People's fear and mistrust in authority leads to cybercrime, say experts at report launch on policing

Internal Security & Governance · 26 September 2026 · Based on The Hindu (original report)

Worth reading — 1 past UPSC question on this theme (Mains GS-3 2022).

2-minute summary

The 'Status of Policing in India Report (SPIR) 2026: Cybercrime—Victim Perspectives and Systemic Responses', published by Lokniti-CSDS and Common Cause, highlights critical vulnerabilities in India's cyber-policing ecosystem. A key finding is that cybercriminals heavily exploit 'social engineering'—manipulating victims' fear of authority and deep-seated mistrust in public governance to execute scams like 'digital arrests'. The report reveals that digital literacy is not the sole safeguard, as many victims perceived digital payments to be highly secure before being targeted. Systemic gaps are glaring: 72% of victims failed to recover any lost money, pointing to a lack of bank accountability. Furthermore, only 23% of financial cybercrime victims believe the police are adequately equipped to handle cybercrimes. Vulnerable groups, particularly women and rural citizens, face additional barriers including police apathy, hurdles in filing FIRs, and corruption. The report also warns against the misuse of publicly available data, which AI can compile into detailed 'relationship graphs', posing severe surveillance and privacy risks.

Why it's in the news

The Lokniti-CSDS and Common Cause have released the 'Status of Policing in India Report 2026: Cybercrime—Victim Perspectives and Systemic Responses'. The report sheds light on the rising threat of cybercrime, the psychological tactics of fraudsters, and the severe lack of preparedness among police forces and banking institutions to protect victims.

Facts to remember

  • The 'Status of Policing in India Report 2026' was published by Lokniti-CSDS and Common Cause.
  • The report highlights that 72% of cybercrime victims failed to recover any lost money, pointing to a lack of bank accountability.
  • India is notably not a signatory to the Budapest Convention on Cybercrime, citing concerns over sovereignty and data-sharing provisions.
  • The Indian Cyber Crime Coordination Centre provides a framework and ecosystem for Law Enforcement Agencies to deal with cybercrimes.

Background and context

India has witnessed an exponential surge in digital transactions over the past decade, driven by UPI and mobile internet penetration. However, this rapid digital transition has not been matched by corresponding growth in digital hygiene or cyber-defense infrastructure. Cybercriminals have shifted from purely technical hacks to 'social engineering' tactics, exploiting psychological vulnerabilities. The 'digital arrest' phenomenon is a prime example, where fraudsters pose as law enforcement officers to blackmail citizens. Historically, Indian police forces, structured under the colonial-era Police Act of 1861, have struggled with modernization, capacity building, and specialized training. This has led to a widening gap between the sophisticated, cross-border nature of cyber syndicates and the localized, resource-constrained capabilities of state police departments.

Constitutional provisions

  • Article 21 — Guarantees the Right to Life and Personal Liberty, which the Supreme Court (in the K.S. Puttaswamy judgment) ruled includes the Right to Privacy. Cybercrimes involving data leaks and surveillance directly violate this right.
  • Seventh Schedule (List II, Entry 1 & 2) — 'Public Order' and 'Police' are State subjects, making state governments primarily responsible for cybercrime prevention and investigation, leading to fragmented capabilities across states.
  • Seventh Schedule (List I, Entry 31 & 97) — The Union government has jurisdiction over telecommunications, technology, and residuary powers, under which the Information Technology Act, 2000 was enacted.

Committees and reports

  • Status of Policing in India Report (SPIR) 2026 — Highlights victim perspectives, police unpreparedness, banking loopholes, and the psychological exploitation of public trust deficits in cybercrimes.
  • Parliamentary Standing Committee on Finance - Report on Cyber Security — Emphasized the need for a centralized regulatory authority to combat cyber-financial fraud and recommended fixing accountability on banking institutions.

Government schemes

  • Indian Cyber Crime Coordination Centre (I4C) — Provides a framework and eco-system for Law Enforcement Agencies (LEAs) to deal with cybercrimes in a coordinated and comprehensive manner.
  • National Cyber Crime Reporting Portal (cybercrime.gov.in) — A centralized portal facilitating citizens to report cybercrime complaints online, with a specific focus on crimes against women and children.

International organisations

  • Budapest Convention on Cybercrime — The first international treaty seeking to address Internet and computer crime by harmonizing national laws. India is notably not a signatory, citing concerns over sovereignty and data-sharing provisions.

Previous UPSC questions on this theme

  • Mains GS-3 2022 — What are the different elements of cyber security? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

Mains practice: Analyze how systemic trust deficits in public governance and policing infrastructure exacerbate the vulnerability of citizens to cybercrimes in India. Suggest corrective measures.

The Status of Policing in India Report (SPIR) 2026 highlights a critical paradox: cybercriminals increasingly exploit citizens' fear of authority and mistrust in public institutions to execute sophisticated frauds like 'digital arrests'. This underscores that cybercrime is as much a governance and psychological challenge as it is a technological one.

**How Trust Deficit and Infrastructure Gaps Exacerbate Vulnerabilities:**

• **Exploitation of Fear:** Fraudsters leverage the public's fear of state coercive power. Because citizens perceive state authority as punitive rather than protective, they comply with extortionist demands (e.g., fake CBI/police calls) rather than seeking immediate official help.

• **Inadequate Police Preparedness:** According to SPIR 2026, only 23% of financial cybercrime victims believe the police are equipped to handle such cases. Local police stations often lack specialized cyber cells, forensic tools, and trained personnel, leading to low registration of FIRs and poor investigation rates.

• **Lack of Institutional Accountability:** Financial institutions often escape accountability. The report notes that 72% of victims fail to recover any lost money, indicating a weak redressal mechanism and lack of coordination between banks and law enforcement.

• **Vulnerability of Marginalized Groups:** Women and rural victims face compounded barriers, including police apathy, demands for bribes, and a lack of localized digital grievance redressal mechanisms.

**Corrective Measures Required:**

• **Police Capacity Building:** Establish dedicated cyber cells in every district with continuous training on emerging technologies like AI-driven fraud and social engineering.

• **Institutionalizing Bank Accountability:** Implement strict timelines for banks to freeze fraudulent accounts and establish a mandatory, simplified victim-compensation framework.

• **Community-Centric Policing:** Rebuild public trust through transparent police communication, citizen-awareness programs, and simplified, non-punitive reporting systems.

• **Robust Data Protection Enforcement:** Strictly regulate the public availability of personal data to prevent criminals from constructing detailed 'relationship graphs' for targeted phishing.

**Conclusion:**

Addressing cybercrime in India requires moving beyond firewall installations. It demands systemic police reforms, enhanced institutional accountability, and a trust-building exercise between the state and its citizens to dismantle the psychological leverage held by cybercriminals.

Prelims practice questions

Q1. With reference to the Indian Cyber Crime Coordination Centre (I4C), consider the following statements: 1. It functions under the aegis of the Ministry of Electronics and Information Technology (MeitY). 2. It acts as a nodal point to coordinate fight against cybercrime among various states and Union Territories. Which of the statements given above is/are correct?

  1. 1 only
  2. 2 only
  3. Both 1 and 2
  4. Neither 1 nor 2

Answer: B. Statement 1 is incorrect because the Indian Cyber Crime Coordination Centre (I4C) functions under the Ministry of Home Affairs (MHA), not MeitY. Statement 2 is correct as its primary mandate is to coordinate efforts against cybercrime across states and UTs.

Q2. The 'Budapest Convention', sometimes seen in the news, is associated with which of the following fields?

  1. International cooperation against cybercrime
  2. Protection of intellectual property rights in digital media
  3. Transboundary movement of hazardous wastes
  4. Conservation of wetland ecosystems

Answer: A. The Budapest Convention on Cybercrime is the first international treaty addressing internet and computer crimes by harmonizing national laws and improving investigative techniques. India is not a signatory to this convention.

Q3. Under the Constitution of India, 'Police' and 'Public Order' fall under which of the following lists of the Seventh Schedule?

  1. State List (List II)
  2. Union List (List I)
  3. Residuary Powers
  4. Concurrent List (List III)

Answer: A. Under the Seventh Schedule of the Constitution of India, 'Police' (Entry 2) and 'Public Order' (Entry 1) are subjects allocated to the State List (List II). Therefore, state governments are primarily responsible for policing, including local cybercrime investigation.

Revision flashcards

  • What is 'Social Engineering' in the context of cybercrime? The psychological manipulation of individuals into performing actions or divulging confidential information, rather than using technical hacking methods.
  • Which organizations publish the 'Status of Policing in India Report' (SPIR)? Lokniti-CSDS and Common Cause.
  • What is a 'Mule Account' in cyber-financial fraud? A bank account used by criminals to receive and quickly transfer illicitly acquired funds, hiding the identity of the actual perpetrators.
  • What is a 'Digital Arrest' scam? A cyber-fraud tactic where criminals pose as law enforcement officers, falsely accusing victims of crimes online and coercing them into staying on video calls while demanding money.
  • Why has India opted out of signing the Budapest Convention on Cybercrime? Due to concerns over national sovereignty, as the convention allows foreign law enforcement agencies access to domestic data without going through traditional mutual legal assistance treaties.

All stories for 26 September 2026 · ← 25 September 2026 · 27 September 2026 →