Skip to content

Cyber Security

Basics of Cyber Security


Cyber Threat Landscape & Components

Cyber Threat Landscape & Components
Cue WordsNotes
What are the key classes of cyber threats? Provide examples.
    Key threat vectors:
  • Malware: Ransomware (WannaCry, Locky), Spyware (Pegasus), Worms, and Trojans.
  • Social Engineering: Phishing, Spear Phishing (highly targeted).
  • Infrastructure Attacks: DDoS (Traffic flooding), SQL Injection, Zero-Day exploits.
  • State-Sponsored Actors: Advanced Persistent Threats (APTs) like Lazarus Group (NK), APT10 (China).
What are the six core components of a robust cybersecurity system?
  • Cyber Security Components:
    1. Application Security: Secure coding, regular patches, vulnerability testing.
    2. Information Security: Data encryption (at rest/in transit), access controls (IAM), data loss prevention (DLP).
    3. Network Security: Firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), VPNs.
    4. Operational Security: Strict security policies, employee access control, incident response.
    5. Disaster Recovery & Business Continuity: Backup systems, hot sites, recovery procedures.
    6. End-user Education: Security awareness, phishing simulations, password hygiene.
Why is cybersecurity critical for national security and strategic autonomy?
    Need and Importance:
  • National Security: Protects critical infrastructure (power, dams, defense communications) and prevents cyber-terrorism.
  • Economic Security: Secures payment gateways (UPI, SWIFT), stock exchanges, and guards against intellectual property theft.
  • Social Stability: Prevents cyber-bullying, identity theft, and secures personal data.
  • Governance: Secures Digital India databases (Aadhaar, DigiLocker, voter registries).
  • Strategic Autonomy: Promotes indigenous tech stacks, reducing reliance on vulnerable foreign software/hardware.

Cyber Crimes & Warfare: The Fifth Domain

Cyber Crimes & Warfare: The Fifth Domain
Cue WordsNotes
Classify the different types of cybercrimes with Indian contexts.
    Classification of Cybercrimes:
  • Financial Crimes: UPI/net banking fraud, card cloning/skimming, cryptocurrency theft.
  • Data Breaches: Aadhaar/PAN leaks, corporate espionage, medical records theft.
  • Social Crimes: Cyber bullying, stalking, revenge porn, and sextortion.
  • Against Individuals: Identity theft, online harassment, lottery/job scams.
  • Against Organizations: Ransomware (WannaCry), DDoS disruption, defacement.
  • Against Government: Critical infrastructure targets, cyber espionage, state-sponsored misinformation.
How does Cyber Warfare differ from Traditional Warfare across key operational parameters?
    Cyber Warfare (The Fifth Domain) vs Traditional Warfare:
  • Attribution: Traditional is clear and unambiguous. Cyber is extremely difficult to attribute due to proxy servers/spoofing.
  • Geography: Traditional is bound by physical frontiers. Cyber is completely borderless.
  • Cost: Traditional is highly capital-intensive. Cyber has a very low entry barrier.
  • Speed: Traditional requires mobilization time. Cyber is instantaneous.
  • Casualties: Traditional results in direct physical casualties. Cyber results in economic and system disruption.
  • Legal Framework: Traditional is governed by Geneva Conventions. Cyber is governed by emerging, non-binding global norms.
What are the key foreign cyber threat actors targeting India?
    Hostile State Actors:
  • China: APT groups (APT1, APT10) targeting power grids and space institutions.
  • Pakistan: Inter-Services Intelligence (ISI) cyber cells pushing malware and fake news.
  • North Korea: Lazarus Group conducting ransomware and crypto-heists for state revenue.

India's Cyber Vulnerabilities


Vulnerability Analysis & Historic Attacks

Vulnerability Analysis & Historic Attacks
Cue WordsNotes
What are the main technical, human, and regulatory vulnerabilities in India's cyber ecosystem?
    Key Vulnerabilities:
  • Infrastructure & Technical: Outdated legacy software in government offices, poor patch management, and high import dependence for hardware/chips (supply chain risk).
  • Human Factors: Low digital literacy, weak passwords, susceptibility to social engineering, and a severe shortage of skilled cyber professionals.
  • Organizational: Inadequate cybersecurity budgets, lack of periodic third-party audits, and poor incident response systems.
  • Legal & Regulatory: Slow judicial processes under the outdated IT Act (2000) leading to low conviction rates.
Detail major cyberattacks in India and the average cost of data breaches.
    Major Incidents & Statistics:
  • 2020 Mumbai Power Outage: Suspected Chinese malware targeted SCADA systems, causing grid failure.
  • 2021 AIIMS Ransomware: Encrypted critical patient databases, disrupting healthcare delivery for weeks.
  • Aadhaar & CoWIN leaks: Recurrent security alerts over the exposure of personal data of millions.
  • 2016 Debit Card Hack: Compromised 3.2 million debit cards across major Indian banks.
  • Statistics: India ranks as the 3rd most targeted country globally. The average cost of a data breach in India is estimated at ₹17.9 crore.

Critical Information Infrastructure (CII)

Critical Information Infrastructure (CII)
Cue WordsNotes
Define Critical Information Infrastructure (CII) and its legal protection in India.
  • CII Definition:
  • Under Section 70 of the IT Act 2000, CII is defined as any computer resource, the destruction or disruption of which would have a debilitating impact on national security, economy, public health, or safety.
Identify the seven key sectors designated as CII.
  • Designated CII Sectors:
    1. Power and Energy (Grid stations, nuclear plants)
    2. Banking and Finance (Payment networks, stock exchanges)
    3. Telecommunications (Fiber networks, data centers)
    4. Transport (Air traffic control, railways, metros)
    5. Government (Sovereign databases, e-gov systems)
    6. Strategic Enterprises (Space, defense)
    7. Healthcare (Vaccine management, hospitals)
What is the role of NCIIPC? Specify its parent agency and year of establishment.
  • NCIIPC:
  • Established in 2014 under Section 70A of the IT Act. It functions under the National Technical Research Organisation (NTRO) as the national nodal agency for protecting Critical Information Infrastructure.
What are the operational challenges and way forward for protecting India's CII?
    CII Protection Strategy:
  • Challenges: Securing legacy OT/SCADA systems, supply-chain vulnerabilities, and coordinate gaps between private and public operators.
  • Way Forward: Mandate **Air-Gapping** for nuclear/grid controls, establish redundancy (backups), conduct mandatory third-party audits, and create Public-Private Partnerships for threat sharing.

Government Initiatives


Institutional and Legal Framework
Cue WordsNotes
What is CERT-In? Detail its nodal role, parent ministry, and reporting guidelines.
    CERT-In (Indian Computer Emergency Response Team):
  • Established in 2004 under the Ministry of Electronics and Information Technology (MeitY).
  • It is the national nodal agency for responding to computer security incidents, running situational alerts, and issuing threat advisories.
  • UPSC Trap Under 2022 guidelines, CERT-In mandates all entities to report cyber incidents within 6 hours of detection.
What is the I4C? Specify its ministry, nodal portal, and core modules.I4C (Indian Cybercrime Coordination Centre): - Established in 2020 under the Ministry of Home Affairs (MHA). - Acts as a comprehensive portal to fight cybercrimes, hosting the National Cybercrime Reporting Portal (Helpline 1930). - Features the National Cybercrime Threat Analytics Unit (TAU), Joint Cybercrime Investigation Team, and the National Cybercrime Forensic Laboratory.
Explain the key sections of the IT Act 2000 and the controversy surrounding Section 66A.
    IT Act 2000 Key Sections:
  • Section 43: Penalty for damage to computer system/unauthorized access.
  • Section 66: Computer-related offenses (hacking, data theft).
  • Section 66A: Punishment for sending offensive messages (Struck down by SC in Shreya Singhal vs Union of India (2015) for violating Article 19(1)(a)).
  • Section 66F: Defines and punishes Cyber Terrorism with life imprisonment.
  • Section 69: Government power to intercept, monitor, or decrypt information.
  • Section 70: Legal declaration of Protected Systems (CII).
Detail the compliance requirements introduced under the IT Rules 2021 and 2023 Amendments.
    IT Rules 2021 & 2023:
  • Traceability: Obligates messaging platforms to identify the first originator of a message.
  • SSMIs: Significant Social Media Intermediaries (5M+ users) must appoint a Chief Compliance Officer, Resident Grievance Officer, and Nodal Contact Person.
  • Grievance Appellate Committees (GACs): 2023 amendment set up government panels to hear user appeals against intermediary content moderation decisions.
Outline the core principles, duties, and penalties under the Digital Personal Data Protection (DPDP) Act, 2023.
    DPDP Act 2023:
  • Constitutional Basis: Rooted in Article 21 (Right to Privacy) following the K.S. Puttaswamy judgment.
  • Entities: Identifies the Data Principal (individual) and Data Fiduciary (data processor).
  • Core Principles: Informed consent, purpose limitation, storage limitation, and data minimization.
  • Data Protection Board of India (DPBI): Set up as the independent, digital-first adjudicatory body.
  • SDFs: Significant Data Fiduciaries face higher compliance (data impact assessments, independent audits).
  • Penalties: Graded financial penalties capped at ₹250 crore for failure to prevent data breaches.
  • Mains Critique: Broad exemptions granted to state agencies on sovereignty/security grounds, lack of data portability rights, and potential dilute of the RTI Act.

Schemes, R&D and Global Alliances

Schemes, R&D and Global Alliances
Cue WordsNotes
What is the Cyber Surakshit Bharat Initiative?
  • Cyber Surakshit Bharat (2018):
  • Launched by MeitY in partnership with industry leaders to spread awareness about cyber hygiene and train Chief Information Security Officers (CISOs) in government departments.
Detail the functions of Cyber Swachhta Kendra and NCCC.
    Defense Tools & Monitoring:
  • Cyber Swachhta Kendra: Botnet cleaning and malware analysis center, providing free malware detection tools to citizens.
  • Sanchar Saathi & Chakshu Portal: DoT citizen portal to report fraud calls/messages (Chakshu) and block/trace lost or stolen phones (via the CEIR database).
  • NCRF (National Cybersecurity Reference Framework): Guidelines issued by NCIIPC defining governance standards for IT and Operational Technology (OT) networks.
  • NCCC (National Cyber Coordination Centre): Under MeitY; performs metadata-level scanning to provide real-time situational awareness of cyber threats.
Explain the role of DCyA and NATGRID.
    Special Agencies:
  • Defense Cyber Agency (DCyA): Tri-service command responsible for offensive and defensive military operations in cyberspace.
  • NATGRID: A centralized intelligence-sharing platform connecting 21 databases of security and intelligence agencies.
What is the Budapest Convention? Explain India's stance and the reasons behind it.
    Budapest Convention on Cybercrime (2001):
  • The first international treaty addressing computer crimes by harmonizing national laws.
  • UPSC Trap India is NOT a signatory.
  • Stance: India argues the convention was drafted without its participation, conflicts with national sovereignty (allows foreign agencies cross-border access to data without local warrants), and advocates instead for a UN-led multilateral framework.
Identify key bilateral and multilateral alliances India uses for cyber diplomacy.
    Cyber Diplomacy:
  • UN GGE: Participates in establishing voluntary norms for state behavior.
  • SCO & BRICS: Cooperative cyber-drills and joint ICT security working groups.
  • Bilateral Joint Working Groups: Active frameworks with the US (US-India Cyber Dialogue), Japan, Israel, and the UK for real-time intelligence sharing.

Emerging Technologies & Challenges


Facial Recognition & Surveillance Backing

Facial Recognition & Surveillance Backing
Cue WordsNotes
What is NAFRS? Detail its implementation and key concerns.
    NAFRS (National Automated Facial Recognition System):
  • Implemented by the NCRB (National Crime Records Bureau) to create a centralized database of photographs for matching against CCTV feeds.
  • Benefits: Speeds up criminal tracking, search for missing children, and border verification.
  • Concerns: High risk of mass surveillance, high false-positive rates (especially for women/minorities), lack of explicit user consent, and functioning in a legislative vacuum without dedicated FRT laws.
Detail the legal backing and oversight mechanism for state surveillance in India.
    Surveillance Framework:
  • Legal Backing: Section 69 of the IT Act (for digital intercepts) and the Indian Telegraph Act 1885 (for phone tapping).
  • Authorization: Interception orders must be signed by the Union Home Secretary (Centre) or State Home Secretary (States).
  • Oversight: Orders are subject to review by a cabinet-level Review Committee to prevent arbitrary misuse.
  • Pegasus Controversy (2021): Highlighted vulnerabilities regarding zero-click commercial spyware targeting civil society, reinforcing the need for independent judicial warrant systems.
What is the Puttaswamy proportionality test for state surveillance?
  • Proportionality Test (Puttaswamy 2017):
  • State surveillance must satisfy four criteria:
    1. Legality: Backed by a clear, accessible law.
    2. Necessity: Must serve a legitimate state aim (e.g., national security).
    3. Proportionality: The least intrusive method must be used.
    4. Procedural Safeguards: Must be subject to independent oversight (judicial/parliamentary).

Challenges & Way Forward

Challenges & Way Forward
Cue WordsNotes
Summarize the core structural challenges facing India's cybersecurity.
    Key Challenges:
  • Technical: Extreme hardware import dependency, lack of native OS/chip fabrication, and slow adoption of quantum-safe encryption.
  • Skill Deficit: Shortage of estimated 1 million cybersecurity professionals; brain drain of top talent.
  • Prosecution: Low conviction rate in cybercrimes (below 5%) due to poor forensic collection and police training.
  • International: Borderless nature of attacks and safe havens in hostile nations make prosecution almost impossible.
What are the key policy and institutional recommendations for a secure cyber future?
    Way Forward Actions:
  • Policy: Enact a unified National Cyber Security Strategy (updating the 2013 Policy), and include safe harbor protections for ethical security researchers.
  • Institutional: Create a single-command National Cyber Security Agency (NCSA) to streamline actions across CERT-In, MHA, and Defense.
  • Capacity: Fund cybersecurity academies in IITs/NITs, mandate cyber hygiene education in schools, and set up state-level cyber forensics laboratories.
  • Technology: Incentivize indigenous hardware and software fabrication (Security-by-Design), launch national bug bounty programs, and build quantum-key distribution networks.

Recent Developments (2025–26)


Financial & Crypto Cyber Incidents

Financial & Crypto Cyber Incidents
Cue WordsNotes
What DDoS-related steps did banks take after FM's cybersecurity review meeting?
    Bank DDoS Preparedness:
  • FM chaired a review of financial-sector cybersecurity; banks must designate 2 senior officials — one for cyber incident reporting, one for operational continuity (ATM cash availability).
  • Banks confirmed deployment of anti-DDoS systems; DDoS uses a **botnet** (multiple compromised systems), unlike single-source DoS attacks.
  • **Bot detection** (e.g., CAPTCHA) helps identify and block automated attack tools.
Detail the CoinDCX and WazirX crypto exchange breaches.
    Crypto Exchange Hacks:
  • WazirX (2024): North Korean attackers exploited a multi-signature wallet, stealing $230 million — India's largest crypto breach.
  • CoinDCX (2025): FIU-registered exchange (1.6 crore users) had an operational **hot wallet** on a partner exchange compromised via server breach; only internal liquidity affected, no customer funds lost.
  • Stablecoins/CBDC: US passed GENIUS Act (enables dollar-backed stablecoins), CLARITY Act, and Anti-CBDC Act amid de-dollarisation concerns post-2022 Russia sanctions.

Quantum Threats & Emerging Fraud Vectors

Quantum Threats & Emerging Fraud Vectors
Cue WordsNotes
What is Harvest Now, Decrypt Later (HNDL) and why does quantum computing threaten encryption?
    Quantum Cyber Readiness:
  • MeitY, CERT-In, and SISA released whitepaper "Transitioning to Quantum Cyber Readiness."
  • Quantum computers threaten RSA-based cryptography by solving complex problems far faster than classical computers.
  • HNDL (Harvest Now, Decrypt Later): adversaries store encrypted data today to decrypt once quantum decryption becomes feasible.
What is APK fraud and how is it reported/investigated in India?
    APK Scams & Reporting Infrastructure:
  • Malicious APK apps mimic official portals to trick users into granting permissions, spreading malware.
  • National Cyber Crime Reporting Portal (launched 2019, dedicated 2020 under I4C/MHA) covers financial fraud, ransomware, cyberbullying, online stalking; supports anonymous filing and complaint tracking via reference ID.
Explain 2FA mechanics: TOTP, HOTP, and hardware tokens.
    Two-Factor Authentication (2FA):
  • First factor: something you know (password); second factor: something you have (authenticator app/token).
  • TOTP (Time-based OTP): uses HMAC-SHA-256, codes valid ~30 seconds; device and server compute matching codes independently.
  • HOTP: counter-based instead of time-based; other methods include push-based approval apps and hardware tokens (e.g., YubiKeys).
What legal gaps exist around cyberbullying, doxxing, and deepfake abuse in India?
    Cyberbullying & Legal Gaps:
  • India lacks a dedicated law for online hate speech/sustained trolling; existing BNS (Sections 74, 75, 351, 356, 196) and IT Act (66C, 66D, 67) provisions don't explicitly criminalise persistent non-obscene anonymous abuse.
  • Doxxing (publishing private/identifying info with malicious intent) flagged as a serious threat by Delhi HC (2023); DPDPA's "publicly available data" exemption is undefined, risking cyber-harassment via data aggregation.
  • NCII (Non-Consensual Intimate Image) abuse: deepfake pornography generated without consent; regulatory frameworks remain inadequate.
  • Modern fraud sophistication includes digital arrests (impersonating officials), OTP/UPI frauds, and identity theft via Aadhaar/PAN misuse — punishable under Section 66D of the IT Act (up to 3 years + ₹1 lakh fine).

Recent Cyber Threats & Incidents (2025-26)


Financial, Fraud & Infrastructure Threats

Financial, Fraud & Infrastructure Threats
Cue WordsNotes
What legal gaps exist around cyberbullying, doxxing, and deepfake abuse in India?
    Cyberbullying & Legal Gaps:
  • BNS covers outraging modesty (S.74), sexual harassment (S.75), criminal intimidation (S.351), defamation (S.356); IT Act covers identity theft (S.66C), impersonation (S.66D), obscenity (S.67) — none explicitly criminalise persistent, non-obscene, anonymous online abuse.
  • Doxxing (publishing private/identifying info with malicious intent) was flagged as a serious threat by Delhi HC in 2023; DPDPA's undefined "publicly available data" exemption risks enabling harassment via data aggregation.
  • NCII (Non-Consensual Intimate Image) abuse: AI-generated deepfake pornography without consent — an urgent gap in conventional legal frameworks.
What is a DDoS attack and how is India's financial sector responding?DDoS & Financial Sector: - DDoS floods a target server/network via a botnet (multiple compromised systems), unlike a single-source DoS attack. - Banks now must designate 2 senior officials — one for cyber-incident reporting, one for operational continuity (ATM cash availability) — and deploy anti-DDoS systems. - CAPTCHA-based bot-detection tools help identify and block automated traffic.
What are the CoinDCX and WazirX crypto breaches, and how is the US regulating stablecoins?
    Crypto Exchange Hacks:
  • WazirX (2024): N. Korean attackers exploited a multi-signature wallet, stealing $230M — India's largest crypto breach.
  • CoinDCX (2025): An operational hot wallet on a partner exchange was compromised via server breach; only internal liquidity affected, no customer funds lost.
  • US passed the GENIUS Act (enables dollar-backed stablecoin issuance), CLARITY Act, and Anti-CBDC Act amid de-dollarisation fears post the Russia-Ukraine asset freezes.
What is Quantum Cyber Readiness and the Harvest Now, Decrypt Later threat?
    Quantum Threat:
  • MeitY, CERT-In and SISA released a whitepaper on quantum cyber readiness, warning that quantum computers threaten RSA-based encryption.
  • Harvest Now, Decrypt Later (HNDL): Adversaries store encrypted data today to decrypt once quantum computing matures.
What is the APK scam, and what does the National Cyber Crime Reporting Portal (NCRP) cover?
    APK Fraud & NCRP:
  • APK Scam: Malicious apps mimicking official portals trick users into granting permissions, spreading malware.
  • NCRP: Launched 2019, dedicated to the nation in 2020 under I4C (MHA); covers financial fraud, ransomware, cyberbullying, CSAM, stalking; allows anonymous filing and evidence upload, with 24 crime-type guidelines (phishing, vishing, etc.).

Surveillance, Anonymity & Cybercrime Geography

Surveillance, Anonymity & Cybercrime Geography
Cue WordsNotes
How does 2FA/TOTP work, and what newer authentication methods exist?
    Two-Factor Authentication (2FA):
  • First factor: something you know (password); second factor: something you have (authenticator app).
  • TOTP uses HMAC-SHA-256 to generate a ~30-second numeric code; device and server independently compute matching codes.
  • Other methods: HOTP (counter-based), push-notification 2FA, and hardware tokens (YubiKeys).
What is GhostPairing, and how does VPN traffic create security trade-offs?
    WhatsApp GhostPairing & VPN Risks:
  • GhostPairing: Exploits WhatsApp's "Linked Devices" feature to hijack accounts without passwords/SIM swaps, tricking victims into authorising an attacker's browser as a device.
  • VPNs encrypt traffic and mask IPs but can also shield cybercriminal activity; CERT-In's 2022 directions require VPN providers to log Indian users' data — large firms (ExpressVPN, NordVPN) responded by shifting "India" servers to Singapore while retaining India-linked IP blocks.
  • VPN services were suspended in Poonch and Rajouri districts amid security concerns.
What is GPS/GNSS spoofing, and how does it differ from jamming?
    GPS Spoofing:
  • Spoofing: Transmits counterfeit satellite signals to feed false position/navigation data (seen over Delhi and India-Pakistan border areas).
  • Jamming: Overpowers satellite signals with radio interference to disrupt navigation (distinct from spoofing).
  • Aircraft redundancies (Inertial Reference System) can operate safely for up to 5 hours without primary GPS; NavIC is ISRO's independent regional navigation system.
Where are Southeast Asian cybercrime scam hubs located, and what is the global legal response?
    Scam Hubs & Global Cooperation:
  • KK Park (Myawaddy, Myanmar) — a junta-linked Border Guard Force-controlled compound; other hubs in Cambodia (Sihanoukville, Bavet, O'Smach).
  • Signature fraud: "pig butchering" (investment + romance fraud via fake crypto platforms).
  • The UN Convention against Cybercrime (Hanoi) is the first universal cybercrime treaty; India has not signed it, though SC has urged the Centre to consider ratification.
  • Mule bank accounts launder scam proceeds via layered transactions; RBI launched MuleHunter.AI for detection.
How can Wi-Fi signals enable covert surveillance without network access?
    Wi-Fi Sensing Privacy Risk:
  • Beamforming Feedback Information (BFI), an unencrypted signal routers use for efficient beamforming, can identify individuals from how their bodies disturb Wi-Fi signals — accessible on off-the-shelf hardware (unlike Channel State Information, which needs special firmware).
  • No network access or password needed; creates an "inverse panopticon" — covert tracking unlike visible CCTV.

Revision Strategy

Master Agencies: CERT-In (2004, MeitY), NCIIPC (2014, NTRO), I4C (2020, MHA). Remember Laws: IT Act 2000 (Sections 43, 66, 69, 70), IT Rules 2021 (originator traceability), DPDP Act 2023 (₹250 cr cap, DPBI). Concepts: Fifth Domain of Warfare, APT, Zero-Day Exploit, DDoS, Proportionality Test, NAFRS. Major Attacks: WannaCry 2017, Mumbai Power Outage 2020, AIIMS Ransomware 2021. Diplomacy: Budapest Convention (India is NOT a signatory), UN GGE, SCO.

*Ultra-Fast Revision Series for UPSC CSE.*I'll read the specified section of the notes file and convert every Cyber Security, Money Laundering, Organised Crime, Terrorism, and Military/Police Operations detail into VitePress + Cornell Notes format with zero loss.The military ops are near the end of that range; I'll search the rest of the notes for CERT-In, I4C, PMLA, FATF, NIA, and UAPA.Cyber Security / PMLA / NIA content isn't in that NOTES_FILE range—only the military ops are. I'll locate the full security block in the source materials.Checking for existing Cornell security conversions and reading the I4C/UAPA sections for completeness.Confirming: Cyber Security / PMLA / NIA live in the ECO security source; NOTES_FILE 3401–4224 holds the listed operations. Converting both into zero-loss Cornell notes.# Internal Security — Cyber · Money Laundering · Organised Crime · Terrorism · Military/Police Operations

Source conversion (zero-loss): NOTES_FILE.md lines 4200–4224 (Military/Police Ops) + Security corpus (CERT-In, I4C, PMLA, FATF, NIA, UAPA, Organised Crime) · VitePress + Cornell Notes format


A. Cyber Security (CERT-In, I4C)

CERT-In — Status, Mandate & Key Actions
Cue WordsNotes
What is CERT-In and under which law is it designated?
  • Under Section 70B of the Information Technology (IT) Act, 2000, CERT-In is designated as the national agency for responding to cyber security incidents.
  • It is the central agency for: incident response, vulnerability handling, and security management.
  • It plays a vital role in controlling cybersecurity incidents and coordinating incident response activities.
What are key CERT-In actions / advisories in the notes?
  • Quantum Cyber Readiness: MeitY, CERT-In, and SISA launched whitepaper "Transitioning to Quantum Cyber Readiness" on cybersecurity impact of quantum technologies.
  • Warned quantum computers threaten current encryption (especially RSA); can solve complex problems and do ML/optimization far faster.
  • Highlighted Harvest Now, Decrypt Later (HNDL) attacks — encrypted data stored now, decrypted later.
  • Issued advisory on active threat campaign targeting WhatsApp users using GhostPairing.
  • In 2022, published directions requiring VPN providers to maintain logs of Indian users.
What is Cyber Swachhta Kendra?
  • Initiative focused on detecting and removing malicious botnet programs from computers and devices.
  • Provides free tools for malware analysis and helps improve system security.
I4C — Structure, Portals & e-Zero FIR
Cue WordsNotes
What is I4C?
  • Indian Cybercrime Coordination Centre (I4C) established in 2018 under MHA to coordinate and address cybercrime-related issues at the national level.
What is the National Cybercrime Reporting Portal?
  • Launched in 2019; officially dedicated to the nation in 2020 under I4C by the MHA.
  • Enables online reporting of cybercrimes.
  • Covers: financial frauds, ransomware, cyberbullying, child pornography, online stalking, social media crimes.
  • Allows evidence upload and anonymous filing for sensitive cases.
  • Users can track complaint status via a reference ID; complaints forwarded to law enforcement.
  • Features cyber safety tips; guidelines on 24 crime types (e.g., phishing, vishing).
  • Secure and anonymous mechanisms; focus on women- and children-related crimes.
  • Aims to strengthen coordination among LEAs, banks, and financial institutions for faster action against cyber fraud.
What rackets does I4C flag?
  • As per I4C: digital arrest, trading scam, investment scam, romance/dating scam.
What is the e-Zero FIR Initiative?
  • I4C launched a system that automatically converts financial cybercrime complaints above ₹10 lakh into FIRs.
  • Launched on a pilot basis in Delhi.
  • Aim: expedite investigations; crack down swiftly on cybercriminals; address difficulties in recovering money lost to financial cybercrime.
  • Integrates: I4C’s National Cybercrime Reporting Portal + Delhi Police’s e-FIR system + NCRB’s CCTNS.
  • MHA stated initiative will be extended nationwide soon.
What is CCTNS (linked to I4C ecosystem)?
  • Initiated in 2009 by MHA as Mission Mode Project under National e-Governance Plan.
  • Connects 17,130+ police stations nationwide — centralized platform for crime investigation, detection, law enforcement.
  • Records crime data, FIRs, investigations, charge-sheets digitally for nationwide tracking.
  • Provides complaint tracking, verification, and police clearance via integrated online portal.
  • Linked with ICJS (Integrated Criminal Justice System) — connecting police, courts, prisons, prosecution, and forensic labs.
Key Cyber Threats, Frauds & Legal Provisions
Cue WordsNotes
What is a DDoS attack?
  • DDoS: attempt to disrupt normal functioning of a targeted server/service/network by overwhelming it with a flood of internet traffic.
  • Unlike a single-source DoS, DDoS leverages multiple compromised systems (a botnet) to generate traffic.
  • Bot detection technologies such as CAPTCHA can identify and block automated tools/bots.
  • Context: FM chaired meeting on cybersecurity preparedness of financial institutions; banks must designate 2 senior officials — 1 for cyber incident reporting, 1 for operational continuity (incl. ATM cash); banks confirmed deployment of anti-DDoS systems.
What laws apply to cyberbullying / online abuse?
  • BNS: Section 74 (outraging modesty), 75 (sexual harassment), 351 (criminal intimidation), 356 (defamation), 196 (promoting enmity).
  • IT Act, 2000: Section 66C (identity theft), 66D (impersonation), 67 (obscene material).
  • These laws do not explicitly criminalise persistent, non-obscene, anonymous online abuse.
  • Section 69A IT Act: government may block content for public order/national security; non-compliant platforms lose safe harbour under Section 79.
  • Doxxing acknowledged by Delhi HC (2023) as serious threat — search for and publish private/identifying info online, typically with malicious intent.
  • DPDPA exempts “publicly available data” but fails to define it — potential for cyber harassment via data aggregation.
  • NCII (Non-Consensual Intimate Image Abuse): algorithms generate deepfake pornographic images without knowledge/control.
What are modern cyber frauds and Section 66D?
  • Modern frauds: phishing (fake emails/SMS); remote access scams via malicious apps; job and loan scams; OTP and UPI frauds; identity theft (Aadhaar, PAN, bank details); digital arrests (criminals impersonate officials).
  • Section 66D IT Act, 2000: cheating by impersonation using a communication device or computer resource — imprisonment up to 3 years + fine up to ₹1 lakh.
  • Cases under 66D include deepfake-related offences and digital impersonation scams.
  • Karnataka accounted for more than one-fourth of all cybercrime cases nationwide in 2023; first State to establish a dedicated city-level cybercrime police station.
  • Cybercrime cases surged by 31.2% in 2023 vs 2022; majority: fraud, extortion, sexual exploitation.
What is a Digital Arrest scam?
  • Fraudsters impersonate law enforcement through video calls and threaten fake arrests to extort money.
  • Often claim victims have sent/are to receive parcels containing illegal goods, drugs, fake passports, or other contraband.
What is 2FA / TOTP?
  • Two-Factor Authentication (2FA): second layer of security; widely implemented via Google Authenticator and TOTP (Time-based One-Time Password).
  • First factor: something you know (password). Second: something you have (authenticator app).
  • OTPs valid only for ~30 seconds.
  • TOTP uses cryptographic function HMAC-SHA-256 to generate short numeric code; both device and server compute same code → match = authenticated.
  • Hash function: one-way, fixed-length output; sensitive to small changes.
  • HMAC: Hash-based Message Authentication Code — secret key + message with hash.
  • Other 2FA: HOTP (counter-based); push-based apps; hardware tokens (e.g., YubiKeys).
What are APK scams, CoinDCX, and SE Asia scam hubs?
  • APK fraud: malicious apps mimic official portals; trick users into granting permissions; can spread malware.
  • CoinDCX breach: FIU-registered crypto exchange (~1.6 crore users); operational hot wallet on partner exchange compromised via server breach; only internal liquidity wallet affected — no customer funds compromised.
  • WazirX hack (2024): N. Korean attackers exploited multi-signature wallet; stole $230M — India’s largest crypto breach.
  • Hot wallet: continuously connected to internet for quick transactions.
  • Multi-signature wallet: requires multiple keys to unlock/approve transactions.
  • ~500 Indians fled KK Park cybercrime hub in Myawaddy, Myanmar (junta-allied BGF-controlled “scam city” on Myanmar–Thailand border) — set for repatriation.
  • Most infamous scam: “pig butchering” — investment + romance fraud using fake crypto platforms.
  • Cambodia major hub: Sihanoukville, Bavet, O’Smach.
What is GPS spoofing?
  • Cyberattack transmitting false GPS signals to mislead navigation systems.
  • GNSS spoofing: counterfeit satellite signals → incorrect aircraft position, higher pilot workload, potential safety risks despite redundancies.
  • Rare over inland metropolitan airspace; more common in border/conflict zones; unusual over Delhi vs India–Pakistan border.
  • Delhi among top 10 global hotspots.
  • Does not hamper aircraft safety: redundancies include Inertial Reference System (safe up to 5 hours if primary fails).
  • Spoofing = counterfeit signals for wrong position; jamming = overpowering satellite signals with strong radio interference.
  • NavIC: independent navigation satellite system by ISRO.
What about VPN regulation and GhostPairing?
  • VPN traffic: encrypted point-to-point tunnel; masks IP; can sidestep website blocks/firewalls.
  • Authorities suspended VPN services in Poonch and Rajouri for two months.
  • CERT-In 2022 directions: VPN providers must maintain logs of Indian users; large paid firms (ExpressVPN, NordVPN) refused and shifted “India” servers to Singapore; bought India-associated IP blocks while serving from Singapore.
  • GhostPairing: hijacks WhatsApp without passwords/SIM swaps; exploits “Linked Devices” — victims authorize attacker’s browser as “ghost” device → full real-time access to chats, media, contacts.
What are mule accounts and MuleHunter.AI?
  • Mule bank accounts: used to launder proceeds from investment scams, gaming apps, QR frauds, digital arrests — layered transactions obscure trails.
  • RBI launched MuleHunter.AI for detection.
What is the UN Convention against Cybercrime?
  • SC underlined importance of international cooperation; asked Centre to take a call on ratifying the UN Convention against Cybercrime.
  • World’s first universal legislative framework; 72 of 193 UN members signed in Hanoi, Vietnam; as of October, India has not signed.
  • Proposes framework for LEA cooperation + technical assistance; covers illegal interception, money laundering, hacking, online CSAM.

B. Money Laundering (PMLA, FATF)

PMLA, 2002 — Definition, Stages, Features & ED
Cue WordsNotes
What is money laundering under PMLA?
  • Defined under Section 3, PMLA as concealing/using proceeds of crime and projecting them as untainted property.
  • Laundromat: term from U.S. crime syndicates; all-purpose financial vehicle — laundering crime proceeds, hiding asset ownership, embezzlement, tax evasion, offshore transfers.
What are the three stages of money laundering?
  • Placement: introducing illicit money.
  • Layering: moving funds via investments/transactions.
  • Integration: reintroducing into the economy.
What are key features of PMLA?
  • Enacted in line with UN 1990 declaration to prevent laundering and confiscate assets.
  • Burden of proof on the accused.
  • ECIR (Enforcement Case Information Report): internal ED document when a PMLA case is opened; similar to FIR; sufficient to initiate proceedings.
  • Scheduled (predicate) offence is essential for prosecution under Sec 3.
  • But property attachment under Section 5 can proceed without a pre-registered case → scope for misuse.
  • ED can provisionally attach property if it has a “reason to believe” it is linked to proceeds of crime, even if the predicate offence is not yet registered.
  • Why in news: since 2015, ED took up 5,892 PMLA cases but only 15 convictions — rising cases vs low conviction rate.
What is the Enforcement Directorate (ED)?
  • Established 1956 as ‘Enforcement Unit’ under DEA, Ministry of Finance, to handle exchange control violations under FERA, 1973.
  • Later renamed ED; transferred to Department of Revenue; entrusted with enforcing financial laws.
  • Enactment of FEMA (1999) and PMLA (early 2000s) increased ED’s powers; aligned functions with international AML standards.
FATF — Structure, Lists, India & Reports
Cue WordsNotes
What is FATF?
  • Founded 1989 by G7 countries.
  • Purpose: combat money laundering and terrorist financing; mandate expanded in 2001 to include terror funding.
  • HQs: Paris, France.
  • Develops and promotes international standards for combating financial crimes; recommends measures to enhance financial systems’ integrity; assesses member compliance with FATF recommendations.
  • Comprises about 39–40 members (countries + regional organizations). India became a member in 2010 (observer in 2006).
  • Plenary = decision-making body; meets three times a year.
  • Pakistan is not a FATF member, but of APG (Asia Pacific Group on Money Laundering) — largest FATF-Style Regional Body. India is member of both APG and FATF.
  • GCC is full FATF member, but five individual GCC states (Bahrain, Kuwait, Oman, Qatar, UAE) are not; Saudi Arabia is FATF member since 2019.
What are Grey List and Black List?
  • Grey List: countries under increased monitoring; encouraged to address AML/CFT deficiencies.
  • Black List: non-cooperative countries in combating ML and TF.
  • Notes state: 21 countries on Grey List; 3 on Black List — Iran, Myanmar, North Korea.
  • Demanding grey-list status for Pakistan requires member-led nomination and Plenary approval.
What FATF cases / reports are in the notes?
  • 2020 Kandla seizure: India seized dual-use autoclaves from Pakistan-bound vessel Da Cui Yun; linked to Pakistan’s NDC (missile development). FATF confirmed mis-declaration and MTCR violation. Autoclaves critical for chemical coating/insulation of missile motors.
  • FATF Report: first time a separate section on state-sponsored terrorism. 2025 Comprehensive Update on Terrorist Financing Risks — terror orgs receive financial/other support from national governments. Project co-led by UNSC CTED and France; India played significant role. India’s 2022 NRA identified Pakistan as state sponsor of terrorism; U.S. 2024 NTFR Assessment noted threats from Pakistan, Afghanistan, East Africa.
What is the FATF Asset Recovery Framework?
  • FATF released “Asset Recovery Guidance and Best Practices” to strengthen asset recovery against financial crimes.
  • Practical measures: identify, trace, freeze, manage, confiscate, and return criminal assets.
  • Includes examples from ED cases as models of effective recovery and inter-agency coordination.
  • First time: mandated non-conviction-based confiscation when prosecution is not feasible.
  • Encourages extended confiscations and unexplained wealth orders (prove lawful origin under reasonable suspicion).
  • Greater emphasis on provisional measures to secure assets early and prevent dissipation.

C. Organised Crime

Organised Crime — NATGRID, MAC & Network Database
Cue WordsNotes
What is NATGRID and how does it link to organised crime?
  • National Intelligence Grid (NATGRID): platform for police and investigating agencies to securely access government and private databases in real time.
  • Single platform instead of seeking data from multiple sources.
  • Conceptualised 2009; became operational later; linked to NPR (family-wise details of 119 crore residents).
  • Datasets include: driving licence, Aadhaar, airline data, bank records, social media accounts sharing posts on particular issues.
  • Access now available to SP-rank officers (earlier only 10 Central agencies).
  • Organised Crime Network Database developed on NATGRID’s IT platform for secure data-sharing between NIA and State ATS.
  • Upgraded tools, especially “Gandiva”, support multi-source data collection/analysis (e.g., facial recognition).
What is the Multi Agency Centre (MAC)?
  • Counter-terrorism grid under IB; conceptualised post-Kargil (2001).
  • MHA inaugurated the revamped MAC.
  • New MAC network connects all police districts securely; built at ₹500 crore.
  • 28 organisations including RAW, armed forces, and State police share real-time intelligence.
  • MHA: new MAC will help combat the terror ecosystem linked with organised crime.
  • Functions 24/7; collates/analyzes inputs under heads: J&K, Northeast, LWE, Rest of India; coordinates via Subsidiary MACs (SMACs) in States/districts.
  • Upgraded 2025 at ₹500 crore — AI/ML, GIS for predictive analytics and hotspots.
  • Connects NATGRID and CCTNS for seamless data fusion and last-mile connectivity.
How does NIA link terrorism to organised crime?
  • NIA now focuses not only on terror acts but on dismantling the broader ecosystem — financial and logistical wings, including organised criminal gangs, narco-terrorism, and terror financing.

D. Terrorism (NIA, UAPA)

NIA — Origin, Mandate & Expansion
Cue WordsNotes
Why and how was the NIA established?
  • Created after the 26/11 Mumbai terror attacks for specialised investigation of complex, inter-state, and trans-national terror plots.
  • NIA Act, 2008 enacted immediately after the attack.
  • Under administrative control of MHA — specialised central agency for transnational/complex terror plots.
What is NIA’s primary function and expanded role?
  • Investigate and prosecute scheduled offences under the NIA Act, 2008 — serious crimes involving national security and those under the UAPA, 1967.
  • Role expanded: dismantling broader terror ecosystem — financial/logistical wings, organised criminal gangs, narco-terrorism, terror financing.
  • NIA (Amendment) Act, 2019 significantly broadened the agency’s powers.
What recent NIA-related policy/events are noted?
  • GoI finalising first anti-terror policy as template for States to combat and respond to terror attacks.
  • 2-day Anti-Terrorism Conference–2025 organised by NIA.
UAPA — Investigation, Bail & Chargesheet
Cue WordsNotes
What are key UAPA investigation / chargesheet rules?
  • Chargesheet must be filed within the statutory period under UAPA, 1967.
  • Section 43D(2)(a): investigation period may be extended only up to 180 days.
  • Section 43D(7): statutory bar on bail for a non-Indian citizen who entered illegally, except in exceptional circumstances.
What is the UAPA bail regime (Section 43D(5))?
  • Why in news: Delhi HC denied bail again to Umar Khalid and others; held 5-year custody not sufficient ground for bail under stringent UAPA provisions.
  • Section 43D(5) bars bail if there are “reasonable grounds” to believe accusations are prima facie true.
  • Law forbids detailed examination of evidence at bail stage — courts forced to accept prosecution narrative; if charge sheet alleges conspiracy with voluminous material, accused remains jailed.
  • 180-day investigation period + prohibition of anticipatory bail → process itself becomes punishment.
  • If delay substitutes for conviction, it undermines Articles 19 and 21.
Terror Cases — Ricin, TATP, Tech Misuse & Forensics
Cue WordsNotes
What is ricin and how does it act?
  • Extremely lethal toxin derived from castor beans; protein extracted from castor bean (grown industrially in India, Brazil, China for castor oil).
  • Seeds: typically 30–60% castor oil; ricin = 1–5% of solid residue weight.
  • Attaches to ribosomes (RNA + protein organelles that read genetic code and synthesise proteins) → stops protein synthesis → multi-organ failure / death depending on cells affected.
  • No antidote; treatment is symptomatic.
  • Context: arrests over chemical weapons plot with global terror network links; accused developing ricin for planned terror strikes.
  • Related: two infiltrators killed in Keran sector, Kupwara (N. Kashmir) under Operation Pimple.
What explosives and forensics tools are noted (Red Fort blast context)?
  • Forensic analysis: mixture of ammonium nitrate + TATP (triacetone triperoxide).
  • TATP (“Mother of Satan”): peroxide-based organic compound; extreme sensitivity / “hair-trigger” volatility; nitrogen-free → can evade nitrogen-detecting scanners; sensitive to friction, shock, heat, static electricity; can detonate without traditional detonator.
  • Detonation described as “entropy burst” (not mainly thermochemical heat): each solid TATP molecule → four gas molecules (1 ozone + 3 acetone) → devastating blast pressure.
  • Can be synthesised from household ingredients: acetone (nail polish remover); hydrogen peroxide (hair bleach/disinfectants); acid catalyst (sulfuric/hydrochloric/citric).
  • Forensics: FTIR / ATR-FTIR (IR interaction); Raman spectroscopy (chemical composition of explosives); SEM (morphology of fragments); EDX (elemental analysis); thermal analysis (chemical activity/stability).
  • PESO: statutory authority ensuring safety from fire/explosion; administers Explosives Act 1884, Petroleum Act 1934, Inflammable Substances Act 1952 + rules; under DPIIT, Ministry of Commerce and Industry.
How was technology misused by terror suspects?
  • Threema (Swiss messaging app): high privacy; no phone/email required — random user ID; end-to-end encryption, no metadata storage, message deletion → hard to reconstruct communication chains.
  • Dead-drop emails: shared email account; messages saved as unsent drafts, accessed by others, then deleted — almost no digital footprint (no in/out email record).

E. Military / Police Operations

UPSC Prelims PYQ — Army Goodwill Operations
Cue WordsNotes
PYQ 2024: Operations for upliftment of local population in remote areas are called?
  • Question: Operations undertaken by the Army towards upliftment of the local population in remote areas to include addressing of their basic needs is called…
  • (a) Operation Sankalp
  • (b) Operation Maitri
  • (c) Operation Sadbhavana
  • (d) Operation Madad
  • Answer: 1(c) — Operation Sadbhavana
Domestic Operations — Op Sarvashakti · Op Sadbhavana · Op Sankalp
Cue WordsNotes
What is Operation Sarvashakti (2024)?
  • Lead Agency: Indian Army
  • Objective: Anti-terror initiative to flush out terrorists from the Pir Panjal range (J&K).
What is Operation Sadbhavana?
  • Lead Agency: Indian Army
  • Objective: Ongoing “Goodwill” mission in J&K and Ladakh focusing on schools (Army Goodwill Schools) and health.
  • Matches the PYQ framing: Army operations for upliftment of local population / basic needs in remote areas.
What is Operation Sankalp?
  • Lead Agency: Indian Navy
  • Objective: Maritime security operations in the Persian Gulf and Gulf of Oman to ensure safety of Indian-flagged vessels.
Other Operations — Op Sindoor · Op Mahadev · Op Thunderbolt · Op Rakshak · Op Black Tornado
Cue WordsNotes
What is Operation Sindoor?
  • Lead Agency: Indian forces
  • Location: Pakistan Border Areas
  • Objective / Context: Recent multi-domain operation responding to the Pahalgam terror incidents.
What is Operation Mahadev?
  • Lead Agency: Army / CRPF
  • Location: Kashmir
  • Objective / Context: Joint counter-terror operation by the Indian Army, CRPF, and Jammu & Kashmir Police, which neutralized three terrorists responsible for the Pahalgam attack.
What is Operation Thunderbolt?
  • Lead Agency: Kerala Police
  • Location: Kerala
  • Objective / Context: Counter-insurgency by “Kerala Thunderbolts” (Special Task Force) to curb Maoist sightings in the Western Ghats.
What is Operation Rakshak?
  • Lead Agency: Indian Army
  • Location: J&K / Punjab
  • Objective / Context: Longest-running counter-insurgency operation (since 1990) to curb cross-border militancy.
What is Operation Black Tornado?
  • Lead Agency: NSG
  • Location: Mumbai
  • Objective / Context: The specific 2008 operation to neutralize terrorists during the 26/11 Mumbai attacks.

Quick Ops Matrix (Zero-loss table form)

OperationLead AgencyLocation / TheatreObjective / Context
Op Sarvashakti (2024)Indian ArmyPir Panjal (J&K)Anti-terror flush-out of terrorists
Op SadbhavanaIndian ArmyJ&K and LadakhOngoing “Goodwill” — Army Goodwill Schools & health
Op SankalpIndian NavyPersian Gulf & Gulf of OmanSafety of Indian-flagged vessels
Op SindoorIndian forcesPakistan Border AreasMulti-domain response to Pahalgam terror incidents
Op MahadevArmy / CRPF (+ J&K Police)KashmirNeutralized 3 terrorists responsible for Pahalgam attack
Op ThunderboltKerala Police (“Kerala Thunderbolts” STF)Kerala / Western GhatsCurb Maoist sightings
Op RakshakIndian ArmyJ&K / PunjabLongest-running CI ops since 1990; curb cross-border militancy
Op Black TornadoNSGMumbaiNeutralize terrorists in 26/11 (2008)