1. India Plans Tighter Mandatory Reporting for AI Incidents and Autonomous-Agent Failures
India’s IT Ministry is working to strengthen rules governing AI-related incident reporting, including the timeline, information and technical details companies must provide authorities. Officials specifically acknowledged incidents in which autonomous AI agents operate beyond their intended task as falling within the broader cybersecurity-incident framework.
At the same time, the government says it sees no reason to pause Indian AI research, distinguishing India’s application-focused ecosystem from concerns surrounding frontier-model development.
Why it matters: This could become the beginning of an Indian AI Incident Response & Reporting regime analogous to conventional cyber-incident reporting. A mature framework should distinguish events such as model escape, unauthorised agent actions, consequential hallucinations, deepfake misuse, credential exposure and AI-enabled cyber intrusions—and preserve prompts, agent logs, tool calls and system actions as forensic evidence.
2. Bengaluru Cyber Police Uncover 507 Mule Accounts and Automated OTP-Forwarding Infrastructure
A Bengaluru cybercrime investigation that began with a ₹93.6-lakh investment fraud has uncovered 507 suspected mule bank accounts linked to cybercrime complaints across several states. Three people have been arrested and six mobile phones seized.
The more significant discovery is the operating method. Police say current, corporate and trust accounts were procured along with net-banking credentials and SIM cards. Account holders were allegedly placed in hotels where ZNPAY/SMS-forwarding APKs were installed so banking OTPs and SMS messages could be forwarded remotely to fraud operators.
Investigators found 51 additional APKs and have sent details to I4C for technical analysis. Binance wallets, WhatsApp, Telegram and Botim also feature in the investigation, while preliminary IP analysis pointed toward Kolkata, Hong Kong and California. Those overseas indicators still require verification.
Why it matters: This is an important DFIR case study because it exposes a Mule-Account-as-a-Service infrastructure rather than merely individual mules:
Account procurement → SIM → SMS-forwarding APK → Remote OTP → Net banking → Layering → Crypto → Overseas controller
APK reverse engineering, device forensics, IMEI/IMSI correlation, bank telemetry, IPDR and blockchain analysis could expose much more of the network.
3. Indian Army to Deploy Six AASHVAST Labs for Mandatory Drone Firmware Security Screening
The Indian Army is expanding AASHVAST — Assessment and Analysis of Electronic Systems Hardware for Vulnerabilities and Security Threats — to six laboratories nationwide. One facility is already operational in Delhi, while five more are planned. Military drones will undergo security inspection, with CCTV systems expected to follow.
Unlike conventional physical inspection, AASHVAST analyses firmware and embedded systems. It can look for hidden commands, embedded passwords and encryption keys, remote-access mechanisms, location- or time-triggered behaviour and other weaknesses.
The programme also addresses concerns over potentially insecure foreign-origin, particularly Chinese-origin, components in military UAS.
Why it matters: India is effectively institutionalising hardware and firmware DFIR for defence procurement. A drone can appear physically compliant yet contain software capable of geofencing, remote control, data exfiltration or mission disruption. The same security-certification principle is relevant to police drones, body cameras, CCTV, IoT sensors and other law-enforcement equipment.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
4. ED Searches Six Locations in Alleged ₹116.79-Crore Indian Overseas Bank Fraud
The Enforcement Directorate says its Chennai Zonal Office-II searched six premises in Chennai and Tirupur on 18 September as part of a PMLA investigation concerning an alleged ₹116.79-crore fraud involving Indian Overseas Bank and PGC Corporation Ltd. The money-laundering investigation stems from a CBI case.
Authorities seized approximately ₹82 lakh in unexplained cash, two luxury vehicles, laptops, pen drives, mobile phones and property documents. The company’s loan account had reportedly been classified as an NPA in 2013 and declared fraudulent in 2020.
The allegations remain under investigation and have not been judicially established.
Why it matters: Bank-fraud investigations increasingly combine forensic accounting and DFIR. Laptops, phones and removable media can establish communications, beneficial ownership, fabricated documentation and movement of funds that conventional ledger examination alone may miss.
The ideal investigative model is:
Loan → Related Entities → Layering → Beneficial Owner → Digital Evidence → Asset → Attachment
5. New Open-Weight Cybersecurity AI Designed to Keep Sensitive Source Code On-Premises
Belgian cybersecurity company Aikido Security has launched Altar, an open-weight AI model customised for cybersecurity and designed for local deployment. The company says organisations can use the model without sending sensitive source code to an external AI provider.
The model is based on a compressed and customised version of Z.AI’s GLM-5.3 and is expected to be used in deployments including Belgian bank Belfius.
Why it matters: This signals an important direction for government, BFSI, defence and law enforcement: Sovereign/Local AI for Cybersecurity.
Source code, malware samples, investigation data and vulnerability information are often too sensitive for unrestricted cloud-model processing. Locally hosted security models can reduce data-exposure risk while supporting vulnerability analysis and secure-code review—provided the model itself is securely governed.
Today’s Strategic Signal
The common theme is forensics moving deeper into the technology stack. Police are no longer tracing only bank accounts but malicious APKs and remote OTP infrastructure; the Army is moving from physical inspection to firmware analysis; financial investigators are pairing accounting trails with seized digital devices; and AI governance is moving toward preserving machine actions as reportable incidents.
The emerging investigative stack is increasingly:
Money → Identity → Device → Application → Firmware → AI Agent
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics