Mitigating the Threat of International Spoof Calls: Joint Efforts by the DoT and Telecom Service Providers
On 22nd October 2024, Jyotiraditya Scindia, Union Minister for Communications, launched the (DoT) Department of Telecoms’ International Incoming Spoofed Calls Prevention System. This was introduced in light of efforts toward preventing international fraudulent calls that enable cyber crimes. A recent report as per PIB claims for the system to have been effective and played a role in a 90% reduction in the number of spoofed international calls, its instances falling from 1.35 Crore to 6 Lakhs within two months of the launch of the system.
International spoof calls are calls that masquerade as numbers originating from within the country when displayed on the target's mobile screen. This is done by manipulating the calling line identity or the CLI, commonly known as the phone number. Previous cases reported mention that such spoof calls have been used for conducting financial scams, impersonating government officials to carry out digital arrests, and inducing panic. Instances of threats of disconnecting numbers by TRAI officials, and narcotics officials on finding drugs or even contraband through couriers are also rampant.
International Incoming Spoofed Calls Prevention System
As was addressed in the Budget in 2024, the system was previously called the Centralised International Out Roamer (CIOR), and the DoT was allocated Rs.38.76 crore for the same. The Digital Intelligence Unit (DIU) under the DoT is another project that aims to investigate and research fraudulent use of telecom resources, including messages, scams, and spam - the budget for which has been increased from 50 to 85 crores.
The International Incoming Spoofed Calls Prevention System was implemented in two phases, the first one was at the level of the telephone companies (telcos). Telcos can verify their subscribers and Indian SIMs based on the Indian Telecom Service Providers (TSPs) international long-distance (ILD) network. When a user with an Indian number travels abroad, the roaming feature gets activated, and all calls hit the ILD network of the TSP. This allows the TSP to verify whether the numbers starting with +91 are genuinely making calls from abroad or from India. However, a TSP can only verify numbers that are issued with their TSP ILD network and not those of other TSPs. This issue was addressed in the second phase, as the DIU of DoT and the TSPs built an integrated system so that a centralised database could be used to check for genuine subscribers.
CyberPeace Outlook
A press release on 23rd December 2024 encouraged the TSPs to label incoming International calls as International calls on the mobile screen of the receiver. Some of them have already started adding labels and are sending awareness messages informing their subscribers of tips on staying safe from scams. Apart from these, there are also applications available online that help in identifying callers and their location, however, these are at the behest of the users' efforts and have moderate trust value. At the level of the public, the practice of blocking unknown international numbers and not calling back, along with awareness regarding country codes is encouraged. Coordinated and updated efforts on the part of the Government and the TSPs are much appreciated in today's time as scammers continue to find new ways to commit cyber crimes using telecommunication resources.
References
- https://www.hindustantimes.com/india-news/jyotiraditya-scindia-launches-dot-system-to-block-spam-international-calls-101729615441509.html
- https://www.business-standard.com/india-news/centre-launches-system-to-block-international-spoofed-calls-curb-fraud-124102300449_1.html
- https://www.opindia.com/2024/12/number-of-spoofed-international-calls-used-in-cyber-crimes-goes-down-by-90-in-2-months/
- https://www.cnbctv18.com/technology/telecom/telecom-department-anti-spoofed-international-calls-19529459.htm
- https://pib.gov.in/PressReleaseIframePage.aspx?PRID=2067113
- https://pib.gov.in/PressReleasePage.aspx?PRID=2087644
- https://www.hindustantimes.com/india-news/display-international-call-for-calls-from-abroad-to-curb-scams-dot-to-telecos-101735050551449.html
Related Blogs

Introduction
When Tamil Nadu Police arrested a man from Vellore in May 2026 on suspicion of being the point person helping Indian youth to be smuggled into cyber scam compounds in Cambodia, the papers led with the accused. They shouldn't have led with the accused but with the system. The arrest, one in a long string of them in Tamil Nadu, Madurai, and other states, is not simply another one-off policing victory. Rather, the arrest gives us an insight into a larger, darker world: an international criminal organisation that has successfully combined human trafficking and cybercrime, a new trend in criminality that specialists are calling 'cyber slavery.'
What Is Cyber Slavery?
“Cyber slavery” involves trafficking persons under the pretence of employment, forcing them into committing online fraud to serve criminal enterprises. Victims are not merely victims of the work they are forced to do; they are often turned into culprits as they become complicit in victimising others. Trafficked victims are compelled to participate in frauds targeted at unsuspecting victims all around the globe. These activities, organised into robust criminal schemes, involve victims of sex or labour trafficking who are forced into operating romance scams or the so-called "pig butchering" scams that defraud people of their investment in cryptocurrency, all in heavily secured complexes guarded with threats of violence and torture. The extent of the problem is enormous, with the UN Office of the High Commissioner for Human Rights estimating in a 2023 report that there are over 100,000 victims of cyber scam compounds in Cambodia and another 120,000 in Myanmar. Schemes throughout Southeast Asia were projected to commit as much as $39.9 billion in fraudulent schemes a year.
Why Southeast Asia? The Geography of Organised Crime
In order to answer why Cambodia, Myanmar, Laos, and the surrounding regions have developed into the cyber slavery hub of the world, we can draw together an array of structural reasons:
- Casino clampdown and crime diversification: Cambodia's ban on online gambling in 2019 broke down established casino-related criminal networks. This saw old casinos and Special Economic Zones turn into cyber scam compound operations.
- Corruption and state complicity: A pre-existing environment of corruption and involvement of politically linked figures permitted scamming networks to flourish, and the armed groups in the border areas of Myanmar are reportedly complicit in these operations through supplying land and protection for the networks to operate in.
- Poor governance in the border areas: The lack of state control in the frontier areas of Myanmar provided the criminal networks with a secure sanctuary in which they could operate with impunity and cross borders to escape crackdowns and move their operations.
- Post-pandemic growth: The economic stress associated with the COVID-19 pandemic led to an increase in the supply of vulnerable individuals available to fill the scam networks, as well as unprecedented profit margins on scams.
The Recruitment Pipeline: How Are Indian Youth Trapped?
The typical journey from an Indian town or village to a locked compound in Southeast Asia follows the same narrative:
- The bait: On platforms like Facebook, WhatsApp, and Telegram, gangs lure with posts of lucrative overseas employment for IT work, customer service, data entry, and digital marketing with attractive, albeit feasible, pay packages (Rs. 80,000 to Rs. 1.5 lakh per month) and destinations such as Thailand and Singapore added for a veneer of genuineness.
- The recruiters: Local agents who gain trust, arrange visas and flight tickets, and collect the application fees are key intermediaries. Cases registered in Vellore and Madurai hint at recruitment agents receiving a commission for each person successfully smuggled into a trap, linked to larger travel and immigration networks.
- The lie: Victims are assured that they will be working legitimately in Thailand, but on reaching the border and crossing over, they find themselves pushed into scam compounds in neighbouring countries and have their passports, mobile phones and devices confiscated, thus rendering any escape attempt futile.
- The trap: In the interim, fake interviews, false job promises and convincing flight tickets serve to maintain the facade until the victims are forced to participate in cyber-fraud schemes.
The Architecture of Coercion: Life Inside the Scam Compounds
It is in these compounds that the fates of the victims become known. Survivor accounts, investigations and UN human rights reports provide evidence of these circumstances. These compounds are often surrounded by barbed wire fences, monitored with cameras and heavily guarded. Once a potential victim is captured, they are stripped of their passports and any other electronic devices, preventing them from being able to contact the outside world or to escape. Workers are allocated stringent targets, ranging from the number of potential victims they must solicit for scams and the amount of money they must acquire through such scams. Failure to do so, or perceived disobedience, may lead to beatings, electroshock treatment, starvation and long periods in confinement. These beatings are supplemented with psychological torture, with scammers assuring their victims that they owe money for their journey, stay and training. This method of debt bondage keeps people at the compound even when the opportunity for escape is presented to them. The victims are then forced to take part in more complex online scams, which involve romance scams, fake investment scams, and impersonation scams using scripts and with supervision. In some cases, families will be encouraged to pay for their captive relatives' release by ransom, whereas those who refuse to comply or meet performance requirements may be sold and transferred to another compound as a piece of property within a transnational criminal network.
Cybercrime Is No Longer Just About Hacking
This emergency challenges the existing notion of cybercrime. The scam compound of Southeast Asia is not about a lonely hacker or a standalone breach; it is a form of organised cyber slavery in which trafficked individuals are made to commit financial fraud on an industrial level.
The probe of India's NIA found that recruitment is done in the Indian states of Bihar and Uttar Pradesh. Transport agents in Chennai and Madurai provide logistics, and Dubai and Bangkok act as transit points on the way to Cambodia, Laos, and Vietnam. It makes use of cryptocurrency wallets, shadow banking, and shell companies for the movement of funds across international borders. Companies such as the Huione Group has been accused of facilitating billions of dollars in financial transactions for scam infrastructure before receiving sanctions from the U.S.
To illustrate the threat landscape, the U.S. Treasury imposed sanctions on 19 entities spread across Myanmar and Cambodia and said that cyber scam operations looted $10 billion worth last year. Also, cryptocurrency transactions related to trafficking crimes jumped by 85% last year, which speaks to the expanding nature of the global criminal infrastructure.
India's Exposure: A National Vulnerability
The scale of exposure for India is large and expanding. The most likely victims are educated, and aspirational young men and women from Tier 2 and Tier 3 cities, seeking work abroad, which perfectly aligns with the primary target of such human trafficking networks.
Repeated incidents of people from Tamil Nadu falling victim to these networks have come to light. As far back as 2022, the chief minister wrote to the prime minister that close to 300 Indians, roughly 50 Tamils included, were being held in Myanmar. The Madurai-Cambodia case that came to light in 2026 revealed an entire network spanning Cambodia, Laos, and Vietnam, with authorities believing that thousands of Indians might have been trafficked there over the past three years. Such cases from Kerala, Karnataka, Andhra Pradesh, and some northern Indian states have been reported. Last year, India had to charter Air Force flights to rescue over 549 Indians from cyber scam centres along the Myanmar-Thailand border.
The Indian embassy in Phnom Penh assisted the Indian nationals along with the CBI, MEA, and NIA in the rescue of 67 Indians in September 2024; however, these operations are largely reactive in the face of the vast and evolving transboundary crisis.
Prevention
The best solution is awareness. The following are tangible signs that a job offer might be a lead to trafficking:
Red Flags within the job offer:
- Receiving unsolicited recruitment messages on WhatsApp, Telegram or Instagram from unknown numbers/contacts.
- Offer of unbelievably high salaries in undefined roles like ‘data entry,’ ‘online marketing’ or ‘customer service’ outside India.
- Request for upfront money to cover costs of visas, travel, accommodation, and training.
- Job offers to places in Thailand or Singapore involving complex transit routes through other countries.
- An interview process entirely through messaging apps, where the company has no real office address or registration number.
- Urgency and/or confidentiality required.
Verification:
- Check if the recruiter is registered on MEA's e-Migrate portal-this is a portal where MEA lists authorised overseas recruiters.
- Verify the authenticity of the company through its business registration with official registries in the foreign country.
- Contact the Indian Embassy/Consulate in that foreign country if something doesn't add up about the offer.
- Do not hand over your passport to your employer on arrival; it is standard practice for recruiters working as traffickers to confiscate it.
What to do if trapped:
- Contact the closest Indian embassy or consulate immediately.
- Call the MEA overseas helpline: 1800-11-3090.
- Lodge a report on the National Cybercrime Reporting Portal (cybercrime.gov.in).
Policy Imperatives
On their own, individual consciousness cannot undo such a massive criminal infrastructure. India has to enforce the Emigration Act rigorously, implement mandatory licensing of recruitment agents and create a specialised task force consisting of NIA, CBI, MEA and the states’ cybercrime units. Pre-departure orientations should also become mandatory for migrant workers who go to Southeast Asia. Globally, India needs to work more closely with Cambodia, Myanmar, Thailand and Laos via intel sharing protocols, victim repatriations and action against scam compounds. Financial probes must be on par with enforcement investigations to catch up with the perpetrators’ network, the cryptocurrency and hawala channels that facilitate money laundering and finance trafficking operations, as that would severely hit these networks.
Conclusion
This arrest of the recruiter in Vellore is just a small piece of a larger network. What we see in these instances is the marriage of cybercrime, trafficking, and financial fraud into a larger transnational ecosystem that systematically preys on the economic vulnerability of individuals. These young Indians are not simply falling for scams; they are being systematically targeted, recruited, trafficked, and forced into these criminal operations by a networked structure. The scam compounds in Cambodia and along the border of Myanmar and Thailand are only the end of a process that very likely starts with a convincing job offer on social media. Fighting cyber slavery will not be as simple as more arrests; we need education and international efforts, as well as policy responses that match the scope and scale of the problem.
References
- https://the420.in/78415-2vellore-man-cambodia-cyber-slavery-trafficking-case/
- https://the420.in/madhan-vadivel-cambodia-cyber-slavery-trafficking-racket-investigation/
- https://www.newsonair.gov.in/tamil-nadu-police-arrest-key-recruiter-in-cambodia-cyber-slavery-racket/
- https://kashmirdotcom.in/2026/05/16/cambodia-linked-human-trafficking-cyber-slavery-racket-nia-chargesheets-five-including-absconding-kingpin/
- https://www.aljazeera.com/news/2025/7/16/more-than-1000-arrested-in-cambodian-cyber-scam-raids
- https://www.pbs.org/newshour/world/why-southeast-asias-online-scam-industry-is-so-hard-to-shut-down
- https://www.cfr.org/articles/how-myanmar-became-global-center-cyber-scams
- https://www.amlrightsource.com/resources/scam-states-the-cybercrime-corruption-complex-in-southeast-asia-and-the-collapse-of-anti-money-laundering-enforcement
- https://newlinesinstitute.org/global-security-mil-priorities/cybercrimes-human-trafficking-and-cryptocurrency-in-southeast-asias-special-economic-zones/
- https://www.theweek.in/news/india/2026/03/21/lured-by-jobs-sold-into-slavery-indias-crackdown-on-cyber-trafficking-continues.html
.webp)
Introduction
MSMEs, being the cornerstone of the Indian economy, are one of the most vulnerable targets in cyberspace and no enterprise is too small to be a target for malicious actors. MSMEs hardly ever perform a cyber-risk assessment, but when they do, they may run into a number of internal problems, such as cyberattacks brought on by inadequate networking security, online fraud, ransomware assaults, etc. Tackling cyber threats in MSMEs is critical mainly because of their high level of dependance on digital technologies and the growing sophistication of cyber attacks. Protecting them from cyber threats is essential, as a security breach can have devastating consequences, including financial loss, reputational damage, and operational disruptions.
Key Cyber Threats that MSMEs are facing
MSMEs are most vulnerable to are phishing attacks, ransomware, malware and viruses, insider threats, social engineering attacks, supply chain attacks, credential stuffing and brute force attacks and Distributed Denial of Service (DDoS) Attacks. Some of these attacks are described as under-
- Insider threats arise from employees or contractors who intentionally or unintentionally compromise security. It involves data theft, misuse of access privileges, or accidental data exposure.
- Social engineering attacks involve manipulating individuals into divulging confidential information or performing actions that compromise security by pretexting, baiting, and impersonation.
- Supply chain attacks exploit the trust in relationships between businesses and their suppliers and introduce malware, compromise data integrity, and disrupt operations.
- Credential stuffing and brute force attacks give unauthorized access to accounts and systems, leading to data breaches and financial losses.
Challenges Faced by MSMEs in Cybersecurity
The challenges faced by MSMEs in cyber security are mainly due to limited resources and budget constraints which leads to other issues such as a lack of specialized expertise as MSMEs often lack the IT support of cyber security experts. Awareness and training are needed to mitigate poor understanding of cyber threats and their complexity in nature. Vulnerabilities in the supply chain are present as they rely on third-party vendors and partners often, introducing potential supply chain vulnerabilities. Regulatory compliance is often complex and is taken seriously only when an issue crops up but it needs special attention especially with the DPDP Act coming in. The lack of an incident response plan leads to delayed and inadequate responses to cyber incidents, increasing the impact of breaches.
Best Practices for Tackling Cyber Threats for MSMEs
To effectively tackle cyber threats, MSMEs should adopt a comprehensive approach such as:
- Implementing and enforcing strong access controls by using MFA or 2FA and password policies. Limiting employee access as role based and updating the same as and when needed.
- Regularly apply security patches and use automated patch management solutions to prevent exploitation of known vulnerabilities.
- Conduct employee training and awareness programs and promote a security-first approach for the employees and assessing employee readiness to identify improvement areas.
- Implement network security measures by using firewalls and intrusion detection systems. Using secure Wi-Fi networks via strong encryptions and changing default credentials for the router are recommended, as is segmenting networks to limit lateral movement within the network in case of a breach.
- Regular data backup ensures that in case of an attack, data loss can be recovered and made available in secure offsite locations to protect it from unauthorized access.
- Developing an incident response plan that outlines the roles, responsibilities and procedure for responding to cyber incidents with regular drills to ensure readiness and clear communication protocols for incident reporting to regulators, stakeholders and customers.
- Implement endpoint security solutions using antivirus and anti-malware softwares. Devices should be against unauthorized access and implement mobile device management solutions enforcing security policies on employee-owned devices used for work purposes.
- Cyber insurance coverage will help in transferring financial risks in case of cyber incidents. It should have comprehensive coverage including business interruptions, data restoration, legal liabilities and incident response costs.
Recommended Cybersecurity Solutions Tailored for MSMEs
- A Managed Security Service Provider offers outsourced cybersecurity services, including threat monitoring, incident response, and vulnerability management that may be lacking in-house.
- Cloud-Based Security Solutions such as firewall as a service and Security Information and Event Management , provide scalable and cost-effective protection for MSMEs.
- Endpoint Detection and Response (EDR) Tools detect and respond to threats on endpoints, providing real-time visibility into potential threats and automating incident response actions.
- Security Awareness Training Platforms deliver interactive training sessions and simulations to educate employees about cybersecurity threats and best practices.
Conclusion
Addressing cyber threats in MSMEs requires a proactive and multi-layered approach that encompasses technical solutions, employee training, and strategic planning. By implementing best practices and leveraging cybersecurity solutions tailored to their specific needs, MSMEs can significantly enhance their resilience against cyber threats. As cyber threats continue to evolve, staying informed about the latest trends and adopting a culture of security awareness will be essential for MSMEs to protect their assets, reputation, and bottom line.
References:
- https://economictimes.indiatimes.com/small-biz/security-tech/security/cyber-security-pitfalls-and-how-negligence-can-be-expensive-for-msmes/articleshow/99508822.cms?from=mdr
- https://www.investopedia.com/financial-edge/0112/3-ways-cyber-crime-impacts-business.aspx
- https://www.financialexpress.com/business/sme-msme-tech-cisco-launches-new-tool-for-smbs-to-assess-their-cybersecurity-readiness-2538348/
- https://www.cloverinfotech.com/blog/small-businesses-big-problems-are-cyber-attacks-crushing-indias-msmes/

About Global Commission on Internet Governance
The Global Commission on Internet Governance was established in January 2014 with the goal of formulating and advancing a strategic vision for Internet governance going forward. Independent research on Internet-related issues of international public policy is carried out and supported over the two-year initiative. An official commission report with particular policy recommendations for the future of Internet governance will be made available as a result of this initiative.
There are two goals for the Global Commission on Internet Governance. First, it will encourage a broad and inclusive public discussion on how Internet governance will develop globally. Second, through its comprehensive policy-oriented report and the subsequent marketing of this final report, the Global Commission on Internet Governance will present its findings to key stakeholders at major Internet governance events.
The Internet: exploring the world wide web and the deep web
The Internet can be thought of as a vast networking infrastructure, or network of networks. By linking millions of computers worldwide, it creates a network that allows any two computers, provided they are both online, to speak with one another.
The Hypertext Transfer Protocol is the only language spoken over the Internet and is used by the Web to transfer data. Email, which depends on File Transfer Protocol, Usenet newsgroups, Simple Mail Transfer Protocol, and instant messaging, is also used on the Internet—not the Web. Thus, even though it's a sizable chunk, the Web is only a part of the Internet [1]. In summary, the deep Web is the portion of the Internet that is not visible to the naked eye. It is stuff from the World Wide Web that isn't available on the main Web. Standard search engines cannot reach it. More than 500 times larger than the visible Web is this enormous subset of the Internet [1-2].
The Global Commission on Internet Governance will concentrate on four principal themes:
• Improving the legitimacy of government, including standards and methods for regulation;
• Promoting economic innovation and expansion, including the development of infrastructure, competition laws, and vital Internet resources;
• Safeguarding online human rights, including establishing the idea of technological neutrality for rights to privacy, human rights, and freedom of expression;
• Preventing systemic risk includes setting standards for state behaviour, cooperating with law enforcement to combat cybercrime, preventing its spread, fostering confidence, and addressing disarmament-related issues.
Dark Web
The part of the deep Web that has been purposefully concealed and is unreachable using conventional Web browsers is known as the "dark Web." Dark Web sites are a platform for Internet users who value their anonymity since they shield users from prying eyes and typically utilize encryption to thwart monitoring. The Tor network is a well-known source for content that may be discovered on the dark web. Only a unique Web browser known as the Tor browser is required to access the anonymous Tor network (Tor 2014). It was a technique for anonymous online communication that the US Naval Research Laboratory first introduced as The Onion Routing (Tor) project in 2002. Many of the functionality offered by Tor are also available on I2P, another network. On the other hand, I2P was intended to function as a network inside the Internet, with traffic contained within its boundaries. Better anonymous access to the open Internet is offered by Tor, while a more dependable and stable "network within the network" is provided by I2P [3].
Cybersecurity in the dark web
Cyber crime is not any different than crime in the real world — it is just executed in a new medium: “Virtual criminality’ is basically the same as the terrestrial crime with which we are familiar. To be sure, some of the manifestations are new. But a great deal of crime committed with or against computers differs only in terms of the medium. While the technology of implementation, and particularly its efficiency, may be without precedent, the crime is fundamentally familiar. It is less a question of something completely different than a recognizable crime committed in a completely different way [4].”
Dark web monitoring
The dark Web, in general, and the Tor network, in particular, offer a secure platform for cybercriminals to support a vast amount of illegal activities — from anonymous marketplaces to secure means of communication, to an untraceable and difficult to shut down infrastructure for deploying malware and botnets.
As such, it has become increasingly important for security agencies to track and monitor the activities in the dark Web, focusing today on Tor networks, but possibly extending to other technologies in the near future. Due to its intricate webbing and design, monitoring the dark Web will continue to pose significant challenges. Efforts to address it should be focused on the areas discussed below [5].
Hidden service directory of dark web
A domain database used by both Tor and I2P is based on a distributed system called a "distributed hash table," or DHT. In order for a DHT to function, its nodes must cooperate to store and manage a portion of the database, which takes the shape of a key-value store. Owing to the distributed character of the domain resolution process for hidden services, nodes inside the DHT can be positioned to track requests originating from a certain domain [6].
Conclusion
The deep Web, and especially dark Web networks like Tor (2004), offer bad actors a practical means of transacting in products anonymously and lawfully.
The absence of discernible activity in non-traditional dark web networks is not evidence of their nonexistence. As per the guiding philosophy of the dark web, the actions are actually harder to identify and monitor. Critical mass is one of the market's driving forces. It seems unlikely that operators on the black Web will require a great degree of stealth until the repercussions are severe enough, should they be caught. It is possible that certain websites might go down, have a short trading window, and then reappear, which would make it harder to look into them.
References
- Ciancaglini, Vincenzo, Marco Balduzzi, Max Goncharov and Robert McArdle. 2013. “Deepweb and Cybercrime: It’s Not All About TOR.” Trend Micro Research Paper. October.
- Coughlin, Con. 2014. “How Social Media Is Helping Islamic State to Spread Its Poison.” The Telegraph, November 5.
- Dahl, Julia. 2014. “Identity Theft Ensnares Millions while the Law Plays Catch Up.” CBS News, July 14.
- Dean, Matt. 2014. “Digital Currencies Fueling Crime on the Dark Side of the Internet.” Fox Business, December 18.
- Falconer, Joel. 2012. “A Journey into the Dark Corners of the Deep Web.” The Next Web, October 8.
- Gehl, Robert W. 2014. “Power/Freedom on the Dark Web: A Digital Ethnography of the Dark Web Social Network.” New Media & Society, October 15. http://nms.sagepub.com/content/early/2014/ 10/16/1461444814554900.full#ref-38.