
Every era has its preferred method of deception. The forged signature belonged to the twentieth century; phishing email defined the early internet; today, deception has become conversational. It speaks with the authority of a police officer, the confidence of a bank manager and increasingly, the voice of someone you know. Modern cyber crime is no longer just about breaking into machines. It is about tricking people into opening the door.
For decades, cyber security has been understood as a technological problem. We have invested in stronger passwords, encrypted communication and increasingly sophisticated fraud detection systems, yet some of the most devastating cyber crimes in India involve none of these. They don’t exploit software vulnerabilities; they exploit human behaviour.
The Hackers Never Logged In
Perhaps no scam can illustrate this transformation better than the phenomenon known as “digital arrest”. Victims receive phone calls from individuals claiming to represent the Central Bureau of Investigation (CBI), Delhi Police, Customs authorities, or the Telecom Regulatory Authority of India (TRAI). These so-called authorities inform them that a parcel registered in their name contained narcotics, forged passports, or illegal documents. The conversation is escalated to a supposed senior officer who produces forged identity cards, fabricated legal notices and official-looking videos, making everything look authentic; everything other than the law.
Indian law has no concept of digital arrest. Neither the Bharatiya Nyaya Sanhita, 2023 (BNS) nor the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) authorises investigating authorities to conduct investigations over continuous video calls or require suspects to transfer money to verify their innocence.
The entire premise of this scam is legally fictitious, however widely successful. This very success raises the question: if the law never authorised such conduct, why do so many people comply? The answer lies not in technology but in human psychology.
When Deception Becomes Consent
What distinguishes modern cyber crime from its predecessors is not merely the technology employed, but the manner in which the harm is inflicted. Traditional cyber offences typically involved unauthorised access such as breaking into systems or stealing data. Social engineering has reversed this equation; now, victims voluntarily disclose passwords, authorise bank transfers or share confidential information.
The scammers manufacture this apparent consent through deception. Fear, urgency and psychological manipulation through impersonation create an environment in which victims believe that they are complying with lawful instructions rather than facilitating a crime.
This is where India’s cyber crime framework reveals its strengths and limitations. Section 66D of the Information Technology Act, 2000, criminalises cheating by impersonation through the use of computer resources, while Section 66C addresses identity theft. Depending on the circumstances, perpetrators may also be prosecuted under the BNSS for offences relating to cheating, criminal intimidation, forgery, extortion, and impersonating public servants.
However, these provisions were not drafted with Artificial Intelligence (AI)- generated voices, deepfake video calls, or psychological manipulation in mind. The law successfully criminalises the outcome, but it has yet to grapple with the evolving methods used to achieve it. The crime is changing. It is moving from unauthorised access to computers to unauthorised access to human judgement.
The Business of Manipulation
The digital arrest scam is only one manifestation of the huge economy of cyber deception. Romance scams cultivate emotional intimacy over weeks before introducing false financial emergencies. Fake courier and FedEx scams begin with an apparently routine delivery notification, then escalate into allegations of customs violations. Deepfake voice scams replicate the speech patterns of family and friends to create convincing requests for urgent financial assistance, and investment scams impersonate analysts and wealth managers through carefully curated social media profiles.
Each scam has different stories but the same architecture, following a remarkably consistent sequence of establishing credibility, manufacturing urgency, isolating the victim and preventing independent verification. Generative AI has made this model very scalable, allowing fraudsters to produce realistic voices, forged documents and convincing video calls at a speed unimaginable a few years ago.
Can the Law Keep Up?
The legal framework is not without answers, but is increasingly playing catch-up. The IT Act remains primarily focused on identity theft, impersonation, and misuse of computer resources, while the Bharatiya Sakshya Adhiniyam, 2023 (BSA) governs the treatment and admissibility of electronic evidence. Together, these statutes can address many forms of social engineering fraud, but they do not directly confront the evidentiary and regulatory problems created by synthetic media.
1. Authentication
The immediate challenge is therefore one of authentication. Where an accused disputes the authenticity of an AI-generated voice recording, manipulated video or synthetic message, courts cannot simply assume that the digital file accurately represents the underlying communication. A more appropriate approach would place greater emphasis on provenance: preserving original files and metadata, documenting how the evidence was obtained, conducting forensic examination where authenticity is disputed, and corroborating it with independent evidence such as call records, transaction logs, or contemporaneous communications.
Existing rules governing electronic evidence can provide the procedural foundation for this approach. Still, courts will increasingly need to develop consistent standards for determining when AI-generated or AI-manipulated material is sufficiently reliable to be admitted and relied upon.
2. Preventive Responsibility
The second difficulty concerns preventive responsibility. Traditional fraud often blames the victim. But AI changes this. When an AI scam perfectly mimics a loved one, blaming the victim makes little sense. This suggests a need to move beyond a purely victim-centric model of responsibility. Banks, telecom operators and digital platforms could, within their respective regulatory frameworks, be expected to adopt proportionate safeguards for high-risk transactions. For example, additional verification where transaction patterns are anomalous, stronger authentication for changes to account credentials, and mechanisms to rapidly freeze or review suspicious transfers.
Such measures would not eliminate fraud, but could reduce the extent to which a seemingly “authorised” transaction automatically ends the inquiry into responsibility.
Accordingly, the principal weakness of the present framework is not simply the absence of an offence specifically labelled “AI fraud.” Many AI-enabled frauds can already be prosecuted through existing offences relating to cheating, personation, identity theft and unauthorised use of computer resources. The larger gap lies in evidence and prevention: determining whether synthetic communications are authentic, establishing who generated or disseminated them, and deciding when institutions should bear responsibility for failing to detect objectively unusual transactions.
The law therefore needs clearer evidentiary guidance for synthetic media, stronger and proportionate preventive duties for digital intermediaries, and a more nuanced framework for allocating liability where fraud is carried out through apparently authorised transactions. As AI continues to blur the line between authentic and fabricated communications, the law must consequently evolve from a predominantly reactive framework into one capable of anticipating and mitigating emerging forms of cyber-enabled deception.
Distrust is the New Password
For years, cyber security campaigns have warned citizens not to share OTPs, passwords or banking credentials. While these warnings remain vital, they do not address one of the most significant vulnerabilities in cyber space. Cyber crime will not be defined by more sophisticated malware but by more persuasive conversations. Criminals no longer need to bypass security systems when they can convince victims to dismantle them voluntarily.
Perhaps this is the defining lesson of India’s billion-dollar scam economy: the greatest vulnerability was not software, but our psychology. The strongest firewall we possess may not be technological at all, but simply the willingness to pause, question authority, and remember that sometimes the most dangerous cyber scam begins with a perfectly polite phone call.
Maanya Bhambhal, currently an undergraduate student at OP Jindal Global University, has contributed this article to the blog.