India’s cyber and technology landscape is evolving across financial crime, quantum-resistant payments, government-linked infrastructure security, AI-enabled border defence and emerging risks from frontier AI.

Cyber Alert: Today’s Biggest Cyber Crime Stories Shaking India – 21st September

The420.in Staff
6 Min Read

1. Delhi Police Cuts Cyber-Fraud Restoration Pendency From ~90% to 13.6%

Delhi Police says pendency under I4C’s Money Restoration Module (MRM) has fallen from roughly 90% a month ago to 13.60%, while pendency under the Grievance Redressal Mechanism has fallen to 16.30%.

Police have now forwarded restoration requests covering ₹2.32 crore, up dramatically from ₹3.26 lakh on 2 March.

The MRM is designed to return funds that banks have successfully put on hold after financial cybercrime complaints submitted through NCRP.

Why it matters: Cyber-policing success should increasingly be measured by money saved and restored, not only FIRs and arrests. The operational chain is becoming:

1930/NCRP → Bank Hold → I4C/MRM → Police Verification → Victim Restoration → Investigation

Reducing administrative latency is crucial because rapid freezing has little victim value if legitimately recoverable funds remain stuck for months.

2. Haryana Police Arrests 66 Cybercrime Suspects in One Week; ₹39.73 Lakh Frozen

Haryana Police says Faridabad’s three cyber police stations arrested 66 alleged cyber fraudsters between 12 and 18 September in connection with 12 cases.

Police also disposed of 470 cybercrime complaints, froze ₹39.73 lakh in accounts linked to complaints and recovered ₹4.90 lakh from accused persons.

Why it matters: The numbers illustrate the shift from case-by-case cyber investigation towards high-volume disruption of criminal infrastructure. The next investigative layer should connect suspects across NCRP complaints using bank accounts, mobile numbers, IMEI/IMSI, IPDR, devices and common beneficiaries to identify the controllers rather than stopping at individual mules.

3. India Successfully Tests Indigenous KAL Long-Range One-Way Attack Drone at Pokhran

India’s indigenous KAL long-range one-way attack UAV has successfully completed a flight trial at Pokhran. Developed by Noida-headquartered IG Defence, the vehicle-launched platform is designed for a range of up to 1,000 km, endurance of roughly 7–8 hours, payload capacity of up to 50 kg, and operations up to 5,000 metres above mean sea level.

The trial validated the integrated airframe, propulsion, avionics, navigation and mission architecture. KAL combines multi-band GNSS with inertial navigation and was launched from a mobile vehicle platform.

Why it matters: Recent conflicts have demonstrated the strategic value of relatively inexpensive long-range one-way UAVs for saturation attacks and strikes against radar, air-defence and logistics infrastructure. Indigenous development also reduces foreign supply-chain dependence. The next important technical questions concern navigation in GNSS-denied environments, electronic-warfare resilience, terminal guidance, swarm coordination and counter-UAS survivability.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

4. Cybercrime War Erupts: ShinyHunters Claims Takeover of Rival Cl0p’s Dark-Web Infrastructure

In an unusual global cybercrime development, data-extortion group ShinyHunters says it compromised the dark-web infrastructure of rival ransomware/data-theft gang Cl0p after exploiting a vulnerability in Cl0p’s own software.

Two threat-intelligence specialists told Reuters that the confrontation appeared genuine, although Reuters could not independently verify all of ShinyHunters’ account.

The dispute reportedly centres on an Oracle E-Business Suite zero-day. Cl0p subsequently exploited that vulnerability against more than 100 companies, according to an estimate cited by Reuters. Cl0p had previously exploited MOVEit in 2023, affecting more than 600 organisations.

Why it matters: Ransomware groups are increasingly behaving like competing technology businesses—researching zero-days, running infrastructure and fighting over intellectual property and victims. A compromise of criminal infrastructure can potentially expose operator identities, affiliates, victim lists, cryptocurrency wallets, exploit development, negotiation records and internal communications, creating valuable opportunities for international law enforcement.

5. US Proposes AI “Incident Notification Mechanism” With China for National-Security Events

The United States has proposed a formal AI incident-notification mechanism with China for events capable of affecting national security, US Treasury Secretary Scott Bessent said following discussions with Chinese Vice Premier He Lifeng in New York on 20 September.

The proposal seeks greater transparency between what Bessent described as the world’s two leading AI powers and comes ahead of planned high-level US–China talks. This remains a proposal, not an agreed bilateral mechanism.

Why it matters: This is potentially the beginning of an AI equivalent of cyber or nuclear confidence-building measures. Future reportable incidents could conceivably include uncontrolled agent behaviour, major AI-enabled cyber operations, military-AI accidents or other cross-border events capable of escalation. India should closely study whether similar protocols are eventually needed for military AI, autonomous weapons and AI-enabled cyber operations.

Today’s Strategic Signal : Security is moving from post-event investigation towards real-time intervention.

Delhi is accelerating restoration after fraud, Haryana is disrupting cybercrime networks at scale, India is building long-range autonomous strike capability, criminal groups are attacking each other’s infrastructure, and major powers are beginning to discuss notification mechanisms for dangerous AI incidents.

For policing and national security, the emerging doctrine is increasingly:

Detect Early → Intervene Fast → Preserve Evidence → Attribute the Network → Recover/Neutralise → Learn and Adapt

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected