A Digital Epidemic: The Scale of Online Fraud
India's rapid digitalisation has been transformative, but it has also opened the door to a surge in cybercrime. According to official data, the number of cybercrime complaints has skyrocketed in recent years. Between 2021 and 2025, complaints registered
on the National Cybercrime Reporting Portal grew from around 2.6 lakh to 24 lakh. The financial impact is even more staggering, with reported losses increasing dramatically over the same period. This isn't just about isolated incidents; it signifies a growing and organised threat. Fraud is the primary driver, accounting for the vast majority of all registered cybercrimes. Scammers are using increasingly sophisticated methods, from AI-powered phishing campaigns to social engineering tactics that are harder than ever to detect.
Understanding Multi-Platform Fraud
Today’s scams are rarely a one-shot attempt. Multi-platform fraud is a coordinated attack where criminals use information gathered from one service to exploit you on another. For example, a scammer might find your personal details on a social media profile, use that information to gain your trust in a WhatsApp message, and then send you a malicious link to a fake banking or e-commerce website to steal your financial credentials. Scammers may impersonate law enforcement officials in 'digital arrest' scams, pose as delivery agents, or create fake investment schemes. They exploit the trust we place in technology by tampering with QR codes for payments or using screen-sharing apps under the guise of providing technical support to gain access to your device. This interconnectedness means a single weak link in your digital life can create a domino effect, putting all your accounts at risk.
The First Line of Defence: A Sceptical Mindset
Before any technology, your strongest shield is a healthy dose of scepticism. The core of most online fraud is social engineering—tricking you into giving up information or authorising a payment willingly. Always question unsolicited communications, whether it's an email, an SMS, or a phone call. Banks, reputable companies, and government agencies will never ask for your PIN, OTP (One-Time Password), or full password over the phone or email. Be wary of any message that creates a false sense of urgency, such as threatening to suspend your account or offering a prize that is too good to be true. Remember, if you did not initiate a transaction or request, you should never need to enter a PIN or OTP to receive money.
Essential Controls for Digital Hygiene
Building strong digital habits is crucial for protecting yourself across all platforms. Start with your passwords: use strong, unique passwords for every account and consider using a password manager to keep track of them. The single most effective step you can take is to enable multi-factor authentication (MFA) or two-factor authentication (2FA) wherever it is offered—on your email, social media, and especially your financial apps. Regularly review the privacy settings and app permissions on your phone and social media accounts. Be cautious about what you share publicly, as details like your birthday or hometown can be used by hackers. Finally, always keep your software and apps updated to ensure you have the latest security patches.
Securing Your Financial Transactions
When it comes to your money, extra vigilance is required. For UPI and other digital payments, always verify the recipient's details before sending money. Scammers often misuse the 'request money' feature, so scrutinise any such requests from unknown contacts. A critical rule to remember is that you only scan a QR code to send money, not to receive it. Avoid using public Wi-Fi for financial transactions, as these networks can be insecure. Only download financial and UPI apps from official sources like the Google Play Store or Apple App Store. Enable real-time transaction alerts for all your accounts and monitor your transaction history regularly to spot any unauthorised activity immediately.












