Cybersecurity
₹52,976 Crore Lost to Cyber Fraud in Six Years: Investment Scams Emerge as the Biggest ‘Monster’
India has suffered cumulative losses of ₹52,976 crore due to cyber fraud and cheating-related crimes between 2020 and 2025, according to data from the Indian Cyber Crime Coordination Centre (I4C) under the Union Home Ministry. Analysts warn that cyber fraud has evolved into a highly organized, industrial-scale financial crime ecosystem.
2025 Marks a Record Year
The spike in cybercrime was most pronounced in 2025, which alone accounted for ₹19,812 crore in losses — nearly one-third of the six-year total. Over 21.77 lakh complaints were filed, signaling a rapid increase in both the scale and sophistication of scams.
Year-wise losses and complaints show the escalation:
- 2024: ₹22,849 crore; 19.18 lakh complaints
- 2023: ₹7,463 crore; 13.10 lakh complaints
- 2022: ₹2,290 crore; 6.94 lakh complaints
- 2021: ₹551 crore; 2.62 lakh complaints
- 2020: ₹8.56 crore; 1.27 lakh complaints
A senior cybercrime official noted, “Cyber fraud is no longer opportunistic — it is industrial and structured.”
Investment Scams Dominate
Investment-related scams were the largest contributor, accounting for 77% of 2025 losses. Other categories included:
- Digital arrest scams: 8%
- Credit card fraud: 7%
- Sextortion: 4%
- E-commerce fraud: 3%
- App/malware-based fraud: 1%
Victims are often targeted through fake trading apps, cloned investment platforms, social media ads, and fraudulent “financial experts” promising high returns.
Most Affected States
States with high digital adoption and transaction volumes saw the heaviest losses:
- Maharashtra: ₹3,203 crore; 28.33 lakh complaints
- Karnataka: ₹2,413 crore; 21.32 lakh complaints
- Tamil Nadu: ₹1,897 crore; 12.32 lakh complaints
- Uttar Pradesh: ₹1,443 crore; 27.52 lakh complaints
- Telangana: ₹1,372 crore; ~95,000 complaints
Together, these five states accounted for over half of national cyber fraud losses. Gujarat, Delhi, and West Bengal were also significant contributors.
International Links
Research from the Future Crime Research Foundation (FCRF) found that nearly 45% of 2025 cyber fraud cases had links to Southeast Asia, particularly Cambodia, Myanmar, and Laos. Fraud types included:
- Investment fraud: 36%
- Credit card fraud: 27%
- Sextortion: 18%
- E-commerce fraud: 10%
- Digital arrest scams: 6%
- App/malware-based fraud: 3%
Many scams are operated from overseas, with funds routed through layered bank accounts, shell companies, and cryptocurrency.
Why Cyber Fraud Is Surging
Experts point to multiple factors driving the growth:
- Rapid digitization and surge in UPI and online payments
- Professionally run scam networks with scripted calls and tech teams
- Advanced social engineering and psychological manipulation
- Expansion into smaller towns and rural areas
“These operations now resemble corporate-style setups, with recruiters, tech handlers, mule accounts, and fund managers,” a senior investigator explained.
Addressing the Crisis
Authorities stress that combating cyber fraud requires:
- Stricter regulation of investment platforms
- Faster coordination between banks and police
- Real-time fraud detection and alert systems
- Public awareness campaigns and financial-cyber literacy
As India’s digital economy grows, experts warn that without robust security, regulation, and awareness, losses from cybercrime are likely to escalate further.
Cyber Crime
FutureCrime Summit Panel Explores Planning and Management of Cybersecurity Laboratories
As cybercrime becomes increasingly sophisticated, the ability to investigate and preserve digital evidence depends heavily on specialised infrastructure. This challenge was a key focus at the FutureCrime Summit 2026, where experts examined how organizations can plan, establish and manage effective cybersecurity and digital-forensics laboratories.
A panel discussion and workshop titled “Planning, Setting Up, and Managing a Cybersecurity Laboratory” explored the practical requirements involved in developing laboratories that can support digital investigations, forensic analysis, incident response and professional training.
The session featured Ajay Sariyal, Technical Product Specialist at MSAB; Abhinav Saurabh of Forensic Care; Sub-Inspector Saurabh Haritesh of Delhi Police; and Priya Choudhary. Their combined perspectives highlighted the importance of aligning technology, investigative requirements, personnel and laboratory management.
Cyber Labs Must Be Designed Around Their Mission
Establishing a modern cybersecurity laboratory involves far more than purchasing computers and forensic software. The facility must be designed according to the type of work it is expected to perform.
Depending on its purpose, a laboratory may support mobile-device examinations, digital evidence analysis, malware investigations, network forensics, cybercrime response or specialist training.
Infrastructure planning can include forensic workstations, specialised tools, secure networks, controlled-access areas and reliable systems for storing digital evidence. Each component must contribute to a workflow that protects the integrity and reliability of investigations.
For law-enforcement agencies, these requirements become particularly important because laboratories may handle evidence connected to criminal cases. Proper documentation, controlled evidence handling and repeatable examination procedures are therefore essential.
Skilled Investigators Remain Critical
The panel also underscored a fundamental point: advanced technology is only as effective as the professionals using it.
Digital-forensics personnel need the expertise to acquire, preserve, examine and interpret evidence while maintaining appropriate investigative procedures. Continuous training is equally important because digital devices, operating systems, applications and cyberattack techniques change rapidly.
Ajay Sariyal’s experience in mobile-device forensics brought a technology-focused perspective to the discussion. The participation of Abhinav Saurabh from Forensic Care added a forensic-services dimension, while Sub-Inspector Saurabh Haritesh represented the operational challenges faced by police investigators.
Together, these perspectives highlighted the need for cybersecurity laboratories to combine specialised technology with practical investigative expertise.
Laboratory Management Does Not End After Setup
Another important issue raised by the session was the need for sustained management once a laboratory becomes operational.
Cybersecurity and forensic facilities require ongoing maintenance, software upgrades, licence management, equipment replacement, secure storage and access-control reviews. Documented procedures must also be updated as investigative techniques and technologies evolve.
Growing caseloads can create another challenge. Laboratories must develop efficient workflows for prioritising examinations and managing evidence backlogs without compromising forensic standards or the reliability of findings.
This makes laboratory development a continuing institutional responsibility rather than a one-time investment in technology.
A Foundation for Modern Cybercrime Investigations
The FutureCrime Summit session highlighted that an effective cybersecurity laboratory depends on the interaction of technology, trained personnel, secure processes and long-term management.
As digital evidence becomes increasingly important in criminal investigations, organizations need facilities capable of handling complex and diverse forms of electronic information. A well-planned laboratory can provide investigators with the controlled environment and specialist capabilities required to examine digital evidence effectively.
The broader takeaway from the discussion was that the success of a cyber-forensics facility should not be measured simply by the number of tools it contains. Its real value lies in how efficiently its technology, personnel and procedures work together to support reliable investigations.
Corporate Compliance
FutureCrime Summit Panel Examines Data Fiduciary Accountability and DPO Responsibilities
The growing importance of privacy governance and responsible data management took centre stage at the FutureCrime Summit 2026, where industry experts discussed how Indian organizations can strengthen accountability for personal information.
A panel titled “Data Fiduciary Accountability: Governance, Audits and the Role of Data Protection Officers in India” examined the changing responsibilities of businesses as India’s digital ecosystem and privacy framework continue to evolve.
The discussion featured Suditi Tandon, Senior Officer, Global Data Privacy Office Specialist, Corporate Legal & Compliance at Hella India Automotive Private Limited; Krishan Kumar, Vice President at SPECTRA; Dipanshu Parashar; and Nirmal Raj M, Principal Officer & Risk Compliance Lead at Onmeta.
Data Governance Is Becoming a Business Responsibility
A key message from the discussion was that data protection can no longer be viewed solely as a legal or compliance exercise.
Organizations handling personal information need to establish clear oversight over the entire data lifecycle. This includes understanding what information is collected, the purpose for collecting it, where it is stored, who has access to it and when it should be deleted or retained.
The challenge becomes more complex as businesses increasingly depend on cloud infrastructure, digital platforms and external technology providers. Maintaining visibility over personal information across these interconnected systems requires stronger internal governance and clearly defined accountability.
Privacy policies and consent mechanisms remain important, but they are only part of an effective data protection framework. Organizations also need operational controls that translate privacy principles into everyday business practices.
Data Audits Can Reveal Hidden Governance Gaps
The panel also highlighted the role of audits in determining whether privacy policies are working in practice.
A well-designed data audit can assess areas such as information inventories, access permissions, retention procedures, third-party relationships and internal controls. Such reviews can identify weaknesses that may not be apparent from written policies alone.
Third-party data processing was another important consideration. When organizations rely on outside vendors or technology platforms, they need adequate oversight of how information is processed throughout its lifecycle. Simply transferring data to a service provider does not remove the need for effective accountability.
Regular audits can therefore serve as an important mechanism for identifying operational shortcomings before they become larger compliance, privacy or security concerns.
DPOs Moving Beyond Traditional Compliance
The evolving role of Data Protection Officers was another major theme of the session.
DPOs increasingly operate across several areas, including privacy law, technology, risk management and corporate governance. Their responsibilities can extend beyond maintaining documentation to advising senior leadership, assessing privacy risks and helping organizations build stronger data-handling processes.
The professional backgrounds of the panelists also reflected the multidisciplinary nature of modern privacy governance, bringing together corporate privacy, legal technology, artificial intelligence, compliance, risk management and cybercrime-related perspectives.
This broader role positions DPOs as an important part of an organization’s internal accountability structure rather than simply as administrative compliance personnel.
Building Trust Through Stronger Accountability
The FutureCrime Summit discussion underlined a broader shift in the way organizations approach personal data.
Effective data protection requires cooperation between management, legal and compliance teams, technology professionals, security functions and other business units. Clearly assigned responsibilities, regular audits and appropriate technical safeguards all contribute to a stronger governance framework.
As businesses become increasingly dependent on personal information and digital services, responsible data management is also becoming closely linked to consumer confidence and digital trust.
The panel’s central takeaway was clear: accountability for personal data must be embedded across an organization rather than left to a single department or compliance function.
Cybersecurity
FutureCrime Summit Panel Examines AI-Powered Cybercrime and Cyber Resilience
New Delhi: The growing role of artificial intelligence in cybercrime and the urgent need to strengthen digital resilience were key themes at the FutureCrime Summit 2026, where cybersecurity experts discussed the evolving risks facing critical infrastructure.
A panel titled “Defending the Digital Backbone: AI-Powered Cybercrime, Critical Infrastructure, and Cyber Resilience” brought together experts from academia, cyber defence, incident response, forensics and managed security services.
The session featured Dr. Akash Thakar, Assistant Professor at Rashtriya Raksha University; Himanshu Patel, Senior Manager – Cyber Defence, Incident Response and Forensics at Protiviti; Dr. Nishant Sawant, Director, Managed Security Services; and Er. Kritika.
AI Is Reshaping the Cyber Threat Landscape
Panelists examined how artificial intelligence is changing both the scale and speed of cyberattacks. AI-enabled tools can potentially help malicious actors automate tasks such as reconnaissance, identify weaknesses and create increasingly convincing social-engineering campaigns.
The same technology, however, is also becoming an important tool for cybersecurity teams. AI-based systems can analyse large volumes of network activity, identify unusual patterns and help security professionals prioritise potentially serious threats.
Experts stressed that deploying AI alone is not enough. Organizations also need skilled personnel, effective governance frameworks and clearly defined incident-response procedures to ensure that AI-driven security tools are used effectively.
Critical Infrastructure Faces Wider Cyber Risks
The discussion placed particular emphasis on the protection of critical infrastructure. Modern economies depend heavily on interconnected digital systems supporting sectors such as banking, telecommunications, transportation and public services.
A cyber incident affecting one system can potentially create consequences across connected networks. This makes resilience just as important as prevention, particularly for organizations responsible for essential services.
According to the themes discussed at the summit, effective cyber resilience involves rapidly identifying threats, containing compromised systems, maintaining critical operations and restoring services after an incident. Organizations must also preserve digital evidence so that forensic teams can investigate the attack.
Cybersecurity Becomes an Organizational Responsibility
The panel also highlighted the changing role of cybersecurity within organizations. Protecting digital infrastructure is increasingly viewed as a strategic responsibility rather than a function limited to technical teams.
The diverse expertise of the panel reflected this broader approach. Academic research, cyber defence, incident response, digital forensics and managed security services each contribute to building stronger security capabilities.
The discussion underscored a central challenge for organizations: how to benefit from increasingly powerful AI systems while preventing the same technology from creating additional opportunities for cybercriminals.
Resilience Requires More Than Security Technology
Experts stressed that there is no single technology capable of addressing the full range of modern cyber threats. Strong cybersecurity requires a combination of advanced tools, trained professionals, effective governance and preparedness for major incidents.
Organizations also need the ability to continue essential operations when security controls are bypassed and recover quickly after an attack.
As artificial intelligence becomes increasingly embedded in both legitimate digital services and criminal activity, the ability to withstand disruption and recover from cyber incidents is expected to become an increasingly important measure of cybersecurity maturity.
-
Business3 years agoPot Odor Does Not Justify Probable Cause for Vehicle Searches, Minnesota Court Affirms
-
Business3 years agoNew Mexico cannabis operator fined, loses license for alleged BioTrack fraud
-
Business3 years agoAlabama to make another attempt Dec. 1 to award medical cannabis licenses
-
Business3 years agoWashington State Pays Out $9.4 Million in Refunds Relating to Drug Convictions
-
Business3 years agoMarijuana companies suing US attorney general in federal prohibition challenge
-
Business3 years agoLegal Marijuana Handed A Nothing Burger From NY State
-
Business3 years agoCan Cannabis Help Seasonal Depression
-
Blogs3 years agoCannabis Art Is Flourishing On Etsy
