By Sunil Garodia
First publised on 2026-08-20 10:34:51
Parliament has now said what cyber-fraud victims have known for years: India's response remains heavy on procedures and light on accountability
India likes to describe itself as a digital economy. UPI has transformed everyday payments, banking has moved onto smartphones, and millions now transact without touching cash. But when a citizen's money disappears from an account within minutes, the sophistication of that infrastructure seems to vanish with it. The victim is told to call 1930, file a complaint, approach the bank, and hope the money is frozen before it disperses through a maze of mule accounts. The criminals, it turns out, understand the system better than the system understands them.
A Parliamentary Standing Committee on Finance has now delivered an unusually blunt verdict on the government's handling of cyber-enabled financial fraud, rejecting the Department of Financial Services' reply as largely procedural and accusing it of ignoring critical operational gaps, particularly the use of mule accounts through which stolen money is rapidly siphoned away. That criticism deserves more attention than it has received, because behind every statistic is a citizen who has lost money, and increasingly that citizen is being asked to absorb the cost of weaknesses in a system the government, banks, regulators and police collectively control.
The scale is no longer deniable
Reported cybersecurity incidents rose from 10.29 lakh in 2022 to 22.68 lakh in 2024, and cyber frauds worth Rs 36.45 lakh crore had been reported on the National Cyber Crime Reporting Portal by February 28, 2025. In response, the government has built an alphabet soup of institutions: I4C, NCRP, CFCFRMS, the 1930 helpline, CERT-In, RBI's MuleHunter, NPCI's fraud-monitoring systems. None of this is in short supply. What is in short supply is accountability when these mechanisms fail. The CFCFRMS has helped save over Rs 5,489 crore across 17.82 lakh complaints, a real achievement, but one that raises an obvious question: if the system saves that much when it works, how much more could it save if it worked quickly and consistently?
The Golden Hour keeps slipping away
The committee identified time as the system's central weakness. In cyber fraud, the first three to four hours, the so-called "Golden Hour," often decide whether stolen funds can still be frozen. That window is routinely lost because victims report late and because district police frequently lack the technical capacity to coordinate with banks in real time. The real test isn't whether a sophisticated national architecture exists on paper, but whether, at 2 a.m., a bank can trace a transaction, freeze a receiving account, and act before the money moves again. If the answer is usually no, the architecture is mostly decorative.
Mule accounts and the moral hazard
The most troubling finding concerns mule accounts, the plumbing through which much of the fraud economy runs. The committee found the proposed compensation framework places 65 per cent of the burden on the RBI while beneficiary banks bear only 10 per cent, calling this a "severe moral hazard." If a bank's own KYC and monitoring systems fail to catch an account that behaves like a mule account, but the bank's liability is capped low regardless, there is little incentive to fix those systems. The committee's call for recalibrated liability and penalties for negligent branches goes to the heart of this.
Awareness cannot substitute for institutional protection
Citizens are routinely told not to click suspicious links or share OTPs, and that advice is necessary but not sufficient. A citizen can make one mistake; a bank has AI-driven monitoring, compliance teams and regulatory obligations, and the two cannot be treated as bearing equal responsibility. This is not the first warning either: a Standing Committee on Home Affairs said in August 2025 that cybercrime laws are fragmented and called for integrated legislation and stronger safeguards, meaning the Finance Committee's rebuke lands on a government that had already been told, and had already not fully responded.
Recovery, not reporting, is the real measure
India has gotten good at telling victims where to complain. It has not gotten good at answering the questions that actually matter: how much stolen money is recovered, how quickly mule accounts are frozen, how many negligent branches are penalised, how fast a police complaint translates into bank action. A portal that logs a complaint after the money is gone, or a helpline that records fraud after the Golden Hour has passed, is not a solution.
India cannot build a trillion-dollar digital economy on the assumption that citizens will simply get better at spotting criminals while the criminals keep adapting faster than the State does. Banks need real accountability for mule accounts, district police need the tools to act in minutes, and where institutional negligence contributes to a loss, the victim should not be left to absorb it alone. Until then, every successful cyber fraud remains not just a scammer's win, but a bill handed to an innocent citizen for the system's failures.









