Written by Ayushi Srivastava is a fifth-year student at the National Law University Odisha.
Introduction
According to the National Human Rights Commission (NHRC), over the past six years, Indians lost a staggering ₹52,976 crore to cyber fraud, with nearly 8% linked to the rising menace, the Digital Arrest Scams. This scam, where fraudsters pose as law enforcement officers or government officials, is spreading like wildfire, with 1,23,672 complaints filed in 2024, representing a massive jump from 39,925 in 2022.
This scam’s modus operandi includes scammers using high-pressure audio or video calls to trap victims, accusing them of crimes like money laundering, tax evasion, or drug trafficking. This creates a sense of anxiety due to concern over damage to reputation and the potential consequences for family members hampering the decision-making of individuals, which is also exacerbated due to the pressure created for immediate decisions, leaving no room for consultations with others or verification of the claims. The primary question here arises, that with cybercriminals getting more sophisticated, how are law enforcement agencies fighting back?
Understanding Cyber Laws: Key Regulations and Frameworks
The root of digital arrest scams lies in a combination of data breaches, psychological coercion, impersonation, and financial fraud, all of which constitute individual offences under the Bharatiya Nyaya Sanhita. However, their implications under cyber laws require special attention. In this context, the rising threat of digital arrest fraud falls under the purview of two key legislations in India, the Information Technology Act, 2000 (IT Act, 2000) and the Digital Personal Data Protection Act, 2023. These laws define the offences related to cyber fraud, prescribing penalties not only for the perpetrators but also for third parties involved in unlawfully providing victims’ personal data.
The first step of this scam is the breach of sensitive and confidential information provided by individuals to third-party platforms. Most commonly, the fraudsters committing digital arrest obtain personal sensitive information, which is sold on the dark web either by cyber criminals through targeted hacking of third-party platforms or intermediaries due to weak firewalls and obsolete software or by such platforms themselves for personal gain. Data fiduciaries are under an obligation to safeguard personal data in its possession or control, including any processing done by a Data Processor on its behalf. Such platforms are required to implement appropriate technical and organisational measures for the protection of data and to prevent data breaches. Further, in case of a data breach, the third-party platform is required to promptly inform the affected individuals and the Data Protection Board of India (DPBI). The Act imposes additional obligations on entities classified as Significant Data Fiduciaries (SDFs), which handle a large volume and high sensitivity of personal data as it increases, potential risks to Data Principals’ rights, and broader impacts on national sovereignty, electoral integrity, security, and public order. An intermediary, who, in the course of providing services under a lawful contract, gains access to material containing another person’s personal information and, with the intent to cause or with knowledge that such disclosure may cause wrongful loss or wrongful gain, shares this information with a third party, without the consent of the individual or in violation of a lawful contract, may attract liability under Section 72A of the IT Act, including imprisonment for up to three years, a fine of up to five lakh rupees, or both. Also, a corporate entity that owns, controls, or operates a computer resource that processes sensitive personal data is liable to compensate the affected individual for the damages caused in case of failure to implement reasonable security measures, resulting in wrongful loss or gain to any person under Section 43 the IT Act, 2000. The Data Protection Board Of India can also impose a monetary penalty on a person, after providing an opportunity to be heard if he has committed a personal data breach, which is determined based on factors such as the severity, duration, and repetition of the breach, the type of data affected, any gains or losses incurred, mitigation efforts, and the need for deterrence.
The fraudsters for getting access to information may also resort to hacking where they dishonestly receive or retain a stolen computer resource or communication device, by having the knowledge or reason to believe that it is stolen, making them liable to be punished with imprisonment for up to three years, a fine of up to one lakh rupees, or both under Section 66B of the IT Act, 2000. While reaching out to the victims the scammers falsely assume the identity of government officials with the intent to mislead or deceive making them liable under Section 66D of the IT Act, 2000 which provides that anyone who commits cheating by personation using a communication device or computer resource shall be subject to imprisonment for up to three years and may also face a fine of up to ₹1 lakh. Additionally, Section 66C of the IT Act, 2000 makes it punishable with imprisonment of up to three years and a fine of up to one lakh rupees for anyone who fraudulently or dishonestly uses another person’s electronic signature, password, or any other unique identification feature.
Challenges In Digital Arrest Regulation In India
The Information Technology Act of 2000 has been very instrumental in combating the menace of cybercrime and digital fraud in India. Operating alongside the IPC and other Indian laws, covering the internet and related technologies, it provides legal safeguards for individuals in combating cybercrime, whether a computer is used as a tool or targeted directly. However, the Act did not cover data protection and privacy and to ensure this the Digital Personal Data Protection (DPDP) Act in 2023 was introduced. The Act regulates digital personal data processing and ensures data protection while allowing lawful use, grants individuals rights over their data, including access, correction, deletion, and grievance redressal, with penalties for violations. The digital arrest regulation in India suffers from a concoction of both legal and technical challenges.
Among the legal challenges, the primary one is the absence of a formal definition of digital arrest in the present cyber laws in India, leading to ambiguity in its interpretation and application. Secondly, though the IT Act, 2000 and DPDP Act, 2023 elaborately discuss hacking, identity theft, unauthorised data access, impersonation and financial fraud, however, they do not discuss psychological coercion, one of the most imperative components of digital arrest. Another important issue is no clear accountability of third-party platforms in cases of data leaks, which is due to the presence of safe harbour provisions in the present cyber legislation. This provision is imbibed under Section 79 of the IT Act, 2000 which provides, an exemption to intermediaries from liability for third-party information, data or communication links hosted or transmitted through their platforms, if the intermediary merely provides access to a communication system, does not initiate, select, or modify the content, and complies with due diligence and government-prescribed guidelines. Entities and individuals who collect sensitive personal data and information also function as intermediaries when they store and distribute such information. Thus, in case of an accidental data leak or leak by a hacker, intermediaries won’t be held liable, however, this protection is lost if the intermediary actively participates in unlawful activities by conspiring, abetting, or inducing them. Additionally, if notified by the government or an agency about illegal content, the intermediary must promptly remove or disable access to it; failure to do so results in liability.
According to data released by the Ministry of Home Affairs (MHA), 46% of digital fraud cases, including digital arrests, trading scams, task-based investment scams, and romance/dating scams, were linked to scammers operating from Myanmar, Laos, and Cambodia. The primary problem stems from the issue that the DPDP Act, of 2023, allows the transfer of data to other territories outside India, however, it does not elaborate upon the kind of data transferred and the purpose for which it is transferred, resulting in cross-border transfer of data which is often sensitive in nature. When the data is transferred outside the Indian territories, the scammers utilise Voice over Internet Protocol (VoIP), a sophisticated technology enabling phone calls and other forms of communication over the Internet, to conceal their true identities. Fraudsters for this illicitly obtain SIP trunk services from Indian telecom providers Jio and Tata Tele Services, enabling them to generate Indian landline numbers which creates a false sense of authenticity, deceiving victims. To catch hold of them, the police had to trace the IP of these calls, which can also be challenging at times. The issues faced while tracing the IP address of calls include constant change by the fraudsters to avoid getting caught, the use of VPNs to obscure a user’s location, shared IP addresses among multiple individuals on a network, the inaccuracies of geolocation tracking, and privacy safeguards that restrict ISPs from easily disclosing detailed user data all contribute to the challenge of identifying a specific person or device behind an IP address.
Other than the technical difficulties in tracing the IP address of calls made, there is the problem of Cross-Border Data Access for Law Enforcement, to investigate the digital arrest crimes committed locally. To investigate cross-border crimes, countries tend to sign the Mutual Legal Assistance Treaty (MLAT), a framework for international cooperation, allowing countries to assist each other in preventing, investigating, and prosecuting crimes, ensuring criminals cannot evade justice due to evidence being located in different jurisdictions. When the countries do not have an MLAT one of the methods to gain access to outside border data is through a Letter Rogatory (LR), an official request from an Indian criminal court, made on behalf of an investigating agency, asking a foreign court or authority to help collect evidence however, both MLAT and LR suffers from various loopholes. Accessing information through the MLAT or LR process is slow and complex, requiring coordination between multiple agencies, which can often be cumbersome and cause significant delays. The granting of Mutual Legal Assistance (MLA) depends on the requested State’s laws and willingness to cooperate. Ideally, refusals should be minimal and rare, as per international standards, however, in practice, different principles allow refusals, making obtaining assistance difficult. MLAT also raises privacy concerns as they are general agreements with little specifics on data transfer processes or user protections, which can lead to potential harm to users’ rights. Moreover, the absence of uniform guidelines for processing Letters Rogatory leads to variability in how countries handle such requests as some nations may require extensive documentation or impose specific procedural prerequisites, causing delays and inconsistencies in judicial cooperation.
Recent Judicial Response and its Limitations
While the existing legal framework addresses some aspects of the digital arrest scams, significant gaps still linger in their prevention, inter-agency coordination, financial recovery and victim protection. In its attempt to secure a coordinated institutional response to digital arrest the Hon’ble Supreme Court of India in August 2026 took suo motu cognizance of the menance of digital arrest and issued a series of directions aimed at strengthening the mechanism for prevention, investigation, and restoration of the defrauded money to the victims.
The Court directed the Reserve Bank of India to formulate a Standard Operating Procedure (SOP) for placing temporary debit holds on the accounts connected with money-mule activity and cyber-enabled fraud. It further gave directions to all the States and law enforcement agencies to operationalize grievance redressal and money-restoration mechanisms. States that had not yet notified and operationalized their State Cybercrime Coordination Centres were directed to do so and take steps for the adoption of e-Zero FIR mechanism. The court further called for a scheme for shared-liability and victim-compensation be considered. The CBI was asked to study whether the ₹10 crore limit for initiating investigations was appropriate and whether cases that involved the same organized group could be combined. Further, the Ministry of Communication and Information Technology, Department of Telecommunications, and Indian Internet & Mobile Association were asked to consider whether there could be a “kill switch” based on time for audio and video communications and the Department of Telecommunications was requested to examine problems related to the SIM card misuse. The Court also directed to explore the possible technological steps for assisting in prevention, recovering, investigation of digital arrest.
These directions are much heralded as steps toward strengthening prevention, institutional coordination and victim restitution. However, these directions do not in entirety resolves the structural challenges associated with digital arrest scams. Firstly, the directions are largely implementation oriented and particularly fails to address substantive gaps in the existing legal framework. Administrative coordination merely cannot remedy the problem of digital arrest scams, in the absence of statutory framework addressing them. The apex Court’s consideration of digital arrest frauds as a standalone offence further underscores that institutional mechanism must be supported by legislative reform. Secondly, with regard to the proposed temporary debit hold mechanism, an account identified being associated with money-mule activity may not necessarily belong to a person involved in the fraud and may have been misused without the account holder’s knowledge. Its effectiveness will thus depend on the clear criteria for imposing a hold, maximum periods for a debit hold, periodic review and a rapid mechanism to challenge the restriction. Thirdly, the mere establishment of a money restoration mechanism does not necessarily guarantee actual recovery. This is because, digital arrest scams may involve the rapid movement of funds through intermediary accounts. Thus, the difference between freezing, tracing, recovering and ultimately restoring the funds is of great importance. It might be the case that by the time the victim reports the fraud, the money may have moved beyond the immediate banking system. Therefore, the success of the restoration system will depend not on it’s availability but on the speed with which complaints are processed, suspicious transactions are tracked and funds are frozen. Fourthly, the proposed shared-liability and victim-compensation framework also depicts an unresolved aspect of the problem. This leaves a major question to be considered i.e., where the perpetrators cannot be identified or the defrauded money cannot be recovered who should bear the loss ultimately? The answer to this may involve difficult questions concerning the respective responsibility of banks, payment intermediaries, telecom service providers, data fiduciaries and victims themselves. A comprehensive framework would therefore need to establish clear principles for allocating liability rather than relying solely on the recovery of funds from individual perpetrators. Fifthly, the proposed time-based “kill switch” for audio and video calls though helpful in disrupting fraudulent communications raises questions about technology feasibility, false positives and proportionality. Thus, it would only be a success if defined triggers to distinguish fraudulent interactions from legitimate calls, safeguards against arbitrary or excessive interference with lawful communications exists. Lastly, the primary focus of these directions remains on the financial, technological and institutional aspects of digital arrest scam with leaving little attention to psychological coercion which forms the core of the scam. The success of this scam depends not merely on the technological and infrastructural issues but because the victims are manipulated through fear, impersonation, urgency and isolation. Thus, while the Supreme Court’s intervention represents an important step towards strengthening India’s institutional response, its effectiveness will ultimately depend on various other factors.
Conclusion
According to The Economic Times report, there is no provision for Digital Arrest worldwide. The recent guidelines demonstrate that there is an increasing awareness in India of the need for a coordinated approach, quick financial action, accountability, and redress of victims. However, its success will depend entirely upon their consistency and ability to cover issues associated with digital arrest other than those relating to financial scams.
Time and again MLATs have proven to be tedious, which hampers getting cross-border data. It is crucial to bring legislation which eliminates foreign government agencies and requests data directly from tech companies stored outside India. For this cue, can be taken the Clarifying Lawful Overseas Use of Data (CLOUD) Act, enacted by the U.S. in March 2018, helps the US government and foreign partners with whom executive agreements have been signed to quickly access electronic evidence stored by U.S.-based tech companies stored on servers outside U.S. territory for serious crime investigations, including terrorism, cybercrime, and child exploitation giving them direct access to electronic evidence. Similar to the CLOUD Act, the EU e-Evidence Regulation enhances access to electronic evidence by enabling authorities in one Member State to directly request data from service providers in another Member State. The Regulation also provides the time period within which the data has to be transferred. Under normal circumstances, the service provider must deliver the requested electronic evidence to the issuing authority within 10 days of receiving the European Production Order Certificate (EPOC) while in urgent situations, the provider has 8 hours to transmit the requested data.
The safe harbour provision under Section 79 of the IT Act, 2000 has cultivated a dynamic online space, promoting free speech and allowing internet users to express themselves without unwarranted interference by shielding intermediaries from liability for third-party content. However, it has also been criticised for allowing platforms to escape liability in case of data breaches unless actively participated. While the Indian government time and again has reconsidered Section 79 of the IT Act, 2000, it is important to understand the repercussions associated with it. Therefore, rather than a complete removal of the Safe Harbour Clause, India can introduce provisions similar to Section 83 of the General Data Protection Regulation which penalizes organisations for accidental data breaches with the maximum penalty reaching €20 million or 4% of a company’s annual global revenue, whichever is greater, based on the severity of the breach and the mitigation efforts undertaken.
Another important challenge while dealing with digital arrest is the non-inclusion of psychological coercion using electronic devices in the present legal landscape of India. One can take reference from the Online Safety Act, of 2023 which introduces three new offences related to of psychological coercion through online communications for individuals as follows firstly, sending or posting a message that contains a serious threat of harm secondly, sending a communication with the intent to cause psychological harm or severe emotional distress and thirdly, intentionally sending false information with the aim of causing harm. It makes a person commiting an offence liable, if they knowingly send a false message with the intent to cause non-trivial psychological or physical harm to a likely audience which includes individuals who are reasonably expected to encounter the message or its forwarded version online, and the offence applies even if harm was not intended for a specific person but rather a broader group and without a reasonable excuse penalising them with imprisonment of up to 6 months (or 51 weeks in certain cases) and/or a fine. Similar to the UK’s 2023 Act, Section 875 of the 18 U.S.C. makes it punishable to transmit a threat across state or international borders to harm someone’s property, or reputation (including that of a deceased person), or to falsely accuse someone of a crime for extortion purposes is punishable by a fine, up to two years in prison, or both.
Thus, a robust legal framework is essential to effectively combat the challenges posed by digital crimes, including digital arrest. Drawing from global best practices like the CLOUD Act, the EU’s e-Evidence Regulation, the GDPR, and the UK’s Online Safety Act, India can develop a balanced legal framework that ensures accountability while safeguarding fundamental rights. By integrating these measures, India can strengthen its cybercrime enforcement mechanisms and create a safer digital environment without stifling innovation or free expression.


Leave a Reply