This article is written by Suhani Sharma, a Fifth Year B.A. LL.B. student at Army Law College, Pune.
Abstract
Digital arrest scams have emerged as one of the most organised and financially devastating forms of cybercrime in India. In this scheme, fraudsters impersonate officers of law enforcement agencies and compel victims ,typically through sustained video calls ,to transfer large sums of money under the threat of fabricated criminal charges. This article examines the anatomy of digital arrest scams, evaluates their legal treatment under the Information Technology Act 2000 and the Bharatiya Nyaya Sanhita 2023, identifies the structural challenges that impede effective prosecution, and considers the directions in which legislative and institutional reform must move. The article also reviews landmark judicial interventions, including the Supreme Court’s suo motu directions of 2025, to assess how India’s legal architecture is responding to a threat that continues to evolve in sophistication.
I. Introduction
The phrase “digital arrest” entered the Indian public consciousness with considerable force in 2024, after the Prime Minister, in the 115th episode of his radio programme Mann Ki Baat, publicly warned citizens against a scam in which cybercriminals pose as police officers, Central Bureau of Investigation agents, or Enforcement Directorate officials and “arrest” victims virtually through video calls.[1] The mechanics of the fraud are calculated to overwhelm. A victim receives a call ,often on WhatsApp or Skype ,from a person dressed in what appears to be a police uniform, seated before what appears to be a government office backdrop. The caller accuses the victim of a grave criminal offence: narcotics trafficking, money laundering, identity theft. The victim is told that a warrant has been issued, that an FIR has been registered, and that the only way to avoid immediate physical arrest is to remain on the video call ,sometimes for hours, sometimes for days ,and to transfer money into an account specified by the caller.
The scheme is not merely a confidence trick. It is an organised criminal enterprise that has, according to data compiled by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs, caused losses of approximately Rs 1,935 crore to Indian citizens in the year 2024 alone,[2] with over 1.23 lakh complaints registered on the National Cyber Crime Reporting Portal in the same year.[3] The present article analyses the legal framework under which digital arrest scams are prosecuted, identifies the challenges that diminish the effectiveness of that framework, examines relevant judicial pronouncements, and proposes directions for reform.
II. Understanding the Phenomenon: Modus Operandi and Scale
A digital arrest scam typically unfolds in three stages. In the first stage, the victim receives a telephone call ,frequently spoofed to appear as though it originates from a government agency ,alleging that a package in their name has been intercepted containing contraband, that their mobile number is linked to a fraud case, or that their Aadhaar number has been used for illicit activity. In the second stage, the caller transfers the victim to a “senior officer” via video call. This officer, often in a realistic-looking police or CBI uniform and operating against a digitally generated backdrop of a government office, produces forged documents ,fabricated FIRs, arrest warrants, even purported Supreme Court orders ,and informs the victim that they are under “digital arrest” and must not leave the video call or contact anyone until the matter is resolved. In the third and final stage, the victim is coerced into transferring money to release themselves from the threat of physical arrest.[4]
The Ministry of Home Affairs, in its written reply to the Lok Sabha dated 3 December 2024, confirmed that digital arrest complaints had more than tripled between 2022 and 2024, with recorded financial losses escalating from approximately Rs 91 crore in 2022 to Rs 1,935 crore in 2024 ,a twenty-one-fold increase in two years.[5] The I4C has further established that approximately 45 to 50 per cent of such scams originate from organised call centres located in Southeast Asian countries, particularly Cambodia, Myanmar, Laos, and Thailand,[6] where what investigators describe as “scam factories” operate with distinct verticals: one responsible for sourcing victim data (including from social media, Aadhaar databases, and PAN records), another for executing the calls, and a third for laundering the proceeds through networks of “mule” bank accounts.
The NCRB’s Crime in India 2024 Report records that senior citizens constitute a disproportionately large share of victims, a pattern that the Supreme Court of India specifically noted when it took suo motu cognisance of the issue in October 2025.[7] High-profile cases underscore both the gravity and the audacity of these frauds: an Associate Professor at a leading medical institution in Lucknow lost Rs 2.81 crore after being told by a fake CBI official that her account had been used for money laundering; the Chairman and Managing Director of the Vardhman Group, an 82-year-old industrialist, was defrauded of Rs 7 crore by fraudsters impersonating multiple government agencies including the Supreme Court of India itself.
III. The Legal Framework Governing Digital Arrest Scams
3.1 Information Technology Act, 2000
The Information Technology Act 2000 (IT Act) provides the primary statutory basis for prosecuting the digital dimension of these offences. Section 66C of the IT Act criminalises identity theft ,the fraudulent or dishonest use of another person’s electronic signature, password, or any other unique identification feature.[8] In a digital arrest scam, the fraudster appropriates the digital identity of a law enforcement officer, using fabricated credentials, forged letterheads, and simulated government portals to impersonate an official. Section 66D separately penalises cheating by personation through computer resources or communication devices, which corresponds precisely to the impersonation of a CBI officer or ED official in a video call.[9] Both offences are punishable with imprisonment of up to three years and a fine.
Where a digital arrest scam targets critical infrastructure or is conducted in a manner that threatens the unity, integrity, or security of the State ,such as impersonating a senior judicial authority or fabricating Supreme Court orders ,Section 66F of the IT Act, which addresses cyber terrorism and prescribes punishment extending to life imprisonment, may also be invoked.[10] Additionally, Sections 43 and 66 of the IT Act are applicable where the scammers gain unauthorised access to the victim’s computer or device, or where they deploy malicious applications (APKs) to remotely access financial accounts.
3.2 Bharatiya Nyaya Sanhita, 2023
The Bharatiya Nyaya Sanhita 2023 (BNS), which replaced the Indian Penal Code 1860 with effect from 1 July 2024, consolidates and strengthens several provisions that are directly applicable to digital arrest scams. Section 318 of the BNS, which consolidates the erstwhile Sections 415, 417, 418, and 420 of the IPC into a single, graduated provision on cheating, is the most widely invoked in digital fraud cases.[11] The section punishes deception that dishonestly or fraudulently induces the victim to deliver property or take an action that causes wrongful loss, with imprisonment up to seven years and a fine under its most serious sub-clause (Section 318(4)).
Section 319 of the BNS specifically penalises cheating by personation ,where a person pretends to be someone else and by that impersonation deceives another ,and is applicable to every instance in which a digital arrest fraudster poses as a CBI officer, customs official, or magistrate.[12] Section 204 of the BNS penalises impersonation of a public servant, which captures the act of dressing in a police uniform, carrying a fake identity card, or displaying forged official credentials during a digital arrest call.[13] Section 351 extends the offence of criminal intimidation to threats made “by any means,” which the legislature specifically intended to capture electronic threats, bringing intimidatory digital arrest scripts squarely within its ambit.[14]
Critically, Section 111 of the BNS introduces, for the first time in codified Indian criminal law, the offence of organised crime, defined to expressly include cybercrime committed by a syndicate through coercion, intimidation, or any other unlawful means for material benefit.[15] Given that digital arrest scams are coordinated by transnational criminal organisations with specialised operational verticals, Section 111 is potentially the most powerful provision available. It provides for punishment up to life imprisonment where the offence causes death, and not less than five years in other cases. The forgery of FIRs, warrants, and court orders ,a defining feature of digital arrest scams ,is separately addressed under Section 336 of the BNS.[16]
3.3 Intermediary Liability and Regulatory Provisions
Platforms such as WhatsApp and Skype are the primary conduits through which digital arrest calls are conducted. Section 79 of the IT Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 impose due diligence obligations on such intermediaries, including requirements to remove unlawful content upon knowledge and to cooperate with law enforcement investigations.[17] In the context of digital arrests, the Ministry of Home Affairs has issued directions to WhatsApp to block device IDs (IMEIs) of repeat offenders, deploy AI-based tools to detect impersonation of law enforcement agencies, and introduce SIM-binding mechanisms for accounts. As of November 2024, the government had blocked over 83,668 WhatsApp accounts and 3,962 Skype IDs identified in connection with digital arrest scams, along with 7.81 lakh SIM cards and over 2 lakh IMEIs.
IV. Landmark Judicial Interventions
4.1 Shreya Singhal v Union of India (2015)
While not directly concerned with digital arrest scams, Shreya Singhal v Union of India remains constitutionally foundational to the regulation of online conduct in India.[18] The Supreme Court’s striking down of Section 66A of the IT Act established that penal provisions governing online speech must satisfy the tests of clarity, proportionality, and compliance with Article 19(2) of the Constitution. In the context of digital arrest fraud, this judgment is significant because it prevents law enforcement from using overly broad provisions to prosecute victims or witnesses who speak out against digital arrest scams online, and it requires that any future legislative response to digital arrests be drawn with the requisite precision.
4.2 Justice K.S. Puttaswamy (Retd.) v Union of India (2017)
The nine-judge constitutional bench decision in Justice K.S. Puttaswamy v Union of India declared that the right to privacy is a fundamental right guaranteed under Articles 14, 19, and 21 of the Constitution of India.[19] This judgment has direct relevance to digital arrest scams in two respects. First, digital arrest fraudsters routinely breach the informational privacy of victims by accessing and exploiting personal data ,Aadhaar numbers, PAN details, bank account information, and social media history ,to lend credibility to their false accusations. The constitutional protection of informational privacy provides a basis for demanding stronger data protection obligations from platforms and data fiduciaries that enable such data harvesting. Second, the judgment’s emphasis on proportionality as a test for State action informs the standard against which any surveillance-based anti-digital arrest measures must be evaluated.
4.3 In Re: Digital Arrest Scam Cases, Supreme Court Suo Motu Writ (2025)
The most direct and consequential judicial intervention on digital arrest scams came on 1 December 2025, when a bench of the Supreme Court of India comprising the Chief Justice Surya Kant and Justice Joymalya Bagchi issued sweeping directions in a suo motu writ petition arising from a complaint by an elderly couple from Ambala, Haryana, who lost Rs 1.5 crore to fraudsters brandishing forged Supreme Court orders.[20] The Court stated that “digital arrest scams require the immediate attention of the premier investigating agency of the country,” and directed the Central Bureau of Investigation to lead a nationwide investigation, noting that the fragmentation of state-level inquiries had failed to produce an effective response against transnational criminal networks.
The bench further directed all States and Union Territories that had not yet accorded general consent to the CBI to do so immediately, thereby removing jurisdictional barriers to a unified national investigation. Social media intermediaries were directed to cooperate fully with the CBI. The Reserve Bank of India was asked to examine whether AI and machine learning tools could be deployed to detect and automatically freeze mule accounts.[21] The Department of Telecommunications was directed to submit proposals to prevent the issuance of multiple SIM cards in a single name ,a practice identified as a primary enabler of digital arrest operations.[22] The CBI was also authorised to seek the assistance of Interpol in cases with cross-border dimensions. This judgment signals a decisive shift from ad hoc state-level responses to a structured, centrally coordinated legal and institutional response.
V. Enforcement Challenges
5.1 Cross-Border Jurisdiction
The dominant operational challenge in prosecuting digital arrest scams is their transnational character. A majority of the call centres involved are located in Southeast Asian countries with which India has limited bilateral Mutual Legal Assistance Treaty (MLAT) arrangements.[23] The process of serving commissions rogatoire, obtaining foreign call records, or securing the physical handover of suspects is slow, treaty-dependent, and subject to the cooperation of foreign sovereigns who may have little domestic incentive to prioritise Indian complaints. The Supreme Court’s 2025 direction for the CBI to engage Interpol addresses this gap at the investigative level, but the absence of a binding international cybercrime treaty remains a structural constraint.
5.2 Mule Accounts and Money Laundering
Proceeds of digital arrest scams are routed through multiple layers of “mule” bank accounts ,accounts opened in the names of third parties, often without their knowledge or under economic duress ,to obscure the trail from victim to beneficiary. The Prevention of Money Laundering Act 2002 is applicable to these laundering transactions,[24] but the speed with which funds are moved across accounts (sometimes within minutes of receipt) consistently outpaces the ability of enforcement agencies and banks to freeze accounts. The I4C’s Citizen Financial Cyber Fraud Reporting and Management System, launched in 2021, had saved over Rs 3,431 crore across more than 9.94 lakh complaints by 2024 through rapid account freezing,[25] but the percentage of total defrauded funds recovered remains low ,approximately 19 per cent by early 2026, up from 6 per cent in 2021.
5.3 Underreporting and Investigative Capacity
A substantial proportion of digital arrest scam victims do not report the offence. The psychological impact of having been manipulated ,combined with social stigma, particularly where the scam involved allegations of a sexual or criminal nature ,leads many victims, especially elderly persons, to absorb the loss silently. NCRB data indicates that conversion of cybercrime complaints into FIRs remains below 25 per cent.[26] At the investigative stage, most district-level cybercrime cells lack the digital forensic infrastructure and trained personnel required to analyse server logs, trace VoIP call origins, or recover cryptocurrency transactions. The majority of the 6.69 lakh SIM cards blocked by the Government of India by November 2024 were identified through complaints rather than proactive intelligence, which reflects a reactive rather than preventive enforcement posture.
VI. The Need for Reform
The foregoing analysis discloses that while India’s existing legal framework ,constituted by the IT Act 2000, the BNS 2023, and the associated regulatory rules ,is, in principle, broad enough to cover digital arrest offences, its practical enforcement is undermined by structural and institutional deficiencies. The following reforms are warranted.
First, India should enact a standalone provision or dedicated chapter specifically targeting digital impersonation of law enforcement authorities. While Section 204 of the BNS addresses impersonation of a public servant, there is no provision that captures the combination of sustained psychological confinement, extortion, and digital impersonation that characterises a digital arrest scam. A purpose-built offence with a mandatory minimum sentence and extended territorial jurisdiction would fill this gap.
Second, the Digital Personal Data Protection Act 2023 must be operationalised expeditiously through its supporting rules and regulatory framework.[27] The data that scammers use to personalise and lend credibility to digital arrest calls ,Aadhaar numbers, PAN details, bank account information ,is sourced from either data breaches or careless data sharing by companies. Robust data protection enforcement and significant penalties for data breaches would reduce the quality of intelligence available to scam operators.
Third, the due diligence obligations of intermediaries under Rule 3 of the IT Rules 2021 should be supplemented by sector-specific guidelines requiring video communication platforms to implement caller identity verification, AI-based detection of impersonation of law enforcement symbols and uniforms in video calls, and mandatory warnings when calls from unverified accounts cross a threshold duration.[28] The MHA’s current directions to WhatsApp represent an administrative measure; statutory codification of platform obligations would provide a more durable and enforceable basis.
Fourth, following the Supreme Court’s 2025 directions,[29] the RBI should mandate real-time AI-based anomaly detection in the banking system capable of flagging transfers to newly opened accounts that receive large sums within hours of account activation ,a pattern characteristic of mule account activity. Banks in whose systems mule accounts are opened negligently or through complicit branch officers should face proportionate regulatory consequences under the Prevention of Money Laundering Act 2002.
VII. Conclusion
Digital arrest scams represent a sophisticated convergence of technology, social engineering, and organised crime that has already extracted thousands of crores of rupees from Indian citizens and shaken public confidence in digital institutions. India’s legal framework ,comprising the Information Technology Act 2000, the Bharatiya Nyaya Sanhita 2023, and the intermediary guidelines ,contains sufficient legal provisions to address the constituent elements of these offences. However, the absence of a specific statutory offence of digital impersonation, deficiencies in cross-border enforcement, inadequate banking-sector surveillance, and the slow operationalisation of data protection law continue to leave significant gaps.
The Supreme Court’s suo motu intervention in December 2025 ,centralising investigations under the CBI, directing multi-agency coordination, and compelling regulatory action from the RBI and the Department of Telecommunications ,signals that the judiciary has recognised the inadequacy of the existing institutional response. Whether this judicial energy translates into durable legislative and regulatory reform will determine whether India’s legal system can keep pace with the rapidly evolving architecture of digital fraud. The protection of citizens ,particularly the elderly and the digitally vulnerable ,from the paralysing trauma of a digital arrest demands nothing less than that reform be pursued with the same sense of urgency that the Supreme Court brought to its December 2025 directions.
[1]Prime Minister Narendra Modi, Mann Ki Baat (Episode 115, All India Radio, 27 October 2024).
[2]Indian Cyber Crime Coordination Centre (I4C), Ministry of Home Affairs, Government of India, Annual Report 2024 (MHA 2025).
[3]ibid.
[4]Ministry of Home Affairs, Government of India, Press Information Bureau, ‘Alert Against Incidents of Blackmail and Digital Arrest by Cyber Criminals Impersonating State/UT Police, NCB, CBI, RBI and Other Law Enforcement Agencies’ (PIB, December 2024) <https://www.pib.gov.in/Pressreleaseshare.aspx?PRID=2082761> accessed 28 June 2026.
[5]Ministry of Home Affairs, Government of India, Written Reply to Lok Sabha Unstarred Question No 1283 (3 December 2024) <https://www.mha.gov.in/MHA1/Par2017/pdfs/par2024-pdfs/LS03122024/1283.pdf> accessed 28 June 2026.
[6]I4C (n 2).
[7]National Crime Records Bureau, Crime in India 2024 (Ministry of Home Affairs, Government of India 2025).
[8]ibid s 66C.
[9]Information Technology Act 2000 (Act No 21 of 2000) s 66D.
[10]ibid s 66F.
[11]Bharatiya Nyaya Sanhita 2023 (Act No 45 of 2023) s 318.
[12]ibid s 319.
[13]ibid s 204.
[14]ibid s 351.
[15]ibid s 111.
[16]ibid s 336.
[17]Information Technology Act 2000 (Act No 21 of 2000) s 79; Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021.
[18]Shreya Singhal v Union of India (2015) 5 SCC 1 (Supreme Court of India).
[19]Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1 (Supreme Court of India).
[20]In Re: Digital Arrest Scam Cases (Suo Motu Writ Petition No ___ of 2025) (Supreme Court of India, 1 December 2025); see ‘Digital Arrest Scam: SC Orders Pan-India CBI Probe’ The Tribune (New Delhi, 1 December 2025).
[21]ibid; ‘Supreme Court Assigns CBI to Lead Charge Against Cyber Rackets’ The Week (1 December 2025).
[22]In Re: Digital Arrest Scam Cases (n 20).
[23]Telecommunications Act 2023 (Act No 44 of 2023); Ministry of Home Affairs, Government of India, I4C Report (n 2).
[24]Prevention of Money Laundering Act 2002 (Act No 15 of 2003).
[25]Ministry of Home Affairs, National Cyber Crime Reporting Portal <https://cybercrime.gov.in> accessed 28 June 2026; Citizen Financial Cyber Fraud Reporting and Management System, I4C.
[26]I4C (n 2); Ministry of Home Affairs, Written Reply to Lok Sabha (n 4).
[27]Digital Personal Data Protection Act 2023 (Act No 22 of 2023).
[28]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, r 3.
[29]In Re: Digital Arrest Scam Cases (n 20).