepted cyber rules.
    6. Example: A cyberattack disrupting electricity or healthcare systems may create severe consequences but still fall into a legal grey zone below the threshold of armed conflict.

    Why do attribution and evidence create major barriers to litigation?

    1. Secrecy of Operations: Cyber incidents frequently involve classified intelligence, covert capabilities, and anonymous actors.
    2. Evidentiary Constraints: Technical evidence often remains insufficient for legal admissibility in courts.
    3. Causation Complexity: Courts face difficulties in establishing who conducted the operation, the extent of damage caused, and links to specific harm.
    4. Sensitive Information Risks: Litigation may require disclosure of intelligence capabilities, creating national security concerns.
    5. Escalation Risks: States often avoid formal legal proceedings to prevent diplomatic retaliation or military escalation.
    6. Example: Even where intelligence agencies possess strong suspicions, states may avoid public attribution due to inability to disclose classified evidence.

    Why are international legal forums inadequate for cyber disputes?

    1. Jurisdictional Limitations: The International Court of Justice (ICJ) requires state consent, limiting compulsory dispute settlement.
    2. Sovereign Immunity: Foreign states often enjoy immunity protections in domestic courts.
    3. Institutional Deficit: No dedicated global tribunal exists for cyber conflict resolution.
    4. Cross-Border Complexity: Cyber operations transcend territorial boundaries, complicating jurisdiction.
    5. Limited Legal Remedies: Victims struggle to secure reparations, injunctions, or punitive action.
    6. Example: Domestic courts face obstacles when foreign-state actors conduct cyber intrusions through multiple jurisdictions.

    How are international institutions attempting to regulate cyberspace?

    1. Budapest Convention on Cybercrime: Establishes international cooperation mechanisms against cybercrime and digital evidence sharing. However, focus remains primarily on criminal enforcement rather than state cyber warfare.
    2. UN Convention against Cybercrime: Expands global legal cooperation to address emerging cyber threats.
    3. UN Framework Discussions: Ongoing deliberations seek responsible state behaviour, accountability norms, and confidence-building measures in cyberspace.
    4. Norm Development: Attempts to define acceptable conduct, critical infrastructure protection, and proportional responses.
    5. Implementation Gap: Enforcement mechanisms remain weak despite institutional developments.

    Why must India actively shape emerging cyber norms?

    1. Digital Dependence: India increasingly relies on digital infrastructure across finance, governance, energy, healthcare, and defence.
    2. Strategic Vulnerability: Greater digitisation increases exposure to cyber espionage, infrastructure disruption, and information warfare.
    3. Normative Leadership: India can influence evolving global cyber governance frameworks through multilateral diplomacy.
    4. Institutional Participation: Active engagement in accountability, attribution standards, and responsible state behaviour strengthens India’s strategic interests.
    5. Cyber Preparedness: Enhances resilience of critical information infrastructure and national security architecture.
    6. Example: India’s expanding digital public infrastructure, including UPI and Aadhaar-linked systems, requires stronger cyber resilience frameworks.

    Conclusion

    Cyber warfare is growing faster than global laws can handle. It is difficult to identify attackers and prove responsibility. Existing legal systems are not fully prepared for digital conflicts. Countries, including India, must strengthen cyber security and help build stronger global cyber rules.

    International Legal Frameworks Relevant to Cyber Warfare

    1. Tallinn Manual 2.0: Non-binding academic interpretation of how international law applies to cyber operations and cyber warfare.
    2. Article 2(4), UN Charter: Prohibits threat or use of force against territorial integrity or political independence of states.
    3. Due Diligence Principle: The concept was solidified by the International Court of Justice (ICJ) in the landmark 1949 Corfu Channel Case, which ruled that a state cannot knowingly allow its territory to be used for acts contrary to the rights of other states.
    4. Principle of Sovereignty: Recognises cyber intrusions into critical systems as possible violations of territorial sovereignty. It is anchored in the UN Charter (1945) under Article 2(1), which declares the sovereign equality of all member nations.
    5. Law of Armed Conflict (LOAC): Governs proportionality, distinction, and military necessity in cyber-enabled warfare. It is heavily codified under the Geneva Conventions of 1949 and their Additional Protocols (1977), as well as the Hague Conventions. It is also known as International Humanitarian Law (IHL).

    India’s Cyber Institutional Architecture

    • CERT-In: Coordinates cyber incident response and vulnerability management.
    • National Critical Information Infrastructure Protection Centre (NCIIPC): Protects critical sectors including banking, telecom, power, and transport.
    • National Cyber Security Policy: Strengthens resilience, skill development, and institutional coordination.
    • Indian Cyber Crime Coordination Centre (I4C): Supports cybercrime prevention and inter-agency cooperation.
  • Crypto Rules Tightened: Live Selfies and Geo Tagging Mandatory for Users

    Why in the News

    India’s Financial Intelligence Unit has rolled out stringent Anti Money Laundering and Know Your Customer norms for cryptocurrency exchanges, making live selfie verification and geographical tracking compulsory during user onboarding under guidelines issued on 8 January 2026.

    Regulatory Framework

    • Crypto exchanges classified as Virtual Digital Asset service providers
    • Covered as Reporting Entities under the Prevention of Money Laundering Act
    • FIU designated as the single point regulator for crypto exchanges in India

    New Mandatory KYC Requirements

    Live Selfie Verification

    • Capture of live photograph
    • Liveliness detection using eye blinking or head movement
    • Prevents use of static images and deepfakes
    • Confirms physical presence of the user

    Geo Tagging and Technical Data

    • Mandatory capture of
      • Latitude and longitude
      • Date and timestamp
      • IP address of onboarding location

    Penny Drop Verification

    • Re 1 bank transaction
    • Confirms bank account ownership and activity

    Identity and Authentication

    • Permanent Account Number compulsory
    • One additional identity document
      • Aadhaar
      • Passport
      • Voter ID
    • OTP verification of mobile number and email ID
    [2020] With reference to “Blockchain Technology” consider the following statements: 

    1. It is a public ledger that everyone can inspect, but which no single user controls

    2. The structure and design of blockchain is such that all the data in it are about cryptocurrency only

    3. Applications that depend on basic features of blockchain can be developed without anybody’s permission. 

    Which of the statements given above is/are correct? 

    (a) 1 only (b) 1 and 2 only (c) 2 only (d) 1 and 3 only

  • [8th Jaunary 2026] The Hindu OpED: Natgrid, the search engine of digital authoritarianism

    PYQ Relevance

    [UPSC 2023] What are the internal security challenges being faced by India? Give out the role of Central Intelligence and Investigative Agencies tasked to counter such threats.

    Linkage: NATGRID represents the technological backbone of intelligence coordination among central agencies. The question allows analysis of how intelligence reforms post-26/11 rely increasingly on data integration, while raising concerns of accountability and oversight.

    Mentor’s Comment

    This article examines the transformation of India’s intelligence architecture through the National Intelligence Grid (NATGRID). It evaluates how a system conceived after the 26/11 terror attacks for intelligence coordination is evolving into a large-scale, algorithm-driven surveillance infrastructure. The piece raises constitutional, institutional, and ethical concerns relevant to internal security, governance, civil liberties, and democratic accountability.

    Introduction

    Conceived as a technological “crown jewel,” NATGRID aimed to enable seamless intelligence coordination. However, its evolution from a post-crisis intelligence grid into a population-wide surveillance architecture marks a fundamental shift in India’s security-liberty balance.

    Why in the News?

    NATGRID has re-emerged as a major policy concern due to recent reports highlighting its expanded operationalisation, widening user base, and integration with the National Population Register (NPR). Intelligence access has shifted from post-event investigation to real-time, algorithmic risk assessment. The scale is unprecedented, around 45,000 queries per month, extended to state police officers down to the Superintendent of Police rank, marking a sharp departure from earlier centralised intelligence control. This expansion occurs without a statutory framework or independent oversight, raising fears of institutionalised mass surveillance and digital authoritarianism.

    Why did NATGRID emerge after 26/11?

    1. Intelligence Fragmentation: Identified failure to synthesise scattered inputs such as visa records, travel itineraries, hotel stays, and financial trails related to David Headley.
    2. Post-Crisis Imperative: Positioned as a technological fix to prevent future terror attacks through real-time data aggregation.
    3. Institutional Expansion: Envisioned as middleware enabling 11 central agencies to query databases across 21 categories, spanning identity, travel, telecom, finance, and assets.

    How did NATGRID evolve institutionally?

    1. Administrative Clearance: Operationalised through executive decisions rather than Parliamentary legislation.
    2. Delayed Rollout: Long gestation period led to perceptions of “vapourware” until post-2020 acceleration.
    3. Operational Activation: Publicly announced in 2009; cleared in 2012 without statutory safeguards; rebranded under Mission Mode Project “Horizon.”

    What scale of intelligence access does NATGRID now enable?

    1. Query Volume: Handles approximately 45,000 intelligence queries per month.
    2. User Expansion: Access widened beyond central agencies to state police officers up to SP rank.
    3. Routine Policing Shift: Intelligence access integrated into everyday law enforcement rather than exceptional counter-terror operations.

    Why does integration with NPR mark a structural break?

    1. Population Mapping: NPR data includes demographic, biometric, residential, lineage, and identity details.
    2. Function Creep: Converts a population register into an intelligence query platform.
    3. Paradigm Shift: Moves intelligence from tracking discrete events to continuous surveillance of individuals.
    4. Political Sensitivity: NPR’s linkage with NRC debates amplifies concerns of profiling and citizenship filtering.

    How does algorithmic policing change the nature of surveillance?

    1. Entity Resolution: Deployment of “Gandiva,” an analytics engine capable of linking fragmented datasets to identify individuals.
    2. Predictive Risk Assessment: Uses facial recognition, KYC databases, and driving licence records.
    3. Inference at Scale: Algorithms determine intent based on pattern recognition rather than human judgment.
    4. Bias Amplification: Existing social biases embedded in data risk reinforcing caste, religious, and geographic profiling.

    Why is lack of oversight a central concern?

    1. Absence of Statute: No dedicated law governing scope, limits, or accountability of NATGRID.
    2. Judicial Gap: Legality of large-scale intelligence surveillance remains unadjudicated despite pending cases.
    3. Clerical Overload: Tens of thousands of monthly requests undermine meaningful scrutiny.
    4. Autonomous Surveillance: Weak Parliamentary oversight allows self-justifying intelligence architectures.

    Why does the argument of “intelligence necessity” fall short?

    1. Operational Failures: 26/11 highlighted deficits in training and ground-level policing, not data scarcity.
    2. Over-Reliance on Technology: Intelligence failures often stem from institutional silos, not lack of databases.
    3. False Positives Risk: Automated “hits” can trigger irreversible harm without due process.
    4. Learning Deficit: Local police lacked firearm training during 26/11 despite intelligence availability.

    What constitutional values are at stake?

    1. Privacy Erosion: Expansive surveillance contradicts proportionality standards laid down in privacy jurisprudence.
    2. Due Process Deficit: Automated suspicion undermines presumption of innocence.
    3. Chilling Effect: Normalisation of surveillance reshapes citizen-state relations.
    4. Judicial Precedent: Reliance on Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) contrasts with unchecked surveillance growth.

    Conclusion

    NATGRID reflects a decisive shift in India’s internal security architecture from intelligence coordination to continuous, technology-driven surveillance. While conceived to prevent failures like 26/11, its expansion in scale, scope, and access, without a clear statutory framework or independent oversight, raises fundamental concerns about privacy, proportionality, and democratic accountability. Intelligence systems that rely on algorithmic inference and population-wide data integration risk normalising suspicion and eroding constitutional safeguards. Effective counter-terrorism requires not only technological capability but also institutional accountability, legal clarity, and professional capacity-building. Without these correctives, NATGRID risks functioning less as a preventive security instrument and more as an enduring infrastructure of digital authoritarianism.

  • Financial Fraud Risk Indicator (FRI)

    Why in the News?

    The Department of Telecommunications has reported that the Financial Fraud Risk Indicator (FRI) has prevented potential losses of about ₹660 crore across the banking ecosystem within six months of its rollout.

    What is Financial Fraud Risk Indicator (FRI)?

    • A risk based early warning system to detect financial fraud
    • Launched in May 2025
    • Developed by the Digital Intelligence Unit
    • Classifies mobile numbers based on likelihood of financial fraud

    Risk Categories Under FRI

    • Medium Risk
    • High Risk
    • Very High Risk

    Data Sources Used for Classification

    Indian Cybercrime Coordination Centre via National Cybercrime Reporting Portal
    • DoT’s Chakshu platform
    • Intelligence shared by banks and financial institutions

    How FRI Works

    • Suspected mobile number is flagged by any stakeholder
    • Number undergoes multidimensional risk analysis
    • Classified into Medium, High, or Very High fraud risk
    • Risk status shared instantly with stakeholders through DoT’s Digital Intelligence Platform (DIP)

    Role of Mobile Number Revocation List (MNRL)

    • Issued regularly by DoT’s Digital Intelligence Unit
    • Contains numbers disconnected due to:
    • Cybercrime involvement
    • Failed verification
    • Exceeding permissible usage limits
    • Such numbers are frequently reused for financial fraud

    Why FRI is Effective?

    • Fraudulent numbers are often short lived
    • Traditional verification takes time
    • FRI provides preemptive risk signalling before losses occur

    Use by Banks and Financial Institutions

    • Decline suspicious transactions
    • Delay high risk transactions
    • Send alerts and warnings to customers
    • Strengthen UPI and digital payment security

    Prelims Pointers

    • FRI is a preventive tool, not a law enforcement mechanism
    • Operates in real time
    • Enhances coordination between telecom and financial sectors
    • Supports secure digital payments ecosystem

    Which of the following is a most likely consequence of implementing the ‘Unified Payments Interface (UPI)’? (2017)

    (a) Mobile wallets will not be necessary for online payments

    (b) Digital currency will totally replace physical currency

    (c) FDI inflows will drastically increase

    (d) Direct transfer of subsidies… will become very effective.

  • GhostPairing Cyber Attack

    Why in the News?

    The Indian Computer Emergency Response Team has issued an advisory warning WhatsApp users about a new cyber attack technique called GhostPairing.

    What is GhostPairing?

    • GhostPairing is a WhatsApp account takeover attack
    • Hackers secretly link their own device to a victim’s WhatsApp account
    • No password theft or SIM swap is required
    • Victim often remains unaware of the compromise
    • Gives attackers near complete access to chats and data

    How GhostPairing Works (Modus Operandi)?

    • Victim receives a message from a trusted contact saying “Hi, check this photo”
    • Message contains a malicious link with Facebook style preview
    • Link opens a fake Facebook photo viewer
    • User is prompted to “verify” to view content
    • Victim enters phone number and pairing code
    • Attackers use the code to link their device
    • Full WhatsApp access is granted to attackers

    Advisory and Preventive Measures

    • Do not click suspicious links even from known contacts
    • Never share WhatsApp verification or pairing codes
    • Regularly check Linked Devices in WhatsApp settings
    • Enable two step verification
    • Log out unknown linked devices immediately

    Prelims Pointers

    • GhostPairing exploits human trust, not software vulnerability
    • Uses social engineering and fake web interfaces
    • CERT In is the nodal agency for cyber security advisories in India
    • Linked device feature can be misused if verification codes are shared

    The terms ‘Wanna Cry, Petya and Eternal Blue’ sometimes mentioned in the news recently are related to: (2018)

    (a) Exo-planets 

    (b) Crypto-currency 

    (c) Cyber attacks 

    (d) Mini satellites

  • Compound effect: On digital arrest scams

    Introduction

    The Supreme Court of India’s recent directive for a comprehensive probe into proliferating digital scams underscores the scale and sophistication of cyber fraud plaguing Indian citizens. The Court’s focus on “digital arrest” scams, where criminals impersonate law enforcement officials to extort money highlights a disturbing transformation in global cybercrime: industrial-scale scam operations embedded in Southeast Asian conflict zones.

    Why in the News

    For the first time, the Supreme Court has intervened directly to address the globalised architecture of digital scams targeting Indian citizens. These scams run from “scam compounds” in Myanmar, Cambodia, and other parts of Southeast Asia combine human trafficking, digital slavery, and organised crime. Thousands of Indians have fallen victim, some trafficked to operate scams, others defrauded online. The situation represents both a national security concern and a humanitarian crisis, demanding urgent multilateral action.

    Understanding the ‘Scam Compound’ Phenomenon

    1. Industrial-scale operations: Scam compounds operate from conflict-ridden or special economic zones in Myanmar, Cambodia, and Laos, exploiting weak governance.
    2. Cross-border architecture: These are not isolated crimes but coordinated, transnational enterprises involving militias, private entities, and local regimes.
    3. Digital slavery model: Trafficked individuals are forced, under threat and torture, to perpetrate scams such as “digital arrest,” “pig butchering,” and crypto investment frauds.
    4. State complicity: In Myanmar, regime-backed Border Guard Forces allegedly facilitate these compounds, converting scams into revenue streams for military operations.

    KK Park Cyber Scam Hub in Myanmar

    How the Digital Scam Network Operates

    1. Recruitment through deception: Victims are lured by fake job ads in cities like Bangkok, offering attractive salaries under visa-free entry regimes.
    2. Trafficking & confinement: Once recruited, they are trafficked into border regions controlled by ethnic militias in Myanmar and held captive in “digital sweatshops.”
    3. Coercive work environment: Workers face violence, sexual harassment, and torture if they fail to meet scam targets.
    4. Key scam types:
      1. “Digital arrest scams” impersonation of law enforcement to extort money.
      2. “Pig butchering scams” combining online romance and crypto fraud.
    5. Crypto laundering networks: Proceeds are funneled via money mules and institutions like Cambodia’s Huione Pay, then converted into cryptocurrency to evade tracing.

    Why Southeast Asia Became the Epicentre

    1. Conflict & weak governance: Myanmar’s post-2021 coup turmoil has enabled militia-run economies.
    2. Borderland lawlessness: Regions under Border Guard Forces function beyond formal state oversight.
    3. Economic desperation: Regional instability and poverty create fertile recruitment grounds.
    4. Regime complicity: Militias tax scam centres to fund armed operations, sustaining a vicious cycle of profit and repression.

    India’s Dual Crisis

    1. Forced scam labour: Thousands of Indian citizens trafficked and enslaved in these compounds.
    2. Domestic victimisation: Thousands more in India fall prey to online frauds orchestrated by these same captives.
    3. Diplomatic and enforcement challenge: Tackling both victim rescue abroad and fraud prevention at home requires synchronised national and international coordination.

    Policy Imperatives and India’s Way Forward

    1. Public awareness campaigns: The Reserve Bank of India and Union Ministries must amplify citizen education about emerging digital fraud patterns.
    2. Cybercrime infrastructure: Strengthening cyber policing, digital forensics, and cross-border data sharing frameworks.
    3. Regional cooperation: Collaborate with China, Thailand, Vietnam, and affected ASEAN nations to forge joint task forces.
    4. Diplomatic pressure: Use bilateral and multilateral diplomacy to pressurise Myanmar’s junta and Cambodia’s regime to dismantle scam hubs.
    5. Global recognition: Mobilise the United Nations to classify this crisis as a modern manifestation of slavery needing urgent international intervention.

    Conclusion

    The proliferation of scam compounds across Southeast Asia exposes the dark underbelly of the global digital economy where technology meets trafficking. For India, the challenge is dual: protect citizens from victimisation and rescue those coerced into perpetration. This crisis demands that India integrate cyber security, diplomacy, and human rights enforcement under one coordinated regional framework.

    PYQ Relevance

    [UPSC 2021] Keeping in view India’s internal security, analyse the impact of cross-border cyber attacks. Also, discuss defensive measures against these sophisticated attacks.

    Linkage: This question directly relates to the rise of transnational scam compounds in Southeast Asia that exploit digital networks to target Indian citizens. It underscores the urgent need for coordinated international and domestic cyber defense frameworks.

  • KK Park Cyber Scam Hub in Myanmar

    Why in the News?

    Around 500 Indian nationals who escaped the KK Park cybercrime compound in Myawaddy township, southeastern Myanmar, are being rescued by the Government of India.

    KK Park Cyber Scam Hub in Myanmar

    About KK Park Cyber Scam Hub:

    • Location & Setting: Situated in Myawaddy township, Karen State, Myanmar, near the Thailand border; originally built (2019–2021) as a border trade zone, later transformed into a cybercrime and human trafficking hub.
    • Control & Operations: Managed by the Border Guard Force (BGF) under Saw Chit Thu, a junta-allied militia leader sanctioned by the U.S. Treasury.
    • Nature of Activities: Functions as a “scam city” employing thousands of trafficked workers for online fraud, crypto scams, and romance-investment schemes.
    • Human Trafficking: Victims are recruited via fake overseas job offers, then imprisoned, tortured, and forced to commit cybercrimes after passport confiscation.
    • Scale: At its peak, housed over 20,000 trafficked workers, generating billions annually through global online fraud networks.
    • Structure: Operated like a self-contained enclave with dormitories, shops, and armed security — preventing worker escape.

    Global Concern and UN Findings:

    • UN Reports:  Identified by the United Nations Office on Drugs and Crime (UNODC) and the Global Initiative Against Transnational Organized Crime (GI-TOC) as part of a network of cyber-scam compounds spanning Myanmar, Cambodia, and the Lao People’s Democratic Republic (Laos).
    • Economic Scale: The cyber-scam economy earns over USD 10 billion annually, victimising users in 110 countries.
    • Myanmar’s 2025 Raid: Seizure of 30 Starlink terminals was seen as a cosmetic crackdown, as ringleaders escaped beforehand.
    • UN Appeal: Calls for cross-border enforcement, crypto tracking, and victim rehabilitation, viewing scam hubs as a fusion of trafficking and transnational organised crime.

    How does it impact Indians?

    • Victimisation: India serves as both a source and target of such scams; hundreds trafficked to Myanmar and Cambodia under fake IT job offers.
    • Rescue Operations: Since 2022, over 1,600 Indians repatriated, including 500 from KK Park (2025); IAF rescued 283 stranded in Thailand earlier.
    • Cyber Threats: Rising crypto frauds, impersonation scams, and digital extortion targeting Indian citizens.
    • Government Response: EAM S. Jaishankar confirmed coordination for repatriation and stronger cyber-diplomacy engagement.
    • Policy Imperative: Highlights India’s need for international law enforcement cooperation, cybersecurity awareness, and anti-trafficking vigilance across Southeast Asia.
    [UPSC 2024] Consider the following statements:
    Statement-I: There is instability and worsening security situation in the Sahel region.
    Statement-II: There have been military takeovers/coups d’état in several countries of the Sahel region in the recent past.
    Which one of the following is correct in respect of the above statements?
    Options: (a) Both Statement-I and Statement-II are correct and Statement-II explains Statement-I *
    (b) Both Statement-I and Statement-II are correct, but Statement-II does not explain Statement-I
    (c) Statement-I is correct, but Statement-II is incorrect
    (d) Statement-I is incorrect, but Statement-II is correct

     

  • CERT-In makes Annual Cybersecurity Audit Mandatory for Companies

    Why in the News?

    The Indian Computer Emergency Response Team (CERT-In) has mandated annual third-party cybersecurity audits for both private and public-sector organisations operating digital infrastructure.

    Cybersecurity Directive: Key Highlights:

    • Annual third-party cyber audits are mandatory for all digital infrastructure.
    • Sectoral regulators may require more frequent checks based on risk.
    • Audits must be risk-based, domain-specific, and aligned with business context.

    About the Indian Computer Emergency Response Team (CERT-In):

    • Parent Ministry: Ministry of Electronics and Information Technology
    • Established: January 2004
    • Constituency: All entities operating in Indian cyberspace
    • Core Responsibilities:
      • Collect, analyse, and disseminate cybersecurity incident data
      • Forecast and alert about emerging cyber threats
      • Provide emergency response support to affected entities
      • Issue security guidelines, advisories, and best practices
    • International Role: Signs MoUs with other countries to:
      • Share real-time cyber threat intelligence
      • Collaborate on incident response and recovery
      • Exchange knowledge on global cybersecurity practices

    India’s Cybersecurity Ecosystem:

    • Institutional Framework:
      • National Critical Information Infrastructure Protection Centre (NCIIPC): Protects key sectors like telecom, banking, and power
      • National Cyber Coordination Centre (NCCC): Monitors real-time cyber threats across public and private domains
      • National Cyber Security Coordinator (NCSC): Ensures coordination across ministries and departments
      • Sector-Specific Response Teams (CSIRTs): For domains like finance (CSIRT-Fin), power (CSIRT-Power)
    • Legal and Policy Measures:
      • Information Technology Act, 2000: Core law for cybercrime and electronic governance
      • National Cyber Security Policy, 2013: Strategic vision for securing cyberspace
      • Digital Personal Data Protection Act, 2023: Ensures privacy, mandates breach reporting
      • Cyber Crisis Management Plan: Framework for cyber incident response in government agencies
    • Capacity Building Programs:
      • Pradhan Mantri Gramin Digital Saksharta Abhiyan (PMGDISHA): Promotes digital literacy in rural areas
      • Cyber Surakshit Bharat Initiative: Trains Chief Information Security Officers of public sector organisations
      • Indian Cyber Crime Coordination Centre (I4C): Multi-agency platform to handle cybercrimes
    [UPSC 2017] In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data Centres 3. Body corporate Select the correct answer using the code given below:

    Options: (a) 1 only (b) 1 and 2 only (c) 3 only (d) 1, 2 and 3*

     

  • E-Zero FIR to speed up action on Cyber Frauds

    Why in the News?

    The Ministry of Home Affairs (MHA) has launched a pilot project for the e-Zero FIR (First Information Report) system in Delhi to help police take faster action in high-value cyber financial frauds.

    What is Zero FIR?

    • Purpose: Zero FIR allows any police station to register an FIR for a cognisable offence without assigning a regular FIR number initially.
    • No diary: Whereas FIRs have serial numbers assigned to them, zero FIRs are assigned the number ‘0’. Hence the name.

    About the e-Zero FIR System:

    • Launch and Objective: The MHA has launched a pilot e-Zero FIR project in Delhi to speed up action in cyber financial frauds over ₹10 lakh.
    • System Developer: It has been developed by the Indian Cybercrime Coordination Centre (I4C) under the MHA.
    • How It Works: Victims can file complaints via the National Cybercrime Reporting Portal (NCRP) or by calling the 1930 helpline.
    • FIR Process: The e-Crime Police Station in Delhi registers the FIR digitally, which is then transferred electronically to the correct local police station.
    • Legal Basis: The project is implemented under Section 173(1) and 173(1)(ii) of the Bharatiya Nagrik Suraksha Sanhita (BNSS), 2023.
    • Jurisdiction-Free Filing: Victims can report crimes without worrying about police station limits.
    • Digital Integration: The system connects the I4C’s NCRP, Delhi Police’s e-FIR portal, and NCRB’s CCTNS platform.

    Key Features and Victim Support:

    • Automatic Registration: FIRs are automatically registered for cyber frauds involving over ₹10 lakh.
    • Anywhere Access: Victims can file from any location, ensuring jurisdiction-free access.
    • Fast FIR Transfer: FIRs are sent electronically to the appropriate police station for follow-up.
    • Mandatory Visit: Victims must visit a cybercrime police station within 3 days to convert the Zero FIR into a regular FIR.
    • Improved Recovery: Early registration improves the chances of recovering lost funds in time-sensitive fraud cases.
    • Simplified Process: The system makes legal action easier and more accessible for cybercrime victims.
    [UPSC 2021] With reference to India, consider the following statements:

    1. Judicial custody means an accused is in the custody of the concerned magistrate and such an accused is locked up in a police station, not in jail.
    2. During judicial custody, the police officer in charge of the case is not allowed to interrogate the suspect without the approval of the court.

    Which of the statements given above is/are correct?

    Option: (a) 1 only (b) 2 only * (c) Both 1 and 2 (d) Neither 1 nor 2