Digital Arrest Scams and the Enforcement Gap: Why Existing Criminal Provisions Struggle With Organised Impersonation Fraud

Introduction

In October 2024, Prime Minister Narendra Modi used his monthly radio programme Mann Ki Baat to warn the nation about a phenomenon that had quietly devastated thousands of Indian households: the “digital arrest.” In these scams, criminals impersonating officers of the Central Bureau of Investigation, the Enforcement Directorate, the Narcotics Control Bureau, or the Telecom Regulatory Authority of India contact victims through video calls and inform them that they are under digital arrest in connection with a serious criminal investigation. Victims are instructed not to speak to family members, to remain visible on camera, and ultimately to transfer large sums of money to secure their release from this fictitious legal jeopardy. The Prime Minister’s public intervention was remarkable not merely because of the office from which it came, but because it acknowledged that the collective response of law enforcement agencies, the judiciary, and the legislature had thus far been insufficient to protect Indian citizens from this form of sophisticated impersonation fraud.

This article examines the criminal law framework applicable to digital arrest scams, the structural reasons why existing provisions struggle to contain a form of fraud that is inherently transnational and technologically enabled, the institutional responses that have been developed, and the reforms that would be necessary to address the enforcement gap in a sustained manner.

Legal Framework

The Bharatiya Nyaya Sanhita 2023, which replaced the Indian Penal Code 1860 with effect from 1 July 2024, contains several provisions that are applicable to digital arrest conduct. Section 318 BNS covers cheating and dishonestly inducing delivery of property, which corresponds to the former Section 420 IPC. A digital arrest scam that results in the victim transferring money constitutes cheating under this provision, as the scammer by impersonation creates a false belief in the victim’s mind and thereby induces the transfer. Section 319 BNS addresses cheating by personation, making it an offence to cheat by pretending to be some other person, whether that person exists or is fictitious. The impersonation of a CBI or ED officer in a digital arrest scam would fall squarely within this provision.

Section 351 BNS addresses criminal intimidation, which covers threatening a person with injury to cause that person to do an act which they are not legally bound to do. The threats typically made in digital arrest scams, including threats of arrest, prosecution, and public disgrace, would constitute criminal intimidation if made with the intent to cause the victim to transfer money.

The Information Technology Act 2000 provides additional grounds of liability. Section 66D specifically addresses cheating by personation using computer resources, prescribing imprisonment of up to three years and fine. This provision was designed precisely for the kind of impersonation that digital arrest scams involve, though it was enacted long before such scams attained their current sophistication and scale. Section 66C addresses identity theft in the context of electronic signatures and other authentication data. Where scammers have used stolen identity documents or information to create the appearance of official communication, this provision may be engaged. Section 43A imposes civil liability on entities that handle personal data negligently, which is relevant where data breaches have enabled the personalised targeting that makes digital arrest scams more convincing.

The BNSS 2023 also provides for electronic evidence, making it procedurally possible to prosecute these offences using digital records. However, the substantive provisions of criminal law in India were not designed with organised transnational impersonation fraud in mind, and their application to this phenomenon requires significant prosecutorial creativity.

Judicial Developments

Indian courts have not yet developed a substantial body of case law specifically addressing digital arrest scams as a distinct legal phenomenon, which itself reflects the recency and the evidentiary challenges associated with these cases. There are, however, judicial observations and orders that provide some guidance. Several High Courts, responding to petitions filed by victims who were subsequently prosecuted or whose assets were frozen as a consequence of fraudulent proceedings initiated against them, have emphasised that no law enforcement agency in India has the power to conduct arrests through video calls. Orders from the Delhi High Court and the Gujarat High Court have affirmed this position, which may seem self-evident but which evidently needs to be restated given the numbers of people who are deceived.

The Supreme Court has, in broader cybercrime contexts, emphasised the need for expeditious investigation and has directed that FIRs registered in cybercrime matters should not be treated as invitations for indefinite delay. In X v. State of Maharashtra (2023), the Court emphasised that the victim’s vulnerability and the technological sophistication of the perpetrator should be taken into account in deciding bail applications in cybercrime matters, a direction relevant to the perpetrators of digital arrest scams who are occasionally apprehended domestically.

The Indian Cybercrime Coordination Centre, established under the Ministry of Home Affairs, has handled citizen reporting through the National Cybercrime Reporting Portal, but the translation from complaint receipt to prosecution remains statistically weak.

Contemporary Issues and Analysis

The structural difficulty with digital arrest scams is that they are designed from the ground up to be enforcement-resistant. The most organised versions of these scams operate from call centres located in Myanmar, Cambodia, and other jurisdictions in Southeast Asia where Indian law enforcement has no direct reach. These call centres sometimes employ individuals who are themselves victims of human trafficking, having been lured abroad with promises of legitimate employment and then coerced into participating in fraud operations. This creates a layered victimisation dynamic that complicates the moral and legal analysis.

The call chain in a typical digital arrest scam involves multiple layers of technological obfuscation. Calls are routed through internet telephony services that display falsified caller IDs replicating the numbers of actual government agencies. The video call interface is designed to resemble an official setting, complete with logos, uniforms, and props that convincingly mimic a government operations room. The combination of visual authenticity and procedural vocabulary drawn from actual law enforcement practice produces a high rate of victim compliance.

INTERPOL has issued multiple Purple Notices related to the modus operandi of these scams, and the I4C has shared intelligence with law enforcement counterparts in the relevant jurisdictions. However, INTERPOL operates through national central bureaus and has no independent enforcement power. Extradition from Myanmar is complicated by the political situation in that country. Cambodia, while a signatory to bilateral treaties with India, has had mixed results in cooperating on cybercrime investigations.

The evidentiary challenge is substantial. Digital evidence in these cases may be located in multiple jurisdictions, hosted on servers that change location to evade detection, or encrypted in ways that require specialist forensic capability to unlock. Establishing the chain of custody for evidence obtained through international cooperation requests adds layers of procedural complexity. In many cases that reach prosecution, the accused are domestic money mules rather than the organisers of the fraud, meaning that even successful prosecution targets peripheral participants rather than the architects of the scheme.

The victim’s role in the evidentiary process is also complicated. Many victims are elderly or from less digitally literate demographics. They often have difficulty articulating the sequence of events in ways that satisfy the precision required by criminal pleadings. The stigma associated with having been defrauded, combined with the frequently personal nature of the threats made (scammers often reference family members by name), creates reluctance to report and to testify.

Comparative and International Perspective

The United Kingdom’s approach to organised fraud combines robust substantive offences under the Fraud Act 2006 with specialised investigative capability through the National Fraud Intelligence Bureau and Action Fraud. The Proceeds of Crime Act 2002 provides powerful asset recovery mechanisms that apply regardless of whether prosecution is ultimately successful. The combination of a simplified fraud offence (requiring only dishonesty and intent to make a gain) with strong asset recovery tools means that even partially successful investigations can have deterrent effect.

The United States has used wire fraud and conspiracy statutes to prosecute international telephone fraud schemes, including “grandparent scams” and IRS impersonation schemes that bear structural resemblance to India’s digital arrest phenomenon. US prosecutors have been creative in asserting jurisdiction wherever a US financial institution processes a transfer or wherever a US communications network is used in the scheme. This broad assertion of jurisdiction, combined with treaty-based extradition and mutual legal assistance, has produced convictions of foreign nationals.

Singapore, which operates as a regional financial hub, has faced its own variants of impersonation fraud and has responded with the Online Criminal Harms Act 2023, which empowers authorities to direct online platforms to restrict access to content associated with criminal activity and to direct financial institutions to block suspicious transactions on an expedited basis. India lacks a comparable expedited administrative response mechanism, meaning that by the time a victim reports and law enforcement begins inquiry, the money has usually been moved through multiple accounts and is irretrievable.

Practical and Policy Implications

The I4C’s establishment is a positive development but its capacity remains constrained relative to the scale of the problem. Cybercrime police stations have been established across states, but the quality of investigation is uneven and the conviction rate in cybercrime cases nationally remains low. The first-responder problem is acute: when a victim reports a digital arrest scam at the local police station, the officer who receives the complaint may have no training in handling the complaint, no access to the technical tools needed to preserve digital evidence, and no mechanism to alert the financial intelligence unit quickly enough to intercept the fraudulent transfer.

The financial system is a critical intervention point. In India, the Home Ministry’s Citizen Financial Cyber Fraud Reporting and Management System allows victims to report cybercrime within the golden hour and can trigger holds on suspect accounts. However, awareness of this system is not universal, and fraudsters have adapted by using accounts that are rapidly emptied through a sequence of transfers to non-cooperating jurisdictions. Cryptocurrency exits are an increasingly common laundering mechanism that is difficult to trace without specialised capability.

The public warning by the Prime Minister, while symbolically significant, also illustrates a governance paradox: the state is compelled to use its highest executive communications channel to educate citizens about an ongoing criminal phenomenon that law enforcement has been unable to suppress at source. This places the burden of prevention on potential victims rather than on enforcement agencies, which reflects a failure of the enforcement architecture.

Suggestions and Reforms

A dedicated cyber fraud prosecution unit at the national level, staffed with prosecutors who specialise in digital evidence, international cooperation, and asset recovery, would represent a qualitative improvement over the current arrangement where cyber fraud cases are handled by generalist prosecutors with no specialist support. Such a unit should have a direct working relationship with the Financial Intelligence Unit, the I4C, and international counterpart agencies.

The substantive law requires a specific provision addressing organised impersonation fraud conducted through electronic means. The current patchwork of cheating, personation, and IT Act provisions requires prosecutorial effort to fit the facts into definitions that were not designed for this conduct. A dedicated offence, with enhanced penalties reflecting the organised and transnational character of the crime, would simplify prosecution and enable clearer sentencing guidelines.

Asset recovery mechanisms need strengthening. The Prevention of Money Laundering Act already applies to proceeds of predicate offences that include cheating, but the timeline from complaint to provisional attachment is too slow to intercept money that may move through several accounts in hours. An expedited freezing mechanism, triggered by victim complaint within a defined period and subject to prompt judicial confirmation, would increase the recoverability of stolen funds.

Bilateral cybercrime cooperation agreements, specifically tailored to digital fraud rather than relying on general mutual legal assistance treaties, should be prioritised in diplomatic engagement with the countries that host the call centre infrastructure. India has significant economic leverage with several Southeast Asian nations that could be applied in negotiations.

Conclusion

Digital arrest scams represent a convergence of technological capability, legal arbitrage, and institutional failure that existing criminal law frameworks have not adequately addressed. The Prime Minister’s October 2024 public warning was a measure of how significantly this phenomenon has penetrated ordinary Indian life, affecting not just urban professionals but rural pensioners, retired government servants, and others who have no framework for understanding why an official-looking government officer would conduct an arrest through a phone screen. The existing provisions of the BNS and the IT Act are applicable to the conduct but were not designed for its specific characteristics, and they cannot substitute for the international cooperation, specialised prosecution capability, and expedited financial intervention that effective suppression requires. The enforcement gap is real, it is widening, and it will not be closed by public awareness campaigns alone.

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these

✶ Message sent! We'll get back to you shortly.