
₹55,659.81 CrTotal losses, 2020–2025
80%+Lost in just 2024–2025
28.15 Lakh Cases reported in 2025
76%Losses from investment fraud
The Numbers That Should Worry Every Indian
Government data tells a stark story: Indians lost a total of Rs 55,659.81 crore to cyber fraud between 2020 and 2025, with Rs 45,344.16 crore siphoned off during 2024 and 2025 alone — more than 80 percent of six years of losses compressed into just twenty-four months.
Break that down further and the picture gets sharper. Indians lost at least Rs 22,495 crore to cyber fraud in 2025, compared to Rs 22,845 crore in 2024, even as reported cases rose from 22.68 lakh to 28.15 lakh. Losses have plateaued at a punishingly high level while the sheer volume of victims keeps climbing — a sign that fraud has industrialized faster than either enforcement or public awareness.
The composition of these losses is also revealing. Of the total money lost in 2025, 76 percent was due to investment frauds — Ponzi schemes, fake stock trading platforms, and cryptocurrency scams. Digital arrest scams, where fraudsters impersonate CBI, ED, customs, or police officials to coerce transfers, accounted for roughly 9 percent of losses, while sextortion made up about 4 percent of losses but nearly a fifth of all cases.
This piece looks at what the law currently does — and doesn’t do — to address a crime wave of this scale.
The Existing Legal Architecture
The Information Technology Act, 2000
The IT Act remains India’s primary cyber law statute. Section 66C penalizes identity theft (fraudulent use of passwords, digital signatures, or unique identifiers), Section 66D specifically targets cheating by personation using computer resources, and Section 43 creates civil liability for unauthorised access resulting in loss. These provisions were largely drafted for an earlier generation of cybercrime — hacking, data theft, website defacement — and sit uneasily alongside today’s dominant fraud pattern: socially-engineered, voice-and-message-driven scams that exploit human trust rather than technical vulnerabilities.
Bharatiya Nyaya Sanhita, 2023
With the criminal law overhaul that replaced the IPC, cheating (Section 318 BNS), criminal breach of trust (Section 316), and forgery provisions now run parallel to IT Act offences. Most cyber fraud FIRs invoke both statutes together — a BNS cheating charge alongside an IT Act identity-theft or impersonation charge. This dual-track approach helps prosecutors but also creates definitional overlap and forum confusion, since cyber cells, economic offences wings, and local police stations can each claim jurisdiction over the same complaint.
RBI’s Customer Liability Framework
For fraud involving bank accounts, the RBI’s 2017 circular on customer liability in unauthorised electronic transactions is the operative legal standard. It creates three liability tiers:
- Zero liability where the fraud results from bank-side negligence or a third-party breach not attributable to the customer, provided the customer reports promptly.
- Limited liability capped at a fixed amount where the customer contributed to the fraud through delayed reporting, subject to time-bound slabs.
- Full liability where the loss results from customer negligence (sharing OTPs, PINs, or credentials) or if reporting happens beyond the specified window.
In practice, this framework is under strain. Banks routinely classify OTP or UPI-authenticated frauds as “customer negligence” even where victims were manipulated through sophisticated social engineering, pushing the burden of proof onto the defrauded party in ombudsman proceedings and consumer forums.
Where the Legal Framework Is Failing
1. Jurisdiction Is Fundamentally Broken
Cyber fraud is intrinsically cross-jurisdictional, but Indian criminal procedure still assumes territorial policing. A scam typically involves a caller in one state, mule bank accounts in a second, and SIM cards issued in a third — and Indian law requires an FIR to be registered where the offence (or a part of it) occurred, forcing victims into multi-state coordination that most police stations aren’t equipped to handle.
FIRs actually declined to 55,484 in 2025 from 66,370 the year before, despite cases rising from 22.68 lakh to 28.15 lakh — a widening gap between complaints and formal criminal proceedings.
2. The Complaint-to-FIR Gap Undermines Legal Recourse
A complaint filed on the National Cyber Crime Reporting Portal is not, by itself, an FIR. It does not automatically trigger a criminal investigation with attendant powers (arrest, seizure, Section 91 BNSS summons for evidence) unless converted. Banks intervening to freeze funds before formal FIR registration is presented as a success story — and it often is for immediate fund recovery — but it also means a large share of victims never enter the formal criminal justice pipeline, leaving them without documented legal remedy if recovery fails.
3. Intermediary Liability Remains Toothless in Practice
Under Section 79 of the IT Act, intermediaries (banks, telecom operators, payment apps, social media platforms) enjoy safe harbour from liability provided they exercise due diligence and act on takedown or blocking requests. But enforcement of “due diligence” obligations against telecom companies that issue mule SIMs, or payment platforms that onboard mule accounts, has been minimal. Regulatory data shows banks flagging over 18 lakh suspect identifiers and roughly 24–25 lakh mule accounts — yet relatively few cases have resulted in intermediaries themselves facing regulatory penalty, as opposed to individual mule-account holders facing prosecution.
4. No Standalone Statutory Compensation Right
Victims currently rely on a patchwork of remedies: RBI ombudsman complaints for banking negligence, consumer protection claims under the Consumer Protection Act, 2019, or civil suits for damages. There is no dedicated, time-bound statutory compensation mechanism specifically for cyber fraud victims, unlike some jurisdictions (the UK’s mandatory APP fraud reimbursement rules under the Payment Systems Regulator, for instance).
5. Cross-Border Enforcement Gaps
A significant share of cyber fraud operations — particularly “digital arrest” scams and investment fraud call centres — are believed to run from outside India’s territorial jurisdiction, including from Southeast Asian scam-compound networks. Mutual Legal Assistance Treaty (MLAT) requests are slow, and India’s ability to compel foreign platforms or payment intermediaries to cooperate remains limited absent bilateral enforcement arrangements.
Institutional Response: What’s Been Built
To be fair, the legal and institutional response hasn’t been static:
- The Indian Cyber Crime Coordination Centre now links states, banks, and financial institutions, with banks flagging 18.43 lakh suspect identifiers and 24.67 lakh mule accounts, helping block fraudulent transactions worth over Rs 8,031.56 crore.
- The Citizen Financial Cyber Fraud Reporting and Management System, launched in 2021, has saved over Rs 7,130 crore across roughly 23 lakh complaints through immediate reporting mechanisms.
- Dedicated cyber police stations have expanded to 459 nationally, up from 169 in 2020, with Uttar Pradesh leading in numbers.
These are meaningful operational gains — largely executive and administrative measures rather than new substantive legal rights for victims.
What Legal Reform Should Look Like
A dedicated Cyber Fraud Victim Compensation frameworkA time-bound, statutorily mandated reimbursement scheme — similar in spirit to the UK’s APP fraud rules — would shift some of the burden of proof from individual victims onto banks and payment intermediaries, particularly for social-engineering frauds that don’t involve clear customer negligence.
Unified jurisdiction for cyber offencesAmending the BNSS to allow FIR registration and investigation consolidation at a single nodal cyber cell, for offences involving inter-state mule accounts or telecom infrastructure, would reduce the jurisdictional churn that currently stalls investigations.
Stricter, audited KYC accountability for intermediariesMoving from complaint-driven mule-account detection to mandatory periodic audits, with statutory penalties for intermediaries whose onboarding failures are repeatedly used in fraud, would push responsibility further up the chain.
Faster MLAT and platform-cooperation mechanismsFor cross-border scam operations, potentially through updated bilateral treaties or working arrangements with countries hosting scam-compound networks.
Conclusion
The legal architecture around Indian cyber fraud is not absent — it is fragmented. The IT Act, BNS, RBI circulars, and consumer protection law each address a slice of the problem, but no single framework treats the modern, socially-engineered, cross-border, high-velocity fraud ecosystem as a coherent legal category with a coherent remedy. Until compensation, jurisdiction, and intermediary accountability are addressed as a single legislative package rather than through incremental circulars and portal upgrades, the gap between reported losses and actual legal recourse for victims is likely to persist — even as institutional fund-blocking mechanisms continue to show incremental gains.