
India is living through a cybercrime epidemic that has no parallel in the country’s history. In 2025 alone, over 28 lakh cybercrime complaints were filed across the country. Indians lost a staggering ₹22,495 crore to cyber fraud — and the recovery rate was just 6 paise per rupee stolen. That means for every ₹100 stolen, only ₹6 came back. The remaining ₹94 was gone forever.
The World Economic Forum’s Global Risk Report 2026 now ranks cybersecurity as India’s number one national risk — ahead of climate disasters, economic downturns, and armed conflict. Yet the awareness among ordinary citizens remains dangerously low. Most victims only learn how these scams work after they have already been defrauded.
This article covers five of the most significant and devastating cybercrime cases from 2025 and 2026 — real incidents, real victims, real money lost. Understanding these cases could be the difference between protecting your savings and losing them overnight.
The Scale of the Problem: Numbers You Need to See
Before diving into individual cases, it is important to understand the overall landscape of India’s cyber threat environment in 2025 and 2026:
- 28.15 lakh complaints were filed on the National Cybercrime Reporting Portal in 2025 — a 24% increase from 2024.
- Investment scams alone accounted for 75% of total financial losses, making them the single largest category of cybercrime in India.
- Over 30,000 digital arrest complaints were filed in 2025, with the Supreme Court estimating losses of over ₹3,000 crore from this scam alone.
- More than 50% of cyber fraud operations targeting Indians are run from fortified compounds in Cambodia, Myanmar, and Laos — beyond the immediate reach of Indian law enforcement.
- Only 55,484 FIRs were registered out of 28 lakh complaints — meaning for every FIR, over 50 victims walked away with no legal action taken.
- 1 in 5 UPI users has experienced a fraud attempt, and 51% of them never reported it to anyone.
These are not abstract statistics. Behind each number is a family that lost its savings, a senior citizen who could not pay for medical treatment, or a young professional whose career was derailed. The five cases below put a human face on these numbers.
Case 1: The WazirX Hack — How North Korea Stole ₹2,000 Crore from India’s Biggest Crypto Exchange
When: July 2024 – October 2025 | Where: Mumbai / Singapore | Amount Lost: ₹2,000 crore ($234.9 million)
On the morning of July 18, 2024, India woke up to news that would shake the country’s entire cryptocurrency ecosystem for the next 15 months. WazirX — India’s largest domestic crypto exchange, handling billions of rupees in daily transactions — had been completely drained overnight. The culprit was North Korea’s elite Lazarus Group, the same state-sponsored hacking organisation responsible for the Bangladesh Bank heist and dozens of other global financial cyberattacks.
What made this hack particularly alarming was its surgical precision. Lazarus did not simply brute-force their way in. Instead, they spent months studying WazirX’s internal systems after creating a legitimate-looking account and depositing tokens. Their target was WazirX’s multi-signature cold wallet — a system that required approval from five WazirX officials and one from their custodian, Liminal, before any transaction could be processed. In theory, this should have been nearly impossible to break.
But Lazarus found the gap. At the exact moment that WazirX signatories were logged into the system, the hackers modified the underlying smart contract controlling the wallet — effectively hijacking control without ever needing anyone’s private keys. Within minutes, ₹2,000 crore in digital assets had been transferred out of the exchange and into wallets controlled by North Korean operatives.
WazirX immediately suspended all trading and withdrawals. Hundreds of thousands of Indian users found themselves completely locked out of their funds — with no timeline, no legal recourse, and no regulator to appeal to. One individual, SK Masud Alam from West Bengal, was arrested for creating a mule account used in the attack, but the Lazarus Group operatives responsible for the actual hack remain in North Korea, beyond India’s jurisdiction.
The road to recovery was long and brutal. WazirX underwent insolvency proceedings in Singapore. India’s Supreme Court dismissed a victim petition, ruling that crypto regulation was a policy matter, not a judicial one. It was only in October 2025 — over a year after the hack — that 95.7% of creditors voted to approve a restructuring plan, with WazirX promising to restore 85% of funds over time. For the thousands of investors who had their life savings locked in the exchange, a year of uncertainty with no legal safety net was a nightmare they had not signed up for.
What this means for you: No cryptocurrency exchange — no matter how reputable or established — offers a legal guarantee on your funds. If an exchange is hacked, you are not protected the way a bank depositor would be under India’s deposit insurance. Never keep large amounts of cryptocurrency on any exchange. Use a personal hardware cold wallet for significant holdings. Crypto regulation in India cannot come soon enough, but until it does, the risk falls entirely on the individual investor.
Case 2: Digital Arrest — The Scam That Held Indians Under Fake Police Custody for Days
When: Throughout 2025 | Where: Pan-India | Estimated Losses: ₹3,000 crore+
Imagine receiving a video call from someone dressed in full police uniform, sitting in what appears to be an official government office. They show you a document — a First Information Report — and your name is on it. They tell you that your Aadhaar card has been linked to a money laundering operation, or that a suspicious package in your name has been intercepted at an airport containing drugs and fake passports. You are told that you are now under “digital arrest” — and that you must remain on this call at all times, must not contact your family, must not leave your house, and must transfer money immediately to “clear your name” and avoid physical arrest.
This is India’s most psychologically devastating fraud of 2025 — and it works because it is designed with terrifying attention to psychological detail. The scammers, operating from fortified compounds in Myanmar, Laos, and Cambodia, use fake government seals, official-looking office backdrops, and scripted dialogues to create an overwhelming sense of official authority. Victims — including educated, professionally successful individuals — have been kept on continuous video calls for two, three, sometimes even five days, while their bank accounts were systematically drained.
The tactics include complete social isolation. Victims are told that speaking to family members will result in their arrest too. They are told that only silence and immediate cooperation can save them. In this state of manufactured panic, people transfer lakhs of rupees without telling a single person in their life.
In March 2025, an elderly couple in Karnataka died by suicide after being defrauded of ₹50 lakh by a digital arrest gang. Mumbai cyber police dismantled a single digital arrest network that had laundered ₹58 crore across thousands of fake bank accounts. The Supreme Court of India took suo motu cognizance and directed a pan-India CBI investigation. Prime Minister Modi personally addressed the nation about digital arrest in his Mann Ki Baat broadcast. The government’s I4C division partnered with Microsoft to identify and block over 1,000 Skype IDs being used specifically for these scams.
Despite all of this, digital arrest fraud continued to rise throughout 2025, primarily because the operators are physically located outside India’s jurisdiction and because the psychological manipulation involved is extraordinarily effective even on highly educated victims.
What this means for you: No government agency — not the CBI, not the Enforcement Directorate, not the Income Tax department, not the police — will ever arrest you over a video call, demand money to “clear your name,” or instruct you to stay on a call and not speak to anyone. This is a professionally designed script. The moment someone on a call uses the phrase “digital arrest,” hang up immediately and dial 1930. Then call your family. There is no such thing as digital arrest under Indian law.
Case 3: The WhatsApp Investment Scam Empire — ₹7,000 Crore Lost to Fake Stock Experts
When: 2024–2025 | Where: Nationwide | Estimated Losses: ₹7,000+ crore
It begins innocuously enough — a Meta advertisement featuring what appears to be a credentialed financial expert promising consistent, high stock market returns. One click, and you are added to a WhatsApp group. The group has hundreds of members. Every morning, the group admin posts stock tips. Members respond with screenshots showing impressive profits. There is a sense of community, of shared success. The admin personally messages you, calls you by name, guides you through your first investment.
Every element of this experience is fabricated. The group members are either bots or paid actors hired specifically to create the illusion of a thriving investment community. The profit screenshots are Photoshopped. The “financial expert” is a scammer sitting in a call centre in Cambodia or Laos. The entire operation is a carefully choreographed performance designed to build trust before taking everything.
Once a victim is sufficiently convinced, they are directed to a polished, professional-looking trading app — custom-built by the scam organisation — where their “portfolio” shows consistent, impressive growth. When the victim eventually tries to withdraw money, there is always an obstacle: a tax payment required, a processing fee, a verification charge, a “regulatory hold.” The victim pays these charges, believing they are unlocking real profits. The money never comes.
India’s I4C estimates that investment scams of this type caused over ₹7,000 crore in financial losses in 2024, with figures climbing significantly in 2025. What makes this particularly troubling is the profile of the victims: these are not naive or financially illiterate individuals. Engineers, doctors, retired government officers, senior corporate professionals — people who consider themselves sophisticated — have been routinely defrauded by these schemes. The scams are designed by professionals who deeply understand human psychology and the desire for financial security.
In 2025, the CBI dismantled one such network that had defrauded over one lakh Indian victims. The operation was run entirely from Cambodia by Chinese nationals who used Indian mule bank accounts as financial pipelines to move money out of the country.
What this means for you: SEBI-registered investment advisors do not operate through WhatsApp or Telegram groups. Guaranteed stock market returns do not exist — not for anyone, not under any circumstances. Any platform that displays impressive profits on screen but refuses or delays actual withdrawals is running a scam. Before investing with any advisor or platform, verify their registration at sebi.gov.in. If they are not listed there, do not invest a single rupee.
Case 4: The BSE CEO Deepfake — When AI Put Fake Words in the Bombay Stock Exchange Chief’s Mouth
When: January–March 2026 | Where: Mumbai | Status: Ongoing — multiple victims reported
In January 2026, a video began spreading rapidly through WhatsApp forwards and Telegram channels. In the video, Sundararaman Ramamurthy — the MD and CEO of the Bombay Stock Exchange, Asia’s oldest and one of the world’s largest stock exchanges — appeared to be directly addressing viewers. He spoke about exclusive investment opportunities, promised “extraordinary profits,” and encouraged viewers to join a special investment group that could help them “accumulate ₹80 lakh by 2027” and “become multi-millionaires.”
The video was entirely fake. Every second of it had been generated using artificial intelligence deepfake technology. Ramamurthy said none of those things. The BSE issued an urgent public advisory on January 12, 2026, confirming that the video was “completely fabricated” and warning the public that no BSE official operates personal investment groups or gives stock recommendations through messaging platforms.
Despite removal efforts by BSE and platform moderators, the video resurfaced on Telegram and WhatsApp in March 2026, spreading to an entirely new audience of potential victims. The BSE was forced to issue a second public advisory on March 8, 2026, just eight weeks after the first one.
The economics of this attack illustrate just how serious the deepfake threat has become. A synthetic identity kit capable of producing a convincing executive deepfake was found being sold on dark web marketplaces for approximately $5 — less than the price of a cup of coffee at a city café. Artificial intelligence has made high-quality executive impersonation accessible to anyone with a basic internet connection and malicious intent.
According to a 2026 survey, 47% of Indian adults have either been victimised by or personally know a victim of an AI voice or deepfake scam. This figure is nearly double the global average, reflecting both India’s massive digital footprint and its relative vulnerability to this emerging form of fraud.
What this means for you: If any video circulates on WhatsApp or Telegram showing a senior official from SEBI, BSE, RBI, or any major financial institution offering stock tips, investment advice, or special opportunities — it is a deepfake. These officials never operate personal investment groups on messaging platforms. Before taking any action, verify through official institutional websites: bseindia.com, sebi.gov.in, rbi.org.in. Treat all unsolicited investment videos with absolute scepticism, regardless of how real they look.
Case 5: AI Voice Cloning — “Dad, I’m in Trouble” — When the Voice Was Not Your Child’s
When: 2025–2026 | Where: Haryana and pan-India | Reported Cases: 2,300+ in Q4 2025 alone
A father receives a phone call. The voice on the other end is unmistakably his son’s — the same accent, the same way of speaking, even the same verbal habits that only a parent would immediately recognise. The voice is distressed. It says there has been an accident. Money is needed urgently. Please do not call anyone else. Please do not ask questions.
The son is sitting safely at home, completely unaware. The voice was generated by an artificial intelligence system using just three to five seconds of audio — scraped from the son’s Instagram reels or YouTube videos that were publicly accessible to anyone on the internet.
This is AI voice cloning fraud, and it has crossed a threshold in 2025 that security experts had warned about for years. Modern voice synthesis technology can now produce an indistinguishable replica of any person’s voice from just a few seconds of audio. The result sounds completely natural — same pitch, same cadence, same emotional texture. Even parents, who have heard their children’s voices every day for decades, cannot reliably tell the difference in a high-stress moment.
Haryana Cyber Cell reported over 2,300 voice cloning fraud cases in the fourth quarter of 2025 alone — a 450% increase compared to the same period in the previous year. Scammers cross-reference social media profiles to identify family relationships, personal details, and context that makes their calls more convincing. They know the names of the victim’s children, where they study or work, and even recent events from their lives — all pulled from publicly accessible social media posts.
The same technology is being rapidly deployed in corporate India. In these cases, scammers clone the voices of company CEOs or CFOs and call finance department employees with urgent instructions to execute wire transfers to external accounts. According to the 2026 Thales Data Threat Report, 65% of Indian organisations have already experienced deepfake-driven cyberattacks — one of the highest rates in the Asia-Pacific region.
What this means for you: Establish a secret family verification code word today — something only your immediate family members know, that would never appear in any social media post or public context. Make it a firm rule: if anyone calls claiming to be a family member in distress, they must say the code word before you take any action or transfer any money. No AI system can guess a code word that exists only in your family’s private conversations. If the code word is not given, hang up and call the family member directly on their known, saved number.
Red Flags: Warning Signs Every Indian Must Recognise in 2026
Regardless of the specific type of scam, most cybercrime targeting Indians in 2025 and 2026 follows recognisable patterns. Learning to identify these warning signs immediately is the first and most important layer of defence:
- “Digital Arrest” calls: CBI, ED, Income Tax, and Police never arrest anyone over WhatsApp, Skype, or any video platform. Any call threatening arrest and demanding money is a scripted fraud. End it.
- WhatsApp “stock expert” groups: SEBI-registered advisors operate through regulated, licensed platforms — not WhatsApp groups promising guaranteed returns. Every such group is a fraud setup.
- Celebrity or executive investment videos on social media: Any video showing a BSE, SEBI, RBI, or corporate executive offering investment tips through messaging platforms is a deepfake. Verify only through official institutional channels.
- Distressed family member calls requesting urgent money: AI can replicate any voice from seconds of public audio. Always verify through a separate, independent call before taking any action.
- “You are receiving a payment” on UPI: Entering your UPI PIN does not receive money — it sends it. This is the most basic and most exploited misconception in India’s UPI fraud landscape.
- Part-time job offers requiring upfront investment: Legitimate employment never requires you to invest your own money first. Task-based schemes on Telegram that show “profits” you can never withdraw are always traps.
- Unexpected KYC update requests via SMS or call: Banks and telecom companies do not update KYC by calling you and asking for OTPs. Any such request is a phishing attempt.
- Too-good-to-be-true returns with urgency pressure: Urgency — “offer closes tonight,” “limited slots available,” “you must transfer right now” — is a manipulation tactic. Genuine investments allow time for due diligence.
8 Concrete Steps to Protect Yourself and Your Family Right Now
Awareness alone is not enough. These are specific, actionable steps that every Indian should take immediately — not someday, not after finishing this article, but today.
- Set a secret family verification code word today. Choose a random word that would never appear in any social media post or public conversation. Make every family member memorise it. Anyone calling in distress must say this word before you send a single rupee. This one step can protect your family against voice cloning scams entirely.
- Save 1930 in your phone contacts right now. India’s National Cybercrime Helpline operates 24 hours a day, seven days a week. If you are defrauded, calling 1930 immediately — within the first few minutes or hours — can trigger a freeze on the fraudulent transaction before the money is fully transferred out. Time is the critical variable in fraud recovery. Also file a complaint at cybercrime.gov.in.
- Teach every family member this one UPI fact: Your UPI PIN only sends money. It never receives. There is no transaction type in UPI where entering your PIN results in money being deposited into your account. Share this with your parents, grandparents, and anyone in Tier-2 or Tier-3 cities who uses UPI.
- Verify every investment advisor or platform on sebi.gov.in before investing anything. The SEBI website maintains a public register of all licensed investment advisors and registered entities. If a platform or individual is not listed there, do not invest. No exceptions, regardless of how professional they appear or how many people seem to be profiting.
- Do not keep significant cryptocurrency holdings on any exchange. The WazirX hack demonstrated that even India’s largest and most established exchange can be drained overnight, leaving users with no legal recourse and no timeline for recovery. Invest in a hardware cold wallet for any meaningful cryptocurrency holdings.
- Replace SMS-based two-factor authentication with an authenticator app. SIM swapping — where attackers duplicate your SIM card and intercept your OTPs — is rising rapidly in India. Use Google Authenticator, Microsoft Authenticator, or a similar app for 2FA wherever possible, especially for banking, email, and financial accounts.
- Check your Aadhaar usage history regularly. Visit uidai.gov.in to see every instance where your Aadhaar has been authenticated. Fraudsters who obtain your Aadhaar number use it to create fake digital identities and open mule bank accounts. Regular checks can alert you to unauthorised use before significant damage is done.
- Spend five minutes explaining these scams to your parents and grandparents. Over 50% of digital arrest victims and a large proportion of investment scam victims are senior citizens. These frauds are specifically designed to exploit people who are less familiar with how digital fraud operates. Five minutes of your time explaining the basics — no government arrests over video calls, no UPI PIN to receive money, no WhatsApp stock tips — could save their life savings.
The Bigger Picture: Why India’s Cybercrime Problem Is Structural
India’s cybercrime crisis is not simply a technology problem. It is the predictable outcome of several structural conditions converging simultaneously: the world’s largest UPI ecosystem, 535 million WhatsApp users, 900 million internet users, a massive population of first-generation digital users who received no formal digital literacy education, cryptocurrency markets operating largely outside regulatory oversight, and a generation of scam operators who have professionalised fraud into an industrial-scale enterprise run from territories beyond India’s legal reach.
The I4C has noted that while 28 lakh cases were reported in 2025, only 55,484 FIRs were filed. For every FIR registered, over 50 victims walked away with no legal action taken. India’s cybercrime enforcement machinery needs to grow as rapidly as the crime itself — and that process is underway, with significant investments in I4C, cyber policing, and international law enforcement cooperation. But the gap between the scale of the problem and the scale of the response remains enormous.
Until that gap is closed, the responsibility falls on individual citizens to protect themselves, their savings, and their families. The scams described in this article are not exotic edge cases — they are the most common and financially devastating forms of fraud operating in India today. Understanding them is the first and most important step toward not becoming their next victim.
If You Have Been Defrauded: What to Do Immediately
If you or someone you know has been a victim of cybercrime, act immediately:
- Call 1930 — National Cybercrime Helpline, available 24×7. Do this first, within minutes of realising the fraud.
- File a complaint online at cybercrime.gov.in — you can do this even if you have already called 1930.
- Contact your bank immediately to report the fraudulent transaction and request a freeze on your account if necessary.
- Do not feel ashamed. These are professional criminal organisations with sophisticated scripts and technology. They have defrauded engineers, doctors, lawyers, and senior government officials. Reporting quickly is the single most important factor in recovering your money.
Sources: Ministry of Home Affairs (MHA) Annual Cybercrime Report · I4C (Indian Cyber Crime Coordination Centre) · SEBI · Bombay Stock Exchange (BSE) Public Advisories · Haryana Cyber Cell · Thales Data Threat Report 2026 · World Economic Forum Global Risk Report 2026 · Supreme Court of India · Wikipedia (WazirX Hack)