Navigating the Path to CyberPeace: Insights and Strategies
Featured Blogs

Introduction
For years, the story of terror recruitment in Jammu & Kashmir followed a familiar arc: physical infiltration across the Line of Control, local Over Ground Workers (OGWs) acting as couriers, and recruitment pitches on mainstream apps like WhatsApp and Facebook Messenger. Indian security agencies built entire surveillance architectures around that arc. Now, officials say, the architecture is being outflanked in a way few anticipated: through pornography and dating platforms.
The New Front: Chat Rooms Nobody Is Watching
According to officials cited in recent reporting, Pakistan-based terror handlers working in coordination with Pakistan's ISI have begun exploiting the real-time chat features built into pornography and dating websites to reach recruits in Jammu & Kashmir. These pornography platforms feature real-time chat tools that operate under the guise of helping users find dates nearby, and handlers are exploiting that feature to broadcast messages and coordinate activities. It's a strikingly mundane pivot for an organisation engaged in violent extremism, but that is precisely the point that nobody expects a counter-terror dragnet to be watching a dating chatbox.
Officials say the tactic is designed to evade the surveillance that has become standard on conventional social media platforms, allowing handlers to convey instructions to recruits while staying off the radar of established monitoring tools. WhatsApp, Signal and Facebook Messenger have all, in various ways, become known quantities to Indian intelligence subject to legal intercepts, metadata analysis and years of institutional familiarity. A chat window buried inside an adult content site is not.
Tor, Encrypted Nodes, and Apps Built to Disappear
Other than porn sites, investigators have also flagged a cluster of niche, privacy-first messaging apps that route traffic through Tor-based, encrypted nodes to mask user identity. Security agencies have placed a wide array of specialised digital tools under scrutiny, with terror handlers relying on Tor-based messaging applications like Coatex and Conion to route data through encrypted nodes and obscure user identities. Access to at least one of these apps' installation files is reportedly already restricted within India, though enforcement against sideloaded Android packages remains an uphill battle.
What makes these platforms attractive to handlers isn't unique code so much as the design philosophy behind privacy-first messaging generally. Some of these apps offer only basic encryption, while others go further with end-to-end encryption, self-destructing messages, and strong on-device encryption algorithms that keep data processing off any third-party server. Several reportedly allow account creation without a phone number or SIM verification, stripping away one of the most basic identity anchors that Indian telecom-linked surveillance depends on.
There's also an operational, almost logistical, reason for the shift: connectivity. Officials note that some of these applications provide end-to-end encryption, self-destructing messages and registration without a phone number or email, making it difficult for security agencies to trace users, even as terror networks also shift away from commonly used platforms. In the hilly, forested and often poorly connected terrain of Jammu's border districts, apps engineered to function on weak 2G or EDGE networks have an obvious tactical advantage over data-hungry mainstream platforms.
VPNs, Banned Apps, and a Cat-and-Mouse Game
Virtual Private Networks add another layer of obfuscation, letting operatives access apps banned in India and mask the geographic origin of their traffic. This isn't new tradecraft, but its pairing with adult-content chat infrastructure and Tor-routed messaging represents a genuinely novel combination in the Kashmir context, according to the officials describing the pattern to reporters.
The broader trend line, officials say, is a steady migration away from platforms Indian agencies have learned to monitor. Terror networks are increasingly moving away from mainstream, commonly used platforms in favour of more obscure alternatives, forcing intelligence agencies into a perpetual game of catch-up: each time a monitoring capability matures against one platform, handlers migrate to the next.
This is not the first time investigators have flagged this cat-and-mouse dynamic. Reporting on a recent case in Jammu's Bathindi area described a 19-year-old allegedly radicalised through the encrypted app. Session the same platform reportedly linked to suspects in a Delhi bomb plot investigation after months of contact with Pakistan-based handlers. Investigators in that case noted that terror organisations have increasingly turned to multi-layered encrypted messaging services specifically to evade monitoring by intelligence agencies.
The Virtual SIM Problem
Alongside app-layer evasion, foreign-issued virtual SIM cards remain a persistent headache for investigators. The most cited example remains the 2019 Pulwama attack investigation, in which agencies reportedly traced more than 40 virtual SIM cards to the Jaish-e-Mohammed suicide bomber and his network numbers that could be provisioned and abandoned without ever touching an Indian telecom's KYC system. That case became something of a template for how virtual and foreign-registered numbers can be used to build communication chains that are extremely difficult to map after the fact, since there is no physical SIM, no retail purchase record, and often no domestic carrier data trail at all.
More recent J&K cases echo the same pattern in a different form. Police investigating a cross-border radicalisation network noted that intelligence agencies now suspect unauthorised SIM card distribution is being used by terrorists to communicate with handlers across the border, part of a broader push to choke off the logistical and communication backbone that keeps sleeper modules alive even when direct physical contact with a local handler is minimal or non-existent.
How Agencies Are Responding
To their credit, security agencies aren't standing still. Officials say cyber-surveillance frameworks are actively being redesigned to map and intercept these "off-grid" communication channels, a phrase that itself signals how far outside traditional monitoring territory this recruitment method has moved. Agencies say they continue to adapt their cyber-surveillance frameworks specifically to map and intercept these off-grid communication channels. That has included moving to restrict access to specific APKs, tightening scrutiny of virtual number providers, and, as seen in recent CIK (Counter Intelligence Kashmir) operations, proactively disrupting online propaganda networks before recruitment pitches can mature into operational plots. One recent CIK operation, for instance, intercepted attempts to recruit two teenage boys who were allegedly being fed terror content in the direction of a Pakistan-based handler, underlining how young the target pool for these campaigns has become.
Conclusion
What this episode really illustrates isn't a single clever trick but a structural truth about counter-terror surveillance: it is inherently reactive. Every time agencies build competence around a platform, handlers find a low-attention, high-friction-to-monitor alternative: first fringe messaging apps, then Tor-routed clients, and now the sprawling, largely unregulated back-end of adult content platforms, which few people would ever think to associate with national security. It's a reminder that the fight against radicalisation online is no longer confined to obviously "extremist" corners of the internet; it can hide in plain sight, inside the most ordinary-looking corners of the web.
Sources
- New J-K terror tactic: Pornography apps, Tor network used for secret messaging — The Tribune
- New J&K terror tactic: Handlers turn to porn sites, encrypted apps to contact recruits — Deccan Herald
- Terrorists using porn website, encrypted apps for chats with recruits — Organiser
- New J&K Terror Tactic: Pornography Apps, Tor Network Used For Secret Messaging — Kashmir Dot Com
- From WhatsApp to Porn Sites: Terror Groups Adopt New Digital Tactic in J&K — Jammu Kashmir Now
- Jammu teenager's arrest exposes cross-border radicalisation network — The Tribune
- After OGW network, J&K cops target communication channel of terrorists — The Tribune
- CIK busts online radical network, foils recruitment of two minors — The Tribune

CyberPeace | Automotive Cybersecurity & Digital Forensics
Introduction
After a crash, the story usually comes from the driver, a witness or a police report. But a modern vehicle can leave another version behind - a digital one. An Event Data Recorder (EDR), commonly called a car's black box, can preserve selected information from the seconds around a crash. NHTSA describes EDRs as recording vehicle dynamics, driver inputs, crash characteristics, restraint status and some post-crash information.[1] The exact fields depend on the vehicle. A black box is not a magical device that records everything; it is one evidence source inside a much larger vehicle.
A modern vehicle can also contain safety controllers, diagnostic interfaces, ADAS, telematics and software-update systems. For an investigator, the question is what evidence can be linked to the EDR and what that combined record can actually support.
What Is Actually in the Black Box?

An EDR is best understood as a short event record, not a continuous driving diary. Depending on the vehicle and its configuration, forensic extraction may reveal items such as speed, acceleration, delta-V, engine RPM, throttle position, brake status, steering input, ABS or stability-control activity, seat-belt status and airbag or restraint events. NHTSA's published EDR material shows that data elements can include longitudinal and lateral acceleration, delta-V, vehicle speed, engine speed, throttle, service-brake status, roll/pitch/yaw information and steering input.[2] Do not overread the data: A field that exists in one model should not automatically be assumed to exist in another. A forensic report must identify exactly which module and fields were available and actually recovered.
What Can a Forensic Examination Recover?

A Brake Failure Example
Consider a driver who reports: “I pressed the brake, but nothing happened.” The statement should be preserved, but a forensic investigation should test it. Was brake status captured? What was the speed before the event? Did ABS activate? What were the acceleration and delta-V patterns? Were there relevant fault codes? Was the vehicle recently repaired or updated? Suppose the recovered records show a brake input, ABS activity and a change in vehicle speed before impact. That does not prove the brakes were mechanically perfect. It does, however, make the sentence “nothing happened” too simple. Conversely, a relevant fault appearing just before the event may give investigators a stronger lead. The important part is the comparison: human account, vehicle record, physical evidence and technical history should be examined together.
Smart Vehicles, Digital Evidence and Cybersecurity Investigation
A connected vehicle can communicate through cellular networks, Bluetooth, Wi-Fi, mobile applications, workshop tools and cloud services. If unusual activity appears around a safety-critical incident, investigators may need to look beyond the EDR. Useful questions include:
• Was there unusual diagnostic or service activity before the incident?
• Was a software update or configuration change recently applied?
• Do timestamps from different modules line up, or is there clock drift?
• Can the extracted record be tied back to the original vehicle and module?
• Is there a non-cyber explanation - such as a hardware fault or software defect - that fits the evidence better?
The mindset matters: A cyberattack should be a conclusion supported by evidence, not the default explanation for strange vehicle behaviour.
The Forensic View: From Data to Evidence

Automotive forensics is not simply plugging in a tool and exporting a report. The investigator should document the vehicle identity, module involved, extraction method, tool version, acquisition time and evidence-preservation steps. The goal is to make the work repeatable and defensible.
• Identify the relevant modules and evidence sources.
• Preserve the vehicle and extracted data against unnecessary alteration.
• Acquire data using a documented and appropriate method.
• Validate provenance, integrity, timestamps and completeness.
• Correlate EDR, diagnostics, software history, connected records and physical evidence.
• Report both findings and uncertainty.
A useful forensic rule: “Recorded” does not mean “proven.” Evidence becomes persuasive when its source, integrity and context are clear.
What the Law and Standards Are Changing
India is moving toward a more formal automotive cybersecurity lifecycle. IS-189 focuses on vehicle cybersecurity and the Cyber Security Management System (CSMS), while AIS-190 deals with software updates and the Software Update Management System (SUMS).[4][5] The wider statutory and type-approval framework is provided by the Motor Vehicles Act, 1988 and the Central Motor Vehicles Rules, 1989. For vehicle prototypes, Rule 126 provides for testing and approval by authorized testing agencies.[6][7]
In June 2026, the Ministry of Road Transport and Highways (MoRTH) came out with draft G.S.R. 503(E). The draft proposes new CMVR Rules 125-T and 125-U covering cybersecurity and software-update requirements. Since G.S.R. 503(E) is still a draft notification, its proposed requirements and the dates from which they may apply should be verified with the latest final notification before treating them as applicable law.[8]
At the international level, UN Regulation No. 155 addresses vehicle cybersecurity, while UN Regulation No. 156 covers software updates and their management.[9][10] This matters to forensics because lifecycle cybersecurity creates an expectation that manufacturers should be able to understand and manage security risks over time. In other words, logs, software-state information, vulnerability records and incident evidence can become part of the security story, not merely post-incident paperwork.
The Real Takeaway
The black box is valuable because it can reduce guesswork. It may tell us how fast the vehicle was moving, whether the driver applied the brake, how the vehicle responded, and what certain safety systems were doing around the event. But it rarely answers the whole case on its own. The strongest investigation is built by joining several pieces: EDR data, diagnostics, software context, connected-system evidence and what was found at the crash scene.
For cybersecurity professionals, the lesson is simple: a secure vehicle should not only resist attacks. It should also leave trustworthy evidence when something goes wrong. Good access controls, reliable timestamps and careful evidence handling help turn “something failed” into a defensible explanation.
Conclusion
The phrase “car black box” sounds simple, but the evidence behind it is not. An EDR can preserve a small but valuable window into a crash. During forensic examination, investigators may also be able to recover diagnostic, safety-system, software and connected-vehicle information, depending on the vehicle and what has been retained. The job is not to collect the largest possible amount of data. It is to collect the right data, preserve it properly and understand what each record can - and cannot - prove.
That is where automotive cybersecurity and digital forensics meet. As vehicles become more connected and software-driven, the ability to reconstruct an incident becomes part of security itself.
References
1. National Highway Traffic Safety Administration (NHTSA), Event Data Recorder (EDR) overview and research resources.
2. NHTSA, Use of Event Data Recorder (EDR) Technology for Highway Crash Data Analysis.
3. NHTSA, Light-Vehicle Event Data Recorder Technologies Update.
4. Automotive Research Association of India (ARAI), AIS-189, Approval of Vehicles with Regards to Cyber Security and Cyber Security Management System, April 2024.
5. Automotive Research Association of India (ARAI), AIS-190, Approval of Vehicles with Regards to Software Update and Software Update Management System, April 2024.
6. Government of India, Motor Vehicles Act, 1988.
7. Government of India, Central Motor Vehicles Rules, 1989, Rule 126.
8. Ministry of Road Transport and Highways, G.S.R. 503(E), 17 June 2026, draft Central Motor Vehicles (Amendment) Rules concerning cybersecurity and software updates.
9. UNECE, UN Regulation No. 155, Cyber Security and Cyber Security Management System.
10. UNECE, UN Regulation No. 156, Software Update and Software Update Management System.
11. NIST, SP 800-86, Guide to Integrating Forensic Techniques into Incident Response.

Introduction
In a significant step, the Indian Army beefed up its information warfare capacity on June 25, 2026, with the operationalisation of @MythbusterXX, its dedicated fact-checking handle designed to counter any form of misinformation, disinformation, malinformation, and deepfakes on the army swiftly. Adopting the motto 'Verify Before You Amplify,' the service seeks to pivot from reactive statements to active cognitive warfare. In a milieu where manipulated narratives can be as decisive in shaping public perception as kinetic force is on the battlefield, truth itself has transformed into a critical national security objective.
This is clear proof that protecting India’s digital battleground will from now on be defined not just by troop deployments but also by its institutional verification capacities, swift attribution mechanisms, and public awareness.
When the Battlefield Went Digital
Today warfare extends to timelines, group chats, and prime-time graphics packages. The distinction between misinformation , disinformation , and malinformation is crucial to operations. After all, they necessitate different types of counters. Generative AI just exponentially increased their velocity, cost, and the creepy believability of synthesized audio, video, and images. Operation Sindoor, India's May 2025 military response to a Pahalgam terror attack, provides a blueprint for just how large it can get.
According to the fact-checking site BOOM, 68% of fact checks in May related to Operation Sindoor, describing the campaign as a misinformation superspreader, and, more directly, India's Chief of Defence Staff General Anil Chauhan lamented at last year’s Shangri-La Dialogue that roughly 15% of his military’s operational time was spent on countering false news. New Delhi matched this response level; the Ministry of Information and Broadcasting had blocked over 1,400 URLs, many bearing false information or communally inciteful narratives from accounts in Pakistan. These challenges won't be vanishing any time soon. Microsoft's July 2025 Digital Defence Report lists India among the top countries targeted for AI-powered state-backed hacking, noting the automation of attacks and generation of fake content used to influence opinion.
CyberPeace's regulatory tracking also indicates steps toward building infrastructure to mitigate this, a Rule 7 complaint system for deepfakes, and efforts to foster local detection capabilities under the IndiaAI mission signal it's now an infrastructural threat.
Why the Army Chose to Speak First
On 1 June 2026, the Indian government’s official fact-checking unit debunked a deepfake of former Army Chief General Dhiraj Seth talking about India’s engagement with the Taliban that emanated from Pakistan-affiliated propaganda sources, appearing within days of a change of military command. Barely days after General Dhiraj Seth was elevated to Chief of Army Staff, the 31st person to hold the post, another fabricated deepfake used spliced authentic footage with AI-cloned audio to falsely allege he had blamed the past army leadership for hiding the bodies of soldiers to protect their image.
Such a dual targeting of India’s army chiefs with deepfakes in such close succession is a testament as to why an authoritative, constantly running fact-check machine isn’t an optional extra but a strategic must-have.
Architecture is as important as architecture itself. India tried a statutory fact-checking model with a government-owned Fact Check Unit under the Information Technology (IT) Rules of 2023 through the Press Information Bureau (PIB). It had to retreat from the edge of the constitutional cliff. In September 2024, when the Bombay High Court struck down key provisions of these rules. It ruled it unconstitutional to empower the state to declare digital content relating to the state itself as fake, false, or misleading. A similar reading of the analysis by CyberPeace found that digital speech should be given the same protections as offline speech, and this should be the benchmark for any counter-misinformation policy.
MythbusterXX carefully avoids the constitutional controversy by acting as an institutional avenue that produces verified information and rebuttals in response to disinformation. There is a profound distinction between answering falsehoods with factual, credible speech versus shutting them down with state power, the very proportionality that civil libertarians have said must govern a democracy's approach to online misinformation.
Platforms as Accelerants, Not Just Conduits
Part of the issue lies upstream, with the algorithms and broadcasters that favor speedy falsehood over careful confirmation. A month’s supply of “false and misleading stories,” the Reuters Institute for the Study of Journalism observed, streamed online within hours of Operation Sindoor's onset: one fact-checker identified approximately seventy false claims by the close of day one. Meanwhile, on the small screen, graphics depicting escalating conflicts were being televised, with broadcasters forced to scramble under 24/7 competition.
Amplified manipulation of the crisis narrative is also a factor; studies show that thousands of accounts have been reposting exactly the same party content for three years, making crisis-induced viral narratives predictable rather than organic phenomena. For the most part, the platforms that manage these narratives and the algorithms that direct content on both sides of the divide are not just innocent delivery systems.
Digital Literacy as the First Line of Defence
Institutional rebuttals only go so far if citizens lack the reflex to pause before sharing, which is where CyberPeace's own work becomes directly relevant. Through a multi-year, Google.org-backed initiative, CyberPeace Foundation aims to reach over 40 million Indian internet users, including 9 million underserved beneficiaries, through a multilingual resource centre offering 650 hours of content, state-level helplines, and quick-response teams staffed by digital forensics and fact-checking experts. Longer-running efforts such as the Digital Shakti campaign and the annual eRaksha competition, run with NCERT, have built a culture of responsible digital citizenship among young and first-time internet users since 2019, while CyberPeace Corps, the foundation's volunteer arm, carries the same message into classrooms and campuses through cyber-awareness sessions run with universities and school networks nationwide. Notably, CyberPeace's own research on children's online safety had already flagged manipulated Army-related videos as a category of digital manipulation designed to cast doubt on official military positions, well before @MythbusterXX existed. The Army's tagline and CyberPeace's mission converge on the same insight: verification is a civic skill, not merely an institutional service.
A Season of Deepfakes
The history book of compromised defence material in the past year alone would be edifying. The International Federation of Journalists recorded one such deepfake widely circulated that relied on AI voice cloning and lip-sync tools to present the Pakistani PM conceding defeat, though the video actually contained his praise for the Pakistani air force’s performance following Operation Sindoor.
Other similar videos featured the Indian Prime Minister, External Affairs Minister, and Home Minister allegedly apologising to Pakistan and a deepfake with a foreign head of state in voice-cloned style applauding India’s armed forces. None needed a state’s resources, but just a laptop, voice cloning available readily, and a citizenry ready to spread rather than confirm the authenticity of any such sensational information before spreading it on to the masses.
Building the Verification Reflex
A resilient information ecosystem needs different actors playing complementary roles:
- Citizens: Do not equate virality with credibility. Verify all national security-related information through official sources, such as @MythbusterXX, before reposting or forwarding it.
- Journalists: Apply rigorous verification standards to live broadcasts, war-room graphics, and breaking reports, just as you would to print journalism, and avoid speculation during fast-moving military operations.
- Researchers and fact-checkers: Use open-source forensic and AI-detection technologies to authenticate questionable material. BOOM researchers, for instance, used Deepfake-o-meter to scrutinize misleading videos of political leaders before fact-checking and publishing them.
- Policymakers: Favored constitutionally proportional and carefully tailored regulations over broad-based takedown mandates. While the 2026 IT Amendment Rules require platforms to shift their obligations from compliance with takedowns towards preventive diligence on synthetic media, implementation should continue to be informed by judicial protections afforded to freedom of speech and due process.
Cyber Resilience Is National Security Now
Legal scholars examining Operation Sindoor have drawn a useful distinction between coordinated information warfare, which is strategic and intentional, and the diffuse, uncoordinated mis/disinformation that dominated timelines during the conflict, cautioning that disproportionate state responses to the latter can compromise citizens' right to know just as much as the falsehoods themselves. Getting that balance right, between speed and due process, between institutional voice and censorship, is the real test facing India's information ecosystem, in defence and far beyond it. CyberPeace has made a related argument in its own work on AI-enabled espionage: institutions such as the National Critical Information Infrastructure Protection Centre and the Defence Cyber Agency are already folding AI-based monitoring into their processes, yet no amount of institutional surveillance substitutes for a citizenry trained to spot manipulation on sight.
@MythbusterXX will not end deepfakes, and no single handle can. But it signals something CyberPeace has argued for years: resilience against synthetic and manipulated media requires authoritative institutional voices, digitally literate citizens, forensically equipped researchers, and proportionate policy, all pulling in the same direction. "Verify before you amplify" is not just an Army campaign. It is the operating discipline a democracy needs to protect its own information age.
Conclusion
@MythbusterXX can't possibly kill deepfakes and disinformation, but this marks a milestone shift towards developing an institutional resilience for India's info battlefield. For, after all, national security in the age of info warfare depends less on tech and more on robust institutions, constitutional balance in policymaking, responsible social platforms, and a citizenry that clicks "forward" only after clicking "verify."
* * * * *
This piece is part of CyberPeace's ongoing work on misinformation, disinformation, and digital citizenship in India. For more on CyberPeace's initiatives in digital literacy and cyber resilience, visit cyberpeace.org.
Key Sources
- Dynamite News, "Indian Army launches fact-check push against deepfake videos and fake military claims" (June 2026)
- ADG PI – Indian Army, official announcement on X (@adgpi)
- Press Information Bureau, Government of India, press release on countering misinformation during Operation Sindoor
- Reuters Institute for the Study of Journalism, "Truth is the casualty: How Indian fact-checkers debunked false claims during the India-Pakistan crisis"
- International Federation of Journalists, "AI, Deepfakes, and the Fog of War" and "Operation Sindoor and the Two Wars" (June 2025)
- Republic World, "Operation Sindoor Haunts Pakistan: Islamabad's Latest AI Deepfake Bid Against Indian Army Chief General Dhiraj Seth Exposed" (July 2026)
- TechPolicy Press, "Sanity Prevails as Bombay High Court Strikes Down India Government's Fact Check Unit", and LiveLaw, coverage of the tie-breaker verdict, on the IT Amendment Rules, 2023 (Fact-Check Unit)
- Dark Reading, "Indian Army Propaganda Spread by 1.4K AI-Powered Social Media Accounts"
- Inforrm, "(Dis)information warfare and the right to know: lessons from Operation Sindoor"
- CyberPeace Foundation, initiatives page and The CyberPeace Initiative (Google.org-backed digital literacy programme)
- CyberPeace Foundation, "AI-Powered Espionage: How India's Cybersecurity Strategy Must Evolve"
- CyberPeace Foundation, "From Deepfakes to Due Diligence – Decoding India's IT Amendment Rules"
- Wikipedia, CyberPeace Foundation (background on Digital Shakti and eRaksha)

Introduction
Recently, the Delhi Police arrested a licensed telecom PoS agent, who identified himself as “Shivam Telecom," from a roadside kiosk adjacent to Hindu Rao Hospital. On the face of it, the headline may have simply read, “One man, one arrest." However, beneath that arrest is the unsettling story of a fully legitimate retail shop actively forging other people’s identification documents into weapons, one SIM card at a time, for as little as ₹500-600 each. This is not an account of an isolated offender; it is a peek into the vulnerability of SIM card security for typical end-users and the reasons why every mobile phone subscriber must pay attention to the unseen journey of his number.
Why SIM Security Matters Now
Erstwhile, a SIM card was only a simple device for sending text messages and making calls. Today, however, it’s also a direct link to most of our lives online, be it online banking to verify it through one-time passwords (OTP) or Unified Payments Interface (UPI); social media platforms; or email accounts to reset a forgotten password, two-factor authentications (2FA), or even numerous other online services. Therefore, losing a SIM card and getting it fraudulently issued under your name, or criminals accessing your identity to buy a SIM, can be a serious cause of concern, as they can then impersonate you, conduct various frauds, bypass checks, or commit acts that can lead to you being wrongly implicated.
According to the investigation, criminals were procuring SIM cards through the authorized outlets of telecom companies, not unlicensed dealers. This clearly proves a deficiency in the Know Your Customer (KYC) process for the SIM card activation. The situation, however, is worse and is also highlighted by the fact that more than 21 lakh mobile numbers from the more than 114 crore mobile numbers reviewed under the Sanchar Saathi initiative launched by the department of telecommunications (DoT) were associated with fake or invalid identity documents. A state police chief of Tamil Nadu claims that 90% of the cyber fraud cases involved SIM cards obtained through misused identity documents.
How Illegally Activated SIMs Fuel Everyday Scams?
Once a SIM is activated using someone else's identity documents or biometric data, without their knowledge, it becomes a disposable, hard-to-trace tool for criminals. Here's how that plays out in practice:
- Phishing and impersonation calls: Using an honest person’s details for a SIM registration allows the scammer to have a “clean” number that won’t tip off victims about a potential scam immediately when carrying out a fake bank call, fake delivery scam, or fake impersonation of an officer.
- OTP and account-takeover fraud: Since the SIM card is used as the anchor to OTP verification, an unauthorized SIM can be used to capture one-time passwords to activate new digital payments, create a new digital payments account, or use other personal information linked to your phone number to reset your service passwords.
- Financial fraud and money mule networks: According to the investigators, such SIMs were extensively being used to open digital payment accounts as well as to flow money across a number of fraud chains, thus enabling the fraudsters to build a layer of financial infrastructure that is not linked with their actual identities.
- Identity theft with real-world consequences: The identity of the Aadhaar holder (whose document was used to activate the SIM card) might be unaware that a SIM exists under his name until the fraud is uncovered during a loan default or a criminal investigation where he is forced to justify a crime committed using “his” number that he is oblivious to.
That is the anonymity that SIM-card fraud has: the fact that the SIM on the face of it seems genuine, but the one operating it and the registered owner have absolutely no relationship whatsoever.
Red Flags Every Mobile User Should Watch For
Most people won't know their identity has been misused until something goes visibly wrong. A few warning signs are worth taking seriously:
- Your SIM suddenly loses network connectivity or displays "No Service" for an extended period without any known outage, SIM replacement request, or billing issue.
- You stop receiving OTPs or verification messages for banking, UPI, or other online services, particularly if login attempts continue to occur on your accounts.
- You receive unexpected OTPs, verification codes, or account alerts for services you never signed up for, indicating that someone may be attempting to use your mobile number.
- You receive calls or messages intended for someone else or asking you to confirm activities you never performed, which may suggest your number has been misused or duplicated.
- Your bank or telecom provider notifies you of unusual account activity, failed identity verification, or changes that you did not authorize.
- You discover multiple mobile connections registered in your name that you never requested, a risk that often remains unnoticed unless you proactively check through the Department of Telecommunications' Sanchar Saathi portal.
None of these guarantee fraud, but any of them is a reason to check further rather than assume it's a glitch.
Practical Steps to Protect Yourself
The good news is that Indian users now have direct tools to check and control this exposure:
- Identify your SIMs: Via the Department of Telecom’s Sanchar Saathi website, you can access a list of all mobile numbers registered in your name. Report and get any SIMs you do not recognize deactivated promptly.
- Safeguard your identity documents and biometrics: Do not disclose your Aadhaar information, OTPs, or biometrics to unofficial persons or retail agents. Ensure your SIM is activated in your presence by an official dealer of the telecom company.
- Tighten the security of your accounts: Wherever possible, use the most secure multi-factor authentication methods; an authenticator app, rather than just SMS, would be ideal. Consider enabling account change or SIM swap notifications from your telecom provider.
- Stay vigilant about your bank accounts and financial activities. Watch for unusual OTP requests, password change requests, login notifications, and unrecognized devices being logged into your online accounts. Being observant early on helps minimize losses.
- Take swift action if a SIM stops working: Contact your telecom provider and report the misuse to the Sanchar Saathi website as well as your nearest cyber station, or file a complaint through the cybercrime helpline number.
A Shared Responsibility
Consumer vigilance is not enough to save the system. Telecom providers must verify customer authenticity and check their retail points sufficiently so that a roadside vendor of the likes of “Shivam Telecom” cannot have their retail outlet anywhere the retail outlets may not need to be established and can be run even from an abandoned car body on the street for weeks. Authorities are ensuring this by making all franchisees and PoS agents and distributors register, such that the individual activating each SIM is perfectly identifiable. Consumers should take precautions and report suspicious patterns and be vigilant for fraud detection and protect themselves by knowing the system, like the use of the Sanchar Saathi platform.
Conclusion
The Delhi fake SIM case proves that even sophisticated technologies are not enough to protect India’s telecom ecosystem. No amount of biometric validation, AI fraud prevention tools, or rigid KYC compliance can offset a single corrupt agent selling SIM cards over the counter. While law enforcement works to clamp down, the responsibility also falls upon consumers, who need to regularly monitor their SIM registrations, safeguard their identity, and report any suspicious transactions in time to minimize the threat of identity theft and SIM-based cybercrime.
Sources
- https://www.prokerala.com/news/articles/a1784141.html
- https://the420.in/dots-sanchar-saathi-initiative-exposes-21-lakh-sim-cards-activated-illegally
- https://www.sancharsaathi.gov.in/
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2113857
- https://www.business-standard.com/amp/industry/news/nearly-4-million-sims-deactivated-as-govt-cracks-down-on-digital-fraud-125080500300_1.html
- https://www.digit.in/news/telecom/here-are-5-new-sim-card-rules-implemented-by-dot-amid-rising-scams-and-frauds.html

Introduction
India is becoming more digital. People are using cards and phones to pay for things. This means there is a risk of people stealing card information and committing fraud. The Payment Card Industry Data Security Standard or PCI DSS is a set of rules that helps companies keep card information safe. It was created by the PCI Security Standards Council, which was started by Visa, Mastercard, American Express, Discover and JCB. The goal of PCI DSS is to reduce the risk of data breaches and card fraud by making sure companies have security controls in place. For India, where digital payments are becoming more popular, PCI DSS is becoming a thing to do.
Applicability in India
PCI DSS applies to all companies in India that store, process or transmit card information. This includes banks, payment companies like Razorpay, PayU and CCAvenue and online sellers. Even companies that use a hosted payment page are responsible for following the rules. Companies that have their payment forms and handle card information have to follow more rules.
Why PCI DSS Matters
Payment security is very important for customers to trust a company. If a company has a security breach it can expose a lot of card information. Damage the company's reputation. In India, where cybercrime's a big problem, PCI DSS helps companies keep card information safe. It has rules for firewalls, encryption, access controls and regular testing to prevent fraud.
Regulatory Landscape: The RBIs Role
PCI DSS is not a law in India. The Reserve Bank of India or RBI has made it a requirement. The RBI has rules that require companies to follow PCI DSS and have security audits. Non-bank companies have to get permission from the RBI and follow rules to store payment information in India. This makes PCI DSS a standard for keeping card information safe in India.
Key Requirements and the Compliance Process
The current version of PCI DSS has twelve requirements that companies have to follow. These requirements include building a network protecting card information and regular testing. Companies have to start by identifying what parts of their system handle card information. Then do a gap analysis to see what they need to do to comply. Smaller companies can usually do this in a week but bigger companies may take several months.
Common Challenges and Practical Solutions
Some problems companies face when trying to comply with PCI DSS include old computer systems that cannot handle modern encryption and unclear rules that make it hard to know what to do. Some solutions include separating the card information system from the rest of the network using tokens and encryption to keep card information safe and regularly checking for vulnerabilities.
Business and Regulatory Benefits
Following PCI DSS rules can help companies avoid penalties and have security breaches. It can also make it easier for companies to work with banks and card networks and build trust with customers. Regulators also look favorably on companies that follow the rules.
Recent Developments and Trends
The RBI has been making rules and requiring companies to follow PCI DSS more closely. As digital payments become more popular it is likely that the RBI will keep making rules to keep card information safe.
As India's digital economy grows, keeping payment information safe is becoming more important. PCI DSS is a set of rules that helps companies keep card information safe. The RBI has made it a requirement for companies to follow these rules. Companies that follow the rules can build trust with customers. Avoid security breaches.
Conclusion
As India's digital economy deepens, protecting payment data is no longer optional; it is the price of participating in the card ecosystem. PCI DSS gives banks, fintechs, gateways and merchants a common, internationally recognised language for security, while RBI's guidelines add local regulatory teeth. Organisations that treat compliance as a continuous discipline, rather than a once-a-year audit exercise, will find it easier to earn customer trust, avoid costly breaches, and scale with confidence. For every business touching cardholder data in India, the message is clear: PCI DSS compliance is now foundational to running a secure, trustworthy digital payments operation.
References
- https://www.pcisecuritystandards.org/document_library/
- https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx
- https://www.rbi.org.in/Scripts/NotificationUser.aspx
- https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11822
- https://www.incorpx.io/blog/pci-dss-compliance-ecommerce-fintech-india
- https://cyraacs.com/pci-dss-compliance-checklist
- https://www.skydo.com/blog/pci-dss-compliance-guide
- https://www.cybercrime.gov.in/

Governments in nations across the globe are consequently vying to draw in data centre investments as components of the wider AI sovereignty policies. However, recent events in Ireland make it clear that such an infrastructure is associated with significant environmental and social price tags. In geographically dense and resource-strained countries such as India, these trade-offs pose some pressing questions of whether today's AI ambitions are socially or environmentally sustainable. The data centre crisis in Ireland provides a handy reminder. It puts emphasis on the capacity of land use, water stress, energy demand, and disruption of communities to amplify quickly as digital infrastructure continues to increase at a faster rate than the regulatory and ecological capacity. These lessons should be paid close attention to as India continues to develop the IndiaAI Mission and establish itself as an AI hub in the future.
Why Data Centres Are Ecological Stress Multipliers
The data centres are sometimes referred to as clean digital infrastructure; however, in an actual sense, they are heavy industrial guardians of resources. Centres of large proportions demand an extensive amount of land, constant electricity, and a significant amount of water to cool down.
The most apparent effect is on energy consumption. Data centres are 24/7, round the clock, and need to be powered with a high-quality and stable electricity supply. By 2022, data centres had more than a quarter of the overall national electricity demand in Ireland, which created problems regarding grid stability and energy security (EirGrid, 2022). This compelled regulators to limit new connections in some of the areas. These trends also bring some similarities to certain regions of the United States, especially in Virginia, where particular data centres have led to peaks in the electricity demand in the region (U.S. Energy Information Administration, 2023).
Another primary source of pressure is the use of water. Heavy liquid coolers are very intensive systems in data centres, which tend to use the local freshwater sources. This may directly compete with residential and agricultural requirements in case of heatwaves or drought. In the western US, environmental advocates have issued notices that data centres contribute to a water deficit in other overextended basins (New York Times, 2023).
It also depends on local pollution and land use. Data centres are normally constructed on large plots close to urban or peri-urban centres, having good accessibility. This may push aside farmlands, increase property rates, and change local ecologies. The backup diesel generators, which are employed during power cuts, add to air and noise pollutants, and they thus impact the adjacent communities.
Ireland’s Experience and the Social Backlash
The low corporate taxes, cool climate, and PIC access to the EU market made Ireland a big data centre hub. The concentration of facilities around Dublin was, however, done unintentionally, leading to its rapid concentration. The population in their local communities also experienced mounting housing pressure, power competition, and underemployment because the number of long-term jobs created by a data centre is comparatively low.
The Irish government later realised that data centre expansion was causing strain on climate commitments and electricity infrastructure on a national level. The grid operators started denying new connections to data centres in sections of the country, which amounted to a kind of moratorium on further growth (TechPolicy.Press, 2024). What was initially a digital success story became a government issue, an ecology versus economic plan clash.
This experience particularly applies to smaller or densely populated countries. Countries such as Ireland and India have concentrated influences on fewer points, unlike the United States or China, which are able to spread data centres over wide areas.
India’s Emerging Data Centre Geography
India is advertising data centres as a way of advancing its digital and AI platforms. There are a number of states that have published data centre policies, such as Maharashtra, Tamil Nadu, Telangana, and Uttar Pradesh. The connectivity, financial infrastructure, and location to large user bases are making Mumbai, Chennai, Hyderabad, and Noida major hubs (MeitY, 2023).
Nevertheless, these areas are already stressed in terms of the environment. Mumbai also suffers from land shortage and flooding. There is a permanent water scarcity in Chennai. Hyderabad and Noida cannot cope with the intensity of population growth and energy demand in urban areas. Locating such large-scale data centres in these locations will pose a risk of augmenting the existing vulnerabilities instead of decentralising the benefits of development.
India, in contrast to the United States or China, does not have continental-scale low-density areas with spare water and power near demand centres. Each additional data centre in India is thus likely to have an impact on an increasing number of people per unit of infrastructure, by land acquisition, water diversion, grid pressure, or environmental externalities.
Community Impacts and Uneven Costs
The cost incurred by local communities to increase their data centre expansion is not proportionate to the benefits enjoyed. The after construction efforts to generate employment is minimal and the long term effects include strains on infrastructure. Tariffs can be increased with the growth of electric power demand. The extraction of water may have impacts on local supply. The prices of real estate may crowd out the lower-income population.
These impacts may be enhanced in India, where urban inequality is already high. The informal settlements along the industrial areas are such that they are vulnerable to pollution as well as diversion of resources. Data centres will otherwise be yet another project that creates unequal development without proper consultation with the community and other environmental protection measures.
What This Means for India’s AI Sovereignty Plans
The IndiaAI Mission of India focuses on developing local AI potential, data networks, and processing units to minimise the use of external systems ( IndiaAI Mission Document, 2024). This vision is based on data centres. Nevertheless, the concept of simple AI autonomy is made difficult by ecological limits.
An AI infrastructure that compromises water security, energy availability, or climate objectives could come under opposition and regulation backlash, as in the case of Ireland. This would delay deployment and add up to more expenses. Physical expansion is not sufficient to have true AI sovereignty. It should also take into consideration sustainability, decentralisation, and efficiency.
This brings about strategic concerns. India must invest more vigorously in energy-efficient computing, edge AI and model optimisation as opposed to scale. Is renewable energy integration viable to maintain the information centre demand? Is data centre siting to comply with long term water and land use planning, and not the short-term incentives of investment?
Towards a Sustainable Digital Infrastructure Strategy
India can still afford to learn not to repeat the errors experienced elsewhere. This will necessitate data centres being regarded as digital assets, not important infrastructures that have an environmental and social impact. Both more robust environmental impact assessments and public water and energy accounting and community involvement must become unavoidable.
From an AI policy perspective, sustainability should be seen as a pillar of sovereignty. An AI ecosystem that depends on fragile ecological foundations is not resilient. By learning from Ireland and adapting global lessons to local realities, India can pursue AI leadership without creating new environmental crises.
The future of AI will not be decided only by algorithms and talent. It will also be shaped by land, water, energy, and the communities that live alongside digital infrastructure. Ignoring those realities would make AI ambition fragile rather than sovereign.
References
- TechPolicy.Press. What Ireland’s Data Center Crisis Means for the EU’s AI Sovereignty Plans. 2024. https://techpolicy.press
- EirGrid. Electricity Demand Forecast Statement. 2022. https://www.eirgridgroup.com
- U.S. Energy Information Administration. Data Centers and Energy Demand. 2023. https://www.eia.gov
- New York Times. Data Centers Are Straining Water Supplies in the American West. 2023. https://www.nytimes.com
- Ministry of Electronics and Information Technology. India Data Centre Policy and Digital Infrastructure Initiatives. 2023. https://www.meity.gov.in
- IndiaAI Mission. Official Mission Document and Framework. 2024. https://indiaai.gov.in

Introduction
For more than 10 years, WhatsApp has been designed around one seemingly trivial but impactful idea: your phone number is your digital identity. This concept offered simplicity in terms of contact discovery and onboard- ing but inevitably exposed users to fraud, spam and the everyday necessity of sharing personal phone numbers with complete strangers in group chats and conversations. On June 29th Meta finally revealed a major move: you’ll now be able to choose and reservate a WhatsApp username and communicate without sharing your phone number.
This shift to a username based identity marks the company catching up to platforms like Telegram and Signal, which have utilized this functionality for years.
However, while presented as a push towards greater privacy for the millions using its platform, this new change has already created some alarm around impersonation, cybersquatting, and identity theft. The issues became amplified when, according to reports, the Indian Ministry of Electronics and Information Technology advised WhatsApp to halt the implementation of the new features while it clarifies details, shifting a mundane app update into a high-stakes discussion on digital privacy, platform responsibility, and government regulation.
How does the mechanism work?
“WhatsApp’s username is an added pseudonym layer on its current phone number architecture, not a replacement,” Meta said in a statement on Thursday, as reported by TechCrunch. A WhatsApp username is a three to 35-character name containing lower case letters, numbers, periods and underscores that must contain at least one letter and “should not look like a website address.” The feature will allow you to “reserve a unique identifier that you can share as an alternative to your phone number in WhatsApp Settings - Accounts - Username.”
It said the usernames will work in parallel with a username key which can serve as a passphrase to initiate conversation “with a recipient before sending a message for the first time.”
“The change - which will have some additional, protective measures like reserving usernames for people of public interest or those that would cause impersonation, and rate limits on claiming names - can help maintain phone number protection, while offering people more choices,” Meta said. WhatsApp said usernames will replace phone numbers as the primary way to initiate new chats, but will not be publicly searchable: “Anyone you message would need your exact username, and would still need you to respond.”
The Genuine Privacy Case
The upside is real. Phone numbers double as keys to two-factor authentication, banking apps and SIM-swap fraud, so handing one to a new acquaintance, a group chat of strangers or a customer-support bot has always carried quiet risk. Numbers harvested from public groups already fuel spam and scam campaigns, and a username-first model narrows that exposure considerably.
For journalists, small business owners and anyone who fields messages from people they've never met, decoupling identity from a number that also unlocks their bank account is a meaningful, overdue shift – and one that WhatsApp's closest competitors adopted years ago without major incident.
The Scammer's Paradise Scenario
The trouble lies in what a username removes. A phone number was never just an identifier; it was also a rough verification signal and, for law enforcement, a traceable data point. Security reporters testing the reservation system found that lookalike handles mimicking prominent Indian politicians, film stars and the Reserve Bank of India remained available to claim. Crypto executive Changpeng Zhao's own failed bid to capture his desired handle highlighted the first-come, first-served danger of the rollout and led researchers to advise people to manually activate the optional username key that Meta leaves disabled by default.
The Mozilla Foundation was unvarnished about the tradeoff, noting that impersonation from fake accounts and scams are an “inevitable consequence” of a design that abandons the “implicit signal of authenticity” that comes from owning a phone number.
Indian entrepreneur Ankur Warikoo called the rollout a potential “disaster” if robust enforcement against fraud isn’t immediately applied because scammers could register handles a few characters removed from a popular brand or public figure to launch investment and payment schemes, a concern mirrored by cyber security researchers who observed that many users neglect to check verification badges before trusting an account.
India's Regulatory Scrutiny of WhatsApp's Username Feature
So far the strongest reaction comes from New Delhi. The Ministry of Electronics and Information Technology (MeitY) issued an official notice to Meta's compliance office that it should “temporarily suspend the feature” in the country pending further consultations and “provided an explanation in three days”. The cited concerns involve “digital arrest” fraud, a rapid boom category that involves crooks impersonating investigators like those with India's CBI, judges or customs agents to extort victims, in addition to standard concerns around phishing and bank or government impersonation.
A subtler concern, for India’s government anyway, is “traceability.”
At present, say officials, an Indian mobile number is a launching pad to determine whether a given suspect is a domestic or international actor, while a username and foreign SIM would leave authorities nowhere to begin. The Department of Telecommunications independently voiced concerns over how the change intersects with its SIM-binding regulations and over WhatsApp's lag time for such requests. The MeitY notice, the legal basis for which, incidentally, is in contention with some digital rights groups, specifically invokes Section 79 of the IT Act and various IT Rules from 2021 and provisions on identity theft and impersonation that target individual criminals rather than the tech tools. Not everyone, however, shares MeitY’s reading of the legal ground: the Internet Freedom Foundation says that Section 79 “deal with liability of intermediary” and “does not confer on the government power to license the features of a product,” while arguing the relevant criminal statutes were designed to criminalize impersonators, not tech platforms whose services are misused, echoing concerns that killed a similar government advisement about AI models last spring.
In the meantime, Meta says usernames are unavailable in the country for now and the multilayered safeguards it designed were always intended for exactly this level of risk.
Conclusion
WhatsApp's username feature is neither a total privacy upgrade nor a major security problem; instead, it reallocates risk, reducing phone number exposure while adding a risk of identity spoofing and misuse. Whether it pays off will hinge on the strength of Meta's crackdown on fraudulent usernames, the uptake of extra security features like the username key and whether the company can adequately satisfy regulatory concerns about traceability and user safety. Until all those questions are fully settled, users may want to use the feature tentatively, secure a desired username, enable any other protections and be watchful about new contacts.
References
- https://blog.whatsapp.com/its-time-to-reserve-your-whatsapp-username
- https://www.businesstoday.in/technology/news/story/whatsapp-usernames-why-indias-top-creators-fear-scams-impersonation-and-identity-theft-540359-2026-07-02
- https://www.outlookindia.com/national/outlook-explains-why-is-the-indian-government-worried-about-whatsapp-usernames
- https://techcrunch.com/2026/06/29/whatsapp-now-lets-you-reserve-usernames/
- https://bestmediainfo.com/mediainfo/mediainfo-digital/whatsapp-says-username-feature-not-live-yet-after-meity-asks-meta-to-pause-rollout-12124813

Artificial Intelligence (AI) continues to grow in importance in today’s world not just as technological advancement but also becoming the backbone of economic growth, national security, scientific research, and digital governance. However, AI innovations of such a sophisticated kind require significant computing power that is currently only within the reach of a few countries. Against this backdrop, India and the United Arab Emirates (UAE) have taken a significant step by partnering to build one of India's most powerful AI supercomputing infrastructures. What began as a discussion about digital infrastructure under the ambit of the new found India-UAE tech relationship, has come to a stage that is likely to usher in new AI-centric developments in the country, while bolstering the partnership between India and UAE.
From Vision to Concrete Action
This collaboration stemmed from the strengthening relationship between India and the UAE. The goal is to focus more on digital cooperation after the 2023 G20 Summit held in India. During this period, Artificial Intelligence, digital public infrastructure, and strong digital ecosystems became key topics of discussion between the two countries. This partnership received formal recognition with the India-UAE Digital Infrastructure Memorandum of Understanding (MoU) signed in 2024. This agreement identified Artificial Intelligence, high-performance computing (HPC), cloud infrastructure, and digital innovation as priority areas for cooperation.
The initiative has now moved from policy talks to actual implementation. In February 2026, the UAE announced plans to deploy an 8-exaflop AI Super Computing Cluster in partnership between CDAC and in May 2026, when our Hon’ble Prime Minister visited UAE, both governments formalized the commercial framework for establishing the system, marking one of the largest AI infrastructure collaborations between the two countries. It was one the significant agendas discussed between the two countries among others.
What Does the Agreement Include?
The agreement between the countries is for the deployment of ‘Condor Galaxy India supercomputer’, which is an AI supercomputing cluster designed specifically for complex and advanced artificial intelligence workloads. Some of the major points of agreement include:
- Deployment of an 8 Exaflop Super Computing Cluster, meaning it can perform up to eight quintillion (8 × 10¹⁸) AI-related calculations per second. This would place it among the world's most powerful AI supercomputing systems.
- This project will be implemented by G42, which is an Abu Dhabi-based AI technology company, in partnership with India's Centre for Development of Advanced Computing (C-DAC).
- The computing infrastructure will utilise 64 Cerebras CS-3 AI systems, built using wafer-scale processor technology designed for large AI models.
- G42 and C-DAC will jointly oversee installation, deployment, operation, and maintenance of the infrastructure.
- The supercomputer will support India's IndiaAI Mission, strengthening domestic AI research and innovation. It is also a step in the direction of India’ AI mission through mindful collaboration.
- Notably, the system will be physically located within India and operate under Indian governance frameworks and laws ensuring that sensitive datasets remain under India’s jurisdiction.
While beyond the infrastructure, the partnership also aims for research efforts within fields like healthcare & genomics, climate change modeling & optimization of energy, geointelligence, research studies & government usages, as well as growing startups in AI. It is hoped that the computing infrastructure will be made accessible to researchers, academic bodies, government organizations & startups from both nations to foster collaborative research.
How Are India and the UAE Collaborating?
The partnership involves more than simply sharing the hardware, the two countries are entering into a multiyear technology partnership where each brings different but complementary expertise. On one hand India offers the knowledge and experience of C-DAC, a large number of AI engineers, startups, academics and researchers, and the IndiaAI Mission, a framework to enable access to the advanced computing infrastructure needed to use these researchers.
In return, the UAE offers investment in AI infrastructure and expertise in global AI cloud infrastructure, and sovereign AI platform development, from AI cloud infrastructure company G42, a company that has deployed large AI computing clusters as part of the Condor Galaxy network. Among the biggest names involved in the new initiative is also Cerebras Systems, the artificial intelligence (AI) computing company that will supply the AI chips for the supercomputer. The leading designer of AI compute technology, Cerebras develops the world's fastest AI hardware. In particular, the flagship Wafer Scale Engine (WSE-3), a revolutionary single chip that is the largest AI processor in the world, offers significant gains in speed and computational efficiency. This partnership will spur a joint R&D effort. That allows both India and the UAE to harness their respective knowledge and resources to accelerate better results for all stakeholders in various domains.
This collaboration will enable joint research and development (R&D), allowing both countries to combine their expertise and resources to produce more effective outcomes that are mutually beneficial across multiple sectors.
Cyber and Digital Security Benefits
From a cybersecurity perspective, this partnership is particularly significant.
- Moving towards AI Sovereignty
Possessing the infrastructure within India can ensure that sensitive government, healthcare, research, and enterprise data remains within Indian jurisdiction. This will reduce dependence on foreign cloud infrastructure while improving regulatory control over sensitive and critical datasets.
- Modernising Cyber Defence
Having a high-performance computing system will improve our cyber defence through AI-based threat detection, malware flagging, vulnerability assessment and cyber testing of safeguarding critical infrastructure. These are necessary in current times considering the growing capabilities and mode of cyber attacks.
- Secure AI Development
Countries worldwide are moving toward "Sovereign AI" which is a goal of developing AI systems within nationally governed infrastructure to protect sensitive information. The India-UAE partnership directly supports this objective by combining national governance and world-class computing capability development.
- Economic Benefits for India
The project offers several long-term economic advantages. First, easing the entry barrier for startups and researchers in India as they are often reliant on expensive overseas cloud computing services. Second, enabling availability of more computing power that can accelerate innovation across sectors such as healthcare, agriculture, manufacturing, fintech, education, and logistics. Third, stronger AI computing infrastructure could foster the inflow of global capital into India’s tech ecosystem by provisioning requisite resources to run frontier AI computations. Finally, the initiative supports India's ambition of becoming a global AI innovation hub under the IndiaAI Mission by enabling domestic development of advanced AI models rather than relying solely on imported technologies that will in long-term make India a sought out destination as an AI-hub.
Why the UAE Benefits?
In the case of the UAE, the partnership further helps Abu Dhabi's vision to become a global leader in artificial intelligence by extending the reach of G42's AI capabilities internationally, while strengthening ties with one of the world’s leading digital economies as a trusted strategic technology partner. In harnessing India's extensive talent base, research communities, and growing AI capabilities, the UAE unlocks opportunities for scale and innovation, while also cementing its status as a dependable technological enabler across emerging economies. The project is a part of the UAE’s long-standing agenda to move away from hydrocarbons and towards growth in areas such as AI, digital infrastructure, and technologies of the future.
Conclusion
The India-UAE supercomputer collaboration is a step in the direction of being self-dependent in terms of having a strong computing infrastructure base in India. This also changes the outlook of international technology partnerships from traditional trade relationships to collaborations focused on AI, digital infrastructure, research, and strategic innovation. AI is becoming a defining factor in economic competitiveness and national resilience on a global scale and the access to sovereign computing infrastructure will increasingly shape our influence in world markets. By uniting UAE’s investment capacity and AI infrastructure expertise and India’s advantages. If successfully implemented, the collaboration could serve as a model of what cooperation toward sovereign and trusted AI can entail.
REFERENCES
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2006207®=48&lang=2
- https://www.pib.gov.in/PressReleaseDetail.aspx?PRID=2261385®=48&lang=1
- https://www.pib.gov.in/PressReleaseDetail.aspx?PRID=2261393®=48&lang=1

Introduction
Imagine receiving a WhatsApp message from your CEO late on a Friday afternoon. The message is urgent: a confidential business deal requires an immediate wire transfer before markets close. The profile picture matches, the tone sounds familiar, and the account it came from has your CEO's name on it. Everything appears legitimate except it is not. This is the essence of the 'Boss Scam,' a sophisticated form of CEO impersonation fraud that has emerged as one of the most financially devastating cybercrime trends of 2025. India's Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, issued an urgent national advisory on this threat in June 2025, warning that organisations across the country are falling victim to an evolved and technically advanced version of executive impersonation fraud that bypasses many traditional cybersecurity safeguards.
Understanding the Boss Scam
What Is CEO Impersonation Fraud?
CEO fraud, also known as Business Email Compromise (BEC) or executive impersonation fraud, is a targeted cyberattack in which criminals assume the digital identity of a high-ranking executive most commonly the Chief Executive Officer to deceive subordinate employees into authorising fraudulent financial transactions or divulging sensitive information. Unlike generic phishing campaigns that cast a wide net, CEO fraud is a precision attack. Cybercriminals invest significant time and resources researching their targets, studying organisational hierarchies, communication styles, and internal financial workflows before executing the scam. The attack is devastatingly effective because it weaponises one of the most powerful forces in any workplace: authority. An instruction that appears to originate from the CEO carries an implicit demand for immediate compliance, often bypassing normal checks and verification procedures. The FBI's Internet Crime Complaint Center (IC3) has consistently identified BEC as one of the most financially destructive categories of cybercrime, with adjusted losses of approximately USD 2.77 billion reported in 2024 alone across the United States.
The New and Evolved Variant: India's I4C Advisory
The variant identified by India's I4C represents a dangerous evolution of traditional CEO fraud. The earlier versions of this scam relied on spoofed email addresses or fake WhatsApp profiles that merely mimicked an executive's account. Employees were trained to spot tell-tale warning signs suspicious domains, unusual sender addresses, or spelling errors in email IDs. The latest
Boss Scam variant eliminates many of these red flags entirely by hijacking the executive's actual and legitimate WhatsApp account. This sophisticated attack begins not with the employee, but with the CEO. Cybercriminals approach senior executives through email or WhatsApp while posing as regulatory authorities in India's context, this includes impersonating officials from the Reserve Bank of India (RBI) or other government bodies. These messages claim an urgent compliance violation or regulatory breach requiring immediate remedial action. The communication contains a compressed ZIP archive, which the executive is prompted to open. Inside the archive are malicious executable (.exe) and Dynamic Link Library (.dll) files that, when run on a Windows system, deploy a Trojan dropper a form of malware capable of establishing persistent access on the device and hijacking active WhatsApp Web session tokens.
Once the session token is compromised, the attacker gains complete control over the executive's WhatsApp account without needing the phone, password, or any two-factor authentication code. The legitimate account is now in criminal hands, and any message sent from it appears entirely authentic to recipients.
How the Boss Scam Operates: A Step-by-Step Breakdown
Stage 1: Targeting the Executive: The operation begins with careful reconnaissance. Attackers study the target organisation's leadership, identify the CEO or a senior executive, and gather publicly available information about their communication patterns, business relationships, and company operations through LinkedIn, corporate websites, and news sources. They then contact the executive under a false regulatory identity, engineering a sense of crisis and urgency.
Stage 2: Malware Deployment:The fraudulent regulatory communication contains a ZIP file disguised as a compliance document, a security patch, or a mandatory software update. Upon execution on a Windows machine, the embedded malware installs itself and begins hijacking the WhatsApp Web session. Critically, in many documented cases, the CEO innocently forwards this regulatory message and the malicious attachment to their own finance officer or IT team, inadvertently widening the attack surface.
Stage 3: Account Takeover and Impersonation:With the CEO's legitimate WhatsApp account now under their control, cybercriminals send highly convincing messages to subordinate staff, particularly those in finance, accounts payable, or treasury functions. These messages carry the full weight of genuine executive authority correct name, profile photo, and account history making them extraordinarily difficult to distinguish from authentic communications.
Stage 4: The Financial Strike:The fraudulent instruction typically requests an urgent, confidential wire transfer to an unfamiliar account, often accompanied by requests for complete secrecy. The employee, believing the instruction to be genuine and fearing the consequences of non-compliance with a directive from their CEO, processes the transaction. By the time the fraud is discovered, the funds have been routed through multiple mule accounts, making recovery extremely difficult.
The Broader Landscape: Scale and Impact
The Boss Scam is not an isolated Indian phenomenon it represents the cutting edge of a global epidemic of executive impersonation fraud. According to the FBI's data, BEC has been the costliest category of cybercrime for several years running, with cumulative global losses that officials have described as exceeding USD 50 billion over the past decade. A 2025 fraud survey found that 90 per cent of U.S. companies experienced attempted cyber-fraud in 2024, with business email compromise and impersonation scams surging by 103 per cent year-on-year. The technological sophistication of these attacks has grown in lockstep with the availability of AI tools. In early 2024, a finance worker at a multinational firm in Hong Kong was tricked into authorising a payment of USD 25 million after attending a video conference in which the CFO and other senior executives were entirely fabricated using deepfake technology. In March 2025, a similar attack unfolded in Singapore, where a finance director authorised nearly USD 499,000 after joining a Zoom call populated entirely by AI-generated deepfakes of company executives. Deepfake attacks against businesses reportedly surged by 3,000 per cent in 2023, and voice cloning fraud rose by 680 per cent the following year. In India, the Telangana Cyber Security Bureau reported over 300 complaints related to the Boss Scam variant alone within a twenty-day period in June 2025. In one prominent case, formerPrime Minister I.K. Gujral's son, Naresh Gujral, reportedly lost approximately Rs 7.8 crorethrough a messaging-app impersonation scheme targeting his company's Chief Financial Officer.
Warning Signs Every Employee Must Recognise
Identifying a Boss Scam attempt requires situational awareness and healthy scepticism. The following red flags should prompt immediate caution:
● Any request for urgent or secret financial transfers received via WhatsApp or email, without prior discussion or formal documentation.
● Instructions to bypass standard approval procedures or to maintain secrecy from colleagues or senior management.
● Compressed files (.zip, .rar) or executable attachments received from any source, including apparently known contacts, claiming to be compliance documents or regulatory updates.
● Messages from executives at unusual hours, particularly those emphasising that a transaction must be completed immediately.
● Claims that a request comes from a government regulator, such as the RBI, delivered through informal channels like WhatsApp.
● Any communication that creates extreme urgency, invokes authority, and simultaneously demands confidentiality the classic triangle of social engineering manipulation. Protective Measures: Defending Against the Boss Scam
For Employees and Finance Teams
The I4C advisory and global cybersecurity authorities recommend several concrete steps that employees can take. The most important is to independently verify any urgent financial instruction through a direct voice call or in-person confirmation before taking action, regardless of how convincing the digital message appears. No financial transaction of significance should be authorised on the basis of a WhatsApp message or email alone.
For Organisations and Leadership
Organisations must implement multi-layered verification protocols for all wire transfers above a defined threshold, making dual authorisation and out-of-band verification mandatory. IT teams should deploy updated malware detection tools, enforce software restriction policies that block unauthorised executable files, and regularly audit devices for signs of compromise. WhatsApp linked devices should be reviewed periodically. Leadership must also commit to regular, mandatory cybersecurity awareness training for all staff, with particular attention to social engineering tactics. The I4C has also emphasised that legitimate regulatory bodies including the RBI , do not distribute software, compliance tools, or security patches via WhatsApp or email attachments. Any such communication must be treated as a potential attack vector and reported immediately.
Conclusion
The Boss Scam exploits organisational trust and human psychology rather than technical vulnerabilities and with deepfake technology now capable of replicating familiar voices and faces, traditional verification instincts are no longer reliable. The strongest defence is a culture of verification without embarrassment, where questioning an unusual instruction is seen as diligence, not insubordination. Awareness, clear protocols, and scepticism towards urgency remain our most powerful tools. If you've encountered such a scam, contact India's National Cybercrime Helpline at 1930 or report at cybercrime.gov.in.
References
- https://www.cybercrime.gov.in
- https://www.business-standard.com/india-news/boss-scam-ceo-impersonation-fraudgovt- advisory-i4c-126062300353_1.html
- https://www.indiatvnews.com/news/india/boss-scam-all-about-the-new-cyber-fraudtargeting- corporates-and-precautions-listed-by-mha-2026-06-23-1045827
- https://www.freepressjournal.in/business/boss-scam-on-whatsapp-new-ceo-fraudbypasses- traditional-cybersecurity-checks
- https://hyderabadmail.com/tgcsb-warns-boss-scam-ceo-impersonation-fraud-malwarealert/
- https://www.newkerala.com/news/a/rising-boss-scam-threat-targets-senior-executiveswarns- 242.html
- https://www.ic3.gov
- https://www.mcafee.com/learn/is-that-really-your-boss/
- https://abnormal.ai/glossary/ceo-fraud
- https://www.brside.com/blog/deepfake-ceo-fraud-50m-voice-cloning-threat-cfos
- https://www.eftsure.com/blog/cyber-crime/these-7-deepfake-ceo-scams-prove-that-nobusiness- is-safe/
- https://www.knowbe4.com/ceo-fraud
- https://trustpair.com/blog/ceo-fraud-how-to-protect-your-organization-from-fraudsters/
- https://hacked.com/services/executive-impersonation-and-ceo-fraud-protecting-high-networth- individuals/
- https://www.certifid.com/article/ceo-fraud

With AI touching new milestones everyday an increasing need for making it secure is also arising. As these AI companies increase their operations and position in the market as providers of powerful tools in the market. A recent concern due to Anthropic's recent privacy policy update which will be effective from July 8, 2026 shows how companies have begun expanding the amount of personal information they collect in the name of safety, compliance, and trust. While they are being demonstrated as measures to improve safety of users and prevent abuse, it raises important questions about privacy, biometric data, surveillance, data retention, and user autonomy, some of which we will be addressing in this article.
Identity Verification of consumers
One of the most notable update to Anthropic's privacy policy is the category of "Verification Data." According to the policy, users may be asked to verify their age or identity in certain circumstances. Depending on the verification method, Anthropic may collect:
- Images of government-issued identity documents;
- Information appearing on those documents, including identification numbers and date of birth for age verification;
- Photographs or videos of the user;
- Facial geometry templates, which may constitute biometric data under certain legal frameworks; and
- The outcome of the verification process.
At first, this may appear similar to the Know Your Customer (KYC) procedures employed by banks or financial institutions but Claude is not a banking service. It is a consumer AI platform. The issue is not that verification exists, but that the circumstances under which it may be required remain undefined.
THE PROBLEM WITH “CERTAIN CIRCUMSTANCES”
The policy refers to verification being required in "certain circumstances." The public notification from Anthropic mentions that these circumstances may include access to particular features, routine platform integrity checks, abuse prevention mechanisms, policy enforcement activities, or legal compliance obligations. The ambiguity of this phrase raises important concerns. From a user perspective, it is difficult to determine, When verification may be triggered ? Whether verification applies only to suspicious accounts ? Whether access to future features may depend upon verification ? Whether users in particular regions will face more frequent verification requirements ? Whether verification requests may increase as AI regulation expands ? This broad language and discretionary power that the company has along with flexibility in the hands of the company creates uncertainty for users who may have initially joined a platform expecting only an email address and payment information to be required.
Government IDs collection: A new risk category
Almost all AI services have operated without collecting government-issued identity documents. Once a company begins processing such information, the privacy implications change dramatically. Because government issued IDs contain: Full legal names, Dates of birth, Identification numbers, Addresses, Photographs and information regarding nationality. When companies collect these documents, they will have an important database of highly sensitive personal information. Even if the company itself does not retain the documents indefinitely, the existence of a verification process introduces additional privacy and security risks. As per Anthropic has stated that identity verification is conducted through third-party providers such as Persona. According to article on the official site titled ‘Identity verification on Claude’, Persona stores the identity documents and selfie data, while Anthropic retains access to verification records when necessary. From the user's perspective, several important realities remain: First, the data still exists somewhere. Second, another third party organization is now involved in processing highly sensitive personal information. Third, Anthropic retains the ability to access verification records under certain circumstances. Therefore, although Anthropic may not directly maintain copies of every uploaded identity document, the practical result remains that sensitive information enters a broader ecosystem of entities and systems. Identity documents today are among the most valuable forms of personal information from the perspective of fraudsters, cybercriminals, and malicious actors. Therefore, any system that handles such documents becomes an attractive target for attack.
More information on persona’s government ID verification- https://withpersona.com/blog/what-is-government-id-verification
The Biometric Dimension
Another significant aspect of the update is the reference to facial geometry templates. Unlike passwords, biometric identifiers cannot easily be changed if compromised. A person can replace a password or even obtain a new identification card, but they cannot simply obtain a new face. Facial geometry templates are sensitive because they enable automated identity matching. Although these templates, as claimed, are not equivalent to photographs, they are nevertheless derived from unique physical characteristics of a person. In many jurisdictions, including parts of the European Union and several U.S. states, biometric data receives enhanced legal protection because of its permanence and sensitivity, let us see how it unfolds in these jurisdictions.
The Unanswered Retention Question
It is unclear in the policy as to how long the data will be retained because retention limits serve as one of the most important safeguards in modern privacy law, they have given another vague answer that “They're bound to protect it with industry-standard security controls and delete it in line with the retention limits we've set and applicable law.” The longer sensitive information remains stored, the greater the likelihood of unauthorized access, misuse, accidental disclosure, or legal compulsion.
Court Orders and Government Access
Anthropic may be required to disclose information pursuant to valid legal processes such as subpoenas, court orders, warrants, or regulatory directives. The existence of identity verification records means that future requests could potentially be linked to verified identities rather than pseudonymous accounts. This does not mean governments receive unrestricted access to user data. However, it does mean that once identity verification information exists within a company's ecosystem, it may become subject to lawful disclosure requirements. The privacy implications are therefore materially different from those associated with anonymous or pseudonymous AI usage.
Shifting Responsibility onto Users
Another concern is that the privacy policy states that users are responsible for ensuring they possess the necessary rights, permissions, or authority when uploading files, connecting third-party services, or instructing Claude to retrieve information. Anthropic is effectively informing users that they bear responsibility for ensuring that uploaded or connected data is lawfully accessible. As AI assistants gain greater capabilities, this transfer of responsibility from platform to user is likely to become increasingly common. Beyond individual privacy, Anthropic's verification policy also raises larger questions about data sovereignty and the cross-border movement of sensitive personal information. In India, the Justice K.S. Puttaswamy (Retd.) v. Union of India judgment recognized privacy as a fundamental right under Article 21 of the Constitution, affirming that individuals have the right to informational self-determination and control over their personal data. Yet, under Anthropic's verification framework, an Indian user may be required to upload a government-issued identity document and biometric information, which are processed by Persona, a U.S.-based identity verification company acting on behalf of Anthropic. Although users voluntarily consent to this process, it nevertheless results in highly sensitive identity information crossing national borders and entering the control of foreign private entities governed primarily by foreign contractual arrangements and multiple legal regimes. While governments issue identity documents as sovereign instruments of citizenship, their verification and processing are increasingly outsourced to multinational technology companies. Questions arise not only about how securely such information is handled, but also about which country's laws ultimately govern access, retention, disclosure, and accountability when personal data leaves the jurisdiction in which it originated. Under the Digital Personal Data Protection Act, 2023, cross-border transfer of personal data is generally permitted unless the Central Government specifically restricts transfers to certain jurisdictions. Therefore, a foreign company processing identity documents is not, by itself, unlawful but this legality does not eliminate legitimate concerns. Users realistically have limited bargaining power and little practical understanding of how long their identity documents, biometric templates, or verification records will be retained, who within the corporate ecosystem may access them, or how they may be disclosed pursuant to foreign legal processes.
Conclusion
The policy is commendable in some respects because it openly identifies the categories of information that may be collected rather than obscuring them behind vague terminology. However, important concerns remain regarding the extent of verification triggers, the handling of biometric information, the absence of clearly disclosed retention periods, and the long-term implications of linking AI accounts to government-issued identities. As AI systems become more integrated into daily life, these questions will likely become central issues in debates about digital privacy, surveillance, autonomy, and the future governance of artificial intelligence.
.webp)
Introduction
Imagine spending two years , 730 days of early mornings, missed social events, and relentless mock tests preparing for a single examination. Now imagine that on the morning of that exam, your phone buzzes with a forwarded video claiming the question paper has already leaked. Your heart sinks. You do not know whether to trust it or ignore it. You have about forty minutes before you must enter the hall. This was the reality for a section of the 22 lakh students who sat for the NEET UG 2026 re-examination on June 21, 2026, when a fabricated video alleging a paper leak on Telegram began circulating across WhatsApp groups and X within hours of the exam commencing. The National Testing Agency (NTA) swiftly and categorically denied the claims, activated the Indian Cyber Crime Coordination Centre (I4C), and appealed to the public not to amplify unverified content. The examination concluded without incident. But the episode laid bare a challenge that no security perimeter or surveillance camera can fully address: the weaponisation of misinformation against India's high-stakes examination ecosystem.
The Anatomy of Examination Misinformation
Why Examinations Are a Prime Target
India's national examinations are uniquely fertile ground for misinformation. With over 22 lakh candidates registered for NEET UG 2026 alone, the audience is vast, anxious, and hungry for any update verified or otherwise. Research by MIT has found that false stories spread six times faster than accurate ones on social media, and are seventy percent more likely to be reshared. In India, where over 535 million people use WhatsApp and studies show that most users tend to trust messages forwarded by family and friends, the conditions for viral misinformation are near-ideal. According to a 2020 Microsoft survey, 52 percent of Indian respondents encountered misinformation at least once a day, the highest rate globally.
What makes examination-related misinformation especially dangerous is its timing. Fabricated content is almost always released on examination day itself, the precise moment when candidates are most emotionally vulnerable, official channels are stretched thin, and the window for effective rebuttal is narrowest. The NEET UG 2026 fake video, circulated on Telegram and amplified across closed WhatsApp groups, fits this pattern precisely. It was engineered not to inform, but to destabilise.
A History That Sharpens the Anxiety
This misinformation did not emerge in a vacuum. The shadow of the 2024 NEET UG controversy in which the Supreme Court of India confirmed that at least 155 students had directly benefited from a genuine paper leak, and which triggered nationwide protests, CBI investigations, and a parliamentary uproar — still looms large. Students and parents conditioned by that experience are primed to believe the worst, even when claims are entirely false. In 2026, that residual anxiety became the very vulnerability that bad actors sought to exploit. The government's response which included temporarily restricting access to Telegram in the lead-up to the re-examination underscored just how seriously the threat of examination misinformation is now being taken at the highest levels.
The NTA's Response: Why It Matters
- Speed and Transparency as Governance Tools: In crisis communication, the first credible voice usually wins. The NTA's near-immediate public denial posted on official social media handles and amplified by the Press Information Bureau's PIB Fact Check unit was a meaningful departure from the delayed, defensive responses that characterised earlier examination controversies. By directly labelling the video "FAKE" in capital letters, describing its creation as "a serious offence," and simultaneously appealing to students to rely only on official sources at neet.nta.nic.in, the NTA left little room for the false narrative to consolidate. NTA Director General Abhishek Singh went further, publicly stating that the agency was "100 per cent confident" in the integrity of the process and that no complaints of a genuine paper leak had been received. This matters beyond crisis management. Public trust in examination systems is not rebuilt through official statements alone , it is rebuilt through the consistent, transparent exercise of institutional authority. A swift, fact-based rebuttal, deployed before rumour hardens into public belief, is as much a governance act as it is a communications strategy.
- Cybercrime Coordination as a Structural Shift: Perhaps the most significant development in the NTA's response was its coordination with I4C and law enforcement agencies to trace the origin of the fabricated video. This signals a structural evolution: examination misinformation is no longer being treated as an administrative inconvenience but as cybercrime with legal consequences under the Information Technology Act, 2000. The announcement that legal action would follow also carries a deterrent message to potential future actors — that the machinery of cybercrime enforcement will be activated, and that fabricating content to mislead examination candidates is a prosecutable offence.
The Human and Institutional Cost
The costs of examination misinformation are neither abstract nor trivial. Mental health experts have warned that controversies surrounding national-level examinations can have serious long-term psychological consequences for aspirants. Dr. Mustafa Nadeem Kirmani of Amity University has noted that such crises increase the risk of students taking "extreme steps like suicide attempts, anger toward the system, and hopelessness," and can, in the long run, lead to clinical depression. In the wake of the 2026 paper leak controversy, multiple reports of student deaths by suicide were linked to the compounded pressures of exam cancellation and uncertainty a grim reminder of the real human stakes behind governance failures in this domain. For institutions, every viral misinformation episode generates an avoidable administrative crisis. Helplines are overwhelmed, examination centre staff face panicked queries, and senior officials are pulled into damage control rather than exam administration. The credibility of clarifications issued under pressure is itself questioned by a public already primed for suspicion. This administrative burden, multiplied across 5,440 examination centres in India and 14 abroad, represents a significant and entirely unnecessary cost.
Building a Resilient Ecosystem: What Needs to Change
- Proactive Communication and Platform Coordination: Institutional credibility is built before a crisis, not during one. Examination bodies must invest in sustained pre-examination communication that educates candidates and parents about the existence of misinformation campaigns and tells them exactly where to look for verified updates. This means highly visible, verified social media presences with large followings, real-time update protocols, and formal escalation channels with platforms like WhatsApp, Telegram, X, and YouTube to enable rapid takedown of false examination-related content. The IT Amendment Rules of 2023, which require significant social media intermediaries to act on government-flagged content, provide a legal basis for such coordination but the operational infrastructure to activate it at speed must be built in advance, not improvised on the day.
- Fact-Checking Partnerships and Digital Literacy: Independent organisations such as BOOM Live, Alt News, and Vishvas News have proven their capacity to rapidly debunk examination misinformation. Formalising their role through a structured public-private partnership where examination authorities share real-time verified information with empanelled fact-checkers could close the window during which false content circulates unchallenged. Equally critical is investment in digital media literacy among students and parents. A 2018 survey found that nearly 45 percent of Indian respondents were unaware of any fact-checking organisations. Addressing this gap through school curricula, coaching networks, and the Ministry of Education's DIKSHA platform is a preventive investment far less costly than repeated crisis management.
Conclusion
The NTA's handling of the NEET UG 2026 fake video was, by recent standards, exemplary. It was fast, transparent, authoritative, and backed by the activation of cybercrime enforcement. But a single well-managed episode does not constitute a resilient system. India runs some of the world's largest entrance examinations, and the stakes medical seats, livelihoods, and the aspirations of crores of young people are too high for crisis response alone to suffice. Combating examination misinformation requires permanent structural investment: dedicated rapid-response cells within examination bodies, formalised fact-checking pipelines, proactive platform coordination, and a sustained public education effort around digital verification. Protecting the integrity of India's examination ecosystem is not merely an administrative responsibility. It is a commitment to the millions of students who give everything they have to compete fairly and who deserve a system that protects them not only from cheating, but from the fear of it.
References
- https://timesofindia.indiatimes.com/articleshow/131900261.cms
- https://www.india.com/education/neet-ug-2026-re-exam-paper-leak-claim-goes-viral-nta-says-video-is-fake-and-false-fabricated-examination-conducted-successfully-8453620/
- https://www.republicworld.com/education/neet-ug-re-exam-nta-says-paper-leak-video-fake-test-conducted-successfully-2026-06-22-129346
- https://thefederal.com/category/education/neet-re-exam-paper-leak-admission-system-crisis-247410
- https://www.outlookindia.com/healthcare-spotlight/beyond-the-paper-leak-emotional-trauma-among-neet-aspirants-raises-concern
- https://en.wikipedia.org/wiki/2024_NEET_controversy
- https://kaval.chat/blog/misinformation-scam-statistics-india-2026/
- https://www.ijert.org/the-virality-gap-political-misinformation-and-the-information-crisis-in-india-s-digital-democracy-ijertv15is050041
- https://www.science.org/doi/10.1126/science.aap9559 https://www.microsoft.com/en-us/digital-skills/digital-civility
- https://www.meity.gov.in/content/information-technology-intermediary-guidelines-and-digital-media-ethics-code-amendment
- https://www.indiacode.nic.in/handle/123456789/1999
- https://pib.gov.in/PressReleasePage.aspx
- https://www.careerindia.com/news/addressing-the-mental-health-crisis-sparked-by-net-and-neet-paper-leaked-in-india-041963.html
- https://thediplomat.com/2025/03/indias-growing-misinformation-crisis-a-threat-to-democracy/

Introduction
Picture this - you wake up one morning, check your phone, and discover that a fraudster has emptied your bank account overnight. Your first instinct is to call someone, anyone, who can stop the money from vanishing for good. For millions of Indians today, that number is 1930, the national cybercrime helpline. At a high-level review meeting in June 2026, Union Home Minister Amit Shah directed that the helpline undergo a comprehensive revamp, one that brings in artificial intelligence, multilingual support, and a stronger framework for resolving victim grievances. This is not a minor patch. It is a signal that India wants to treat cybercrime response as a serious governance priority rather than an administrative checkbox.
The Evolution of 1930: From a Pilot Number to National Infrastructure
The helpline’s origin lies in 155260 (Old helpline no.), launched in 2020 by the Indian Cyber Crime Coordination Centre (I4C) with the Reserve Bank of India and the banking sector, built specifically to intercept financial fraud before funds could be laundered across accounts. In 2021, it was renamed 1930 to make the number easier for citizens to recall under stress, a small but telling decision: a security architecture only works if people can remember it during a crisis. It was paired with the National Cybercrime Reporting Portal, launched in August 2019 to strengthen reporting and response mechanisms nationwide, which was later expanded to cover all categories of cybercrime after starting out limited to content-related offences. Over five years, state police forces extended 1930 into round-the-clock, multi-line operations and linked it to local cyber cells, turning a central scheme into genuinely federated infrastructure. The numbers now justify that investment: more than ₹7,000 crore has been saved nationally through the Citizen Financial Cyber Fraud Reporting and Management System, while Mumbai alone blocked or recovered nearly ₹202 crore for victims in 2025 through the helpline. What began as a pilot number has become a core node in India’s financial security architecture.
AI and Multilingual Support as a Citizen-Centric Governance Shift
What makes Shah’s directive significant is not the technology itself but the design philosophy it embeds. The instruction to integrate AI and multilingual support is explicitly aimed at removing language barriers and enabling faster, more efficient complaint registration across the country. For a country with no single dominant spoken language, this is not a feature addition; it is a recognition that uniform, English-or-Hindi-first service design has been quietly excluding the citizens most vulnerable to fraud. Multilingual access addresses a long-standing gap by allowing citizens from non-Hindi-speaking states to report cybercrime in their own languages, significantly broadening reach. This marks a shift away from treating digital governance as a one-size-fits-all portal and toward treating it as a service obligation that adapts to the citizen rather than the reverse, a principle with implications well beyond cybercrime reporting.
Routing, Tracking and Escalation: Engineering Accountability into Redressal
The proposed reforms move beyond the front-end call experience into the architecture of follow-through. AI integration is expected to improve call routing, enable faster identification of fraud patterns, and assist real-time coordination between central and state law enforcement agencies. This matters because cyber fraud is intrinsically cross-jurisdictional: a victim in one state is often defrauded through an account opened in another. Shah directed central agencies to work closely with state governments to ensure that every call received on the helpline is followed through to its logical conclusion — language that, in policy terms, is an attempt to convert a complaint-registration system into a complaint-resolution system. Intelligent routing and case tracking, if implemented well, replace ad hoc coordination between states with a traceable escalation mechanism, the missing link that has historically allowed cases to stall after the first call was logged.
Frozen Accounts and the Procedural Burden on Victims
No part of the revamp is more consequential for ordinary victims than the directive on bank account freezes. The problem is compounded when a cybercrime complaint is registered in one state while the frozen account sits in another, leaving legitimate account holders, sometimes innocent third parties, locked out of their own funds for weeks. Shah directed that grievances arising from the freezing of bank accounts linked to financial frauds be addressed promptly, an instruction that responds directly to a problem now before the courts Judicial scrutiny on this exact question is intensifying: the Karnataka High Court recently held that banks cannot freeze an account completely when investigating agencies have directed only a partial freeze limited to a specified amount. A national, technology-backed mechanism for resolving such freezes would convert a recurring source of citizen grievance into a procedural safeguard, addressing one of the most cited failures of the existing system.
Reading the Reforms Within India’s Broader Cyber Resilience Strategy
Positioned within India’s wider digital governance trajectory, the 1930 revamp fits a recognisable pattern: build foundational infrastructure first, then layer intelligence and personalisation onto it once adoption is proven. The same logic shaped Aadhaar, UPI and the Digital India programme more broadly. India has seen a sharp rise in digital financial fraud, investment scams, sextortion and phishing attacks in recent years, and the Ministry of Home Affairs’ response, expanding I4C, building specialised cybercrime units, and now investing in AI-led citizen interfaces, signals that cyber resilience is being treated less as a law-enforcement afterthought and more as a core pillar of financial-system integrity, alongside RBI and NPCI-led safeguards.
Will These Reforms Strengthen Trust?
The credibility of any reform lies in implementation, not announcement. Public commentary on the revamp captures this tension well: citizens have welcomed the intent while noting that earlier promises of coordination did not always translate into resolved cases, and that awareness gaps in rural India persist regardless of how sophisticated the backend becomes The 1930 revamp will be judged not by how quickly complaints are registered, an area where India already performs reasonably, but by how reliably they are closed. If AI-driven routing and a genuine national escalation mechanism reduce the gap between complaint and resolution, particularly on account freezes, the reform will have done more for citizen trust than any awareness campaign could. If implementation falters at the state-bank coordination layer, the technology will simply make an old problem move faster without making it smaller.
Conclusion
The story of 1930 is the story of Indian digital governance maturing in real time: from a hastily assembled fraud helpline to a piece of national financial security infrastructure now being re-engineered for scale, language diversity and accountability. Amit Shah’s directive should be read not as a single announcement but as an acknowledgment that citizen-facing systems must keep pace with the sophistication of the threats they are built to counter. Whether this becomes a genuine trust-building reform or another well-intentioned upgrade depends entirely on what happens after the press statement — in LEA’s call centres, bank back-offices and state coordination desks across the country.
References
- https://www.republicworld.com/india/amit-shah-orders-major-overhaul-of-national-cybercrime-helpline-1930-calls-for-ai-upgrade-2026-06-17-128739
- https://the420.in/amit-shah-national-cybercrime-helpline-revamp/
- https://inc42.com/buzz/home-minister-amit-shah-calls-for-ai-led-revamp-of-national-cybercrime-helpline/
- https://thenewsmill.com/2026/06/amit-shah-directs-ai-upgrade-for-national-cybercrime-helpline-1930/
- https://risingkashmir.com/national/amit-shah-reviews-national-cybercrime-helpline-1930-calls-for-ai-upgrade-12048424
- https://www.newkerala.com/news/a/amit-shah-reviews-national-cybercrime-helpline-1930-calls-929.htm
- https://simple.wikipedia.org/wiki/1930_(Indian_Cybercrime_Helpline)
- https://www.newsonair.gov.in/over-rs-7000-crore-saved-through-citizen-financial-cyber-fraud-reporting-and-management-system
- https://the420.in/mumbai-1930-cyber-helpline-saves-202-crore-2025
.webp)
Introduction
The rise of artificial intelligence has transformed how individuals search for information, buy and compare products online. Unlike the traditional search engines like Google that presents the user with a set of links and directs users to websites, AI-powered systems provide synthesised answers and recommendations which means we don't have to click through every link to find what we are looking for, we simply have to ask an LLM and it provides recommendations based on our needs expressed through prompt. This development has raised important legal and commercial questions, one such question was addressed in the judgement of Indiamart Inter Mesh Limited v. Open AI Inc. and Others (2026 SCC OnLine Cal 5738) decided by HMJ Ravi Krishan Kapur of Calcutta High court on 20 May 2026. If an AI platform becomes a primary source of information, can a business demand inclusion in its responses? Is it a legal injury if the LLM omits a business? More fundamentally, how do the existing laws classify technologies that not only process information, but also generate new content? These were the questions that came before Calcutta High Court. Although the dispute arose from Indiamart’s complaint regarding visibility on ChatGPT search, the judgement explored beyond the disagreement between two private entities.
The Dispute
IndiaMart is one of India’s largest electronic business-to-business marketplaces since 1996, serving millions of buyers and sellers across India. They also have registered trademarks and their entire business depends on visibility on the internet considering the digitalisation of the market. Open AI launched ChatGPT search in October 2024, which is a feature that supplements AI responses with links to relevant web sources. Indiamart alleged that ChatGPT was not displaying links to their online platform in the same way that it displayed links to other competing services or individual sellers. A major grievance raised by Indiamart was that ChatGPT allegedly bypassed IndiaMart market listings by directing users to sellers’ individual websites while continuing to provide platform level links for other competing platforms. Hence, they contended that this practice diverted users away from their platform and negatively affected their business interests. The company argued that such exclusion amounted to discriminatory treatment and resulted in economic harm, diluted its trademarks and amounted to disparagement. They alleged that it violated their rights under article 14, 19, 21 under the constitution and rights under IT Act and IT Rules also. When IndiaMart sought an explanation from OpenAI, the company stated that its decision was influenced by the inclusion of IndiaMart in the United States Trade Representative (USTR) Review of Notorious Markets for Counterfeiting and Piracy 2024, a U.S. government report that identifies online and physical marketplaces alleged to facilitate intellectual property infringements. IndiaMart challenged this justification, arguing that the USTR report has no statutory or binding force in India. It further alleged selective discrimination, pointing out that several other platforms featured on the same USTR list including DHGate, Pinduoduo, Shopee, and Taobao continued to remain accessible through ChatGPT-generated responses. Consequently, IndiaMart approached the Calcutta High Court seeking interim relief directing ChatGPT to display and provide access to IndiaMart links in its responses.
ARGUMENTS BEFORE THE COURT
IndiaMart's contentions: They argued that ChatGPT, because its search feature, performs the role of an "intermediary" within the meaning of Section 2(1)(w) of the IT Act and is therefore required to comply with the obligations imposed under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Relying on Rule 3(1)(n), IndiaMart argued that an intermediary cannot engage in discriminatory treatment of platforms or selectively restrict access to information. IndiaMart further maintained that users have a right to access information relating to its platform and that the omission of IndiaMart links from ChatGPT's responses violated this interest. They alleged violation of Articles 14, 19, and 21 of the Constitution, along with the broader principle of a user's "right to know", to argue that OpenAI owed an obligation to display IndiaMart listings in response to relevant queries. In addition, IndiaMart alleged that the exclusion of its links caused commercial harm, diluted its trademarks, amounted to disparagement, and constituted an unfair trade practice that adversely affected its business and reputation.
OpenAI's contentions: OpenAI asserted that IndiaMart had no legally enforceable ‘Right to visibility’ on ChatGPT. They argued that neither contract, statute, nor constitutional law imposed any obligation on OpenAI to display, prioritise, or recommend IndiaMart links in response to user queries. In the absence of any recognised legal right, there could be no actionable injury and therefore no valid cause of action. OpenAI also challenged the classification of ChatGPT as an "intermediary" under the Information Technology Act, 2000. According to OpenAI, ChatGPT does not merely host, transmit, or facilitate access to third-party content but also generates responses through its large language model (LLM) and therefore functions more closely as an "originator" than an intermediary. Consequently, the obligations applicable to intermediaries under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, including those relied upon by IndiaMart, were inapplicable. With respect to the USTR Notorious Markets List, OpenAI submitted that its reliance on the report formed part of its internal risk-management and business policies. Such decisions, it argued, were matters of private commercial judgment and not ordinarily subject to judicial review. OpenAI further pointed out that IndiaMart had also previously blocked ChatGPT from accessing and crawling its website that weakened the company's demand for greater visibility within ChatGPT-generated responses.
Court’s decision: The court rejected Indiamart's claim that they were entitled to be displayed in ChatGPT searches. The court emphasised the autonomy of private businesses, the court held that the right to carry on trade and business is "inviolable" and that no law can compel one private entity to operate their platform for the benefit of another, which is based on foundational economic philosophy of laissez faire. Unless there is a contractual, statutory or constitutional obligation, a platform has no duty to the other platform to promote or advance their economic interest. Applying this principle, the court found no such duty or “vested legal right” that entitled IndiaMart’s visibility on ChatGPT. The court reasoned that even if users possess the ‘right to know’, Indiamart could not convert that interest into an enforceable claim under article 19(1)(g) or other legal provision. The court looked at the dispute as one arising from commercial disadvantage rather than violation of any legally protected right. Although the reduced visibility may have had economic consequences, economic harm does not by itself create a cause of action.
The court also took into consideration whether ChatGPT should be classified as an intermediary under Section 2(1)(w) of the Information Technology Act, 2000 or as an originator under Section 2(1)(za). This was an important distinction, because the intermediaries can claim safe harbour protection under section 79 of the IT act, but the originators cannot. The court expressed a preliminary view that ChatGPT is generative capabilities, place it closer to an originator than an intermediary because, unlike conventional search engines, which identify and rank existing information, Generative AI systems, analyse the data and produce new output based on algorithms, which is in response to the user’s prompt. The Court also referenced the NITI Aayog National Strategy for Artificial Intelligence (pages 7 to 12) to support its observations that ChatGPT does not merely store, host or transmit information, it can produce essays, research material, code, creative writing, and other forms of content that did not previously exist in that exact form, hence extending beyond the conventional understanding of an intermediary. The court also recognised that it is a vexed issue and remains unsettled because AI systems operate in response to users instructions and do not function independently, which is why the court refrained from providing a definitive classification and acknowledged that the question may ultimately require legislative clarification as well.
In addition to this, the Court took the view that the IndiaMart’s grievances did not amount to an Intellectual property dispute, as they found no trademark infringement or dilution because any reference to the "IndiaMart" mark was merely descriptive and did not constitute commercial use "in the course of trade" under Section 29(4) of the Trade Marks Act. IndiaMart also hadn’t demonstrated any false or misleading use of its trademark.
Similarly, the Court found that claims of disparagement, trade libel, and injurious falsehood were unsustainable because such claims require the publication of a false statement that harms reputation and since ChatGPT had not published any derogatory statement about IndiaMart, the mere omission of links could not amount to disparagement or libel. The Court relied on Tech Plus Media v. Jyoti Janda, that allegations of unfairness or copyright infringement must be supported by specific pleadings and evidence.
Beyond the immediate dispute, the judgment shed light on the growing difficulty of applying legal categories created for an earlier internet era to generative AI systems. The Information Technology Act was enacted at a time when internet regulation focused primarily on websites, service providers, and electronic communications and therefore existing classifications may not adequately address the hybrid nature of contemporary AI technologies. The Court acknowledged OpenAI's concern that granting IndiaMart's request could trigger floodgates of litigation on similar claims from businesses dissatisfied with AI-generated visibility, however, it clarified that such concerns cannot outweigh genuine legal claims or fundamental rights. The Court suggested that legislative intervention may eventually be necessary.
Conclusion
This judgement not only addressed the visibility issue in AI generated responses, but also whether visibility itself can become a legally protected interest in AI-driven searches? As more and more users rely on AI generated output for their preference rather than traditional search engine output, the power to decide what information is displayed and what is not will eventually become economically significant. The Calcutta High Court through this judgement declined to create any such right through judicial interventions and also highlighted that the existing legal framework is not adequately equipped to address the novel challenges posed by generative AI.
(This blog is based on the judgment in Indiamart Inter Mesh Limited v. Open AI Inc. and Others, 2026 SCC OnLine Cal 5738, decided on May 20, 2026 by the Calcutta High Court, and related reporting by LiveLaw and SCC Times.)
References
- https://www.livelaw.in/high-court/calcutta-high-court/no-right-to-visibility-exists-on-private-ai-platforms-calcutta-high-court-refuses-to-direct-chatgpt-to-display-indiamart-links-536891
- https://www.scconline.com/blog/post/2026/06/03/chatgpt-intermediary-originator-it-act-calcutta-high-court/
- https://indiankanoon.org/doc/198449710/

Introduction
In June 2026, the Government of India temporarily restricted access to Telegram amid concerns that the platform had been used to facilitate examination related malpractice, including the alleged circulation of leaked question papers during the NEET UG re examination. The move reignited a familiar debate about the responsibility of digital platforms for unlawful activities carried out through them.
Critics of such restrictions raise a fundamental question: if a traffic accident occurs on a road, do we shut down the road? If theft takes place inside a shopping mall, do we close the entire mall? By the same logic, is it reasonable to block a communication platform because some individuals misuse it? These questions lie at the heart of a broader conflict between state interests in maintaining public order and the protection of digital rights, privacy, and freedom of communication in an increasingly interconnected world.
The controversy surrounding Telegram therefore extends beyond a single examination or messaging application. It raises a deeper and more pressing question: who should bear responsibility for illegal acts committed through encrypted digital platforms, and where should the law draw the line between effective enforcement and the preservation of fundamental digital freedoms?
Beyond mere communication for millions of students in India, Telegram is a classroom in the digital sense, an archive for their notes, practice papers, lecture recordings, and community groups that hundreds of millions of candidates refer to every single day. Therefore, why on a routine day in June 2026 did the messaging app top every other channel? Temporary internet restriction on the platform had become necessary to stop examination-related malpractice like leakage of question papers and was temporarily suspended, with reports suggesting that this move by the government was on the occasion of the NEET-UG re-examination.
This ban once again brings up a bigger question that cannot be contained within one particular examination. When has it become okay to hold a communication platform responsible and accountable for illegal acts committed over it? Or are the perpetrators solely to blame, and the service can be prohibited? Ultimately, where is the line drawn between public interest, law enforcement, and digital rights and privacy?
End-to-End Encryption: Architecture and Benefits
At the heart of these discussions of Telegram and other apps lies a technology referred to as "end-to-end encryption" or "E2EE." Quite literally, it means a message is locked with cryptography on the sender's device and can only be unlocked by the intended recipient. Not even the tech platform running the communication app can decipher it for everyone else; it just looks like random gibberish.
The Process
This kind of modern communication relies on public key cryptography. Each person has a public key they can share with anyone and a private key that stays only on their devices. When they send you a message, it is scrambled with crypto that can be unlocked by only your private key. WhatsApp and Signal, for example, use the Signal Protocol, which features "perfect forward secrecy" and is designed to protect communications from ever being unlocked even if one key is compromised. Telegram's approach is a bit unique. By default, Telegram messages aren't encrypted with end-to-end crypto; this only comes via an optional feature called "Secret Chats," a key difference in the regulatory debate.
The Dark Side: Crime, Misuse, and the Moderation Dilemma
The very features that make end-to-end messaging popular among everyday people are privacy, speed, anonymity, and mass reach which also make end-to-end messaging popular among criminals. That, unfortunately, is the catch for policymakers globally: The technology designed to protect innocent users is also the technology that facilitates criminal activity.
3.1 Criminal Abuse
Telegram, in particular, has frequently come under fire for its role in hosting a spectrum of criminal activities, most notably in the recent controversy in India regarding NEET-UG 2026 examination papers where channels allegedly advertised leaked question papers for enormous sums, convincing desperate candidates. In these instances, messages could be altered or deleted using Telegram’s message editing feature, fabricating evidence of prior leaks. However, this extends to illicit marketplaces, drug trafficking, financial fraud, money laundering, and distributing other prohibited content. Telegram's usage in disseminating extremist propaganda and aiding criminal organizations is also frequently cited, leading to bans or restrictions in countries ranging from Brazil to Nepal to Somalia to Vietnam.
3.2 The Moderation Dilemma
But the difficulty is not just with misuse; it’s also about effective moderation. Moderation, however, requires content transparency. Strong encryption is built to obscure just that. Many end-to-end messaging services like Signal and WhatsApp emphasize that even if they wanted to, they would have been able to decipher the content of a user’s message due to their architecture. Telegram has been in scrutiny for years due to its limited cooperation with law enforcement agencies because its default chats are not completely end-to-end encrypted, though there has been an attempt by Pavel Durov, the platform’s founder, to increase cooperation following his 2024 arrest in France.
This gives policymakers the following challenge: How can governments require increased access to fight crime without forcing tech companies to weaken security for everyone? As cryptographers point out, a specific "backdoor" intended to allow access to law enforcement officials can be easily exploited by hackers, foreign governments, and any other actor with nefarious intent.
Comparison of Regulatory Approaches Worldwide
4.1 Authoritarian Countries' Responses
China, for instance, has had the app blocked as part of its strategy to control access to the internet since 2015, and Iran did so in 2018 when the app was used to help organize protests against the government. An infamous Russian bid to block Telegram in 2018 turned into a cautionary story. Trying to censor the service disrupted the IPs of millions of computers, including significant services like those run by Amazon and Google. The move was met by a surge of users turning to VPNs to get access. It’s an expensive, disruptive, and incomplete form of censorship.
4.2 Democratic Countries' Approaches
Democratic jurisdictions generally prefer targeted interventions. Telegram was suspended in Brazil in 2022 and 2023, though again, only in response to a judge’s order in relation to particular investigations, and was lifted when it came into compliance. The EU’s approach has been to build on an established approach of regulation by use of a broader legislative framework, including the Digital Services Act and the Digital Markets Act, aimed at platform liability rather than outlawing encryption outright.
Meanwhile, the proposed scanning of encrypted communications has run into strong judicial headwinds, with the European courts stressing the danger of backdoors to privacy.
4.3 The United Kingdom Approach
The UK offers a middle way. With its Investigatory Powers Act, the government can oblige tech companies to collaborate in legitimate investigations. But this came to a head earlier this year with the case of Apple and the government's attempts to force it to unlock encrypted iCloud backups. Apple not only refused to reduce its encryption but also decided instead to disable some of its features for British users. This has created a problem for democracies across the world: how to balance access for investigators against the need to maintain the security that makes our systems safer.
Judicial and Legislative Perspectives: India and Beyond
In the Indian context, to have a perspective about the legal frameworks concerning content moderation, let’s explore some of the foundational decisions from the Supreme Court. Three decisions have laid the building block for digital rights laws: the first being Shreya Singhal v. Union of India (2015), where Section 69A of the IT Act, 2000, was upheld, but only by laying rigorous conditions on the review process and chance of challenging the said decision. Another important decision in this sphere is Justice K.S. Puttaswamy v. Union of India (2017) which stated that the right to privacy is fundamental in nature under Article 21 of the Constitution and stipulated the constitutional requirements of legality, legitimacy, and proportionality against the state’s interventions in fundamental rights. The most recent important case law to consider, in this context, would be Anuradha Bhasin v. Union of India (2020) which set certain limitations, such as any internet shut-downs or orders have to be temporary, proportional, and have scope for appeal. Further, the Supreme Court demanded transparency around any and all orders of blocking.
These principles of proportionality and legal limitations are highly pertinent to the Telegram issue, especially since Section 69A confers powers to block information in case of concerns about public order, national security, etc., but activists often cite this power to target specific content rather than entire platforms like Telegram. The ban on Telegram in June 2026 and disabling of message editing will force authorities to justify not only their statutory authority but also the need for proportionate means.
These aspects are amplified by IT Rules, 2021, which mandate that some instant messaging platforms may require identification of the ‘first originator’ of messages, and the Digital Personal Data Protection Act, 2023, to protect digital personal data by ensuring it does not undermine national security exceptions to this end.
Moreover, the use of encryption to ensure secure and private communications is becoming an important point of legal discourse globally. Recently, the European Court of Human Rights in Podchasov v. Russia (2024) held that mandating decryption on devices as a tool of investigative power constituted a disproportionate interference with an individual's right to privacy implying that while states may indeed have authority to regulate communication and digital services, any such measures limiting the scope of encryption will have to meet strict requirements of legality, necessity, and proportionality to be legally justifiable.
Constitutional Validity of the Ban
The government's case for a constitutional ban on Telegram rests upon its ability to satisfy the proportionality framework established by Puttaswamy and Anuradha Bhasin.
- Legitimate aim: The state's strong suit. This is the government's best argument. Protection of the integrity of NEET-UG, a high-stakes test with close to 2.4 million students, can indeed be a legitimate state objective. Given that there is evidence of channels that allegedly were involved in selling leaked question papers, the action is presumably justifiable under section 69A for preventing the incitement or occurrence of public disorder or preventing cognizable offenses.
- Necessity: The National Testing Agency (NTA) itself admitted that localized removal of suspicious accounts on Telegram had already mitigated the risks, while Telegram insisted that it had independently taken down numerous channels. The fact that the block affected more than 150 million users in India, where the medium is widely used for personal communication and is also utilized on other platforms like WhatsApp, Discord, and Instagram to a similar or higher extent, raises the responsibility to justify a strict platform-wide ban. Moreover, there is a significant legal question regarding the state’s authority under section 69A to direct Telegram to disable its message-editing capability.
- Proportionality and process: The block, even though it was temporary and intended to ensure fairness in the examination system, severely undermined legitimate uses of the platform by students who used it to share educational materials and organize study groups. Moreover, the opaqueness around the section 69A order is itself hard to reconcile with the transparency requirements set out in Anuradha Bhasin.
Thus, while the objectives of preventing exam fraud may be legitimate, the necessity and proportionality of single platform-wide bans remain highly suspect under Indian constitutional law.
Policy Recommendations and the Path Forward
The Telegram controversy points to the need for a better balancing act in platform governance in India. Firstly, instead of blanket platform shutdowns, action should target specific channels, bots, or URLs, as may be the case. Secondly, any attempt to dictate changes to features, such as disabling message editing, should be based on specific statutory provisions, not an expansive reading of Section 69A. Furthermore, there is a dire need for increased transparency; blocking orders must state the justification for the order, what is being blocked, and for how long, as far as possible. In the long run, stricter cross-border cooperation via streamlined MLATs, or through the appointment of local legal representatives by foreign platforms, would facilitate easier enforcement. Ultimately, all major blocking decisions must be accompanied by proportionality assessments. Lastly, India must resist pressure to provide access to encryption backdoors; while this might ease investigative burdens, doing so would severely jeopardise the cybersecurity of India, its businesses, and citizens.
Conclusion
The Telegram ban is an example of the tricky equilibrium between protection of public interest and protection of digital liberties in our hyper-connected world. While the intent to counter exam fraud is justifiable, a blanket ban on any platform has much broader implications on questions of necessity, proportionality and transparency. India has a well-developed constitutional and legal framework to deal with this issue already, and the challenge will be to see if those powers are used appropriately.
References
Cases:
- Shreya Singhal v. Union of India (2015) 5 SCC 1 — Supreme Court of India
- Justice K.S. Puttaswamy v. Union of India (2017) 10 SCC 1 — Supreme Court of India (Nine-Judge Bench)
- Anuradha Bhasin v. Union of India (2020) 3 SCC 637 — Supreme Court of India
- Podchasov v. Russia, European Court of Human Rights (Application No. 33696/19, February 2024)
- Apple Inc. v. United States (In re Search of an Apple iPhone, C.D. Cal. 2016)
- Telegram Messenger Inc. v. Union of India & Anr., Delhi High Court (June 2026) — Sub judice
Legislation & Rules:
- Information Technology Act, 2000 (India) — Sections 69A, 79
- IT (Procedure and Safeguards for Blocking Access to Information by Public) Rules, 2009
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
- Digital Personal Data Protection Act, 2023 (India) & DPDP Rules, 2025
- EU Digital Services Act, 2022 (Regulation 2022/2065)
- EU Digital Markets Act, 2022 (Regulation 2022/1925)
- EU Child Sexual Abuse Regulation (CSAR) Proposal — In Trilogue, June 2026
- UK Investigatory Powers Act, 2016
Policy Sources:
- Internet Freedom Foundation, Statement on Telegram Block, 16 June 2026
- European Commission, ProtectEU Security Strategy, June 2025
- MeitY Section 69A Blocking Order re: Telegram (June 2026)
- NTA Press Release on NEET-UG 2026 Re-Examination, 16 June 2026

Executive Summary:
New Linux malware has been discovered by a cybersecurity firm Volexity, and this new strain of malware is being referred to as DISGOMOJI. A Pakistan-based threat actor alias ‘UTA0137’ has been identified as having espionage aims, with its primary focus on Indian government entities. Like other common forms of backdoors and botnets involved in different types of cyberattacks, DISGOMOJI, the malware allows the use of commands to capture screenshots, search for files to steal, spread additional payloads, and transfer files. DISGOMOJI uses Discord (messaging service) for Command & Control (C2) and uses emojis for C2 communication. This malware targets Linux operating systems.
The DISCOMOJI Malware:
- The DISGOMOJI malware opens a specific channel in a Discord server and every new channel corresponds to a new victim. This means that the attacker can communicate with the victim one at a time.
- This particular malware connects with the attacker-controlled Discord server using Emoji, a form of relay protocol. The attacker provides unique emojis as instructions, and the malware uses emojis as a feedback to the subsequent command status.
- For instance, the ‘camera with flash’ emoji is used to screenshots the device of the victim or to steal, the ‘fox’ emoji cracks all Firefox profiles, and the ‘skull’ emoji kills the malware process.
- This C2 communication is done using emojis to ensure messaging between infected contacts, and it is almost impossible for Discord to shut down the malware as it can always change the account details of Discord it is using once the maliciou server is blocked.
- The malware also has capabilities aside from the emoji-based C2 such as network probing, tunneling, and data theft that are needed to help the UTA0137 threat actor in achieving its espionage goals.
Specific emojis used for different commands by UTA0137:
- Camera with Flash (📸): Captures a picture of the target device’s screen as per the victim’s directions.
- Backhand Index Pointing Down (👇): Extracts files from the targeted device and sends them to the command channel in the form of attachments.
- Backhand Index Pointing Right (👉): This process involves sending a file found on the victim’s device to another web-hosted file storage service known as Oshi or oshi[. ]at.
- Backhand Index Pointing Left (👈): Sends a file from the victim’s device to transfer[. ]sh, which is an online service for sharing files on the Internet.
- Fire (🔥): Finds and transmits all files with certain extensions that exist on the victim’s device, such as *. txt, *. doc, *. xls, *. pdf, *. ppt, *. rtf, *. log, *. cfg, *. dat, *. db, *. mdb, *. odb, *. sql, *. json, *. xml, *. php, *. asp, *. pl, *. sh, *. py, *. ino, *. cpp, *. java,
- Fox (🦊): This works by compressing all Firefox related profiles in the affected device.
- Skull (💀): Kills the malware process in windows using ‘os. Exit()’
- Man Running (🏃♂️): Execute a command on a victim’s device. This command receives an argument, which is the command to execute.
- Index Pointing up (👆) : Upload a file to the victim's device. The file to upload is attached along with this emoji
Analysis:
The analysis was carried out for one of the indicator of compromised SHA-256 hash file- C981aa1f05adf030bacffc0e279cf9dc93cef877f7bce33ee27e9296363cf002.
It is found that most of the vendors have marked the file as trojan in virustotal and the graph explains the malicious nature of the contacted domains and IPs.


Discord & C2 Communication for UTA0137:
- Stealthiness: Discord is a well-known messaging platform used for different purposes, which means that sending any messages or files on the server should not attract suspicion. Such stealthiness makes it possible for UTA0137 to remain dormant for greater periods before launching an attack.
- Customization: UTA0137 connected to Discord is able to create specific channels for distinct victims on the server. Such a framework allows the attackers to communicate with each of the victims individually to make a process more accurate and efficient.
- Emoji-based protocol: For C2 communication, emojis really complicates the attempt that Discord might make to interfere with the operations of the malware. In case the malicious server gets banned, malware could easily be recovered, especially by using the Discord credentials from the C2 server.
- Persistence: The malware, as stated above, has the ability to perpetually exist to hack the system and withstand rebooting of systems so that the virus can continue to operate without being detected by the owner of the hacked system.
- Advanced capabilities: Other features of DISGOMOJI are the Network Map using Nmap scanner, network tunneling through Chisel and Ligolo and Data Exfiltration by File Sharing services. These capabilities thus help in aiding the espionage goals of UTA0137.
- Social engineering: The virus and the trojan can show the pop-up windows and prompt messages, for example the fake update for firefox and similar applications, where the user can be tricked into inputting the password.
- Dynamic credential fetching: The malware does not write the hardcoded values of the credentials in order to connect it to the discord server. This also inconveniences analysts as they are unable to easily locate the position of the C2 server.
- Bogus informational and error messages: They never show any real information or errors because they do not want one to decipher the malicious behavior easily.
Recommendations to mitigate the risk of UTA0137:
- Regularly Update Software and Firmware: It is essential to regularly update all the application software and firmware of different devices, particularly, routers, to prevent hackers from exploiting the discovered and disclosed flaws. This includes fixing bugs such as CVE-2024-3080 and CVE-2024-3912 on ASUS routers, which basically entails solving a set of problems.
- Implement Multi-Factor Authentication: There are statistics that show how often user accounts are attacked, it is important to incorporate multi-factor authentication to further secure the accounts.
- Deploy Advanced Malware Protection: Provide robust guard that will help the user recognize and prevent the execution of the DISGOMOJI malware and similar threats.
- Enhance Network Segmentation: Utilize stringent network isolation mechanisms that seek to compartmentalize the key systems and data from the rest of the network in order to minimize the attack exposure.
- Monitor Network Activity: Scanning Network hour to hour for identifying and handling the security breach and the tools such as Nmap, Chisel, Ligolo etc can be used.
- Utilize Threat Intelligence: To leverage advanced threats intelligence which will help you acquire knowledge on previous threats and vulnerabilities and take informed actions.
- Secure Communication Channels: Mitigate the problem of the leakage of developers’ credentials and ways of engaging with the discord through loss of contact to prevent abusing attacks or gaining control over Discord as an attack vector.
- Enforce Access Control: Regularly review and update the user authentication processes by adopting stricter access control measures that will allow only the right personnel to access the right systems and information.
- Conduct Regular Security Audits: It is important to engage in security audits periodically in an effort to check some of the weaknesses present within the network or systems.
- Implement Incident Response Plan: Conduct a risk assessment, based on that design and establish an efficient incident response kit that helps in the early identification, isolation, and management of security breaches.
- Educate Users: Educate users on cybersecurity hygiene, opportunities to strengthen affinity with the University, and conduct retraining on threats like phishing and social engineering.
Conclusion:
The new threat actor named UTA0137 from Pakistan who was utilizing DISGOMOJI malware to attack Indian government institutions using embedded emojis with a command line through the Discord app was discovered by Volexity. It has the capability to exfiltrate and aims to steal the data of government entities. The UTA0137 was continuously improved over time to permanently communicate with victims. It underlines the necessity of having strong protection from viruses and hacker attacks, using secure passwords and unique codes every time, updating the software more often and having high-level anti-malware tools. Organizations can minimize advanced threats, the likes of DISGOMOJI and protect sensitive data by improving network segmentation, continuous monitoring of activities, and users’ awareness.
References:
https://otx.alienvault.com/pulse/66712446e23b1d14e4f293eb
https://thehackernews.com/2024/06/pakistani-hackers-use-disgomoji-malware.html?m=1
https://cybernews.com/news/hackers-using-emojis-to-command-malware/
https://www.volexity.com/blog/2024/06/13/disgomoji-malware-used-to-target-indian-government/

Introduction
The ‘Barbie’ fever is going high in India, and it’s hype to launch online scams in India. The cybercriminals attacking the ‘Barbie’ fans in India, as the popular malware and antivirus protection MacAfee has recently reported that India is in the top 3rd number among countries facing major malware attacks. After the release of ‘barbie’ in theatres, the Scams started spreading across India through the free download of the ‘Barbie’ movie from the link and other viruses. The scammers trick the victims by selling free ‘Barbie’ tickets and, after the movie’s hit, search for the free download links on websites which leads to the Scams.
What is the ‘Barbie’ malware?
After the release of the ‘Barbie’ movie, trying to keep up with the trend, Barbie fans started to search the links for free movie downloads from anonymous sources. And after downloading the movie, there was malware in the downloaded zip files. The online scam includes not genuine dubbed downloads of the movie that install malware, barbie-related viruses, and fake videos that point to free tickets, and also clicking on unverified links for the movie access resulted in Scam. It is important not to get stuck in these trends just because to keep up with them, as it could land you in trouble.
Case: As per the report of McAfee, several cases of malware trick victims into downloading the ‘ Barbie’ movie in different languages. By clicking the link, it prompts the user to download a Zip file, which is packed with malware
Countries-wise malware distribution
Cyber Scams witnessed a significant surge in just a few weeks, with hundreds of incidents of new malware cases. And The USA is on the top No. Among all the countries, In the USA there was 37 % of ‘Barbie’ malware attacks held per the, while Australia, the UK, and India suffered 6 % of malware attacks. And other countries like Japan, Ireland, and France faced 3% of Malware attacks.
What are the precautions?
Cyber scams are evolving everywhere, users must remain vigilant and take necessary precautions to protect their personal information. The user shall avoid clicking on suspicious links, also those which are related to unauthorised movie downloads or fake ticket offers. The people shall use legitimate and official platforms to access movie-related content. Keeping anti-malware and antivirus will add an extra layer of protection.
Here are some following precautions against Malware:
- Use security software.
- Use strong passwords and authentication.
- Enforce safe browsing and email.
- Data backup.
- Implement Anti-lateral Movement.
Conclusion
Cyberspace is evolving, and with that, Scams are also evolving. With the new trend of ‘Barbie’ Scams going on the rise everywhere, India is on top 3rd No. In India, McAfee reported several malicious attacks that attempted to trick the victims into downloading the free version of ‘Barbie’ movie in dubbed languages. This resulted in a Scam. People usually try to keep up with trends that land them in trouble. The users shall beware of these kinds of cyber-attacks. These scams result in huge losses. Technology should be used with proper precautions as per the incidents happening around.

Introduction
A famous quote, “Half knowledge is always dangerous”, but “Too much knowledge of anything can lead to destruction”. Recently very infamous spyware and malware named WyrmSpy and Dragon Egg were invented by a Chinese group of hackers APT41. The APT41 is a state-endorsed Clandstein active group based in the People’s Republic of China that has been active since 2012. In contrast to numerous countries-government supported, APT has a footprint record jeopardising both government organisations for clandestine activities as well as different private organisations or enterprises for their financial gain. APT41 group aims at Android devices through spyware wyrmspy and dragon egg, which masquerades as a legitimate application. According to the U.S. jury legal accusation from 2019 to 2020, the group was entangled in threatening over more than 100 public and private individuals and organisations in the United States and around the world.Moreover, a detailed analysis report was shared by the Lookout Threat Researchers, that has been actively monitoring and tracking both spyware and malware.
Briefing about how spyware attacks on Android devices take place
To begin with, this malware imitates a real source Android application to show some sort of notification. Once it is successfully installed on the user’s machine, proclaims multiple device’s permission to enable data filtration.
Wyrmspy complies with log files, photos, device locations, SMS(read and write), and audio recordings. It has also authenticated that there are no detection malware activities found on google play even after running multiple security levels. These malicious things are made with the intent to obtain rooting access privileges to the device and monitor activities to the specified commands received from the C2 servers.
Similarly, Dragon Egg can collect data files, contacts, locations, and audio recordings, and it also accesses camera photos once it successfully trade-off the device. Dragon egg receives a payload that is also known as “smallmload.jar”, which is either from APK(Android Packet Kit).
WyrmSpy initially masquerades as a default operation system application, and Dragon Egg simulates a third-party keyboard/ messaging application.
Overview of APT41 Chinese group background
APT41 is a Chinese-based stealth activity-carrying group that is said to be active since mid-2006. Rumours about APT41 that it was also a part of the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department. Owning to that fact, 2006 has seen 140+ organisations’ security getting compromised, ranging from 20 strategically crucial companies.APT is also recognised for rationally plundering hundreds of terabytes of data from at least 141 organisations between 2006 and 2013. It typically begins with spear-phishing emails to the targeted victims. These sent emails contain official templates along with language pretending to be from a legitimate real source, carrying a malicious attachment. As the victim opens the attached file, the backdoor bestows the control of the targeted machine to the APT groups machine. Once there is an unauthorised gain of access, the attacker visits and revisits the victim’s machine. The group remains dormant for lengthy durations, more likely for months or even for years.
Advisory points need to adhere to while using Android devices
- The security patch update is necessary at least once a week
- Clearing up unwanted junk files.
- Cache files of every frequently used application need to clear out.
- Install only required applications from
Google play store. - Download only necessary APK files only it comes from trusted resources.
- Before giving device permission, it is advisable to run your files or URLs on VirusTotal.com this website will give a good closure to the malicious intent.
- Install good antivirus software.
- Individuals need to check the source of the email before opening an attachment to it.
- Never collect or add any randomly found device to your system
- Moreover, the user needs to keep track of their device activity. Rather than using devices just for entertainment purposes, it is more important to look for data protection on that device.
Conclusion
Network Crack Program Hacker Group (NCPH), which grew as an APT41 group with malicious intent, earlier performed the role of grey hat hacker, this group somehow grew up greedy to enhance more money laundering by hacking networks, devices, etc. As this group conducts a supply chain of attacks to gain unauthorised access to the network throughout the world, targeting hundreds of companies, including an extensive selection of industries such as social media, telecommunications, government, defence, education, and manufacturing. Last but not least, many more fraud-making groups with malicious intent will be forming and implementing in the future. It is on individuals and organisations to secure themselves but practise basic security levels to safeguard themselves against such threats and attacks.

Pretext
The Army Welfare Education Society has informed the Parents and students that a Scam is targeting the Army schools Students. The Scamster approaches the students by faking the voice of a female and a male. The scamster asks for the personal information and photos of the students by telling them they are taking details for the event, which is being organised by the Army welfare education society for the celebration of independence day. The Army welfare education society intimated that Parents to beware of these calls from scammers.
The students of Army Schools of Jammu & Kashmir, Noida, are getting calls from the scamster. The students were asked to share sensitive information. Students across the country are getting calls and WhatsApp messages from two numbers, which end with 1715 and 2167. The Scamster are posing to be teachers and asking for the students’ names on the pretext of adding them to the WhatsApp Groups. The scamster then sends forms links to the WhatsApp groups and asking students to fill out the form to seek more sensitive information.
Do’s
- Do Make sure to verify the caller.
- Do block the caller while finding it suspicious.
- Do be careful while sharing personal Information.
- Do inform the School Authorities while receiving these types of calls and messages posing to be teachers.
- Do Check the legitimacy of any agency and organisation while telling the details
- Do Record Calls asking for personal information.
- Do inform parents about scam calling.
- Do cross-check the caller and ask for crucial information.
- Do make others aware of the scam.
Don’ts
- Don’t answer anonymous calls or unknown calls from anyone.
- Don’t share personal information with anyone.
- Don’t Share OTP with anyone.
- Don’t open suspicious links.
- Don’t fill any forms, asking for personal information
- Don’t confirm your identity until you know the caller.
- Don’t Reply to messages asking for financial information.
- Don’t go to a fake website by following a prompt call.
- Don’t share bank Details and passwords.
- Don’t Make payment over a prompt fake call.

Introduction
Discussions took place focused on cybersecurity measures, specifically addressing cybercrime in the context of emerging technologies such as Non-Fungible Tokens (NFTs), Artificial Intelligence (AI), and the Metaverse. Session 5 of the conference focused on the interconnectedness between the darknet and cryptocurrency and the challenges it poses for law enforcement agencies and regulators. They discussed that Understanding AI is necessary for enterprises. AI models have difficulties, but we are looking forward to trustworthy AIs. and AI technology must be transparent.
Darknet and Cryptocurrency
The darknet refers to the hidden part of the internet where illicit activities have proliferated in recent years. It was initially developed to provide anonymity, privacy, and protection to specific individuals such as journalists, activists, and whistleblowers. However, it has now become a playground for criminal activities. Cryptocurrency, particularly Bitcoin, has been widely adopted on the darknet due to its anonymous nature, enabling anti-money laundering and unlawful transactions.
Three major points emerge from this relationship: the integrated nature of the darknet and cryptocurrency, the need for regulations to prevent darknet-based crimes, and the importance of striking a balance between privacy and security.
Key Challenges:
- Integrated Relations: The darknet and cryptocurrency have evolved independently, with different motives and purposes. It is crucial to understand the integrated relationship between them and how criminals exploit this connection.
- Regulatory Frameworks: There is a need for effective regulations to prevent crimes facilitated through the darknet and cryptocurrency while striking a balance between privacy and security.
- Privacy and Security: Privacy is a fundamental right, and any measures taken to enhance security should not infringe upon individual privacy. A multistakeholder approach involving tech companies and regulators is necessary to find this delicate balance.
Challenges Associated with Cryptocurrency Use:
The use of cryptocurrency on the darknet poses several challenges. The risks associated with darknet-based cryptocurrency crimes are a significant concern. Additionally, regulatory challenges arise due to the decentralised and borderless nature of cryptocurrencies. Mitigating these challenges requires innovative approaches utilising emerging technologies.
Preventing Misuse of Technologies:
The discussion emphasised that we can step ahead of the people who wish to use these beautiful technologies meant and developed for a different purpose, to prevent from using them for crime.
Monitoring the Darknet:
The darknet, as explained, is an elusive part of the internet that necessitates the use of a special browser for access. Initially designed for secure communication by the US government, its purpose has drastically changed over time. The darknet’s evolution has given rise to significant challenges for law enforcement agencies striving to monitor its activities.
Around 95% of the activities carried out on the dark net are associated with criminal acts. Estimates suggest that over 50% of the global cybercrime revenue originates from the dark net. This implies that approximately half of all cybercrimes are facilitated through the darknet.
The exploitation of the darknet has raised concerns regarding the need for effective regulation. Monitoring the darknet is crucial for law enforcement, national agencies, and cybersecurity companies. The challenges associated with the darknet’s exploitation and the criminal activities facilitated by cryptocurrency emphasise the pressing need for regulations to ensure a secure digital landscape.
Use of Cryptocurrency on the Darknet
Cryptocurrency plays a central role in the activities taking place on the darknet. The discussion highlighted its involvement in various illicit practices, including ransomware attacks, terrorist financing, extortion, theft, and the operation of darknet marketplaces. These applications leverage cryptocurrency’s anonymous features to enable illegal transactions and maintain anonymity.
AI's Role in De-Anonymizing the Darknet and Monitoring Challenges:
- 1.AI’s Potential in De-Anonymizing the Darknet
During the discussion, it was highlighted how AI could be utilised to help in de-anonymizing the darknet. AI’s pattern recognition capabilities can aid in identifying and analysing patterns of behaviour within the darknet, enabling law enforcement agencies and cybersecurity experts to gain insights into its operations. However, there are limitations to what AI can accomplish in this context. AI cannot break encryption or directly associate patterns with specific users, but it can assist in identifying illegal marketplaces and facilitating their takedown. The dynamic nature of the darknet, with new marketplaces quickly emerging, adds further complexity to monitoring efforts.
- 2.Challenges in Darknet Monitoring
Monitoring the darknet poses various challenges due to its vast amount of data, anonymous and encrypted nature, dynamically evolving landscape, and the need for specialised access. These challenges make it difficult for law enforcement agencies and cybersecurity professionals to effectively track and prevent illicit activities.
- 3.Possible Ways Forward
To address the challenges, several potential avenues were discussed. Ethical considerations, striking a balance between privacy and security, must be taken into account. Cross-border collaboration, involving the development of relevant laws and policies, can enhance efforts to combat darknet-related crimes. Additionally, education and awareness initiatives, driven by collaboration among law enforcement, government entities, and academia, can play a crucial role in combating darknet activities.
The panel also addressed the questions from the audience
- How law enforcement agencies and regulators can use AI to detect and prevent crimes on the darknet and cryptocurrency? The panel answered that- Law enforcement officers should also be AI and technology ready, and that kind of upskilling program should be there in place.
- How should lawyers and the judiciary understand the problem and regulate it? The panel answered that AI should only be applied by looking at the outcomes. And Law has to be clear as to what is acceptable and what is not.
- Aligning AI with human intention? Whether it’s possible? Whether can we create an ethical AI instead of talking about using AI ethically? The panel answered that we have to understand how to behave ethically. AI can beat any human. We have to learn AI. Step one is to focus on our ethical behaviour. And step two is bringing the ethical aspect to the software and technologies. Aligning AI with human intention and creating ethical AI is a challenge. The focus should be on ethical behaviour both in humans and in the development of AI technologies.
Conclusion
The G20 Conference on Crime and Security shed light on the intertwined relationship between the darknet and cryptocurrency and the challenges it presents to cybersecurity. The discussions emphasised the need for effective regulations, privacy-security balance, AI integration, and cross-border collaboration to tackle the rising cybercrime activities associated with the darknet and cryptocurrency. Addressing these challenges will require the combined efforts of governments, law enforcement agencies, technology companies, and individuals committed to building a safer digital landscape.

Introduction
According to a shocking report, there are multiple scam loan apps on the App Store in India that charge excessive interest rates and force users to pay by blackmailing and harassing them. Apple has prohibited and removed these apps from the App Store, but they may still be installed on your iPhone and running. You must delete any of these apps if you have downloaded them. Learn the names of these apps and how they operated the fraud.
Why Apple banned these apps?
- Apple has taken action to remove certain apps from the Indian App Store. These apps were engaging in unethical behaviour, such as impersonating financial institutions, demanding high fees, and threatening borrowers. Here are the titles of these apps, as well as what Apple has said about their suspension.
- Following user concerns, Apple removed six loan apps from the Indian App Store. Loan apps include White Kash, Pocket Kash, Golden Kash, Ok Rupee, and others.
- According to multiple user reviews, certain apps seek unjustified access to users’ contact lists and media. These apps also charge exorbitant fees that are not necessitated. Furthermore, companies have been found to engage in unethical tactics such as charging high-interest rates and “processing fees” equal to half the loan amount.
- Some lending app users have reported being harassed and threatened for failing to return their loans on time. In some circumstances, the apps threatened the user’s contacts if payment was not completed by the deadline. According to one user, the app company threatened to produce and send false photographs of her to her contacts.
- These loan apps were removed from the App Store, according to Apple, because they broke the norms and standards of the Apple Developer Program License Agreement. These apps were discovered to be falsely claiming financial institution connections.
Issue of Fake loan apps on the App Store
- The App Store and our App Review Guidelines are designed to ensure we provide our users with the safest experience possible,” Apple explained. “We do not tolerate fraudulent activity on the App Store and have strict rules against apps and developers who attempt to game the system.
- In 2022, Apple blocked nearly $2 billion in fraudulent App Store sales. Furthermore, it rejected nearly 1.7 million software submissions that did not match Apple’s quality and safety criteria and cancelled 428,000 developer accounts due to suspected fraudulent activities.
- The scammers also used heinous tactics to force the loanees to pay. According to reports, the scammers behind the apps gained access to the user’s contact list as well as their images. They would morph the images and then scare the individual by sharing their fake nude photos with their whole contact list.
Dangerous financial fraud apps have surfaced on the App Store
- TechCrunch acquired a user review from one of these apps. “I borrowed an amount in a helpless situation, and a day before the repayment due date, I got some messages with my picture and my contacts in my phone saying that repay your loan or they will inform our contacts that you are not paying the loan,” it said.
- Sandhya Ramesh, a journalist from The Print, recently tweeted a screenshot of a direct message she got. A victim’s friend told a similar story in the message.
- TechCrunch contacted Apple, who confirmed that the apps had been removed from the App Store for breaking the Apple Developer Program License Agreement and guidelines.
Conclusion
Recently, some users have claimed that some quick-loan applications, such as White Kash, Pocket Kash, and Golden Kash, have appeared on the Top Finance applications chart in recent days. These apps necessitate unauthorised and intrusive access to users’ contact lists and media. According to hundreds of user evaluations, these apps charged exorbitantly high and useless fees. They used unscrupulous techniques such as demanding “processing fees” equal to half the loan amount and charging high-interest rates. Users were also harassed and threatened with restitution. If payments were not made by the due date, the lending applications threatened to notify users’ contacts. According to one user, the app provider even threatened to generate phoney nude images of her and send them to her contacts.

Introduction
In a distressing incident that highlights the growing threat of cyber fraud, a software engineer in Bangalore fell victim to fraudsters who posed as police officials. These miscreants, operating under the guise of a fake courier service and law enforcement, employed a sophisticated scam to dupe unsuspecting individuals out of their hard-earned money. Unfortunately, this is not an isolated incident, as several cases of similar fraud have been reported recently in Bangalore and other cities. It is crucial for everyone to be aware of these scams and adopt preventive measures to protect themselves.
Bangalore Techie Falls Victim to ₹33 Lakh
The software engineer received a call from someone claiming to be from FedEx courier service, informing him that a parcel sent in his name to Taiwan had been seized by the Mumbai police for containing illegal items. The call was then transferred to an impersonator posing as a Mumbai Deputy Commissioner of Police (DCP), who alleged that a money laundering case had been registered against him. The fraudsters then coerced him into joining a Skype call for verification purposes, during which they obtained his personal details, including bank account information.
Under the guise of verifying his credentials, the fraudsters manipulated him into transferring a significant amount of money to various accounts. They assured him that the funds would be returned after the completion of the procedure. However, once the money was transferred, the fraudsters disappeared, leaving the victim devastated and financially drained.
Best Practices to Stay Safe
- Be vigilant and skeptical: Maintain a healthy level of skepticism when receiving unsolicited calls or messages, especially if they involve sensitive information or financial matters. Be cautious of callers pressuring you to disclose personal details or engage in immediate financial transactions.
- Verify the caller’s authenticity: If someone claims to represent a legitimate organisation or law enforcement agency, independently verify their credentials. Look up the official contact details of the organization or agency and reach out to them directly to confirm the authenticity of the communication.
- Never share sensitive information: Avoid sharing personal information, such as bank account details, passwords, or Aadhaar numbers, over the phone or through unfamiliar online platforms. Legitimate organizations will not ask for such information without proper authentication protocols.
- Use secure communication channels: When communicating sensitive information, prefer secure platforms or official channels that provide end-to-end encryption. Avoid switching to alternative platforms or applications suggested by unknown callers, as fraudsters can exploit these.
- Educate yourself and others: Stay informed about the latest cyber fraud techniques and scams prevalent in your region. Share this knowledge with family, friends, and colleagues to create awareness and prevent them from falling victim to similar schemes.
- Implement robust security measures: Keep your devices and software updated with the latest security patches. Utilize robust anti-virus software, firewalls, and spam filters to safeguard against malicious activities. Regularly review your financial statements and account activity to detect any unauthorized transactions promptly.
Conclusion:
The incident involving the Bangalore techie and other victims of cyber fraud highlights the importance of remaining vigilant and adopting preventive measures to safeguard oneself from such scams. It is disheartening to see individuals falling prey to impersonators who exploit their trust and manipulate them into sharing sensitive information. By staying informed, exercising caution, and following best practices, we can collectively minimize the risk and protect ourselves from these fraudulent activities. Remember, the best defense against cyber fraud is a well-informed and alert individual.

Introduction
Deepfakes are artificial intelligence (AI) technology that employs deep learning to generate realistic-looking but phoney films or images. Algorithms use large volumes of data to analyse and discover patterns in order to provide compelling and realistic results. Deepfakes use this technology to modify movies or photos to make them appear as if they involve events or persons that never happened or existed.The procedure begins with gathering large volumes of visual and auditory data about the target individual, which is usually obtained from publicly accessible sources such as social media or public appearances. This data is then utilised for training a deep-learning model to resemble the target of deep fakes.
Recent Cases of Deepfakes-
In an unusual turn of events, a man from northern China became the victim of a sophisticated deep fake technology. This incident has heightened concerns about using artificial intelligence (AI) tools to aid financial crimes, putting authorities and the general public on high alert.
During a video conversation, a scammer successfully impersonated the victim’s close friend using AI-powered face-swapping technology. The scammer duped the unwary victim into transferring 4.3 million yuan (nearly Rs 5 crore). The fraud occurred in Baotou, China.
AI ‘deep fakes’ of innocent images fuel spike in sextortion scams
Artificial intelligence-generated “deepfakes” are fuelling sextortion frauds like a dry brush in a raging wildfire. According to the FBI, the number of nationally reported sextortion instances came to 322% between February 2022 and February 2023, with a notable spike since April due to AI-doctored photographs. And as per the FBI, innocent photographs or videos posted on social media or sent in communications can be distorted into sexually explicit, AI-generated visuals that are “true-to-life” and practically hard to distinguish. According to the FBI, predators often located in other countries use doctored AI photographs against juveniles to compel money from them or their families or to obtain actual sexually graphic images.
Deepfake Applications
- Lensa AI.
- Deepfakes Web.
- Reface.
- MyHeritage.
- DeepFaceLab.
- Deep Art.
- Face Swap Live.
- FaceApp.
Deepfake examples
There are numerous high-profile Deepfake examples available. Deepfake films include one released by actor Jordan Peele, who used actual footage of Barack Obama and his own imitation of Obama to convey a warning about Deepfake videos.
A video shows Facebook CEO Mark Zuckerberg discussing how Facebook ‘controls the future’ with stolen user data, most notably on Instagram. The original video is from a speech he delivered on Russian election meddling; only 21 seconds of that address were used to create the new version. However, the vocal impersonation fell short of Jordan Peele’s Obama and revealed the truth.
The dark side of AI-Generated Misinformation
- Misinformation generated by AI-generated the truth, making it difficult to distinguish fact from fiction.
- People can unmask AI content by looking for discrepancies and lacking the human touch.
- AI content detection technologies can detect and neutralise disinformation, preventing it from spreading.
Safeguards against Deepfakes-
Technology is not the only way to guard against Deepfake videos. Good fundamental security methods are incredibly effective for combating Deepfake.For example, incorporating automatic checks into any mechanism for disbursing payments might have prevented numerous Deepfake and related frauds. You might also:
- Regular backups safeguard your data from ransomware and allow you to restore damaged data.
- Using different, strong passwords for different accounts ensures that just because one network or service has been compromised, it does not imply that others have been compromised as well. You do not want someone to be able to access your other accounts if they get into your Facebook account.
- To secure your home network, laptop, and smartphone against cyber dangers, use a good security package such as Kaspersky Total Security. This bundle includes anti-virus software, a VPN to prevent compromised Wi-Fi connections, and webcam security.
What is the future of Deepfake –
Deepfake is constantly growing. Deepfake films were easy to spot two years ago because of the clumsy movement and the fact that the simulated figure never looked to blink. However, the most recent generation of bogus videos has evolved and adapted.
There are currently approximately 15,000 Deepfake videos available online. Some are just for fun, while others attempt to sway your opinion. But now that it only takes a day or two to make a new Deepfake, that number could rise rapidly.
Conclusion-
The distinction between authentic and fake content will undoubtedly become more challenging to identify as technology advances. As a result, experts feel it should not be up to individuals to discover deep fakes in the wild. “The responsibility should be on the developers, toolmakers, and tech companies to create invisible watermarks and signal what the source of that image is,” they stated. Several startups are also working on approaches for detecting deep fakes.

Introduction
In recent years, the city of Hyderabad/Cyberabad has emerged as a technology hub, a place with the strong presence of multi corporations, Startups, and research institutions, Hyderabad has become a hub of innovations and technological advancement. However, this growing land of cyber opportunities has also become a hub for cybercriminals as well. In this blog post, we shall explore the reasons why professionals are being targeted and the effects of cyber fraud on techies. Through this investigation, we hope to raise awareness about the seriousness of the problem as well as give vital insights and techniques for Cyberabad’s computer workers to defend themselves against cyber theft. We can work together to make Cyberabad’s technology ecosystem safer and more secure.
Defining Cyber Fraud
In today’s age, where everything has an interconnected digital world, cyber fraud cases are increasing daily. Cyber fraud encompasses a wide range of threats and techniques employed by bad actors, such as Phishing, Ransomware, identity theft, online scams, data breaches, and fake websites designed for users. The sophistication of cyber fraud techniques is constantly evolving, making it challenging for individuals and organisations to stay ahead. Cybercriminals use software vulnerabilities, social engineering tactics, and flaws in cybersecurity defences to carry out their harmful operations. Individuals and organisations must grasp these dangers and tactics to protect themselves against cyber fraud.
Impact of Cyber Frauds
The consequences of Falling victim to cyber fraud can be devastating, both personally and professionally. The emotional and financial toll on individuals may be a challenge. Identity theft may lead to damaged credit scores, fraudulent transactions, and years of recovery work to rehabilitate one’s image. Financial fraud can result in depleted bank accounts, unauthorised charges, and substantial monetary losses. Furthermore, being tricked and violated in the digital environment can generate anxiety, tension, and a lack of confidence.
The impact of cyber fraud goes beyond immediate financial losses and can have long-term consequences for individuals’ and organisations’ entire well-being and stability. As the threat environment evolves, it is critical for people and organisations to recognise the gravity of these repercussions and take proactive actions to protect themselves against cyber theft.

Why are Cyberabad Tech Professionals Targeted?
Tech professionals in Cyberabad are particularly vulnerable to cyber due to various factors. Firstly, their expertise and knowledge in technology make them attractive targets for cybercrooks. These professionals possess valuable coding, Software, and administration skills, making them attractive to cybercriminals.
Secondly, the nature of work often involves enormous use of technology, including regular internet contacts, email exchanges, and access to private information. This expanded digital presence exposes them to possible cyber dangers and makes them more vulnerable to fraudsters’ social engineering efforts. Furthermore, the fast-moving nature of the tech industry, with many deadlines and work pressure to deliver, can create a distraction. This can let them click on some malicious links or share sensitive information unknowingly all these factors let the cyber criminals exploit vulnerabilities.
Unveiling the Statistics
According to various reports, 80% of cyber fraud victims in Hyderabad are techies; the rest are the public targeted by cyber crooks. This surprising number emphasises the critical need to address the vulnerabilities and threats this specific segment within the IT community faces.
Going further into the data, we can acquire insights into the many forms of cyber fraud targeting tech workers, the strategies used by cybercriminals, and the impact these occurrences have on individuals and organisations. Examining precise features and patterns within data might give important information for developing successful preventative and protection methods.
Factors Contributing
Several reasons contribute to the elevated risk of cyber fraud among ICT professionals in Cyberabad. Understanding these aspects helps explain why this group is specifically targeted and may be more vulnerable to such assaults.
Technical Expertise: Tech workers frequently have specialised technical knowledge, but this knowledge may only sometimes extend to cybersecurity. Their primary concentration is writing software, designing systems, or implementing technologies, which may result in missing possible vulnerabilities or a lack of overall cybersecurity understanding.
Confidence in Technology: IT workers have a higher level of confidence in technology because of their knowledge and dependence on technology. This trust can sometimes make individuals more vulnerable to sophisticated frauds or social engineering approaches that prey on their faith in the services they utilise.
Time Constraints and Pressure: Tech workers frequently operate under tight deadlines and tremendous pressure to reach project milestones. This may result in hurried decision-making or disregarding possible warning signals of cyber fraud, rendering them more exposed to assaults that prey on time-sensitive circumstances.
Cybercriminals know that technology workers have valuable knowledge, trade secrets, and intellectual property that may be economically profitable. As a result, they are attractive targets for attacks aiming at stealing sensitive data or gaining unauthorised access to critical systems.
The best practices that cyber techies can apply to safeguard their personal and professional data by following these simple tips:
Strong Passwords: create a strong password, using passwords for all your online accounts and changing them regularly. Remember to use unique combinations!
MFA (Multi-Factor Authentication): Enable MFA wherever possible. This provides an extra degree of protection by requiring a second form of verification, such as a code texted to your mobile device and your password.
Use Secured WiFi: Use secure and encrypted Wi-Fi networks, especially while viewing sensitive information. Avoid connecting to public or unprotected networks, as they can be readily exploited. Recognising Red Flags and Staying Ahead
Social Engineering: Be sceptical of unwanted solicitations or offers, both online and offline. Cybercriminals may try to persuade or fool you using social engineering tactics. Before revealing any personal or private information, think critically and confirm the veracity of the request.
Secure Web Browsing: Only browse trustworthy websites with valid SSL certificates (look for “https://” in the URL). Avoid clicking on strange links or downloading files from unknown sources since they may contain malware or ransomware.
Report Suspicious actions: If you encounter any suspicious or fraudulent actions, report them to the relevant authorities, such as the Cyber Crime Police or your organisation’s IT department. Reporting events can assist in avoiding additional harm and aid in identifying and apprehending hackers.
Stay Current on Security Practises: Stay up to speed on the newest cybersecurity risks and best practices. Follow credible sources, participate in cybersecurity forums or seminars, and remain current on new threats and preventative measures.

Conclusion
The rise in cybercrimes and fraud cases among tech experts in Cyberabad is a disturbing trend that requires prompt intervention. We can establish a safer tech cluster that lives on creativity, trust, and resilience by adopting proactive actions, raising awareness, and encouraging cooperation. Let us work together to prevent cybercrime and ensure the future of Cyberabad’s IT ecosystem.

Introduction
The information of hundreds of thousands of Indians who received the COVID vaccine was Leaked in a significant data breach and posted on a Telegram channel. Numerous reports claim that sensitive information, including a person’s phone number, gender, ID card details, and date of birth, leaked over Telegram. It could be obtained by typing a person’s name into a Telegram bot.
What really happened?
The records pertaining to the mobile number registered in the CoWin portal are accessible on the Malayalam news website channel. It is also feasible to determine which vaccination was given and where it was given.
According to The Report, the list of individuals whose data was exposed includes BJP Tamil Nadu president K Annamalai, Congress MP Karti Chidambaram, and former BJP union minister for health Harsh Vardhan. Telangana’s minister of information and communication technology, Kalvakuntla Taraka Rama Rao, is also on the list.
MEITY stated in response to the data leak, “It is old data, we are still confirming it. We have requested a report on the matter.
After the media Report, the bot was disabled, but experts said the incident raised severe issues because the information might be used for identity theft, phishing emails, con games, and extortion calls. The Indian Computer Emergency Response Team (CERT-In), the government’s nodal body, has opened an investigation into the situation
The central government declared the data breach reports regarding the repository of beneficiaries against Covid to be “mischievous in nature” on Monday and claimed the ‘bot’ that purportedly accessed the confidential data was not directly accessing the CoWIN database.
According to the first complaint by CERT-In, the government’s cybersecurity division, the government claimed the bot might be displaying information from “previously stolen data.” Reports.
The health ministry refuted the claim, asserting that no bots could access the information without first verifying with a one-time password.
“It is made clear that all of these rumours are false and malicious. The health ministry’s CoWIN interface is entirely secure and has sufficient data privacy protections. The security of the data on the CoWIN portal is being ensured in every way possible, according to a statement from the health ministry.
Meity said the CoWin program or database was not directly compromised, and the shared information appeared to be taken from a previous intrusion. But the hack again highlights the growing danger of cyber assaults, particularly on official websites.

Recent cases of data leak
Dominos India 2021– Dominos India, a division of Jubilant FoodWorks, faced a cyberattack on May 22, 2021, which led to the disclosure of information from 180 million orders. The breach exposed order information, email addresses, phone numbers, and credit card information. Although Jubilant FoodWorks acknowledged a security breach, it refuted any illegal access to financial data.
Air India – A cyberattack that affected Air India in May 2021 exposed the personal information of about 4.5 million customers globally. Personal information recorded between August 26, 2011, and February 3, 2021, including names, dates of birth, contact information, passport information, ticket details, frequent flyer information from Star Alliance and Air India, and credit card information, were exposed in the breach.
Bigbasket – BigBasket, an online supermarket, had a data breach in November 2020, compromising the personal information of approximately 20 million consumers. Email IDs, password hashes, PINs, phone numbers, addresses, dates of birth, localities, and IP addresses were among the information released from an insecure database containing over 15 GB of customer data. BigBasket admitted to the incident and reported it to the Bengaluru Cyber Crime Department.
Unacademy – Unacademy, an online learning platform, experienced a data breach in May 2020, compromising the email addresses of approximately 11 million subscribers. While no sensitive information, such as financial data or passwords, was compromised, user data, including IDs, passwords, date joined, last login date, email IDs, names, and user credentials, was. The breach was detected when user accounts were uncovered for sale on the dark web.
2022 Card Data- Cybersecurity researchers from AI-driven Singapore-based CloudSEK found a threat actor offering a database of 1.2 million cards for free on a Dark Web forum for crimes on October 12, 2022. This came after a second problem involving 7.9 million cardholder records that were reported on the BidenCash website. This comprised information pertaining to State Bank of India (SBI) clients. And other well-known companies were among those targeted in high-profile data breach cases that have surfaced in recent years.

Conclusion
Data breach cases are increasing daily, and attackers are mainly attacking the healthcare sectors and health details as they can easily find personal details. This recent CoWIN case has compromised thousands of people’s data. The All-India Institute of Medical Sciences’ systems were compromised by hackers a few months ago. Over 95% of adults have had their vaccinations, according to the most recent data, even if the precise number of persons impacted by the CoWin privacy breach could not be determined.

Introduction
The advent of AI-driven deepfake technology has facilitated the creation of explicit counterfeit videos for sextortion purposes. There has been an alarming increase in the use of Artificial Intelligence to create fake explicit images or videos for sextortion.
What is AI Sextortion and Deepfake Technology
AI sextortion refers to the use of artificial intelligence (AI) technology, particularly deepfake algorithms, to create counterfeit explicit videos or images for the purpose of harassing, extorting, or blackmailing individuals. Deepfake technology utilises AI algorithms to manipulate or replace faces and bodies in videos, making them appear realistic and often indistinguishable from genuine footage. This enables malicious actors to create explicit content that falsely portrays individuals engaging in sexual activities, even if they never participated in such actions.
Background on the Alarming Increase in AI Sextortion Cases
Recently there has been a significant increase in AI sextortion cases. Advancements in AI and deepfake technology have made it easier for perpetrators to create highly convincing fake explicit videos or images. The algorithms behind these technologies have become more sophisticated, allowing for more seamless and realistic manipulations. And the accessibility of AI tools and resources has increased, with open-source software and cloud-based services readily available to anyone. This accessibility has lowered the barrier to entry, enabling individuals with malicious intent to exploit these technologies for sextortion purposes.

The proliferation of sharing content on social media
The proliferation of social media platforms and the widespread sharing of personal content online have provided perpetrators with a vast pool of potential victims’ images and videos. By utilising these readily available resources, perpetrators can create deepfake explicit content that closely resembles the victims, increasing the likelihood of success in their extortion schemes.
Furthermore, the anonymity and wide reach of the internet and social media platforms allow perpetrators to distribute manipulated content quickly and easily. They can target individuals specifically or upload the content to public forums and pornographic websites, amplifying the impact and humiliation experienced by victims.
What are law agencies doing?
The alarming increase in AI sextortion cases has prompted concern among law enforcement agencies, advocacy groups, and technology companies. This is high time to make strong Efforts to raise awareness about the risks of AI sextortion, develop detection and prevention tools, and strengthen legal frameworks to address these emerging threats to individuals’ privacy, safety, and well-being.
There is a need for Technological Solutions, which develops and deploys advanced AI-based detection tools to identify and flag AI-generated deepfake content on platforms and services. And collaboration with technology companies to integrate such solutions.
Collaboration with Social Media Platforms is also needed. Social media platforms and technology companies can reframe and enforce community guidelines and policies against disseminating AI-generated explicit content. And can ensure foster cooperation in developing robust content moderation systems and reporting mechanisms.
There is a need to strengthen the legal frameworks to address AI sextortion, including laws that specifically criminalise the creation, distribution, and possession of AI-generated explicit content. Ensure adequate penalties for offenders and provisions for cross-border cooperation.
Proactive measures to combat AI-driven sextortion
Prevention and Awareness: Proactive measures raise awareness about AI sextortion, helping individuals recognise risks and take precautions.
Early Detection and Reporting: Proactive measures employ advanced detection tools to identify AI-generated deepfake content early, enabling prompt intervention and support for victims.
Legal Frameworks and Regulations: Proactive measures strengthen legal frameworks to criminalise AI sextortion, facilitate cross-border cooperation, and impose offender penalties.
Technological Solutions: Proactive measures focus on developing tools and algorithms to detect and remove AI-generated explicit content, making it harder for perpetrators to carry out their schemes.
International Cooperation: Proactive measures foster collaboration among law enforcement agencies, governments, and technology companies to combat AI sextortion globally.
Support for Victims: Proactive measures provide comprehensive support services, including counselling and legal assistance, to help victims recover from emotional and psychological trauma.
Implementing these proactive measures will help create a safer digital environment for all.

Misuse of Technology
Misusing technology, particularly AI-driven deepfake technology, in the context of sextortion raises serious concerns.
Exploitation of Personal Data: Perpetrators exploit personal data and images available online, such as social media posts or captured video chats, to create AI- manipulation violates privacy rights and exploits the vulnerability of individuals who trust that their personal information will be used responsibly.
Facilitation of Extortion: AI sextortion often involves perpetrators demanding monetary payments, sexually themed images or videos, or other favours under the threat of releasing manipulated content to the public or to the victims’ friends and family. The realistic nature of deepfake technology increases the effectiveness of these extortion attempts, placing victims under significant emotional and financial pressure.
Amplification of Harm: Perpetrators use deepfake technology to create explicit videos or images that appear realistic, thereby increasing the potential for humiliation, harassment, and psychological trauma suffered by victims. The wide distribution of such content on social media platforms and pornographic websites can perpetuate victimisation and cause lasting damage to their reputation and well-being.
Targeting teenagers– Targeting teenagers and extortion demands in AI sextortion cases is a particularly alarming aspect of this issue. Teenagers are particularly vulnerable to AI sextortion due to their increased use of social media platforms for sharing personal information and images. Perpetrators exploit to manipulate and coerce them.
Erosion of Trust: Misusing AI-driven deepfake technology erodes trust in digital media and online interactions. As deepfake content becomes more convincing, it becomes increasingly challenging to distinguish between real and manipulated videos or images.
Proliferation of Pornographic Content: The misuse of AI technology in sextortion contributes to the proliferation of non-consensual pornography (also known as “revenge porn”) and the availability of explicit content featuring unsuspecting individuals. This perpetuates a culture of objectification, exploitation, and non-consensual sharing of intimate material.
Conclusion
Addressing the concern of AI sextortion requires a multi-faceted approach, including technological advancements in detection and prevention, legal frameworks to hold offenders accountable, awareness about the risks, and collaboration between technology companies, law enforcement agencies, and advocacy groups to combat this emerging threat and protect the well-being of individuals online.

Introduction
In an alarming event, one of India’s premier healthcare institutes, AIIMS Delhi, has fallen victim to a malicious cyberattack for the second time in the year. The Incident serves as a clear-cut reminder of the escalating threat landscape faced by the healthcare organisation in this digital age. In the attack, which unfolded with grave implications, the attackers not only explored the vulnerabilities present in the healthcare sector, but this also raised the concern about the security of patient data and the uninterrupted delivery of critical healthcare services. In this blog post, we will explore the incident, what happened, and what safety measures can be taken.
Backdrop
The cyber-security systems deployed in AIIMS, New Delhi, recently detected a malware attack. The nature and scope of the attack were both sophisticated and targeted. This second hack acts as a wake-up call for healthcare organisations nationwide. As the healthcare business increasingly depends on digital technology to improve patient care and operational efficiency, cybersecurity must be prioritised to protect sensitive data. To minimise cyber-attack dangers, healthcare organisations must invest in robust defences such as multi-factor authentication, network security, frequent system upgrades, and employee training.
The attempt was successfully prevented, and the deployed cyber-security systems neutralised the threat. The e-Hospital services remain to be fully secure and are functioning normally.
Impact on AIIMS
Healthcare services have been under hackers’ radar worldwide, and the healthcare sector has been impacted badly. The attack on AIIMS Delhi’s effects has been both immediate and far-reaching. The organisation, which is recognised for delivering excellent healthcare services and performing breakthrough medical research, faced significant interruptions in its everyday operations. Patient care and treatment processes were considerably impeded, resulting in delays, cancellations, and the inability to access essential medical documents. The stolen data raises serious concerns about patient privacy and confidentiality, raising doubts about the institution’s capacity to protect sensitive information. Furthermore, the financial ramifications of the assault, such as the cost of recovery, deploying more robust cybersecurity measures, and potential legal penalties and forensic analyses, contribute to the scale of the effect. The event has also generated public concerns about the institution’s ability to preserve personal information, undermining confidence and degrading AIIMS Delhi’s image.
Impact on Patients: The attacks not only impact the institutes but also have serious implications for the patients and here are some key highlights:
Healthcare Service Disruption: The hack has affected the seamless delivery of healthcare services at AIIMS Delhi. Appointments, surgeries, and other medical treatments may be delayed, cancelled, or rescheduled. This disturbance can result in longer wait times, longer treatment periods, and potential problems from delayed or interrupted therapy.

Patient Privacy and Confidentiality are jeopardised because of the breach of sensitive patient data. Medical data, test findings, and treatment plans may have been compromised. This breach may diminish patient faith in the institution’s capacity to safeguard their personal information, discouraging them from seeking care or submitting sensitive information in the future.
As a result of the cyberattack, patients may endure mental anguish and worry. Fear of possible exploitation of personal health information, confusion about the scope of the breach, and concerns about the security of their healthcare data can all have a negative impact on their mental health. This stress might aggravate pre-existing medical issues and impede total recovery.
Trust at stake: A data breach may harm patients’ faith and confidence in AIIMS Delhi and the healthcare system. Patients rely on healthcare facilities to keep their information secure and confidential while providing safe, high-quality care. A hack can doubt the institution’s ability to safeguard patient data, affecting patients’ overall faith in the organisation and potentially leading to patients seeking care elsewhere.
Cybersecurity Measures
To avoid future hacks and protect patient data, AIIMS Delhi must prioritize enhancing its cybersecurity procedures. The institution can strengthen its resistance to changing threats by establishing strong security practices. The following steps can be considered.
Using Multi-factor Authentication: By forcing users to submit several forms of identity to access systems and data, multi-factor authentication offers an extra layer of protection. AIIMS Delhi may considerably lower the danger of unauthorised access by applying this precaution, even in the case of leaked passwords or credentials. Biometrics and one-time passwords, for example, should be integrated into the institution’s authentication systems.
Improving Network Security and Firewalls: AIIMS Delhi should improve network security by implementing strong firewalls, intrusion detection and prevention systems, and network segmentation. These techniques serve to construct barriers between internal systems and external threats, reducing attackers’ lateral movement within the network. Regular network traffic monitoring and analysis can assist in recognising and mitigating any security breaches.
Risk Assessment: Regular penetration testing and vulnerability assessments are required to uncover possible flaws and vulnerabilities in AIIMS Delhi’s systems and infrastructure. Security professionals can detect vulnerabilities and offer remedial solutions by carrying out controlled simulated assaults. This proactive strategy assists in identifying and addressing any security flaws before attackers exploit them.
Educating and training Healthcare Professionals: Education and training have a crucial role in enhancing cybersecurity practices in healthcare facilities. Healthcare workers, including physicians, nurses, administrators, and support staff, must be well-informed about the importance of cybersecurity and trained in risk-mitigation best practices. This will empower healthcare professionals to actively contribute to protecting the patient’s data and maintaining the trust and confidence of patients.
Learnings from Incidents
AIIMS Delhi should embrace cyber-attacks as learning opportunities to strengthen its security posture. Following each event, a detailed post-incident study should be performed to identify areas for improvement, update security policies and procedures, and improve employee training programs. This iterative strategy contributes to the institution’s overall resilience and preparation for future cyber-attacks. AIIMS Delhi can effectively respond to cyber incidents, minimise the impact on operations, and protect patient data by establishing an effective incident response and recovery plan, implementing data backup and recovery mechanisms, conducting forensic analysis, and promoting open communication. Proactive measures, constant review, and regular revisions to incident response plans are critical for staying ahead of developing cyber threats and ensuring the institution’s resilience in the face of potential future assaults.

Conclusion
To summarise, developing robust healthcare systems in the digital era is a key challenge that healthcare organisations must prioritise. Healthcare organisations can secure patient data, assure the continuation of key services, and maintain patients’ trust and confidence by adopting comprehensive cybersecurity measures, building incident response plans, training healthcare personnel, and cultivating a security culture. Adopting a proactive and holistic strategy for cybersecurity is critical to developing a healthcare system capable of withstanding and successfully responding to digital-age problems.

Introduction
The two-day Apple’s Worldwide Developer Conference (WWDC) 2023, which was held on the 6th & 7th of June, has become an essential and highly anticipated part of our calendar as frequently as the trend. This year’s keynote announcements will include all of the usual enhancements for iOS, iPadOS, watchOS, macOS, and more. However, this year is also unique due to the unveiling of the Vision Pro headset, a brand-new Apple product.
In this blog, we will examine the exciting announcements made at Apple WWDC 2023, which was a ground-breaking event.
macOS Sonoma
macOS Sonoma, the new presentation of macOS disclosed at the WWDC full of exciting features. It comes with stunning video screensavers that show stunning scenes from all over the world. Gadgets can now be added genuinely to the work area and adjusted totally based on the client’s action. Also, it changes variety and blurring out of the spotlight while utilising applications. In addition, Death Stranding: Directors Cut for Mac announced that the Game Mode is added to make Macs more suitable for gaming. A presenter overlay enhances video presentations, and viewers can respond to them with interactive responses. Updated Safari is also included in the WebApp feature that turns frequently used websites into dedicated windows, a new Profile system for separating browsing history, and secure password sharing. Currently, the developer beta is available and the public beta will be available in July, and the final release is anticipated for the fall.
ios 16
Apple WWDC 2023 shows the following iOS, and iOS 16 replication, offering plenty of energising highlights for iPhone and iPad clients. Apple maintains its commitment to privacy with iOS 16, which introduces enhanced privacy settings that give users even more control over their data and online privacy. Users can also personalise their devices according to their preferences thanks to the new operating system’s refinement and customisable user interface.Improved multitasking capabilities like redesigned Files app and advanced note-taking features are just a few of the productivity enhancements included in the iOS 16. With iOS 16, Apple also improves its AR capabilities, allowing developers to develop even more immersive and interactive AR experiences.

WatchOS 9
Apple WWDC 2023 carried energising updates to the Apple Watch with the presentation of watchOS 9. The Apple Watch is an essential companion for sustaining a healthy lifestyle because the most recent version of the operating system includes cutting-edge health and fitness features. WatchOS 9 gives users unprecedented control over their health, offering personalised fitness recommendations and advanced sleep tracking.
Additionally, new watch faces were added, enhancing communication capabilities and improving app performance in watchOS 9, making the Apple Watch even easier to use daily.
ios 17
Rather than focusing on major features, Apple focused on quality-of-life enhancements when it announced iOS 17 at WWDC 2023. Live Voicemail with real-time transcripts of voicemails, personalised personal contact “posters,” and video voicemails for FaceTime are all part of the update. Search filters, a catch-up arrow, live location sharing, and a safety feature called Check-In are all available in Messages. AirDrop now supports NameDrop for transferring contact information; stickers have been expanded. The autocorrect and recording features on the keyboard have been improved for accuracy. Standby in the lock screen is an intelligent home display that shows the weather, upcoming appointments, and notifications. Siri works on Standby and adjusts itself for the night. The developer beta is currently available now, and a public beta will take place next month before the full release is in the fall.
Vision Pro VR Headset
Apple unveiled the Vision Pro AR headset, their first foray into virtual reality (VR), during the WWDC keynote. The Vision Pro is a virtual reality headset that competes with PlayStation VR2 and Meta Quest 3. This is in contrast to the long-awaited Apple smart glasses. Apple put a lot of effort into making a thin and light headset by using premium materials when needed. Voice, hand, and eye commands are all used to operate the Digital Crown-equipped device. The showcases offer extraordinary clarity, which is fueled by Apple’s M2 processor with a committed R1 chip. The Vision Pro combines virtual reality (VR) and augmented reality (AR), enabling users to interact with Apple apps and gain access to the company’s existing ecosystem. The expanded reality space created by the headset’s sensors and cameras allows users to place apps in real-world environments and adjust their level of concentration. Optic ID is a security and unlocking eye-tracking technology that is incorporated into the Vision Pro. It allows for a more immersive screen experience because it is compatible with Apple accessories like Magic Keyboard and Mac. At launch, the Vision Pro supports over a hundred Apple game galleries. Disney gave a hint that Apple and Disney might work together in the future by announcing support for the Vision Pro and making the Disney Plus app available immediately. The show highlighted the headset’s lightweight plan and recommended Apple clients wear it for extended periods. However, widespread adoption may be difficult due to the high price of $3,499 (₹289,093.01 approx). Apple is expected to release the Vision Pro for public use in 2024.

15-inch MacBook Air
At the WWDC event, Apple revealed a new MacBook Air with a larger 15-inch model instead of the standard 13-inch model. The 15-inch MacBook Air features a powerful Apple M2 processor, a thin, light, and long-lasting design, and a stunning 15.3-inch Retina display. It comes in four colours and has a headphone jack, two USB-C ports, and MagSafe charging. The display has six spatial speakers, a 1080p webcam, and 500 nits of brightness. Apple claims a battery life of up to 18 hours.
Conclusion
At Apple’s 2023 WWDC, the company demonstrated its commitment to developing technology that is user-friendly and accessible to all. Apple’s commitment to improving the user experience across all of its products is demonstrated in the updates to operating systems, improvements of Siri, breakthroughs in augmented reality, and enhancements to health and fitness.By making complex innovations more like-minded and easy to understand, Apple is enabling people to use the maximum capacity of their gadgets. Apple’s innovations at WWDC 2023 are expected to shape the future of technology, simplifying everyday tasks and revolutionising how we interact with the digital world.As we push ahead, it is exciting to guess what these advancements will proceed to develop and decidedly mean for our lives. The future holds even more incredible possibilities for all of us because of Apple’s focus on privacy, user-centric design, and pushing the boundaries of innovation. Thus, prepare to embrace a future where innovation flawlessly incorporates into our lives because of the endeavours displayed at Apple WWDC 2023.

Introduction
In recent years, India has witnessed a significant rise in the popularity and recognition of esports, which refers to online gaming. Esports has emerged as a mainstream phenomenon, influencing players and youngsters worldwide. In India, with the penetration of the internet at 52%, the youth has got its attracted to Esports. In this blog post, we will look at how the government is booting the players, establishing professional leagues, and supporting gaming companies and sponsors in the best possible manner. As the ecosystem continues to rise in prominence and establish itself as a mainstream sporting phenomenon in India.
Factors Shaping Esports in India: A few factors are shaping and growing the love for esports in India here. Let’s have a look.
Technological Advances: The availability and affordability of high-speed internet connections and smart gaming equipment have played an important part in making esports more accessible to a broader audience in India. With the development of smartphones and low-cost gaming PCs, many people may now easily participate in and watch esports tournaments.
Youth Demographic: India has a large population of young people who are enthusiastic gamers and tech-savvy. The youth demographic’s enthusiasm for gaming has spurred the expansion of esports in the country, as they actively participate in competitive gaming and watch major esports competitions.
Increase in the Gaming community: Gaming has been deeply established in Indian society, with many people using it for enjoyment and social contact. As the competitive component of gaming, esports has naturally gained popularity among gamers looking for a more competitive and immersive experience.
Esports Infrastructure and Events: The creation of specialised esports infrastructure, such as esports arenas, gaming cafés, and tournament venues, has considerably aided esports growth in India. Major national and international esports competitions and leagues have also been staged in India, offering exposure and possibilities for prospective esports players. Also supports various platforms such as YouTube, Twitch, and Facebook gaming, which has played a vital role in showcasing and popularising Esports in India.
Government support: Corporate and government sectors in India have recognised the potential of esports and are actively supporting its growth. Major corporate investments, sponsorships, and collaborations with esports organisations have supplied the financial backing and resources required for the country’s esports development. Government attempts to promote esports have also been initiated, such as forming esports governing organisations and including esports in official sporting events.
Growing Popularity and Recognition: Esports in India has witnessed a significant surge in viewership and fanbase, all thanks to online streaming platforms such as Twitch, YouTube which have provided a convenient way for fans to watch live esports events at home and at high-definition quality social media platforms let the fans to interact with their favourite players and stay updated on the latest esports news and events.

Esports Leagues in India
The organisation of esports tournaments and leagues in India has increased, with the IGL being one of the largest and most popular. The ESL India Premiership is a major esports event the Electronic Sports League organised in collaboration with NODWIN Gaming. Viacom18, a well-known Indian media business, established UCypher, an esports league. It focuses on a range of gaming games such as CS: GO, Dota 2, and Tekken in order to promote esports as a professional sport in India. All of these platforms provide professional players with a venue to compete and establish their profile in the esports industry.
India’s Performance in Esports to Date
Indian esports players have achieved remarkable global success, including outstanding results in prominent events and leagues. Individual Indian esports players’ success stories illustrate their talent, determination, and India’s ability to flourish in the esports sphere. These accomplishments contribute to the worldwide esports landscape’s awareness and growth of Indian esports. To add the name of the players and their success stories that have bought pride to India, they are Tirth Metha, Known as “Ritr”, a CS:GO player, Abhijeet “Ghatak”, Ankit “V3nom”, Saloni “Meow16K”.Apart from this Indian women’s team has also done exceptionally well in CS:GO and has made it to the finale.
Government and Corporate Sectors support: The Indian esports business has received backing from the government and corporate sectors, contributing to its growth and acceptance as a genuine sport.
Government Initiatives: The Indian government has expressed increased support for esports through different initiatives. This involves recognising esports as an official sport, establishing esports regulating organisations, and incorporating esports into national sports federations. The government has also announced steps to give financial assistance, subsidies, and infrastructure development for esports, therefore providing a favourable environment for the industry’s growth. Recently, Kalyan Chaubey, joint secretary and acting CEO of the IOA, personally gave the athletes cutting-edge training gear during this occasion, providing kits to the players. The kit includes the following:
Advanced gaming mouse.
Keyboard built for quick responses.
A smooth mousepad
A headphone for crystal-clear communication
An eSports bag to carry the equipment.
Corporate Sponsorship and Partnerships
Indian corporations have recognised esports’ promise and actively sponsored and collaborated with esports organisations, tournaments, and individual players. Companies from various industries, including technology, telecommunications, and entertainment, have invested in esports to capitalise on its success and connect with the esports community. These sponsorships and collaborations give financial support, resources, and visibility to esports in India. The leagues and championships provide opportunities for young players to showcase their talent.
Challenges and future
While esports provides great job opportunities, several obstacles must be overcome in order for the industry to expand and gain recognition:
Infrastructure & Training Facilities: Ensuring the availability of high-quality training facilities and infrastructure is critical for developing talent and allowing players to realise their maximum potential. Continued investment in esports venues, training facilities, and academies is critical for the industry’s long-term success.
Fostering a culture of skill development and giving outlets for formal education in esports would improve the professionalism and competitiveness of Indian esports players. Collaborations between educational institutions and esports organisations can result in the development of specialised programs in areas such as game analysis, team management, and sports psychology.
Establishing a thorough legal framework and governance structure for esports will help it gain legitimacy as a professional sport. Clear standards on player contracts, player rights, anti-doping procedures, and fair competition policies are all part of this.
Conclusion
Esports in India provide massive professional opportunities and growth possibilities for aspiring esports athletes. The sector’s prospects are based on overcoming infrastructure, perception, talent development, and regulatory barriers. Esports may establish itself as a viable and acceptable career alternative in India with continued support, investment, and stakeholder collaboration

BharOS’s successful testing grabbed massive online attention after Ashwini Vaishnaw, Minister of Communications and Electronics & IT, and Union Education Minister Dharmendra Pradhan unveiled the new mobile operating system. On Data Privacy Day, January 28, it’s appropriate to discuss the safety factors.
The OS is developed by JandKops, which has been incubated by IIT Madras Pravartak Technologies Foundation. It is claimed that BharOS will ensure the prevention of the “execution of any malware” and “execution of any malicious application”.
Even though it is called a Made in India OS, there are many people who disagree with this. It is because the OS is based on an AOSP (Android Open Source Project). It includes similar methodologies, functionalities, and basics used in Google Android.
Global safety factor
Security and data safety has been worldwide issue. A few years ago, Alphabet CEO Sundar Pichai also testified in front of US Congress while facing questions related to privacy, data collection, and location tracking.
While experts say that Android’s app ecosystem is a privacy and security disaster, a study that examined 82,501 apps pre-installed on 1,742 Android smartphones sold by 214 vendors concluded that users are woefully unaware of the significant security and privacy risks posed by pre-installed applications.
Even Apple, which takes cybersafety issues as a top priority, sometimes finds itself in a vulnerable situation. For example, last year Apple users were advised to update their devices to protect against a pair of security flaws that could allow attackers to take complete control.
It was said that one of the software flaws affected the kernel, the deepest layer of the OS shared by all Apple devices, while the other had an impact on WebKit, the technology that powers the Safari web browser.
Security researchers, including NordVPN, said that Apple’s closed development OS makes it more difficult for hackers to develop exploits, while Android raises the threat level since anyone can see its source code to develop exploits.
BharOS is not like iOS but it is kind of similar to Android and based on AOSP. So the question is, how safe would this OS be?
‘Security blanket’
Sandip Kumar Panda, Co-founder and CEO of InstaSafe, told News18: “BharOS acts as a security blanket for devices. The framework is designed in a manner that it prevents the execution of any malicious app and verifies each app on the devices before making it live on the BharOS platform.”
There are no apps without any vulnerabilities, he said. “As the app development progresses, vulnerabilities get introduced either in the form of insecure coding practices or third-party software vulnerabilities integrated with the platform. Since several Android vulnerabilities were discovered over the years, all those bugs would have been fixed now and updates would already have been for AOSP, which will be much more mature now,” he added.
Vineet Kumar, Founder and President of CyberPeace Foundation, believes that “the use of AOSP as the foundation for BharOS is a positive step” as it is a robust platform.
But according to him, it is important to note that no OS can be completely immune to all forms of cyber threats. “The key to staying safe online is to stay vigilant, use security software, keep your software updated, and be mindful of the apps you install and the websites you visit,” he said,
Furthermore, the expert stated that it is possible to make an OS more secure by implementing a variety of security features and technologies such as sandboxing, whitelisting, and application control, as well as rigorous testing and code review processes.
Kumar said: “It would be important for an independent, reputable security firm to evaluate BharOS and test its security features before it can be stated with certainty that it is more secure than other OSs.”
It is difficult to say whether the BharOS will be free of cybersecurity issues without more information about the specific features and security measures that have been implemented, he noted while adding that this OS has to go through a rigorous testing and certification process.
“It will be important to see how it measures up against established security standards and how well it can withstand real-world attacks,” the expert stated.
Reference Link : https://www.news18.com/amp/news/tech/data-privacy-day-how-safe-is-bharos-what-do-cybersecurity-experts-say-you-are-about-to-find-out-6932521.html

Introduction
The world has been surfing the wave of technological advancements and innovations for the past decade, and it all pins down to one device – our mobile phone. For all mobile users, the primary choices of operating systems are Android and iOS. Android is an OS created by google in 2008 and is supported by most brands like – One+, Mi, OPPO, VIVO, Motorola, and many more and is one of the most used operating systems. iOS is an OS that was developed by Apple and was introduced in their first phone – The iPhone, in 2007. Both OS came into existence when mobile phone penetration was slow globally, and so the scope of expansion and advancements was always in favor of such operating systems.
The Evolution
iOS
Ever since the advent of the iPhone, iOS has seen many changes since 2007. The current version of iOs is iOS 16. However, in the course of creating new iOS and updating the old ones, Apple has come out with various advancements like the App Store, Touch ID & Face ID, Apple Music, Podcasts, Augmented reality, Contact exposure, and many more, which have later become part of features of Android phone as well. Apple is one of the oldest tech and gadget developers in the world, most of the devices manufactured by Apple have received global recognition, and hence Apple enjoys providing services to a huge global user base.
Android
The OS has been famous for using the software version names on the food items like – Pie, Oreo, Nougat, KitKat, Eclairs, etc. From Android 10 onwards, the new versions were demoted by number. The most recent Android OS is Android 13; this OS is known for its practicality and flexibility. In 2012 Android became the most popular operating system for mobile devices, surpassing Apple’s iOS, and as of 2020, about 75 percent of mobile devices run Android.
Android vs. iOS
1. USER INTERFACE
One of the most noticeable differences between Android and iPhone is their user interface. Android devices have a more customizable interface, with options to change the home screen, app icons, and overall theme. The iPhone, on the other hand, has a more uniform interface with less room for customization. Android allows users to customize their home screen by adding widgets and changing the layout of their app icons. This can be useful for people who want quick access to certain functions or information on their home screen. IOS does not have this feature, but it does allow users to organize their app icons into folders for easier navigation.
2. APP SELECTION
Another factor to consider when choosing between Android and iOS is the app selection. Both platforms have a wide range of apps available, but there are some differences to consider. Android has a larger selection of apps overall, including a larger selection of free apps. However, some popular apps, such as certain music streaming apps and games, may be released first or only available on iPhone. iOS also has a more curated app store, meaning that all apps must go through a review process before being accepted for download. This can result in a higher quality of apps overall, but it can also mean that it takes longer for new apps to become available on the platform. iPhone devices tend to have less processing power and RAM. But they are generally more efficient in their use of resources. This can result in longer battery life, but it may also mean that iPhones are slower at handling multiple tasks or running resource-intensive apps.
3. PERFORMANCE
When it comes to performance, both Android and iPhone have their own strengths and weaknesses. Android devices tend to have more processing power and RAM. This can make them faster and more capable of handling multiple tasks simultaneously. However, this can also lead to Android devices having shorter battery life compared to iPhones.
4. SECURITY
Security is an important consideration for any smartphone user, and Android and iPhone have their own measures to protect user data. Android devices are generally seen as being less secure than iPhones due to their open nature. Android allows users to install apps from sources other than the Google Play Store, which can increase the risk of downloading malicious apps. However, Android has made improvements in recent years to address this issue. Including the introduction of Google Play Protect, which scans apps for malware before they are downloaded. On the other hand, iPhone devices have a more closed ecosystem, with all apps required to go through Apple‘s review process before being available for download. This helps reduce the risk of downloading malicious apps, but it can also limit the platform’s flexibility.
Conclusion
The debate about the better OS has been going on for some time now, and it looks like it will get more comprehensive in the times to come, as netizens go deeper into cyberspace, they will get more aware and critical of their uses and demands, which will allow them to opt for the best OS for their convenience. Although the Andriod OS, due to its integration, stands more vulnerable to security threats as compared to iOS, no software is secure in today’s time, what is secure is its use and application hence the netizen and the platforms need to increase their awareness and knowledge to safeguard themselves and the wholesome cyberspace.

Introduction
With the increasing reliance on digital technologies in the banking industry, cyber threats have become a significant concern. Cyberlaw plays a crucial role in safeguarding the banking sector from cybercrimes and ensuring the security and integrity of financial systems.
The banking industry has witnessed a rapid digital transformation, enabling convenient services and greater access to financial resources. However, this digitalisation also exposes the industry to cyber threats, necessitating the formulation and implementation of effective cyber law frameworks.
Recent Trends in the Banking Industry
Digital Transformation: The banking industry has embraced digital technologies, such as mobile banking, internet banking, and financial apps, to enhance customer experience and operational efficiency.
Open Banking: The concept of open banking has gained prominence, enabling data sharing between banks and third-party service providers, which introduces new cyber risks.

How Cyber Law Helps the Banking Sector
The banking sector and cyber crime share an unspoken synergy due to the mass digitisation of banking services. Thanks to QR codes, UPI and online banking payments, India is now home to 40% of global online banking transactions. Some critical aspects of the cyber law and banking sector are as follows:
Data Protection: Cyberlaw mandates banks to implement robust data protection measures, including encryption, access controls, and regular security audits, to safeguard customer data.
Incident Response and Reporting: Cyberlaw requires banks to establish incident response plans, promptly report cyber incidents to regulatory authorities, and cooperate in investigations.
Customer Protection: Cyberlaw enforces regulations related to online banking fraud, identity theft, and unauthorised transactions, ensuring that customers are protected from cybercrimes.
Legal Framework: Cyberlaw provides a legal foundation for digitalisation in the banking sector, assuring customers that regulations protect their digital transactions and data.
Cybersecurity Training and Awareness: Cyberlaw encourages banks to conduct regular training programs and create awareness among employees and customers about cyber threats, safe digital practices, and reporting procedures.

RBI Guidelines
The RBI, as India’s central banking institution, has issued comprehensive guidelines to enhance cyber resilience in the banking industry. These guidelines address various aspects, including:
Technology Risk Management
Cyber Security Framework
IT Governance
Cyber Crisis Management Plan
Incident Reporting and Response
Recent Trends in Banking Sector Frauds and the Role of Cyber Law
Phishing Attacks: Cyberlaw helps banks combat phishing attacks by imposing penalties on perpetrators and mandating preventive measures like two-factor authentication.
Insider Threats: Cyberlaw regulations emphasise the need for stringent access controls, employee background checks, and legal consequences for insiders involved in fraudulent activities.
Ransomware Attacks: Cyberlaw frameworks assist banks in dealing with ransomware attacks by enabling legal actions against hackers and promoting preventive measures, such as regular software updates and data backups.
Master Directions on Cyber Resilience and Digital Payment Security Controls for Payment System Operators (PSOs)
Draft of Master Directions on Cyber Resilience and Digital Payment Security Controls for Payment System Operators (PSOs) issued by the Reserve Bank of India (RBI). The directions provide guidelines and requirements for PSOs to improve the safety and security of their payment systems, with a focus on cyber resilience. These guidelines for PSOs include mobile payment service providers like Paytm or digital wallet payment platforms.
Here are the highlights-
The Directions aim to improve the safety and security of payment systems operated by PSOs by providing a framework for overall information security preparedness, with an emphasis on cyber resilience.
The Directions apply to all authorised non-bank PSOs.
PSOs must ensure adherence to these Directions by unregulated entities in their digital payments ecosystem, such as payment gateways, third-party service providers, vendors, and merchants.
The PSO’s Board of Directors is responsible for ensuring adequate oversight over information security risks, including cyber risk and cyber resilience. A sub-committee of the Board may be delegated with primary oversight responsibilities.
PSOs must formulate a Board-approved Information Security (IS) policy that covers roles and responsibilities, measures to identify and manage cyber security risks, training and awareness programs, and more.
PSOs should have a distinct Board-approved Cyber Crisis Management Plan (CCMP) to detect, contain, respond, and recover from cyber threats and attacks.
A senior-level executive, such as a Chief Information Security Officer (CISO), should be responsible for implementing the IS policy and the cyber resilience framework and assessing the overall information security posture of the PSO.
PSOs need to define Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to identify potential risk events and assess the effectiveness of security controls. The sub-committee of the Board is responsible for monitoring these indicators.
PSOs should conduct a cyber risk assessment when launching new products, services, technologies, or significant changes to existing infrastructure or processes.
PSOs, including inventory management, identity and access management, network security, application security life cycle, security testing, vendor risk management, data security, patch and change management life cycle, incident response, business continuity planning, API security, employee awareness and training, and other security measures should implement various baseline information security measures and controls.
PSOs should ensure that payment transactions involving debit to accounts conducted electronically are permitted only through multi-factor authentication, except where explicitly permitted/relaxed.

Conclusion
The relationship between cyber law and the banking industry is crucial in ensuring a secure and trusted digital environment. Recent trends indicate that cyber threats are evolving and becoming more sophisticated. Compliance with cyber law provisions and adherence to guidelines such as those provided by the RBI is essential for banks to protect themselves and their customers from cybercrimes. By embracing robust cyber law frameworks, the banking industry can foster a resilient ecosystem that enables innovation while safeguarding the interests of all stakeholders or users.

Introduction
The insurance industry is a target for cybercriminals due to the sensitive nature of the information it holds. This makes it essential for insurance companies to have robust cybersecurity measures to protect their data and customers’ personal information.
Cyber fraud in India’s insurance industry is increasing. It is reported that the Indian insurance sector has witnessed a surge in cyber-attacks, with several instances of data breaches, identity thefts, and financial fraud being reported. These cybercrimes not only pose a significant threat to the financial stability of the insurance industry but also to the privacy and security of policyholders.
Cyber Frauds in the Insurance Industry
The insurance industry in India has been the target of increasing cyber fraud in recent years. With the growing digital transformation trend, insurance companies have become increasingly vulnerable to cyber-attacks. Cyber frauds in the insurance industry are initiated by hackers who use various techniques such as phishing, malware, ransomware, and social engineering to gain unauthorised access to policyholders’ personal data and sensitive information
Kinds of cyber frauds in the insurance industry
It is essential for insurers and policyholders alike to be aware of these kinds of cyber-attacks on insurance companies in today’s digital age. Staying educated about these threats can help prevent them from happening in the future.
Identity theft– One common type of cyber fraud that occurs in the insurance industry is identity theft. In this type of fraud, criminals steal personal information such as name, address, date of birth and social security numbers through phishing emails or fraudulent websites. They then use this information to open fraudulent policies or access existing ones.
Payment fraud- Another type of cyber fraud that is on the rise is payment fraud. In this type of fraud, hackers intercept electronic payments made by policyholders or agents using fake bank accounts or compromised payment gateways. The money is then siphoned into untraceable accounts, making it difficult for law enforcement agencies to identify and arrest the perpetrators.
Phishing attacks- Where the fraudsters posed as company officials and sent emails to policyholders requesting their account details. The unsuspecting customers fell for this scam and shared their sensitive information, which was then used to access their accounts and steal funds.
Hacking- Where hackers breach the company’s system to gain access to policyholder data. The hackers’ stoles personal records, including names, addresses, phone numbers, social security numbers, and financial information, which they later sell on the dark web.
Fake policies scam- Fraudsters create fake policies using stolen identities and collect premiums from innocent customers. The insurer then voided these policies due to fraudulent activity leaving those people without valid coverage when they needed it most. The victims suffer significant financial losses due to this scam.
Fake Insurance Websites- Discuss the creation of deceptive websites that imitate well-known insurance companies, where unsuspecting individuals provide their personal details, leading to identity theft or financial losses.

Prevention of Cyber Frauds in the Insurance Industry- Best practices to follow
Prevention is better than cure, which also holds true in the case of cyber fraud in the insurance industry. The industry must take proactive steps to prevent such frauds from occurring in the first place. One of the most effective ways to do so is by investing in cybersecurity measures that are specifically designed for the insurance sector.
Insurance companies must conduct regular employee training programs on cybersecurity best practices. This includes educating employees on how to identify and avoid phishing emails, create strong passwords, and recognise potential cyber threats. Companies should also establish a reporting mechanism for employees to report suspicious activity or incidents immediately.
Having proper access controls in place is also necessary. This means limiting access to sensitive data only to those employees who need it, implementing two-factor authentication, and regularly monitoring user activity logs. Regular audits can also provide an extra layer of protection against potential threats by identifying vulnerabilities that may have been overlooked during routine security checks.
Another essential step is encrypting all data transmitted between different systems and devices. Encryption scrambles data into unreadable codes that can only be deciphered using a decryption key, making it difficult for hackers to intercept or steal information in transit.
Legal Framework for Cyber Frauds in the Insurance Industry
The legal framework for cyber fraud in the insurance industry is critical to preventing such crimes. The Insurance Regulatory and Development Authority of India (IRDAI) has issued guidelines for insurers to establish a cybersecurity framework. The guidelines require insurers to conduct regular risk assessments, implement security measures, and ensure compliance with data privacy laws.
The Information Technology Act 2000, is another significant piece of legislation dealing with cyber fraud in India. The act defines offences such as unauthorised access to a computer system, hacking, and tampering with data. It also provides for stringent penalties and imprisonment for those found guilty of such offences.
The IRDAI’s guidelines provide insurers with a roadmap to establish robust cybersecurity measures to help prevent cyber fraud in the insurance industry. Stringent implementation of these guidelines will go a long way in safeguarding sensitive customer information from falling into the wrong hands.
Best Practices for Insurers and Policyholders
Insurers:
Implementing Strong Authentication: Encouraging the use of multi-factor authentication and secure login processes to safeguard customer accounts and prevent unauthorised access.
Regular Employee Training: Conduct cybersecurity awareness programs to educate employees about the latest threats and preventive measures.
Investing in Advanced Technologies: Utilizing robust cybersecurity tools and systems to promptly detect and mitigate potential cyber threats.
Policyholders:
Vigilance and Awareness: Policyholders must stay vigilant while sharing personal information online and verify the authenticity of insurance websites and communication channels.
Regular Updates and Patches: Advising individuals to keep their devices and software up to date to minimise vulnerabilities that cybercriminals can exploit.
Secure Online Practices: Encouraging the use of strong and unique passwords, avoiding sharing sensitive information on unsecured networks, and exercising caution when clicking on suspicious links or attachments.

Conclusion
As the Indian insurance industry embraces digitisation, the risk of cyber scams and data breaches becomes a significant concern. Insurers and policyholders must collaborate to ensure robust cybersecurity measures are in place to protect sensitive information and financial interests.
It is essential for insurance companies to invest in robust cybersecurity measures that can detect and prevent fraud attempts. Additionally, educating employees on the dangers of cyber fraud and implementing strict compliance measures can go a long way in mitigating risks. With these efforts, the insurance industry can continue to provide trustworthy and reliable services to its customers while protecting against cyber threats. As technology continues to evolve, it is imperative that the insurance industry adapts accordingly and remains vigilant against emerging threats.

Introduction
The European Union has fined the meta $ 1.3 billion for infringing the EU privacy laws by transferring the personal data of Facebook users to the United States. The EU fined Meta’s business in Ireland. As per the European Union, transferring Personal data to the US is a breach of the General data protection Regulation or European Union law on data protection and privacy.
GDPR Compliance
The terms of GDPR promise to gather users’ personal information legally and under strict conditions. And those who collect and manage personal data must protect users’ personal data from exploitation. The GDPR restricts an organisation’s capacity to transfer personal data outside the EU if the transfer is solely based on that body’s evaluation of the sufficiency of the personal data’s protection. Transfers should only be made where European authorities have determined that a third country, a territory within that third country, or an international organisation provides acceptable protection for data protection.
Violation by Meta
The punishment, announced by Ireland’s Data Protection Commission, might be one of the most significant in the five years since the European Union passed the landmark General Data Protection Regulation. According to regulators, Facebook failed to comply with a 2020 judgment by the European Union’s top court that Facebook data transferred over the Atlantic was not sufficiently safeguarded from American espionage agencies. However, whether Meta will ever need to encrypt Facebook users’ data in Europe is still being determined. Meta announced it would appeal the ruling, launching a potentially legal procedure.
Simultaneously, European Union and American officials are negotiating a new data-sharing pact that would provide legal protections for Meta and scores of other companies to continue moving information between the US and Europe. This pact could overturn much of the European Union’s Monday ruling.
Article 46(1) GDPR Has been violated by the meta, And as per the Irish privacy.
What is required by the GDPR before transferring personal information across national boundaries?

Personal data transfers to countries outside the European Economic Area are generally permitted if these nations are regarded to provide a sufficient degree of data protection. According to Article 45 of the GDPR, the European Commission evaluates the degree of personal data protection in third countries.
The European Union judgment demonstrates how government rules are upending the borderless way data has traditionally migrated. Companies are increasingly being pressed to store data within the country where it is acquired rather than allowing it to transfer freely to data centres around the world as a result of data-protection requirements, national security laws, and other regulations.
The US internet giant had previously warned that if forced to stop using SCCs (standard contractual clauses) without a proper alternative data transfer agreement in place, it would be compelled to shut down services such as Facebook and Instagram in Europe.
What will happen next for Facebook in Europe?
The ruling includes a six-month transition period before it must halt data flows, meaning the service will continue to operate in the meantime. (More specifically, Meta has been given a five-month transition period to freeze any future transfer of personal data to the United States and a six-month deadline to terminate the unlawful processing and/or storage of European user data it has previously transferred without a legitimate legal basis. Meta has also stated that it will appeal and appears to seek a stay of execution while it pursues its legal arguments in court.
Conclusion
The GDPR places restrictions on transferring personal data outside the European Union to third-party nations or international bodies to ensure that the GDPR’s level of protection for individuals is not jeopardised. But the meta violated the European Union’s privacy laws by the user’s personal information to the US. Under the compliance of GDPR, transferring and sending personal information to users intentionally is an offence. and presently, the personal data of Facebook users has been breached by the Meta, as they shared the information with the US.

Introduction
Recent advances in space exploration and technology have increased the need for space laws to control the actions of governments and corporate organisations. India has been attempting to create a robust legal framework to oversee its space activities because it is a prominent player in the international space business. In this article, we’ll examine India’s current space regulations and compare them to the situation elsewhere in the world.
Space Laws in India
India started space exploration with Aryabhtta, the first satellite, and Rakesh Sharma, the first Indian astronaut, and now has a prominent presence in space as many international satellites are now launched by India. NASA and ISRO work closely on various projects

India currently lacks any space-related legislation. Only a few laws and regulations, such as the Indian Space Research Organisation (ISRO) Act of 1969 and the National Remote Sensing Centre (NRSC) Guidelines of 2011, regulate space-related operations. However, more than these rules and regulations are essential to control India’s expanding space sector. India is starting to gain traction as a prospective player in the global commercial space sector. Authorisation, contracts, dispute resolution, licencing, data processing and distribution related to earth observation services, certification of space technology, insurance, legal difficulties related to launch services, and stamp duty are just a few of the topics that need to be discussed. The necessary statute and laws need to be updated to incorporate space law-related matters into domestic laws.
India’s Space Presence
Space research activities were initiated in India during the early 1960s when satellite applications were in experimental stages, even in the United States. With the live transmission of the Tokyo Olympic Games across the Pacific by the American Satellite ‘Syncom-3’ demonstrating the power of communication satellites, Dr Vikram Sarabhai, the founding father of the Indian space programme, quickly recognised the benefits of space technologies for India.
As a first step, the Department of Atomic Energy formed the INCOSPAR (Indian National Committee for Space Research) under the leadership of Dr Sarabhai and Dr Ramanathan in 1962. The Indian Space Research Organisation (ISRO) was formed on August 15, 1969. The prime objective of ISRO is to develop space technology and its application to various national needs. It is one of the six largest space agencies in the world. The Department of Space (DOS) and the Space Commission were set up in 1972, and ISRO was brought under DOS on June 1, 1972.

Since its inception, the Indian space programme has been orchestrated well. It has three distinct elements: satellites for communication and remote sensing, the space transportation system and application programmes. Two major operational systems have been established – the Indian National Satellite (INSAT) for telecommunication, television broadcasting, and meteorological services and the Indian Remote Sensing Satellite (IRS) for monitoring and managing natural resources and Disaster Management Support.
Global Scenario
The global space race has been on and ever since the moon landing in 1969, and it has now transformed into the new cold war among developed and developing nations. The interests and assets of a nation in space need to be safeguarded by the help of effective and efficient policies and internationally ratified laws. All nations with a presence in space do not believe in good for all policy, thus, preventive measures need to be incorporated into the legal system. A thorough legal framework for space activities is being developed by the United Nations Office for Outer Space Affairs (UNOOSA). The “Outer Space Treaty,” a collection of five international agreements on space law, establishes the foundation of international space law. The agreements address topics such as the peaceful use of space, preventing space from becoming militarised, and who is responsible for damage caused by space objects. Well-established space laws govern both the United States and the United Kingdom. The National Aeronautics and Space Act, which was passed in the US in 1958 and established the National Aeronautics and Space Administration (NASA) to oversee national space programmes, is in place there. The Outer Space Act of 1986 governs how UK citizens and businesses can engage in space activity.

Conclusion
India must create a thorough legal system to govern its space endeavours. In the space sector, there needs to be a legal framework to avoid ambiguity and confusion, which may have detrimental effects. The Pacific use of space for the benefit of humanity should be covered by domestic space legislation in India. The overall scenario demonstrates the requirement for a clearly defined legal framework for the international acknowledgement of a nation’s space activities. India is fifth in the world for space technology, which is an impressive accomplishment, and a strong legal system will help India maintain its place in the space business.

Pretext
On 20th October 2022, the Competition Commission of India (CCI) imposed a penalty of Rs. 1,337.76 crores on Google for abusing its dominant position in multiple markets in the Android Mobile device ecosystem, apart from issuing cease and desist orders. The CCI also directed Google to modify its conduct within a defined timeline. Smart mobile devices need an operating system (OS) to run applications (apps) and programs. Android is one such mobile operating system that Google acquired in 2005. In the instant matter, the CCI examined various practices of Google w.r.t. licensing of this Android mobile operating system and various proprietary mobile applications of Google (e.g., Play Store, Google Search, Google Chrome, YouTube, etc.).
The Issue
Google was found to be misusing its dominant position in the tech market, and the same was the reason behind the penalty. Google argued about the competitive constraints being faced from Apple. In relation to understanding the extent of competition between Google’s Android ecosystem and Apple’s iOS ecosystem, the CCI noted the differences in the two business models, which affect the underlying incentives of business decisions. Apple’s business is primarily based on a vertically integrated smart device ecosystem that focuses on the sale of high-end smart devices with state-of-the-art software components. In contrast, Google’s business was found to be driven by the ultimate intent of increasing users on its platforms so that they interact with its revenue-earning service, i.e., online searches, which directly affects the sale of online advertising services by Google. It was seen that google had created a dominant position among the android phone manufacturers as they were made to have a set of google apps preinstalled in the device to increase the user’s dependency on google services. The CCI felt that Google had created a dominant position to which they replied that the same operations are done by Apple as well, to which the commission responded that apple is a phone and app manufacturer and they have Apple-owned apps in Apple devices only, but Google here in had made a pseudo mandate for android manufactures to have the google apps pre-installed which is, in turn, a possible way of disrupting the market equilibrium and violative of market practices. The CCI imposed a penalty of Rs. 1,337.76 for abusing its dominant position in multiple markets in India, CCI delineated the following five relevant markets in the present matter –

- The market for licensable OS for smart mobile devices in India
- The market for app store for Android smart mobile OS in India
- The market for general web search services in India
- The market for non-OS specific mobile web browsers in India
- The market for online video hosting platforms (OVHP) in India.
Supreme Courts Opinion
In October 2022, the Competition Commission of India (CCI) ruled that Google, owned by Alphabet Inc, exploited its dominant position in Android and told it to remove restrictions on device makers, including those related to the pre-installation of apps and ensuring exclusivity of its search. Google lost a challenge in the Supreme Court to block the directives, as the learned court refused to put a stay on the imposed penalty, further giving seven days to comply. The Supreme Court has said a lower tribunal—where Google first challenged the Android directives—can continue to hear the company’s appeal and must rule by March 31.
Counterpoint Research estimates that about 97% of 600 million smartphones in India run on Android. Apple has just a 3% share. Hoping to block the implementation of the CCI directives, Google challenged the CCI order in the Supreme Court by warning it could stall the growth of the Android ecosystem. It also said it would be forced to alter arrangements with more than 1,100 device manufacturers and thousands of app developers if the directives kick in. Google has been concerned about India’s decision as the steps are seen as more sweeping than those imposed in the European Commission’s 2018 ruling. There it was fined for putting in place what the Commission called unlawful restrictions on Android mobile device makers. Google is still challenging the record $4.3 billion fine in that case. In Europe, Google made changes later, including letting Android device users pick their default search engine, and said device makers would be able to license the Google mobile application suite separately from the Google Search App or the Chrome browser.
Conclusion
As the world goes deeper into cyberspace, the big tech companies have more control over the industry and the markets, but the same should not turn into anarchy in the global markets. The Tech giants need to be made aware that compliance is the utmost duty for all companies, and enforcement of the law of the land will be maintained no matter what. Earlier India lacked policies and legislation to govern cyberspace, but in the recent proactive stance by the govt, a lot of new bills have been tabled, one of them being the Intermediary Rules 2021, which has laid down the obligations nand duties of the companies by setting up an intermediary in the country. Such bills coupled with such crucial judgments on tech giants will act as a test and barrier for other tech companies who try to flaunt the rules and avoid compliance.

What are Wi-Fi attacks?
Wi-fi is an important area of cyber security and there is no need for physical cable for the network. Wi-Fi has access to a network signal radius everywhere. The devices and systems can have a network without physical access due to Wi-fi. But everything comes with cons and pros, and if we talk about cybersecurity, it has been established that Wi-fi networks are extremely vulnerable to security breaches and it is very easy to be hacked by hackers. Wi-Fi can be accessed by almost every device in the modern day: it can be smartphones, tablets, computers, and laptops. To know whether someone has been tampering with your personal Wi-Fi there are certain signs that can prove it. The first and most important sign is that your internet speed gets slower, as someone else is using your Wi-Fi surf.
Why would anyone hack someone’s Wi-Fi network?
Usually, hackers hack the network because they want access to the confidential data of someone and they can observe all the online activities and data that have been sent through a network. An unauthorize hacker will pretty much be able to see everything you do online. Wi-Fi allows hackers o view information on sites. Any financial information which is saved in the browser can be accessed by hackers and they can alter it and can alter the content you see online. And all the information saved in Wi-fi networks can be used by hackers for their own benefit, they can sell it, impersonate you, or even take money out of your bank through Wi-Fi.
Avoiding vulnerable Wi-Fi networks
The first and foremost rule of protection is that you should not use public networks if that network is easily open to you then that is also available to others and from others, and someone can who wishes to use your confidential and sensitive information, can access that. If you really need to access the public network in an urgent situation, then you must make sure to limit your activities while connected. And avoid accessing your online banking or pages that require login information. Also, a good measure to take as well is to always delete your cookies after using public WIFI.
How To Secure Your Home Wi-Fi Network
Your home’s wireless internet connection is your Wi-Fi network. Typically, a wireless router is used, which broadcasts a signal into the atmosphere. You can connect to the internet using that signal. However, if your network is not password-protected, any nearby device can grab the signal off the air and connect to your internet. The benefit of Wi-Fi? Wireless access to the internet is possible. The negative? Your internet activity, including your personal information, may be visible to neighboring users who connect to your unprotected network. Furthermore, if someone uses your network to conduct a crime or send out unauthorized spam, you might be held accountable.
Wi-Fi or Li-Fi? –
The common consensus is that Li-Fi technology is more secure than Wi-Fi. Li-Fi systems can be made more secure by integrating a variety of security features. Although these qualities might appear when Li-Fi is widely used in the near future, it is already thought to be safer because of a number of security features. Since the connection’s characteristics make it simpler to lock connections, limit access, and track users even in the absence of encryption and other security features, Li-Fi is seen as being safer. Li-Fi systems will be able to support new security protocols, which will not only enable high-speed networking but also open the door for innovative security techniques to strengthen connections.
Conclusion
A hacker can sniff the network packets without having to be in the same building where the network is located. As wireless networks communicate through radio waves, a hacker can easily sniff the network from a nearby location. Most attackers use network sniffing to find the SSID and hack a wireless network.
Any wireless network can theoretically be attacked in a number of different ways. Use of the default SSID or password, WPS pin authentication, insufficient access control, and leaving the access point available in open locations are all examples of potential vulnerabilities that could allow for the theft of sensitive data. Kismet’s architecture in WIDS mode may guard against DOS, MiTM, and MAC spoofing attacks. routine software updates on the other hand, the use of firewalls may help defend the network against outside intrusion. The act of finding infrastructure issues that could allow harmful code to be injected into a service, system, or organization is known as ethical hacking. They use this technique to prevent invasions by lawfully breaking into networks and looking for weak spots.

Introduction
Google Play has announced its new policy which will ensure trust and transparency on google play by providing a new framework for developer verification and app details. The new policy requires that new developer accounts on Google Play will have to provide a D-U-N-S number to verify the business. So when an organisation will create a new Play Console developer account the organisation will need to provide a D-U-N-S number. Which is a nine-digit unique identifier which will be used to verify their business. The new google play policy aims to enhance user trust. And the developer will provide detailed developer details on the app’s listing page. Users will get to know who is behind the app which they are installing.
Verifying Developer Identity with D-U-N-S Numbers
To boost security the google play new policy requires the developer account to provide the D-U-N-S number when creating a new Play Console developer account. The D-U-N-S number assigned by Dun & Bradstreet will be used to verify the business. Once the developer creates his new Play Console developer account by providing a D-U-N-S number, Google Play will verify the developer’s details, and he will be able to start publishing the apps. Through this step, Google Play aims to validate the business information in a more authentic way.
If your organisation does not have a D-U-N-S number, you may check on or request for it for free on this website (https://www.dnb.com/duns-number/lookup.html). The request process for D-U-N-S can take up to 30 days. Developers are also required to keep the information up to date.
Building User Trust with Enhanced App Details
In addition to verifying developer identities in a more efficient way, google play also requires that developer provides sufficient app details to the users. There will be an “App Support” section on the app’s store listing page, where the developer will display the app’s support email address and even can include their website and phone number for support.
The new section “About the developer” will also be introduced to provide users with verified identity information, including the developer’s name, address, and contact details. Which will make the users more informed about the valuable information of the app developers.
Key highlights of the Google Play Polic
- Google Play came up with the policy to keep the platform safe by verifying the developers’ identity and it will also help to reduce the spread of malware apps and help the users to make confident informed decisions about the apps they download. Google Play announced the policy by expanding its developer verification requirement to strengthen Google Play as a platform and build user trust. When you create a new Play Console Developer account and choose organisation as your account type you will now need to provide a D-U-N-S number.
- Users will get detailed information about the developers’ identities and contact information, building more transparency and encouraging responsible app development practices.
- This policy will enable the users to make informed choices about the apps they download.
- The new “App support” section will provide enhanced communication between users and developers by displaying support email addresses, website and support phone numbers, streamlining the support process and user satisfaction.
Timeline and Implementation
The new policy requirements for D-U-N-S numbers will start rolling out on 31 August 2023 for all new Play Console developer accounts. The “About the developer” section will be visible to users as soon as a new app is published. and In October 2023, existing developers will also be required to update and verify their existing accounts to comply with the new verification policy.
Conclusion
Google Play’s new policy will aim to enhance the more transparent app ecosystem. This new policy will provide the users with more information about the developers. Google Play aims to establish a platform where users can confidently discover and download apps. This new policy will enhance the user experience on google play in terms of a reliable and trustworthy platform.

Introduction
Recently, a Consultation Paper on Regulatory Mechanisms for Over-The-Top (OTT) Communication Services was published by the Telecom Regulatory Authority of India (TRAI). The paper explores several OTT regulation-related challenges and solicits input from stakeholders on a suggested regulatory framework. We’ll summarise the paper’s main conclusions in this blog.
Structure of the Paper
The Telecom Regulatory Authority of India’s Consultation Paper on Regulatory Mechanism for Over-The-Top (OTT) Communication Services and Selective Banning of OTT Services intends to solicit comments and recommendations from stakeholders about the regulation of OTT services in India. The paper is broken up into five chapters that cover the introduction and background, issues with regulatory mechanisms for OTT communication services, issues with the selective banning of OTT services, a summary of the issues for consultation, and an overview of international practices on the topic. Written comments from interested parties are requested and may be sent electronically to the Advisor (Networks, Spectrum and Licencing) at TRAI. These comments will also be posted on the TRAI website.
Overview of the Paper
- Chapter 1: Introduction and Background
- The first chapter of the essay introduces the subject of OTT communication services and argues why regulatory frameworks are necessary. The chapter also gives a general outline of the topics and the paper’s organisation that will be covered in the following chapters.
- Chapter 2: Examination of the Issues Related to Regulatory Mechanism for Over-The-Top Communication Services
- The second chapter of the essay looks at the problems with OTT communication service regulation. It talks about the many kinds of OTT services and how they affect the conventional telecom sector. The chapter also looks at the regulatory issues raised by OTT services and the various strategies used by various nations to address them.
- Chapter 3: Examination of the Issues Related to Selective Banning of OTT Services
- The final chapter of the essay looks at the problems of selectively outlawing OTT services. It analyses the justifications for government restrictions on OTT services as well as the possible effects of such restrictions on consumers and the telecom sector. The chapter also looks at the legal and regulatory structures that determine how OTT services are prohibited in various nations.
- Chapter 4: International Practices
- An overview of global OTT communication service best practices is given in the paper’s fourth chapter. It talks about the various regulatory strategies used by nations throughout the world and how they affect consumers and the telecom sector. The chapter also looks at the difficulties regulators encounter when trying to create efficient regulatory frameworks for OTT services.
- Chapter 5: Issues for Consultation
- This chapter is the spirit of the consultation paper as it covers the points and questions for consultation. This chapter has been classified into two sub-sections – Issues Related to Regulatory Mechanisms for OTT Communication Services and Issues Related to the Selective Banning of OTT Services. The inputs will be entirely focused on these sub headers, and the scope, extent, and ambit of the consultation paper rests on these questions and necessary inputs.
Conclusion
An important publication that aims to address the regulatory issues raised by OTT services is the Consultation Paper on Regulatory Mechanisms for Over-The-Top Communication Services. The paper offers a thorough analysis of the problems with OTT service regulation and requests input from stakeholders on the suggested regulatory structure. In order to make sure that the regulatory framework is efficient and advantageous for everyone, it is crucial for all stakeholders to offer their opinion on the document.

Introduction
Twitter Inc.’s appeal against barring orders for specific accounts issued by the Ministry of Electronics and Information Technology was denied by a single judge on the Karnataka High Court. Twitter Inc. was also given an Rs. 50 lakh fine by Justice Krishna Dixit, who claimed the social media corporation had approached the court defying government directives.
As a foreign corporation, Twitter’s locus standi had been called into doubt by the government, which said they were ineligible to apply Articles 19 and 21 to their situation. Additionally, the government claimed that because Twitter was only designed to serve as an intermediary, there was no “jural relationship” between Twitter and its users.
The Issue
In accordance with Section 69A of the Information Technology Act, the Ministry issued the directives. Nevertheless, Twitter had argued in its appeal that the orders “fall foul of Section 69A both substantially and procedurally.” Twitter argued that in accordance with 69A, account holders were to be notified before having their tweets and accounts deleted. However, the Ministry failed to provide these account holders with any notices.
On June 4, 2022, and again on June 6, 2022, the government sent letters to Twitter’s compliance officer requesting that they come before them and provide an explanation for why the Blocking Orders were not followed and why no action should be taken against them.
Twitter replied on June 9 that the content against which it had not followed the blocking orders does not seem to be a violation of Section 69A. On June 27, 2022, the Government issued another notice stating Twitter was violating its directions. On June 29, Twitter replied, asking the Government to reconsider the direction on the basis of the doctrine of proportionality. On June 30, 2022, the Government withdrew blocking orders on ten account-level URLs but gave an additional list of 27 URLs to be blocked. On July 10, more accounts were blocked. Compiling the orders “under protest,” Twitter approached the HC with the petition challenging the orders.
Legality
Additionally, the government claimed that because Twitter was only designed to serve as an intermediary, there was no “jural relationship” between Twitter and its users.
Government attorney Additional Solicitor General R Sankaranarayanan argued that tweets mentioning “Indian Occupied Kashmir” and the survival of LTTE commander Velupillai Prabhakaran were serious enough to undermine the integrity of the nation.
Twitter, on the other hand, claimed that its users have pushed for these rights. Additionally, Twitter maintained that under Article 14 of the Constitution, even as a foreign company, they were entitled to certain rights, such as the right to equality. They also argued that the reason for the account blocking in each case was not stated and that Section 69a’s provision for blocking a URL should only apply to the offending URL rather than the entire account because blocking the entire account would prevent the creation of information while blocking the offending tweet only applied to already-created information.
Conclusion
The evolution of cyberspace has been substantiated by big tech companies like Facebook, Google, Twitter, Amazon and many more. These companies have been instrumental in leading the spectrum of emerging technologies and creating a blanket of ease and accessibility for users. Compliance with laws and policies is of utmost priority for the government, and the new bills and policies are empowering the Indian cyberspace. Non Compliance will be taken very seriously, and the same is legalised under the Intermediary Guidelines 2021 and 2022 by Meity. Referring to Section 79 of the Information Technology Act, which pertains to an exemption from liability of intermediary in some instances, it was said, “Intermediary is bound to obey the orders which the designate authority/agency which the government fixes from time to time.”

Introduction
Cert-In (Indian Computer Emergency Response Team) has recently issued the “Guidelines on Information Security Practices” for Government Entities for Safe & Trusted Internet. The guideline has come at a critical time when the Draft Digital India Bill is about to be released, which is aimed at revamping the legal aspects of Indian cyberspace. These guidelines lay down the policy framework and the requirements for critical infrastructure for all government organisations and institutions to improve the overall cyber security of the nation.
What is Cert-In?
A Computer Emergency Response Team (CERT) is a group of information security experts responsible for the protection against, detection of and response to an organisation’s cybersecurity incidents. A CERT may focus on resolving data breaches and denial-of-service attacks and providing alerts and incident handling guidelines. CERTs also conduct ongoing public awareness campaigns and engage in research aimed at improving security systems. The Ministry of Electronics and Information Technology (MeitY) oversees CERT-In. It regularly releases alerts to help individuals and companies safeguard their data, information, and ICT (Information and Communications Technology) infrastructure.
Indian Computer Emergency Response Team (CERT-In) has been established and appointed as national agency in respect of cyber incidents and cyber security incidents in terms of the provisions of section 70B of Information Technology (IT) Act, 2000.
CERT-In requests information from service providers, intermediaries, data centres, and body corporates to coordinate reaction actions and emergency procedures regarding cyber security incidents. It is a focal point for incident reporting and offers round-the-clock security services. It manages cyber occurrences that are tracked and reported while continuously analysing cyber risks. It strengthens the security barriers for the Indian Internet domain.
Background
India is fast becoming one of the world’s largest connected nations – with over 80 Crore Indians (Digital Nagriks) presently connected and using the Internet and cyberspace – and with this number is expected to touch 120 Crores in the coming few years. The Digital Nagriks of the country are using the Internet for business, education, finance and various applications and services including Digital Government services. Internet provides growth and innovation and at the same time it has seen rise in cybercrimes, user harm and other challenges to online safety. The policies of the Government are aimed at ensuring an Open, Safe & Trusted and Accountable Internet for its users. Government is fully cognizant and aware of the growing cyber security threats and attacks.
It is the Government of India’s objective to ensure that Digital Nagriks experience a Safe & Trusted Internet. Along with ubiquitous applications of Information & Communication Technologies (ICT) in almost all facets of service delivery and operations, continuously evolving cyber threats have become a concern for the Government. Cyber-attacks can come in the form of malware, ransomware, phishing, data breach etc., that adversely affect an organisation’s information and systems. Cyber threats leading to cyber-attacks or incidents can compromise the confidentiality, integrity, and availability of an organisation’s information and systems and can have far reaching impact on essential services and national interests. To protect against cyber threats, it is important for government entities to implement strong cybersecurity measures and follow best practices. As ICT infrastructure of the Government entities is one of the preferred targets of the malicious actors, responsibility of implementing good cyber security practices for protecting computers, servers, applications, electronic systems, networks, and data from digital attacks, also remain with the ICT assets’ owner i.e. Government entity.
What are the new Guidelines about?
The Government of India (distribution of business) Rules, 1961’s First Schedule lists a number of Ministries, Departments, Secretariats, and Offices, along with their affiliated and subordinate offices, which are all subject to the rules. They also comprise all governmental organisations, businesses operating in the public sector, and other governmental entities under their administrative control.
“The government has launched a number of steps to guarantee an accessible, trustworthy, and accountable digital environment. With a focus on capabilities, systems, human resources, and awareness, we are extending and speeding our work in the area of cyber security, according to Rajeev Chandrasekhar, Minister of State for Electronics, Information Technology, Skill Development, and Entrepreneurship.
The Recommendations
- Various security domains are covered in the standards, including network security, identity and access management, application security, data security, third-party outsourcing, hardening procedures, security monitoring, incident management, and security audits.
- For instance, the rules advise using only a Standard User (non-administrator) account to use computers and laptops for regular work regarding desktop, laptop, and printer security in the workplace. Users may only be granted administrative access with the CISO’s consent.
- The usage of lengthy passwords containing at least eight characters that combine capital letters, tiny letters, numerals, and special characters; Never save any usernames or passwords in your web browser. Likewise, never save any payment-related data there.
- They include guidelines created by the National Informatics Centre for Chief Information Security Officers (CISOs) and staff members of Central government Ministries/Departments to improve cyber security and cyber hygiene in addition to adhering to industry best practises.
Conclusion
The government has been proactive in the contemporary times to eradicate the menace of cybercrimes and therreats from the Indian cyberspace and hence now we have seen a series of new bills and polices introduced by the Ministry of Electronics and Information Technology, and various other government organisations like Cert-In and TRAI. These policies have been aimed towards being relevant to time and current technologies. The threats from emerging technologies like web 3.0 cannot be ignored and hence with active netizen participation and synergy between government and corporates will lead to a better and improved cyber ecosystem in India.

Introduction
The Telecom Regulatory Authority of India (TRAI) issued a consultation paper titled “Encouraging Innovative Technologies, Services, Use Cases, and Business Models through Regulatory Sandbox in Digital Communication Sector. The paper presents a draft sandbox structure for live testing of new digital communication products or services in a regulated environment. TRAI seeks comments from stakeholders on several parts of the framework.
What is digital communication?
Digital communication is the use of internet tools such as email, social media messaging, and texting to communicate with other people or a specific audience. Even something as easy as viewing the content on this webpage qualifies as digital communication.
Aim of Paper
- Frameworks are intended to support regulators’ desire for innovation while also ensuring economic resilience and consumer protection. Considering this, the Department of Telecom (DoT) asked TRAI to offer recommendations on a regulatory sandbox framework. TRAI approaches the issue with the goal of encouraging creativity and hastening the adoption of cutting-edge digital communications technologies.
- Artificial intelligence, the Internet of Things, edge computing, and other emerging technologies are revolutionizing how we connect, communicate, and access information, driving the digital communication sector to rapidly expand. To keep up with this dynamic environment, an enabling environment for the development and deployment of novel technologies, services, use cases, and business models is required.
- The regulatory sandbox concept is becoming increasingly popular around the world as a means of encouraging innovation in a range of industries. A regulatory sandbox is a regulated environment in which businesses and innovators can test their concepts, commodities, and services while operating under changing restrictions.
- Regulatory Sandbox will benefit the telecom startup ecosystem by providing access to a real-time network environment and other data, allowing them to evaluate the reliability of new applications before releasing them to the market. Regulatory Sandbox also attempts to stimulate cross-sectoral collaboration for carrying out such testing by engaging the assistance of other ministries and departments in order to give the starting company with a single window for acquiring all clearances.
What is regulatory sandbox?
- A regulatory sandbox is a controlled regulatory environment in which new products or services are tested in real-time.
- It serves as a “safe space” for businesses because authorities may or may not allow certain relaxations for the sole purpose of testing.
- The sandbox enables the regulator, innovators, financial service providers, and clients to perform field testing in order to gather evidence on the benefits and hazards of new financial innovations, while closely monitoring and mitigating their risks.
What are the advantages of having a regulatory sandbox?
- Firstly, regulators obtain first-hand empirical evidence on the benefits and risks of emerging technologies and their implications, allowing them to form an informed opinion on the regulatory changes or new regulations that may be required to support useful innovation while mitigating the associated risks.
- Second, sandbox customers can evaluate the viability of a product without the need for a wider and more expensive roll-out. If the product appears to have a high chance of success, it may be authorized and delivered to a wider market more quickly.
Digital communication sector and Regulatory Sandbox
- Many countries’ regulatory organizations have built sandbox settings for telecom tech innovation.
- These frameworks are intended to encourage regulators’ desire for innovation while also promoting economic resilience and consumer protection.
- In this context, the Department of Telecom (DoT) had asked TRAI to give recommendations on a regulatory sandbox framework.
- Written comments on the drafting framework will be received until July 17, 2023, and counter-comments will be taken until August 1, 2023. The Authority’s goal in the digital communication industry is to foster creativity and expedite the use of emerging technologies such as artificial intelligence (AI), the Internet of Things (IoT), and edge computing. These technologies are changing the way individuals connect, engage, and access information, causing rapid changes in the industry.
Conclusion
According to TRAI, these technologies are changing how individuals connect, engage, and obtain information, resulting in significant changes in the sector.
The regulatory sandbox also wants to stimulate cross-sectoral collaboration for carrying out such testing by engaging the assistance of other ministries and departments in order to give the starting company with a single window for acquiring all clearances. The consultation paper covers some of the worldwide regulatory sandbox frameworks in use in the digital communication industry, as well as some of the frameworks in use inside the country in other sectors.

Introduction
The Telecom Regulatory Authority of India (TRAI) has directed all telcos to set up detection systems based on Artificial Intelligence and Machine Learning (AI/ML) technologies in order to identify and control spam calls and text messages from unregistered telemarketers (UTMs).
The TRAI Directed telcos
The telecom regulator, TRAI, has directed all Access Providers to detect Unsolicited commercial communication (UCC)by systems, which is based on Artificial Intelligence and Machine Learning to detect, identify, and act against senders of Commercial Communication who are not registered in accordance with the provisions of the Telecom Commercial Communication Customer Preference Regulations, 2018 (TCCCPR-2018). Unregistered Telemarketers (UTMs) are entities that do not register with Access Providers and use 10-digit mobile numbers to send commercial communications via SMS or calls.
TRAI steps to curb Unsolicited commercial communication
TRAI has taken several initiatives to reduce Unsolicited Commercial Communication (UCC), which is a major source of annoyance for the public. It has resulted in fewer complaints filed against Registered Telemarketers (RTMs). Despite the TSPs’ efforts, UCC from Unregistered Telemarketers (UTMs) continues. Sometimes, these UTMs use messages with bogus URLs and phone numbers to trick clients into revealing crucial information, leading to financial loss.
To detect, identify, and prosecute all Unregistered Telemarketers (UTMs), the TRAI has mandated that Access Service Providers implement the UCC.
Detect the System with the necessary functionalities within the TRAI’s Telecom Commercial Communication Customer Preference Regulations, 2018 framework.
Access service providers have implemented such detection systems based on their applicability and practicality. However, because UTMs are constantly creating new strategies for sending unwanted communications, the present UCC detection systems provided by Access Service providers cannot detect such UCC.
TRAI also Directs Telecom Providers to Set Up Digital Platform for Customer Consent to Curb Promotional Calls and Messages.
Unregistered Telemarketers (UTMs) sometimes use messages with fake URLs and phone numbers to trick customers into revealing essential information, resulting in financial loss.

TRAI has urged businesses like banks, insurance companies, financial institutions, and others to re-verify their SMS content templates with telcos within two weeks. It also directed telecom companies to stop misusing commercial messaging templates within the next 45 days.
The telecom regulator has also instructed operators to limit the number of variables in a content template to three. However, if any business intends to utilise more than three variables in a content template for communicating with their users, this should be permitted only after examining the example message, as well as adequate justifications and justification.
In order to ensure consistency in UCC Detect System implementations, TRAI has directed all Access Providers to deploy UCC and detect systems based on artificial intelligence and Machine Learning that are capable of constantly evolving to deal with new signatures, patterns, and techniques used by UTMs.
Access Providers have also been directed to use the DLT platform to share intelligence with others. Access Providers have also been asked to ensure that such UCC Detect System detects senders that send unsolicited commercial communications in bulk and do not comply with the requirements. All Access Providers are directed to follow the instructions and provide an update on actions done within thirty days.
The move by TRAI is to curb the menacing calls as due to this, the number of scam cases is increasing, and now a new trend of scams started as recently, a Twitter user reported receiving an automated call from +91 96681 9555 with the message “This call is from Delhi Police.” It then asked her to stay in the queue since some of her documents needed to be picked up. Then he said he works as a sub-inspector at the Kirti Nagar police station in New Delhi. He then inquired whether she had recently misplaced her Aadhaar card, PAN card, or ATM card, to which she replied ‘no’. The scammer then poses as a cop and requests that she authenticate the last four digits of her card because they have found a card with her name on it. And a lot of other people tweeted about it.

Conclusion
TRAI directed the telcos to check the calls and messages from Unregistered numbers. This step of TRAI will curb the pesky calls and messages and catch the Frauds who are not registered with the regulation. Sometimes the unregistered sender sends fraudulent links, and through these fraudulent calls and messages, the sender tries to take the personal information of the customers, which results in financial losses.

Introduction
To combat the problem of annoying calls and SMS, telecom regulator TRAI has urged service providers to create a uniform digital platform in two months that will allow them to request, maintain, and withdraw customers’ approval for promotional calls and messages. In the initial stage, only subscribers will be able to initiate the process of registering their consent to receive promotional calls and SMS, and later, business entities will be able to contact customers to seek their consent to receive promotional messages, according to a statement issued by the Telecom Regulatory Authority of India (TRAI) on Saturday.
TRAI Directs Telecom Providers to Set Up Digital Platform
TRAI has now directed all access providers to develop and deploy the Digital Consent Acquisition (DCA) facility for creating a unified platform and process to digitally register customers’ consent across all service providers and principal entities. Consent is received and maintained under the current system by several key entities such as banks, other financial institutions, insurance firms, trading companies, business entities, real estate businesses, and so on.
The purpose, scope of consent, and the principal entity or brand name shall be clearly mentioned in the consent-seeking message sent over the short code,” according to the statement.
It stated that only approved online or app links, call-back numbers, and so on will be permitted to be used in consent-seeking communications.
TRAI issued guidelines to guarantee that all voice-based Telemarketers are brought under a single Distributed ledger technology (DLT) platform for more efficient monitoring of nuisance calls and unwanted communications. It also instructs operators to actively deploy AI/ML-based anti-phishing systems as well as to integrate tech solutions on the DLT platform to deal with malicious calls and texts.
TRAI has issued two separate Directions to Access Service Providers under TCCCPR-2018 (Telecom Commercial Communications Customer Preference Regulations) to ensure that all promotional messages are sent through Registered Telemarketers (RTMs) using approved Headers and Message Templates on Distributed Ledger Technologies (DLT) platform, and to stop misuse of Headers and Message Templates,” the regulator said in a statement.
Users can already block telemarketing calls and texts by texting 1909 from their registered mobile number. By dialing 1909, customers can opt out of getting advertising calls by activating the do not disturb (DND) feature.

Telecom providers operate DLT platforms, and businesses involved in sending bulk promotional or transactional SMS must register by providing their company information, including sender IDs and SMS templates.
According to the instructions, telecom companies will send consent-seeking messages using the common short code 127. The goal, extent of consent, and primary entity/brand name must be clearly stated in the consent-seeking message delivered via the shortcode.
TRAI stated that only whitelisted URLs/APKs (Android package kits file format)/OTT links/call back numbers, etc., shall be used in consent-seeking messages.
Telcos must “ensure that promotional messages are not transmitted by unregistered telemarketers or telemarketers using telephone numbers (10 digits numbers).” Telecom providers have been urged to act against all erring telemarketers in accordance with the applicable regulations and legal requirements.
Users can, however, refuse to receive any consent-seeking messages launched by any significant Telcos have been urged to create an SMS/IVR (interactive voice response)/online service for this purpose.
According to TRAI’s timeline, the consent-taking process by primary companies will begin on September 1.According to a nationwide survey conducted by a local circle, 66% of mobile users continue to receive three or more bothersome calls per day, the majority of which originate from personal cell numbers.
There are scams surfacing on the internet with new types of scams, like WhatsApp international call scams. The latest scam is targeting Delhi police, the scammers pretend to be police officials of Delhi and ask for the personal details of the users and the calling them from a 9-digit number.
A recent scam
A Twitter user reported receiving an automated call from +91 96681 9555, stating, “This call is from Delhi Police.” It went on to ask her to stay in the queue since some of her documents needed to be picked up. Then he said he is a sub-inspector at New Delhi’s Kirti Nagar police station. He then questioned if she had lately misplaced her Aadhaar card, PAN card, or ATM card, to which she replied ‘no’. The fraudster then claims to be a cop and asks her to validate the final four digits of her card because they have discovered a card with her name on it. And so many other people tweeted about this.
The scams are constantly increasing as earlier these scammers asked for account details and claimed to be Delhi police and used 9-digit numbers for scamming people.
TRAI’s new guidelines regarding the consent to receive any promotional calls and messages to telecommunication providers will be able to curb the scams.
The e- KYC is an essential requirement as e-KYC offers a more secure identity verification process in an increasingly digital age that uses biometric technologies to provide quick results.

Conclusion
The aim is to prevent unwanted calls and communications sent to customers via digital methods without their permission. Once this platform is implemented, an organization can only send promotional calls or messages with the customer’s explicit approval. Companies use a variety of methods to notify clients about their products, including phone calls, text messages, emails, and social media. Customers, however, are constantly assaulted with the same calls and messages as a result of this practice. With the constant increase in scams, the new guideline of TRAI will also curb the calling of Scams. digital KYC prevents SIM fraud and offers a more secure identity verification method.

Introduction
Online Gaming has gained popularity over the past few years, attracting young players worldwide and global concerns. In response to the growing fame of this industry, the Indian government has recently announced introducing a set of regulations to address various concerns and ensure a safer and more regulated online gaming environment. In this blog post, we will explore the critical aspects of these regulations and their impact on the gaming industry.
Why are Regulations needed?
Recently some games faced a ban in India – games that involve betting, games that can be harmful to the user, and games that involve a factor of addiction. Furthermore, with rising popularity, With the exponential rise of online gaming platforms in India, extensive laws to safeguard players and ensure fair gameplay needs to be implemented. Players’ protection is one of the critical factors addressing the issues which involve online addiction, underage involvement, fraud, and data privacy has become critical for the well-being of Indian gamers.
Regulatory Ambiguity: The previous legislative structure, such as the outmoded Public Gambling Act of 1867, required an update to fit the digital gambling age fully.
Outline of the New Regulations
Implementing new regulations for online gaming in India represents the government’s commitment to addressing different issues and ensuring a safer and more regulated gaming sector. Let’s have a look at these rules in detail:
National-Level Standards: The Indian government is currently working on creating national-level standards to standardise online gaming practices across all states. These rules attempt to create a uniform platform for both operators and participants. The government has also made an announcement to set SRO within 90 days to regulate online gaming.
Licencing and Compliance: To legally operate in the Indian market, online gaming firms must secure licences. The operator’s financial soundness, security measures, and adherence to responsible gaming practices will be scrutinised throughout the licencing process. Operators will need to comply with the regulations in order to maintain operations.
Measures to Promote Ethical Gaming: The new regulations emphasise player protection and ethical gaming practices. This includes steps like age verification to prevent underage involvement, self-exclusion choices for gamers who want to limit their gaming activities, and adopting tools like session limits and reality checks to promote responsible gaming.
Data Privacy: Recognising the importance of data privacy, the laws are intended to contain protections for protecting user data. To safeguard sensitive player information from unauthorised access or exploitation, online gambling operators must comply with data protection regulations and deploy strong security measures.
Restrictions on Advertising and Marketing: The legislation may limit the advertising and marketing of online gaming platforms. The emphasis will be on eliminating aggressive marketing tactics that target vulnerable people, such as kids. Stricter standards for ad content and placement may be implemented.
Anti-Fraud and Anti-Money Laundering Measures: To combat criminal activity within the gaming ecosystem, the new legislation will almost certainly force online gambling companies to employ anti-fraud and anti-money laundering measures. Operators may need to set up mechanisms to detect fraud, report suspicious activity, and work with law enforcement.
Consumer Grievance Redressal: The legislation may emphasise the construction of efficient channels for resolving consumer complaints. Players should be able to report difficulties, seek resolution, and offer feedback on their play experiences through channels. The objective is to create a transparent and accountable conflict resolution mechanism.

Impact on Online Gaming Ecosystem
Adopting new laws for online gambling in India will likely have several consequences for the gaming industry. Let us look at some of these consequences:
Increased Player Trust: Implementing restrictions will increase player confidence in online gaming platforms. Establishing clear rules and procedures and steps to safeguard participants’ interests will develop a sense of trust and transparency. This can lead to increased participation and engagement in the gaming community.
Industry Consolidation: Stricter restrictions may result in industry consolidation. Compliance with the new legislation would need resources and investments, which might favour more prominent and more established gambling firms. Smaller and more non-compliant operators may find it challenging to fulfil regulatory standards, resulting in a more consolidated gaming sector.
Technological Progress: The requirement to comply with rules could lead to technological advancements in the online gambling sector. Operators may invest in modern identity verification systems, fraud detection methods, and responsible gaming solutions to satisfy their regulatory requirements. This can result in technological breakthroughs that improve gamers’ overall gaming experience.
Foreign Investment and Collaboration: Clear laws might entice overseas investors to enter the Indian gaming business. The regulated environment may appeal to international gambling enterprises looking to enter or extend their presence in India. Collaborations between Indian and foreign gaming firms may also expand, resulting in the sharing of experience, resources, and the production of high-quality gaming products.
Legal Clarity: Implementing particular laws would give online gambling operators and users clearer legal standards. This transparency can eliminate ambiguity and possible legal issues, allowing stakeholders to navigate the gaming ecosystem with better confidence and knowledge.
Contribution to the Indian Economy: A well-regulated online gaming business has the potential to contribute to the Indian economy. It has the potential to create jobs, attract investment, and produce tax money for the government. The economic effect of the gaming ecosystem is expected to increase as it grows under the new restrictions.
Challenges and Future Approach
One of the toughest challenges will be the efficient implementation and enforcement of the new regulations. Consistency in applying the legislation across multiple jurisdictions and guaranteeing compliance by all operators would necessitate comprehensive monitoring and regulatory measures. Developing suitable enforcement organisations and transparent standards for reporting and dealing with noncompliance will be critical. Besides this, online gaming is open to more than area-specific and many gaming platforms and operates internationally. Ensuring cross-border operations is a big challenge in addressing jurisdictional challenges will be complex. Collaborative efforts between nations can regulate cross-border online gaming. There may be increased collaboration between Indian and foreign gaming firms, resulting in the exchange of information, skills, and resources. This partnership can help the Indian gaming sector flourish while attracting foreign players and investments.
Esports Development: Esports have grown in popularity worldwide, and India is no exception. The Indian esports business has the potential to thrive with proper regulation and support, drawing both players and viewers. Esports-specific factors like player contracts, tournament integrity, and licencing requirements may be addressed in the regulations.

Conclusion
Despite obstacles, India’s new online gambling legislation can potentially establish a safer and more regulated gaming sector. the future depends on successful implementation, adjusting to a shifting landscape, finding the correct balance between regulation and innovation, and promoting ethical gaming practices. The Indian online gaming business can develop sustainably with the appropriate strategy, benefiting gamers and the broader economy.

Introduction
Ministry of Electronics and Information Technology (MeitY) Announces to Centre Government to Plan to Certify Permissible Online Games.
In a recent update to the notification released by the Ministry of Electronics and Information Technology (MeitY) on April 6, MeitY has requested gaming entities to establish self-regulatory organisations (SROs) within a timeframe of 30 days or a maximum of 90 days from the date of the notification, which is April 6, 2023. The Ministry of Electronics and Information Technology (MeitY) has further announced that the central government will certify which online games are permissible until the SROs are officially established. The intention behind establishing SROs is to assist intermediaries, such as Apple or Google, in determining what constitutes a permitted online game, but the SRO will take 2-3 months to complete. In the meanwhile, the Central government will step in and determine what is a permissible online game.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 & Intermediary Guidelines and Digital Media Ethics Code Amendment Rules, 2023
By enacting these rules, the Indian government has taken decisive action to protect Indian gamers and their financial resources against scams and fraud. The rules also serve to promote responsible gaming while preventing young and vulnerable users from being exposed to indecent or abusive content.
Amendment Rules developed the concept of a “Permissible online real money game.” This designation is reserved for games that have passed a review process conducted by a self-regulatory body (SRB). Amendment rules indicate that Online Gaming Intermediaries must ensure that they do not permit any third party to host non-permissible online real money games on their platforms. This development is important because it empowers us to distinguish between legitimate and illicit real money games.
The Amendment Rules define an online gaming provider as an “intermediary” under the Information Technology Act of 2000, creating a separate classification called ‘Online Gaming Intermediary’.

Central government to certify what is an ‘Online Permissible Game’
The industry has been wondering what games come under wagering and will be banned. So, until the SROs are officially established, the government, in the interim, will certify what is a permissible game, what is wagering, and what is not wagering. Games that involve elements of wagering are going to be barred. The new regulations prohibit wagering on any outcome, whether in skill-based or chance-based games. Hence gaming applications involving wagering and betting apps will be barred.
Self-Regulatory Organizations (SROs)
According to the new regulations by the Ministry of Electronics and Information Technology (MeitY), online gaming intermediaries must establish a Self-Regulatory Body (SRO) to approve games offered to users over the Internet. The SRO must be registered with the Ministry and develop a framework to ensure compliance with the IT Rules 2021 objectives. An ‘online game’ can be registered by the SRO if it meets specific criteria, which include that the game is offered by an online gaming intermediary that is a member of the self-regulatory body, the game is not containing any content harmful to India’s interests, and complying with all relevant Indian regulations. If these requirements are met, the intermediary can display a visible registration mark indicating its registration with the self-regulatory authority.
Conclusion
MeitY found that with the rapid growth of the gaming industry, the real money gaming (RMG) sector had to be regulated properly. Rules framed must be properly implemented to stop gambling, betting, and wagering apps.
The IT Rules 2021, along with the Amendment Rules 2023, are created to take concrete action to curb the proliferation of gambling, betting, and wagering apps in India. These rules empower to issue of directives to ban specific apps that facilitate or promote such activities. The app ban directive allows the government to take decisive action by blocking access to these apps, making them unavailable for download or use within the country. This measure is aimed at curbing the negative impact of gambling, betting, and wagering on individuals and society, including issues related to addiction, financial loss, and illegal activities. Rules aim to actively combat the spread and influence of such apps and provide a safer online environment for gaming users.
The self-regulatory body in the context of online gaming will have the authority to grant membership to gaming intermediaries, register online games, develop a framework for regulation, interact with the Central Government, address user complaints, report instances of non-compliance, and take necessary actions to safeguard online gaming users.

Introduction
India has been a nation where technology penetration has been a little slower in the previous decades; however, that has changed now. Cyberspace has influenced and touched every country and has significantly diminished the gap between developing nations, developed nations, and underdeveloped nations. This has also been substantiated and strengthened during the Covid-19 pandemic as the world went into lockdown and the cyberspace was the only medium of communication and information. India witnessed a rise of 61% in terms of internet users, and a significant part of this number represented rural India.
New Standards
These standards have been released in threefold aspects covering – Digital Television Receivers, USB Type-C chargers, and Video Surveillance Systems, thus streamlining the use of gadgets and reduction of e-waste for the country.
1. Digital Television Receivers
The Indian standard IS 18112:2022 specification for digital television, and this standard would enable reception of free-to-air TV and radio channels just by connecting a dish antenna with LNB mounted on a suitable area with good signal reception. This will help in the transmission of knowledge about government initiatives and schemes, the educational content of Doordarshan, and the repository of Indian cultural programs. Doordarshan is in the process of phasing out analog transmission, and free-to-air channels will continue to be broadcast using digital satellite transmission. The keen aspects of educational and awareness programs run by the Govt and CSOs will impact more Indians than before as the Ministry of Information and Broadcast intends to increase their free channels of Doordarshan from 55 to 200 by the end of this year, which shows the importance of developments in the mass media industry.
2. USB Type C
Standard (IS/IEC 62680-1-3:2022) for USB Type-C receptacles, plugs, and cables adopting the existing global standard IEC 62680-1-3:2022. This standard provides for the requirements for USB type C ports and cables for use in various electronic devices like laptops, mobile phones, and other gadgets. This standard is similar to the new European standard, which is also aimed at the reduction of carbon emissions and e-waste; this move will result in ease for the industry and the end users. This will also contribute towards the strengthening of the cyber security aspects and prevent threats like ‘Juice Jacking’ to a massive extent.
3. Video Surveillance System
IS 16190, this standard provides a detailed outline of the aspects of a video surveillance system, such as requirements for its components like camera devices, interfaces, system requirements, and tests to ascertain the camera’s image quality on different devices. This series of standards would assist customers, installers, and users in establishing their requirements and determining the appropriate equipment required for their intended application and also provide means of evaluating the performance of the VSS objectively. This will also help in the improvement of surveillance by the individuals, and this will also help in the better investigation by Law enforcement agencies and faster apprehension of criminals, thus contributing to an overall safe society.

The Advantages
These standards are in power with the Internationally prevalent standards, thus taking the safety factors to the global aspect. This will also allow the Indian industry to create world-class products which can be shared all across the globe. This will open India to various opportunities and job avenues, thus opening the world to invest in India. The aspect of Atma Nirbhar Bharat and Digital India will be strengthened to a new level as the nation will be able to deliver products in power with quality in developed countries. The end Indian consumer will benefit the most from these upgraded standards in terms of Digital Televisions, Type ‘C’ USB chargers, and Video surveillance systems, as these impacts the consumers’ daily activities in terms of security and access to information.
- Reduction in Carbon Emission
- Production of World Class components and devices
- Boost to the economy and Atmanirbhar Bharat
- New avenues and opportunities for startups and MSMEs
- Better transmission of Knowledge
- Boosting FDI
- Improved quality of products for the end consumer
- New innovation hubs and exposure to global talents
This government move simply shows how India is working toward securing the Sustainable development Goals (SDG) by United Nations. This clearly shares the message to the world that India is ready for the future and will also be a helping hand to various developing and underdeveloped nations in the times to come.
Conclusion
These standards will significantly contribute towards the reduction of E-Waste and unnecessary accessories for daily use gadgets. This strengthens the reduction in carbon emissions and thus contributes towards the perseverance of the environment and working towards sustainable development goals. Such standards will lead the future towards securing the netizens and their new and evolving digital habits. In the current phase of cyberspace, the most essential aspect of establishing Critical Infrastructure as the same will act as a shield against the threats of cyberspace.