The Expanding Edge of Cybercrime: Bridging India's Intelligence Gap
Nullcon Goa 2026 · Day 1
Overview
This talk, delivered by the Director of the National Cyber Crime Training Center (NCTC) at the Indian Cyber Crime Coordination Center (I4C) under the Ministry of Home Affairs, provides a comprehensive and urgent assessment of the escalating cybercrime landscape in India. It dissects the evolving tactics of cybercriminals, from low-value, semi-professional schemes to sophisticated, high-value, organized, and even state-backed operations. The speaker, drawing on extensive experience within the ministry and coordinating with various intelligence and law enforcement agencies, highlights the critical challenges posed by this exponential rise in digital illicit activity and the strategic imperative to treat cybersecurity as an integral component of national security.

Key moments
- 1:30 Indian Cyber Crime Coordination Center (I4C) mission
- 3:55 Alarming financial losses due to cybercrime in India
- 4:30 I4C's effectiveness evident in reduced losses
- 6:00 Shocking 37 crore digital arrest fraud example
- 6:50 Understanding cybercrime hotspots and mule accounts
- 9:50 How criminals channelize and launder stolen funds
The Expanding Edge of Cybercrime: Bridging India's Intelligence Gap
Speakers: Director, National Cyber Crime Training Center (NCTC) at Indian Cyber Crime Coordination Center (I4C), Ministry of Home Affairs
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=ttuASqP3p8M
Overview
This talk, delivered by the Director of the National Cyber Crime Training Center (NCTC) at the Indian Cyber Crime Coordination Center (I4C) under the Ministry of Home Affairs, provides a comprehensive and urgent assessment of the escalating cybercrime landscape in India. It dissects the evolving tactics of cybercriminals, from low-value, semi-professional schemes to sophisticated, high-value, organized, and even state-backed operations. The speaker, drawing on extensive experience within the ministry and coordinating with various intelligence and law enforcement agencies, highlights the critical challenges posed by this exponential rise in digital illicit activity and the strategic imperative to treat cybersecurity as an integral component of national security.
The presentation emphasizes the Indian Cyber Crime Coordination Center's pivotal role as an apex agency established to consolidate fragmented efforts and foster real-time, coordinated responses among diverse stakeholders, including state law enforcement agencies (LEAs), banks, telecom providers, and internet intermediaries. It showcases I4C's significant strides in combating financial cyber fraud, detailing the creation of a robust infrastructure designed to track, freeze, and recover stolen funds, as well as to enhance investigative capabilities and build national capacity through specialized training programs.
The talk is particularly significant for anyone involved in cybersecurity, law enforcement, financial institutions, and policy-making in India and globally, as it illustrates the complex interplay between technology, human psychology, and organized crime. It underscores the urgent need for a multi-faceted approach that combines technological solutions, inter-agency collaboration, public awareness, and strategic investment to counter the expanding edge of cybercrime effectively. By presenting real-world data on financial losses and recoveries, the speaker provides a compelling narrative for prioritizing cybersecurity at both the executive and national levels, advocating for tangible metrics to demonstrate the return on investment in security measures.
Background
▶ Watch: Indian Cyber Crime Coordination Center (I4C) mission (1:30)
The genesis of the Indian Cyber Crime Coordination Center (I4C) in 2018-2019 was a direct response to the alarming, exponential surge in cybercrime across India over the past decade. Prior to I4C's establishment, the fight against cybercrime was significantly hampered by a critical lack of coordination among the myriad of stakeholders involved. Law enforcement agencies (state police, cyber cells), banks, telecom infrastructure providers, and various internet intermediaries often operated in silos, making a unified and rapid response to dynamic cyber threats exceedingly difficult. This fragmented approach allowed cybercriminals to exploit jurisdictional gaps and communication breakdowns, leading to substantial financial losses and a growing sense of insecurity among citizens.
The problem's existence is multifaceted. Firstly, the ubiquitous adoption of digital technologies, particularly after initiatives like the government's drive to provide bank accounts to nearly every citizen post-COVID, created a vast new attack surface. While beneficial for financial inclusion, this also meant that even individuals with minimal digital literacy or engagement became potential targets, with their often-redundant bank accounts becoming attractive assets for criminals. Secondly, the nature of cybercrime itself evolved. What once might have been considered "petty crime" perpetrated by "semi-professional criminals" (e.g., small-scale frauds ranging from ₹5,000 to a few lakhs) rapidly transformed. Organized crime syndicates, traditionally involved in human trafficking, drug smuggling, and illegal weapons, recognized the immense scalability and reduced risk associated with technology-enabled crime. They began orchestrating these smaller criminal elements into sophisticated, high-value operations, with individual frauds sometimes escalating to multiple lakhs or even crores of rupees.
Furthermore, the speaker explicitly states that many of these organized cybercrime operations are now "state-backed by our adversaries." This alarming development means that significant financial gains from these crimes are being funneled to countries "not very friendly to India," adding a geopolitical and national security dimension to the problem. The adversaries leverage technology to scale their operations, recruit talent (sometimes through coercion and human trafficking), and employ advanced techniques, making the challenge far more complex than simple criminal activity. This confluence of technological advancement, organizational sophistication, and state sponsorship created an urgent need for an apex agency like I4C to bridge the intelligence gap and orchestrate a cohesive national response.
Key Findings
▶ Watch: I4C's effectiveness evident in reduced losses (4:30)
The talk presents several critical findings that underscore the severity and evolving nature of cybercrime in India, alongside I4C's impact:
- Exponential Financial Losses: India has witnessed an alarming increase in financial losses due to cybercrime. The known money lost escalated from ₹551 Crores in 2021 to ₹2,300 Crores in 2022, then to over ₹7,000 Crores in 2023, and a staggering ₹22,000 Crores in 2024. This exponential rise highlights the growing scale of the menace.
- Impact of I4C: While the losses were increasing, I4C's efforts began to show a tangible impact. For the first time, in 2025, there was a "minuscule but notable drop" in the money lost, indicating the effectiveness of the initiatives put in place. The recovery rate of defrauded money has significantly improved, from under 5% initially to almost 25% by January 26th of the current year.
- Common Cybercrime Models:
- Low-Value Frauds: Often perpetrated by semi-professional criminals, these typically involve amounts from ₹5,000 to a few lakhs.
- High-Value Frauds: These are the "big ticket ones," starting from multiple lakhs to multiple crores. Examples include investment frauds, loan app scams, digital arrests, and gaming app frauds. A notable case involved a retired gentleman losing ₹37 Crores over 36 days due to a digital arrest scam.
- Cybercrime Hotspots and Modus Operandi:
- Suspect Bank Branches and Mule Accounts: Criminals exploit redundant bank accounts (e.g., Jan Dhan accounts) by "hiring" them via channels like Telegram. These mule accounts are used to quickly transfer defrauded money through multiple hops, often within minutes, to obscure the money trail before it's cashed out, converted to crypto, or moved offshore.
- Suspect Locations: Geographical locations from where fraudulent calls and operations originate are mapped by I4C.
- Financial Channels: Stolen money is laundered through mule accounts, payment aggregators, virtual accounts, cryptocurrencies, e-commerce sites, and ATM withdrawals.
- Misuse of Technology and Platforms:
- Fintech Services: Increasingly used to perpetuate and channelize funds from crimes.
- Shell Companies & Virtual Accounts: Used for financial obfuscation.
- SMS Headers: For luring victims with deceptive messages.
- UPI & Payment Gateways: Exploited for transactions.
- Spoofed Websites: Created for fake advertisements, lucrative messages, or even national events (e.g., Kumbh Mela tent bookings).
- Social Media & Intermediaries: Platforms like WhatsApp, Google, Facebook, and Instagram are used for advertising fraudulent loan and investment apps. I4C is actively engaging these intermediaries to filter malicious ads using their AI engines and due diligence, aligning with recent IT rules amendments.
- Social Engineering as the Primary Vector: Most cybercrimes initiate through social engineering, playing on human emotions:
- Greed: Lucrative investment or loan offers.
- Panic: Threats of account deactivation or SIM card blocking (e.g., "KYC update" scams).
- Trust: Impersonating bank officials or customer service.
- Fear: Digital arrests, threats of legal action.
- Lust: Dating app scams, often involving honey trapping or distributing malicious code (Trojans) embedded in images or videos, which can compromise device microphones and sensitive data even if not explicitly shared.
- Evolution to Organized and State-Backed Crime: Cybercrime has evolved from petty individual acts to highly organized operations. The speaker explicitly states that many high-value investment apps are launched from "countries not very friendly to India," and a lot of money is "channelized to these countries," indicating state-backed adversaries.
- Technology as an Enabler for Criminals:
- Scaling Operations: Criminals use technology to expand rapidly.
- Talent Acquisition: Hiring skilled individuals through lucrative offers or, increasingly, through human trafficking, luring individuals (especially Indians) to countries like Cambodia, Thailand, and Myanmar under false job pretenses, then confiscating passports and forcing them into "cyber slavery."
- Deepfakes: Blatantly used for advertising fraudulent schemes, impersonating public figures or known faces in videos on social media platforms.
- "As-a-Service" Models on Dark Web: Various malicious services are openly available on dark web marketplaces, including Telecom Mule as a Service, Ransomware as a Service, Money Laundering as a Service, and Hacking as a Service.
Technical Deep Dive
▶ Watch: Shocking 37 crore digital arrest fraud example (6:00)
The Indian Cyber Crime Coordination Center (I4C) has developed a sophisticated, multi-pronged technical and operational framework to combat the escalating cybercrime threat. This framework is designed to provide real-time response, facilitate investigations, and enhance national capacity.
At the core of I4C's citizen-facing operations is the 1930 helpline and the Citizen Financial Cyber Fraud Reporting and Management System (CFC RMS), accessible via cybercrime.gov.in. These are the primary conduits for victims to report financial cyber frauds. The design philosophy behind CFC RMS is to enable rapid action, leveraging the "golden hour" concept, which the speaker clarifies is often as short as 10 to 15 minutes for financial fraud.
The real-time response mechanism is spearheaded by the Cyber Fraud Mitigation Center (CFMC). This is a specialized control room where representatives from nearly all major banks in India, along with officials from law enforcement agencies and intelligence agencies, operate collaboratively at individual workstations. When a complaint is lodged via 1930 or cybercrime.gov.in, a unique token is generated and immediately routed to the relevant bank representative at CFMC. For example, if a victim's account is with ICICI Bank, the ICICI representative instantly checks the transaction details. If the money has moved to an HDFC Bank account, the token is then passed to the HDFC representative, who verifies if the funds are still present. If so, a freeze is immediately placed on the account. This process continues through multiple "hops" (e.g., to an SBI account), ensuring that the money trail is followed and funds are blocked as quickly as possible. The speaker emphasizes that if a report is not made within the initial 15-20 minutes, the money is likely to have taken several hops, converted into cryptocurrency, or cashed out, making recovery significantly more challenging.
Beyond immediate fund recovery, I4C supports broader law enforcement efforts. It provides investigation assistance to all state police, cyber cells, and intelligence agencies across the country, connecting to police stations up to the district level. The SUMAN MAPAP portal (Cyber Crime Linkages and Interstate Coordination) is a critical tool in this regard. It connects all law enforcement agencies across states and Union Territories, facilitating the real-time sharing of information. This enables investigators to link criminal activities across different jurisdictions, as a criminal operating in one state might have committed similar offenses elsewhere, thereby aiding in their identification and apprehension.
For proactive threat intelligence and content moderation, I4C operates several specialized units and platforms:
- National Cyber Crime Threat Analytical Unit (NCT-TAW) is dedicated to cyber threat research, analyzing emerging patterns and methodologies of cybercriminals.
- The SAHO portal is designed for the takedown and blocking of illegal or inflammatory content, primarily operating under Section 79(3) bravo of India's IT rules. This involves collaboration with various intermediaries to ensure swift removal of malicious content, including fraudulent advertisements and spoofed websites.
Criminals, in turn, exploit various technical and social vectors:
- Mule accounts are a cornerstone of their financial infrastructure. These accounts are often procured through social engineering (e.g., luring individuals with offers of ₹5,000-₹10,000 per month for sharing bank credentials), or by using dummy/stolen identities. They specifically target accounts with low organic transaction volumes, making them less conspicuous.
- Payment aggregators, virtual accounts, and cryptocurrencies are key channels for money laundering, providing layers of obfuscation for stolen funds.
- SMS headers are spoofed to create urgency or legitimacy for phishing attempts.
- Spoofed websites mimic legitimate services or national events, often embedding payment links to defraud victims.
- Social engineering is pervasive, leveraging AI and deepfake technologies. Criminals use deepfakes of public figures to advertise fake loan and investment apps on platforms like Instagram and Facebook. They also embed Trojans in seemingly innocuous image or video files shared on dating apps. These Trojans can gain control over a victim's device, including its microphone, allowing criminals to surreptitiously record conversations in sensitive environments, even if the user is not actively sharing data.
- The rise of "as-a-service" models on the dark web (e.g., Telecom Mule as a Service, Ransomware as a Service, Money Laundering as a Service, Hacking as a Service) significantly lowers the barrier to entry for aspiring criminals, providing ready-made toolkits and infrastructure for malicious activities.
I4C's technical strategy is thus a dynamic interplay of defensive infrastructure, investigative tools, and collaborative platforms, constantly evolving to counter the sophisticated and technologically adept methods employed by cybercriminals.
Demo / Proof of Concept
▶ Watch: Understanding cybercrime hotspots and mule accounts (6:50)
The talk primarily focused on describing the operational mechanisms, infrastructure, and strategic initiatives undertaken by the Indian Cyber Crime Coordination Center (I4C) to combat cybercrime. It detailed the processes, systems, and collaborative efforts in place, such as the 1930 helpline, the CFC RMS portal, and the real-time money tracking system within the CFMC. However, the speaker did not present a live demonstration or a proof of concept of any specific tool, exploit, or system during this presentation. The emphasis was on the organizational and procedural aspects of India's national response to cyber fraud.
Defensive Implications
▶ Watch: How criminals channelize and launder stolen funds (9:50)
The insights shared in this talk carry significant defensive implications for various stakeholders, from individual citizens to national agencies and global technology companies. A multi-layered defense strategy is imperative to counter the evolving threat landscape.
For Individual Citizens:
- Rapid Reporting is Paramount: The most critical defense against financial cyber fraud is immediate reporting. Victims must contact the 1930 helpline or lodge a complaint on
cybercrime.gov.inwithin the "golden hour," ideally 10-15 minutes, of realizing they have been defrauded. This window is crucial for I4C's CFMC to freeze funds before they are moved through multiple mule accounts or converted. - Vigilance Against Social Engineering: Be highly skeptical of unsolicited communications that play on emotions like greed (e.g., lucrative investment/loan offers), panic (e.g., threats of account deactivation, KYC updates), trust (e.g., fake bank officials), fear (e.g., digital arrests), or lust (e.g., dating app scams).
- Media File Caution: Exercise extreme caution when opening images, videos, or links from unknown sources, especially those received on dating apps or suspicious platforms. These can contain Trojans or malicious code that can compromise device microphones and other functionalities, leading to surreptitious data exfiltration even without explicit sharing.
- Verify Information: Always independently verify any claims, offers, or threats by contacting official channels directly, rather than relying on provided links or contact numbers.
For Financial Institutions (Banks, Payment Aggregators):
- Strengthen Mule Account Detection: Banks must implement advanced fraud detection systems to identify and flag suspicious transaction patterns indicative of mule accounts. This includes monitoring accounts with sudden, high-volume transactions that lack organic activity, especially those linked to specific geographical hotspots identified by I4C.
- Real-time Fraud Response: Enhance internal coordination with I4C's CFMC and similar national frameworks to facilitate immediate freezing of defrauded funds. This requires dedicated personnel and robust, integrated systems for rapid information exchange.
- Customer Awareness: Actively educate customers about common cyber fraud tactics, the dangers of sharing credentials, and the importance of timely reporting.
For Telecom Providers:
- Combat "Telecom Mule as a Service": Work closely with law enforcement and regulatory bodies to identify and neutralize services that provide telecom infrastructure for malicious use. This includes cracking down on the fraudulent issuance of SIM cards and misuse of SMS headers for phishing.
For Internet Intermediaries (Meta, Google, Social Media Platforms):
- Proactive Content Moderation: Implement and continuously improve AI engines and due diligence processes to filter out fraudulent advertisements, deepfakes, and malicious content before they are published.
- Compliance with IT Rules: Adhere strictly to amendments in IT rules, collaborating with agencies like I4C to take down illegal content quickly via portals like SAHO. This includes removing fake loan apps, investment schemes, and accounts promoting human trafficking.
For Law Enforcement Agencies (LEAs) and Intelligence Agencies:
- Leverage I4C Resources: Fully utilize the 1930 helpline, CFC RMS, CFMC, NCT-TAW, and SUMAN MAPAP portal for intelligence sharing, investigation assistance, and inter-state coordination.
- Capacity Building: Actively participate in training programs like the "cyber commandos" initiative to enhance cyber investigation and forensics skills. The goal of creating 5,000 cyber commandos over five years highlights the critical need for specialized human resources.
- International Cooperation: Strengthen collaboration with international partners (e.g., Thailand, Cambodia, Myanmar) to combat cross-border cybercrime, particularly human trafficking schemes that fuel cyber slavery.
For Academia and Industry:
- Strategic Collaboration with I4C: Engage with I4C on offered collaboration areas, including threat intelligence, cyber forensics, legal aspects, capacity building, R&D, and tool development. This partnership can drive innovation in defensive technologies and strategies.
- ROI on Security: Develop clear Key Performance Indicators (KPIs) that translate security investments into tangible returns, such as the number of attacks mitigated and money saved. This will elevate cybersecurity to an executive priority at the board level and strengthen the CISO mechanism.
By adopting these defensive strategies collectively, stakeholders can create a more resilient digital ecosystem, making it significantly harder for cybercriminals to operate and succeed.
Key Takeaways
- Escalating Threat: Cybercrime in India is experiencing an exponential rise, with financial losses reaching ₹22,000 Crores in 2024. It has evolved from petty individual acts to sophisticated, organized operations, often backed by state adversaries.
- I4C's Impact: The Indian Cyber Crime Coordination Center (I4C) has demonstrated tangible success, reducing the rate of financial loss in 2025 and significantly improving the recovery rate of defrauded money to almost 25% by leveraging its multi-faceted infrastructure.
- Critical "Golden Hour": For financial cyber fraud, the first 10-15 minutes after the incident are crucial. Rapid reporting via the 1930 helpline or
cybercrime.gov.inenables I4C's CFMC to freeze funds before they are laundered through mule accounts or moved offshore. - Social Engineering & Tech Exploitation: Social engineering remains the primary vector, exploiting emotions like greed, panic, trust, fear, and lust. Criminals extensively misuse technology, including deepfakes for advertising fake apps, Trojans embedded in media files, and "as-a-service" models on the dark web for various malicious activities.
- Collaborative Defense: Effective defense against cybercrime requires robust collaboration among law enforcement agencies (utilizing platforms like SUMAN MAPAP), financial institutions, telecom providers, internet intermediaries (for content moderation), academia, and industry, alongside international cooperation to combat cross-border threats like human trafficking.
- Executive Priority & Measurable ROI: Cybersecurity must be elevated to an executive and board-level priority. Organizations need to define clear KPIs to demonstrate the tangible Return on Investment (ROI) of security measures, showcasing money saved through prevented and mitigated attacks.
About the Speaker(s)
The speaker for this insightful talk is the Director of the National Cyber Crime Training Center (NCTC) at the Indian Cyber Crime Coordination Center (I4C), operating under the Ministry of Home Affairs. In this pivotal role, they are responsible for overseeing training, capacity building initiatives, and various information security aspects for the nation.
Prior to their current position at I4C, the speaker served directly with the Ministry, where they played a crucial role in coordinating efforts with a wide array of stakeholders. These included key national agencies such as CERT-In, NCIC, NS, and intelligence agencies like IB. Their responsibilities encompassed dealing with critical policy matters, process development, and other essential elements necessary to foster a safe and secure cyberspace for India. The speaker's extensive background provides them with a unique perspective on the operational challenges and strategic imperatives in the fight against cybercrime, as evidenced by their active involvement in initiatives like the creation of 5,000 "cyber commandos" and their open invitation for industry and academia to collaborate with I4C.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A substantive policy/intel briefing from someone who actually sits inside the machine — the financial loss trajectory data, the CFMC's 15-minute golden-hour mechanics, and the frank admission of state-backed adversaries funneling money offshore give this real signal value. It won't move a technical researcher, but for practitioners trying to understand India's national cybercrime response architecture, it delivers more than a press release.
Heather Calloway (CISO) — SOLID
A credible insider account of how India built a national cyber fraud response infrastructure, with real data on financial losses and recovery rates that translate directly to executive attention. The governance architecture is genuinely interesting, but the talk stays descriptive — it tells you what I4C built without giving the audience a transferable decision or a hard lesson learned.