Thugs on the Information Highway: Four Investigators Unmask India’s Cyber Frauds-KBS Sidhu, IAS Retd

In the 1830s, when Captain William Sleeman set about dismantling the thuggee networks of central India, the first thing his officers had to grasp was that the thug never looked like a thug. He fell in with a party of pilgrims or traders on the road, shared their fire and their food for days, sometimes weeks, offered small kindnesses along the way, and only when trust was complete, at a camping ground chosen well in advance, did the yellow rumal come out. The violence was the last five minutes of a long courtship.

Nearly two centuries later the courtship has moved to the phone, and the rumal has become a ringtone. That, stripped to its essentials, is the argument of a 411-page manuscript that reached my inbox on 1 October 2026 with a request from one of its authors, Prof. (Dr.) Sanjeev Chaddha, that I review it. He is at MGSIPA (the Mahatma Gandhi State Institute of Public Administration, Chandigarh), which I headed as Director-General in my final assignment before superannuation. Readers may make whatever allowance they think fit for that connection. I have tried to make none.

Twenty-Seven Chapters, One Modus Operandi
The book is the work of four authors. Three are seasoned career investigators from some of the country’s premier agencies: Rajesh Chandra Khatri, Additional Superintendent of Police with the CBI at Jammu, who conceived the book; K. Pradeep Kumar, Superintendent of Police in the CBI’s economic offences wing at New Delhi, who spent eight years in its Cyber Crime Investigation Division; and Braj Bhushan Pathak, Additional SP with the NIA (National Investigation Agency) at Patna. The fourth, Prof. (Dr.) Sanjeev Chaddha of the Mahatma Gandhi State Institute of Public Administration of the Government of Punjab at Chandigarh, adds a sociological, psychological and human-oriented perspective to their investigative experience.

A personal word of appreciation is in order. I count Prof. Chaddha among the very best of MGSIPA’s permanent faculty, the teachers who carry its work on governance, administration and citizen-centric schemes from one batch of officers to the next. The preface credits him with taking special care in editing every chapter, and it shows in how steadily the book keeps the victim, rather than the technology, at its centre.

After an opening overview, twenty-two chapters take one species of fraud each: lottery and advance-fee scams, YouTube-review and pre-paid task scams, fake share-market portals, digital arrest, customs and “social-media friendship” frauds, betting apps, matrimonial sites, insurance, rentals, online shopping, phishing, crypto, sextortion, card fraud, job offers, SIM swaps, honey traps, skimming, rogue mobile apps, QR codes, deepfakes, and the Aadhaar Enabled Payment System (AEPS). The last four chapters widen the lens: a miscellany of newer threats, the psychology of the crime, its sociology, and a glossary for the lay reader.

Karan Bir Singh Sidhu: The author is a retired IAS officer of the 1984 batch, Punjab cadre, and Founder-Editor of The KBS Chronicle.

Read end to end, the catalogue resolves into a single plot. The fraudster first pays you (fifty rupees for liking a video, a modest “profit” on a dummy trading screen) and only then asks you to pay him, in amounts that rise with your confidence. The preface reaches for an old English idiom, penny wise and pound foolish. Sleeman’s men would have recognised the shared meal.

Arrest Without a Warrant, Custody Without a Cell
The chapter that will be read first, and most anxiously, is the one on digital arrest. It opens with a sentence every Indian household should tape to its refrigerator, stating that the term has no basis in law and that neither Indian criminal procedure nor any agency recognises it. What follows is a clinical anatomy of the con: the courier parcel said to contain drugs or passports, the escalating cast of “police officers”, “public prosecutors” and “notaries”, the forged warrants bearing government seals, the instruction to stay on a continuous video call and tell no one, and finally the “security deposit” to be refunded once innocence is “verified”.

The case studies are sobering. A Gandhinagar doctor parted with ₹19.25 crore over three months in 2025. Closer home, a 78-year-old Ludhiana industrialist was told by a “Delhi Airport official” that a parcel in his name bound for Malaysia held passports and debit cards, and then by a “Delhi Police officer” that he was implicated in a ₹38 crore laundering racket; he paid ₹86 lakh, and then another ₹15 lakh, before he understood. The forgeries the authors describe would not survive a minute’s scrutiny by anyone who has handled genuine court processes. That is precisely why the scheme isolates its victims. The one person who could spot the forgery is never allowed on the call.

The Thumb That Signed Away the Savings
The chapter I found most arresting, for reasons of my own, is the one on AEPS. It begins with Prof. Chaddha’s own account. An e-mail told him that an Aadhaar authentication he had never initiated had succeeded; his account was ₹10,000 lighter; he called 1930, complained to the bank, had the Aadhaar linkage frozen and then removed, and wrote to UIDAI. The authentication logs showed requests routed through eleven banks where he held no account. A second attempt the next day failed, because the door had already been shut. It takes a certain courage for a co-author of a book on fraud to confess that he was defrauded, and the confession teaches more than a chapter of theory.

Another case in that chapter stopped me cold. In Uttar Pradesh, the authors record, criminals lifted thumb impressions and Aadhaar details from property registration records, cloned the prints, and drained some ₹35 lakh through AEPS withdrawals. For a former Financial Commissioner Revenue, that is an uncomfortable sentence. The thumb impression on a registered deed was meant as a safeguard against impersonation; digitised and left open, it becomes the impersonator’s raw material. The authors’ remedy, to lock your Aadhaar biometrics through UIDAI and unlock them only when needed, is sound. Revenue departments, Punjab’s included, would do well to ask what their own digitised deed registers expose.

Why the Clever Fall
The preface makes an observation that will sting some readers of this Chronicle: it is the educated (doctors, engineers, MBAs, police and IAS officers, even judges) who often lose most, and who are least willing to report it, for fear of becoming a laughing stock. The closing chapters take this seriously. The psychology chapter names the levers (authority, urgency, fear, sympathy, greed, the fear of missing out), and the sociology chapter, written by Mr. Pathak, draws on Ulrich Beck’s “risk society” and on Robert Merton, among others, to explain why the technology that brings progress also manufactures new vulnerability. It takes on victim-blaming directly (”Why did you click that link?”), because shame is the fraudster’s best ally, and an unreported fraud is a fraud repeated on the next person. One proverb from that chapter will stay with me — trust arrives on foot and leaves on horseback.

It is rare to find a book on cybercrime by serving investigators that bothers with sociological theory at all. This one does, and it is the better for it.

Errands for the Second Edition
A first edition of 411 pages, written by four busy officers, is bound to leave some errands for the second. In the spirit in which I was asked, I offer five.

First, the apparatus. The contents table still awaits its page numbers, and a book of this size would profit from an index, so that a frightened reader at midnight can find “digital arrest” or “SIM swap” without leafing through three hundred pages. A careful copy-edit of names and technical terms would complete the job.

Second, the sources. The preface candidly says that names, places and dates in some examples may not be real. Readers would be better served if each case carried its newspaper or court source, with composites plainly labelled as such. The cases are the book’s strongest asset, and attribution would make them stronger still.

Third, a single tear-out card for the first hour: call 1930, file on cybercrime.gov.in, alert the bank (since a customer’s liability under the Reserve Bank’s protection rules turns on how quickly the fraud is reported), report the suspicious number through the Chakshu facility on the Department of Telecommunications’ Sanchar Saathi portal, and lock the Aadhaar biometrics. Most of this is already in the book, scattered across chapters.

Fourth, the supply side. Many of these calls are made by Indians trafficked to scam compounds in Southeast Asia and forced to work the phones. A chapter on that grim back office would complete the picture for policy readers.

Fifth, the frontier. The book rightly flags Anthropic’s Claude Mythos as an AI model capable of finding and exploiting software vulnerabilities, and describes it as unreleased. Since June 2026, however, the Mythos-class model has been publicly available as Claude Fable, now in version 5.1, with additional safeguards for cybersecurity among other fields, while the unrestricted Mythos Preview remains confined to a small number of vetted organisations under Anthropic’s Project Glasswing. A paragraph of update will keep the chapter from dating, in a field where six months is an age.

What Sleeman Knew
What broke thuggee was intelligence: approvers who turned and explained the method, meticulous records of who travelled with whom, and a public that slowly learned the stranger at the fire might not be a fellow pilgrim. The authors of this book are approvers in reverse: investigators who have sat across the table from the method and now explain it to the rest of us.

I would like MGSIPA, and every police and administrative training institute in the country, to put this book on its induction syllabus. And I would like you, reader, to do something simpler. The next time a uniformed stranger on a video call tells you not to tell anyone, put the phone down and tell someone at once.

Miscellaneous Top New