💥Join UPSC 2027,2028 Mentorship (July Batch) + XFactor Notes & Microthemes PDF

GS Paper: Cyber Security

  • [pib] DoT introduces Financial Fraud Risk Indicator (FRI)

    Why in the News?

    In a major move to fight cyber fraud and financial crime, the Department of Telecommunications (DoT) has launched the Financial Fraud Risk Indicator (FRI) as a part of the Digital Intelligence Platform (DIP).

    Back2Basics: Digital Intelligence Platform (DIP)

    • DIP is developed by the Department of Telecommunications (DoT) as a secure, integrated platform for real-time intelligence sharing.
    • Stakeholders Involved: It connects Telecom Service Providers (TSPs), law enforcement agencies (LEAs), banks, financial institutions, social media platforms, and identity document issuers.
    • Functionality: The platform contains information on telecom resource misuse and supports case tracking and coordinated action.
    • Sanchar Saathi Integration: DIP acts as a backend system for citizen requests submitted through the Sanchar Saathi portal.
    • Access Control: DIP is available only to authorized stakeholders via secure connections and is NOT accessible to public.

    What is the Financial Fraud Risk Indicator (FRI)?

    • Purpose: FRI is a risk-based tool that flags mobile numbers as Medium, High, or Very High risk for financial fraud.
    • Data Sources: It pulls inputs from the National Cybercrime Reporting Portal (NCRP), DoT’s Chakshu Platform, and banking institutions.
    • Beneficiaries: Helps banks, NBFCs, and UPI service providers implement added security for high-risk numbers.
    • How It Works:
      • The Digital Intelligence Unit (DIU) shares a Mobile Number Revocation List (MNRL) with reasons like cybercrime, failed verification, or excess usage.
      • The tool performs multi-dimensional analysis and assigns a fraud risk level.
      • Risk status is shared in real-time via DIP, enabling early action before fraud occurs.

    Case Study: PhonePe’s use of FRI System

    • PhonePe was one of the first adopters of the FRI system.
    • It uses FRI to:
      • Block transactions linked to Very High-risk numbers.
      • Display alerts using the PhonePe Protect feature.
    • For Medium-risk numbers, PhonePe is working on showing proactive user warnings before transactions.
    • The tool has proven highly accurate in identifying numbers involved in cyber fraud.

     

    [UPSC 2021] Which one of the following effects of the creation of black money in India has been the main cause of worry to the Government of India?

    Options: (a) Diversion of resources to the purchase of real estate and investment in luxury housing (b) Investment in unproductive activities and purchase of precious stones, jewelry, gold, etc. (c) Large donations to political parties and the growth of regionalism (d) Loss of revenue to the State Exchequer due to tax evasion*

     

  • CAPTCHA: a digital border between Humans and Bots

    Why in the News?

    This newscard is an excerpt from the original article published in The Hindu.

    What is CAPTCHA?

    • CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart.
    • It is a security measure used to differentiate humans from automated bots on websites.
    • It helps protect websites against spam and misuse by ensuring that the user performing actions is a human.
    • It was developed in the early 2000s by Luis von Ahn, Manuel Blum, Nicholas J. Hopper, and John Langford as a response to the proliferation of automated bots on the internet that created fake accounts, spammed websites, and stole data.
    • The first patent for CAPTCHA was filed in 2003.

    How Does CAPTCHA Work?

    • CAPTCHA presents tasks that are easy for humans to solve but hard for machines.
    • These tasks typically involve recognizing distorted text, images, or sounds that machines cannot interpret as reliably as humans.
    • It operates on the principle of the Turing test, designed by British mathematician Alan Turing in the 1950s.
      • This assesses a machine’s ability to exhibit human-like behaviour.
    • Over the years, CAPTCHA has evolved from simple text recognition to more complex tests:
    1. Image Recognition CAPTCHA: Users are asked to identify specific objects within images, such as cars, traffic lights, or storefronts.
    2. reCAPTCHA: Launched by Google in 2009, this system not only serves as a CAPTCHA but also helps digitize text from scanned documents. Users transcribe words that OCR software has been unable to recognize.
    3. Invisible reCAPTCHA: Introduced by Google in 2014, this version analyzes the user’s interaction with the website, such as mouse movements, to determine if they are human without needing them to complete a specific challenge.

    Limitations of CAPTCHA

    • Accessibility Issues: CAPTCHA can be challenging for people with disabilities, such as visual or hearing impairments.
    • User Inconvenience: The need to solve CAPTCHAs can be cumbersome, particularly on mobile devices, and may detract from user experience.
    • Advancing Bot Technology: As bots become more sophisticated with AI, they are increasingly capable of bypassing CAPTCHA systems, necessitating more complex solutions.
    [UPSC 2019] Consider the following statements: A digital signature is

    1. an electronic record that identifies the certifying authority issuing it

    2. used to serve as a proof of identity of an individual to access information or server on Internet.

    3. an electronic method of signing an electronic document and ensuring that the original content is unchanged

    Which of the statements given above are correct?

    (a) 1 and 2 only (b) 2 and 3 only (c) 1 and 3 only (d) 1, 2 and 3

     

  • How did a DDoS attack cripple Kaveri 2.0?

    Why in the News?

    In January, the Kaveri 2.0 web portal, which helps with property registrations in Karnataka, experienced frequent server crashes. This caused a major disruption, bringing property registration and related citizen services to a near halt in the state.

    What is a DDoS attack?

    • A DDoS (Distributed Denial of Service) attack is when a website or online service is flooded with too much traffic all at once, making it crash or slow down so that real users can’t access it.
    • Instead of coming from one source, the attack comes from many different computers or devices that have been taken over by attackers. These devices work together to send massive amounts of fake traffic to the target, overwhelming it and causing it to stop working.

    What are other major DDoS attacks?

    • Dyn DDoS Attack (2016): The Dyn DDoS attack disrupted major websites including Twitter, Netflix, and Reddit. The attack used a botnet of IoT devices, such as cameras and routers, to flood Dyn’s servers with traffic, causing widespread outages.
    • GitHub DDoS Attack (2018): In 2018, GitHub was hit by one of the largest DDoS attacks in history, with traffic peaking at 1.35 terabits per second. The attack exploited memcached servers to amplify the traffic, overwhelming GitHub’s servers before mitigation efforts kicked in.
    • AWS DDoS Attack (2020): Amazon Web Services (AWS) faced a 2.3 Tbps DDoS attack in 2020, which was one of the largest publicly reported DDoS attacks. AWS mitigated the attack using its cloud infrastructure and security services like AWS Shield.
    • Cloudflare DDoS Attack (2021): In 2021, Cloudflare thwarted a 26 million request-per-second DDoS attack, one of the largest HTTPS DDoS attacks at the time. It was mitigated using Cloudflare’s advanced rate-limiting and traffic filtering technologies.
    • Microsoft Azure DDoS Attack (2023): Microsoft Azure faced one of the largest DDoS attacks ever recorded, peaking at 3.47 terabits per second. The attack, attributed to a botnet leveraging vulnerable devices, aimed to disrupt services for enterprise clients.

    What are the steps taken by the Indian Government? 

    • Cybersecurity Regulations and Policies: In 2025, new cybersecurity regulations were introduced to enhance the existing framework, including mandatory data localization and strengthened data protection laws. The National Cyber Security Policy, established in 2013, continues to guide these efforts by providing strategies for securing cyberspace and protecting critical information infrastructure.
    • Increased Budget Allocations: The Union Budget for 2025 allocated over ₹1,600 crore for cybersecurity initiatives, reflecting the government’s recognition of its importance for national security and economic stability. This includes significant funding for CERT-In and capital projects aimed at bolstering cybersecurity infrastructure across various sectors.
    • Formation of Cybersecurity Agencies: The establishment of agencies such as CERT-In (Computer Emergency Response Team) and NCIIPC (National Critical Information Infrastructure Protection Centre) has been crucial.
      • These agencies are responsible for monitoring cyber threats, coordinating responses, and enhancing the security of critical sectors like banking, telecommunications, and energy.
    • Skill Development Initiatives: To address the shortage of cybersecurity professionals, the government has launched skill development programs aimed at training a workforce of over 500,000 IT experts. This initiative is part of a broader strategy to create a resilient cyber ecosystem capable of responding to evolving threats.

    How can such attacks be mitigated? (Way forward)

    • Traffic Filtering & AI-Based Detection: Uses firewalls, intrusion detection systems (IDS), and AI-based threat analysis to filter out malicious traffic before it reaches the target server.
      • Example: Google Cloud Armor helped mitigate a 46 million request-per-second (RPS) DDoS attack in 2022 by detecting abnormal traffic patterns and blocking it in real-time.
    • Rate Limiting & Load Balancing: Restricts the number of requests a user can make in a given timeframe and distributes traffic across multiple servers to prevent overload.
      • Example: Cloudflare’s Rate Limiting and Load Balancer mitigated an HTTP flood attack on a European banking institution, ensuring legitimate users were not affected.
    • Bot Detection & CAPTCHAs: Uses CAPTCHA tests, behavioural analytics, and browser fingerprinting to block automated bot traffic.
      • Example: GitHub (2015 DDoS Attack by China-based botnet) introduced CAPTCHA-based protection to prevent automated malicious requests targeting anti-censorship tools.
    • CDN & Cloud-Based DDoS Protection: Content Delivery Networks (CDNs) and cloud-based security providers absorb attack traffic before it reaches the main infrastructure.
      • Example: Amazon AWS Shield protected against a 2.3 Tbps DDoS attack (2020) by leveraging global CDN distribution and real-time attack mitigation.
    • Incident Response Plan & Collaboration with Cybersecurity Agencies: Organizations monitor threats, conduct regular security audits, and coordinate with government agencies for rapid response.
      • Example: Kaveri 2.0 Attack (2024, Karnataka, India) led to a cybercrime investigation and strengthened security protocols after the portal faced 6.2 lakh malicious requests in two hours.

    Mains PYQ:

    Q Discuss the potential threats of Cyber attack and the security framework to prevent it.(UPSC IAS/2017)

  • Struggling with poor cyber security

    Why in the News?

    Kaveri 2.0, a web portal launched in 2023 to make property registrations in Karnataka easier was recently hit by a DDoS attack carried out using AI-powered bots.

    What is a DDoS attack? 

    • A Distributed Denial of Service (DDoS) attack is a type of cyberattack where multiple computers or bots flood a website or online service with excessive traffic, overwhelming its servers and causing it to slow down or crash.

    What are the key issues with Karnataka’s response to cyber attacks, specifically the DDoS attack on Kaveri 2.0?

    • Lack of Proactive Cybersecurity Measures: Despite previous cyber incidents like the 2017 WannaCry ransomware attack and the 2019 e-procurement portal hack, the State failed to implement robust preventive measures. The DDoS attack on Kaveri 2.0 in December 2024 – February 2025 exposed the absence of real-time threat monitoring systems.
    • Poor Coordination Between Departments: The e-Governance Department did not involve the State cyber crime police until February 7, 2025, despite weeks of disruption. Resistance within departments to share cybersecurity concerns with law enforcement delayed incident response, worsening the crisis.
    • Lack of a Dedicated Cybersecurity Infrastructure: Karnataka lacks a Cyber Security Operation Centre like Maharashtra and Odisha. A ₹20 crore cybersecurity centre, proposed in February 2023, was scrapped after the new government took over, leaving critical digital infrastructure vulnerable.
    • Government Response and Security Measures: While the government has initiated a police probe and FIR registration under the Information Technology Act, and the Kaveri 2.0 application has been restored with enhanced security measures,
      • Karnataka launched a cyber security policy in 2024 to combat rising cybercrime, focusing on awareness, skill building, and industry promotion.

    How have past attacks influenced the current state of cyber security?

    • Failure to Implement Robust Cybersecurity Measures: Despite the 2017 WannaCry ransomware attack on the Karnataka State Data Centre and the 2019 e-Procurement portal hack (₹11.5 crore stolen), the state did not establish strong preventive mechanisms.
      • The lack of a dedicated Cyber Security Operation Centre resulted in inadequate monitoring and delayed responses to threats like the recent DDoS attack on Kaveri 2.0 (2024-25).
    • Persistent Coordination Gaps Between Departments: Earlier attacks, such as the 2022 cyber attack on NIMHANS, highlighted poor inter-departmental coordination, yet similar gaps persisted during the Kaveri 2.0 DDoS attack.
      • The e-Governance Department handled the crisis alone without informing the cyber crime police, delaying investigative action until February 7, 2025.
    • Neglect of Cybersecurity Infrastructure Development: A ₹20 crore Cyber Security Operation Centre, proposed in February 2023, was dropped in the May 2023 budget revision after a change in government.
      • Unlike Maharashtra and Odisha, which have dedicated cyber security setups, Karnataka still lacks a real-time threat detection system, leaving it vulnerable to repeated cyber attacks.

    Why has the coordination between the e-Governance Department and the State Police been ineffective during cyber incidents?

    • Lack of a Unified Cybersecurity Framework: Karnataka’s Cyber Security Committee (2023) is led by bureaucrats without police representation, unlike national-level bodies like I4C (Indian Cyber Crime Coordination Centre) and NCIIPC (National Critical Information Infrastructure Protection Centre).
      • This results in fragmented decision-making, where cybersecurity response remains within the e-Governance Department, sidelining law enforcement agencies.
    • Delayed Involvement of the Cyber Crime Police: In the Kaveri 2.0 DDoS attack (2024-25), the e-Governance Department did not inform the State cyber crime police until February 7, 2025—long after the attack began in December 2024.
      • Earlier incidents like the 2019 e-Procurement portal hack and 2022 NIMHANS cyber attack also saw delayed police involvement, allowing attackers more time to operate.
    • Departmental Hesitation to Engage Law Enforcement: Sources indicate a reluctance within the e-Governance Department to involve the police, possibly due to bureaucratic hurdles or fears of administrative scrutiny.
      • This lack of trust and procedural clarity has led to independent firefighting efforts rather than a coordinated response between technical teams and law enforcement.

    Why is it crucial for the state to establish a Cyber Security Operation Centre similar to the national model?

    • Real-Time Threat Detection and Response: The DDoS attack on Kaveri 2.0 (2024-25) went undetected for weeks, causing major disruptions in property registrations. A Cyber Security Operation Centre (CSOC) would enable 24/7 monitoring and early detection of cyber threats.
      • National agencies like I4C (Indian Cyber Crime Coordination Centre) and NCIIPC (National Critical Information Infrastructure Protection Centre) use AI-driven analytics and real-time threat intelligence to mitigate cyber risks, a model Karnataka must adopt.
    • Coordinated and Rapid Incident Response: Karnataka’s e-Governance Department handled the Kaveri 2.0 attack alone, only involving cyber crime police weeks later, delaying mitigation efforts.
      • A CSOC would centralize cybersecurity efforts, ensuring immediate coordination between technical experts, government departments, and law enforcement agencies to prevent prolonged disruptions.

    Way forward: 

    • Establish a Cyber Security Operation Centre (CSOC): Revive the ₹20 crore CSOC proposal with real-time threat monitoring, AI-driven analytics, and centralized coordination between government agencies and law enforcement.
      • Implement automated response mechanisms to detect and neutralize cyber threats before they escalate.
    • Strengthen Inter-Departmental Coordination and Cybersecurity Framework: Mandate immediate police involvement in cyber incidents and integrate law enforcement into cybersecurity governance structures like the Cyber Security Committee.
      • Conduct joint cybersecurity drills between the e-Governance Department, State Police, and IT experts to improve incident response efficiency.

    Mains PYQ:

    Q What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy. (UPSC IAS/2022)

  • What is Central Suspect Registry?

    Why in the News?

    In just three months since its launch, the Central Suspect Registry (CSR) has successfully declined over 6 lakh fraudulent transactions, saving ₹1,800 crore, according to the Ministry of Home Affairs (MHA).

    About the Central Suspect Registry (CSR)

    • The CSR aims to strengthen fraud risk management by maintaining a comprehensive registry of cybercrime suspects.
    • It contains data on 1.4 million cybercriminals linked to financial fraud and other cybercrimes.
    • The registry was created by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs.
    • The registry is accessible to states, Union Territories, central investigation agencies, intelligence agencies, and financial institutions.
    • Developed with inputs from banks and financial institutions, the CSR serves as a central database consolidating cybercrime-related data.

    Significance of the CSR:

    • Integration with NCRP: Uses data from the National Cybercrime Reporting Portal to identify potential cybercriminals.
    • Fraud Detection and Prevention: Helps financial institutions and law enforcement agencies identify and block fraudulent activities.
    • Support from Financial Entities: The RBI has directed all banks to integrate the registry into their systems for fraud prevention.
    • Impact:
      • Over 6.10 lakh fraudulent transactions blocked, saving ₹1,800 crore as of December 1, 2024.
      • 8.67 lakh mule accounts frozen by banks and financial intermediaries.
      • 7 lakh SIM cards and 1.4 lakh mobile devices blocked.
      • Financial fraud transactions amounting to ₹3,850 crore saved since 2021 through the Citizen Financial Cyber Frauds Reporting and Management System.
      • 1,03,151 suspicious online content items blocked under the powers conferred by the Information Technology Act, 2000.

    PYQ:

    [2020] In India, under cyber insurance for individuals, which of the following benefits are generally covered, in addition to payment for the loss of funds and other benefits?

    1. Cost of restoration of the computer system in case of malware disrupting access to one’s computer
    2. Cost of a new computer if some miscreant wilfully damages it, if proved so
    3. Cost of hiring a specialised consultant to minimise the loss in case of cyber extortion
    4. Cost of defence in the Court of Law if any third party files a suit

    Select the correct answer using the code given below:

    (a) 1, 2 and 4 only
    (b) 1, 3 and 4 only
    (c) 2 and 3 only
    (d) 1, 2, 3 and 4

  • India’s journey so far on the AI military bandwagon

    Why in the News?

    India has started leveraging AI to bolster its defence ecosystem, but significant challenges remain.

    What are the strategic implications of AI integration in India’s defence?

    • Enhanced Military Capabilities: The integration of AI is expected to revolutionize military operations through improved predictive analytics, autonomous decision-making systems, and advanced operational efficiency.
    • Modernization Focus: With a defence budget of ₹6.21 lakh crore ($75 billion) for 2023-24, India is prioritizing modernization efforts, including the development of innovative products like the Indrajaal autonomous drone security system.
    • Global Competitiveness: To keep pace with countries like Israel and China that have rapidly advanced their military AI capabilities, India recognises the need for a clear vision and strategy for AI deployment in defence.

    How does India plan to overcome challenges in implementing AI in military operations?

    • Funding and Infrastructure: A significant barrier to effective AI integration is the high cost of data centres and the infrastructure necessary for running advanced AI systems. The military’s focus on replacing outdated legacy systems adds to financial pressures.
    • Fragmented Policies: India’s current policies regarding AI deployment are often fragmented, lacking comprehensive guidelines specifically tailored for military applications. Existing frameworks do not adequately address accountability and transparency in military AI use.
    • Inter-Service Silos: The historically siloed nature of the Indian Armed Forces—where the Army, Navy, and Air Force operate independently—hinders interoperability and complicates joint operations.

    What role does collaboration between the public and private sectors play in advancing AI in defence?

    • Public-Private Partnerships (PPPs): To enhance technological advancements in defence, India needs to foster collaboration between public sector units (PSUs) and private entities. This approach can leverage the innovation capabilities of startups and private companies.
    • Knowledge Sharing: Collaborations with foreign tech giants like Microsoft, which has committed approximately $3 billion to develop data centres in India, can facilitate knowledge transfer and resource sharing essential for building a robust AI ecosystem.
    • Accelerating Innovation: Engaging private sector expertise can lead to faster development cycles and more effective deployment of AI technologies within the military framework.

    Way forward: 

    • Strengthen Policy Frameworks and Coordination: Develop cohesive and actionable policies for AI deployment in defence, focusing on inter-service interoperability, accountability, and transparency while operationalizing bodies like DAIC and DAIPA effectively.
    • Promote Public-Private Collaboration: Enhance public-private partnerships (PPPs) to leverage private innovation and attract foreign investments, ensuring resource optimization and accelerated AI adoption in military operations.

    Mains PYQ:

    Q Discuss different types of cyber crimes and measures required to be taken to fight the menace. (UPSC IAS/2020)

  • UNGA adopts milestone Cybercrime Treaty

    Why in the News?

    The United Nations General Assembly (UNGA) has adopted a legally binding treaty on cybercrime, marking the culmination of a five-year effort by Member States. This is the first international criminal justice treaty negotiated in over 20 years.

    About UN Convention against Cybercrime: Important Facts

    • The UN Convention against Cybercrime is a legally binding treaty adopted by the UN General Assembly in December 2024.
    • Its primary aim is to prevent and combat cybercrime, enhance international cooperation, and protect human rights in cyberspace.
    • The convention was finalized after five years of negotiations and unanimously adopted by all 193 UN member states.
    • A signing ceremony is scheduled for 2025 in Hanoi, Vietnam.
    • Key Provisions:
    1. Addressing Cybercrime:
      • Targets crimes like terrorism, human trafficking, financial fraud, drug smuggling, and data theft facilitated by ICT platforms.
    2. Victim-Centric Approach:
      • Focuses on protecting victims, particularly vulnerable groups, and ensuring they receive justice.
    3. International Cooperation:
      • Promotes evidence-sharing, joint investigations, and capacity-building among Member States.
    4. Safeguarding Human Rights:
      • Balances the need for cybersecurity with the protection of freedom of expression, privacy, and access to information.
    5. Adaptability:
      • Allows for additional protocols to address emerging cyber threats, ensuring the convention remains relevant.
    6. Capacity-Building:
      • Provides support to develop cybercrime legislation, build infrastructure, and enhance law enforcement capabilities in Member States.
    7. Public Awareness:
      • Encourages global education campaigns and proactive measures to prevent cyber offenses.

    Significance:

    • Landmark in International Law: Marks the first international criminal justice treaty in over 20 years, representing a global commitment to cybersecurity.
    • Strengthening Cybersecurity: Offers tools and mechanisms to mitigate ICT-enabled threats that undermine global security and economies.
    • Protecting Vulnerable Groups: Emphasizes justice and protection for marginalized communities affected by online crimes.
    • Economic and Social Benefits: Preserves global economies, promotes investment in cybersecurity infrastructure, and safeguards individuals.
    • Flexibility for Future Threats: Incorporates provisions for additional protocols to handle new challenges, such as AI-driven cyber threats.

    PYQ:

    [2022] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

  • In the Pegasus case, a stark difference in the efficiency of law enforcement in India and the US

    Why in the News?

    The US court ruling found the maker of Pegasus spyware guilty of hacking WhatsApp, while in India, the investigation ended quietly without any results.

    What are the implications of the US court ruling against NSO Group?

    • Legal Accountability Established: The US District Court’s ruling that NSO Group is liable for hacking WhatsApp users marks a significant legal precedent. It affirms that private companies engaged in illegal surveillance can be held accountable in a court of law, which may encourage other jurisdictions to take similar actions against such entities.
    • Protection of Privacy Rights: The ruling underscores the importance of user privacy and proprietary technology protection. It emphasizes that courts can act decisively to safeguard individual rights against corporate malfeasance, setting a standard for privacy protection that could influence global norms.
    • Pressure on NSO Group: The verdict amplifies economic and operational pressures on NSO Group, potentially leading to stricter regulations and oversight of surveillance technology firms worldwide. This could deter similar future actions by other companies in the industry.

    Why has India’s inquiry into the Pegasus allegations been ineffective?

    • Government Evasion: The Indian government’s refusal to confirm or deny the use of Pegasus spyware has significantly hampered any meaningful investigation. This silence has been framed as a matter of national security but is perceived as a deliberate evasion of accountability.
    • Lack of Cooperation: The Supreme Court’s appointed committee faced challenges due to the government’s lack of cooperation.
      • Key stakeholders like WhatsApp and Apple were not compelled to provide evidence or testimony, limiting the committee’s ability to draw conclusive findings.
    • Judicial Delays and Inaction: India’s judicial system is plagued by delays and inefficiencies, which have further stalled inquiries into Pegasus. Parliamentary debates have devolved into unproductive exchanges, failing to generate actionable outcomes.

     

    What are the legislations related to spyware attacks in India?

    • Information Technology Act, 2000 (IT Act):
      • Section 43: Criminalizes unauthorized access to computer systems and networks, making hacking a punishable offense.
      • Section 66: Addresses cybercrime and provides penalties for violations of computer-related laws.
      • Section 69: Allows government agencies to intercept data on grounds of national security but does not authorize the installation of spyware like Pegasus on devices without proper oversight.
    • Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009: These rules require that no interception can occur without the direction and approval of a competent authority, aiming to provide some level of oversight.
    • Digital Personal Data Protection Act (DPDPA): Recently passed in 2023, this act has faced criticism for allegedly providing legal cover for state surveillance while lacking robust protections for individual privacy rights. Critics argue that its vague language allows for arbitrary government.

    What should be the next steps for Indian authorities following the US verdict? (Way forward)

    • Reinitiate Investigations: Indian authorities should consider reopening investigations into Pegasus with renewed vigour, leveraging insights from the US court ruling. This includes calling for transparency from technology companies involved in the case.
    • Engage with Stakeholders: Authorities should actively engage with WhatsApp, Apple, and other relevant parties to gather comprehensive evidence regarding the spyware’s use in India. This collaboration is crucial for establishing accountability.
    • Legislative Reforms: There is an urgent need for systemic reforms in surveillance laws and practices in India. Authorities should work towards creating robust frameworks that protect citizens’ privacy rights and establish clear guidelines for state surveillance activities.
    • Public Disclosure: To rebuild public trust, it is essential for the government to disclose findings from previous inquiries and commit to transparency moving forward. This includes making reports from technical committees publicly available

    Mains PYQ:

    Q Discuss different types of cyber crimes and measures required to be taken to fight the menace. (UPSC IAS/2020)

  • What are the Digital Arrest Scams?

    digital arrest

    Why in the News?

    The Prime Minister in his recent broadcast of “Mann Ki Baat” warned about the ‘Digital Arrest’ scams in India.

    What is Digital Arrest?

    Details
    What are they? A fraudulent scheme where scammers impersonate law enforcement officials to extort money from victims under the false pretence of an arrest.
    Modus Operandi • Scammers use audio or video calls to intimidate victims.
    • Claim involvement in illegal activities (e.g., drugs, contraband).
    • Victims are kept under constant visual surveillance until demands are met.
    Common Tactics • Use of deepfake videos and fake arrest warrants.
    • Threats regarding family members being involved in crimes.
    • Fake claims about parcels containing illegal goods.
    Victim Impact Victims may face significant financial losses, emotional distress, and a sense of vulnerability due to the intimidation tactics employed by scammers.
    Recent Trends • Increase in reported cases; over 11 lakh complaints of financial cyber fraud in 2023.
    • Rising incidents attributed to the expansion of internet users.
    Prevention Measures • Awareness of scams and verification of callers’ identities.
    • Immediate disconnection of suspicious calls.
    • Reporting incidents to local police and cybercrime helplines.
    Legal Framework • Governed by the Information Technology Act, 2000.
    • Reports can be filed through the National Cyber Crime Reporting Portal (www.cybercrime.gov.in).

     

    PYQ:

    [2017] In India, it is legally mandatory for which of the following to report on cyber security incidents?

    1. Service providers

    2. Data centres

    3. Body corporate

    Select the correct answer using the codes given below:

    (a) 1 only

    (b) 1 and 2 only

    (c) 3 only

    (d) 1, 2 and 3

  • Global Cybersecurity Index, 2024

    Why in the News?

    • India has achieved Tier 1 status in the Global Cybersecurity Index (GCI) 2024, published by the International Telecommunication Union (ITU).
      • With a score of 98.49 out of 100, India is now among the top nations demonstrating role-model cybersecurity practices.

    About Global Cybersecurity Index (GCI):

    Details
    Launch  2015, by the International Telecommunication Union (ITU)

    About ITU

    • Founded on 17 May 1865 as the International Telegraph Union
    • Presently has 193 member states, with South Sudan joining most recently in 2011
    • India became a member in 1869

    Objective • Measures the commitment of countries to cybersecurity based on five pillars.
    • Helps identify areas for improvement and encourages capacity and capability building.
    Five Pillars Legal: Laws and regulations on cybercrime and cybersecurity
    Technical: Implementation of technical capabilities via national and sector-specific agencies
    Organizational: National strategies and organizations implementing cybersecurity
    Capacity Development: Awareness, training, education, and incentives for cybersecurity
    Cooperation: Partnerships between agencies, firms, and countries
    Strengths and Weaknesses • Most countries are strongest in the Legal pillar.
    • The Capacity Development and Technical pillars are where most countries are weakest.
    GCI 2024 Five-Tier Analysis Tier 1 (Role-modelling): Score of 95-100
    Tier 2 (Advancing): Score of 85-95
    Tier 3 (Establishing): Score of 55-85
    Tier 4 (Evolving):

     

    PYQ:

    [2020] In India, under cyber insurance for individuals, which of the following benefits are generally covered, in addition to payment for the loss of funds and other benefits?

    1. Cost of restoration of the computer system in case of malware disrupting access to one’s computer

    2. Cost of a new computer if some miscreant willfully damages it, if proved so.

    3. Cost of hiring a specialized consultant to minimize the loss in case of cyber extortion

    4. Cost of defence in the Court of Law if any third-party files a suit

    Select the correct answer using the code given below:

    (a) 1, 2 and 4 only

    (b) 1, 3 and 4 only

    (c) 2 and 4 only

    (d) 1, 2, 3, and 4