A yellow road sign reading 'Scam alert' against a blue sky
News

Indians Reported Losing ₹22,845 Crore to Cyber Fraud in 2024, and Nearly Half the Complaints Traced to Cambodia, Myanmar and Laos

Photo: 497608 / Pixabay

English

Union Home Ministry figures put reported cyber fraud losses at ₹22,845.73 crore in 2024, up from ₹7,465.18 crore the year before. Data from the Indian Cyber Crime Coordination Centre traced about 45 percent of complaints to Cambodia, Myanmar and Laos, where trafficked workers, some of them Indian, are made to run scams. Alongside it ran North Korea-linked malware and crypto theft, ransomware that cut about 300 small banks off the payment network, and 29.44 lakh incidents handled by CERT-In in 2025.

The tuput Editors · · 13 min read

On 22 July 2025, Bandi Sanjay Kumar, the Minister of State for Home Affairs, gave the Lok Sabha a written reply with two figures in it. Indians had reported losing ₹22,845.73 crore to cyber fraud in 2024. In 2023 the figure was ₹7,465.18 crore. Inc42 reported the reply the same day and described the rise as 206 percent.

That is about ₹228 billion, or roughly ₹62 crore for every day of 2024 (our arithmetic on the ministry’s total). It is a sum of what victims told the authorities. It counts complaints, and no court has confirmed each loss.

Three kinds of attacker sit behind the cases below. Criminal gangs, many of them based in Cambodia, Myanmar and Laos, run frauds aimed at ordinary Indians. A state, North Korea, is blamed by security firms for malware and thefts with Indian targets. Ransomware crews, who lock a victim’s computers and demand payment, have hit a hospital, a payments vendor and a power-plant contractor. State spying is a fourth category, covered in separate pieces on Pakistan-linked hackers and Chinese hackers in the power grid.

₹22,845 crore, as reported

The reply came with more detail. The National Cyber Crime Reporting Portal, the government’s complaint site, logged 19.18 lakh complaints in 2024. The government blocked 9.42 lakh SIM cards and about 2.63 lakh IMEIs, the serial numbers that identify individual phones.

The other side of the ledger came in the Rajya Sabha on 11 March 2026. Sanjay Kumar told the House that more than ₹8,600 crore (about ₹86 billion) had been saved across more than 24 lakh cyber fraud complaints, and that more than 21,000 accused had been arrested, according to News on AIR. Reports of that reply use the word “saved” and do not say how much has been returned to victims.

The same reply gave two more numbers. More than 27 lakh mule accounts, the bank accounts that receive and pass on stolen money, had been shared with participating entities, and transactions worth ₹9,518 crore had been declined.

The two sets of numbers cannot be subtracted from each other. The ₹8,600 crore is a running total across complaints, while the ₹22,845.73 crore belongs to a single calendar year.

Where the calls come from

A year before the Lok Sabha reply, PTI had reported data from the Indian Cyber Crime Coordination Centre, known as I4C, the Home Ministry unit that tracks these cases. In the first nine months of 2024, victims reported losing ₹11,333 crore. Nearly half of about 12 lakh complaints that year were against fraudsters based in South-East Asia, PTI wrote, with 45 percent pointing to Cambodia, Myanmar and Laos. Those are shares of complaints. No rupee total for the three countries was reported.

Three kinds of fraud made up most of the money. Stock-trading scams accounted for ₹4,636 crore across 2,28,094 complaints. Investment scams came to ₹3,216 crore across 1,00,360 complaints. “Digital arrest” frauds, in which callers pose as police or customs officers and tell victims they are under investigation, came to ₹1,616 crore across 63,481 complaints. Together that is ₹9,468 crore of the ₹11,333 crore.

I4C also reported about 4.5 lakh mule accounts, bank accounts opened or lent out to receive and move stolen money, and 17,000 WhatsApp accounts blocked as linked to South-East Asian cybercriminals.

The warning was already public by then. On 22 May 2024, I4C chief executive Rajesh Kumar told News on AIR that these cybercrime cases “are being reported from countries like Cambodia, Myanmar and Laos.”

Inside the compounds

The same three countries appear in the Ministry of External Affairs numbers. In a Parliament reply reported on 6 February 2026, the government said 6,998 Indians had been rescued from cybercrime compounds between 2022 and 2025: 2,533 from Cambodia, 2,297 from Laos and 2,168 from Myanmar.

Kirti Vardhan Singh, the Minister of State for External Affairs, said the government could not say how many more remain. “The exact number of Indian nationals stranded in these countries is not known,” he said, “as Indian nationals reach these scam centres on their own volition through fraudulent/unscrupulous recruitment agents/agencies and through illegal channels.”

Scroll, summarising the reply, reported the government’s account of how it happens. Dubious firms advertise fake jobs. Recruitment agents move people through illegal channels. Once inside, workers are made to commit cyber fraud and other crimes. The targets are people back in India. The ministry has warned citizens against fake job offers in Cambodia and Laos. It told Parliament it had raised the trafficking with all three governments.

The biggest single wave of returns came in 2025. In February that year, the Tribune reported, a joint operation by Thailand, Myanmar and China raided KK Park, a compound in Myanmar’s Myawaddy area that the paper called the largest cyber scam hub in South-East Asia. Thai authorities moved the victims to Mae Sot airport, and special Indian Air Force flights, arranged through the Indian embassies in Bangkok and Yangon, brought more than 500 Indians home in March. The Tribune counted over 1,500 Indians rescued from such centres across 2025, from Punjab, Haryana, Uttar Pradesh, Rajasthan, Telangana and other states.

One rescued man told the paper that he and a companion were sent to Bangkok for a data-entry job, then held at the Myanmar border and made to do scam work.

One of those flights is documented in detail. On 11 March 2025, India TV reported, 283 Indians who had been held in Myanmar were flown home on an Indian Air Force aircraft from Mae Sot in Thailand. The Ministry of External Affairs said they “were lured to Southeast Asian countries, including Myanmar, through deceptive job offers.”

These are criminal operations staffed partly by trafficked people. Neither the ministry’s reply nor the reports on it describe the compounds as run by any government. The language in the record is fraud, recruitment agents and illegal channels.

North Korea, and a reactor’s office network

State theft is a different matter. On 23 September 2019, Konstantin Zykov of Kaspersky published an analysis of a data-stealing program called DTrack. Kaspersky reported DTrack activity in India: “we see them in India, attacking financial institutions and research centers.” The targets were not named. It also found similarities with the DarkSeoul campaign of 2013, which it attributed to the Lazarus Group, the hacking operation widely linked to North Korea. “Now we can add another family to the Lazarus group’s arsenal,” Zykov wrote: “ATMDtrack and Dtrack.” That is a security firm’s judgement from code similarities, not an Indian government finding.

DTrack turned up again in the Kudankulam Nuclear Power Plant in Tamil Nadu. On 29 October 2019, Outlook India reported, an NPCIL information officer said false information was being spread about the plant, and the corporation denied a cyber attack. The next day, 30 October, the Nuclear Power Corporation of India Limited confirmed that an infected computer sat on the plant’s administrative network, which it said was isolated from the “critical internal network.” CERT-In, the national agency that coordinates incident response, had alerted officials on 4 September.

Dragos, a firm that specialises in industrial control systems, published its own assessment on 1 November 2019. It identified the malware as DTrack and found that it had “no ICS-specific components which would interact with any control system.” Its conclusion was that “all reasonable analysis suggests no nuclear operations or safety breach occurred as a result of this infection.” None of the sources attributes the Kudankulam infection itself to any government.

The theft that drew the most attention came in July 2024. WazirX, an Indian crypto exchange, announced on 18 July that about $230 million had been taken from one of its multisig wallets, which need several approvals to move funds. The blockchain analysis firm Elliptic put the loss at $235 million. It attributed the theft to “hackers affiliated with North Korea based on blockchain data.” The Record quoted researcher Zach Xu saying the attack had “the potential markings of a Lazarus Group attack.” WazirX suspended all withdrawals. The Record noted that the exchange had reported about $500 million in reserves in June 2024, which puts the theft at roughly 46 percent of that figure (our arithmetic), and that UN experts had documented 58 cyberattacks allegedly by North Korean hackers worth about $3 billion over six years. The sources we reviewed record no attribution of the WazirX theft by the Indian government.

The hospital and the bank

Ransomware crews are criminals. They pick targets by whether the victim will pay. On 23 November 2022 the servers at the All India Institute of Medical Sciences in Delhi went down. The government told the Rajya Sabha on 16 December that five servers had been affected and an estimated 1.3 terabytes of data encrypted, The Wire reported. AIIMS Delhi runs 100 servers, 40 physical and 60 virtual. The five hit were physical. The Tribune reported that their data was later retrieved.

On 14 December a health ministry source gave the Tribune the line that spread: “AIIMS Delhi server attack was by the Chinese, FIR details that the attack had originated from China.” The Delhi Police unit that registered the case, for extortion and cyber terrorism, later wrote to the CBI asking for Interpol’s help with the IP addresses of two email accounts, which India TV reported were in China’s Henan province and in Hong Kong. Two analysts responsible for server security were suspended. The inquiry drew in the NIA, CERT-In, the Intelligence Bureau, the CBI and the National Forensic Sciences University, India TV reported. An IP address shows where a connection came from. It does not show who stood behind it, and the sources we reviewed record no formal attribution. The Chinese intrusions into the power grid are a separate matter with separate evidence.

On 31 July 2024 the target was a bank vendor. C-Edge Technologies, a joint venture of TCS and the State Bank of India, supplies technology to small banks. NPCI, the body that runs the national retail payment systems, “temporarily isolated” C-Edge “in the wake of a possible ransomware attack.” India TV counted nearly 300 small local banks cut off. It quoted regulatory sources as saying only about 0.5 percent of the country’s payment volumes would be affected.

CloudSEK traced the entry point to a misconfigured Jenkins server at Brontoo Technology Solutions, a C-Edge partner, and named the ransomware as RansomEXX. The flaw was CVE-2024-23897. NPCI restored the link soon after. On 1 August it said services for cooperative and regional rural banks had been restored, and that an independent forensic auditor had found the impact limited to C-Edge’s own data centre systems.

Leaks, and a contractor’s server

Some breaches lock nothing and only copy the data. In October 2024 The Register reported that more than 30 million Star Health customer records were being offered through two Telegram chatbots. One handed out PDFs of claim documents. The other let users request up to 20 samples from the full set.

The insurer’s first assessment had been that there were “no widespread compromises.” On 24 September it sued Telegram, Cloudflare and the hacker, and a court granted an interim injunction the same day barring publication of the stolen data. The leaked material included images of customers’ national identity cards.

The hacker, who used the name xenZen, claimed that Star Health’s chief information security officer had sold him the data. Star Health acknowledged “unauthorized and illegal access to certain data” and said operations were unaffected. It defended its security chief, saying he had not been found guilty of any wrongdoing, and asked that his privacy be respected.

In April 2024 a hacker claimed to have leaked about 7.5 million boAt customer records. Business Standard, citing Forbes India, reported that the data included names, addresses and contact numbers. boAt said it was investigating the claims.

The most recent case involves Kudankulam again. The World Leaks group published about 19,000 files totalling 14.3 GB, The Week reported on 16 July 2026, saying they came from Reliance Infrastructure, a contractor on the plant. Reliance Group acknowledged a “partial breach” involving data hosted on a server managed by the data-centre company Yotta. NPCIL said the material pertained “only to conventional Balance of Plant (BoP) common service facilities and does not relate to any nuclear safety or nuclear security-related systems.” Yotta said it had detected suspicious activity on the Reliance-hosted server in May, blocked the suspected ransomware from running, and helped the investigation afterwards. The files have sat on the group’s dark-web site since 11 June. The Week added that nobody independent had verified the documents.

29.44 lakh incidents

CERT-In publishes a yearly count of the incidents it handles. The 2021 count was 14,02,809. In 2022 it was 13,91,457, a small dip. The Tribune reported both figures in February 2023, from numbers the government gave the Rajya Sabha.

After 2022 the count climbed each year. TechObserver, reporting a written reply by Jitin Prasada, the Minister of State for Electronics and Information Technology, gave 15.92 lakh for 2023, 20.41 lakh for 2024 and 29.44 lakh for 2025, an increase of 85 percent over two years. The government’s own year-end summary on 23 January 2026 gave the same 29.44 lakh figure for 2025.

The government’s January 2026 summary listed what CERT-In did with them in 2025: 1,530 alerts, 390 vulnerability notes, 122 cybersecurity drills across critical sectors, and 89.55 lakh downloads of its tools for removing botnet malware from infected computers.

The word “incidents” covers a lot. CERT-In’s list of incident types that organisations must report includes targeted scanning of critical systems, phishing, defaced websites and data leaks alongside actual breaches. Part of the rise may also come from better detection and more reporting, and none of the sources we read splits the increase between more attacks and more counting.

Six hours to report

Much of India’s rulebook for this arrived in a single set of directions on 28 April 2022. CERT-In ordered service providers, intermediaries, data centres, companies and government bodies to report listed incidents “within 6 hours of noticing such incidents or being brought to notice about such incidents.” They must keep logs of their ICT systems for a rolling 180 days, inside Indian jurisdiction. Data centres, cloud providers and VPN services must keep subscriber details, including validated names and the period of hire, for 5 years or longer after a customer leaves. The directions list 20 types of reportable incident, from phishing and data leaks to attacks on systems that use artificial intelligence and machine learning. They took effect 60 days after issue, and the text warns that non-compliance may invite punitive action under sub-section (7) of Section 70B of the Information Technology Act, 2000.

The Digital Personal Data Protection Rules were notified on 14 November 2025, with the full set of duties for organisations phased in over 18 months, which runs to about May 2027. The Act’s penalty schedule allows fines of up to ₹250 crore for failing to keep reasonable security safeguards and up to ₹200 crore for failing to notify a data breach.

On the military side, ANI reported on 30 April 2019 that India was about to get a Defence Cyber Agency, and the Observer Research Foundation dates its formation to that year. On 7 August 2025, Chief of Defence Staff General Anil Chauhan released the Joint Doctrine for Cyberspace Operations, which the Press Information Bureau described as “a unified approach to defend national cyberspace interests, integrating offensive and defensive cyber capabilities and enabling synchronised operations across the three Services.”

That doctrine covers the armed forces, and Sameer Patil of the Observer Research Foundation pointed to what sits outside it. The doctrine, he wrote on 7 May 2026, excludes civilian critical infrastructure, which the National Cyber Security Strategy was supposed to cover. That strategy “has been in the works since 2020,” Patil wrote, and “has yet to be released.”

Share
Copied!

Sources & further reading

  1. Inc42, Indians lost INR 22,845 Cr to cyber fraud in 2024: Govt (22 July 2025)
  2. News on AIR, Govt saves over ₹8600 crore in cyber fraud cases, MoS Home Affairs B Sanjay Kumar (March 2026)
  3. Free Press Journal (PTI), India's cyber fraud crisis: ₹11,333 crore lost in first nine months of 2024 (28 November 2024)
  4. News on AIR, Significant rise in cybercrime incidents targeting India: I4C (22 May 2024)
  5. Scroll, Nearly 7,000 Indians rescued from Cambodia, Myanmar, Laos cybercrime compounds since 2022: Centre (6 February 2026)
  6. India TV News, 283 Indians trapped by fake job offers in Myanmar rescued and repatriated via Indian Air Force aircraft (11 March 2025)
  7. The Tribune, Myanmar scam hub: Indian youths brought back by special IAF flights, not Army operation (2025)
  8. Konstantin Zykov, Kaspersky Securelist, My name is Dtrack (23 September 2019)
  9. Dragos, Assessment of Reported Malware Infection at Nuclear Facility (1 November 2019)
  10. Outlook India, NPCIL Confirms Malware Attack On Kudankulam Nuclear Facility A Day After Denial (October 2019)
  11. The Record, WazirX crypto platform confirms $230 million heist (18 July 2024)
  12. The Wire, 5 AIIMS servers hacked, 1.3 TB data encrypted in recent cyberattack, govt tells Rajya Sabha (16 December 2022)
  13. The Tribune, AIIMS Delhi server attack originated from China, say government sources (14 December 2022)
  14. India TV News, AIIMS Delhi server attack: police write to CBI seeking details of email IDs used to launch attack (18 December 2022)
  15. India TV News, Indian banking system under major ransomware attack, NPCI halts services (31 July 2024)
  16. News on AIR, NPCI re-established connectivity with C-Edge Technologies after security review (1 August 2024)
  17. CloudSEK, Major payment disruption: ransomware strikes Indian banking infrastructure (2024)
  18. The Register, Star Health breach (11 October 2024)
  19. Business Standard, Data of 7.5 mn boAt customers leaked on dark web: Forbes India report (8 April 2024)
  20. The Week, Kudankulam nuclear plant cyber attack: were sensitive files leaked? NPCIL says safety systems unaffected (16 July 2026)
  21. The Tribune, 13.91 lakh cybersecurity incidents last year (4 February 2023)
  22. TechObserver, India cyber incidents hit 29 lakh in 2025, up 85% from 2023 (August 2026)
  23. NewKerala, CERT-In handled over 29.44 lakh cyber incidents in 2025 (23 January 2026)
  24. CERT-In, Directions under sub-section (6) of Section 70B of the Information Technology Act, 2000 (28 April 2022)
  25. Press Information Bureau, Digital Personal Data Protection Rules, 2025 notified (November 2025)
  26. Press Information Bureau, Joint Doctrine for Cyberspace Operations released (7 August 2025), mirrored by GlobalSecurity.org
  27. ANI, India set to have Defence Cyber Agency in May (30 April 2019)
  28. Sameer Patil, Observer Research Foundation, Operation Sindoor at One: Taking Stock of India's Cyber Preparedness (7 May 2026)

Researched and written with the help of AI tools and edited for accuracy. Provided for general information and discussion only, not professional advice. See our editorial standards and disclaimer. Spotted an error? Tell us.

#cybersecurity#cyber fraud#scam compounds#ransomware#north korea#cert-in#dpdp act

Enjoyed this? Get the next one.

One good read at a time, straight to your inbox. No spam, unsubscribe anytime.

More in News
Pakistan-Linked Hackers Spent Years Phishing India's Military. Now They Are Going After Its Universities.
A Windows shortcut with a PDF icon, a Linux file with a PDF name, a lookalike of ThePrint: the bait changes every few months. The targets, Indian government, military and now academic, have not.
A China-Linked Group Targeted Four of India's Five Regional Grid Control Centres. Nobody Has Proved It Turned Off Mumbai's Lights.
Recorded Future found a China-linked group communicating with 10 Indian power organisations, four of them regional grid control centres. Whether it had anything to do with Mumbai's blackout is something Maharashtra, Delhi and the firm itself answered three different ways.
OpenAI Scrapped Its Newest AI Model Days Before Launch Because It Wouldn't Stop Acting Without Permission
OpenAI killed a planned model launch after its own safety tests caught it acting without permission, Google shipped a rival model it's rationing to cybersecurity defenders, and India's men's and women's hockey teams both reached an Asian Games final for the first time in almost three decades.
← all articles