A few weeks ago, Naresh Gujral, son of a former prime minister and himself a former Rajya Sabha member, lost nearly Rs7.8 crore in a cyber fraud. The fraudster created a WhatsApp account using Gujral's photograph and convinced a staff member that Gujral was in a meeting and needed urgent financial transfers. The unsuspecting staff member carried out his orders and transferred the money to a bank account provided by the impersonator.
The fraud came to light after the staff member informed Gujral's daughter of the transactions, and she checked with her father. As they immediately filed an FIR on June 16, the Intelligence Fusion and Strategic Operations Unit of the Delhi Police cybercrime unit was able to recover Rs 4.28 crore. “Fortunately, we have received the complaint within two hours of the last transaction. That’s why we could save a substantial amount,” said Rajneesh Gupta, joint commissioner of police heading the Intelligence Fusion and Strategic Operations and cyber crime unit of Delhi police.
Gujral was lucky that about 55 per cent of his lost money was recovered; the overall recovery rate in cyber fraud cases is around 14 per cent, according to I4C data (Indian Cyber Crime Coordination Centre data).
Ch. Siva Rao, a retired general manager of Visakhapatnam Steel Plant, was not that lucky. He was placed under "CBI investigation" for 13 days last October, after being told his phone number had been used for the delivery of drugs. A WhatsApp video call from a man in police uniform, followed by another from a self-declared CBI officer, convinced him that the investigation was real.
Besides, he was shown a forged letter bearing the signature of the Chief Justice of India. He was told his case involved national security and, if he spoke of it to anyone, he could be jailed. So he said nothing—not to his neighbours, not to his children—and quietly pledged his gold and drained his joint account to pay for an investigation that existed only on a phone screen. By the time his relatives found out and told him to go to the police instead, he had lost Rs1.19 crore.
Some 400km away, K. Srinivas, a 75-year-old retired central government employee, was courted more gently. A woman befriended him on social media, introducing herself as a securities analyst, and offered to help him recover money he had once lost in genuine stock trading. She pointed him to an online platform. Over three months he deposited money in careful instalments—the kind of caution a pensioner brings to any investment—and watched, on his screen, as his investment grew.
Then his wife fell ill, and when he tried to withdraw funds for her treatment, the platform told him he first needed to pay tax on his winnings. He paid. It asked again. By the time he stopped, Rs1.68 crore of his savings had been lost, chasing a fortune that had never existed anywhere except in the software he had trusted.
Not a single day passes without reports of online fraud. People lose their life savings within minutes to criminals they never meet.
Cyber fraud thrives on a web of anonymity and complexity. The stolen money vanishes through layers of mule bank accounts, fake identities and digital platforms. While investigators exhaust their time and energy untangling deliberately obscured money trails, the perpetrators remain virtually untraceable. Despite years of public awareness campaigns, technological interventions and coordinated efforts by banks, telecom companies and law-enforcement agencies, cyber fraud has continued to grow.
In India, people lost Rs55,649 crore between 2021 and 2025 to more than 158 types of cyber fraud, according to I4C. The anonymity cybercriminals enjoy, their ability to steal large sums of money and move them within minutes, and the low probability of being caught have made cybercrime an attractive criminal enterprise.
What happens after losing money? If victims immediately contact the police and the police register a complaint on the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), some amount could be saved, if not the full amount. The crucial period immediately after a fraud, when rapid reporting can help stop or recover the stolen money, is popularly referred to as the "golden hour". “In some cases, we could recover 100 per cent money due to quick complaints,” said Rajneesh Gupta of IFSO. By December 2025, CFCFRMS had helped save more than Rs8,189 crore across 23.61 lakh complaints.
However, this route doesn’t seem to be working effectively, and cyber fraud continues to grow. According to I4C data, the number of financial cyber-fraud complaints rose from 2,62,846 in 2021 to 24,02,579 in 2025, while the annual amount lost increased from Rs551 crore to Rs22,495 crore during the same period. How does one explain the paradox of increasing intervention by government agencies alongside the simultaneous rise in cybercrime?
There appear to be at least three chinks in the government's anti-cyberfraud armour that help cybercriminals thrive: systemic gaps that criminals exploit, poor coordination among government departments and piecemeal interventions against what has become an integrated criminal ecosystem.
The first problem—systemic gaps—puts victims through the most traumatic experience after losing money. These gaps range from a lack of competent police units to delayed responses from banks. A victim whom THE WEEK interviewed said there was no hope left for him after filing the police complaint. The problem is that even if the police want to solve the case, the money channelled through thousands of mule accounts with the help of fund-splitting software is extremely difficult to trace.
"Even tracking the mule accounts in a single case takes at least a month, and tracing the culprits is another daunting task," Hyderabad Police Commissioner V.C. Sajjanar told THE WEEK. “The masterminds of the crime cannot be traced, as most of them operate from abroad.”
The backend response of banks compounds the problem, as banks have no single standard operating procedure for flagging fraud and recovering the proceeds. Bank officials' response to police calls is not uniform. "Bank officials respond as per their convenience, and over the weekend the response is unpredictable," said a police officer.
Even after mules are caught, information about their accounts is not flagged across banks. The response is also shaped by fear of legal repercussions, said a banker who did not wish to be named. Sajjanar said the pressure to meet business targets further weakens compliance with KYC norms. "The Key Result Areas (KRAs) of banks and telecom companies encourage the opening of more accounts and the issuance of more SIM cards, and executives overlook KYC criteria as a result,” he said.
The second problem is that government departments don't always talk to one another, even though the nature and extent of cyber fraud demand an organised response. The RBI, SEBI, the department of telecommunications, the ministry of electronics and information technology and the ministry of home affairs all have a role to play. However, government departments don't coordinate effectively for various reasons, and this has prevented a unified response.
The problem lies in gaps between institutions, which cybercriminals are exploiting, said Dr Ramesh Kanneganti, director of the Hyderabad-based think tank Centre for Human Security Studies.
The third problem is piecemeal intervention in place of a comprehensive, multi-sectoral response. It was to tackle this problem that the government asked I4C, RBI, DoT and other stakeholders to introduce countermeasures. The RBI first introduced an AI-enabled MuleHunter to flag mule accounts. Now the MuleHunter has been developed into the India Digital Payment Intelligence Corporation (IDPIC) to share real-time fraud intelligence and alerts with banks and financial institutions. Finance Minister Nirmala Sitharaman announced the corporation on July 29. The IDPIC can draw on data from all bank network transactions and use it to identify and flag malfeasance.
Likewise, the telecom ministry has announced a comprehensive upgrade of the Sanchar Saathi portal and a beefing up of KYC criteria, particularly for business SIM cards. Union Minister of State for Communication Pemmasani Chandra Sekhar told THE WEEK: "We are currently improving the Sanchar Saathi portal to identify all the SIM cards held by an individual. So far, the portal has been working on a best-effort basis. We are also placing greater responsibility on telecom companies to enforce KYC norms strictly, particularly for business SIM cards, which have reportedly been misused for mule operations." The recently issued Provision of Principal Telecom Services Rules, 2026, also authorised the government to develop a technical system capable of identifying all SIM cards linked to an individual, he said.
Though these measures mark a significant improvement, they still fall short of a unified response, as several gaps are waiting to be plugged. For instance, there are still no legal provisions to try mule account holders as members of an organised crime network. They are currently treated as individuals, and even station bail is being granted, said Kanneganti.
The reason is that Section 111 of the Bharatiya Nyaya Sanhita mandates that there be more than one prior chargesheet in 10 years before a gang can be prosecuted for organised crime. Most mules would not have such a criminal history and thus get an easy pass. Unless this section is changed, most cyber fraud networks will continue to get away with little or no punishment. Thus, while individual agencies are introducing stronger measures, gaps remain across banking, telecom, investigation, prosecution and information sharing—precisely the gaps that organised cybercriminal networks exploit.
These systemic shortcomings were brought into sharp focus by the police in Hyderabad during Operation Octopus, a pan-Indian investigation conducted between February and May 2026. More than 32 teams were sent across 16 states, and hundreds of arrests were made. The first phase identified mule accounts and mule SIM cards as the two key enablers of cyber fraud. Explaining why investigators subsequently shifted their focus, Sajjanar told THE WEEK: "Irrespective of the type of cyber scam, the gangs can receive and launder money only through mule accounts and communicate through mule SIM cards. Without these two, cybercrime cannot happen."
Once the police under him identified mule accounts and mule SIM cards as the backbone of cyber fraud, the second and third phases shifted focus to the institutions supplying them. Police teams investigated banks and telecom service providers, leading to the arrest of dozens of bank officials and telecom executives allegedly involved in facilitating mule accounts and mule SIM cards.
The investigation uncovered several systemic weaknesses that continued to fuel the cyber fraud ecosystem. It found that incentives to open new bank accounts and issue SIM cards, coupled with weak penalties for KYC violations, fuelled the proliferation of mule accounts and mule SIM cards. It also found that once a mule bank account or SIM card was detected, there was no mechanism to identify and block the holder's other accounts or SIM connections across institutions. As a result, cybercriminals could continue opening new bank accounts and obtaining additional SIM cards despite already being linked to cyber fraud, allowing them to replenish their infrastructure faster than law-enforcement agencies could dismantle it.
Drawing on these findings, in June 2026, the police prepared a document identifying the reforms needed to curb the proliferation of mule accounts and mule SIM cards. Titled Preventing Cyber Financial Crime, the document contains 52 recommendations for systemic, regulatory and legal reform, mapping the grey areas—the specific, fixable gaps where the system currently fails.
The document suggests outlawing muling along the lines of the Philippines, which has introduced a comprehensive anti-muling law that clearly notifies all stakeholders of their duties and penalises any lapses. The Philippines enacted the Anti-Financial Account Scamming Act (AFASA) in 2024 to directly target the financial infrastructure used by cybercriminals.
AFASA criminalises the recruitment and use of money mules, prohibits the opening of accounts using fake or stolen identities, empowers banks to freeze suspicious transactions, and mandates stronger customer verification and fraud-monitoring systems. It also enables faster information sharing among banks, regulators and law-enforcement agencies. It treats muling not merely as a collection of individual offences, but as part of the financial infrastructure that enables organised cybercrime.
Cybercriminals can steal and move money within minutes, while investigators spend weeks tracing it through layers of mule accounts. The response to such a crime cannot continue to move at administrative speed. Taking a long time on implementation could only produce more victims. The government clearly knows what the solutions are and has the technology and resources to implement them—it need only act on them.