Digital Arrest Scams: The Hard Questions Behind The Supreme Court’s New Directions
The Supreme Court’s directions seek faster coordination among banks, police and cybercrime agencies, while experts examine bank responsibility, victim compensation and cross-border recovery.
Experts say India has laws, but coordination remains key to stopping digital arrest scams.
The Supreme Court's latest directions on digital-arrest scams seek to make India's response to cyber fraud faster and more coordinated. In its August 4 order, the Court directed the Reserve Bank of India to finalise and circulate a standard operating procedure (SOP) for banks to place temporary debit holds on accounts linked to mule activity and cyber-enabled fraud.
But what do these directions change for a person who has already been defrauded? Was the problem a gap in the law or a failure to coordinate existing institutions? If the victim himself enters the OTP or UPI PIN and transfers the money, can the bank still bear some responsibility? What happens when suspicious funds move through several mule accounts, or leave India altogether?
The experts consulted by LawBeat examine these questions, and their answers point less to a lack of laws than to a system struggling with speed, coordination and the difficult question of who should ultimately bear the loss.
Was the problem a gap in the law or in coordination?
The experts largely agree that India does not lack laws to prosecute digital-arrest scams. The bigger difficulty is making the existing system work quickly and together.
Jitendra Soni, Partner, Argus Partners, said offences such as cheating, impersonation and extortion are already sufficient to prosecute the perpetrators. The difficulty, he said, arises because a single digital-arrest scam can involve a phone call, messaging platform, bank accounts and payment intermediaries, with each institution seeing only part of the transaction trail.
“The larger problem is one of coordination,” Soni said. By the time information from different sources is brought together, the money may already have moved through several accounts.
Anurag Kalavatiya, Founder and Managing Partner at Amicus Legal, similarly said the problem was one of coordination and execution rather than the absence of legislation. The response may require the police, cybercrime units, banks, payment intermediaries, telecom operators and online platforms to act almost simultaneously.
He pointed to mechanisms already put in place, including the Indian Cyber Crime Coordination Centre (I4C), the Cyber Fraud Mitigation Centre, the National Cybercrime Reporting Portal, The Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), the Suspect Registry, Samanvaya and e-Zero FIR. The challenge, he said, is their “uniform and timely implementation across States”.
Rajas Pingle, Managing Partner, Netlawgic Legal, also identified speed and coordination as the central problem. Cybercriminals can move money through several mule accounts within minutes, while coordination between police, banks and intermediaries can take much longer.
Abhishek Kumar Singh, Partner, Luthra and Luthra, pointed to the fact that CFCFRMS has existed since 2021. In his view, the need for judicial intervention despite the existing architecture shows that the issue is not simply the absence of mechanisms, but whether they are being used effectively.
The common thread in these views is that India has already built several systems to report, trace and block cyber fraud. The harder task is making them work at the speed at which the money moves.
What if the victim himself authorised the payment?
This creates a more difficult question for the banking system. In a conventional unauthorised transaction, the customer can say that he did not make the payment. In a digital-arrest scam, the victim may himself enter the OTP, UPI PIN or other authentication details and transfer the money, but only because he has been deceived, threatened, or coerced.
Kalavatiya said the RBI's customer-protection framework was principally designed around unauthorised electronic transactions. Digital-arrest scams present a different situation because the transaction may be technically authorised even though the victim was induced to make it through deception, coercion or impersonation.
Soni similarly said the idea of an “authorised transaction” becomes less straightforward when a person transfers money after being threatened with arrest by someone posing as a police officer. He pointed to the RBI's June 2026 amendments recognising transactions approved by customers under coercion or duress as fraudulent electronic banking transactions.
But treating the transaction as fraudulent does not by itself answer the question of who should bear the loss, Soni said.
The fact that the customer pressed “send”, he said, cannot be irrelevant. At the same time, that should not necessarily end the inquiry if the transaction or recipient account showed warning signs of fraud that the banking system could reasonably have detected.
Pingle made a similar point. The question should not stop at whether the customer authorised the payment. Banks should also consider whether there were red flags that their fraud-monitoring systems could reasonably have detected.
That distinction matters because preventing fraud and compensating its victim are separate questions.
A bank may have been expected to identify suspicious activity, but that does not automatically mean it must reimburse every loss. Conversely, the fact that a victim technically authorised a payment does not necessarily mean the banking system had no responsibility at all.
Singh pointed to the separate issue of restitution. He said the existing framework does not ensure complete recovery in every case, particularly because the compensation mechanisms available to victims operate subject to their own conditions and limitations.
Will the proposed mule-account SOP make banks more responsible?
The experts largely view the proposed SOP as a way of making existing banking responsibilities clearer and more operational, rather than as an automatic new rule requiring banks to compensate victims.
Pingle said banks already have KYC, anti-money laundering and transaction-monitoring obligations. A clearer SOP, however, could establish a more definite standard for identifying and dealing with mule accounts.
If clear warning signs are ignored despite such a framework, he said, the question of bank responsibility would naturally arise.
Kalavatiya similarly described the proposed SOP as an operational strengthening of existing KYC, AML and fraud-risk management duties. Its significance, he said, would be in creating a more uniform and real-time response to suspicious accounts.
Soni drew an important distinction between preventing losses and compensating victims. Banks already have obligations to identify and monitor mule accounts, he said. The SOP could make the response more precise by answering practical questions: when should a temporary debit hold be imposed? How quickly should information be shared with another bank? And how should banks and law-enforcement agencies coordinate once an account is suspected of being linked to fraud?
But better mule-account controls, Soni said, should not automatically be equated with an obligation on banks to compensate every victim.
Singh also cautioned against reading the proposed SOP as a declaration that banks must reimburse every loss arising from a digital-arrest scam.
The Supreme Court's separate direction to examine a shared-liability and victim-compensation framework is significant for precisely this reason. Court has recognised that recovery, bank responsibility and ultimate allocation of the loss are connected questions, but they are not necessarily the same question.
What happens when the money leaves India?
The problem becomes substantially harder when the people running the scam, the accounts receiving the money and the eventual destination of the proceeds are spread across different jurisdictions.
Soni said India has legal mechanisms to pursue conduct and evidence outside the country, but Indian investigators cannot compel a foreign bank or platform to provide records or freeze assets as easily as they can an Indian institution.
The difficulty, he said, is time. Obtaining records, preserving evidence or freezing assets abroad can require assistance from several foreign authorities, while the money may move across jurisdictions almost instantly.
Pingle similarly said traditional international cooperation mechanisms, including mutual legal assistance treaties, often do not operate at the speed required for cyber fraud.
Cryptocurrency can add another layer of difficulty. "We need much faster mechanisms for preservation of digital evidence, freezing of proceeds and cooperation with foreign law-enforcement agencies, banks and technology platforms. The investigation cannot take months to cross borders when the proceeds of crime can cross them in seconds," he said.
Kalavatiya said India has mechanisms including INTERPOL channels and mutual legal assistance to pursue cross-border investigations. But securing foreign records, preserving evidence and freezing assets quickly enough remains a practical challenge. He too points to another layer of complexity added by the increasing use of cryptocurrency.
Singh also stressed that once the proceeds leave India, domestic regulations have limited practical reach. Faster information-sharing, cross-border tracing and freezing of assets, and greater cooperation with foreign law-enforcement agencies and financial institutions would therefore be required.
For the experts, then, the cross-border problem is not simply that India has no legal route to pursue money abroad. It is that the legal route can move much more slowly than the money and digital evidence it is trying to trace.
The Supreme Court's directions seek to tighten the chain within India — from reporting a fraud and identifying suspicious accounts to freezing funds, pursuing recovery and considering compensation.
But digital-arrest scams expose a larger problem. The money can move in minutes, while the institutions responsible for stopping it often have to work through multiple systems, agencies and jurisdictions. The real test of the new framework will be whether that institutional response can become fast enough to match the fraud.