Skip to content

Terrorism

Threats & Strategic Challenges


Variants & Pak-Sponsored Terrorism

Variants & Pak-Sponsored Terrorism
Cue WordsNotes
What are the primary variants of terrorism active in India?
    Key Terrorism Variants:
  • Cross-Border: State-sponsored infiltration (e.g., in Jammu & Kashmir).
  • State-Specific/Regional: Ethno-nationalist insurgencies in the North-East.
  • Ideological: Left-Wing Extremism (LWE/Maoist) active in the Red Corridor.
  • Social/Communal: Hate-driven violence and social media-driven radicalization.
Identify the major Pak-sponsored terror groups targeting India and their profile.
    Major Terror Groups:
  • Lashkar-e-Taiba (LeT): Founded in 1990 by Hafiz Saeed; engineered the 2008 Mumbai attacks and 2001 Parliament attack. Focuses on anti-India strategic operations.
  • Jaish-e-Mohammad (JeM): Founded in 2000 by Masood Azhar; orchestrated the 2019 Pulwama suicide bombing, 2001 Parliament attack, and 2016 Pathankot airbase attack. Expert in suicide sabotage.
  • Hizbul Mujahideen (HM): Indigenous Kashmiri insurgent group founded in 1989; led by Syed Salahuddin (designated global terrorist).
  • Al-Badr & Harkat-ul-Mujahideen: Pakistan-based groups with strong global terror links (Al-Qaeda/Taliban).
What geographical and structural factors facilitate cross-border incursion from Pakistan?
    Facilitating Factors:
  • Geography: High-altitude mountainous terrain, dense forests, and riverine border sections along the 3,323 km India-Pakistan border.
  • State Support: Active funding, training camps in PoK, and logistical support from Pakistan's ISI.
  • Local Facilitators: Overground Workers (OGWs) providing safe houses and intelligence.
  • Technology: Cryptographic comms, GPS-guided drones for weapon/drug drops, and cross-border tunnels.
Detail India's military, border, and intelligence counter-terrorism responses.
    Counter-Terrorism Response:
  • Military Operations: 2016 Surgical Strikes (post-Uri), 2019 Balakot Air Strike (post-Pulwama), and Operation All Out in J&K.
  • Border Management: BOLD-QIT (electronic border tracking), CIBMS (Comprehensive Integrated Border Management System), smart fencing, and thermal arrays.
  • Intelligence: Nodal coordination via Multi-Agency Centre (MAC) and SMAC (states); technical surveillance by NTRO.
  • Diplomacy: FATF grey-listing advocacy against Pakistan, and UN Security Council 1267 sanctions on terror leaders. FATF's 2025 Comprehensive Update on Terrorist Financing Risks included, for the first time, a dedicated section on state-sponsored terrorism (co-led with UNSC CTED and France).
  • Policy: GoI is finalising India's first anti-terror policy as a template for States, alongside periodic NIA-organised Anti-Terrorism Conferences.
  • Apex Coordination: National Security Council (NSC), chaired by the Prime Minister, is India's apex body for security/strategic policy; the National Security Advisor (NSA) is the PM's primary advisor and heads the NSC Secretariat.

Radicalization & De-radicalization

Radicalization & De-radicalization
Cue WordsNotes
What is the radicalization pathway? Detail the four stages.
  • Radicalization Pathway:
  • The process of adopting extremist ideologies and accepting violence as a legitimate tool, running through four stages:
    1. Pre-radicalization: Individual's baseline state before exposure.
    2. Self-identification: Internalizing grievances, seeking solutions.
    3. Indoctrination: Adoption of extremist views under facilitators/internet.
    4. Jihadization: Active association and execution of terror operations.
Distinguish between push and pull factors of radicalization.
    Radicalization Drivers:
  • Push Factors: Socio-economic marginalization, real/perceived discrimination, identity crisis, and political alienation.
  • Pull Factors: Ideological allure, promise of belonging/purpose, charismatic recruiters, and digital echo chambers.
Why has ISIS recruitment in India remained comparatively low?Moderate Islamic fabric in India: - Strong local democratic channels for grievance redressal. - Diverse Islamic traditions (Sufism, Barelvi) that reject hardline Salafi-Jihadism. - Proactive intelligence counter-action and community leader engagement.
What is the difference between de-radicalization and counter-radicalization? Identify global best practices.
    Intervention Strategies:
  • De-radicalization: Targeted process of disengaging already-radicalized individuals (e.g., counseling, vocational rehab, family reintegration).
  • Counter-Radicalization: Preventive population-wide measures (e.g., counter-narratives, education, community policing).
  • Global Practices: Singapore's Religious Rehabilitation Group (RRG), Saudi's Muhammad bin Nayef Center, and UK's Prevent Strategy.

Legislative Framework & Response


legislative Counter-Measures

Legislative Counter-Measures
Cue WordsNotes
What is the UAPA? Detail the key provisions of its 2019 Amendment.
    UAPA 1967 (Unlawful Activities Prevention Act):
  • Acts as India's primary anti-terror legislation, defining terrorism and providing for banning organizations.
  • 2019 Amendment: Empowered the Central Government to designate individuals as terrorists (previously only organizations could be designated).
  • Investigation & Detention: Grants NIA powers to investigate and search properties, and allows up to 180 days detention without bail during investigation.
Detail the jurisdiction, powers, and establishment of the NIA.NIA Act 2008 (National Investigation Agency): - Established post-2008 Mumbai attacks as India's federal counter-terror investigation agency. - Holds pan-India jurisdiction with suo-motu powers to take over terror-related cases from state police forces. - Operates specialized NIA courts for speedy adjudication.
Explain the role of PMLA and Anti-Hijacking laws in counter-terrorism.
    Financial & Aviation Laws:
  • PMLA 2002 (Money Laundering): Designates terror financing as a predicate offense, allowing ED to freeze and seize properties linked to terror assets.
  • Anti-Hijacking Act 2016: Imposes the death penalty if hijacking results in the death of hostage/crew, and extends jurisdiction to foreign-registered aircraft.
What are the key human rights and procedural concerns regarding anti-terror laws?
    Legislative Issues:
  • Burden of Proof: Reversal of the presumption of innocence in certain provisions.
  • Bail Barriers: Exceptionally strict bail conditions under UAPA Section 43D(5) leading to prolonged pre-trial detention.
  • Misuse: Concerns over arbitrary application to silence political dissent or target activist groups.
  • Historical context: Legacy laws like TADA (1985–95) and POTA (2002–04) were repealed/lapsed due to systematic abuse.

UAPA 1967 — Evolution, Bail Barriers & Individual Designation

UAPA 1967 — Evolution, Bail Barriers & Individual Designation
Cue WordsNotes
Trace UAPA's legislative evolution from 1967 to 2019, and its constitutional basis.
    Evolution & Constitutional Basis:
  • Enacted: 30 December 1967, to give effect to the 16th Constitutional Amendment, permitting reasonable restrictions on Articles 19(1)(a)/(c) in the interest of sovereignty and integrity.
  • 1967 (Original): Anti-secession focus (Naga/Mizo movements); no anti-terrorism provisions.
  • 2004: Post-POTA repeal, anti-terrorism provisions and terror schedules merged into UAPA.
  • 2008: Post-26/11; enhanced detention to 180 days, stricter bail, framework for NIA investigation.
  • 2012: Aligned with FATF standards; expanded "terrorist act" to cover economic security offences (counterfeit currency, funding).
  • 2019: Allowed designation of individuals (not just organizations) as terrorists; enhanced NIA property-seizure powers.
Define 'Unlawful Activity' (Section 2(1)(o)) and 'Terrorist Act' (Section 2(1)(k)), and explain the association-banning process.
    Core Definitions & Banning Process:
  • Unlawful Activity (S.2(1)(o)): Any act (speech/writing/representation) disrupting or intending to disrupt India's sovereignty/territorial integrity, causing disaffection, or supporting secession.
  • Terrorist Act (S.2(1)(k)): Act intended to threaten India's unity, security, or economic security using bombs, hazardous substances, or firearms causing death/injury/property damage/disruption of essential services.
  • Section 3 (Declaration) & Section 4 (Tribunal Review): Centre bans an association by Gazette notification; the ban must be referred to a UAPA Tribunal (a sitting High Court Judge) within 30 days, which confirms or cancels it within 6 months.
What did the 2019 Amendment change regarding individual designation, NIA seizure powers, and investigating-officer rank?
    2019 Amendment — Individual Designation:
  • Individual Designation: Empowers the Centre to designate individuals as terrorists (added to the Fourth Schedule) if they commit, participate in, prepare for, promote, or are "otherwise involved in" terrorism.
  • NIA Seizure Powers: Investigating officer can now seize/attach property with the approval of the Director General of NIA alone, bypassing the state DGP requirement of the original Act.
  • Officer Rank: NIA officers of Inspector and above (previously DSP/ACP and above) empowered to investigate.
  • De-listing: A designated individual can apply to the Centre for de-listing; on rejection, can appeal to a Review Committee chaired by a sitting/retired HC Judge.
  • Fourth Schedule entities: LeT, JeM, Hizbul Mujahideen, Indian Mujahideen, CPI (Maoist).
What is the Section 43D(5) bail test, and how have Watali (2019) and Thwaha Fasal (2021) shaped its interpretation? What are the UAPA penalties?
    Section 43D(5) Bail & Penalties:
  • Bail Test: Accused shall not be released on bail if the court, from the case diary/police report, finds reasonable grounds that the accusation is prima facie true (reverses ordinary presumption of innocence).
  • NIA v. Zahoor Ahmad Shah Watali (2019): SC held courts cannot examine evidence's admissibility/reliability in detail at the bail stage — must accept the prosecution's case at face value.
  • Thwaha Fasal v. NIA (2021): SC clarified mere possession of banned-organization literature without intent to incite violence is insufficient to deny bail.
  • Penalties: Unlawful activities up to 7 years; terrorist acts causing death — death penalty/life imprisonment; conspiracy — 5 years to life; membership of banned org — up to 10 years; funding terrorism — 5 years to life.
  • Conviction gap: 5,000+ arrested annually under UAPA, but final conviction rate is only ~2.8%.

NIA Act 2008 & 2019 Amendment — Federal Investigation Architecture

NIA Act 2008 & 2019 Amendment — Federal Investigation Architecture
Cue WordsNotes
What is the NIA's establishment background, structure, and Special Court framework?
    Establishment & Structure:
  • Enacted: 31 December 2008, post-26/11 Mumbai attacks, under the Ministry of Home Affairs.
  • Leadership: Headed by a Director General (DG) with DGP-equivalent rank; staffed by officers on deputation from state police, IPS, and central agencies.
  • Special Courts (S.11): Centre designates Sessions Courts in each state as Special Courts for scheduled offences, judges appointed on High Court Chief Justice's recommendation.
  • Original Schedule (2008): Atomic Energy Act 1962, UAPA 1967, Anti-Hijacking Act, WMD Act 2005, Explosive Substances Act 1908.
Explain the NIA's suo-motu case-transfer powers under Section 6, and the extraterritorial jurisdiction added in 2019.
    Suo-Motu Powers & Extraterritorial Jurisdiction:
  • Section 6: State police must forward scheduled-offence FIRs to the Centre within 15 days; Centre decides within 15 days if NIA should investigate. Under Section 6(5), the Centre can suo-motu direct NIA to take over any scheduled-offence case without the state government's consent.
  • Extraterritorial Jurisdiction (2019): NIA can investigate scheduled offences committed outside India if they target Indian citizens/interests or breach treaties India is party to; trial held at the Special Court in New Delhi.
  • Federalism concern: "Police" and "Public Order" are State subjects (Entry 1 & 2, List II); Centre justifies NIA's reach via National Defence/Foreign Affairs (Entry 1 & 10, List I).
What offences were added to the NIA Schedule by the 2019 Amendment, and what other changes were made?
    2019 Schedule Expansion:
  • Added: Human trafficking (S.370/370A IPC), counterfeit currency (S.489A–489E IPC), prohibited-arms manufacture/sale (Arms Act 1959), cyber terrorism (S.66F IT Act 2000).
  • Officer rank: Inspector and above empowered to investigate (previously DSP and above) — mirrors the UAPA 2019 change.
  • Performance: NIA maintains an approximate 92% conviction rate across registered trials, with 10+ regional branch offices coordinating with state ATS units.

NSA, PMLA, OSA & NDPS — Allied Statutory Framework

NSA, PMLA, OSA & NDPS — Allied Statutory Framework
Cue WordsNotes
What is preventive detention under the National Security Act, 1980, and what safeguards apply?
    National Security Act, 1980:
  • Objective: Authorizes Central/State Governments to preventively detain individuals to protect national security, public order, and essential supplies, under Article 22(3)–22(7).
  • Detaining Authorities: Centre (defence/foreign relations threats), States (state security/public order), and DMs/Police Commissioners if authorized by the state.
  • Safeguards: Grounds communicated within 5 days (extendable to 10–15); case referred to a 3-member Advisory Board (chaired by a serving/retired HC Judge) within 3 weeks, which must report within 7 weeks; detenu heard in person but with no right to legal counsel.
  • Max detention: 12 months; judicial review limited to Habeas Corpus on grounds of procedural non-compliance, mala fide intent, or vague grounds.
How does PMLA 2002 target terror financing? Explain the Section 5 attachment power and the Section 45 twin bail conditions.
    PMLA 2002 — Terror Financing:
  • Enforcement: Enforcement Directorate (ED) under the Ministry of Finance; treats terror financing as a predicate/scheduled offence.
  • Section 5: ED can provisionally attach proceeds-of-crime property for up to 180 days without prior notice, confirmed by the Adjudicating Authority.
  • Section 50: Statements to ED officers are admissible as evidence (unlike statements to police under CrPC S.161).
  • Section 45 Twin Conditions: Bail requires the Public Prosecutor's hearing plus the court's satisfaction that the accused is "not guilty" and unlikely to reoffend.
  • Vijay Madanlal Choudhary v. UOI (2022): SC upheld the twin conditions, reversed burden of proof, and ED's search/seizure/arrest powers as constitutional.
  • Penalty: 3–7 years rigorous imprisonment (up to 10 years for NDPS-linked offences).
What does the Official Secrets Act, 1923 penalize, and why does it conflict with the RTI Act?
    Official Secrets Act, 1923:
  • Section 3 (Espionage): Penalizes entering prohibited places or communicating secret information to foreign agents for purposes prejudicial to state safety; 3–14 years imprisonment, cognizable and non-bailable.
  • Section 5 (Wrongful Communication): Penalizes unauthorized possession/communication/retention of secret documents (covers journalists and whistleblowers too); up to 3 years.
  • RTI conflict: Section 22 of the RTI Act, 2005 states RTI overrides OSA in case of conflict, but implementation remains disputed; 2nd ARC recommended repealing OSA and adding a public-interest defense.
How does the NDPS Act 1985 combat narco-terrorism financing? Explain quantity-based sentencing and Section 37 bail.
    NDPS Act, 1985 — Narco-Terror Financing:
  • Quantity-graded punishment: Small quantity (rehab option, up to 1 year), intermediate (up to 10 years), commercial quantity (10–20 years rigorous imprisonment); Section 31A allows the death penalty for repeat commercial-quantity convictions.
  • Section 37 Bail: For commercial quantity, bail requires Public Prosecutor's hearing plus the court's satisfaction that the accused is not guilty and unlikely to reoffend — mirrors PMLA/UAPA's reversed-burden structure.
  • Section 42–43: Police/excise/customs/NCB officers can search, seize, and arrest without warrant; up to 180 days detention during investigation.
  • Relevance to CT: Golden Crescent/Golden Triangle drug routes fund terror and insurgent groups (Punjab, J&K, NE); NDPS operates alongside PMLA (predicate offence) and UAPA in choking terror finance.

Emerging Threats & Way Forward


Emerging Terror Challenges

Emerging Terror Challenges
Cue WordsNotes
Define 'Lone Wolf' attacks. Explain why they are difficult to counter.
    Lone Wolf Attacks:
  • Definition: Terrorist acts executed by a single individual acting independently of direct organizational command.
  • Detection: Extremely difficult to detect due to lack of intercepts (no group communication) and use of everyday items (trucks, knives) as weapons.
  • Examples: Nice truck ramming (2016), Orlando nightclub shooting (2016).
What are 'Hybrid Terrorists' and how do they impact urban security operations?
    Hybrid Terrorists (Overground Workers):
  • Profile: Ordinary civilians with regular jobs or students who are not listed on security databases.
  • Role: Act as part-time operatives to execute specific attacks, provide logistics/safe houses, and immediately return to normal life.
  • Challenge: Makes profiling and tracking near-impossible for local police.
How has Cyber Extremism changed terror recruitment and funding?
    Digital Threats:
  • Use of end-to-end encrypted apps (Telegram, Signal) for secure coordination and dark web platforms for weapons procurement.
  • Digital crowdfunding and cryptocurrency (Bitcoin) transactions to bypass standard AML checks.
  • Social media algorithms creating echo chambers for rapid self-radicalization.
  • Drone & Explosives Threat: Drones increasingly used to drop weapons/drugs across the Punjab/J&K border; growing concern over improvised explosives like TATP (triacetone triperoxide, nicknamed "Mother of Satan") due to its ease of manufacture from commercially available precursors — used with ammonium nitrate in the 2025 Delhi Red Fort blast.
  • Encrypted Tradecraft: Delhi Red Fort case accused used the Swiss app Threema (no phone/email needed) and "dead-drop emails" (messages left as unsent drafts) to avoid leaving a digital trail.
Analyze India's preparedness against Bioterrorism and identify existing gaps.
    Bioterrorism & Preparedness:
  • Threat: Release of pathogens (Anthrax, Botulinum, Smallpox) targeting dense populations; 2025 Delhi terror plot involved development of ricin (castor-bean-derived toxin that halts ribosomal protein synthesis; no antidote exists).
  • Preparedness: Signatory to the Biological Weapons Convention (1972) and the Australia Group. NDMA has bio-disaster response protocols. IDSP monitors disease outbreaks.
  • Gaps: Critical shortage of Bio-Safety Level 4 (BSL-4) labs, low stockpile of vaccines/PPE, and poor local hospital triage capabilities.

Institutional Evaluation & Way Forward

Institutional Evaluation & Way Forward
Cue WordsNotes
Identify the strengths and weaknesses of India's counter-terrorism response.
    CT Evaluation:
  • Strengths: Highly capable external/internal intelligence (RAW, IB), strong federal laws (UAPA/NIA), and absolute political will.
  • Weaknesses: Local police modernization remains slow, inter-agency coordination gaps (NATGRID integration delayed), and low final conviction rates.
What were the key Second ARC recommendations regarding counter-terrorism?
  • 2nd ARC Recommendations:
    1. Establish a National Counter-Terrorism Centre (NCTC) to unify intelligence.
    2. Create specialized, dedicated counter-terror forces within state police units.
    3. Implement a comprehensive, nationwide witness protection program.
    4. Modernize local police forces to act as the first line of defense.
Outline the institutional, operational, and preventative measures for India's future CT strategy.
    Way Forward:
  • Institutional: Fully integrate and operationalize NATGRID; modernize state police (SMART policing).
  • Operational: Complete border fencing, expand coastal radar grids (post-26/11 lessons), and secure soft targets.
  • Preventative: Establish a National De-radicalization Policy, involve community/religious leaders, and deploy AI/ML tools for tracking cyber-extremist content.
  • Global: Push for the early adoption of the CCIT (Comprehensive Convention on International Terrorism) at the UN.

Revision Strategy

Master Terror Groups: LeT (Hafiz Saeed), JeM (Masood Azhar), HM (Syed Salahuddin). Major Attacks: 2001 Parliament, 2008 Mumbai (26/11), 2016 Uri, 2019 Pulwama. Anti-Terror Laws: UAPA 1967 (2019 individual designation), NIA Act 2008, PMLA 2002. Key Concepts: Lone Wolf, Hybrid Terrorist, OGW, Radicalization Pathway (Pre-rad -> Self-ID -> Indoctrination -> Jihadization). Agencies: NIA (federal investigation), IB (internal intelligence), RAW (external), MAC (coordination). UN & Global: FATF (Paris, grey/black lists), CCIT (proposed by India at UN).

*Ultra-Fast Revision Series for UPSC CSE.*I'll read the specified section of the notes file and convert every Cyber Security, Money Laundering, Organised Crime, Terrorism, and Military/Police Operations detail into VitePress + Cornell Notes format with zero loss.The military ops are near the end of that range; I'll search the rest of the notes for CERT-In, I4C, PMLA, FATF, NIA, and UAPA.Cyber Security / PMLA / NIA content isn't in that NOTES_FILE range—only the military ops are. I'll locate the full security block in the source materials.Checking for existing Cornell security conversions and reading the I4C/UAPA sections for completeness.Confirming: Cyber Security / PMLA / NIA live in the ECO security source; NOTES_FILE 3401–4224 holds the listed operations. Converting both into zero-loss Cornell notes.# Internal Security — Cyber · Money Laundering · Organised Crime · Terrorism · Military/Police Operations

Source conversion (zero-loss): NOTES_FILE.md lines 4200–4224 (Military/Police Ops) + Security corpus (CERT-In, I4C, PMLA, FATF, NIA, UAPA, Organised Crime) · VitePress + Cornell Notes format


A. Cyber Security (CERT-In, I4C)

CERT-In — Status, Mandate & Key Actions
Cue WordsNotes
What is CERT-In and under which law is it designated?
  • Under Section 70B of the Information Technology (IT) Act, 2000, CERT-In is designated as the national agency for responding to cyber security incidents.
  • It is the central agency for: incident response, vulnerability handling, and security management.
  • It plays a vital role in controlling cybersecurity incidents and coordinating incident response activities.
What are key CERT-In actions / advisories in the notes?
  • Quantum Cyber Readiness: MeitY, CERT-In, and SISA launched whitepaper "Transitioning to Quantum Cyber Readiness" on cybersecurity impact of quantum technologies.
  • Warned quantum computers threaten current encryption (especially RSA); can solve complex problems and do ML/optimization far faster.
  • Highlighted Harvest Now, Decrypt Later (HNDL) attacks — encrypted data stored now, decrypted later.
  • Issued advisory on active threat campaign targeting WhatsApp users using GhostPairing.
  • In 2022, published directions requiring VPN providers to maintain logs of Indian users.
What is Cyber Swachhta Kendra?
  • Initiative focused on detecting and removing malicious botnet programs from computers and devices.
  • Provides free tools for malware analysis and helps improve system security.
I4C — Structure, Portals & e-Zero FIR
Cue WordsNotes
What is I4C?
  • Indian Cybercrime Coordination Centre (I4C) established in 2018 under MHA to coordinate and address cybercrime-related issues at the national level.
What is the National Cybercrime Reporting Portal?
  • Launched in 2019; officially dedicated to the nation in 2020 under I4C by the MHA.
  • Enables online reporting of cybercrimes.
  • Covers: financial frauds, ransomware, cyberbullying, child pornography, online stalking, social media crimes.
  • Allows evidence upload and anonymous filing for sensitive cases.
  • Users can track complaint status via a reference ID; complaints forwarded to law enforcement.
  • Features cyber safety tips; guidelines on 24 crime types (e.g., phishing, vishing).
  • Secure and anonymous mechanisms; focus on women- and children-related crimes.
  • Aims to strengthen coordination among LEAs, banks, and financial institutions for faster action against cyber fraud.
What rackets does I4C flag?
  • As per I4C: digital arrest, trading scam, investment scam, romance/dating scam.
What is the e-Zero FIR Initiative?
  • I4C launched a system that automatically converts financial cybercrime complaints above ₹10 lakh into FIRs.
  • Launched on a pilot basis in Delhi.
  • Aim: expedite investigations; crack down swiftly on cybercriminals; address difficulties in recovering money lost to financial cybercrime.
  • Integrates: I4C’s National Cybercrime Reporting Portal + Delhi Police’s e-FIR system + NCRB’s CCTNS.
  • MHA stated initiative will be extended nationwide soon.
What is CCTNS (linked to I4C ecosystem)?
  • Initiated in 2009 by MHA as Mission Mode Project under National e-Governance Plan.
  • Connects 17,130+ police stations nationwide — centralized platform for crime investigation, detection, law enforcement.
  • Records crime data, FIRs, investigations, charge-sheets digitally for nationwide tracking.
  • Provides complaint tracking, verification, and police clearance via integrated online portal.
  • Linked with ICJS (Integrated Criminal Justice System) — connecting police, courts, prisons, prosecution, and forensic labs.
Key Cyber Threats, Frauds & Legal Provisions
Cue WordsNotes
What is a DDoS attack?
  • DDoS: attempt to disrupt normal functioning of a targeted server/service/network by overwhelming it with a flood of internet traffic.
  • Unlike a single-source DoS, DDoS leverages multiple compromised systems (a botnet) to generate traffic.
  • Bot detection technologies such as CAPTCHA can identify and block automated tools/bots.
  • Context: FM chaired meeting on cybersecurity preparedness of financial institutions; banks must designate 2 senior officials — 1 for cyber incident reporting, 1 for operational continuity (incl. ATM cash); banks confirmed deployment of anti-DDoS systems.
What laws apply to cyberbullying / online abuse?
  • BNS: Section 74 (outraging modesty), 75 (sexual harassment), 351 (criminal intimidation), 356 (defamation), 196 (promoting enmity).
  • IT Act, 2000: Section 66C (identity theft), 66D (impersonation), 67 (obscene material).
  • These laws do not explicitly criminalise persistent, non-obscene, anonymous online abuse.
  • Section 69A IT Act: government may block content for public order/national security; non-compliant platforms lose safe harbour under Section 79.
  • Doxxing acknowledged by Delhi HC (2023) as serious threat — search for and publish private/identifying info online, typically with malicious intent.
  • DPDPA exempts “publicly available data” but fails to define it — potential for cyber harassment via data aggregation.
  • NCII (Non-Consensual Intimate Image Abuse): algorithms generate deepfake pornographic images without knowledge/control.
What are modern cyber frauds and Section 66D?
  • Modern frauds: phishing (fake emails/SMS); remote access scams via malicious apps; job and loan scams; OTP and UPI frauds; identity theft (Aadhaar, PAN, bank details); digital arrests (criminals impersonate officials).
  • Section 66D IT Act, 2000: cheating by impersonation using a communication device or computer resource — imprisonment up to 3 years + fine up to ₹1 lakh.
  • Cases under 66D include deepfake-related offences and digital impersonation scams.
  • Karnataka accounted for more than one-fourth of all cybercrime cases nationwide in 2023; first State to establish a dedicated city-level cybercrime police station.
  • Cybercrime cases surged by 31.2% in 2023 vs 2022; majority: fraud, extortion, sexual exploitation.
What is a Digital Arrest scam?
  • Fraudsters impersonate law enforcement through video calls and threaten fake arrests to extort money.
  • Often claim victims have sent/are to receive parcels containing illegal goods, drugs, fake passports, or other contraband.
What is 2FA / TOTP?
  • Two-Factor Authentication (2FA): second layer of security; widely implemented via Google Authenticator and TOTP (Time-based One-Time Password).
  • First factor: something you know (password). Second: something you have (authenticator app).
  • OTPs valid only for ~30 seconds.
  • TOTP uses cryptographic function HMAC-SHA-256 to generate short numeric code; both device and server compute same code → match = authenticated.
  • Hash function: one-way, fixed-length output; sensitive to small changes.
  • HMAC: Hash-based Message Authentication Code — secret key + message with hash.
  • Other 2FA: HOTP (counter-based); push-based apps; hardware tokens (e.g., YubiKeys).
What are APK scams, CoinDCX, and SE Asia scam hubs?
  • APK fraud: malicious apps mimic official portals; trick users into granting permissions; can spread malware.
  • CoinDCX breach: FIU-registered crypto exchange (~1.6 crore users); operational hot wallet on partner exchange compromised via server breach; only internal liquidity wallet affected — no customer funds compromised.
  • WazirX hack (2024): N. Korean attackers exploited multi-signature wallet; stole $230M — India’s largest crypto breach.
  • Hot wallet: continuously connected to internet for quick transactions.
  • Multi-signature wallet: requires multiple keys to unlock/approve transactions.
  • ~500 Indians fled KK Park cybercrime hub in Myawaddy, Myanmar (junta-allied BGF-controlled “scam city” on Myanmar–Thailand border) — set for repatriation.
  • Most infamous scam: “pig butchering” — investment + romance fraud using fake crypto platforms.
  • Cambodia major hub: Sihanoukville, Bavet, O’Smach.
What is GPS spoofing?
  • Cyberattack transmitting false GPS signals to mislead navigation systems.
  • GNSS spoofing: counterfeit satellite signals → incorrect aircraft position, higher pilot workload, potential safety risks despite redundancies.
  • Rare over inland metropolitan airspace; more common in border/conflict zones; unusual over Delhi vs India–Pakistan border.
  • Delhi among top 10 global hotspots.
  • Does not hamper aircraft safety: redundancies include Inertial Reference System (safe up to 5 hours if primary fails).
  • Spoofing = counterfeit signals for wrong position; jamming = overpowering satellite signals with strong radio interference.
  • NavIC: independent navigation satellite system by ISRO.
What about VPN regulation and GhostPairing?
  • VPN traffic: encrypted point-to-point tunnel; masks IP; can sidestep website blocks/firewalls.
  • Authorities suspended VPN services in Poonch and Rajouri for two months.
  • CERT-In 2022 directions: VPN providers must maintain logs of Indian users; large paid firms (ExpressVPN, NordVPN) refused and shifted “India” servers to Singapore; bought India-associated IP blocks while serving from Singapore.
  • GhostPairing: hijacks WhatsApp without passwords/SIM swaps; exploits “Linked Devices” — victims authorize attacker’s browser as “ghost” device → full real-time access to chats, media, contacts.
What are mule accounts and MuleHunter.AI?
  • Mule bank accounts: used to launder proceeds from investment scams, gaming apps, QR frauds, digital arrests — layered transactions obscure trails.
  • RBI launched MuleHunter.AI for detection.
What is the UN Convention against Cybercrime?
  • SC underlined importance of international cooperation; asked Centre to take a call on ratifying the UN Convention against Cybercrime.
  • World’s first universal legislative framework; 72 of 193 UN members signed in Hanoi, Vietnam; as of October, India has not signed.
  • Proposes framework for LEA cooperation + technical assistance; covers illegal interception, money laundering, hacking, online CSAM.

B. Money Laundering (PMLA, FATF)

PMLA, 2002 — Definition, Stages, Features & ED
Cue WordsNotes
What is money laundering under PMLA?
  • Defined under Section 3, PMLA as concealing/using proceeds of crime and projecting them as untainted property.
  • Laundromat: term from U.S. crime syndicates; all-purpose financial vehicle — laundering crime proceeds, hiding asset ownership, embezzlement, tax evasion, offshore transfers.
What are the three stages of money laundering?
  • Placement: introducing illicit money.
  • Layering: moving funds via investments/transactions.
  • Integration: reintroducing into the economy.
What are key features of PMLA?
  • Enacted in line with UN 1990 declaration to prevent laundering and confiscate assets.
  • Burden of proof on the accused.
  • ECIR (Enforcement Case Information Report): internal ED document when a PMLA case is opened; similar to FIR; sufficient to initiate proceedings.
  • Scheduled (predicate) offence is essential for prosecution under Sec 3.
  • But property attachment under Section 5 can proceed without a pre-registered case → scope for misuse.
  • ED can provisionally attach property if it has a “reason to believe” it is linked to proceeds of crime, even if the predicate offence is not yet registered.
  • Why in news: since 2015, ED took up 5,892 PMLA cases but only 15 convictions — rising cases vs low conviction rate.
What is the Enforcement Directorate (ED)?
  • Established 1956 as ‘Enforcement Unit’ under DEA, Ministry of Finance, to handle exchange control violations under FERA, 1973.
  • Later renamed ED; transferred to Department of Revenue; entrusted with enforcing financial laws.
  • Enactment of FEMA (1999) and PMLA (early 2000s) increased ED’s powers; aligned functions with international AML standards.
FATF — Structure, Lists, India & Reports
Cue WordsNotes
What is FATF?
  • Founded 1989 by G7 countries.
  • Purpose: combat money laundering and terrorist financing; mandate expanded in 2001 to include terror funding.
  • HQs: Paris, France.
  • Develops and promotes international standards for combating financial crimes; recommends measures to enhance financial systems’ integrity; assesses member compliance with FATF recommendations.
  • Comprises about 39–40 members (countries + regional organizations). India became a member in 2010 (observer in 2006).
  • Plenary = decision-making body; meets three times a year.
  • Pakistan is not a FATF member, but of APG (Asia Pacific Group on Money Laundering) — largest FATF-Style Regional Body. India is member of both APG and FATF.
  • GCC is full FATF member, but five individual GCC states (Bahrain, Kuwait, Oman, Qatar, UAE) are not; Saudi Arabia is FATF member since 2019.
What are Grey List and Black List?
  • Grey List: countries under increased monitoring; encouraged to address AML/CFT deficiencies.
  • Black List: non-cooperative countries in combating ML and TF.
  • Notes state: 21 countries on Grey List; 3 on Black List — Iran, Myanmar, North Korea.
  • Demanding grey-list status for Pakistan requires member-led nomination and Plenary approval.
What FATF cases / reports are in the notes?
  • 2020 Kandla seizure: India seized dual-use autoclaves from Pakistan-bound vessel Da Cui Yun; linked to Pakistan’s NDC (missile development). FATF confirmed mis-declaration and MTCR violation. Autoclaves critical for chemical coating/insulation of missile motors.
  • FATF Report: first time a separate section on state-sponsored terrorism. 2025 Comprehensive Update on Terrorist Financing Risks — terror orgs receive financial/other support from national governments. Project co-led by UNSC CTED and France; India played significant role. India’s 2022 NRA identified Pakistan as state sponsor of terrorism; U.S. 2024 NTFR Assessment noted threats from Pakistan, Afghanistan, East Africa.
What is the FATF Asset Recovery Framework?
  • FATF released “Asset Recovery Guidance and Best Practices” to strengthen asset recovery against financial crimes.
  • Practical measures: identify, trace, freeze, manage, confiscate, and return criminal assets.
  • Includes examples from ED cases as models of effective recovery and inter-agency coordination.
  • First time: mandated non-conviction-based confiscation when prosecution is not feasible.
  • Encourages extended confiscations and unexplained wealth orders (prove lawful origin under reasonable suspicion).
  • Greater emphasis on provisional measures to secure assets early and prevent dissipation.

C. Organised Crime

Organised Crime — NATGRID, MAC & Network Database
Cue WordsNotes
What is NATGRID and how does it link to organised crime?
  • National Intelligence Grid (NATGRID): platform for police and investigating agencies to securely access government and private databases in real time.
  • Single platform instead of seeking data from multiple sources.
  • Conceptualised 2009; became operational later; linked to NPR (family-wise details of 119 crore residents).
  • Datasets include: driving licence, Aadhaar, airline data, bank records, social media accounts sharing posts on particular issues.
  • Access now available to SP-rank officers (earlier only 10 Central agencies).
  • Organised Crime Network Database developed on NATGRID’s IT platform for secure data-sharing between NIA and State ATS.
  • Upgraded tools, especially “Gandiva”, support multi-source data collection/analysis (e.g., facial recognition).
What is the Multi Agency Centre (MAC)?
  • Counter-terrorism grid under IB; conceptualised post-Kargil (2001).
  • MHA inaugurated the revamped MAC.
  • New MAC network connects all police districts securely; built at ₹500 crore.
  • 28 organisations including RAW, armed forces, and State police share real-time intelligence.
  • MHA: new MAC will help combat the terror ecosystem linked with organised crime.
  • Functions 24/7; collates/analyzes inputs under heads: J&K, Northeast, LWE, Rest of India; coordinates via Subsidiary MACs (SMACs) in States/districts.
  • Upgraded 2025 at ₹500 crore — AI/ML, GIS for predictive analytics and hotspots.
  • Connects NATGRID and CCTNS for seamless data fusion and last-mile connectivity.
How does NIA link terrorism to organised crime?
  • NIA now focuses not only on terror acts but on dismantling the broader ecosystem — financial and logistical wings, including organised criminal gangs, narco-terrorism, and terror financing.

D. Terrorism (NIA, UAPA)

NIA — Origin, Mandate & Expansion
Cue WordsNotes
Why and how was the NIA established?
  • Created after the 26/11 Mumbai terror attacks for specialised investigation of complex, inter-state, and trans-national terror plots.
  • NIA Act, 2008 enacted immediately after the attack.
  • Under administrative control of MHA — specialised central agency for transnational/complex terror plots.
What is NIA’s primary function and expanded role?
  • Investigate and prosecute scheduled offences under the NIA Act, 2008 — serious crimes involving national security and those under the UAPA, 1967.
  • Role expanded: dismantling broader terror ecosystem — financial/logistical wings, organised criminal gangs, narco-terrorism, terror financing.
  • NIA (Amendment) Act, 2019 significantly broadened the agency’s powers.
What recent NIA-related policy/events are noted?
  • GoI finalising first anti-terror policy as template for States to combat and respond to terror attacks.
  • 2-day Anti-Terrorism Conference–2025 organised by NIA.
UAPA — Investigation, Bail & Chargesheet
Cue WordsNotes
What are key UAPA investigation / chargesheet rules?
  • Chargesheet must be filed within the statutory period under UAPA, 1967.
  • Section 43D(2)(a): investigation period may be extended only up to 180 days.
  • Section 43D(7): statutory bar on bail for a non-Indian citizen who entered illegally, except in exceptional circumstances.
What is the UAPA bail regime (Section 43D(5))?
  • Why in news: Delhi HC denied bail again to Umar Khalid and others; held 5-year custody not sufficient ground for bail under stringent UAPA provisions.
  • Section 43D(5) bars bail if there are “reasonable grounds” to believe accusations are prima facie true.
  • Law forbids detailed examination of evidence at bail stage — courts forced to accept prosecution narrative; if charge sheet alleges conspiracy with voluminous material, accused remains jailed.
  • 180-day investigation period + prohibition of anticipatory bail → process itself becomes punishment.
  • If delay substitutes for conviction, it undermines Articles 19 and 21.
Terror Cases — Ricin, TATP, Tech Misuse & Forensics
Cue WordsNotes
What is ricin and how does it act?
  • Extremely lethal toxin derived from castor beans; protein extracted from castor bean (grown industrially in India, Brazil, China for castor oil).
  • Seeds: typically 30–60% castor oil; ricin = 1–5% of solid residue weight.
  • Attaches to ribosomes (RNA + protein organelles that read genetic code and synthesise proteins) → stops protein synthesis → multi-organ failure / death depending on cells affected.
  • No antidote; treatment is symptomatic.
  • Context: arrests over chemical weapons plot with global terror network links; accused developing ricin for planned terror strikes.
  • Related: two infiltrators killed in Keran sector, Kupwara (N. Kashmir) under Operation Pimple.
What explosives and forensics tools are noted (Red Fort blast context)?
  • Forensic analysis: mixture of ammonium nitrate + TATP (triacetone triperoxide).
  • TATP (“Mother of Satan”): peroxide-based organic compound; extreme sensitivity / “hair-trigger” volatility; nitrogen-free → can evade nitrogen-detecting scanners; sensitive to friction, shock, heat, static electricity; can detonate without traditional detonator.
  • Detonation described as “entropy burst” (not mainly thermochemical heat): each solid TATP molecule → four gas molecules (1 ozone + 3 acetone) → devastating blast pressure.
  • Can be synthesised from household ingredients: acetone (nail polish remover); hydrogen peroxide (hair bleach/disinfectants); acid catalyst (sulfuric/hydrochloric/citric).
  • Forensics: FTIR / ATR-FTIR (IR interaction); Raman spectroscopy (chemical composition of explosives); SEM (morphology of fragments); EDX (elemental analysis); thermal analysis (chemical activity/stability).
  • PESO: statutory authority ensuring safety from fire/explosion; administers Explosives Act 1884, Petroleum Act 1934, Inflammable Substances Act 1952 + rules; under DPIIT, Ministry of Commerce and Industry.
How was technology misused by terror suspects?
  • Threema (Swiss messaging app): high privacy; no phone/email required — random user ID; end-to-end encryption, no metadata storage, message deletion → hard to reconstruct communication chains.
  • Dead-drop emails: shared email account; messages saved as unsent drafts, accessed by others, then deleted — almost no digital footprint (no in/out email record).

E. Military / Police Operations

UPSC Prelims PYQ — Army Goodwill Operations
Cue WordsNotes
PYQ 2024: Operations for upliftment of local population in remote areas are called?
  • Question: Operations undertaken by the Army towards upliftment of the local population in remote areas to include addressing of their basic needs is called…
  • (a) Operation Sankalp
  • (b) Operation Maitri
  • (c) Operation Sadbhavana
  • (d) Operation Madad
  • Answer: 1(c) — Operation Sadbhavana
Domestic Operations — Op Sarvashakti · Op Sadbhavana · Op Sankalp
Cue WordsNotes
What is Operation Sarvashakti (2024)?
  • Lead Agency: Indian Army
  • Objective: Anti-terror initiative to flush out terrorists from the Pir Panjal range (J&K).
What is Operation Sadbhavana?
  • Lead Agency: Indian Army
  • Objective: Ongoing “Goodwill” mission in J&K and Ladakh focusing on schools (Army Goodwill Schools) and health.
  • Matches the PYQ framing: Army operations for upliftment of local population / basic needs in remote areas.
What is Operation Sankalp?
  • Lead Agency: Indian Navy
  • Objective: Maritime security operations in the Persian Gulf and Gulf of Oman to ensure safety of Indian-flagged vessels.
Other Operations — Op Sindoor · Op Mahadev · Op Thunderbolt · Op Rakshak · Op Black Tornado
Cue WordsNotes
What is Operation Sindoor?
  • Lead Agency: Indian forces
  • Location: Pakistan Border Areas
  • Objective / Context: Recent multi-domain operation responding to the Pahalgam terror incidents.
What is Operation Mahadev?
  • Lead Agency: Army / CRPF
  • Location: Kashmir
  • Objective / Context: Joint counter-terror operation by the Indian Army, CRPF, and Jammu & Kashmir Police, which neutralized three terrorists responsible for the Pahalgam attack.
What is Operation Thunderbolt?
  • Lead Agency: Kerala Police
  • Location: Kerala
  • Objective / Context: Counter-insurgency by “Kerala Thunderbolts” (Special Task Force) to curb Maoist sightings in the Western Ghats.
What is Operation Rakshak?
  • Lead Agency: Indian Army
  • Location: J&K / Punjab
  • Objective / Context: Longest-running counter-insurgency operation (since 1990) to curb cross-border militancy.
What is Operation Black Tornado?
  • Lead Agency: NSG
  • Location: Mumbai
  • Objective / Context: The specific 2008 operation to neutralize terrorists during the 26/11 Mumbai attacks.

Quick Ops Matrix (Zero-loss table form)

OperationLead AgencyLocation / TheatreObjective / Context
Op Sarvashakti (2024)Indian ArmyPir Panjal (J&K)Anti-terror flush-out of terrorists
Op SadbhavanaIndian ArmyJ&K and LadakhOngoing “Goodwill” — Army Goodwill Schools & health
Op SankalpIndian NavyPersian Gulf & Gulf of OmanSafety of Indian-flagged vessels
Op SindoorIndian forcesPakistan Border AreasMulti-domain response to Pahalgam terror incidents
Op MahadevArmy / CRPF (+ J&K Police)KashmirNeutralized 3 terrorists responsible for Pahalgam attack
Op ThunderboltKerala Police (“Kerala Thunderbolts” STF)Kerala / Western GhatsCurb Maoist sightings
Op RakshakIndian ArmyJ&K / PunjabLongest-running CI ops since 1990; curb cross-border militancy
Op Black TornadoNSGMumbaiNeutralize terrorists in 26/11 (2008)