Cyber Crime In India : Cyber Phishing - Cheating by personation

Cyber Phishing in India 2026: AI Attacks, Social Media Fraud & Bank Security Laws

Cyber Phishing in India: The Changing Face of a Growing Threat and Cheating

In India UPI, mobile banking, Internet Banking, e-commerce, and social media have become inseparable from daily life — and that same convenience has made ordinary citizens the primary target of cyber phishing. What used to be a badly-worded email asking for a bank password has evolved into AI-generated messages, automated bot networks, and social-media-driven personal attacks that are far harder to detect through cyber forensic and, legally, far harder to found the accused.

This piece breaks the problem into its parts: what phishing is, how it has modernized, how social media has become its biggest hunting ground, and why the mobile-banking link makes the damage so severe — with reference to the Indian legal framework that governs it.


1. What Is Cyber Phishing?

Someone has entered into our private space and obtained our personal details. These details are being misused to threaten, intimidate, or attack the victim. Phishing is a form of cyber fraud in which an attacker impersonates a trustworthy entity — a bank, a government department, an employer, a delivery service, or even a known contact — to trick a victim into revealing sensitive information or taking a harmful action. This typically includes:

  • Personal Information
  • Images
  • Login credentials and passwords
  • Debit/credit card numbers, CVV, and OTPs
  • UPI PINs and banking app credentials
  • Aadhaar, PAN, and other identity documents
  • Direct transfer of money under a false pretext

Legal Characterization in India

Phishing does not exist as a single standalone offence with that exact name in Indian statute. Instead, it is prosecuted through a combination of provisions:

  • Section 66 (IT Act, 2000) — computer-related offences, dishonestly or fraudulently accessing a computer resource.
  • Section 66C (IT Act, 2000) — identity theft, including fraudulent use of another person's electronic signature, password, or unique identification.
  • Section 66D (IT Act, 2000) — cheating by personation using a computer resource; the provision most directly applied to phishing and vishing scams.
  • Section 43 (IT Act, 2000) — civil liability and compensation for unauthorized access or data theft, invocable before the Adjudicating Officer without a criminal case.
  • Section 72 (IT Act, 2000) and the Digital Personal Data Protection Act, 2023 (DPDP Act) — cover breach of confidentiality and unlawful processing of personal data collected through phishing.
  • Relevant cheating and forgery provisions under the Bharatiya Nyaya Sanhita, 2023 (BNS), which now runs alongside the IT Act for fraud-related offences.

In short, phishing sits at the intersection of cyber law, data protection law, and general criminal law — which is part of why prosecution is often slow and cross-jurisdictional.


2. The Modern Face of Phishing: AI, Bots, and API-Driven Attacks

The stereotype of a phishing attack — a lone scammer typing out a fake email — no longer reflects how most large-scale campaigns work.

2.1 Phishing Without a Human Footprint

Modern phishing operations increasingly rely on:

  • AI-generated content — Large language models draft highly convincing, grammatically flawless phishing emails and SMS messages, tailored in tone and language to the target (including regional Indian languages), removing the broken-English red flag that once made phishing easy to spot.
  • API-driven automation — Attackers use automated scripts and API agents to send thousands of personalized messages, generate fake payment links, and even operate fake customer-support chatbots that interact with victims in real time, with no human directly typing a single message.
  • Bot networks — Coordinated bot accounts run phishing campaigns at scale across email, SMS, and messaging apps, adapting their scripts dynamically based on how a victim responds.
  • Voice cloning and deepfake audio ("vishing") — AI voice synthesis impersonates bank officials, relatives, or employers in phone calls, adding a layer of deception that text-based filters cannot catch.

2.2 Why This Matters Legally

This shift creates real evidentiary and jurisdictional challenges:

  • Attribution becomes harder. When a bot or an API agent — often hosted on servers outside India — generates and sends the phishing content, establishing who committed the act under Section 66D becomes a multi-layered investigation involving intermediaries, telecom providers.
  • Intermediary liability comes into play. Under the IT Rules, 2021 (as amended in 2023), platforms, telecom operators, and payment intermediaries carry due-diligence obligations to detect and report such fraudulent activity, and failure to do so can expose them to loss of safe-harbour protection under Section 79 of the IT Act.

3. Phishing Through Social Media

Social media has become one of the most effective phishing environments precisely because it blends personal trust with public exposure. Profile pictures and personal information are commonly exploited in phishing attacks. In recent cyberattacks, such information has been misused to impersonate individuals, deceive victims, and facilitate threats or other forms of cybercrime.

3.1 How Attackers Collect Victim Data

  • Public profile scraping — Names, birthdays, workplaces, family details, and location tags are harvested from public posts to build a convincing profile of the target.
  • Fake friend requests and cloned profiles — Attackers impersonate real contacts to gain access to a victim's private circle, then send phishing links disguised as shared photos, job offers, or investment opportunities.
  • Quizzes, contests, and "giveaway" forms — Seemingly harmless quizzes extract answers to common security questions (mother's maiden name, first school, pet's name) used to bypass account recovery.
  • Romance and relationship-based scams — Prolonged personal engagement builds trust before requesting money or sensitive information — a pattern that has grown sharply on dating and social platforms.

3.2 Personal Attacks and Targeted Harassment

Beyond financial fraud, social media phishing frequently escalates into targeted personal attacks: stolen private photos or conversations are used for blackmail (sextortion), and stolen identity details are used to open fraudulent accounts or loans in the victim's name.

Relevant legal provisions:

  • Section 66E (IT Act, 2000) — violation of privacy through capturing, publishing, or transmitting images of a private area without consent.
  • Section 67 / 67A (IT Act, 2000) — publishing or transmitting obscene or sexually explicit material electronically.
  • Section 354D, IPC / corresponding BNS provisions — cyberstalking.
  • DPDP Act, 2023 — unauthorized collection and processing of personal data, with victims entitled to file grievances with the Data Protection Board of India.
  • Platforms are also bound by IT Rules, 2021 to take down non-consensual intimate content and impersonating accounts within a stipulated time once notified.

This form of phishing is genuinely difficult to police because the attacker often operates from outside the victim's social circle but uses information from that circle, and the harm compounds — financial loss, reputational damage, and psychological distress often occur together.


4. The Bank–Mobile Connection: Why the Damage Is So Severe

The defining feature of the Indian digital ecosystem is that almost everything — banking, identity verification, UPI, insurance, and even government benefits — is tied to a single mobile number.

4.1 The Single Point of Failure

  • A phished OTP or SIM-swap attack can give an attacker access to UPI apps, net banking, credit card OTPs, and linked wallets simultaneously, because most banks and payment apps authenticate solely through the registered mobile number.
  • SIM-swap fraud, where an attacker fraudulently obtains a duplicate SIM card, is a growing companion crime to phishing — the phishing step harvests enough personal data (Aadhaar number, address, date of birth) to convince a telecom outlet to issue a replacement SIM.
  • Because UPI, net banking, and e-commerce wallets are often cross-linked, a single successful phishing attack can drain multiple accounts in minutes, well before a victim notices unauthorized activity.

4.2 Legal and Regulatory Response

  • RBI guidelines require banks to have real-time fraud monitoring and to limit customer liability for unauthorized electronic transactions if reported within stipulated timelines — victims who report promptly (typically within 3 working days) are entitled to zero or limited liability under RBI's Customer Protection framework.
  • Section 43A (IT Act, 2000) and the DPDP Act, 2023 place a duty on banks and payment platforms as data fiduciaries to implement "reasonable security practices," and failure to do so can result in compensation claims.
  • Victims can approach:
    • The National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline for immediate reporting of financial fraud, which can trigger fund-freeze requests to receiving banks.
    • The Banking Ombudsman for disputes over unauthorized transaction liability.
    • The Adjudicating Officer under Section 46, IT Act for compensation claims up to ₹5 crore, or civil courts for higher claims.
best cyber advocate in kerala - Advocate Neeraj T Narendran

Conclusion

Cyber phishing in India has evolved from crude, easily-spotted scams into a sophisticated, largely automated threat that exploits AI, social media trust networks, and the deep integration of mobile numbers with financial identity. The legal framework — spanning the IT Act, DPDP Act, BNS, RBI guidelines, and CERT-In directions — has expanded to keep pace, but enforcement remains reactive rather than preventive. For individuals, the most effective protection remains a combination of digital hygiene, immediate reporting, and awareness that a "trustworthy" message today may not have been written, or sent, by a human at all.

Disclaimer: This article is for general informational purposes and does not constitute legal advice. Victims of cyber phishing should consult a qualified cyber law practitioner or approach the nearest cyber crime cell for case-specific guidance.

© 2026 Cyber Law Desk. All rights reserved.
Cyber Crime In India :  Cyber Phishing - Cheating by personation