By Sunil Garodia
First publised on 2026-08-02 06:07:16
The pattern from yesterday's piece on tax-season phishing did not take long to repeat itself under a new institutional name. Since August 1, physical enumeration for Census 2026 has been underway across the country, following a self-enumeration window in which households were invited to complete their details online before an enumerator's visit, and cybercriminals have moved into this process with the same speed and the same playbook they applied to the Income Tax Department a fortnight earlier.
The genuine process is worth stating plainly, because its simplicity is precisely what the fraud depends on people not knowing. Self-enumeration is completed on a single official portal, se.census.gov.in, where a resident enters a mobile number, a captcha and an OTP, selects their state and address, and answers a housing schedule covering matters as routine as construction material, drinking water source and whether the household owns a television or a two-wheeler. According to official guidance issued alongside the self-enumeration facility, the exercise takes fifteen to twenty minutes, and anyone with their basic household details at hand will finish comfortably inside ten. No Aadhaar card, no PAN, no bank passbook and no supporting document of any kind is required at any stage, and the process does not cost a rupee. A household that completes it correctly receives a unique Self-Enumeration ID by SMS, and produces that ID when the enumerator eventually calls, which is the entire transaction from start to finish.
Fraudsters have built three variations on top of this genuine process, and each has already generated advisories from state cyber cells. The first is the phone call or WhatsApp message impersonating a census official, requesting family details, Aadhaar numbers and banking information under the pretext of registration or verification, a request the actual process never makes at any stage. The second, and the more damaging of the three, involves persuading the victim to install a screen-sharing application such as AnyDesk or TeamViewer, framed as a "census verification app," which then hands the caller live visibility into the victim's banking apps and the ability to operate them directly. Rajasthan Police's cyber crime branch has documented this pattern specifically, alongside a third variant in which door-to-door impostors carrying tablets ask residents to scan a QR code or "confirm" their Aadhaar number on the impostor's device rather than their own.
Every institution that enters citizens' lives eventually acquires a digital doppelganger. The census has merely become the latest, but it carries one vulnerability the tax notices did not. Unlike tax filing, which most salaried Indians encounter every year and have some instinct for, Census 2026 introduces millions of households to an online government process they have never previously used, since the country's last census was conducted in 2011 and this is the first to offer digital self-enumeration at all. Novelty itself becomes a security vulnerability in a case like this. People are less able to recognise what is abnormal in a process when they have no prior experience of what normal looks like, which is precisely why a stranger offering to "help" with the form, or a caller asking for an OTP "to complete registration," sounds plausible to a first-time user in a way it would not to someone filing a familiar annual return.
If the tax filing deadline produced the Income Tax Department's doppelganger, the census has now acquired one of its own. The disguise has changed, but the mechanics have not. Authority, urgency and procedural unfamiliarity remain the three ingredients of almost every successful impersonation campaign, and the census supplies all three more generously than the tax notices did, because it arrives not merely as a message on a screen but as an apparently legitimate person standing at the front door, and asks nothing that sounds implausible until the specific moment it asks for an OTP. The genuine census, like the genuine tax department, never needs a citizen's password, OTP or remote access to a device, and any communication or visit that asks for these should be read as disqualifying itself rather than as unusually thorough.
This is also where the appeal of outside help becomes its own risk. Because the process is unfamiliar to a population encountering a digital census for the first time in fifteen years, some households will be tempted to accept assistance from a stranger who offers to "help complete the form," whether over a phone call or at the door. The genuine form does not reward this instinct, since it asks nothing that a literate adult cannot answer alone in the time it takes to boil a kettle, and every version of "help" that involves screen-sharing software, a QR code scan on someone else's device, or a request for a fee, is itself evidence that the helper's interest lies elsewhere. The safest rule is close to the one I gave for the tax notices: complete the process only through se.census.gov.in, entered manually into a browser rather than through a forwarded link, share the OTP with no one, and treat any enumerator or caller who asks for banking details, a payment, or a screen-sharing app as evidence of fraud rather than an unusually eager official. Genuine grievances or suspicious visits can be verified with the local Booth Level Officer or reported to the national cybercrime helpline, 1930, without any cost to the citizen either way.
The real lesson extends well beyond Census 2026. As more government services migrate online, every major public exercise, whether taxation, enumeration, welfare distribution or elections, will almost certainly acquire its own digital doppelganger. The institutions will modernise. So will those seeking to impersonate them. The citizen's most valuable habit, therefore, is not technological sophistication but procedural scepticism: verify first, comply later.










