IIT-Madras Study Explains How Cyber Fraud Victims Are Targeted

The420.in Staff
5 Min Read

Chennai. Falling victim to cyber fraud is not always the result of a lack of digital knowledge or greed.

A study by researchers at IIT-Madras has found that bankers, doctors, IT professionals, experts in management and finance, public-sector officials and even people with cybersecurity qualifications have been victims of financial cybercrime.

The findings challenge the common perception that cyber fraud victims are necessarily careless, digitally inexperienced or driven primarily by the desire to make quick money.

Researchers noted that financial cybercrime data generally records the monetary losses suffered by victims but provides limited insight into the psychological and social impact of fraud. To understand this aspect, the researchers examined the experiences of actual victims. The study was led by P. Kandaswamy and Nandan Sudarsanam, with contributions from Akanksha Jaiswal and Ameeta Fernando.

The study was based on semi-structured interviews with 33 victims from Chennai, Bengaluru, Hyderabad, New Delhi and Mumbai. Twelve senior citizens were also among those interviewed. The research was published in the peer-reviewed journal Humanities and Social Sciences Communications. Researchers examined the experiences of victims from different age groups, professions and levels of digital familiarity to understand the circumstances and vulnerabilities exploited by cybercriminals.

The study identified four prominent vulnerabilities: anticipated financial gain, fear, lack of awareness and threats to self-worth. According to the researchers, cybercriminals exploit these vulnerabilities in different ways. Some victims are promised unusually high returns on investments, while others are threatened with legal action or financial consequences. In certain cases, criminals use a victim’s social reputation, professional identity or sense of self-worth as a means of applying pressure.

These tactics show that cyber fraud is not limited to technical attacks. Criminals frequently rely on conversations, trust, pressure and emotional responses. The objective is often to push victims into a situation where they make payments without adequate verification, share sensitive information or follow instructions given by the fraudsters.

The study examined cases involving investment and stock-trading fraud, task and job scams, digital-payment fraud, malware attacks and digital-arrest scams. Different forms of psychological pressure were used in these frauds. In investment-related cases, the prospect of financial gain can be a major lure, while digital-arrest scams rely more heavily on fear and the threat of official action.

In the Indian context, the researchers also examined tactics involving digital systems such as Aadhaar and UPI. Criminals can exploit public trust in identity and payment systems to influence victims. Even people with considerable technical knowledge may make mistakes when confronted with sudden fear, time pressure or an attractive financial opportunity.

The study also underlines that regular use of digital services or knowledge of cybersecurity does not automatically protect a person from fraud. The presence of victims from banking, medicine, IT and finance shows that cybercriminal strategies are not restricted to exploiting technical weaknesses. Criminals can also manipulate a person’s circumstances and psychological responses to create an opportunity for fraud.

The participation of 12 senior citizens is another significant aspect of the study. By examining victims from different backgrounds, researchers sought to understand how common psychological factors can operate despite differences in age, profession and digital experience. Fear, trust, the expectation of financial gain and concerns about social or professional reputation can all influence a person’s response to pressure from criminals.

According to the researchers, strategies to prevent financial cybercrime should therefore go beyond technical precautions. People also need to understand how cybercriminals use fear, pressure, promises of unusually high returns and official-looking communications to influence their decisions. Viewing fraud only as a consequence of a victim’s carelessness or greed can overlook the wider social and psychological dimensions of such crimes.

The study’s broader finding is that human behaviour needs to receive as much attention in cybersecurity as technical protection. Preventing digital financial fraud requires people to not only identify suspicious links, applications and payment requests, but also recognise situations in which fear, greed or pressure may push them towards making a hurried decision. This understanding could become an important part of protecting people against the evolving methods used in cyber fraud.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected