Revision summary
Cybercrime targets persons, money, computers, and critical infrastructure, often in mixed form. Phishing, UPI fraud, ransomware, CSAM, and CII attacks are the live Indian set. IT Act plus ordinary criminal law, CERT-In, NCIIPC, I4C, and RBI rules are the state toolkit. Backups, MFA, platform duty, and forensic capacity are the practical layer. Most retail cases are social engineering, so literacy is a security control.
Model answer
Introduction
Cybercrime is offence in which a computer or a network is the target, the tool, or the scene of evidence. In India it rides cheap smartphones, UPI, and social media. Types differ; the fight has to mix criminal law, CERT-In, banks, and public habit — not only a new section in the IT Act.
Body
Types
- Against persons: phishing, SIM-swap, OTP fraud, sextortion, cyberstalking, morphing, and child sexual-abuse material online.
- Against property and finance: ransomware, business-email compromise, credit-card and UPI fraud, crypto-enabled laundering, and theft of intellectual property.
- Against the State and infrastructure: website defacement, DDoS, espionage, attacks on CII (power, finance, telecom), and information operations.
- Against computers themselves: malware, botnets, supply-chain compromise.
- Intermediary-enabled harms: fake news for riot, terror recruitment, and drug or arms markets on encrypted apps — crime that is social but cyber-delivered.
Legal and institutional measures
- IT Act, 2000 (with 2008 amendments): unauthorised access, data theft, impersonation, child pornography provisions; IPC/BNS for cheating, defamation, sexual offences that merely use a phone.
- Indian Computer Emergency Response Team (CERT-In) for incident response and directions; NCIIPC for designated critical information infrastructure.
- Police cyber cells, the I4C (Indian Cyber Crime Coordination Centre), and the national cybercrime reporting portal.
- RBI and NPCI rules for payment fraud, two-factor authentication, and bank liability frameworks.
- International: MLATs, Interpol, and cooperation even where India is cautious about the Budapest Convention’s politics.
Technical and social measures
- Hygiene: updates, MFA, segmented networks, backups against ransomware, and no internet-facing SCADA.
- Platform duty: faster takedown of CSAM and fraud pages; KYC on wallets; audit of large intermediaries.
- Literacy: most retail crime is social engineering. School and bank campaigns matter more than a new firewall logo.
- Capacity: trained magistrates and forensic labs so Section 65B evidence actually convicts.
- Supply chain: trusted telecom gear and software bills of materials for government and CII.
Flow diagram
flowchart TD T[Types] --> P[Person fraud abuse] T --> F[Finance ransomware] T --> S[State CII] M[IT Act CERT-In I4C] --> R[Response] H[Hygiene literacy MFA] --> R
Conclusion
Cybercrime ranges from OTP theft to ransomware on a grid. Fighting it needs the IT Act and IPC together, CERT-In and I4C, payment-system rules, and a public that does not type an OTP to a stranger. Technology without investigation and literacy will not close the menace.
Quick related
Students also ask
-
What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India.
Next question on this syllabus topic (2019 · Q10). View answer →
-
Is every WhatsApp cheat only an IT Act case?
Often it is IPC cheating plus IT Act sections. Charge-sheets should use both, not a ritual IT Act citation.
-
Can India arrest a foreign ransomware gang easily?
Attribution and extradition are slow. Resilience and payment-trail disruption matter as much as a wanted poster.
PYQ trend
When UPSC asked this
Related PYQs from other years, newest first. Open a question to read it.
-
2022 · Q19 · GS III · 15 marks
What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy. -
2021 · Q9 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels. -
2021 · Q10 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks. -
2019 · Q10 · GS III · 10 marks
What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India. -
2018 · Q19 · GS III · 15 marks
Data security has assumed significant importance in the digitized world due to rising cyber-crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space? (250 Words, 15 Marks). -
2018 · Q20 · GS III · 15 marks
India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks). -
2017 · Q9 · GS III · 10 marks
Discuss the potential threats of Cyber attack and the security framework to prevent it. -
2015 · Q18 · GS III · 12 marks
Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country.
More from this topic
Q19 · UPSC Mains 2022 · GS III · 15 marks
What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.
Cyber Security and Money Laundering
Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.
Q10 · UPSC Mains 2021 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.
Cyber Security and Money Laundering
Cross-border cyber operations can stall critical infrastructure, rob finance, and steal state data without a kinetic raid. Attribution problems let states and proxies hide behind criminal malware. CERT-In, NCIIPC, Defence Cyber Agency, sector CERTs, and the IT Act are the Indian defensive core. Segmentation, backups, vendor control, and phishing defence are the practical layer. Resilience and international CERT cooperation matter more than a claim of perfect security.
Q9 · UPSC Mains 2021 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels.
Cyber Security and Money Laundering
Global trade, hawala, shells, and now crypto and mule rails turn criminal cash into apparently clean assets. PMLA, FIU-IND, and regulator KYC are the core national tools. FATF, Egmont, and UN conventions organise the international chase and asset return. Technology also helps investigators if travel rules and chain analysis are funded. Beneficial ownership and virtual assets remain the soft spots.
Toppers' copies
Toppers' copies for this question will be uploaded soon.