oppn parties When the System Fails, the Cyber Fraud Victim Pays

News Snippets

  • Calcutta HC rules that it is cruelty if a wife stops her husband from caring for his ailing mother
  • Karnataka SIR: Nearly 20% voters left out in draft rolls under ASDDO (absent, shifted, dead, duplicate and others) and the percentage is as high as 45 in Bengaluru
  • A Class 1 boy was bitten by a venomous snake in Mitra Institution, a prominent government school in Kolkata's Bhawanipore. Later, it was found that upkeep grants had not been disbursed to government schools in the state for the last three years under TMC rule
  • Referring to a trial that went on for 44 years, the Supreme Court called it a 'failure of the judicial system'
  • The Supreme Court expressed concerns over private companies accessing EPFO and ITR data and said safeguards needed to be devised to stop this
  • Bengal chief minister Suvendu Adhikari stirs a controversy, calls Mamata Banerjee 'old', says will ensure she does not hit the streets and remains active only on Facebook, in a reference to her repeated Facebook live events of late
  • Cockroach Janta Party says government is dragging its feet on its demands and it will march from India Gate on September 5 to press for action
  • UPI has turned 10 and has changed the way India pays
  • Serum Institute to launch Japanese encephalitis vaccine in India with Meiji Seika Pharma of Japan
  • Government eyes to net Rs 3000cr by selling 6% of Hindustan Copper
  • TCS to acquire MHP Management, the tech and consultancy arm of Porsche at $373mn, to drive its AI-led transformation
  • World Cup Hockey: Argentina beat India 5-3 to dash their hopes of reaching the semifinals
  • India-Sri Lanka 2nd Test: Dhruv Jurel shines on day 2 with a century to propel India to 503 for 9 declared. Sri Lanka were 8 for 2 at stumps
  • Defence minister Rajnath Singh said that India has the capacity to become global hub for ship-building
  • Uttarakhand HC rules that gratuity cannot be cut after retirement over past pay error
Mumbai auto drivers go on strike against on-raod spoken Marathi test being conducted by the transport department
oppn parties
When the System Fails, the Cyber Fraud Victim Pays

By Sunil Garodia
First publised on 2026-08-20 10:34:51

About the Author

Sunil Garodia Editor-in-Chief of indiacommentary.com. Current Affairs analyst and political commentator. Author of Cyber Scams in India, Digital Arrest, The Money Trap and The Human Hack

Parliament has now said what cyber-fraud victims have known for years: India's response remains heavy on procedures and light on accountability

India likes to describe itself as a digital economy. UPI has transformed everyday payments, banking has moved onto smartphones, and millions now transact without touching cash. But when a citizen's money disappears from an account within minutes, the sophistication of that infrastructure seems to vanish with it. The victim is told to call 1930, file a complaint, approach the bank, and hope the money is frozen before it disperses through a maze of mule accounts. The criminals, it turns out, understand the system better than the system understands them.

A Parliamentary Standing Committee on Finance has now delivered an unusually blunt verdict on the government's handling of cyber-enabled financial fraud, rejecting the Department of Financial Services' reply as largely procedural and accusing it of ignoring critical operational gaps, particularly the use of mule accounts through which stolen money is rapidly siphoned away. That criticism deserves more attention than it has received, because behind every statistic is a citizen who has lost money, and increasingly that citizen is being asked to absorb the cost of weaknesses in a system the government, banks, regulators and police collectively control.

The scale is no longer deniable

Reported cybersecurity incidents rose from 10.29 lakh in 2022 to 22.68 lakh in 2024, and cyber frauds worth Rs 36.45 lakh crore had been reported on the National Cyber Crime Reporting Portal by February 28, 2025. In response, the government has built an alphabet soup of institutions: I4C, NCRP, CFCFRMS, the 1930 helpline, CERT-In, RBI's MuleHunter, NPCI's fraud-monitoring systems. None of this is in short supply. What is in short supply is accountability when these mechanisms fail. The CFCFRMS has helped save over Rs 5,489 crore across 17.82 lakh complaints, a real achievement, but one that raises an obvious question: if the system saves that much when it works, how much more could it save if it worked quickly and consistently?

The Golden Hour keeps slipping away

The committee identified time as the system's central weakness. In cyber fraud, the first three to four hours, the so-called "Golden Hour," often decide whether stolen funds can still be frozen. That window is routinely lost because victims report late and because district police frequently lack the technical capacity to coordinate with banks in real time. The real test isn't whether a sophisticated national architecture exists on paper, but whether, at 2 a.m., a bank can trace a transaction, freeze a receiving account, and act before the money moves again. If the answer is usually no, the architecture is mostly decorative.

Mule accounts and the moral hazard

The most troubling finding concerns mule accounts, the plumbing through which much of the fraud economy runs. The committee found the proposed compensation framework places 65 per cent of the burden on the RBI while beneficiary banks bear only 10 per cent, calling this a "severe moral hazard." If a bank's own KYC and monitoring systems fail to catch an account that behaves like a mule account, but the bank's liability is capped low regardless, there is little incentive to fix those systems. The committee's call for recalibrated liability and penalties for negligent branches goes to the heart of this.

Awareness cannot substitute for institutional protection

Citizens are routinely told not to click suspicious links or share OTPs, and that advice is necessary but not sufficient. A citizen can make one mistake; a bank has AI-driven monitoring, compliance teams and regulatory obligations, and the two cannot be treated as bearing equal responsibility. This is not the first warning either: a Standing Committee on Home Affairs said in August 2025 that cybercrime laws are fragmented and called for integrated legislation and stronger safeguards, meaning the Finance Committee's rebuke lands on a government that had already been told, and had already not fully responded.

Recovery, not reporting, is the real measure

India has gotten good at telling victims where to complain. It has not gotten good at answering the questions that actually matter: how much stolen money is recovered, how quickly mule accounts are frozen, how many negligent branches are penalised, how fast a police complaint translates into bank action. A portal that logs a complaint after the money is gone, or a helpline that records fraud after the Golden Hour has passed, is not a solution.

India cannot build a trillion-dollar digital economy on the assumption that citizens will simply get better at spotting criminals while the criminals keep adapting faster than the State does. Banks need real accountability for mule accounts, district police need the tools to act in minutes, and where institutional negligence contributes to a loss, the victim should not be left to absorb it alone. Until then, every successful cyber fraud remains not just a scammer's win, but a bill handed to an innocent citizen for the system's failures.