💥Mains Ready By December. Smash Mains & Smash PYQ Admissions Open

GS Paper: GS3-21.Role of External State and Non-state Actors in creating challenges to Internal Security.

  • Financial Fraud Risk Indicator crosses ₹5,000 crore in prevented fraud

    Why in News

    1. Milestone crossed: The Financial Fraud Risk Indicator (FRI) has prevented suspected cyber fraud transactions of over ₹5,000 crore.

    Core facts

    1. What FRI is: The Financial Fraud Risk Indicator is a real time risk assessment framework. It flags whether a mobile number may be linked to cyber crime or fraud.
    2. Administering body: The Department of Telecommunications (DoT) developed and operates it. It launched on 22 May 2025.
    3. Risk classes: FRI classifies mobile numbers into three categories. These are Medium, High and Very High risk.
    4. Data sources: It draws on citizen reports through Sanchar Saathi, the National Cybercrime Reporting Portal, telecom operators and financial institutions.
    5. Use by institutions: Banks, payment providers, insurers and pension entities use the risk signal for transaction monitoring.
    6. Amount protected: FRI prevented ₹5,043.73 crore in suspected fraud as of August 2026.
    7. Recent record: Over ₹2,000 crore was prevented between April and August 2026. More than 1,600 organisations are on the platform.

    Static Context

    1. The Digital Intelligence Platform was launched by the Department of Telecommunications in 2024. FRI operates within it.
    2. Sanchar Saathi is a citizen portal to report suspected fraud communication and to block lost or stolen mobile handsets.
    3. The National Cybercrime Reporting Portal is run by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs.

    Prelims angle

    1. FRI custodian: Department of Telecommunications, within the Digital Intelligence Platform.
    2. Related platforms: Sanchar Saathi, National Cybercrime Reporting Portal and I4C are frequently tested.

    Mains angle

    1. GS3, internal security: A question can assess how real time data sharing between telecom and banking systems strengthens India’s response to cyber financial fraud.

    Matching Previous Year Question

    “No direct Prelims PYQ on financial fraud prevention was traced in the provided files. Closest Microtheme: Cyber Security (Internal Security).”

    “[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”

  • Focus on the children, not the platform

    Focus on the children, not the platform

    Why in the News

    Meta has settled a $171 billion case with several United States States over allegations about the effect of its apps on children’s mental health. The settlement requires daily usage limits and “nighttime blocks” for teenagers. It requires “enhanced age assurance measures” (checks intended to establish a user’s age before access is granted) to keep children off the apps. It also requires the depersonalisation of feeds, so a child is served random content rather than content matched to that child’s interests. The outcome is being read as a step towards holding platforms accountable. That framing places the platform at the centre of the problem rather than the child, and the two framings do not produce the same policy.

    Why does a platform centric approach to child safety misfire?

    1. The measures are difficult to enforce: An age gate assumes a child will not defeat it, while children are sophisticated and motivated users of technology who find ways around such checks.
    2. It ignores what children need to be safe online: Poorly designed recommendation systems expose children to harmful content, and stripping personalisation replaces that risk with irrelevant or inappropriate material. It also makes it harder for educational and support services to reach the children who need them.
    3. Online spaces are the only support some children have: Children experiencing neglect or abuse, LGBTQIA+ children and socially isolated children use platforms to find information, companionship or help. A child’s participation is not confined to one service, so a platform that becomes too restrictive simply loses them to platforms with weaker protections.
    4. The offline environment is what pushes children online: In India screens fill a vacuum rather than displacing abundant offline opportunities, because many children have no access to safe public spaces or affordable recreational facilities.

    What would a child centred approach ask for instead?

    1. Equip the child, as is done in the physical world: Children are taught what not to share, how to respond to unsolicited contact, how to recognise manipulation, when to block or report someone, and when to seek help.
    2. Treat digital literacy as the instrument, not the afterthought: Digital literacy and sensitisation are what change a child’s behaviour at the moment a technical control fails, and they receive far less policy attention than platform obligations.
    3. Address the whole ecology of childhood: Responsibility sits across platforms, parents, schools, communities, public spaces and children themselves, so a measure aimed at one of the six leaves the other five untouched.

    Why does the harder answer receive less policy attention?

    1. A platform obligation is visible and countable: A regulator can order a control, verify that it shipped, and record compliance, none of which a curriculum or a public playground delivers on the same timescale.
    2. India’s move so far is a recommendation, not a mandate: The 2026 Economic Survey called for a digital wellness curriculum in schools, and whether it is implemented widely and appropriately is untested.
    3. The effective lever sits outside the regulator’s reach: Digital literacy runs through school systems and recreational space runs through municipalities, while enforcement powers sit with technology and data protection regulators.
    4. The argument does not absolve platforms: Platform responsibility survives intact, and the contest is over which lever produces a safer child rather than over whether platforms owe anything at all.

    Conclusion

    Child online safety is presently measured by the number of controls a service ships. The better measure is what a child is able to do when a control fails, and the settlement model produces no information about that at all. The capability side of the problem belongs to schools, parents and municipalities. The enforcement side belongs to a technology regulator, and nobody owns the gap between the two.

    Child Online Safety in India

    1. What the field covers: The rules governing children’s access to online services, the data those services may collect about a child, and the content they may direct at one.
    2. How India regulates it: Through due diligence obligations on intermediaries under technology law and consent rules under data protection law, rather than through a single children’s online safety statute.
    3. Who counts as a child: Indian data protection law treats every person below 18 as a child, a higher threshold than the 13 year line used in United States children’s privacy law.

    Laws and Rules Governing Child Online Safety

    1. Information Technology Act, 2000, amended in 2008: The parent statute for offences committed through a computer resource, carrying Section 66D on cheating by impersonation and Section 69 on interception.
    2. Section 67B separately punishes publishing or transmitting material depicting children in sexually explicit acts.
    3. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, amended in 2023: Impose due diligence, grievance redressal and content takedown obligations on intermediaries.
    4. Digital Personal Data Protection Act, 2023, with the Digital Personal Data Protection Rules, 2025: Govern consent, data fiduciary duties, breach notification and the Data Protection Board of India.
    5. Section 9 requires verifiable parental consent before a child’s personal data is processed, and bars tracking, behavioural monitoring and advertising targeted at children.
    6. Protection of Children from Sexual Offences Act, 2012: Defines and punishes sexual offences against persons below 18, covers offences committed using electronic material, and makes reporting mandatory.

    [2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023.

  • Need to break Manipur’s cycle of reprisal (Editorial)

    Need to break Manipur’s cycle of reprisal (Editorial)

    Why in the News

    More than three years after the Meitei-Kuki clashes began, Manipur now faces a deepening Kuki-Naga fault line. Four Naga civilians were killed this week in Kuki-dominated Kangpokpi district, an episode that follows the killing of Kuki-Thadou church pastors in May, retaliatory abductions on both sides, and the recovery a month later of the bodies of six Naga men.

    How has the conflict widened beyond the original Meitei-Kuki fault line?

    1. A second, distinct fault line has opened: What began as Meitei-Kuki violence in 2023 has produced a separate Kuki-Naga confrontation, evident in this week’s killing of four Naga civilians in Kangpokpi, a district that sits between Naga-dominated Senapati to the north and Meitei-dominated valley districts to the south.
    2. A traceable chain of retaliation: The killing of Kuki-Thadou pastors in May was followed by retaliatory abductions from both communities, and the subsequent recovery of six Naga men’s bodies a month later, establishing a pattern of reprisal rather than an isolated incident.
    3. Blockades have turned roads into contested territory: Meitei, Kuki and Naga groups have separately imposed blockades that disrupt supplies, raise the cost of food and fuel, and restrict access to healthcare, with Kangpokpi the worst affected due to its position between rival-dominated districts.

    Why has the return of an elected government failed to restore order?

    1. A power-sharing arrangement has not translated into reconciliation: The state government led by Yumnam Khemchand Singh, a Meitei chief minister with deputy chief ministers from the Kuki and Naga communities, returned in February after almost a year of President’s Rule, but has found little success pulling the state back from the brink.
    2. Social segregation has outpaced political representation: The communities remain socially segregated, so political representation across the three groups in government has not by itself addressed the everyday separation that sustains distrust and enables further violence.
    3. Displacement has produced a significant, undercounted toll: Right to Information data has revealed that more than 700 internally displaced people have died in relief camps, a toll separate from and additional to deaths from direct violence.

    Challenges to a political settlement in Manipur

    1. Security forces have struggled to secure supply routes: Security forces have had very little success ensuring the safe movement of convoys carrying essential supplies through blockaded areas. Eg. Blockades imposed by Meitei, Kuki and Naga groups have repeatedly disrupted the movement of food, fuel and medical supplies into Kangpokpi and surrounding districts. Fix. Establish dedicated, jointly monitored humanitarian corridors for essential supplies, with monitoring involving representatives from all three communities rather than security forces alone.
    2. Armed groups remain undisbanded: Militant groups from multiple communities continue to operate, and a crackdown on extremist elements has not kept pace with the scale of continuing violence. Eg. The killing of four Naga civilians in Kangpokpi this week, alongside the earlier killing of Kuki-Thadou pastors, shows armed actors from more than one community remain capable of carrying out attacks. Fix. Pursue simultaneous, verifiable disarmament commitments from armed groups across all three communities rather than sequencing disarmament by community.
    3. No agreed framework exists for resolving land and identity claims: Every claim over land and identity cannot be resolved overnight, and the absence of an interim framework leaves communities without a safe basis for movement, trade or daily coexistence. Eg. The overlapping blockades by all three communities show there is currently no shared understanding of which areas each community can safely access. Fix. Prioritise an interim framework guaranteeing safe movement, trade and access to essential services, deferring final land and identity settlements to a later, dedicated political process.

    Conclusion

    The editorial’s position is that political representation alone, through a Meitei chief minister and Kuki and Naga deputy chief ministers, cannot resolve a conflict sustained by social segregation and repeated cycles of reprisal. It calls for sustained dialogue empowering civil society leaders, an interim framework for safe movement and trade, and simultaneous disarmament and action against extremist elements, alongside the immediate arrest of those responsible for this week’s killings.

    Back2Basics: What is President’s Rule?

    Central takeover of state governance: President’s Rule, imposed under Article 356 of the Constitution, allows the Union government to assume direct control of a state’s administration when its constitutional machinery is deemed to have broken down, as occurred in Manipur for nearly a year before the elected government returned in February.

    1. AI is transforming cyber attacks as well as defences: What this means for India

      AI is transforming cyber attacks as well as defences: What this means for India

      Why in the News

      Artificial Intelligence (AI) is now amplifying cyber threats across the cyber kill chain at speed, scale and sophistication, and is developing the ability to act as an autonomous agent that identifies, plans, adapts and carries out offensive cyber operations. The shift follows the fastest technology adoption on record: the Internet took 15 years to reach a billion users, and ChatGPT did so in three. The tension is that AI capability is concentrated in very few countries, so the same technology that raises the threat also determines who can defend against it. India’s indigenous AI ecosystem lags the United States and China across the entire AI stack, leaving it exposed on both sides of that equation.

      What is the cyber kill chain?

      1. Definition: The cyber kill chain is the sequence of stages an attacker must complete to succeed, running from reconnaissance on a target, through weaponisation of malicious code, to command and control of the compromised system.
      2. Why the framework matters: Defence has traditionally worked by breaking any one link in that chain, since an attack that fails at one stage cannot proceed to the next.
      3. What AI changes: AI is now compressing or automating several stages at once, so breaking a single link no longer stops the sequence.

      How is AI amplifying offensive cyber operations?

      1. Reconnaissance is automated: Gathering information about a target once depended on humans, and research shows ChatGPT models being used to mine social media for precise details to craft AI generated phishing emails.
      2. Deepfakes are now real time: AI is generating real time deepfakes, deepening confusion about what is authentic online.
      3. Social engineering scales: AI enabled social engineering, the use of AI to trick or persuade people into taking harmful actions, no longer requires a human operator per target.
      4. Malware no longer holds a fixed shape: Large language models (LLMs) can autonomously generate, modify and restructure polymorphic malware to suit the situation, unlike traditional malware, which relies on fixed signatures and predictable patterns.
      5. An AI has already run an attack chain: In September 2025 Anthropic claimed a Chinese state sponsored group, GTG-1002, had used Claude Code as an autonomous cyber agent across multiple stages of an attack, in what the company called the first reported case of an AI orchestrated cyber espionage campaign.

      Why does autonomous vulnerability discovery change the risk?

      1. Zero-days are being found at scale: Anthropic’s latest frontier model, Claude Mythos Preview, has identified thousands of zero-day vulnerabilities, meaning flaws previously unknown to developers, across major operating systems and browsers, many of them critical.
      2. It builds the exploits too: The model developed related exploits largely without human intervention, collapsing the gap between finding a flaw and being able to use it.
      3. Hardened systems are not exempt: It found a 27 year old vulnerability in OpenBSD, an operating system reputed to be highly security hardened and widely used to run firewalls and critical infrastructure.
      4. Industrial systems are the exposed surface: Such vulnerabilities are especially dangerous for Operational Technology (OT) and Industrial Control Systems (ICS), the computing that governs nuclear facilities, energy grids, pharmaceutical manufacturing, chemical processing, oil refineries and communication networks.
      5. Exposure grows with integration: That infrastructure becomes more exposed as it integrates further with AI, so the adoption that improves efficiency also widens the attack surface.

      Why do old cyber defences no longer hold?

      1. Signature matching fails against shape shifting code: Traditional antivirus looks for known malware fingerprints, which malware that constantly changes and adapts no longer presents.
      2. Static patching is too slow: Security patches written for known vulnerabilities are far less effective when new flaws are discovered and weaponised faster than patch cycles run.
      3. AI defence works differently: AI in cybersecurity enables real time threat detection, automated response and large scale data analysis, mitigating risks faster than human led triage.
      4. The divide has shifted: The real AI divide is not about who uses AI but about who builds it and who controls its development, which is why cybersecurity capability now tracks AI capability.

      How exposed is India?

      1. A nuclear plant’s data was posted: The ransomware group World Leaks claimed to have stolen and posted data related to India’s largest nuclear plant, Kudankulam, including blueprints of facility parts and supplier details.
      2. The ranking moved sharply: Cyber intelligence firm CloudSEK’s 2024 report placed India as the second most cyber attacked nation after the United States, and its 2025 report placed India sixth.
      3. State backed actors targeted defence during a conflict: During Operation Sindoor, Pakistan backed threat actors such as APT36 targeted India’s critical sectors, including the Ministry of Defence, the Army, the Navy and the Defence Research and Development Organisation (DRDO).
      4. A new target class appeared: The same campaign targeted Bharat Operating System Solutions (BOSS) Linux for the first time, extending the attack surface to India’s indigenous operating system.

      Can India defend a cyberspace built on an AI stack it does not own?

      1. The ecosystem is incremental: India’s indigenous AI ecosystem remains incremental and lags well behind the United States and China across the AI stack.
      2. The gap is at every layer: The shortfall runs across foundational models, graphics processing units, chip design and large scale data centre infrastructure, so no single procurement closes it.
      3. Dependence is the security problem: The lag leaves India heavily dependent on the United States and other technologically advanced countries for the very tools its defence now requires.
      4. Capability determines both roles: Countries with leading AI ecosystems gain a greater ability both to conduct sophisticated cyber campaigns and to defend against them, so dependence caps India’s ceiling on defence as well as deterrence.

      What has India done so far?

      1. CERT-In has shifted its methods: The Indian Computer Emergency Response Team (CERT-In), the national agency for responding to cyber security incidents, has since 2025 adopted AI driven threat detection, cyber resilience measures, trusted AI frameworks and citizen centric malware mitigation.
      2. A specific advisory was issued: In April 2026 it issued an advisory for organisations on defending against AI driven cyber risks.
      3. The advisory’s operative instructions: Recommendations included “removing unnecessary internet-facing services” and treating every newly discovered vulnerability as something that “could be exploited within hours, not weeks”.
      4. Governance work is at the framework stage: The Ministry of Electronics and Information Technology (MeitY) is exploring a consent based framework for synthetically generated content, alongside curbs on agentic AI autonomy and clearer liability frameworks for AI models.

      Challenges to India’s AI-enabled cyber defence

      1. Defence rests on advisories rather than obligations: CERT-In’s guidance to organisations is recommendatory, so a private operator of critical infrastructure faces no penalty for ignoring it. Eg. The April 2026 advisory asked organisations to remove unnecessary internet facing services, with no compliance audit attached. Fix. Convert the advisory content into mandatory, audited security baselines for power, banking, telecom and healthcare operators under the Information Technology Act, 2000.
      2. Compute dependence caps defensive AI: Running real time detection models at national scale needs domestic graphics processing unit capacity that India does not have. Eg. India’s shortfall spans foundational models, chip design and large scale data centre infrastructure alike. Fix. Prioritise sovereign compute for security workloads specifically, reserving a share of publicly funded AI infrastructure for CERT-In and sector CSIRTs.
      3. Attribution is harder when the attacker is an agent: An AI orchestrated campaign leaves a machine’s traces rather than an operator’s, which weakens the evidentiary basis for a state response. Eg. The GTG-1002 campaign was identified by the model provider, not by a victim’s own forensics. Fix. Mandate model providers serving Indian users to report detected misuse of their systems for offensive operations, on the six hour breach reporting model already in force.
      4. Legacy industrial systems cannot be patched quickly: Control systems in refineries and grids run on decade old software where a patch requires a plant shutdown. Eg. A 27 year old OpenBSD flaw survived in software widely used to run firewalls and critical infrastructure. Fix. Require network segmentation and one way data diodes between industrial control networks and corporate networks, so an unpatched system is not internet reachable.
      5. The skills base is thin at the state level: Cyber investigation and forensics capacity is concentrated in central agencies, while most first response happens at state police stations. Eg. Citizen fraud complaints route through the national helpline before reaching local police with the capacity to act. Fix. Establish State Computer Emergency Response Teams and cyber forensic laboratories with dedicated cyber police training academies in every State.

      Conclusion

      AI has moved cyber conflict from a contest between attackers and defenders to a contest between countries that build AI and countries that buy it. India sits on the wrong side of that line while carrying one of the world’s largest attack volumes, from a ransomware posting of Kudankulam plant data to state backed targeting of its defence establishment. India cannot build the AI stack quickly, so the immediate requirement is that AI and cybersecurity stop being treated in silos and are handled as interconnected strands of policymaking: AI for cyber defence, and cybersecurity for AI.

      “[2022, GS3, 10 marks] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.”

    2. Remembering Niketu Iralu: Peace activist, bridge between Nagas, mainland India

      Remembering Niketu Iralu: Peace activist, bridge between Nagas, mainland India

      Why in the News

      Niketu Iralu, a Naga peace activist, died in a Delhi hospital on 18 August 2026 at the age of 91. He spent six decades on reconciliation between Naga factions and between the Naga people and the rest of India, outside every formal negotiating channel. His maternal uncle, Angami Zapu Phizo, led the Naga National Council (NNC), which declared Naga independence on 14 August 1947. The Centre constituted a new ministerial panel last week to carry forward the stalled talks on a final Naga settlement. The conflict has found no solution in the nearly eight decades since that declaration. One position holds that a final text can now be signed. The competing position is that the reconciliation work behind six decades of talks has no institutional successor.

      What is the Naga peace process?

      1. A ceasefire came before any accord: A peace camp at Chedema, on a hilltop near Kohima, negotiated a ceasefire in 1964 between the rebel Naga Federal Government and the Government of India. It was the first suspension of hostilities after more than a decade of armed insurgency.
      2. The Shillong Accord split the movement: NNC representatives signed the Shillong Accord in 1975, accepting the Constitution of India. A faction rejected it and formed the National Socialist Council of Nagaland (NSCN) in 1980.
      3. The current track opened with the 1997 ceasefire: The Centre signed a ceasefire with the NSCN (Isak-Muivah) faction in 1997. Talks under it have run for close to three decades without a final agreement.
      4. The Framework Agreement fixed the terms in 2015: The Centre and the NSCN (Isak-Muivah) signed a Framework Agreement on 3 August 2015 recognising the “unique history” of the Nagas. Its contents have never been published.

      Why did a family at the centre of the sovereignty claim produce its leading peace advocate?

      1. The lineage ran through the sovereignty movement: His father, Sevilie Iralu, was among the first Naga doctors. His maternal uncle led the council that made the 1947 declaration.
      2. He chose a different method: He committed himself to non-violence, dialogue and reconciliation rather than armed struggle. He became known across the Northeast as a peace activist rather than a political negotiator.
      3. Initiatives of Change shaped that method: He worked in Initiatives of Change, an organisation that pursues social transformation through “personal change”. Its premise is that a political conflict is resolved by first changing the people inside it.
      4. Mainland India was a discovery, not an inheritance: He left for Madras Christian College in the 1950s, his first encounter with mainland India. He described the crowds boarding trains at Kolkata as a scale of population that felt unsurvivable.
      5. His house was named for the method: His home at Sechu Zubza in Kohima district was called Kerunyu Ki, “The House of Listening”. People travelled to it for counsel rather than to a party office or a negotiating table.
      6. Recognition came as a bridge builder: He received the Bhupen Hazarika Integration Award among other honours. Hundreds gathered at Dimapur airport when his body arrived from Delhi.

      How does the Second World War figure in Naga political memory?

      1. The war reached Naga villages: The Japanese Army invaded Nagaland in 1944 during the Second World War. His village, Khonoma, was overrun and families fled into the forest.
      2. The battle of Kohima was the turning point: The Japanese retreated after the battle of Kohima. An advance past it would have taken them to the Brahmaputra valley and into mainland India.
      3. The cemetery fixed the memory: The Kohima War Cemetery carries the epitaph, “When you go home, tell them of us and say, for their tomorrow, we gave our today.”
      4. The war left a habit of seeing the enemy as human: His sister slapped a Japanese soldier helping himself to a Naga shawl, and the soldier bowed and left. He read that restraint as evidence that the soldier also had a sister at home.

      What did the 1990 repatriation of Phizo’s body show about informal mediation?

      1. The leader died in exile: Angami Zapu Phizo died in London in April 1990. He had been in exile since 1960, when he left for the United Kingdom to mobilise world opinion for the Naga cause.
      2. The request came from the insurgent side: NNC leaders asked him to help bring the body back to India. No working channel existed between the NNC and the Government of India at that point.
      3. The government feared a funeral would trigger violence: The Janata Dal led government judged that returning the body might set off violence in Nagaland. A Janata Dal member of the Rajya Sabha, who had worked with him in Initiatives of Change for three decades, argued that denying the Nagas the right to grieve was the greater risk.
      4. The ask was procedural, not financial: He told the then Finance Minister at a 5 a.m. meeting that the Nagas had collected the money themselves. He asked only for foreign exchange clearance.
      5. The state supplied the logistics: The remains were received at the technical area of Palam airport. A Home Ministry aircraft then carried the casket to Kohima for the funeral.

      Does reconciliation require a community to confront its own failures?

      1. The demand was turned inward, not outward: A tribute in Ukhrul Times described him as a man who spent decades asking Nagas to confront their failures, resist hatred and recover the courage to listen. The demand was addressed to Naga society, not to the Indian state.
      2. Moral courage was defined as internal criticism: He held that moral courage involves “telling one’s own side what it does not want to hear”. He did not treat reconciliation as a concession or as weakness.
      3. Factional politics penalises exactly that: Naga groups have fought each other as often as they have fought the state, and internal criticism reads as disloyalty inside a faction. Eg. The NSCN split of 1988 into the Isak-Muivah and Khaplang factions produced years of inter-factional killing.
      4. The obstacle is not an administrative clause: The unresolved items are a separate Naga flag and a separate Naga constitution, which are claims about identity rather than about administration. A negotiator can concede an administrative arrangement, and only the community can revise a claim about who it is.

      Challenges to the Naga peace settlement

      1. The flag and constitution demand is unresolved: The NSCN (Isak-Muivah) insists on a separate Naga flag and a separate constitution, the Yehzabo, rejected by the Centre as incompatible with Indian sovereignty. Eg. The talks declared concluded in October 2019 ended without agreement on either demand. Fix. Settle the symbolic claim as a cultural flag protected under Article 371A’s guarantee for Naga customary practice, separated from any constitutional status.
      2. The territorial claim crosses three other States: The “Greater Nagalim” demand would merge Naga inhabited areas of Manipur, Assam and Arunachal Pradesh into one unit. Eg. The Manipur Assembly has repeatedly resolved against any settlement altering the State’s boundaries. Fix. Use non-territorial autonomy, giving Naga councils outside Nagaland cultural and development powers without redrawing State boundaries.
      3. The negotiation has two competing counterparties: The Centre talks in parallel to the NSCN (Isak-Muivah) and to the Naga National Political Groups, and each rejects a settlement signed only with the other. Eg. The Working Committee of the Naga National Political Groups signed a separate Agreed Position in 2017. Fix. Convene one joint negotiating forum so a single signed text binds every group.
      4. Ceasefire ground rules are routinely breached: Cadres under ceasefire run parallel taxation in Nagaland and in Naga areas of Manipur, which keeps an armed economy alive through the negotiation. Eg. Traders and salaried employees in Dimapur pay levies to more than one faction. Fix. Publish the ceasefire monitoring group’s findings with a fixed penalty schedule for each verified breach.
      5. A text kept secret cannot be ratified: The 2015 Framework Agreement has never been published, so no legislature or public body has examined what was agreed. Eg. Nagaland’s own legislators have sought disclosure of the text on the floor of the Assembly. Fix. Table the agreed text in Parliament and in the Nagaland Assembly before signature, so ratification precedes implementation.
      6. Security law feeds the grievance the talks address: The Armed Forces (Special Powers) Act, 1958 remains in force across parts of Nagaland, sustaining the alienation a settlement is meant to end. Eg. The Oting killings of December 2021 in Mon district led the Assembly to demand repeal. Fix. Complete the district by district withdrawal already begun and move residual powers to a civil authority subject to judicial review.

      Conclusion

      The Naga settlement is stalled on claims about identity, not on administrative detail, and identity claims are revised by a community rather than conceded by a negotiator. The reconciliation work that kept six decades of talks survivable was carried by individuals with no official standing, and it has no institutional successor. A ministerial panel can reopen the file. It cannot by itself rebuild the trust that would let a signed text hold.

      “[2025, GS3, 15 marks] What are the major challenges to internal security and peace process in the North-Eastern States? Map the various peace accords and agreements initiated by the government in the past decade.”

    3. In J&K, a facade of normalcy cannot substitute for peace

      Why in the News

      An administrative order circulating in Anantnag directed government employees to take part in a Tiranga Rally, making attendance at a State sponsored event an official obligation. The order brings out the central tension in the governance of Jammu and Kashmir since August 2019, between an official account of restored normalcy and a security regime of raids, dismissals, detentions and attachments that continues without pause. Whether participation of this kind reflects public enthusiasm or administrative compulsion is the question the order leaves unanswered.

      What is Article 370 of the Constitution?

      1. What it provided: A temporary provision under Part XXI that limited Parliament’s legislative power over Jammu and Kashmir to defence, foreign affairs and communications, with other laws requiring the State government’s concurrence.
      2. The linked provision: Article 35A, added by a 1954 Presidential Order, allowed the State to define permanent residents and reserve rights in employment and property for them.
      3. What changed in 2019: Presidential Orders of August 2019 applied the whole Constitution to the State and rendered Article 370 inoperative, and Article 35A ceased to apply.
      4. The statutory change: The Jammu and Kashmir Reorganisation Act, 2019 split the State into two Union Territories, Jammu and Kashmir with a legislature, and Ladakh without one.
      5. The judicial outcome: The Supreme Court upheld the 2019 measures in In re Article 370 of the Constitution (2023) and directed that statehood be restored and elections held.
      6. The contested question: The argument advanced in this piece treats the 2019 change as an abrogation imposed without consent, and reads subsequent governance as its continuation.

      Who is an overground worker?

      1. The term: A person alleged to provide logistical support to militants, such as shelter, transport, money or information, without taking part in armed action.
      2. Why the term matters: It is not defined in statute, so the label carries no fixed evidentiary threshold and can be applied to large numbers after a single incident.

      What is preventive detention?

      1. What it is: Detention ordered by the executive to prevent an anticipated act, without any charge, trial or conviction.
      2. Its basis: Article 22(3) to 22(7) carve preventive detention out of the ordinary protections against arrest, and permit detention up to three months before an Advisory Board must review it.

      What is the United Liberation Council?

      1. What it is: The name attached to a purported threat letter reported on 12 August, described by authorities and sections of the media as an affiliate of Lashkar e Taiba.
      2. What the letter did: It reportedly named several Kashmiri Pandit government employees and carried their telephone numbers.

      Why is the Tiranga Rally order treated as symptomatic rather than isolated?

      1. The object is not the issue: The objection is not to the national flag but to the coercive form of the instruction.
      2. Obligation replaces participation: When attendance at a government event becomes an administrative duty, the resulting turnout cannot be read as evidence of public sentiment.
      3. A pattern of governance: The order fits a style of administration that has defined the region since the Union government took direct control in August 2019.
      4. Display as policy output: A visible ceremony is treated as the deliverable, so the appearance of normalcy substitutes for the conditions that would produce it.
      5. Self defeating measurement: A government that compels attendance loses the only instrument that could have told it whether sentiment had actually changed.

      What measures define administration in the Valley since 2019?

      1. Raids and investigations: Searches and investigations by multiple central and State agencies have become a recurring feature of life in the Valley.
      2. Dismissals from service: Government employees have been dismissed over alleged links with militancy or with militant sympathisers, without the ordinary departmental process.
      3. Mass detention: Thousands have been detained after militant incidents, at times under broad allegations of being overground workers.
      4. Institutional closure: Educational and charitable institutions have faced closure or restriction over alleged links with banned organisations.
      5. Property attachment: Properties worth hundreds of crores of rupees have been attached under various laws.
      6. House demolition: Homes have been demolished where a member of the family stands accused of militancy.
      7. Post incident crackdowns: Thousands were reportedly detained after the killing of a police constable in south Kashmir, and the cycle of raids, detentions and suspicion followed the killing of migrant workers.

      What does the record on the Kashmiri Pandit community show?

      1. The threat letter: Reports on 12 August described a purported threat letter naming several Kashmiri Pandit government employees along with their telephone numbers.
      2. The attributed source: The letter was attributed to the United Liberation Council, described as an affiliate of Lashkar e Taiba.
      3. The casualty count: 25 members of the community have been targeted and killed since 2019.
      4. The named victims: They include Ajay Pandita Bharti, Rakesh Pandita, Makhan Lal Bindroo, Rahul Bhat, Rajni Bala, Puran Krishan Bhat and Sanjay Sharma.
      5. Why the memory matters: For a community displaced in the 1990s, each such threat revives the circumstances of that displacement rather than reading as an isolated crime.
      6. The return condition: Return has to rest on an environment in which the community feels safe, not on participation in official ceremonies designed to demonstrate that everything is normal.

      Why do the claim of normalcy and the continuing security regime contradict each other?

      1. The official account: The government tells the rest of India that Kashmir has entered a new era of peace and normalcy.
      2. The parallel reality: Extraordinary security measures, raids, detentions, dismissals and restrictions continue to shape the everyday lives of ordinary people.
      3. Both cannot be operative: A settled peace does not require a standing apparatus of preventive detention and property attachment to maintain it.
      4. The tourist test fails: Busy markets, full hotels and traffic on the roads are what a visitor sees in a few days. They measure commerce, not security of person.
      5. What each side gains: The government gains a demonstrable output in the display. The population gains nothing it can rely on when the display ends.
      6. The unresolved reminder: The threat letter of 12 August is the demonstration that the underlying problem has not closed, whatever the ceremonies record.

      How should normalcy actually be measured?

      1. Freedom to speak: Whether ordinary people feel secure enough to speak freely without anticipating consequences.
      2. Law as protection: Whether families believe the law will protect them rather than intimidate them.
      3. A visible future: Whether young people see a future for themselves in the region.
      4. Safe return: Whether communities that have suffered displacement and violence feel safe enough to return and rebuild their lives.

      What does the security regime do to a generation born after the conflict?

      1. Who they are: Those in their teens and twenties in Kashmir were born decades after the worst years of the conflict and bear no responsibility for the violence of the 1990s.
      2. What they observe: Many grow up watching fathers, brothers, relatives and neighbours being summoned, detained or questioned.
      3. Collective punishment: Large scale detentions and punitive measures after militant attacks deepen the perception that a whole community is being punished for the acts of individuals.
      4. The asymmetry they learn: One section of society is repeatedly assured that everything is normal while another is continually asked to prove that it is not a threat.
      5. The outcome: This produces bruised memory rather than reconciliation, and bruised memory does not disappear because officials are instructed to display flags.
      6. The time horizon: Brute force can silence a street for a period. It cannot silence a generation’s memory.

      What distinctions must the state draw?

      1. Militant and citizen: The State must distinguish between a militant and an ordinary citizen, which mass categorisation after an incident destroys.
      2. Accused and convicted: It must distinguish between an accused person and a convicted person, which dismissal, attachment and demolition before trial collapse.
      3. Family member and accused: It must distinguish between a family member and the person accused of committing a crime, which punitive action against a household erases.

      Challenges to restoring political normalcy in Jammu and Kashmir

      1. Punitive measures before adjudication: Attachment and demolition operate before a court has decided guilt, so the penalty precedes the finding. e.g. property attachments running to hundreds of crores of rupees under various laws since 2019.
      2. Undefined categories in enforcement: Terms such as overground worker carry no statutory definition, so detention scales with suspicion rather than evidence. e.g. thousands reportedly detained after the killing of a police constable in south Kashmir.
      3. Employment as a security instrument: Dismissal without departmental inquiry converts government service into a lever of security policy. e.g. dismissals of employees over alleged links with militancy since 2019.
      4. Targeted killings of minorities: The safety of returning and resident minority employees remains unsecured. e.g. 25 members of the Kashmiri Pandit community killed since 2019 and a threat letter naming employees on 12 August 2026.
      5. Statehood still pending: Restoration of full statehood remains incomplete, leaving an elected government without control over police and public order. e.g. the Supreme Court’s 2023 direction to restore statehood at the earliest.
      6. Space for civil society: Closure of educational and charitable institutions removes the mediating layer between the State and the population. e.g. restrictions on institutions over alleged links with banned organisations.
      7. Cross border sponsorship: Infiltration and external support keep the security justification alive irrespective of local political settlement. e.g. attacks on migrant workers in the Valley followed by area wide crackdowns.
      8. Economic dependence on tourism: A single security incident removes the region’s main visible income source. e.g. the collapse of bookings in the Valley after major attacks on visitors.

      Conclusion

      The administrative order in Anantnag is a small instrument, and its significance lies in what it substitutes for. Kashmir needs healing built on dignity, justice, security and dialogue, and healing cannot be produced by an order requiring attendance. A facade of normalcy may impress visitors, and it cannot substitute for real peace. The measure of whether the situation has changed is whether the State begins to distinguish the militant from the citizen and the accused from the convict, not whether the flag is displayed on schedule.

      Jammu and Kashmir after 2019

      1. Constitutional status: The former State was reorganised on 31 October 2019 into the Union Territory of Jammu and Kashmir, with a legislature, and the Union Territory of Ladakh, without one.
      2. Political timeline: Assembly elections were held in 2024, the first since 2014, restoring an elected government to the Union Territory.
      3. Statehood question: Full statehood has not been restored. Public order and police remain with the Union government under the Reorganisation Act.
      4. Security geography: The region has a Line of Control of about 740 km with Pakistan and a Line of Actual Control segment with China in Ladakh.
      5. Displacement history: Large scale displacement of the Kashmiri Pandit community occurred from 1990, and return and rehabilitation remains an unfinished policy objective.
      6. Economy: Horticulture, handicrafts and tourism dominate the economy, all of which are directly sensitive to security incidents.

      Constitutional Framework Governing Jammu and Kashmir and Security Measures

      1. Article 1: Declares India a Union of States and makes the territories in the First Schedule part of that Union.
      2. Article 3: Empowers Parliament to form new States and Union Territories and to alter boundaries, the provision used for the 2019 reorganisation.
      3. Article 370: The temporary provision governing the State’s relationship with the Union, rendered inoperative by the Presidential Orders of August 2019.
      4. Article 14: Requires equality before the law, which limits arbitrary classification of persons or communities in security administration.
      5. Article 19: Guarantees freedom of speech, assembly, association and movement, subject to reasonable restrictions on the specified grounds.
      6. Article 21: Protects life and personal liberty, and requires that any deprivation follow a procedure that is fair, just and reasonable.
      7. Article 22: Provides protections on arrest, and separately permits preventive detention with an Advisory Board review after three months.
      8. Article 239A read with the Reorganisation Act: Provides the framework for a legislature in a Union Territory, with police and public order reserved to the Union in the case of Jammu and Kashmir.
      9. Article 355: Places a duty on the Union to protect every State against external aggression and internal disturbance.

      Laws and Rules Governing Security Administration in Jammu and Kashmir

      1. Jammu and Kashmir Reorganisation Act, 2019: Created the two Union Territories and set out the distribution of legislative and executive power between them and the Union.
      2. Unlawful Activities (Prevention) Act, 1967: The principal anti terrorism statute, providing for banning organisations, designating individuals and attaching proceeds of terrorism.
      3. Jammu and Kashmir Public Safety Act, 1978: Permits preventive detention for up to two years on grounds of security of the State or maintenance of public order.
      4. Armed Forces (Jammu and Kashmir) Special Powers Act, 1990: Confers search, arrest and use of force powers on the armed forces in areas declared disturbed, with prior sanction required for prosecution.
      5. National Investigation Agency Act, 2008: Establishes the central counter terrorism investigation agency and defines the scheduled offences it can take over.
      6. Prevention of Money Laundering Act, 2002: Provides for provisional attachment of property representing proceeds of crime, used in terror financing investigations.
      7. Bharatiya Nagarik Suraksha Sanhita, 2023: Replaces the Code of Criminal Procedure, 1973 and carries the powers to issue prohibitory orders and regulate assemblies.

      Back2Basics: In re Article 370 of the Constitution (2023)

      1. What it was: A Constitution Bench judgment of the Supreme Court on the validity of the Presidential Orders of August 2019 and the Jammu and Kashmir Reorganisation Act, 2019.
      2. Holding on sovereignty: The Court held that Jammu and Kashmir retained no element of internal sovereignty after its accession and the adoption of the Constitution.
      3. Holding on Article 370: Article 370 was held to be a temporary provision, and the President’s power to declare it inoperative was held to survive the dissolution of the Constituent Assembly of the State.
      4. Holding on Article 35A: The Court held that the removal of Article 35A did not violate the fundamental rights framework.
      5. Direction on statehood: The Court directed that the statehood of Jammu and Kashmir be restored at the earliest, while upholding the carving out of Ladakh.
      6. Direction on elections: The Election Commission was directed to hold Assembly elections by 30 September 2024.
      7. Additional direction: The Court recommended a truth and reconciliation commission to examine human rights violations in the region since the 1980s.

      Government Initiatives

      1. Prime Minister’s Development Package, 2015: An outlay of about Rs 80,068 crore covering road, power, health, tourism and rehabilitation projects in the region.
      2. Prime Minister’s Package for Kashmiri Migrants: Provides government jobs and transit accommodation to support the return of displaced Kashmiri Pandit families to the Valley.
      3. Udaan and Himayat: Skill development and placement schemes for youth of the region, run through the National Skill Development Corporation and the rural livelihoods mission.
      4. Prime Minister’s Special Scholarship Scheme: Funds higher education outside the region for students from Jammu and Kashmir and Ladakh.
      5. Security Related Expenditure scheme: Reimburses the Union Territory for expenditure on security, relief and rehabilitation of surrendered militants and civilian victims.
      6. Operation Sadbhavana and the Civic Action Programme: Army and central armed police force programmes that fund schools, medical camps and community infrastructure in border and affected areas.
      7. New Central Sector Scheme for Industrial Development, 2021: An outlay of about Rs 28,400 crore of capital and interest incentives to attract manufacturing investment to the Union Territory.

      Key Facts about Jammu and Kashmir

      1. Reorganisation date: The two Union Territories came into existence on 31 October 2019, observed as National Unity Day.
      2. Representation: The Union Territory of Jammu and Kashmir returns five members to the Lok Sabha and Ladakh returns one.
      3. Delimitation: The 2022 delimitation raised Assembly seats to 90, with 43 in the Jammu division and 47 in the Kashmir division, besides seats reserved for Scheduled Castes and Scheduled Tribes for the first time.
      4. Reservation extension: Central laws on reservation, including for Scheduled Tribes such as the Gujjar, Bakarwal, Gaddi and Sippi communities, now apply to the Union Territory.
      5. Boundaries: The region borders Pakistan along the Line of Control and China along the Line of Actual Control in Ladakh.
      6. Geography: The Pir Panjal range separates the Jammu division from the Kashmir Valley, and the Jhelum, Chenab and Indus are the principal rivers.
      7. Treaty link: The Indus Waters Treaty of 1960 governs the use of the western rivers that flow through the region, and India placed it in abeyance in 2025.

      Challenges in Internal Security Management

      1. Balancing force and consent: Security operations that succeed tactically can widen alienation and cost the political objective. e.g. area wide cordon and search operations following a single militant incident.
      2. Preventive detention without adjudication: Detention laws allow long custody without trial, which produces grievance even where the intelligence is sound. e.g. detention up to two years permitted under the Jammu and Kashmir Public Safety Act, 1978.
      3. Radicalisation through digital channels: Recruitment and propaganda have moved online, beyond the reach of physical area domination. e.g. encrypted messaging used for handler communication in recent militancy cases.
      4. Terror financing: Funding routes through hawala, cryptocurrency and front organisations are hard to interdict. e.g. investigations into non governmental organisations and trusts by central agencies since 2017.
      5. Rehabilitation of surrendered cadre: Without livelihood and social acceptance, surrendered militants relapse. e.g. surrender and rehabilitation policies across the Northeast and Left Wing Extremism affected districts.
      6. Centre and State coordination: Multiple agencies operating in the same theatre create gaps in intelligence handover. e.g. the multi agency centre framework created after the 2008 Mumbai attacks.
      7. Human rights accountability: Sanction requirements delay prosecution in cases of alleged excess, which erodes trust in the process. e.g. the prior sanction requirement for prosecuting armed forces personnel.
      8. Border management technology: Infiltration continues where terrain defeats physical fencing. e.g. tunnels detected along the international boundary in the Jammu sector.

      Way Forward

      1. Restore statehood on a stated timeline: Give the elected government responsibility for public order so accountability for security decisions is politically located.
      2. Individualise security action: Confine dismissal, attachment and demolition to persons against whom a case is established, with reasons recorded and an appeal available.
      3. Institutionalise dialogue: Create a standing channel with elected representatives, civil society and displaced communities rather than event driven engagement.
      4. Secure minority employees: Provide verified protection and posting choices to Kashmiri Pandit employees rather than requiring presence at ceremonial events.
      5. Time bound trials: Expand special court capacity so that persons in preventive detention are either charged and tried or released.
      6. Youth employment at scale: Convert skill schemes into placement linked outcomes so that the young have a visible economic route.
      7. Independent grievance mechanism: Set up an accessible body to examine complaints of excess, following the reconciliation mechanism the Supreme Court recommended in 2023.

      “[2023, GS3, 10 marks] Winning of ‘Hearts and Minds’ in terrorism-affected areas is an essential step in restoring the trust of the population. Discuss the measures adopted by the Government in this respect as part of the conflict resolution in Jammu and Kashmir.”

    4. March to July, Govt sent one blocking order to social media firms every minute

      Why in the News

      Nearly 1.95 lakh state backed content blocking orders were sent to Instagram, Facebook and YouTube between March and July 2026, an average of one every 68 seconds, against a daily average of six in the preceding year. Most were routed through the Sahyog portal of the Ministry of Home Affairs and issued under Section 79(3)(b) of the Information Technology Act, 2000, the safe harbour condition, rather than the dedicated blocking power in Section 69A. The surge, combined with automated execution by the platform, converts a conditional legal duty into unconditional compliance.

      What is the Sahyog portal?

      1. What it is: A platform built by the Ministry of Home Affairs through which central and State agencies send content blocking notices to online intermediaries.
      2. Who uses it: Various central and State law enforcement and government agencies issue notices, and all three major social media companies have joined the portal.
      3. Legal hook: Notices are issued under Section 79(3)(b) of the Information Technology Act, 2000, the provision that conditions an intermediary’s legal immunity.
      4. What it replaced: It centralises what were previously scattered notices from individual police units and departments into a single automated channel.
      5. Scale of use: Between October 2024 and October 2025 the portal carried 2,312 blocking orders to 19 online platforms, a daily average of six.
      6. What one order covers: A single blocking order can cover hundreds of individual pieces of content or accounts, so the order count understates the volume removed.

      What is safe harbour under Section 79 of the Information Technology Act, 2000?

      1. The immunity: Section 79 protects an intermediary from liability for content that its users post, provided it does not initiate, select or modify that content.
      2. The condition: Section 79(3)(b) withdraws that immunity if the intermediary fails to remove unlawful material after receiving actual knowledge or a government notification.

      What is Section 69A of the Information Technology Act, 2000?

      1. The power: It allows the Union government to direct the blocking of public access to information in the interest of sovereignty, defence, security of the State, friendly relations, public order or the prevention of a cognisable offence.
      2. The safeguards: Blocking under it follows the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009, which require a committee review and reasons in writing.

      What is actual knowledge in intermediary liability?

      1. The test: Actual knowledge is the point at which an intermediary is informed of specific unlawful content and becomes obliged to act on it.
      2. Where it comes from: The Supreme Court in Shreya Singhal v. Union of India (2015) read down Section 79(3)(b) so that actual knowledge means a court order or a government notification, not a private complaint.

      What is an Application Programming Interface?

      1. What it is: A defined interface that allows one software system to send instructions directly to another without a person operating either end.
      2. Its use here: Meta has integrated its interface with the Sahyog portal, so a flagged item uploaded to the portal is removed from its platforms automatically.

      What does the scale of the blocking orders show?

      1. Total volume: Nearly 1.95 lakh blocking orders in five months, about 1,275 a day, or one every 68 seconds.
      2. Instagram: Around 1,00,000 orders, just over half of the total, and the platform on which the student protests were most visible.
      3. Facebook: Around 80,000 orders.
      4. YouTube: Nearly 15,000 orders.
      5. Concentration: Meta owned platforms received roughly nine out of every ten orders issued to the three companies.
      6. The baseline: The comparable figure for October 2024 to October 2025 was 2,312 orders across 19 platforms, a daily average of six.
      7. Official record: The Ministry of Home Affairs annual report for 2024 and 2025 recorded a little over 1.11 lakh pieces of suspicious online content blocked until March 2025 under Section 79(3)(b).
      8. Comparative removals: Meta reported removing over 23 million pieces of content in Indonesia between July and December 2025 against about 41,000 in India, which had already doubled from 28,000 in the first half of that year.
      9. User base: India has over 600 million social media users, with an estimated 10 million to 100 million posts a day.

      What changed in February 2026?

      1. The amendment: The Ministry of Electronics and Information Technology notified amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
      2. The new deadline: Content must now be removed within two to three hours, against the earlier window of 24 to 36 hours.
      3. Added conditions: The amended rule requires that an order come from an officer of a prescribed rank and state its reasons.
      4. The compliance effect: A window of two to three hours makes case by case human review commercially impossible at Indian volumes.
      5. The platform response: Meta integrated its interface with the Sahyog portal so removal happens machine to machine, without separate human review.
      6. What was removed: Automation eliminates the room for the company to review or contest a directive before complying with it.

      Why does the shift from Section 69A to Section 79(3)(b) matter?

      1. Different purpose: Section 69A is a dedicated blocking power. Section 79(3)(b) is a condition attached to an immunity, not a power to censor.
      2. Different safeguards: Section 69A orders pass through a review committee under the 2009 Rules and carry recorded reasons. Section 79(3)(b) notices carry no equivalent statutory committee.
      3. Different issuing authority: Section 69A is exercised by the Union government. Section 79(3)(b) notices come from a wide range of central and State agencies through the portal.
      4. Different subject matter: Section 69A is largely confined to national security and public order. The portal route is used for a far wider category of content.
      5. The legal consequence: The intermediary that refuses a Section 79(3)(b) notice does not face a penalty. It loses immunity for all user content, which is a far larger risk.
      6. What that produces: The threat of losing safe harbour makes refusal irrational, so the conditional structure operates as a command.

      What content was targeted?

      1. The protest period: The five month window covered the student protests against examination paper leaks at Jantar Mantar in Delhi, which began in early June and were called off on 25 July after the resignation of the Union Education Minister.
      2. Official acknowledgement: A senior government official stated that a considerable share of the orders were issued as the protests gathered momentum, particularly on Instagram.
      3. Protest content: Users reported the removal of posts supporting the student protests.
      4. Policy criticism: Posts criticising the government’s ethanol fuel blending policy were among those blocked.
      5. Electoral content: Content relating to the West Bengal Assembly elections was also removed.
      6. Synthetic media: Deepfakes formed a further category among the removals.
      7. Political speech: The national convenor of a national political party stated that some of his Instagram posts were blocked in India.

      Where does automated compliance turn against the legal design?

      1. The doctrinal problem: Actual knowledge requires that someone at the company know of the content and assess the order. An interface that executes takedowns automatically has no knowledge at all.
      2. No verification of authority: Nobody at the company checks whether the order comes from an officer of the prescribed rank or states the reasons the amended rule requires.
      3. Conditional becomes unconditional: Machine to machine execution converts a conditional legal duty into unconditional compliance, which is the substance of the objection raised by the Internet Freedom Foundation.
      4. The state interest on the other side: Coordinated disinformation, deepfakes and incitement travel faster than any human review cycle, which is the case for a short deadline.
      5. The unequal risk: The cost of over removal falls on the user, who has no notice and no appeal. The cost of under removal falls on the company as loss of immunity for all content.
      6. Notice denied: Meta informs users which State authority sent a request in most markets, but not in India, citing legal obligations and regulatory considerations.
      7. No proportionality check: One order can cover hundreds of accounts, so a single instruction can remove speech at a scale no court has examined.

      Challenges to the content blocking regime

      1. Absence of a review committee: Orders under Section 79(3)(b) carry none of the committee scrutiny that Section 69A orders pass through. e.g. the 2009 Blocking Rules committee has no counterpart for portal notices.
      2. Secrecy of orders: Blocking directions are treated as confidential, so neither the user nor the public sees the reasoning. e.g. Rule 16 of the 2009 Blocking Rules requires confidentiality of complaints and actions taken.
      3. No pre decisional hearing for the user: The person whose speech is removed is not heard before removal and often not informed after it. e.g. account holders learning of removal only from the platform’s generic notification.
      4. Chilling effect on lawful speech: Platforms over comply to protect immunity, which removes lawful criticism along with unlawful content. e.g. removal of posts criticising the ethanol blending policy during the same five month window.
      5. Federal multiplication of issuers: A wide set of central and State agencies can issue notices, so there is no single accountable authority. e.g. the portal carried orders to 19 platforms from multiple agencies in the previous year.
      6. Litigation uncertainty: Platforms that challenge the portal route face the loss of immunity while the case runs. e.g. X Corporation’s challenge to the Sahyog portal before the Karnataka High Court, dismissed in 2025.
      7. Encryption and traceability conflict: The traceability requirement in the 2021 Rules cannot be met without weakening end to end encryption. e.g. the pending challenge by WhatsApp to Rule 4(2) of the 2021 Rules.
      8. Capacity asymmetry: Smaller Indian intermediaries cannot build automated compliance systems and face the same deadlines. e.g. the two to three hour removal window applies to every significant social media intermediary.

      Conclusion

      The volume of blocking orders has risen from six a day to about 1,275 a day, and the legal route has moved from a dedicated blocking power with statutory safeguards to a safe harbour condition that carries none. Automation completes the shift, because a system that removes content without any person reading the order cannot satisfy the actual knowledge standard the Supreme Court built the provision around. The amended rules are in force and the orders continue. The unresolved question is whether Section 79(3)(b) can lawfully function as a general censorship channel when the Constitution requires every restriction on speech to be traced to a specific ground and a recorded reason.

      “[2024, GS3, 15 marks] Social media and encrypting messaging services pose a serious security challenge. What measures have been adopted at various levels to address the security implications of social media? Also suggest any other remedies to address the problem.”

    5. [7th August 2026] The Hindu OpED: Stop the scam: Digital arrest menace

      Why in the News

      The Supreme Court passed an order on 4 August 2026 on the digital arrest scam. It directed banks, states and regulators toward faster action on mule accounts and cyber fraud. The scams persist because they are run largely from overseas hubs.

      What is the digital arrest scam?

      1. Definition: Fraudsters impersonate authorities and coerce victims into transferring money under threat of fake arrest. There is no legal basis or process called digital arrest.
      2. Targets: Older victims fall prey through deference to authority and fear of legal trouble.
      3. New targets: Scammers now also target youth and professionals, and senior citizens whom advisories have not reached.

      Why are digital arrests keep happening?

      1. Human Psychology & Social Engineering: Cybercriminals use social engineering tactics to manipulate people into revealing sensitive information. Fraudsters also exploit emotions like fear (threatening legal action), excitement (fake lottery wins), or urgency (fake emergency fund requests). Cybercriminals often impersonate trusted sources such as banks, government agencies, or even close friends.
      2. Weak Cybersecurity Practices: Common weaknesses include weak password and credentials use, unpatched software and system and poor security hygiene.
      3. Rapidly Evolving Cybercrime Techniques: Cybercriminals constantly evolve their methods to stay ahead of security measures.
      4. Digital Payments & Financial Fraud Risks: With the rise of digital transactions, cybercriminals have developed sophisticated methods to exploit online payment systems like fake UPI requests & QR codes, card skimming & SIM swaps and crypto & investment scams.
      5. Dark Web & Cybercrime Networks: The dark web serves as a marketplace for stolen data, malware tools, and illegal activities. Cybercrime has become an organized industry where criminals buy and sell stolen data and identity theft, organised cyber-crime syndicates and also offer Ransomware-as-a-Service (RaaS) as well.
      6. Lack of Strong Cyber Laws & Enforcement: Despite increasing cyber threats, many scams go unpunished due to slow law enforcements response, cross border crime challenges and lack of cyber crime awareness and policies.

      What did the Supreme Court order?

      1. Debit holds: It directed the Reserve Bank of India (RBI) to circulate a standard operating procedure for temporary debit holds on mule accounts.
      2. State action: States must notify cybercrime coordination centres and operationalise electronic Zero FIRs.
      3. Compensation: An inter departmental committee must examine a victim compensation framework.
      4. Data cited: Complaints on the National Cyber Crime Reporting Portal fell from 1,23,672 in 2024 to 16,377 in the first half of 2026.
      5. Recovery: Money was restored in 36,290 cases involving Rs 18.05 crore.

      What are the key terms in the response?

      1. Indian Cybercrime Coordination Centre (I4C): the nodal body coordinating action against cyber fraud and running the reporting portal.
      2. Mule account: a bank account used to receive and move fraud proceeds across states.
      3. Zero FIR: a First Information Report that can be filed at any police station regardless of jurisdiction.
      4. MuleHunter.AI: a detection system used in over 20 banks to flag mule accounts.

      Why do these scams persist despite falling complaints?

      1. Nimble methods: Fraudsters route calls through SIM boxes to mask origin and appear as Indian numbers.
      2. Deepfakes: They deploy deepfakes on video calls to dupe victims and stay untraceable.
      3. Few convictions: Convictions are rare as many schemes are run from overseas scam compounds.
      4. Overseas hubs: Compounds operate in Myanmar, the wider Golden Triangle and Cambodia, some with official patronage.
      5. Trafficking link: Indians are trafficked and coerced to run digital crimes against fellow citizens.

      Conclusion

      Detection systems and swift account freezes limit the damage even when perpetrators escape conviction. The core problem lies in overseas scam compounds beyond domestic law enforcement reach. New Delhi must use diplomatic pressure with China, the United States and ASEAN to compel host countries to act.

      Back2Basics

      Electronic-Zero FIR (e-zero FIR)

      An e-Zero FIR is an automated digital system in India that converts high-value cyber financial fraud complaints (above ₹10 lakh) filed via the National Cyber Crime Reporting Portal or the 1930 helpline directly into a Zero FIR. It eliminates jurisdictional delays during the critical “golden hour” for fund recovery

      Key Features and Workflow

      1. Automatic Registration: Eligible financial fraud reports trigger an instant e-Zero FIR without requiring an initial physical station visit.
      2. System Integration: Combines the I4C portal, state e-FIR mechanisms, and the NCRB’s Crime and Criminal Tracking Network & Systems (CCTNS).
      3. Auto-Routing: The system instantly routes the electronic document to the correct territorial cybercrime station based on the victim’s location.
      4. Mandatory Follow-Up: Complainants must visit the designated local police station within three days to sign and convert the e-Zero FIR into a regular FIR under the Bharatiya Nagarik Suraksha Sanhita (BNSS).

      PYQ Relevance

      [UPSC 2022] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

      Linkage: The PYQ tests India’s cyber security framework and response to cybercrime. The article highlights recent measures to strengthen India’s response to digital arrest scams and cyber fraud.

    6. Supreme Court orders SOPs against digital arrest cyber fraud and mule accounts

      Why in the News

      The Supreme Court directed the Centre, States, and Union Territories to implement Standard Operating Procedures (SOPs) within four weeks to curb digital arrest cyber fraud, including freezing mule accounts, strengthening grievance redressal, and improving cybercrime coordination.

      What is a Digital Arrest Scam?

      • A cyber fraud where scammers impersonate police or enforcement agencies through video/audio calls.
      • Victims are falsely told they are under “digital arrest” and coerced into transferring money.

      What is a Mule Account?

      • A bank account used to receive and transfer proceeds of cyber fraud.
      • Often opened by unsuspecting or paid individuals.
      • Banks can impose temporary debit holds to prevent fraudulent withdrawals.

      What is the Indian Cyber Crime Coordination Centre (I4C)?

      • A nodal agency under the Ministry of Home Affairs (MHA) for coordinating India’s response to cybercrime.
      • Operates the National Cyber Crime Reporting Portal (NCRP) and the 1930 Cyber Helpline.

      Supreme Court Directions

      • Reserve Bank of India (RBI) to issue SOPs for temporary debit holds on mule accounts.
      • States/UTs to operationalise:
        • State Cyber Crime Coordination Centres.
        • e-Zero FIR mechanism.
      • Strengthen grievance redressal, money restoration, and public awareness.

      Challenges

      • Cross-border cybercrime networks.
      • Rapid movement of funds through mule accounts and cryptocurrencies.
      • Weak inter-agency coordination.
      • SIM spoofing and fake identities.
      • Low public awareness, especially among the elderly.

      Value Addition

      e-Zero FIR

      • Enables registration of a cybercrime complaint without jurisdictional barriers.
      • The complaint is later transferred to the appropriate police station.

      Citizen Response to Financial Cyber Fraud

      • Call 1930 immediately.
      • Report the incident on the National Cyber Crime Reporting Portal (NCRP).
      • Early reporting increases the chances of freezing fraudulent transactions.

      Back2Basics: Indian Cyber Crime Coordination Centre (I4C)

      • Parent Ministry: Ministry of Home Affairs (MHA).
      • Established: 2020.
      • Key Components:
        • National Cyber Crime Reporting Portal (NCRP).
        • 1930 Financial Cyber Fraud Helpline.
      • Mandate: Coordinate law enforcement, banks, telecom operators, and other stakeholders to prevent and investigate cybercrime.

      “[2017] In India, it is legally mandatory for which of the following to report on cyber security incidents?
      1. Service providers
      2. Data Centres
      3. Body corporate
      (a) 1 only
      (b) 1 and 2 only
      (c) 3 only
      (d) 1, 2 and 3

    7. The legal patchwork facing doxxing victims in India

      Why in the News?

      The online targeting of women protesters has highlighted the absence of a dedicated law against doxxing in India, forcing victims to rely on scattered legal provisions.

      What is Doxxing?

      • Doxxing is the unauthorised public disclosure of a person’s private or personal information online to harass, intimidate or threaten them.
      • It can lead to stalking, identity theft, threats and physical harm.

      Existing Legal Framework

      • Bharatiya Nyaya Sanhita (BNS), 2023: Provisions relating to stalking, criminal intimidation and harassment.
      • Information Technology (IT) Act, 2000: Covers privacy violations and unauthorised disclosure of personal information.
      • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: Prescribe due diligence obligations for online platforms and provide safe harbour protection.

      Challenges

      • No specific offence for doxxing under Indian law.
      • Delays in content removal and prosecution.
      • Difficulty in fixing platform liability due to safe harbour provisions.
      • Rising digital threats to privacy and safety.

      Prelims Facts

      • The Digital Personal Data Protection (DPDP) Act, 2023 governs the processing of personal digital data but does not specifically criminalise doxxing.
      • Safe Harbour under Section 79 of the Information Technology (IT) Act, 2000 protects intermediaries from liability if they comply with due diligence requirements.

      [2024] Under which of the following Articles of the Constitution of India, has the Supreme Court of India placed the Right to Privacy?

      (a) Article 15

      (b) Article 16

      (c) Article 19

      (d) Article 21