Current Affairs · · Prelims · Internal Security

SPIR 2026: cyber fraud victims face bribes, delays and low recovery

A survey of 8,306 people across 16 States found that 13% had faced cybercrime in the previous two to three years. Among digital-financial-fraud victims and helpers, 72% recovered no money. Of surveyed victims who approached police, 27% reported paying a bribe. NCRB recorded 1,01,928 cybercrime cases in 2024, up 17.9%.

Event date:

REq1

The brief in 5 cards

  1. Context1 / 5

    The Status of Policing in India Report (SPIR) 2026, Cybercrime: Victim Perspectives and Systemic Responses, examines how people experience cybercrime and seek help. Common Cause and Lokniti-CSDS surveyed 8,306 people in 16 States and conducted qualitative interviews.

    In the survey, 13% said they had faced cybercrime in the previous two to three years. Separately, NCRB recorded 1,01,928 cybercrime cases in 2024, up 17.9% from 86,420 in 2023, while total registered cognisable crime fell by about 6%.

    The central issue is what happens after a fraud: reporting, police and bank response, and recovery of lost money.

  2. Key highlights2 / 5

    More online activity was associated with greater exposure to scam calls and messages. NCRB classified 73,987 of the 1,01,928 registered cybercrime cases in 2024 as fraud, or about 72.6%.

    The survey shows how the route from reporting to recovery can vary across groups. Each figure below refers to the named survey group, not to all cybercrime cases.

    Survey indicatorFinding
    Respondents reporting cybercrime in the previous 2–3 years13%
    Cybercrime victims reporting digital financial fraud54%
    Digital-fraud victims and helpers recovering no money72%
    Digital-fraud victims and helpers informing their bank within 24 hours63%
    Victims who approached police and reported paying a bribe27%
    Poor vs rich victims reporting a police bribe51% vs 12%
    Women vs men reporting a police bribe35% vs 22%
    Rich vs poor victims attended within an hour49% vs 16%
    Rural vs urban victims making at least five police visits38% vs 19%

    The report also found that those who said they paid a bribe were more likely to report full recovery (38% vs 12%). This is an association in survey answers; it does not establish that paying a bribe caused recovery.

  3. Key concepts3 / 5

    Social engineering

    Fraudsters persuade a person to transfer money or reveal information. Fake delivery, investment and bank-official calls exploit trust, fear or the hope of a gain.

    Mule account

    An account used to receive and move fraud proceeds. A Layer-1 mule account receives money directly from the victim. Rapidly stopping the first transfer can aid recovery.

    Who responds?

    Police and public order are State subjects. State police register cases and investigate. The Union supports coordination through the Indian Cyber Crime Coordination Centre (I4C), an attached office of the Ministry of Home Affairs.

  4. Note4 / 5

    Government response: figures to 30 June 2026

    The central response combines reporting, rapid fund blocking, shared identifiers and training. These official figures describe different activities and should not be added together.

    ToolRoleOfficial figure to 30 June 2026
    CFCFRMS, launched in 2021Helps banks and police stop fraud proceeds movingOver ₹11,158 crore saved across over 32.80 lakh complaints
    Suspect Registry, launched 10 September 2024Shares suspect identifiers with banksOver 32.08 lakh Layer-1 mule accounts shared; ₹25,698 crore in transactions declined
    App blocking under IT Act Sections 69A and 79(3)(b)Blocks fraudulent apps, including loan apps3,718 apps blocked
    NCRP–CFCFRMS standard procedureGuides complaints, bank coordination, lien removal and restorationNo numeric figure stated
    CyTrainTrains police and judicial officers onlineOver 1.63 lakh officers registered

    The National Cyber Crime Reporting Portal (NCRP) and 1930 helpline are reporting channels. Money the system describes as “saved” is not necessarily money returned to victims.

  5. Way forward5 / 5

    Suggested measures

    • Act in the first hour: Improve bank, police and telecom coordination so suspect funds can be stopped promptly.
    • Make complaints trackable: Set clear milestones and audit delays and demands for payment. Apply the existing national procedure consistently.
    • Strengthen investigation: Expand cyber-forensic training and cooperation across States.
    • Reach underserved groups: Offer local-language fraud awareness and accessible help desks, particularly for rural residents, poorer households and women.

    The survey shows that prompt bank reporting alone does not ensure recovery: 63% reported within a day, yet 72% reported recovering nothing.

Sources

Syllabus

PaperSubjectSub-topic
PrelimsInternal SecurityCybercrime, I4C, reporting channels and the Information Technology Act
GS3Internal SecurityCybersecurity, communication networks and financial fraud
GS2GovernancePolice accountability, access to redress and vulnerable groups

Topics

GovernanceMiscellaneous PolityInformation and Communication Technology

Related previous-year questions

Asked in earlier UPSC Prelims papers on this topic. Answer, then check.

  1. UPSC Prelims 2020 · International Relations and Current Affairs · Current Affairs

    In India, under cyber insurance for individuals, which of the following benefits are generally covered, in addition to payment for the funds and other benefits? 1. Cost of restoration of the computer system in case of malware disrupting access to one's computer 2. Cost of a new computer if some miscreant wilfully damages it, if proved so 3. Cost of hiring a specialized consultant to minimize the loss in case of cyber extortion 4. Cost of defence in the Court of Law if any third party files a suit Select the correct answer using the code given below:

    1. 1, 2 and 4 only
    2. 1, 3 and 4 only
    3. 2 and 3 only
    4. 1, 2, 3 and 4
    Show answer

    Answer: B. Cyber Insurance is designed to guard businesses from the potential effects of cyber-attacks. It helps an organisation mitigate risk exposure by offsetting costs, after a cyber-attack/breach has happened. Option 1 is correct: Cost of restoration of the computer system in case of malware disrupting access to one's computer is covered under cyber insurance. Option 2 is incorrect: Cyber insurance covers costs arising from cyber breaches — not physical damage to hardware by a miscreant. Physical damage to a computer by a person is covered under property insurance, not cyber insurance. Option 3 is correct: Cost of hiring a specialized consultant to minimize the loss in case of cyber extortion is a covered benefit. Option 4 is correct: Legal expenses arising out of any covered risk, including defence costs if a third party files a suit, are covered. Correct options: 1, 3 and 4 → Option (b).

    Difficulty: hard · statement

    Open this question on its own page, with the full explanation →

  2. UPSC Prelims 2017 · Science and Technology · Information and Communication Technology

    In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data centres 3. Body corporate Select the correct answer using the code given below:

    1. 1 only
    2. 1 and 2 only
    3. 3 only
    4. 1, 2 and 3
    Show answer

    Answer: D. VERDICT: The answer is 1, 2 and 3. Service providers, data centres and body corporates are all legally required to report cyber security incidents. ANALYSIS: Under the information technology framework, the Indian Computer Emergency Response Team serves as the national nodal agency for cyber security, collecting, analysing and disseminating information on cyber incidents, issuing forecasts and alerts, and coordinating incident response. The rules made under the Act make mandatory reporting of cyber security incidents applicable to service providers, intermediaries, data centres and body corporates alike, so all three categories in the question are covered. SOURCE: Press Information Bureau release and the Information Technology Act framework. Source type RR. HOW TO CRACK IT: Reason from the purpose of a national incident response agency. Such a body can only function if it receives reports from every entity that holds or moves data, so a reporting duty confined to one category would defeat the design. Where a regulatory obligation exists to build a national picture, expect the obligation to be broad rather than narrow, and expect the inclusive option. Keep CERT-In tagged as the nodal agency, since that single fact anchors the whole topic.

    Difficulty: hard · statement

    Open this question on its own page, with the full explanation →

Practice questions

  1. Consider these statements about India’s response to cyber fraud: 1. I4C is an attached office under the Ministry of Home Affairs. 2. The Reserve Bank of India maintains the Suspect Registry. 3. Helpline 1930 helps people report financial cyber fraud. Which statements are correct?

    1. 1 and 2 only
    2. 1 and 3 only
    3. 2 and 3 only
    4. 1, 2 and 3
    Show answer

    Answer: B. Statements 1 and 3 are correct. I4C launched the Suspect Registry with banks and financial institutions.

    Difficulty: medium · statement

  2. Consider these statements about mule accounts: 1. A mule account can receive and pass on fraud proceeds. 2. A Layer-1 mule account receives money directly from the victim. 3. Its holder is always the fraud’s mastermind. Which statements are correct?

    1. 1 and 2 only
    2. 2 and 3 only
    3. 1 and 3 only
    4. 1, 2 and 3
    Show answer

    Answer: A. Statements 1 and 2 are correct. An account holder may be an intermediary and need not be the person directing the fraud.

    Difficulty: medium · statement

  3. Consider these statements about SPIR 2026: 1. Common Cause and Lokniti-CSDS produced it. 2. It is an annual NCRB publication. 3. Its 27% bribery finding concerns surveyed victims who approached police. Which statements are correct?

    1. 1 and 2 only
    2. 1 and 3 only
    3. 2 and 3 only
    4. 1, 2 and 3
    Show answer

    Answer: B. Statements 1 and 3 are correct. SPIR is a survey report; NCRB publishes Crime in India. The bribery denominator includes victims who approached police, including some who did not pursue the case.

    Difficulty: medium · statement

Mains practice

Answer-writing practice on this article. Attempt it first, then open the hints.

  1. GS3 · 150 words

    Victims from poorer and rural groups face greater barriers in obtaining justice for cybercrime. Examine the institutional gaps and suggest measures.

    Show hints
    1. Contrast rising registered cybercrime with the wider crime trend.
    2. Use survey findings on repeat visits, bribery and unequal waiting times.
    3. Explain gaps between complaint, bank action and fund recovery.
    4. Assess police capacity and coordination across States.
    5. Suggest trackable complaints and local-language support.
  2. GS3 · 150 words

    Critically examine the role of I4C and CFCFRMS in tackling financial cyber fraud. What limitations remain?

    Show hints
    1. Distinguish the State police role from the Union coordinating role.
    2. Explain how CFCFRMS and helpline 1930 support quick action.
    3. Describe the Suspect Registry and Layer-1 mule accounts.
    4. Distinguish money marked as saved from money refunded.
    5. Use SPIR findings on victims who recovered nothing.