💥Join UPSC 2027,2028 Mentorship (August Batch) + XFactor Notes & Microthemes PDF

Subject: Cyber Security

  • [7th August 2026] The Hindu OpED: Stop the scam: Digital arrest menace

    Why in the News

    The Supreme Court passed an order on 4 August 2026 on the digital arrest scam. It directed banks, states and regulators toward faster action on mule accounts and cyber fraud. The scams persist because they are run largely from overseas hubs.

    What is the digital arrest scam?

    1. Definition: Fraudsters impersonate authorities and coerce victims into transferring money under threat of fake arrest. There is no legal basis or process called digital arrest.
    2. Targets: Older victims fall prey through deference to authority and fear of legal trouble.
    3. New targets: Scammers now also target youth and professionals, and senior citizens whom advisories have not reached.

    Why are digital arrests keep happening?

    1. Human Psychology & Social Engineering: Cybercriminals use social engineering tactics to manipulate people into revealing sensitive information. Fraudsters also exploit emotions like fear (threatening legal action), excitement (fake lottery wins), or urgency (fake emergency fund requests). Cybercriminals often impersonate trusted sources such as banks, government agencies, or even close friends.
    2. Weak Cybersecurity Practices: Common weaknesses include weak password and credentials use, unpatched software and system and poor security hygiene.
    3. Rapidly Evolving Cybercrime Techniques: Cybercriminals constantly evolve their methods to stay ahead of security measures.
    4. Digital Payments & Financial Fraud Risks: With the rise of digital transactions, cybercriminals have developed sophisticated methods to exploit online payment systems like fake UPI requests & QR codes, card skimming & SIM swaps and crypto & investment scams.
    5. Dark Web & Cybercrime Networks: The dark web serves as a marketplace for stolen data, malware tools, and illegal activities. Cybercrime has become an organized industry where criminals buy and sell stolen data and identity theft, organised cyber-crime syndicates and also offer Ransomware-as-a-Service (RaaS) as well.
    6. Lack of Strong Cyber Laws & Enforcement: Despite increasing cyber threats, many scams go unpunished due to slow law enforcements response, cross border crime challenges and lack of cyber crime awareness and policies.

    What did the Supreme Court order?

    1. Debit holds: It directed the Reserve Bank of India (RBI) to circulate a standard operating procedure for temporary debit holds on mule accounts.
    2. State action: States must notify cybercrime coordination centres and operationalise electronic Zero FIRs.
    3. Compensation: An inter departmental committee must examine a victim compensation framework.
    4. Data cited: Complaints on the National Cyber Crime Reporting Portal fell from 1,23,672 in 2024 to 16,377 in the first half of 2026.
    5. Recovery: Money was restored in 36,290 cases involving Rs 18.05 crore.

    What are the key terms in the response?

    1. Indian Cybercrime Coordination Centre (I4C): the nodal body coordinating action against cyber fraud and running the reporting portal.
    2. Mule account: a bank account used to receive and move fraud proceeds across states.
    3. Zero FIR: a First Information Report that can be filed at any police station regardless of jurisdiction.
    4. MuleHunter.AI: a detection system used in over 20 banks to flag mule accounts.

    Why do these scams persist despite falling complaints?

    1. Nimble methods: Fraudsters route calls through SIM boxes to mask origin and appear as Indian numbers.
    2. Deepfakes: They deploy deepfakes on video calls to dupe victims and stay untraceable.
    3. Few convictions: Convictions are rare as many schemes are run from overseas scam compounds.
    4. Overseas hubs: Compounds operate in Myanmar, the wider Golden Triangle and Cambodia, some with official patronage.
    5. Trafficking link: Indians are trafficked and coerced to run digital crimes against fellow citizens.

    Conclusion

    Detection systems and swift account freezes limit the damage even when perpetrators escape conviction. The core problem lies in overseas scam compounds beyond domestic law enforcement reach. New Delhi must use diplomatic pressure with China, the United States and ASEAN to compel host countries to act.

    Back2Basics

    Electronic-Zero FIR (e-zero FIR)

    An e-Zero FIR is an automated digital system in India that converts high-value cyber financial fraud complaints (above ₹10 lakh) filed via the National Cyber Crime Reporting Portal or the 1930 helpline directly into a Zero FIR. It eliminates jurisdictional delays during the critical “golden hour” for fund recovery

    Key Features and Workflow

    1. Automatic Registration: Eligible financial fraud reports trigger an instant e-Zero FIR without requiring an initial physical station visit.
    2. System Integration: Combines the I4C portal, state e-FIR mechanisms, and the NCRB’s Crime and Criminal Tracking Network & Systems (CCTNS).
    3. Auto-Routing: The system instantly routes the electronic document to the correct territorial cybercrime station based on the victim’s location.
    4. Mandatory Follow-Up: Complainants must visit the designated local police station within three days to sign and convert the e-Zero FIR into a regular FIR under the Bharatiya Nagarik Suraksha Sanhita (BNSS).

    PYQ Relevance

    [UPSC 2022] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

    Linkage: The PYQ tests India’s cyber security framework and response to cybercrime. The article highlights recent measures to strengthen India’s response to digital arrest scams and cyber fraud.

  • Supreme Court orders SOPs against digital arrest cyber fraud and mule accounts

    Why in the News

    The Supreme Court directed the Centre, States, and Union Territories to implement Standard Operating Procedures (SOPs) within four weeks to curb digital arrest cyber fraud, including freezing mule accounts, strengthening grievance redressal, and improving cybercrime coordination.

    What is a Digital Arrest Scam?

    • A cyber fraud where scammers impersonate police or enforcement agencies through video/audio calls.
    • Victims are falsely told they are under “digital arrest” and coerced into transferring money.

    What is a Mule Account?

    • A bank account used to receive and transfer proceeds of cyber fraud.
    • Often opened by unsuspecting or paid individuals.
    • Banks can impose temporary debit holds to prevent fraudulent withdrawals.

    What is the Indian Cyber Crime Coordination Centre (I4C)?

    • A nodal agency under the Ministry of Home Affairs (MHA) for coordinating India’s response to cybercrime.
    • Operates the National Cyber Crime Reporting Portal (NCRP) and the 1930 Cyber Helpline.

    Supreme Court Directions

    • Reserve Bank of India (RBI) to issue SOPs for temporary debit holds on mule accounts.
    • States/UTs to operationalise:
      • State Cyber Crime Coordination Centres.
      • e-Zero FIR mechanism.
    • Strengthen grievance redressal, money restoration, and public awareness.

    Challenges

    • Cross-border cybercrime networks.
    • Rapid movement of funds through mule accounts and cryptocurrencies.
    • Weak inter-agency coordination.
    • SIM spoofing and fake identities.
    • Low public awareness, especially among the elderly.

    Value Addition

    e-Zero FIR

    • Enables registration of a cybercrime complaint without jurisdictional barriers.
    • The complaint is later transferred to the appropriate police station.

    Citizen Response to Financial Cyber Fraud

    • Call 1930 immediately.
    • Report the incident on the National Cyber Crime Reporting Portal (NCRP).
    • Early reporting increases the chances of freezing fraudulent transactions.

    Back2Basics: Indian Cyber Crime Coordination Centre (I4C)

    • Parent Ministry: Ministry of Home Affairs (MHA).
    • Established: 2020.
    • Key Components:
      • National Cyber Crime Reporting Portal (NCRP).
      • 1930 Financial Cyber Fraud Helpline.
    • Mandate: Coordinate law enforcement, banks, telecom operators, and other stakeholders to prevent and investigate cybercrime.

    “[2017] In India, it is legally mandatory for which of the following to report on cyber security incidents?
    1. Service providers
    2. Data Centres
    3. Body corporate
    (a) 1 only
    (b) 1 and 2 only
    (c) 3 only
    (d) 1, 2 and 3

  • AI and cyber, the double helix of today’s security threats

    Why in the News?

    Artificial Intelligence (AI) and cyber threats have merged into a single, compounding security risk that traditional defences cannot contain. AI-powered malware now adapts on its own, autonomous agents undermine established protocols, and the newest models can find and exploit vulnerabilities faster than humans. The deeper conflict is that the technology capable of defending systems is the same technology enabling attacks, while the rules to govern it remain undeveloped.

    What is Agentic AI?

    1. Definition: Agentic AI refers to systems that act autonomously to pursue goals, taking sequential actions with minimal human prompting. It differs from Generative AI, which produces content in response to a user request.
    2. Significance: Autonomous agents can perform complex tasks once reserved for people. As agentic operations grow more sophisticated, threat levels rise further.

    Working

    1. Perception: Gathers real-time data from tools, screens, or sensors.
    2. Reasoning: Uses large models to break a big goal into small steps.
    3. Action: Uses external software or APIs to complete the work.
    4. Learning: Adapts its future choices based on past results

    What is Zero Trust?

    1. Definition: Zero Trust is a security model that assumes no user or device is trustworthy by default, verifying every access request continuously. It replaces the older assumption that anything inside a network is safe.
    2. Erosion: Malicious autonomous agents are positioned to undermine Zero Trust protocols. This aggravates insider threat vectors within organisations.

    How is AI transforming cyber threats?

    1. Adaptive malware: AI-powered malware can adapt and evolve in response to its environment. This makes it harder for traditional anti-virus software to detect. Example: Self-Modifying Code: Rewrites internal structures or instructions continuously to change file fingerprints
    2. Vulnerability discovery: The latest AI systems can detect zero-day vulnerabilities across major operating systems. A zero-day is a software flaw unknown to the vendor and unpatched at the time of attack.
    3. Capability transfer: Newer AI machines let rogue groups demonstrate capabilities once limited to nation states. This lowers the barrier to sophisticated attacks.
    4. Dual-use warning: The World Economic Forum warns AI will strengthen cyber defences while also enabling more sophisticated automated attacks. The same model can render current Zero Trust protocols ineffective.

    How is AI reshaping warfare?

    1. Precision targeting: AI-powered smart systems detect, track and predict missile trajectories with high accuracy. This was demonstrated in recent conflicts.
    2. Autonomous munitions: Systems can independently identify and strike targets. This shifts elements of the kill decision away from human operators.
    3. Multi-source intelligence: AI can fuse intelligence from photos, text, radio and electromagnetic signals. This denies adversaries a tactical advantage.
    4. Cognitive core: Automated analytics platforms (such as Palantir Technologies or military software like Ukraine’s Delta) manage vast data inputs to recommend strikes and run logistics.
    5. Drone accuracy: Software upgrades have pushed first-person view drone hit rates from roughly 30–50% up to 80%.

    Where does the deeper tension lie?

    1. Concentrated power: A handful of Western firms hold the most advanced models and behave as owners of future technology. Control over the mightiest technology is concentrating in a few private hands.
    2. Governance vacuum: AI has the potential to become the dominant source of military and economic power. The rules to govern it remain in a fledgling state.
    3. Escalating rivalry: The United States has accused China of stealing from its most advanced language model to build a rival. This reflects the intensity of the US-China technology competition.

    What are the challenges to safe AI and cyber governance?

    1. Hallucinations: Advanced models produce distortions and misleading outputs. Judgments built on them become unreliable and subjective.
    2. Algorithmic bias: Biases creep into AI-driven decisions, including a bias towards national security framing. Unrestricted reliance on such outputs magnifies risk.
    3. Algorithmic radicalisation: AI platforms can push opinion makers towards extreme views. Guarding against this requires active oversight.
    4. Warning-understanding gap: In defence sensing, AI-dictated warnings can outrun proper understanding of reality. Acting on premature warnings carries strategic danger.
    5. Loss of human control: Increasingly capable models and robots are replacing human roles in critical decisions. Keeping machines under human oversight is becoming harder.

    Conclusion

    The convergence of AI and cyber capability creates a civilisation-scale threat because the technology that defends systems is the same one that attacks them, and no adequate governance exists. The single most important precondition, human oversight backed by enforceable rules, is missing, and altruism from AI firms is not a substitute for it.

    Back2Basics

    CERT-In:

    1. Indian Computer Emergency Response Team is the national nodal agency for cyber security incidents under the Ministry of Electronics and Information Technology.
    2. Statutory basis: Operates under the Information Technology Act, 2000.

    Generative vs Agentic AI

    Generative AIAgentic AI
    Creates content (text, images, code, audio) from user prompts.Performs tasks autonomously to achieve a goal.
    Responds to instructions but does not independently plan actions.Plans, reasons, makes decisions, and executes multi-step workflows.
    Output-focused.Outcome-focused.
    Requires frequent human prompts for each step.Needs minimal human intervention after receiving the objective.
    Limited memory and action capability.Can use memory, APIs, tools, and feedback to adapt actions.
    Example: ChatGPT writing an essay or generating code.Example: An AI assistant that books travel, compares prices, sends emails, and updates the calendar automatically.

    PYQ Relevance

    [UPSC 2022] What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

    Linkage: UPSC has examined India’s cyber security architecture and the challenges in developing a comprehensive cyber security strategy. The article shows how AI-powered cyber threats and autonomous agents demand an AI-enabled, adaptive cyber security framework beyond traditional defences.

  • How Serious Is the Kudankulam Data Leak

    Why in the News?

    A ransomware breach at Yotta Data Services, a third-party data-centre vendor for Reliance Infrastructure Ltd, led to the leak of 14.3 GB of operational data related to the Kudankulam Nuclear Power Plant on the dark web platform World Leaks. Nuclear Power Corporation of India Limited (NPCIL) states the breach did not touch core reactor or nuclear-security systems, but the incident exposes how strategic nuclear infrastructure remains vulnerable through third-party digital supply chains.

    What exactly happened, and how did the breach occur?

    1. Breach reported: Reports emerged that multiple gigabytes of data on Kudankulam Nuclear Power Plant operations were copied and leaked as part of a ransomware attack.
    2. Point of infiltration: The infiltration targeted Reliance Anil Dhirubhai Ambani Group’s Reliance Infrastructure Ltd, not NPCIL directly.
    3. Scale of leak: 14.3 GB of Kudankulam-related data formed part of a larger 1.2 TB dataset hosted on World Leaks.
    4. World Leaks: World Leaks is a dark web site operated by cybercriminals who infect firms with ransomware and threaten to publish stolen data if a ransom is not paid.
    5. Trigger for publication: The site claims the ransom was not paid, resulting in the data being leaked publicly.

    Was the reactor or nuclear-safety systems compromised?

    1. NPCIL’s position: NPCIL states the leaked files pertain only to Balance of Plant (BOP: conventional common service facilities of a power plant, distinct from the reactor core) and not to nuclear safety or security-related systems.
    2. Reliance’s position: Reliance states no ransomware execution, data loss, or lateral movement occurred, despite confirming a partial breach of data hosted on Yotta’s servers.
    3. Nature of leaked files: The files reportedly include equipment blueprints, supplier details, meeting and inspection records, and equipment reviews.
    4. Insurance detail exposed: A $112 million insurance policy against terrorist attacks was among the leaked details, with the premium amount undisclosed.

    Why does the official reassurance not fully resolve the concern?

    1. Narrow definition of harm: Restricting concern to “core reactor systems” ignores that BOP data such as blueprints and inspection records can still aid reconnaissance or attack planning against a strategic facility.
    2. Layered outsourcing risk: Reliance itself depends on a third-party vendor, Yotta, for data hosting, showing that critical infrastructure security depends on vendors several steps removed from NPCIL.
    3. Self-assessment, not independent audit: Both Reliance and Yotta’s claims that no ransomware execution or lateral movement occurred rest on the vendor’s own internal forensic assessment, not an independent verification.
    4. Transparency gap: The premium amount for the $112 million terrorism insurance policy remains undisclosed even after the leak, showing incomplete disclosure despite the reassurances offered.

    What does the incident reveal about the plant’s strategic significance going forward?

    1. Current capacity: Kudankulam has commissioned two 1,000 MWe VVER (a Russian-designed pressurised water reactor type) units, supplying up to two gigawatts, built in partnership with Russian firm Rosatom.
    2. Expansion underway: The government plans four more units at the site, which would triple installed capacity, expanding the facility’s strategic value and its digital attack surface.
    3. Gap between messaging and internal concern: The revelations have caused “absolute commotion” among plant officials internally, even as public statements downplay the breach’s significance.

    Conclusion

    The Kudankulam leak shows that reassurances confined to “core reactor safety systems” do not address the full risk profile of a strategic nuclear facility. This is because non-core operational data hosted through layered third-party vendors remains commercially and strategically sensitive. As Kudankulam’s capacity is set to triple, critical infrastructure protection frameworks need to extend cybersecurity accountability across the entire vendor supply chain, not the reactor core alone. Additionally this requires independent verification rather than self-reported vendor assessments.

    PYQ Relevance

    [UPSC 2023] What are the different elements of cybersecurity? Keeping in view the challenges in cybersecurity, examine India’s preparedness in preventing cyber attacks.

    Linkage: The article highlights cybersecurity challenges in protecting India’s critical infrastructure from ransomware and third-party data breaches. The Kudankulam data leak underscores the need to strengthen cyber resilience, vendor security, and protection of critical infrastructure despite no compromise of reactor systems.

  • Discuss different types of cyber crimes and measures required to be taken to fight the menace

    The National Cybercrime Reporting Portal defines Cybercrime as any unlawful act where a computer, computer network, or electronic device is used as a tool or target to commit or facilitate a crime.

    Types of cybercrimes

    Authorized Push Payment- Deceiving victims into voluntarily transferring funds to fraudulent accounts. Eg- “Digital Arrest” scams in 2024-25 – losses of over .

    Ransomware-as-a-Service (RaaS)- Deploying malicious software that encrypts critical data, demanding payment for the key. Eg- attack on Delhi’s Sant Parmanand Hospital

    AI-Enabled Deepfakes & Phishing- Eg- rise in “Deepfake Voice Cloning” used to authorize fraudulent bank transfers.

    Digital Espionage- Unauthorized exfiltration of sensitive personal or strategic data from state or corporate servers.

    State-Sponsored Advanced Persistent Threats (APTs)- Eg- Pakistan-linked actors used “Dance of the Hillary” malware to infiltrate DRDO systems during “Operation Sindoor”

    Cryptocurrency Heists – Eg- theft of $230 million from WazirX exchange

    Cyber-Slavery – Trafficking individuals to foreign “fraud factories” to operate transnational scam centers. Eg- “Cyber Slavery” hubs in Cambodia and Myanmar

    Cyber Stalking and Harassment – Eg- Women targeted through doxxing and revenge porn.

    Online Radicalisation – Eg- ISIS recruitment through social media.

    Man-in-the-Middle (MitM) Attacks- Intercepting and potentially altering communications between two parties without their knowledge. Eg- Pune businessman losing Rs 6.49 cr

    Measures to Strengthen Cyber Security in India

    Legal Measures

    Stringent implementation of the Digital Personal Data Protection Act to hold “Data Fiduciaries” (companies) accountable for breaches.

    Replacing the IT Act, 2000, with the proposed Digital India Act to address modern threats like Deepfakes, AI-driven extortion.

    Institutional Measures

    Expanding the Indian Cyber Crime Coordination Centre to serve as a 24/7 national “War Room” for real-time threat mitigation and interstate coordination.

    Strengthening the NCIIPC to secure “Critical Information Infrastructure” (CII) such as power grids, nuclear plants, and banking systems.

    Establishing dedicated cyber-police stations in every district, integrated with the National Cybercrime Reporting Portal (1930).

    Policy Measures

    Implementing the National Cyber Security Strategy focusing on Sovereign Cyber Defense and building a “Cyber-Resilient” ecosystem.

    Adhering to the CERT-In Cyber Security Audit Policy, which mandates annual third-party audits for all government and critical sector entities.

    Promoting the Golden Hour Protocol to report financial frauds within the first 2 hours.

    Technological Measures

    Zero-Trust Architecture (ZTA)- Transitioning from traditional perimeter security to a “Never Trust, Always Verify” model for all digital access requests.

    AI-Driven Threat Intelligence- Deploying machine learning algorithms for real-time detection of anomalies and Automated Incident Response (AIR).

    Promoting the “Atmanirbhar” development of indigenous operating systems and security software. Eg- Maya OS

    Global Measures

    Leveraging partnerships like the Quad Senior Cyber Group to share threat intelligence on state-sponsored APTs (Advanced Persistent Threats) in the Indo-Pacific.

    Collaborating with Interpol (Project Gateway) and FATF to track and dismantle the financial backbones of transnational “Cyber Slavery” hubs.

    Social Measures

    Digital Literacy (Cyber Shikshaa)- awareness campaigns like #CyberDost

    Capacity building of the judicial and police workforce through the CyTrain portal

    Cyber Hygiene- Eg- Multi-Factor Authentication (MFA) and use of the “Chakshu” portal for reporting suspicious communications.

    As cybercrimes move into the realm of “Grey Zone Warfare,” India’s cyber defense must be proactive rather than reactive.

  • Keeping in view India’s internal security, analyse the impact of cross-border cyber attacks. Also, discuss defensive measures against these sophisticated attacks.

    As per report of CloudSEK, India emerged as the second most targeted nation in terms of cyber attacks in 2024.

    Impact of Cross-Border Cyber Attacks

    Threat to Critical Information Infrastructure (CII) – Eg – attempts by the Pakistan-linked APT36 group to infiltrate India’s Northern Power Grid

    Economic Destabilization by attacks on financial gateways like UPI or BSE.

    Salami-Slicing of Intellectual Property (IP)- Eg- theft of IP from manufacturing and pharmaceutical sectors to weaken India’s “Make in India” competitive edge.

    State-Sponsored Advanced Persistent Threats (APTs)- Eg- Pakistan-linked actors used “Dance of the Hillary” malware to infiltrate DRDO systems during “Operation Sindoor”

    Compromise of National Defense & Military Intelligence- “Operation FlightNight” targeted Indian defense and energy sectors using malware disguised as an Indian Air Force invitation.

    Psychological Warfare- Eg- Following the Pahalgam attack, Pakistan-linked groups flooded social media with 2 lakh deepfakes and “forged” government documents to spread panic.

    Threat to privacy. Eg- Star Health Insurance breach leaking data of 31 million customers

    “Mass Defacement” – Simultaneously taking down hundreds of government websites to Undermine government authority

    Measures to Strengthen Cyber Security in India

    Legal Measures

    Stringent implementation of the Digital Personal Data Protection Act to hold “Data Fiduciaries” (companies) accountable for breaches.

    Empower the CBI to investigate cybercrime cases nationwide without needing general consent from state. (Parliamentary panel on home affairs)

    Replacing the IT Act, 2000, with the proposed Digital India Act to address modern threats like Deepfakes, AI-driven extortion.

    Institutional Measures

    Expanding the Indian Cyber Crime Coordination Centre to serve as a 24/7 national “War Room” for real-time threat mitigation and interstate coordination.

    Strengthening the NCIIPC to secure “Critical Information Infrastructure” (CII).

    Establishing dedicated cyber-police stations in every district, integrated with the National Cybercrime Reporting Portal (1930).

    Policy Measures

    Implementing the National Cyber Security Strategy focusing on Sovereign Cyber Defense and building a “Cyber-Resilient” ecosystem.

    Adhering to the CERT-In Cyber Security Audit Policy, which mandates annual third-party audits for all government and critical sector entities.

    Promoting the Golden Hour Protocol to report financial frauds within the first 2 hours.

    Technological Measures

    Zero-Trust Architecture (ZTA)- Transitioning from traditional perimeter security to a “Never Trust, Always Verify” model for all digital access requests.

    AI-Driven Threat Intelligence- Deploying machine learning algorithms for real-time detection of anomalies and Automated Incident Response (AIR).

    Promoting the “Atmanirbhar” development of indigenous operating systems and security software. Eg- Maya OS

    Global Measures

    Leveraging partnerships like the Quad Senior Cyber Group to share threat intelligence on state-sponsored APTs (Advanced Persistent Threats) in the Indo-Pacific.

    Collaborating with Interpol (Project Gateway) and FATF to track and dismantle the financial backbones of transnational “Cyber Slavery” hubs.

    Social Measures

    Digital Literacy (Cyber Shikshaa)- awareness campaigns like #CyberDost

    Capacity building of the judicial and police workforce through the CyTrain portal

    Cyber Hygiene- Eg- Multi-Factor Authentication (MFA) and use of the “Chakshu” portal for reporting suspicious communications.

    As cybercrimes move into the realm of “Grey Zone Warfare,” India’s cyber defense must be proactive rather than reactive.