Indian authorities blocked nearly 3 lakh fraudulent URLs in five months through the Sahyog portal, targeting investment scams and critical infrastructure threats.

Nearly 3 Lakh Fraudulent Websites Blocked in Five Months as India Scales Up Its Cyber Takedown Machinery

The420 Web Correspondent
5 Min Read

Central and state agencies blocked close to three lakh dangerous URLs between March and July 2026, a sweep officials say primarily targeted websites luring victims into online scams and fraudulent investment schemes. The scale of the operation, and the speed at which it was executed, signals a deliberate shift in India’s cybercrime strategy toward pre-emptive digital disruption rather than reactive investigation alone.

State governments carried the bulk of this effort, with roughly 82 per cent of the blocked URLs, close to 2.44 lakh links, removed based on recommendations submitted by state authorities between March and July. The remainder, more than 51,000 dangerous links, were blocked through direct action by the Indian Cyber Crime Coordination Centre, with a significant share tied specifically to schemes promising unrealistic investment returns, alongside some links flagged for posing risks to critical infrastructure.

Speed Versus a Constantly Regenerating Threat

Cybercrime investigators acknowledge a structural limitation built into this approach. Fraudulent URLs typically have a short operational lifespan by design, since criminal networks can register replacement domains within hours of a takedown and continue operating with minimal disruption to their underlying infrastructure. Blocking a single link, however quickly, therefore addresses a symptom rather than the network generating it.

This has pushed investigators toward examining domain registration patterns, hosting infrastructure, payment channels and the digital identities connected to a fraudulent website, rather than treating each blocked URL as a resolved case. The logic mirrors approaches taken against mule account networks and SIM card fraud rings elsewhere in India’s cybercrime enforcement landscape, where disrupting a single node matters less than mapping and dismantling the broader operation behind it.

The mechanism enabling this rapid blocking is Sahyog, a portal developed by the Ministry of Home Affairs through I4C to streamline takedown notices to intermediaries such as social media platforms and internet service providers under Section 79(3)(b) of the Information Technology Act. Under the system, takedown instructions can only be initiated by officials formally authorised by the central or state governments, with periodic review built in at higher levels.

Sahyog has, however, become the subject of significant legal contestation beyond its use against fraud. Social media platform X has challenged the portal’s constitutional basis before the Karnataka High Court, arguing that Section 79(3)(b) is being used to bypass the more rigorous procedural safeguards required under Section 69A, the IT Act’s dedicated content-blocking provision. The Karnataka High Court upheld Sahyog as a facilitation tool in September 2025, though further petitions challenging specific blockings remain pending before the Delhi High Court, with the Supreme Court having since stayed related proceedings. This broader debate over Sahyog’s legal architecture sits apart from its narrower application against fraud websites, which officials describe as one of its most operationally successful uses to date.

A Volume Problem With No Simple Solution

Underlying the entire enforcement effort is the sheer scale of India’s digital footprint. With around 600 million social media users generating enormous volumes of content daily, identifying fraudulent websites and misleading posts within this ecosystem remains inherently difficult, particularly since cybercriminals can spin up replacement domains and social media accounts almost as quickly as authorities remove the originals.

This dynamic has increased reliance on automated detection systems and cross-agency data sharing to identify suspicious digital infrastructure before it reaches a substantial number of victims, rather than waiting for individual complaints to accumulate. As enforcement agencies refine this approach, the emphasis is expected to shift further toward combining URL blocking with sustained digital forensics and financial-trail analysis, aiming to move beyond simply removing fraudulent links toward dismantling the criminal infrastructure that continues generating them.

Stay Connected