Emerging Cybercrime Threats in India: A Critical Analysis of Legal Frameworks, Enforcement Challenges and Regulatory Reforms
DOI:
https://doi.org/10.29070/ch195n51Keywords:
Cybercrime, Cybersecurity, Information Technology Act, Artificial Intelligence, Deepfakes, Digital Arrest, Financial Cyber Fraud, Data Protection, Cyber Governance, CERT-In; I4C, Electronic Evidence, Regulatory ReformAbstract
The rapid expansion of India's digital economy has transformed communication, banking, commerce, governance, education and social interaction. At the same time, dependence upon interconnected digital systems has generated an increasingly complex cybercrime environment. Conventional offences such as fraud, cheating, extortion and impersonation have acquired technologically sophisticated forms, while cyber-dependent offences including unauthorised access, ransomware, malware deployment, data theft and attacks upon critical infrastructure present distinct challenges to law-enforcement agencies. Artificial intelligence, deepfakes, voice cloning, cryptocurrency, social engineering, anonymisation technologies and transnational digital networks have further altered the nature of cyber offending. Contemporary manifestations such as digital-arrest scams, business-email compromise, investment fraud, UPI-related deception, identity theft, cyberstalking, sextortion and AI-assisted impersonation illustrate the transition of cybercrime from relatively isolated computer misuse to organised, scalable and financially motivated criminal activity.
India has developed a substantial legal and institutional framework through the Information Technology Act, 2000, the Information Technology (Amendment) Act, 2008, the Bharatiya Nyaya Sanhita, 2023, the Digital Personal Data Protection Act, 2023, CERT-In directions, intermediary regulations and the Indian Cyber Crime Coordination Centre. Yet cybercrime continues to increase. NCRB data for 2024 record 101,928 cybercrime cases, compared with 86,420 in 2023, representing an increase of approximately 17.9 per cent. Fraud constituted the dominant motive. Meanwhile, millions of complaints made through the National Cyber Crime Reporting Portal reveal a much broader fraud ecosystem than formal FIR statistics alone.
This article critically examines emerging cybercrime threats in India, the historical development of cyber law, the adequacy of existing substantive and procedural frameworks, investigative and jurisdictional challenges, and the need for regulatory reforms. It argues that India's cybercrime response should evolve from fragmented offence-based regulation towards an integrated model incorporating technological resilience, specialised policing, electronic-evidence capability, platform accountability, data protection, financial-fraud prevention, victim restitution and international cooperation. Comparative developments under the Budapest Convention, the United Nations Convention against Cybercrime, the European Union's NIS2 framework and the United States' cybersecurity governance model are analysed. The article concludes that effective cybercrime regulation requires law to remain technologically adaptive without compromising privacy, proportionality, due process or legitimate digital innovation.
Downloads
References
1. Government of India. (2000). The Information Technology Act, 2000. Ministry of Law, Justice and Company Affairs.
2. Council of Europe. (2001). Convention on Cybercrime. European Treaty Series No. 185.
3. Wall, D. S. (2007). Cybercrime: The transformation of crime in the information age. Polity Press.
4. Government of India. (2008). The Information Technology (Amendment) Act, 2008. Government of India.
5. Brenner, S. W. (2010). Cybercrime: Criminal threats from cyberspace. Praeger.
6. Government of India. (2013). National Cyber Security Policy 2013. Department of Electronics and Information Technology.
7. Shreya Singhal v. Union of India, (2015) 5 SCC 1.
8. Clough, J. (2015). Principles of cybercrime (2nd ed.). Cambridge University Press.
9. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
10. Holt, T. J., Bossler, A. M., & Seigfried-Spellar, K. C. (2018). Cybercrime and digital forensics: An introduction (2nd ed.). Routledge.
11. Government of India. (2021). Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Ministry of Electronics and Information Technology.
12. Indian Computer Emergency Response Team. (2022). Directions relating to information security practices, procedure, prevention, response and reporting of cyber incidents. CERT-In.
13. European Parliament & Council of the European Union. (2022). Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive).
14. Government of India. (2023). Digital Personal Data Protection Act, 2023. Ministry of Law and Justice.
15. Government of India. (2023). Bharatiya Nyaya Sanhita, 2023. Ministry of Law and Justice.
16. Government of India. (2023). Bharatiya Sakshya Adhiniyam, 2023. Ministry of Law and Justice.
17. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce.
18. United Nations General Assembly. (2024). United Nations Convention against Cybercrime (A/RES/79/243). United Nations.
19. Government of India. (2025). Digital Personal Data Protection Rules, 2025. Ministry of Electronics and Information Technology.






