The Scale of India's Scamdemic
The numbers are staggering. In 2024 alone, Indians reportedly lost over ₹19.36 billion to cybercrimes, a twentyfold increase from just two years prior. Scams like 'digital arrest', where fraudsters impersonate police or CBI officials and extort money
under threat of immediate arrest, have become terrifyingly common. These criminals exploit every digital avenue available: unsolicited calls, SMS messages, and increasingly, encrypted chat apps like WhatsApp and Telegram. The government's response has been evolving, but the core problem remains: scammers can easily acquire SIM cards, set up fraudulent websites, and contact millions of potential victims with near-total anonymity.
A New Playbook: Proactive Prevention
Instead of only reacting after money is lost, the government is now focused on prevention, placing the onus on the digital intermediaries that enable these scams. This proactive stance involves several key initiatives. The Sanchar Saathi portal, along with its 'Chakshu' feature, allows citizens to report suspected fraud communications received via call, SMS, or WhatsApp. This data helps the Department of Telecommunications (DoT) identify and disconnect fraudulent numbers before they can target more people. Recent amendments to the IT Rules have also drastically shortened the time platforms have to take down unlawful content—from 36 hours down to just 3 hours for a government or court order, and a mere 2 hours for sensitive issues like impersonation.
WhatsApp and Telegram: The Encryption Debate
Messaging giants WhatsApp and Telegram are at the heart of the new oversight push. Their end-to-end encryption, designed to protect user privacy, also provides a shield for scammers. The government is concerned that features like anonymous usernames could dramatically increase phishing and fraud. Authorities have sent notices to these platforms, questioning their fraud mitigation strategies and seeking greater accountability. While the government has not demanded a break in encryption, it has made it clear that platforms cannot abdicate responsibility, warning Meta (WhatsApp's parent company) that compliance is not optional and that failure to act could risk losing their 'safe harbour' protection, which shields them from liability for user-generated content.
GoDaddy: The Fight Over Domain Privacy
The battle extends to the very infrastructure of the internet. Scammers often use websites with misleading names to appear legitimate. Following a case brought by major brands like Amazon and Microsoft, the Delhi High Court issued sweeping orders against domain registrars like GoDaddy. The court ruled that privacy protection on domain registrations should no longer be the default, and owner details should be made available upon legitimate request. GoDaddy has appealed this, arguing it would expose the personal data of legitimate site owners—from journalists to small businesses—to stalking and harassment, potentially violating privacy laws like the EU's GDPR. The company warns this could make the internet less safe for everyone, not just criminals.
Truecaller: Caught in the Middle
Even platforms designed to fight spam are facing new scrutiny. Truecaller, a widely used caller ID app, has clashed with the Telecom Regulatory Authority of India (TRAI). The regulator has reportedly prevented Truecaller from marking calls from the official '1400' and '1600' series—designated for commercial and service calls—as spam, even if they are reported as such by users. Truecaller argues this restriction limits its ability to protect users, as fraudsters can misuse these official-looking numbers. The company has introduced a 'Frequently Blocked' tag as a workaround but maintains that evidence-based caller ID is crucial for user safety.












