How TCP/IP Became the Backbone of the Internet
Introduction
Have you ever wondered how the internet works? Yes, there are screens and wires, but what’s going on beneath the surface? Every time you open a website, send an email, chat on messaging apps, or stream movies, you’re relying on something you probably don’t think about: the TCP/IP protocol suite. Without it, the internet as we know it wouldn’t exist. Let’s take a look at why this unassuming set of rules allows us to connect to anyone anywhere in the world.
The Problem: Networks That Couldn't Talk to Each Other
The internet is widely called a network of networks. A network is a group of devices that are connected and can share data with each other.
Researchers and governments began building early computer networks in the 1960s and 70s. But as the Cold War intensified, the U.S. military felt the need to establish a robust data-sharing infrastructure through interconnected networks that could withstand attacks. At the time, each network had different standards and protocols, which meant getting networks to communicate wasn’t easy or efficient. One network would have to be subsumed into another. This would lead to major problems in the reliability of data relay, flexibility of including more nodes, scalability of the interconnected network, and innovation.
The Breakthrough: Open Architecture Networking
This changed in the 1970s, when Bob Kahn proposed the concept of open architecture networking. It was a simple but revolutionary idea. He envisioned a system where all networks could talk to each other as equals. In this conceptualisation, all networks, even though unique in design and interface, could connect as peers to facilitate end-to-end communication. End-to-end communication helps deliver data between the source and destination without relying on intermediate nodes to control or modify it. This helps to make data relay more reliable and less prone to errors.
Along with Vint Cerf, he developed a network protocol, the TCP/IP suite, that would go on to enable different networks across satellite, wired, and non-wired domains to communicate with one another.
What Is TCP/IP?
TCP/IP stands for Transmission Control Protocol / Internet Protocol. It’s a set of communication rules that allow computers and devices to exchange information across different networks.
It’s powerful because:
- Layered and open architecture: Each function (like data delivery or routing) is handled by a specific layer. This modular design makes it easy to build new technologies like the World Wide Web or streaming services on top of it.
- Decentralisation: There's no single point of control. Any device can connect to another across the internet, making it scalable and resilient.
- Standardisation: TCP/IP works across all kinds of hardware and operating systems, making it truly universal.
The Core Components
- TCP (Transmission Control Protocol): Ensures that data is delivered accurately and in order. If any piece is lost or duplicated, TCP handles it.
- IP (Internet Protocol): Handles addressing and routing. It decides where each packet of data should go and how it gets there.
- UDP (User Datagram Protocol): A lightweight version of TCP, used when speed is more important than accuracy, such as for video calls or online gaming.
Why It Matters
The TCP/IP protocol suite introduced a set of standardised guidelines that enable networks to communicate, thereby laying the foundation of the Internet. It has made the Internet global, open, reliable, interoperable, scalable, and resilient, — features because of which the Internet has come to become the backbone of modern communication systems. So the next time you open a browser or send a message, remember: it’s TCP/IP quietly making it all possible.
References
- https://www.techtarget.com/searchnetworking/definition/ARPANET
- https://www.internetsociety.org/internet/history-internet/brief-history-internet/
- https://www.geeksforgeeks.org/tcp-ip-model/
- https://www.oreilly.com/library/view/tcpip-network-administration/0596002971/ch01.html
Related Blogs

Australia is set to make its most significant reform to online safety laws since the Online Safety Act 2021. On 8 September 2026, the government published a draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026. This would shift the focus of the online safety regime from responding to harmful content to requiring platforms to take steps to prevent foreseeable harms. Consultation closed on 22 September 2026, and the government has signalled its intent to bring legislation to parliament this year. It should be noted that this is a draft document, and there may be changes before any law is made.
What the Bill Proposes
At its core is a single statutory duty: any person responsible for an online service must ensure, “so far as is reasonably practicable”, a safe online environment. The wording is borrowed from work health and safety law, a parallel the Rickard Review itself drew when recommending the duty. The bill would replace the Basic Online Safety Expectations and the industry codes and standards that currently govern harmful content, following a 12-month transition after Royal Assent.
Who Is Covered
The reach is deliberately wide. The duty applies to nine categories of “online service”: internet carriage services, social media, messaging services, designated internet services (websites and platforms), hosting services, search engines, app stores, equipment suppliers, and a new category for AI generation tools such as chatbots and image generators. It attaches both to the provider and to anyone in a position to exercise day-to-day control, so parent companies and subsidiaries could be caught. The minister may exempt low-risk services, and lawful private communications between consenting adults are excluded.
The “Reasonably Practicable” Test
Whether a provider has done enough is judged by weighing the likelihood and degree of harm, what the provider knows or ought reasonably to know, the availability and cost of safety measures, and the privacy impact of those measures. The privacy limb is notable: measures such as age assurance or AI moderation must not intrude on privacy in a way that is “grossly disproportionate” to the risk. Liability is systems-based, meaning a provider is judged on whether it maintains appropriate systems and processes, not on every individual piece of harmful content that slips through.
Three Tiers of Protection
The “safe online environment” is defined in three layers, each more demanding than the last:
- All people in Australia must be protected from seriously harmful material and conduct, including child sexual exploitation material, grooming, terrorism and violent extremism, and content promoting suicide or self-harm.
- Children under 18 must also be protected from material harmful to children, such as pornography, content promoting disordered eating, bullying, and content encouraging hostile attitudes towards women, as well as addictive design features.
- Children under 16 on social media must not be exposed to design features with negative behavioural impacts, regardless of whether they hold an account.
Design Features and “My Feed, My Way”
A distinctive element is the focus on how services are built. The Bill designates five categories of design feature as having negative behavioural impacts: recommender systems, endless feeds, feedback features such as likes and follower counts, time-limited content such as stories, and logged-in versions of these features. The minister could add more. Providers must manage these features appropriately, including by offering “user empowerment tools”. The flagship is “My Feed, My Way”, under which social media users could opt in to algorithmic recommendations or choose to see only content from accounts they follow, with the detail to be set by legislative instrument.
Compliance Obligations
Providers would need to complete a written risk assessment for each service at least annually and before making changes that could give rise to new risks. These assessments would need to be retained for six years and provided to the eSafety Commissioner within 30 days of a request. Additional requirements include transparency reporting, publication of safety information, accessible complaints processes, and, in some cases, an Australian point of contact.
The Bill also includes a number of other reforms, including take-down timeframes for removal notices reducing from 48 to 24 hours from the day after Royal Assent, the power for the Commissioner to direct the removal of 'nudify' apps, the ability to remove reposted material without a new complaint, and approved university researchers being given access to platform data.
Enforcement and Penalties
The Commissioner will have a range of tools available, including the power to issue formal warnings publicly, impose binding remedial directions, and obtain documents and sworn examinations. Civil pecuniary penalties up to 60,000 penalty units may be imposed for failure to comply with obligations, although for the largest platforms this represents a cap well below a hypothetical turnover-based calculation.
Implications
For businesses, the net is wider than just social media. So any website, app, messaging platform, hosting service or AI tool which is accessible in Australia may be subject to assessment. Risk assessments are effectively discoverable enforcement documents. As such they should be prepared with the same degree of rigour and regard for legal privilege as any document likely to come before a regulator. The reforms are also intersecting with the Privacy Act 'tranche two' draft, the Children's Online Privacy Code and the under-16 social media minimum age. So overlaps need to be mapped together. Uncertainty remains around whether compliance with existing codes would meet the new duty, and regulator guidance will be key.
For users, the likely benefits are greater control over algorithmic feeds, faster removal of harmful content and stronger protections for children. For regulators and policymakers, the bill represents a move from content-by-content moderation to regulation of the systems driving and amplifying harm.
Debate and Criticism
The proposal is contested. The Coalition has said it will oppose the Bill in its current form, citing risks to free speech and journalism. The US Government’s consultation submission warned that the Bill could encourage platforms to over-moderate and questioned how “foreseeable harm” would be defined. Academic commentary from Monash University observes that the Bill expressly protects privacy but not freedom of expression, while legal analysis points to broad delegated powers for the minister to expand the harms and services covered. The short consultation window of 18 days has also drawn comment.
Conclusion
The Digital Duty of Care Bill would change online safety in Australia from a complaints-and-takedown model to a proactive, design-focused duty with serious financial consequences. Because it is still an exposure draft, the sensible response is preparation rather than panic: work out whether your services are in scope, review existing safety and risk practices, map overlapping privacy and children’s obligations, and watch for the Bill’s introduction to Parliament.

Introduction
On June 11, 2026, the Ministry of Home Affairs (MHA) India released one of the most critical Indian government advisories concerning cybersecurity by the Indian Cyber Crime Coordination Centre (I4C) under the National Cybercrime Threat Analytics Unit (NCTAU) concerning the immediate and escalating threat posed by the weaponization of generative artificial intelligence to forge synthetic biometric identities capable of bypassing the existing facial verification mechanisms in India. This advisory is arguably one of the most explicit Indian government recognitions of the deep-seated threats associated with AI-generated deepfakes in the country’s digital financial infrastructure. As many Indian financial service providers embrace facial recognition and biometric verification systems for customer onboarding and authentications, the myth that biometric traits are in themselves secure is slowly unraveling.
The advisory states that cybercriminals are deploying sophisticated AI tools to forge such credible digital simulacrums that exhibit such a precise similarity of facial expressions, eye movements, eye blinks, head movements, and voice patterns that they are virtually indistinguishable from the originals for identity verification mechanisms. Such a confluence of easy AI technology, mass onboarding of digital identities, and underdeveloped infrastructure to detect these synthetics requires urgent regulatory, institutional, and technological intervention.
The I4C Advisory: Core Findings and Threat Architecture
In its advisory, NCTAU describes a complex, multi-step attack chain used by scammers to capture biometric information and perpetrate fraud using everyday social interactions. The attackers typically use social media accounts, chat messengers, online job applications, dating applications, or direct phone calls to reach their targets. These interactions are presented as innocuous, such as for video calls, job interviews, identity checks, or just normal conversation with the intention of recording facial and vocal data.
During these interactions, victims may be asked to perform gestures commonly seen in legitimate video calls, such as look directly at the camera, blink, turn their head, or say specific phrases. However, the perpetrators record this video feed without the victim's knowledge and then use deep learning generative AI technologies to process it. Through methods such as Generative Adversarial Networks (GANs) and diffusion models, the scammers create photorealistic synthetic duplicates of the target, capable of mirroring all physical and vocal attributes, such as facial expressions, blinking patterns, head movements, and even voice tones.
The advisory explicitly states that these synthetic identities can be used for a variety of fraudulent activities, such as spoofing face authentication systems, circumventing liveness detection checks, successfully completing video KYC, enabling fraudulent account recovery processes, and illegally accessing bank and financial services. NCTAU also cautions that these voice deepfakes may be paired with facial deepfakes in an attempt to undermine multi-modal authentication methods, and the occurrence of related SIM-swap attacks can eliminate the last layer of security in OTP verification and facilitate a complete account compromise.
The scale of India's Digital Financial Ecosystem
The scale of I4C's detected threat can be better understood by considering India's entire digital financial landscape. In 2025 India has witnessed over 228 billion UPI transactions, with 21.63 billion in December alone, an annual growth rate of 29% from 2024, and an active user base of over 500 million by the beginning of 2026. Furthermore, total e-KYC transactions by April 2025 have exceeded 2,393 crore, and thus, it can be seen the extent to which these aspects of finance (banking, insurance, and credit) are now conducted via remote digital verification. The transformation, although instrumental in increasing financial inclusion, has, according to some analysts, created an attack surface of historic scale. As hundreds of millions more become financially integrated via the very same channels that now form the country's infrastructure and systems of identity, the threat from identity-based fraud becomes astronomically large.
Indian government data further illustrates the extent to which such frauds are a growing concern. Cybercrime cases jumped 42% year-on-year to 2.27 million in 2024, resulting in losses amounting to nearly 228.45 billion. Within that, 1.34 million UPI cases, worth 1,087 crore, occurred in FY2024 alone, while cybercrimes in general soared from 260,000 cases in 2021 to nearly 2.8 million by 2025, totaling cybercrime losses of 22,931 crore.
How Do Deepfakes Defeat Biometric Systems?
Deepfake fraud, in particular, is extremely difficult to counteract due to the direct attack it poses on the assumptions underlying traditional verification systems. Passive techniques for verifying a live person from a static photo or video existed that primarily looked for similarities in textures, lighting, and geometrical properties or challenged subjects to perform an action in real-time. But the generation of real-time face swapping that contains blinks, head motion, and speaking can now be produced on even cheap machines. Cybercriminals can exploit these by using virtual camera drivers to "inject" the false image feed into the live verification session, nullifying any passive liveness checks. Data from the industry clearly shows the extent of this problem: iProov, a leading authenticator, documented a 7.8-fold rise in injection attacks in 2024; Jumio noted an 88% increase in deepfake-induced fraud in 2025; and voice-deepfake attacks on financial call centres saw a 6.8-fold increase in 2024.
Gartner had also predicted that 30% of organizations would have lost trust in facial verification alone by 2026, and work by Kubam (2024) confirmed a lack of multi-factor authentication such as cross-validation of biometric, document, and device integrity signals used within KYC platforms. Such fears have been corroborated by FATF's 2025 Horizon Scan, which classified deepfakes as an emerging threat to the AML/CDD framework and digital identity verification.
Recommendations by I4C
I4C's advisory goes beyond merely warning about threats and lists actionable recommendations to both institutions and citizens. Banks, NBFCs, fintech companies, and onboarding platforms have been advised to incorporate advanced deepfake and synthetic content detection techniques into their verification flows, given that first-generation liveness checks are not enough. They should employ a multi-modal strategy that considers face features along with the device, network signals, behavioral biometrics, and alignment of face and voice. They also have been advised to make a more robust upgrade of their onboarding and verification platforms, as much of the current remote verification architecture was built in a less sophisticated threat context. This aligns with the KYC Master Direction of the RBI that specifies end-to-end encryption, IP-based access controls, geotagging, and technology platforms and systems are to be upgraded frequently. Citizens are advised by I4C to keep their biometric information secure; be careful of unsolicited video calls and online interviews; keep an eye on transaction-related SMS and emails; and report suspicious instances through the National Cybercrime Reporting Portal and through the telephone number 1930. It is clarified that this advisory aims to create awareness of developing AI-based identity fraud schemes, and it is not a declaration that any specific organization, platform, or service is vulnerable.
The Legislative Dimension: India's Evolving Response to Synthetic Media
The problem highlighted by I4C is evolving in a heavily legislated environment, not a legal void. The first-ever legal definition of "synthetic media" in India came into force in the Information Technology Amendment Rules 2026 on February 20, 2026. These rules oblige significant platforms to remove deepfakes and non-consensual intimate media within three hours and two hours, respectively, or lose their safe harbor protection under Section 79 of the IT Act. While the provision focuses on harm stemming from content, this creates a new legal and normative precedent on dealing with AI-induced deception. However, financial frauds facilitated through deepfakes are not content but involve the use of remote identity verification and customer onboarding systems, which require specific technical standards. The overall policy environment when viewed in light of the FATF Horizon Scan, RBI KYC rules, and recent I4C advisory already offers significant scope to define and introduce mandatory deepfake detection and identity assurance standards even before these are explicitly legislated.
Institutional and Technical Recommendations
- For Financial Institutions and Fintech platforms: The existing verification systems (liveness detection) must be replaced with multi-layered deep-fake detection processes, including injection attack detection, behavioral biometrics, cross-modal facial and voice verification, device integrity check, and hardware attestation during onboarding itself.
- For Regulators: The RBI and Ministry of Home Affairs should work together to release technical standards that specify minimum deepfake-detection requirements for video-KYC and remote onboarding systems in line with FATF digital identity guidance and the upcoming EU AI Act.
- For researchers and academia: Dedicated studies on deepfake detection performance across varied demographic, linguistic, and regional populations of India should be prioritized. Current models are mostly trained on Western data.
- For citizens: Face recordings and other biometric information should be treated with the same caution as sensitive financial details. Be wary of unsolicited video calls, remote interviews, or verification requests from unknown people, and report suspicious activities on any account immediately via the National Cybercrime Helpline (1930) or cybercrime.gov.in.
Conclusion
The I4C advisory of June 2026 marks a critical recognition that advances in generative AI have fundamentally challenged the reliability of facial biometric authentication. For a country whose digital financial ecosystem relies heavily on remote identity verification, the implications are significant. The integrity of India's financial inclusion framework now depends on rapidly strengthening identity assurance mechanisms. Addressing this threat will require coordinated action by regulators, financial institutions, technology developers, researchers, and citizens to develop robust technical standards, enhance detection capabilities, and build public awareness at a pace matching the evolution of AI-enabled fraud.
References and Sources
- I4C / NCTAU Advisory, June 2026 — National Cybercrime Threat Analytics Unit, Indian Cyber Crime Coordination Centre, Ministry of Home Affairs, Government of India. Advisory on AI-Enabled Deepfake Identity Fraud. Issued 11 June 2026.
- shuftipro.com/blog/key-takeaways-from-fatf-horizon-scan-report-on-deepfakes
- https://timesofindia.indiatimes.com/india/fraudsters-creating-deepfakes-to-bypass-facial-authentication-i4c/articleshow/131668958.cms
- hyperverge.co/blog/what-is-a-deepfake
- iproov.com/reports/threat-intelligence-report-2026
- arxiv.org/pdf/2601.06241
.webp)
Introduction
If we look at the concept of scams, they have existed for as long as human societies have. A few decades ago, it was quite common to see scams being carried out in the form of fake landline calls, forged documents or persuasive salesmen. And ‘trust’, being the fundamental aspect of human interaction, has been at the forefront of such interactions. This ‘trust’ factor has been consistently exploited by nefarious individuals all over the world through various acts of deception and a plethora of fraudulent activities.
As the years have gone by, the very same scamming methods have simply shifted mediums. They have transitioned from the geographies of markets and doorsteps to the virtual world of smartphones and digital devices. The senior citizens of today are sitting at a juncture where they come equipped with the ‘habits’ and ‘understanding’ of the offline world. And this is why in today’s technologically driven and fast paced digital environment, they are being targeted via ‘unfamiliar’ digital mediums and tactics, making them highly susceptible to cyber frauds and online scams.
Back in the simpler days, it wasn’t too difficult to catch the whiff of a scammer. One could pick up on their practiced speech patterns, spot their overly polished and formal tone or their sheepish body language and even notice the minute inconsistencies in their statements. This back-and-forth communication would take place in real time, over phone calls and even face to face.
But the scenario today is worse. Since our reliance on digital devices has expanded at an unparalleled pace, it has become all the more difficult to distinguish between what’s fake and what’s genuine. All of a sudden, our entire essential daily activities have become encompassed in the realm of the digital world, ranging from banking, shopping, healthcare to everyday communication. And to further exacerbate the situation, today’s scammers have quietly adapted to this newfound circumstance, as they hide behind screens.
Fake messages or emails can be easily mistaken for being ‘real’ in the current modern digital age. Especially for senior citizens, this shift is presenting a serious challenge. They are being forced to evaluate authenticity and legitimacy through links, messages and apps that basically all look familiar. For example, the logo in an online correspondence might seem to be genuine or its language might look official and credible. At first glance, even the format or the layout of an email or a message may seem familiar enough to not raise any suspicion. This is the point where the danger lies. When there are no warning signs, no rude tones, no spelling errors and no weird behaviour. It becomes very difficult for people to tell what’s real and what’s a trap, especially for the seniors. And in that brief period of confusion, scammers manage to fool people into divulging personal information, clicking dangerous links or even parting with their hard-earned money.
What makes the senior population so vulnerable?
Trapped in the Convenience of Digital Dependence
As the senior population embraces the new and sophisticated digital tools of today, alongside they are also risking their exposure to the online world of cyber security risks and cyber criminals. New devices such as smartphones and tablets do offer unprecedented convenience but they also come with various underlying dangers. Modern technology has made everyday tasks quite easy. Smartphone based UPI applications, bank applications and even online healthcare platforms have simplified life not just for the elderly, but for everyone across society. But many senior citizens may not be as well versed with the usage of these technologies and the digital risks they carry. They may get influenced easily or they may not exercise the same level of caution as the younger generations (who have literally grown up being surrounded by the dynamics of technology). This ‘familiarity gap’ adds up to the vulnerability of seniors. Without any prior visible warning signs they can easily end up getting exposed to online scams, fraudulent transactions and data misuse.
Cybercriminals’ Goldmine: Cash-rich Seniors
Although a person’s vulnerability towards becoming a target or a victim of a cyber crime is mostly shaped by their circumstance and not by age alone. But still, from the point of view of a cyber criminal, senior citizens do seem to be the perfect victims. Most of them are retired and financially sound with lifetime savings, consistent pensions, accumulated assets and anticipated income streams. As they enjoy their solid financial footing, they may not keep a regular check on their online banking accounts and financial records. This ‘financial ease’ can inadvertently make them more prone to cyber crimes, especially when they are simultaneously getting increasingly dependent on digital tools. This lack of oversight may allow suspicious activities or fraudulent transactions to go unnoticed and sometimes even lead to huge losses of money. This is where digital literacy comes in. Keeping the seniors well informed on the safe usage of the internet can significantly lower their chance of getting intertwined in an online scam. It has therefore become crucial to promote and encourage regular account checks, setting up of alerts and foster awareness regarding common online threats that can help seniors safeguard their hard-earned resources.
India itself witnessed an increase of 86% from the years 2020 to 2022 in cyber crime cases related to senior citizens.
Targeting the Psychological Aspects: Panic, Overwhelm, Manipulation and Isolation
Senior citizens are often at an age and stage in life where their routines slow down and the general pace of life shifts towards a gentler rhythm. Thought processes may not be as swift as they used to be, some may even experience mild cognitive decline and many live alone or away from their children or immediate support systems. Research also shows that aging can lead to low memory function which in turn can increase an individual’s susceptibility to digital traps such as phishing emails and financial abuse. According to a comprehensive analysis of senior fraud victims, it has been noted that victimisation increases with advancing age. There are significant associations between fraud victimisation and human cognitive factors, such as: diminished executive functioning, reduced ability of the brain to process information and even impairments in comprehending complex everyday information.
Cybercriminals, who are aware of these soft spots, deliberately exploit the seniors’ psychological and mental space. They strategically deploy methods that create confusion and cognitive overload. They may create a fictitious scenario depicting some kind of ‘urgency’ and use the elderly’s ‘panic response’ to their advantage. They may create false warnings of a blocked bank account, a missed or delayed medical update or inform them of a sudden (but fake) legal issue. They aim at creating a situation of ‘overwhelm, anxiety and severe distress’. And it is common knowledge that when fear encapsulates an individual, the process of rational decision making deeply gets affected. In this scenario elderly victims often fall for the cyber criminals’ malicious antics and end up complying with them without actually verifying their intent and authenticity.
The senior population of the current times was raised in an era where they were rarely taught to question authoritative figures. This is where ‘manipulation’ steps in. The concept of manipulation thrives on the sense of ‘authority, power, position and trust’. Cyber fraudsters use this mechanism and convincingly impersonate government representatives, senior bank officials, healthcare providers, etc. They may project credibility and legitimacy by using authoritative sounding language, creating a sense of power over the victim and manipulating them.
Another important factor that scammers leverage to their advantage is ‘isolation’. A lot of seniors live alone or just with their spouse, with no immediate support systems nearby. They navigate and tread their daily routines on their own, trying hard to adapt to the dynamic digital world. This life of solitude or isolation leaves them in a vulnerable state. They may not even have someone to talk to, or get a second opinion, or even guidance regarding some suspicious online activity that they may be experiencing. This state of isolation combined with their limited digital competence creates the perfect stance for a cybercriminal to manipulate these individuals.
Understanding this psychological dimension has become critical to prevent cyber crimes amongst the elderly. Proper awareness campaigns, reassurance, encouragement of think-and-verify habits can reduce the occurrence of such scams and protect our senior citizens.
Clickbait Cures, Bogus Health Remedies and Expensive False Hopes
It is a known fact that for most senior citizens, their health ranks highest in the list of their priorities. They are always on the lookout for information regarding treatments, medications, dietary supplements and even wellness programs. In an effort to live a healthy and fuller life in this digital age, unknowingly, senior citizens can become easy targets for cybercriminals.
The internet is flooded with eye-catching headlines, ads and clickbaits that promise quick relief and miracle cures. Their wordings may appear like: ‘miracle joint and arthritis relief’, ‘reverse diabetes in seven days’, ‘secret anti-ageing formulas that doctors won’t divulge’, etc. These promises seem all flashy and shiny, but the reality is generally painful. Elderly people can easily get attracted to such ads. Scammers use reassuring language that instantly appeals to the seniors’ attention and their emotions. They create fake doctor profiles or publish fabricated patient reviews with overly dramatised testimonials and false research. In order to seem authentic, some scammers may even use the names and logos of respectable health institutions and organisations such as the ‘World Health Organisation’. They claim to sell products like miracle pills, teas, devices, virtual health services, etc., all at extremely high prices along with pressure inducing statements such as: ‘offer ends tonight’ or ‘only 20 spots left’.
When the elderly fall for this scam and end up paying the amount, either the promised product doesn’t turn up or it proves to be completely ineffective. In worst case scenarios, it may even harm the user’s health. These bogus health products are not regulated by any health association or authority. They may contain unsafe ingredients, incorrect dosages and other toxic substances that can severely impact the elderly’s health. An adverse reaction can take place or an existing medical condition may worsen. What begins as a hopeful step towards better health can eventually lead to loss of finances, physical harm and a deep sense of disappointment and hurt.
Sharing of card details, Adhaar numbers, insurance and medical reports on fake websites can further lead to identity theft and other dangerous cyber crimes.
Protection starts with simple habits. And here families have a big role to play. Making our senior citizens aware of this scenario is the first step. Education brings along ‘awareness’, and with awareness comes ‘caution and confidence’. Teaching the seniors to be wary of any warning signs, to not share any personal or financial details online and to make sure to consult a doctor first before starting any new treatments, are a few ways that can definitely help in reducing the risk of such scams.
Risky Digital Routines: Overexposure and Oversharing
The senior citizens of today are heavily invested in their daily digital routines. They stay virtually connected through various messaging apps (such as WhatsApp), they eagerly curate and maintain their digital identities on online platforms (such as Instagram and Facebook) and they regularly use emails to share messages, articles and forwards within their social circles. Many of us have seen it in our own family groups, that the seniors are the most enthusiastic lot. They are the first to send in their morning salutation messages, photos and other daily updates. This eagerness reflects both their genuine commitment towards staying in touch and also the pure joy that they derive from being active members of these online communities. It is important to understand that these platforms don’t just serve as mere communication tools for them. Beyond messaging and sharing of updates, these online spaces offer a sense of community, belongingness and self-expression to the elderly.
But these everyday digital routines can cause an overexposure to the virtual world which further creates opportunities for scammers. Clicking on unfamiliar links, downloading unknown softwares and giving quick responses to alerts and notifications (without first identifying the source), are a few examples of how seniors end up getting embroiled in risky situations. At the same time, online oversharing of personal details such as addresses, birthdays, travel plans, family updates, phone numbers, even investment plans, etc., can seem to be quite harmless on the face of it. But all of this information builds a goldmine for the scammers. They may be able to piece it together and use it to send highly convincing phishing emails, create fake online offers or even impersonate a loved one.
Senior citizens also tend to take online messages at face value. AI generated videos, images, false news, etc., are all generally shared under the garb of sensational claims or urgent warnings and are therefore easily assumed to be true, especially by the elderly. They may not even take a minute to factcheck the information and instead may forward it to ten other people in their circle.
The above risks can significantly be reduced by practicing safer digital habits. Seniors should be mindful in their digital usage. Pausing and thinking before clicking on a link, fact checking a piece of news, using strong privacy settings and trusted apps, etc., can help protect both their personal data as well as their digital wellbeing.
Silent Suffering: Shame, Underreporting and Systemic Gaps
Research suggests that senior citizens do not always report a cybercrime. This can be due to shame, self blame, ridicule, fear of being judged as incompetent and a general opinion that even if they report it, nothing will come out of it. They may feel embarrassed about getting deceived, believing that they should have known better. This may create an emotional burden which further amplifies underreporting. Informing their family members or just reaching out for some help can seem like a mammoth task for them.
Existing institutional gaps in our systems compounds this silent suffering. While there are law enforcement and consumer protection agencies in place, but the first step, which is the ‘reporting mechanism’, can seem to be inaccessible or too overbearing for the seniors. These systems may not have a very proactive outreach and can fail to tackle the distinct set of challenges faced by the seniors (such as clear guidance on scams or support for recovering lost funds).
This combination of ‘shame, underreporting and weak system support’ creates a dangerous cycle. Senior citizens are left as open prey, exploited and repeatedly targeted without sufficient help or any recognition for their plight.
The Way Forward
Society has to first acknowledge and identify the inimitable vulnerabilities of the seniors. This cycle can be broken by developing information drives that are specially tailored for the seniors. Moreover, along with family involvement, user friendly reporting channels and stronger protections from fraudulent online practices, seniors can see a ray of hope.
Targeted training programs, senior friendly cybersecurity workshops and courses can be a starting point. Teaching them about password creations, safe browsing tactics, phishing recognition and specific mentor-led sessions can empower them with the basic understanding of the online world.
Being able to navigate the digital world with adequate competence and confidence, and without the fear of exploitation, is ultimately what every senior citizen needs.
References
- https://www.staysafeonline.org/articles/why-do-scammers-target-older-adults
- https://pmc.ncbi.nlm.nih.gov/articles/PMC12074955/
- https://cybersecurityasia.net/rise-cyber-crime-targeting-older-adults/
- https://news.ufl.edu/2024/06/older-adults-vulnerable-to-scams/
- https://oklaw.org/resource/why-are-older-people-vulnerable-to-scams
- https://www.crimrxiv.com/pub/g7u4rb9v
- https://www.norc.org/research/library/majority-of-older-adults-experience-cyber-abuse-in-their-lifetim.html
- https://www.sbigeneral.in/blog/cyber-insurance/cyber-tips-and-tricks/how-senior-citizens-can-avoid-internet-scams