Cyber Safety in the Age of Digital Trust: Laws, Risks, and Practical Protection

 

1. Cyber fraud has become one of the biggest threats in everyday lifeWhy do you think even educated and tech-savvy people are falling victim to online scams?

 

Cyber fraud today is no longer limited to crude lottery messages or obvious fake calls. Scams have become psychologically sophisticated: task scams promise easy money for liking reels, fake police calls create panic about a family member, and job scams exploit desperation by demanding “refundable” deposits. These frauds target fear, greed, urgency and trust, not merely technical ignorance.

Even vigilant users fall victim because modern scams use forged identities, leaked personal data and organized networks that make fraudulent contact appear genuine. Courts have recognized that these offences cause systemic harm, especially where institutions fail to maintain adequate safeguards. While individuals must practise cyber hygiene, banks, platforms and data fiduciaries also owe a duty of care under applicable law and rules.

2. As someone from Generation Z, how do you see cyber risks evolving for young people? Are there mistakes that your generation commonly makes online?

 

Gen-Z is hyper-connected, using multiple devices and platforms constantly. The main risks have moved beyond simple phishing to identity exploitation, deepfakes, algorithmic manipulation and misuse of digital footprints.

Over-sharing and privacy: Young users often disclose personal data casually. Even with the Digital Personal Data Protection Act, 2023, voluntary disclosure can expose users to profiling, impersonation and deepfake misuse.

Illusion of anonymity: Posts, chats and shares can become permanent digital evidence. Cyberbullying, illegal sharing and privacy violations can attract liability under the Information Technology Act, 2000.

Trusting digital identities: Fraudsters now use AI voices, fake profiles and familiar interfaces to appear trustworthy. Gen-Z must verify identity outside the platform before sharing money, credentials or private information.

Common mistakes: granting unnecessary app permissions, reusing passwords, ignoring two-factor authentication and treating online spaces as consequence-free. The best safeguard is digital literacy: scrutinise every online action as carefully as a legal document.

3. What are the most common digital frauds you are currently seeing in India—such as UPI scams, fake investment schemes, OTP frauds, job scams, or phishing links? Which should people be most alert to?

 

The most common frauds in India exploit instant payments and social engineering. People should be especially alert to UPI requests, phishing links, OTP traps, fake jobs and investment schemes.

1. UPI and QR-code scams: Fraudsters pose as buyers and send QR codes or payment requests. Remember: if you enter a UPI PIN, you are authorising payment. You never need a PIN to receive money.

Under RBI principles, customer liability often turns on whether the user shared credentials or delayed reporting. Banks usually become liable only after timely reporting, unless there is proven deficiency on their part.

2. OTP and phishing frauds: Victims are tricked into clicking links, downloading remote-access apps or sharing OTPs. Consumer fora have repeatedly treated sharing OTP/payment credentials as customer negligence unless bank fault is shown.

3. Investment and job scams: Fraudsters offer fake jobs or high-return schemes, allow small withdrawals to build trust, then disappear after larger deposits. These may involve cheating, forgery and fake electronic records, but recovery is difficult once money moves through mule accounts or overseas networks.

Be most cautious about: any request requiring OTP, UPI PIN, remote access, urgent payment or “too good to be true” returns.

What can you do? Report immediately to your bank and to 1930/cybercrime.gov.in. Preserve transaction IDs, screenshots and messages. Verify links by visiting official websites directly rather than clicking links received on SMS or WhatsApp.

4. Many people panic when someone threatens to leak their personal photographs, videos, or social media data. What should they do immediately, and what should they never do?

Threats to leak personal photographs, videos or social media data can be deeply distressing. The first step is to stay calm and remember that you are the victim of extortion, criminal intimidation and possible privacy violations. Do not let fear make you act against your own interest.

Do immediately: save all evidence, including screenshots, usernames, numbers, payment demands and chat history. Report the matter on cybercrime.gov.in/1930 and to the local police or cyber cell. Change passwords, enable two-factor authentication and warn trusted people if the blackmailer names them.

Never do: do not pay, negotiate, delete evidence, warn the offender that you have complained, or try to handle a physical confrontation yourself. Paying usually encourages further extortion.

Victims are entitled to legal protection and dignity. Police can register an FIR for cognizable offences, and authorities can ask platforms to remove or disable unlawful private content. Most importantly, the victim is not alone and should seek help quickly.

5. If a person’s bank account has been compromised or money has been fraudulently transferred, what are the first three steps they should take in the first hour?

In a fraudulent transfer, time matters most. The first hour is the “golden hour” to freeze funds before they move through mule accounts.

1. Freeze the account/card immediately: use the banking app or official customer care number from your statement. Obtain a complaint/reference number as proof of reporting.

2. Report to 1930/cybercrime.gov.in: the portal connects to bank nodal officers and can trigger a hold request on the recipient account if reported quickly.

3. Preserve transaction evidence: keep screenshots, UTR/transaction ID, messages, call logs and app notifications. These help banks and police trace the money.

Liability note: RBI norms generally protect customers who report unauthorized transactions promptly, especially within three working days, unless the loss was caused by customer negligence such as sharing PIN/OTP.

6. How effective are India’s cyber laws today in protecting ordinary citizens? Are victims generally able to recover their money or see the offenders brought to justice?

India’s cyber law framework is strong on paper and is evolving rapidly, but recovery and prosecution remain mixed for ordinary citizens.

The Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023 and the BNSS, 2023 classify many cyber offences as serious and cognizable. For financial victims, the RBI customer-protection framework is often the most practical shield. Courts have recognized that timely reporting can limit customer liability where there is no negligence.

The main challenges are anonymity, VPNs, mule accounts, cross-border operations and limited investigative capacity. Monetary recovery is more likely when victims report immediately through 1930 and the bank. Conviction of offenders is harder, but not impossible, especially when evidence is preserved and complaints are filed early.

In short, the law is a powerful shield, but it works best for citizens who act quickly, avoid sharing credentials and document every step.

7. Parents are increasingly worried about children’s online safety. What practical advice would you give families to protect children from cyber bullying, identity theft, and online exploitation?

Children’s online safety requires technical controls, open communication and quick reporting. Parents should treat online risk as seriously as physical-world risk.

1. Set digital boundaries: use parental controls, restrict age-inappropriate apps, set screen-time limits and review privacy settings.

2. Teach identity hygiene: children should not share real names, school details, phone numbers, addresses, location-tagged photos or private images in public chats.

3. Apply the stranger rule: anyone met online is a stranger, even if they appear friendly or familiar. Online grooming and enticement can attract legal consequences under cyber and child-protection laws.

4. Keep communication open: never make the child fear punishment for reporting cyberbullying, threats or inappropriate contact. Early disclosure is the best protection.

5. Watch for warning signs and report: secrecy, sudden fear, irritability or reluctance to use devices may indicate bullying or grooming. Preserve screenshots and report harmful content to cybercrime.gov.in or emergency/child helplines where appropriate.

8. Social media has become an integral part of our lives. What privacy settings and digital habits should every person adopt to reduce the risk of hacking and misuse of personal information?

Treat social media accounts as digital assets. Weak privacy settings and careless habits can expose you to hacking, impersonation and identity theft.

Privacy settings: keep profiles private, review followers/friends, restrict tagging, disable location sharing and avoid exposing personal routines or workplace details.

Account security: use unique passwords, a password manager and authenticator-app-based MFA. Avoid SMS-only authentication where possible because of SIM-swap risks.

App permissions: revoke access for old third-party apps and limit ad-tracking or cross-app activity where settings allow.

Verification habits: confirm urgent money requests through a phone call, check links carefully, and visit official websites directly instead of clicking suspicious messages.

These habits reduce “contributory negligence” arguments and place you in a stronger position if you ever need legal or banking relief after a breach.

9. There is often hesitation in reporting cyber crimes due to embarrassment or fear of social stigma. What would you like to say to victims who are reluctant to approach the authorities?

Silence often helps the offender. Victims should remember that embarrassment is understandable, but the law treats them as victims, not as accused persons.

Blackmailers and scammers rely on shame and fear. Paying or staying silent may encourage repeated harassment. Reporting can protect you and may also stop the same offender from targeting others.

Victims may approach the cyber-crime cell, local police or cybercrime.gov.in. Privacy and discretion should be requested wherever necessary. Most offences such as cheating, extortion and identity theft are cognizable, so police can register and investigate them.

The message to victims is simple: the crime was committed against you. Do not let the offender decide the terms. Preserve evidence, report early and seek support from trusted people or authorities.

10. If you had to leave our readers with five simple ‘Golden Rules of Cyber Safety’ that every family should follow, what would they be?

These five rules create a practical “human firewall” for every family:

  1. Never enter PIN/OTP to receive money: a PIN authorises payment from your account.
  2. Enable MFA everywhere: prefer authenticator apps over SMS where possible.
  3. Do not click suspicious links: type official URLs yourself instead.
  4. Pause before acting: urgency is a scammer’s favourite weapon.
  5. Report immediately: contact your bank and 1930/cybercrime.gov.in within the first hour wherever possible.

Tanushree Chaturvedi