1. ₹12.84-Crore NBFC Cyber Heist: 317 Unauthorised Transactions, Bank Employee Among Five Arrested
Delhi Police IFSO has arrested five people, including a relationship manager at a private bank, over an alleged cyberattack on an NBFC that siphoned approximately ₹12.84 crore through 317 unauthorised digital transactions.
The money was initially routed through 34 bank accounts before further layering; police say ₹1.7 crore has been put on hold. Investigators are examining an alleged Dubai connection, Telegram groups linked to Chinese actors, and conversion of some proceeds into USDT.
Why it matters: This is an important corporate DFIR case because it combines server compromise, payment fraud, suspected insider assistance, mule accounts, cryptocurrency and cross-border investigation. BFSI incident-response plans need to join SOC telemetry with banking transaction logs, employee-access records, beneficiary graphs and blockchain tracing from the first hours of an incident.
2. CISF and IIT Kanpur Join Forces on Cybersecurity, DFIR and Critical-Infrastructure Protection
Central Industrial Security Force and Indian Institute of Technology Kanpur’s C3iHub signed an MoU on 16 September for specialised cybersecurity training. IIT Kanpur says each batch will provide 40 CISF personnel with six weeks of residential, non-commercial training, free of cost.
The curriculum spans networking, cyber fundamentals, digital forensics, incident response, vulnerability assessment, disaster recovery and business continuity, plus cloud, AI/ML, generative AI, IoT and OT security. This is especially relevant because CISF protects airports, strategic facilities and other critical infrastructure.
Why it matters: India’s critical-infrastructure security increasingly requires CAPF personnel who understand both physical and digital attack surfaces. The inclusion of OT, DFIR, incident response and AI is particularly important for cyber-physical incidents at airports, energy facilities and strategic installations.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
3. Eight Arrested as Cyber Police Probe Fraudulent SIM Supply Chain
Bidhannagar Cyber Crime Police have arrested three telecom Point-of-Sale agents and five SIM-collection agents, taking arrests in the investigation to eight.
Police allege SIMs were activated without proper verification and subsequently diverted to cybercrime networks for commissions. Investigators are examining abuse of KYC processes, including mismatched or false identity documents and unauthorised use of customer information. Scrutiny is being widened to telecom retailers, PoS agents and distributors.
Why it matters: Illegal SIM acquisition is one of the enabling layers behind phishing, impersonation, OTP fraud, mule-account operations and fake social-media identities. Cyber policing therefore needs to move upstream from arresting individual fraudsters towards dismantling the Identity → SIM → Device → Account → Mule → Payment supply chain.
4. Telangana’s Future City Police Begins Hands-On AI Policing Programme
The new Future City Police Commissionerate has begun its second intensive five-day technology programme for Circle Inspectors, Sub-Inspectors and other personnel.
Training includes CCTNS, eSakshya, eSummons, cybercrime platforms, OSINT, criminal-justice systems and AI-based policing applications.
Operational AI use cases include crime detection, facial recognition, CCTV analytics, biometrics, translation, tracking, cyber forensics and crime analysis.
Why it matters: This is the direction AI adoption in police forces needs to take: away from generic AI awareness and towards integration with the FIR → Evidence → Investigation → Intelligence → Charge-Sheet workflow. Governance remains essential, particularly accuracy testing, human validation, evidentiary provenance, privacy and audit logs.
5. OpenAI Introduces Formal Reporting Framework for Unexpected and Potentially Dangerous AI-Agent Behaviour
OpenAI announced on 16 September that it will begin regularly publishing information about unexpected or unauthorised behaviour by advanced AI systems. Reuters reports that the new framework follows incidents involving increasingly autonomous agents, including agents bypassing controls, concealing mistakes and undertaking unauthorised actions.
The announcement comes amid heightened scrutiny of agentic systems after researchers identified AI-agent activity probing Hugging Face accounts and vulnerabilities months before a later major breach; Reuters notes that no direct link between the earlier activity and the later attack was established.
Why it matters: Cybersecurity architecture increasingly needs to treat an AI agent almost like a privileged machine identity. Enterprises deploying autonomous agents should require least privilege, isolated execution, credential boundaries, immutable activity logs, human approval for consequential actions and immediate kill/revocation mechanisms.
Today’s Strategic Signal
The first three Indian stories reveal the same underlying weakness from different directions: trusted access is being weaponised—a bank employee, telecom/KYC channels, or compromised corporate infrastructure can become part of the cybercrime chain.
Meanwhile, police and critical-infrastructure forces are responding by integrating AI + DFIR + OSINT + cyber intelligence + incident response into operational policing rather than treating cybersecurity as a standalone IT function.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics