Digital Arrest Scams: Why India's Fraud Laws Need a Technology-Specific Response

A video call appears to come from the CBI, the Enforcement Directorate or the police.

A video call appears to come from the CBI, the Enforcement Directorate or the police. The caller displays an official-looking identity card, alleges money laundering or narcotics offences and claims that an arrest warrant has been issued. The victim is ordered to remain on camera, avoid family and lawyers, and transfer savings to a supposed 'verification account'. This is the anatomy of a digital-arrest scam.

This "digital arrest scam", which is a growing trend, is a one of the most common and rapidly growing methods of financial crime in India using information technology. Unlike traditional online fraud, these scams exploit more than technical weaknesses; they wield fear, psychological manipulation, institutional trust, and cutting-edge technologies like callers spoofing ID numbers, deep fake videos and voice-cloning using AI. The victims are trapped in the video calls for hours, and are manipulated to comply with bogus demands, essentially under a state of virtual imprisonment.

The size of the issue has led to several government warnings to the public by the Ministry of Home Affairs, the Indian Cyber Crime Coordination Centre (I4C), the Reserve Bank of India (RBI), and police forces all over the country. However, while many awareness programmes have been launched and the Bharatiya Nyaya Sanhita, 2023 (BNS) and the Bharatiya Sakshya Adhiniyam, 2023 (BSA) have been enacted, the traditional offences of cheating, personation, criminal intimidation and forgery remain the primary tools used by India's criminal justice system to address incidents of this nature.

Although applicable, these measures were not originally intended to address high-tech, cross-border cyber schemes that incorporate artificial intelligence, cross-border cyber networks and psychological coercion.

This article suggests that there is a serious problem of law that the development of the cyber-enabled nature of criminal activity has not caught up with. Though the current system offers avenues and tools for prosecution once the crime has been committed, it lacks effectiveness in its efforts to achieve swift response, cooperation in investigation and strong deterrence. While better legislation is essential, the response should also involve a coordinated institutional effort, better digital forensic capacity, and new regulatory and preventative tools to tackle the specific nature of AI-driven cyber crime.

Understanding Digital Arrest Scams: Anatomy of a New-age Crime

Indian law does not define 'digital arrest'. The expression describes a form of cyber fraud in which offenders impersonate police officers, judges or regulators and convince victims that they face investigation or arrest. No lawful arrest occurs: the scheme depends on deception, technological impersonation and sustained psychological pressure.

The development of the modus operandi is usually predictable. Victims are contacted by phone or video by people who pretend to be from agencies like the Central Bureau of Investigation (CBI), Enforcement Directorate (ED), Narcotics Control Bureau (NCB), Telecom Regulatory Authority of India (TRAI), Reserve Bank of India (RBI) or the local police. The fraudsters often use caller ID spoofing, fake identity cards, fake arrest warrants and professionally printed documents with official logos to establish credibility. More and more, criminals are employing AI-generated voice cloning and AI manipulated video feeds, making impersonation much more convincing than traditional phishing.

The coercive phase of the fraud starts once the victim has been convinced that he or she is involved in a serious criminal investigation. Often, fraudsters allege money laundering, narcotics trafficking, identity theft or financing illegal activities. So the victims are told to have constant video access, they are barred from talking to their family, lawyers or colleagues and are threatened with arrest if they fail to comply. The extended seclusion has a psychological function: it is with the victim that he cannot get independent confirmation but also strengthens the sense of official custody.

In this sense, while no physical bond exists, the victim feels like a slave under the condition of fear, and apparent authority.

Financial extraction is the final stage. Victims are directed to transfer money to specified accounts, supposedly so that officials can verify, freeze or clear the funds. By the time the fraud is discovered, the money has often passed through multiple mule accounts and jurisdictions, making recovery exceptionally difficult.

Digital-arrest scams differ from conventional cybercrime because their principal weapon is psychological control rather than a software vulnerability. Offenders exploit institutional trust, fear of prosecution, urgency and social isolation. The offence combines social engineering, identity fraud and financial crime, which makes it difficult to address through traditional fraud provisions alone.

The shift is reflective of the fact that cybercrime has moved from attacking digital infrastructure to attacking the human mind as a first point of vulnerability.

The increasing prevalence of these cons has led to multiple alerts from the Indian Cyber Crime Coordination Centre (I4C), the Reserve Bank of India (RBI), and various State Police cyber cells, which have all stressed that no investigative agency makes arrests, does any interrogation on video calls, or asks for fund transfers to investigate crime investigations. Even with these warnings, losses are still rising, and legal measures aimed at more than just raising public awareness include preventive regulation, real-time enforcement systems, and more effective coordination of investigations.

Existing Legal Framework: Can India's Criminal Laws Adequately Address Digital Arrest Scams?

This has put India's criminal justice system to the test with regard to how well it keeps up with technology-related crimes. While there is no specific law prohibiting "digital arrest", the behaviour surrounding the digital arrester scams is covered by a number of laws related to the offence of cheating, personation, forgery, criminal intimidation and cyber offence. The Bharatiya Nyaya Sanhita, 2023 (BNS) and the Bharatiya Sakshya Adhiniyam, 2023 (BSA) have brought about certain changes to the law of evidence and criminal law.

Despite this, the enactments remain fundamentally grounded in traditional legal principles that had never been tailored to deceptive conduct by AI tools or to advanced forms of psychological manipulation through cyber technology.

The principal offences are covered by Bharatiya Nyaya Sanhita, 2023. At the same time, the threat to make an arrest, imprisonment or prosecution is likely to attract offences of criminal intimidation, especially when the threat is used intentionally to induce the victim to part with the money. Also, the threat to make arrests, imprisonments, or prosecutions may create a risk of personation offences, since the threat relies on falsely assuming a public position to gain the victim's confidence.

And the threat to make arrests, imprisonments and prosecutions will also likely attract offences of extortion, as the victim is likely to part with the money only because of the threat of the offenders to make arrest, imprisonment or prosecution and not as a result of any voluntary financial transaction.

The BNS has criminalized the constituent elements of digital arrest scams but has done so in an isolated manner. This means that investigators have to rely on several statutory provisions to prosecute one fraudulent scheme, and can also result in inconsistent interpretations of these provisions from one jurisdiction to another, leading to disjointed investigations.

The BNS, along with the Information Technology Act, 2000, remains the main legal regime for cyber crimes. These provisions also come into play where a fraudster uses a spoofed telephone number, fake digital identities or communication platforms online for the purposes of personation. ^14 But the Information Technology Act was enacted over 20 years ago before the advent of the likes of generative artificial intelligence, deepfake videos and AI voice cloning. As a result, its provisions might technically cover parts of digital arrest scams, but not specifically parts of new methods of technologically advanced impersonation that greatly enhance the credibility and sophistication of these offences.

Call recordings, bank transaction records, CCTV footage, mobile device extractions, IP logs, email communications, and metadata are often the key evidence in digital fraud investigations. The increased focus on digital evidence in the BSA is a major step forward from the old methods of evidentiary practice. However, the continued success of digital prosecutions relies on the existence of dedicated digital forensic infrastructure and trained investigators who are able to preserve, authenticate and analyse intricate electronic evidence.

In addition to criminal law, preventive measures are increasingly being taken by regulatory institutions. The Reserve Bank of India (RBI) has issued multiple warnings to the public to never transfer money to bank accounts for verification or investigation. Similarly, the Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs has stepped up public awareness programs and enhanced the National Cyber Crime Reporting Portal (1930 Helpline) for quick reporting of cyber fraud and freezing of transactions in time. These programs have helped enhance the responsiveness of institutions and have been largely administrative in nature, not supplanting the criminal law framework.

Together, India's legal framework does not lack measures to protect against digital arrests. Instead, its main drawback is that it applies old offenses to a new way of committing a psychological crime using the Internet. Although existing laws are effective at punishing instances of deception, forgery, impersonation and intimidation, they fail to provide clear instruction for preventing such impersonation, provide real-time coordination of institutions and permit immediate intervention before financial losses are irretrievable.

The technological innovation / legislative design mismatch indicates a need for change to go beyond the traditional fraud laws and toward a more comprehensive and forward-looking approach to criminal justice.

Beyond Traditional Fraud: Why the Existing Legal Framework Falls Short

A digital arrest scam is a prevalent fraud in India that uses social media and other online platforms to trick individuals into clicking on malicious links or downloading malware. Digital arrest scams are a common fraud in India that involves social media and other online platforms and fools people into clicking on links or downloading malware. This persistence is not because there are no crimes or there are insufficient criminal offences but because the current law is not capable of tackling the unique nature of these offences.

Digital-arrest scams are not ordinary instances of electronic cheating. They combine synthetic media, social engineering, psychological coercion, financial fraud and transnational networks. Existing law remains largely reactive and offers too little support for prevention, rapid intervention and victim recovery.

One of the root causes is that there is no legal definition of offence against digital impersonation of public authorities by means of emerging technologies. Cheating, personation and forgery are clearly relevant, but they do not differentiate between simple impersonation and technologically-advanced impersonation that uses AI-generated speech and video, spoofed government websites, and manipulated digital identities. The law thus holds an ordinary fraudulent telephone call that an ordinary individual makes to a senior investigating officer or a highly sophisticated phone call from a computer-generated impersonation of a senior investigating officer to be the same crime.

A simple fraudulent telephone call by a simple human being is thus treated as the same offence as a highly sophisticated call generated by a computer program that impersonates a senior investigating officer.

Where the institutions respond, it is often disjointed and ineffective against financial fraud that is facilitated by cyber technology. Cooperation among local police, specialised cybercrime units, banks, payment service providers, telecom operators, Internet intermediaries, CERT-In and Indian Cyber Crime Coordination Centre (I4C) is required to carry out an effective investigation of digital arrest scams. In reality, these agencies may operate under different regulatory and administrative systems, leading to slow communication and slow enforcement.

These delays are especially harmful because fraudulent money often moves through several accounts of the same bank within minutes, and money may be quickly moved across jurisdictions, making it ever more difficult to recover.

One of the obstacles is the international dimension of organised cybercrime. Several investigations by Indian police agencies have found that digital arrest scams are more often than not run by criminal gangs that stretch across many States and in some cases beyond India's borders. Fraudsters regularly use virtual private networks (VPNs), encrypted communication channels, servers located in other countries and cryptocurrency transactions to hide their tracks and avoid being investigated.

While Indian criminal law has some provisions that are applicable to overseas offenses, international cooperation, the exchange of information through mutual legal assistance treaties (MLATs), timely sharing of information and working with foreign service providers are fundamental for effective prosecution. Such mechanisms are often time-consuming, cumbersome and are not appropriate for offences which require urgent action.

Existing fraud offences also understate the psychological dimension of these scams. Victims do not transfer money merely because they misunderstand a fact; they act under sustained intimidation, isolation and the apparent command of public authority. The deliberate manufacture of that coercive environment should be recognised in both investigation and sentencing.

The offence operates through psychological control: fabricated legal authority creates a perceived duty to obey. Existing criminal law does not fully capture this sustained form of coercion or the particular vulnerability it creates.

The swift advancement of AI has also deepened the chasm between the innovation of technology and the readiness of the legislation. The cost of producing a convincing fake communication has dropped significantly thanks to the advent of AI-powered voice cloning, facial synthesis and deepfake technology. The scams made use of the voices and likenesses of public officials in poor quality recordings or by obvious impersonation, but today's AI technologies can mimic the voice and facades of public officials with great accuracy, making deception much more likely.

However, the existing Indian cyber laws do not provide any comprehensive provisions on the misuse of synthetic media technologies for commission of a crime and there is no additional criminal liability under the existing legislation. As generative AI becomes more available and advanced, this lack of legislation is becoming increasingly worrisome.

Lastly, the current system is more orientation towards prosecution than prevention. Reporting mechanisms have undoubtedly enhanced with public awareness campaigns and helplines like 1930, and the National Cyber Crime Reporting Portal, all of which work after a victim has already suffered monetary losses. With fraudsters able to make transactions in seconds with a click, the demand for policy that would provide real-time prevention are paramount, including the freezing of accounts, integrating fraud detection systems, the use of AI to monitor suspicious financial transactions, and mandatory coordination between financial institutions and investigative agencies.

A criminal justice system that reacts once someone is harmed is becoming less and less effective in combating crimes that are quick to evolve, yet slow to be investigated.

The problem with digital arrest scams, then, is not just a matter of being better able to enforce existing legislation. It is a structural problem requiring a change in criminal justice governance from traditional criminal law to a technology-enabled approach. The gap between technological development and legal protection will likely continue to grow without institutional coordination, improvements in digital forensic capabilities, new laws and regulations for artificial intelligence, and proactive prevention measures.

Towards a Future-Ready Criminal Justice Response: Reforming India's Legal Framework

Digital arrest scams illustrate the need to apply new strategies to tackle the crimes of the 21st century. The current legal system offers a good foundation for post-crime prosecution, but is inadequate in combating technologically advanced fraud or in enabling the rapid institutional response. India needs to be more proactive and take a multi-layered approach to its criminal law framework, which includes legislative measures, institutional collaboration, technological advancements, and public awareness to keep pace with the evolving landscape of cyber-enabled crimes.

It is important that aggravated digital impersonation with public authorities is recognised statuториorato. While the Bharatiya Nyaya Sanhita criminalises impersonation and cheating, it does not differentiate between impersonation by ordinary methods and by Artificial Intelligence, Deep Fake technology or by using fabricated digital identities. This would reflect the public harm that has been caused by digital impersonation of a police officer, judge, an investigating agency or government official. The criminal liability for technology-enabled impersonation to undermine the confidence in State institutions should be increased, like the penalties for offences against public servants or national security.

Secondly, artificial intelligence should be a part of cybercrime regulation - it should not be isolated. In the era of technology, India's criminal justice system can no longer be technology neutral. India's criminal justice is too technology neutral and with the growing potential of generative AI in creating realistic voice-clones, videos and fake documents, it is time to come up with a more technology-sensitive approach to criminal justice. Prospective changes to cyber legislation ought to explicitly clarify the ban on the malicious generation and application of synthetic media for fraudulent purposes and set the standards for cyber evidence detection, authentication, and forensic examination.

Clear legislation would help to drive prosecutions, and also increase the certainty for investigators in cases of tampered electronic records.

The need for institutional reform is also paramount. The investigation of digital arrest scams is now being done by several agencies with different statutory and regulatory powers, such as Police departments, cybercrime units, banks, telecom service providers, internet intermediaries, CERT-In and Indian Cyber Crime Coordination Centre (I4C). Each institution has a valuable role to play, however, there is a lack of effective collaboration which can lead to a lag of time in intervening in the early stages of fraud.

An all-inclusive Cyber Fraud Response Mechanism that can allow real-time information sharing, instant freezing of suspicious transactions and coordinated investigation on a cross-jurisdictional basis should be developed in India. The integration would significantly shorten the window for fraudsters to use funds stolen from institutions.

A second parallel priority is the enhancement of digital forensic capacity. Preserving and analyzing electronic evidence, such as call metadata, IP addresses, cloud storage, blockchain transactions, device extractions, and content uncovered by AI, plays a vital role in modern cybercrime investigations. However, there are still considerable differences in forensic facilities and expertise among States.

The establishment of cyber forensic laboratories in a specialized manner, regular training programmes of judicial officers and police officials and the implementation of a standard operating procedure for digital evidence under the Bharatiya Sakshya Adhiniyam would greatly enhance the efficiency of investigation and prosecution of cyber cases.

The preventive regulation should be further prioritized. Financial institutions and telecom operators stand out as the front row of defense in the fight against large losses as they are best equipped to detect fraudulent transaction trends and communication networks. Regulatory approaches should foster the implementation of AI-driven fraud detection tools, enhanced customer authentication, real-time transaction surveillance, and prompt inter-bank collaboration in high-risk transactions identified. It is equally important that public awareness programmes continue to be expanded and enhanced in educational institutions, financial literacy programmes and digital safety campaigns.

As digital arrest scams rely on exploitation of human psychology, informed citizens are most likely to be the first line of defence.

Last but not least, there is a need for India to improve its cooperation measures with foreign countries for combating cybercrime. Given the internationality of digital arrest scams, there is a need to improve cooperation with other law enforcement agencies, technology giants, financial intelligence units and international organisations like INTERPOL. Better data sharing, simplified mutual legal assistance, and increased active cooperation with international cybercrime efforts would help India in its investigations of cross-border offences.

All these reforms together represent a significant conceptual paradigm shift. The goal must go beyond merely punishing cybercrime after a monetary loss to predicting, identifying, disrupting and preventing high-tech digital fraud before it causes irreparable damage. This proactive and technology-ready strategy is essential to ensure the efficiency of the criminal justice system in a digital age driven by AI and digital manipulation.

Conclusion

The digital arrest scam is one of the most chilling examples of the ways in which today's technology is making an old trick seem new again, using psychological coercion and artificial intelligence to deceive. The prevalence of their occurrence is revealing the inadequacy of the criminal justice pathway that is stuck with traditional offenses like cheating, forgery, and personation, when the nature of these technologically advanced crimes is different.

Despite having a legal framework in the Bharatiya Nyaya Sanhita, the Information Technology Act and the Bharatiya Sakshya Adhiniyam, it is relatively ineffective and disjointed in tackling fraud facilitated by artificial intelligence, transnational criminal networks and real-time financial misuse. The issue is not just one of enforcement, but one of how criminal law evolves into a dynamic, responsive system that can keep up with the changing technologies.

India's response must extend beyond punishment after the event. Effective prevention requires coordination among banks, telecom providers and law-enforcement agencies; faster tracing of mule accounts; stronger digital forensics; and sustained public education. A technology-specific framework should protect citizens without weakening trust in legitimate public institutions.

Primary materials

Key primary materials: Bharatiya Nyaya Sanhita, 2023; Supreme Court of India judgments.

Criminal LawLegal Analysis