Cybercrime has become so woven into everyday life that most of us have stopped thinking of it as something that only happens to ‘careless’ people. Barely a day goes by without another story doing the rounds — someone losing money over a call about a stuck parcel, a message from a ‘bank official’, an investment opportunity that sounds a little too good, or simply being taken in by a familiar-looking profile on social media.
 
The latest ‘Status of Policing in India Report (SPIR) 2026: Cybercrime — Victim Perspectives and Systemic Responses’, jointly put together by Common Cause and Lokniti-CSDS, puts some real numbers behind that reality. The study covered more than 8,300 respondents across 16 states, and its qualitative side went further still, with detailed interviews involving cybercrime victims, experts, people who had helped victims and even relatives of those accused of cybercrime.
 
 
What sets this report apart is that it doesn't stop at the money loss. It looks at how people are targeted in the first place, why so many crimes never get reported, and what victims actually encounter once they turn to the police and their banks for help.
 
And the picture that emerges is not a comfortable one. If anything, it makes you wonder what we have been missing all these years in how crime gets reported and detected — and it forces a harder question: how do we actually protect ordinary people from becoming victims in the first place?
 
Anyone Can Be a Target
 
According to the report, cybercriminals rely heavily on social engineering — manipulating people — rather than breaking through a firewall or defeating a clever piece of security technology. Deception, threats (fear factor), coercion (greed!), psychological pressure: these are the real tools of the trade. Behind the scenes, organised networks have built an entire ecosystem to support this by obtaining leaked personal data, mule bank accounts for money transfers and SIM cards obtained on fake documents.
 
This distinction matters more than it might seem. In most cases, the cybercriminal doesn't need to outsmart sophisticated security systems at all. Their real target is the person sitting in front of the screen — often the weakest link in the whole chain.
 
The Common Cause and Lokniti-CSDS survey found that around a third of respondents frequently received fake delivery calls or pitches for high-return investment scams. Close to a quarter said they regularly got bank-impersonation calls, calls tied to illegal activity, or calls from unknown numbers pretending to be a friend. The report also found a link between how often someone uses online payments and how often they are targeted by fraudulent calls — the more digitally active you are, the more of a target you become.
 
About 13% of respondents said they had personally become a victim of cybercrime in the previous two to three years. More than half of the cases reported involved digital financial fraud, though personal data theft, cyberbullying and online sexual abuse also featured.
 
So, the first lesson here is a simple one: don't assume that being careful makes you immune. It doesn't.
 
The Fraud May Last Minutes. The Aftermath Can Drag on for Months
 
For anyone who has just lost money to an online scam, there is really only one question that matters: Can I get it back?
 
The report's findings suggest the honest answer is complicated.
 
Among victims of digital financial fraud, 52% reported the fraud to their bank separately, and 63% did so within 24 hours. And yet, roughly three out of four victims were unable to recover a single rupee of what they lost.
 
Which is exactly why those first few minutes and hours matter so much.
 
If you realise money has gone to a fraudster, don't waste precious time arguing with them, trying to negotiate a refund, or scrolling social media in search of someone who claims they can get it back. Report the transaction through your bank's official channel and the appropriate cybercrime mechanism — call 1930 or file a complaint on the national cybercrime reporting portal (NCRP) (http://cybercrime.gov.in) — as fast as you possibly can.
 
And preserve a record of everything: the transaction reference, screenshots, phone numbers, messages, email IDs, website addresses, UPI IDs, whatever evidence exists. Don't delete the conversation with the fraudster just because it is embarrassing or upsetting to look at. That trail can be exactly what helps investigators piece together what happened and trace the fraudster.
 
Victims Also Face an Institutional Maze
 
The report's findings on police complaints are just as revealing. Only around half of the cybercrime victims surveyed said they had actually complained to the police. Another 11% started the process but gave up along the way. Among those who did complain, nearly a quarter had visited a police station five times or more. And 42% overall said the complaint-registration process was difficult.
 
The qualitative research paints an even starker picture: among 15 victims who approached the police, either online or in person, a first information report (FIR) was registered in just six cases.
 
For victims, this can turn an already painful experience into a second ordeal entirely. And in cases where the loss is just a few hundred rupees, the victim simply decides to forget it. “Another victim lost a little over ₹14 lakh, and his bank refused to register a complaint until an FIR was filed. Once the FIR was filed, the banks shifted the onus of the fraud onto the victim and tried to absolve themselves of any responsibility to act. Thirty days passed without any action from the bank, which prompted the victim to approach the Reserve Bank of India (RBI) ombudsman. Recovery only began after a magistrate’s order compelled it, and a consumer court claim for the remaining ₹4.9 lakh is still pending at the time of the interview,” the report said.
 
It clearly shows that the damage in the aftermath of cybercrime is not only financial. The report's interviews point to real emotional fallout — stress, trauma, depression. For some victims, the aftermath disrupted their lives well beyond the money itself.
 
Which is why cyber fraud should not be brushed off as simply a financial transaction that went wrong. There is a person behind every complaint — someone dealing with fear, embarrassment, confusion, and sometimes the devastating loss of a lifetime's savings.
 
Don't Let Embarrassment Stop You from Reporting
 
One of the biggest advantages cybercriminals have is silence — the silence of the people they have already scammed. A few months ago, while conducting a cybersecurity workshop for senior citizens, the organisers told me about two victims of cyber fraud in their group. One woman stood up and openly shared her experience with the audience so everyone else would know what to watch for. The other, a high-ranking retired government official, would not even speak to me about what had happened to him. As I later learned, the most likely reason was simple embarrassment — mostly the sense that someone in his rank and position should have known better.
 
The report echoes exactly this. It finds cybercrime is significantly underreported, driven by stigma, distrust of authorities and a belief that complaints won't be taken seriously anyway. Underreporting is particularly severe, it notes, when it comes to online gender-based violence and non-consensual image abuse.
 
Unfortunately, this creates a dangerous cycle. A victim thinks, "I should have known better," and says nothing. And that silence buys the criminals exactly what they need — time to move the money, discard the phone number, abandon the account and move on to the next target.
 
The most important thing for any victim to understand is this: nobody is blaming you for what happened.
 
So, report it. Inform your bank by phone and in writing — a letter or email laying out the details of your call with their customer care team. Keep every piece of evidence. Inform the police or use the proper cybercrime reporting channel. And if it is a family member who has been targeted, help them through the process instead of asking why they fell for it in the first place.
 
The Easiest Security Fix Is Often the Most Neglected One
 
The report also exposes a real gap between how people use technology and how carefully they protect themselves while doing it.
 
Unified payment interface (UPI) has become part of daily life for the vast majority of respondents — 49% said they use UPI apps every single day. And yet 20% admitted they don't bother with two-step verification when making UPI transactions. Only 21% said they always follow basic cyber-safety practices, such as avoiding public Wi-Fi, checking app permissions, or verifying a website or app is genuine before using it. Another 21% said they never do any of this at all.
 
In other words, convenience has clearly won the battle for the adoption of digital payments like UPI. Security habits, however, still have a long way to go to catch up.
 
That does not mean you should give up on digital payments or online transactions. It simply means treating your phone as a financial instrument or a treasure, not just a device for messaging and scrolling.
 
What You Can Do
 
A few simple habits go a long way toward reducing your exposure to the most common scams:
  • Never share a one-time passcode (OTP), UPI personal identification number (PIN), card PIN or password with anyone who calls claiming to be from a bank, the police, a courier company or a government agency. No genuine official needs your confidential login credentials to do their job.
  • Don't install an app just because a caller tells you to. Fraudsters often disguise malicious apps as customer support tools, know-your-customer (KYC) updates, delivery trackers or investment platforms. Only download apps from official app stores, and always check the developer’s name and the permissions being requested.
  • Never approve a UPI request simply because someone claims they are sending you money. Before entering your PIN, clearly understand whether you are authorising a payment out or genuinely receiving one.
  • Treat urgency from the other end (fraudster) as a warning sign, not a reason to act fast. "Your account will be blocked in ten minutes," "Your parcel contains illegal material," "You'll be arrested unless you pay" — these are all classic pressure tactics. Stop the conversation and independently contact the organisation using its official number or website.
  • Be sceptical of guaranteed returns. If someone promises unusually high or ‘guaranteed’ profits and pushes you to transfer money immediately, step back. Verify the investment and the entity independently before sending a single rupee.
  • Don't trust caller ID alone. A number can display a familiar name or an organisation's identity and still be entirely fraudulent.
  • Secure your email and social media accounts properly. Use strong, unique passwords, enable multi-factor authentication (MFA) wherever it is available, and review your account recovery settings to remove any unnecessary access.
  • Keep your phone and apps updated. Security patches often close exactly the loopholes criminals rely on.
  • Be careful what you share publicly, especially in social media posts and reels. Personal details posted online can make a fraudster's impersonation attempt far more convincing than it has any right to be.
 
And perhaps the single most important rule of all: if something feels urgent or pressurised, take a break and step away.
 
Fraudsters want you to decide before you have had time to think. Fear, greed, excitement, urgency — these emotions are manufactured deliberately because they push humans to act fast rather than think clearly.
 
What To Do If the Money's Already Gone
 
Once a fraudulent transaction has occurred, don't wait until the next day because you are embarrassed or not sure what to do.
 
Contact your bank or payment provider immediately through its official channel and report the transaction. Preserve every piece of evidence you have. Report the crime through the official channels available, and approach the police where appropriate.
 
And whatever you do, don't pay a second person who promises to ‘recover’ the money you have already lost. Recovery scams specifically target people who have just suffered one loss, precisely because they are desperate and vulnerable.
 
The SPIR 2026 findings underline exactly why speed matters here — but they also show its limits. Despite so many victims quickly reporting the fraud to their banks, 72% said they were unable to recover any of the money they'd lost.
 
Cybersecurity Is Now a Shared Responsibility
 
There is another important message buried in this report: public awareness alone cannot be the whole solution.
 
Nearly three-quarters of respondents felt the police were at least somewhat equipped to handle financial cybercrime, though victims themselves were less confident in the police's preparedness than those who had not been through it.
 
 
The report also raises real concerns about how banks handle victims and coordinate with the police. In its qualitative interviews, most financial-fraud victims said their bank offered little real help with recovery, and — with just one exception — banks tended to characterise victims as having ‘collaborated’ with the fraudster.
 
That perception matters more than it might seem.
 
Almost all bankers must understand that their own customer, who has just been manipulated by a professional fraud network, needs an effective response — not a lecture on why the transaction was technically authorised. Better coordination among banks, payment platforms, the police and cybercrime investigators is no longer a nice-to-have. It is essential that the response always keeps pace with increasingly organised fraud networks.
 
For the rest of us, though, the message is simpler.
 
Pause before you pay. Verify before you trust. Protect your credentials. And if a fraud does happen, report it immediately — not tomorrow, not once you have worked up the nerve, but now.
 
As I keep saying, cybercriminals are no longer lone wolves working from a messy, crumbling room somewhere. Cybercrime today runs like a well-oiled business operation.
 
Our response — individual and institutional alike — needs to become just as disciplined and organised, in turn.
 
Stay Alert, Stay Safe!