The Era of App Bans
Not long ago, public discourse on cyber threats was dominated by app bans. Concerns over data privacy and national security, often linked to foreign-owned applications, led to high-profile blockades. This approach, while decisive, framed the problem as an external
threat that could be contained by shutting a digital door. It created a straightforward narrative: if a platform was problematic, removing it from app stores was the solution. This reactionary, whack-a-mole strategy addressed visible symptoms but left the underlying vulnerabilities of a rapidly digitizing India largely unaddressed. The conversation was about specific actors, not the evolving nature of cybercrime itself.
A New Wave of Financial Fraud
Today, the biggest cyber threat for most Indians is not a foreign app but a text message or phone call originating much closer to home. Financial cyber fraud has exploded, becoming the most common and damaging form of online crime. India's digital fraud rate was nearly double the global average in 2025. Scams involving UPI payments, fraudulent investment schemes, and so-called 'digital arrest' scenarios—where criminals impersonate law enforcement—are rampant. In 2025 alone, over 2.4 million financial fraud complaints were filed on the National Cyber Crime Reporting Portal (NCRP), with reported losses running into thousands of crores. This shift has made the threat intensely personal, moving the debate from abstract data privacy concerns to the immediate risk of losing one's life savings.
The Rise of AI-Driven Disinformation
Beyond financial losses, the debate now grapples with threats to the very fabric of social trust: AI-generated deepfakes and coordinated disinformation campaigns. With hundreds of millions of social media users in India, the potential for manipulated audio and video to sway public opinion, incite violence, or damage reputations is immense. Deepfake technology, once a novelty, is now a recognized tool for creating non-consensual pornography, spreading political misinformation, and committing fraud. Recognizing this, the government has moved to regulate AI-generated content, with new IT rules mandating quick takedowns of synthetic media. This marks a significant pivot from policing platforms to policing a type of malicious content, irrespective of where it appears.
From Reactive Bans to Holistic Regulation
The government's strategy is also evolving. Instead of ad-hoc bans, the focus is shifting toward creating a comprehensive legal and institutional framework. The establishment of the Indian Cyber Crime Coordination Centre (I4C) and the National Cyber Crime Reporting Portal (helpline 1930) provides citizens with a centralized mechanism to report crime and seek redress. Furthermore, legislation like the Digital Personal Data Protection (DPDP) Act, which is being implemented in phases, aims to create a robust data privacy regime. Discussions around the forthcoming Digital India Act, intended to replace the outdated IT Act of 2000, signal an ambition to govern the entire digital ecosystem—from online safety and intermediary liability to emerging technologies like AI—in a more integrated way.












