Navigating the Path to CyberPeace: Insights and Strategies
Featured Blogs

Most laws regulate what people do. This one regulates what clock everyone is doing it by, and once you sit with that idea for a moment, it stops sounding like a bureaucratic footnote and starts sounding like something genuinely foundational.
On 27 August 2026, India's Department of Consumer Affairs notified the Legal Metrology (Indian Standard Time) Rules, 2026, making Indian Standard Time the single legally binding reference for every legal, administrative, commercial, and official purpose across the country. The Rules will come into force 180 days after their publication in the Official Gazette, giving government departments, businesses, and institutions a compliance runway to align their systems before the requirement actually bites.
Why time needed a law at all
It might seem strange that a country needs legislation to tell everyone what time it is. India has used IST, a single time zone five and a half hours ahead of Coordinated Universal Time, since 1947. But using a time zone informally and legally mandating it as the sole authoritative reference for every official and commercial transaction are two very different things, and the gap between them is exactly where this rule lives.
The government's own reasoning, laid out in its official statement, centres on a shift most people experience daily without ever thinking about its plumbing. Banking and digital payments, telecommunications networks, railways, power grids, and government record systems all depend on accurate, synchronised time stamps to function correctly. When different systems quietly draw their time from different sources, even by fractions of a second, the resulting inconsistencies can affect the coordination and recording of transactions in ways that are invisible until something goes wrong. A trade executed on a stock exchange, a UPI payment cleared between banks, a railway signal handoff between two junctions, and an emergency service dispatch all depend on every clock in the chain agreeing with every other clock, and until now, India had no single rule compelling that agreement.
The quieter, more interesting part of the rule
Buried inside the announcement is a detail that matters more than the headline. The Rules do not simply declare IST the law of the land; they also authorise the use of NavIC, India's own satellite navigation system, alongside other approved domestic timing sources, as legitimate means of disseminating that time. The government's stated rationale is candid about the current state of affairs: several critical Indian systems presently draw their time from foreign satellite based sources, and building domestic timing infrastructure through NavIC and legal metrology laboratories is intended to reduce that dependence going forward.
That single sentence carries real weight once you consider how global positioning and timing systems actually work. Most of the world's precise digital time synchronisation ultimately traces back to GPS, the American satellite constellation, whose signals also happen to be notoriously easy to disrupt. GPS and other satellite navigation signals arrive at receivers on Earth as extremely weak radio transmissions, weak enough that they can be jammed with cheap equipment or spoofed, meaning an attacker broadcasts a counterfeit signal that mimics a legitimate one closely enough to fool a receiver into accepting false position or timing data. Researchers and government reports going back years have flagged that a large share of critical infrastructure sectors, power grids, financial markets, telecommunications, and transport among them, carry meaningful dependence on GPS derived timing, and a 2017 UK government assessment specifically warned that systematic satellite signal jamming could cause serious disruption to a country's financial, electricity, and communications systems all at once. Cybersecurity researchers have separately demonstrated proof of concept attacks where a deliberately falsified timing signal, rather than a falsified position, was enough to destabilise systems that assumed their clock could always be trusted.
Seen against that backdrop, embedding NavIC as an approved domestic timing source inside a legal metrology framework is not merely a nationalistic footnote about self reliance. It is a genuine resilience decision. A country that can generate, verify, and distribute its own trusted time signal, independent of a foreign satellite constellation that it does not control and cannot secure on its own, has a meaningfully smaller attack surface for an entire category of infrastructure disruption that rarely makes headlines until it actually happens.
Who actually built this, and why that composition matters
The drafting process itself offers a useful clue about how seriously this was treated. Reports on the rule making process indicate the Rules were shaped by a high powered inter ministerial committee chaired by the Secretary of Consumer Affairs, with representation from the National Physical Laboratory and the Indian Space Research Organisation for the underlying science and satellites, IIT Kanpur for engineering expertise, the National Informatics Centre and CERT In for network infrastructure and its security, the Securities and Exchange Board of India for financial market implications, and the Railways, Telecom, and Financial Services departments for the systems that will actually have to run on this new standard day to day. That is not a committee assembled around a single ministry's convenience; it is a committee assembled around the actual shape of the problem, spanning physics, engineering, finance, and network security together. As part of the broader One Nation, One Time initiative, a White Rabbit Technology based IST Dissemination Demonstration Network was already commissioned at the Regional Reference Standard Laboratory in Bengaluru back in July 2026, suggesting the infrastructure groundwork was underway well before the legal framework caught up to it.
What the 180 day window actually means in practice
It is worth being precise about what compliance actually requires here. This is not a deadline demanding new hardware overnight; for most organisations, it means auditing which internal systems currently reference time from an unverified or foreign source and ensuring they align with certified IST going forward, alongside institutions preparing to receive that certified time through the domestic infrastructure the government is simultaneously building out. The six month runway exists precisely because this touches an unusually wide spread of sectors at once, and forcing an abrupt cutover would create more operational risk than the rule is designed to remove.
The bigger picture
A rule about what time it is legally does not sound like cybersecurity news, and on the surface, it is not. But underneath the administrative language sits a genuinely forward looking recognition: as more of daily life, banking, communication, transport, and governance runs on systems that must agree, down to the second, on a shared reference point, the integrity of that reference point becomes critical infrastructure in its own right. India choosing to build, verify, and legally anchor its own trusted time source, rather than continuing to quietly rely on a foreign satellite system it cannot secure independently, is less about symbolism and more about closing a vulnerability most people never knew existed until they were asked to think about it.
References
- OpenGov Asia, "India Issues Rules to Standardise National Time Reference Systems." https://opengovasia.com/india-issues-rules-to-standardise-national-time-reference-systems/?c=us
- Daily Excelsior, "Centre notifies rules mandating IST as common time reference; 180 day window for compliance." https://www.dailyexcelsior.com/centre-notifies-rules-mandating-ist-as-common-time-reference-180-day-window-for-compliance/
- Greater Kashmir, "Department of Consumer Affairs notifies Legal Metrology Rules, 2026." https://www.greaterkashmir.com/national/department-of-consumer-affairs-notifies-legal-metrology-rules-2026-12454447
- Insights on India, "Legal Metrology (Indian Standard Time) Rules, 2026." https://www.insightsonindia.com/2026/08/31/legal-metrology-indian-standard-time-rules-2026/
- Blitz India Media, "Indian Standard Time Rules 2026: NavIC, Legal Metrology." https://blitzindiamedia.com/news/indian-standard-time-rules-2026-navic-legal-metrology/
- Observer Voice, "India Establishes Legal Framework for Standard Time." https://observervoice.com/india-establishes-legal-framework-for-standard-time-225958/
- The Live Nagpur, "Govt notifies rules to make IST the common time reference." https://thelivenagpur.com/2026/08/31/govt-notifies-rules-to-make-ist-the-common-time-reference/
- Safran Navigation and Timing, "GNSS Security and Cybersecurity: What are the Parallels?" https://safran-navigation-timing.com/gnss-security-and-cybersecurity-what-are-the-parallels/
- Safran Navigation and Timing, "Securing Critical Infrastructures from Jamming and Spoofing Cyberattacks." https://safran-navigation-timing.com/securing-critical-infrastructures-from-jamming-and-spoofing-cyberattacks/
- Combain, "The Silent Threat In The Sky: GPS Jamming, GPS Spoofing." https://combain.com/gps-jamming-spoofing/

Introduction
For years, the story of terror recruitment in Jammu & Kashmir followed a familiar arc: physical infiltration across the Line of Control, local Over Ground Workers (OGWs) acting as couriers, and recruitment pitches on mainstream apps like WhatsApp and Facebook Messenger. Indian security agencies built entire surveillance architectures around that arc. Now, officials say, the architecture is being outflanked in a way few anticipated: through pornography and dating platforms.
The New Front: Chat Rooms Nobody Is Watching
According to officials cited in recent reporting, Pakistan-based terror handlers working in coordination with Pakistan's ISI have begun exploiting the real-time chat features built into pornography and dating websites to reach recruits in Jammu & Kashmir. These pornography platforms feature real-time chat tools that operate under the guise of helping users find dates nearby, and handlers are exploiting that feature to broadcast messages and coordinate activities. It's a strikingly mundane pivot for an organisation engaged in violent extremism, but that is precisely the point that nobody expects a counter-terror dragnet to be watching a dating chatbox.
Officials say the tactic is designed to evade the surveillance that has become standard on conventional social media platforms, allowing handlers to convey instructions to recruits while staying off the radar of established monitoring tools. WhatsApp, Signal and Facebook Messenger have all, in various ways, become known quantities to Indian intelligence subject to legal intercepts, metadata analysis and years of institutional familiarity. A chat window buried inside an adult content site is not.
Tor, Encrypted Nodes, and Apps Built to Disappear
Other than porn sites, investigators have also flagged a cluster of niche, privacy-first messaging apps that route traffic through Tor-based, encrypted nodes to mask user identity. Security agencies have placed a wide array of specialised digital tools under scrutiny, with terror handlers relying on Tor-based messaging applications like Coatex and Conion to route data through encrypted nodes and obscure user identities. Access to at least one of these apps' installation files is reportedly already restricted within India, though enforcement against sideloaded Android packages remains an uphill battle.
What makes these platforms attractive to handlers isn't unique code so much as the design philosophy behind privacy-first messaging generally. Some of these apps offer only basic encryption, while others go further with end-to-end encryption, self-destructing messages, and strong on-device encryption algorithms that keep data processing off any third-party server. Several reportedly allow account creation without a phone number or SIM verification, stripping away one of the most basic identity anchors that Indian telecom-linked surveillance depends on.
There's also an operational, almost logistical, reason for the shift: connectivity. Officials note that some of these applications provide end-to-end encryption, self-destructing messages and registration without a phone number or email, making it difficult for security agencies to trace users, even as terror networks also shift away from commonly used platforms. In the hilly, forested and often poorly connected terrain of Jammu's border districts, apps engineered to function on weak 2G or EDGE networks have an obvious tactical advantage over data-hungry mainstream platforms.
VPNs, Banned Apps, and a Cat-and-Mouse Game
Virtual Private Networks add another layer of obfuscation, letting operatives access apps banned in India and mask the geographic origin of their traffic. This isn't new tradecraft, but its pairing with adult-content chat infrastructure and Tor-routed messaging represents a genuinely novel combination in the Kashmir context, according to the officials describing the pattern to reporters.
The broader trend line, officials say, is a steady migration away from platforms Indian agencies have learned to monitor. Terror networks are increasingly moving away from mainstream, commonly used platforms in favour of more obscure alternatives, forcing intelligence agencies into a perpetual game of catch-up: each time a monitoring capability matures against one platform, handlers migrate to the next.
This is not the first time investigators have flagged this cat-and-mouse dynamic. Reporting on a recent case in Jammu's Bathindi area described a 19-year-old allegedly radicalised through the encrypted app. Session the same platform reportedly linked to suspects in a Delhi bomb plot investigation after months of contact with Pakistan-based handlers. Investigators in that case noted that terror organisations have increasingly turned to multi-layered encrypted messaging services specifically to evade monitoring by intelligence agencies.
The Virtual SIM Problem
Alongside app-layer evasion, foreign-issued virtual SIM cards remain a persistent headache for investigators. The most cited example remains the 2019 Pulwama attack investigation, in which agencies reportedly traced more than 40 virtual SIM cards to the Jaish-e-Mohammed suicide bomber and his network numbers that could be provisioned and abandoned without ever touching an Indian telecom's KYC system. That case became something of a template for how virtual and foreign-registered numbers can be used to build communication chains that are extremely difficult to map after the fact, since there is no physical SIM, no retail purchase record, and often no domestic carrier data trail at all.
More recent J&K cases echo the same pattern in a different form. Police investigating a cross-border radicalisation network noted that intelligence agencies now suspect unauthorised SIM card distribution is being used by terrorists to communicate with handlers across the border, part of a broader push to choke off the logistical and communication backbone that keeps sleeper modules alive even when direct physical contact with a local handler is minimal or non-existent.
How Agencies Are Responding
To their credit, security agencies aren't standing still. Officials say cyber-surveillance frameworks are actively being redesigned to map and intercept these "off-grid" communication channels, a phrase that itself signals how far outside traditional monitoring territory this recruitment method has moved. Agencies say they continue to adapt their cyber-surveillance frameworks specifically to map and intercept these off-grid communication channels. That has included moving to restrict access to specific APKs, tightening scrutiny of virtual number providers, and, as seen in recent CIK (Counter Intelligence Kashmir) operations, proactively disrupting online propaganda networks before recruitment pitches can mature into operational plots. One recent CIK operation, for instance, intercepted attempts to recruit two teenage boys who were allegedly being fed terror content in the direction of a Pakistan-based handler, underlining how young the target pool for these campaigns has become.
Conclusion
What this episode really illustrates isn't a single clever trick but a structural truth about counter-terror surveillance: it is inherently reactive. Every time agencies build competence around a platform, handlers find a low-attention, high-friction-to-monitor alternative: first fringe messaging apps, then Tor-routed clients, and now the sprawling, largely unregulated back-end of adult content platforms, which few people would ever think to associate with national security. It's a reminder that the fight against radicalisation online is no longer confined to obviously "extremist" corners of the internet; it can hide in plain sight, inside the most ordinary-looking corners of the web.
Sources
- New J-K terror tactic: Pornography apps, Tor network used for secret messaging — The Tribune
- New J&K terror tactic: Handlers turn to porn sites, encrypted apps to contact recruits — Deccan Herald
- Terrorists using porn website, encrypted apps for chats with recruits — Organiser
- New J&K Terror Tactic: Pornography Apps, Tor Network Used For Secret Messaging — Kashmir Dot Com
- From WhatsApp to Porn Sites: Terror Groups Adopt New Digital Tactic in J&K — Jammu Kashmir Now
- Jammu teenager's arrest exposes cross-border radicalisation network — The Tribune
- After OGW network, J&K cops target communication channel of terrorists — The Tribune
- CIK busts online radical network, foils recruitment of two minors — The Tribune

Most laws regulate what people do. This one regulates what clock everyone is doing it by, and once you sit with that idea for a moment, it stops sounding like a bureaucratic footnote and starts sounding like something genuinely foundational.
On 27 August 2026, India's Department of Consumer Affairs notified the Legal Metrology (Indian Standard Time) Rules, 2026, making Indian Standard Time the single legally binding reference for every legal, administrative, commercial, and official purpose across the country. The Rules will come into force 180 days after their publication in the Official Gazette, giving government departments, businesses, and institutions a compliance runway to align their systems before the requirement actually bites.
Why time needed a law at all
It might seem strange that a country needs legislation to tell everyone what time it is. India has used IST, a single time zone five and a half hours ahead of Coordinated Universal Time, since 1947. But using a time zone informally and legally mandating it as the sole authoritative reference for every official and commercial transaction are two very different things, and the gap between them is exactly where this rule lives.
The government's own reasoning, laid out in its official statement, centres on a shift most people experience daily without ever thinking about its plumbing. Banking and digital payments, telecommunications networks, railways, power grids, and government record systems all depend on accurate, synchronised time stamps to function correctly. When different systems quietly draw their time from different sources, even by fractions of a second, the resulting inconsistencies can affect the coordination and recording of transactions in ways that are invisible until something goes wrong. A trade executed on a stock exchange, a UPI payment cleared between banks, a railway signal handoff between two junctions, and an emergency service dispatch all depend on every clock in the chain agreeing with every other clock, and until now, India had no single rule compelling that agreement.
The quieter, more interesting part of the rule
Buried inside the announcement is a detail that matters more than the headline. The Rules do not simply declare IST the law of the land; they also authorise the use of NavIC, India's own satellite navigation system, alongside other approved domestic timing sources, as legitimate means of disseminating that time. The government's stated rationale is candid about the current state of affairs: several critical Indian systems presently draw their time from foreign satellite based sources, and building domestic timing infrastructure through NavIC and legal metrology laboratories is intended to reduce that dependence going forward.
That single sentence carries real weight once you consider how global positioning and timing systems actually work. Most of the world's precise digital time synchronisation ultimately traces back to GPS, the American satellite constellation, whose signals also happen to be notoriously easy to disrupt. GPS and other satellite navigation signals arrive at receivers on Earth as extremely weak radio transmissions, weak enough that they can be jammed with cheap equipment or spoofed, meaning an attacker broadcasts a counterfeit signal that mimics a legitimate one closely enough to fool a receiver into accepting false position or timing data. Researchers and government reports going back years have flagged that a large share of critical infrastructure sectors, power grids, financial markets, telecommunications, and transport among them, carry meaningful dependence on GPS derived timing, and a 2017 UK government assessment specifically warned that systematic satellite signal jamming could cause serious disruption to a country's financial, electricity, and communications systems all at once. Cybersecurity researchers have separately demonstrated proof of concept attacks where a deliberately falsified timing signal, rather than a falsified position, was enough to destabilise systems that assumed their clock could always be trusted.
Seen against that backdrop, embedding NavIC as an approved domestic timing source inside a legal metrology framework is not merely a nationalistic footnote about self reliance. It is a genuine resilience decision. A country that can generate, verify, and distribute its own trusted time signal, independent of a foreign satellite constellation that it does not control and cannot secure on its own, has a meaningfully smaller attack surface for an entire category of infrastructure disruption that rarely makes headlines until it actually happens.
Who actually built this, and why that composition matters
The drafting process itself offers a useful clue about how seriously this was treated. Reports on the rule making process indicate the Rules were shaped by a high powered inter ministerial committee chaired by the Secretary of Consumer Affairs, with representation from the National Physical Laboratory and the Indian Space Research Organisation for the underlying science and satellites, IIT Kanpur for engineering expertise, the National Informatics Centre and CERT In for network infrastructure and its security, the Securities and Exchange Board of India for financial market implications, and the Railways, Telecom, and Financial Services departments for the systems that will actually have to run on this new standard day to day. That is not a committee assembled around a single ministry's convenience; it is a committee assembled around the actual shape of the problem, spanning physics, engineering, finance, and network security together. As part of the broader One Nation, One Time initiative, a White Rabbit Technology based IST Dissemination Demonstration Network was already commissioned at the Regional Reference Standard Laboratory in Bengaluru back in July 2026, suggesting the infrastructure groundwork was underway well before the legal framework caught up to it.
What the 180 day window actually means in practice
It is worth being precise about what compliance actually requires here. This is not a deadline demanding new hardware overnight; for most organisations, it means auditing which internal systems currently reference time from an unverified or foreign source and ensuring they align with certified IST going forward, alongside institutions preparing to receive that certified time through the domestic infrastructure the government is simultaneously building out. The six month runway exists precisely because this touches an unusually wide spread of sectors at once, and forcing an abrupt cutover would create more operational risk than the rule is designed to remove.
The bigger picture
A rule about what time it is legally does not sound like cybersecurity news, and on the surface, it is not. But underneath the administrative language sits a genuinely forward looking recognition: as more of daily life, banking, communication, transport, and governance runs on systems that must agree, down to the second, on a shared reference point, the integrity of that reference point becomes critical infrastructure in its own right. India choosing to build, verify, and legally anchor its own trusted time source, rather than continuing to quietly rely on a foreign satellite system it cannot secure independently, is less about symbolism and more about closing a vulnerability most people never knew existed until they were asked to think about it.
References
- OpenGov Asia, "India Issues Rules to Standardise National Time Reference Systems." https://opengovasia.com/india-issues-rules-to-standardise-national-time-reference-systems/?c=us
- Daily Excelsior, "Centre notifies rules mandating IST as common time reference; 180 day window for compliance." https://www.dailyexcelsior.com/centre-notifies-rules-mandating-ist-as-common-time-reference-180-day-window-for-compliance/
- Greater Kashmir, "Department of Consumer Affairs notifies Legal Metrology Rules, 2026." https://www.greaterkashmir.com/national/department-of-consumer-affairs-notifies-legal-metrology-rules-2026-12454447
- Insights on India, "Legal Metrology (Indian Standard Time) Rules, 2026." https://www.insightsonindia.com/2026/08/31/legal-metrology-indian-standard-time-rules-2026/
- Blitz India Media, "Indian Standard Time Rules 2026: NavIC, Legal Metrology." https://blitzindiamedia.com/news/indian-standard-time-rules-2026-navic-legal-metrology/
- Observer Voice, "India Establishes Legal Framework for Standard Time." https://observervoice.com/india-establishes-legal-framework-for-standard-time-225958/
- The Live Nagpur, "Govt notifies rules to make IST the common time reference." https://thelivenagpur.com/2026/08/31/govt-notifies-rules-to-make-ist-the-common-time-reference/
- Safran Navigation and Timing, "GNSS Security and Cybersecurity: What are the Parallels?" https://safran-navigation-timing.com/gnss-security-and-cybersecurity-what-are-the-parallels/
- Safran Navigation and Timing, "Securing Critical Infrastructures from Jamming and Spoofing Cyberattacks." https://safran-navigation-timing.com/securing-critical-infrastructures-from-jamming-and-spoofing-cyberattacks/
- Combain, "The Silent Threat In The Sky: GPS Jamming, GPS Spoofing." https://combain.com/gps-jamming-spoofing/

Introduction
For years, the story of terror recruitment in Jammu & Kashmir followed a familiar arc: physical infiltration across the Line of Control, local Over Ground Workers (OGWs) acting as couriers, and recruitment pitches on mainstream apps like WhatsApp and Facebook Messenger. Indian security agencies built entire surveillance architectures around that arc. Now, officials say, the architecture is being outflanked in a way few anticipated: through pornography and dating platforms.
The New Front: Chat Rooms Nobody Is Watching
According to officials cited in recent reporting, Pakistan-based terror handlers working in coordination with Pakistan's ISI have begun exploiting the real-time chat features built into pornography and dating websites to reach recruits in Jammu & Kashmir. These pornography platforms feature real-time chat tools that operate under the guise of helping users find dates nearby, and handlers are exploiting that feature to broadcast messages and coordinate activities. It's a strikingly mundane pivot for an organisation engaged in violent extremism, but that is precisely the point that nobody expects a counter-terror dragnet to be watching a dating chatbox.
Officials say the tactic is designed to evade the surveillance that has become standard on conventional social media platforms, allowing handlers to convey instructions to recruits while staying off the radar of established monitoring tools. WhatsApp, Signal and Facebook Messenger have all, in various ways, become known quantities to Indian intelligence subject to legal intercepts, metadata analysis and years of institutional familiarity. A chat window buried inside an adult content site is not.
Tor, Encrypted Nodes, and Apps Built to Disappear
Other than porn sites, investigators have also flagged a cluster of niche, privacy-first messaging apps that route traffic through Tor-based, encrypted nodes to mask user identity. Security agencies have placed a wide array of specialised digital tools under scrutiny, with terror handlers relying on Tor-based messaging applications like Coatex and Conion to route data through encrypted nodes and obscure user identities. Access to at least one of these apps' installation files is reportedly already restricted within India, though enforcement against sideloaded Android packages remains an uphill battle.
What makes these platforms attractive to handlers isn't unique code so much as the design philosophy behind privacy-first messaging generally. Some of these apps offer only basic encryption, while others go further with end-to-end encryption, self-destructing messages, and strong on-device encryption algorithms that keep data processing off any third-party server. Several reportedly allow account creation without a phone number or SIM verification, stripping away one of the most basic identity anchors that Indian telecom-linked surveillance depends on.
There's also an operational, almost logistical, reason for the shift: connectivity. Officials note that some of these applications provide end-to-end encryption, self-destructing messages and registration without a phone number or email, making it difficult for security agencies to trace users, even as terror networks also shift away from commonly used platforms. In the hilly, forested and often poorly connected terrain of Jammu's border districts, apps engineered to function on weak 2G or EDGE networks have an obvious tactical advantage over data-hungry mainstream platforms.
VPNs, Banned Apps, and a Cat-and-Mouse Game
Virtual Private Networks add another layer of obfuscation, letting operatives access apps banned in India and mask the geographic origin of their traffic. This isn't new tradecraft, but its pairing with adult-content chat infrastructure and Tor-routed messaging represents a genuinely novel combination in the Kashmir context, according to the officials describing the pattern to reporters.
The broader trend line, officials say, is a steady migration away from platforms Indian agencies have learned to monitor. Terror networks are increasingly moving away from mainstream, commonly used platforms in favour of more obscure alternatives, forcing intelligence agencies into a perpetual game of catch-up: each time a monitoring capability matures against one platform, handlers migrate to the next.
This is not the first time investigators have flagged this cat-and-mouse dynamic. Reporting on a recent case in Jammu's Bathindi area described a 19-year-old allegedly radicalised through the encrypted app. Session the same platform reportedly linked to suspects in a Delhi bomb plot investigation after months of contact with Pakistan-based handlers. Investigators in that case noted that terror organisations have increasingly turned to multi-layered encrypted messaging services specifically to evade monitoring by intelligence agencies.
The Virtual SIM Problem
Alongside app-layer evasion, foreign-issued virtual SIM cards remain a persistent headache for investigators. The most cited example remains the 2019 Pulwama attack investigation, in which agencies reportedly traced more than 40 virtual SIM cards to the Jaish-e-Mohammed suicide bomber and his network numbers that could be provisioned and abandoned without ever touching an Indian telecom's KYC system. That case became something of a template for how virtual and foreign-registered numbers can be used to build communication chains that are extremely difficult to map after the fact, since there is no physical SIM, no retail purchase record, and often no domestic carrier data trail at all.
More recent J&K cases echo the same pattern in a different form. Police investigating a cross-border radicalisation network noted that intelligence agencies now suspect unauthorised SIM card distribution is being used by terrorists to communicate with handlers across the border, part of a broader push to choke off the logistical and communication backbone that keeps sleeper modules alive even when direct physical contact with a local handler is minimal or non-existent.
How Agencies Are Responding
To their credit, security agencies aren't standing still. Officials say cyber-surveillance frameworks are actively being redesigned to map and intercept these "off-grid" communication channels, a phrase that itself signals how far outside traditional monitoring territory this recruitment method has moved. Agencies say they continue to adapt their cyber-surveillance frameworks specifically to map and intercept these off-grid communication channels. That has included moving to restrict access to specific APKs, tightening scrutiny of virtual number providers, and, as seen in recent CIK (Counter Intelligence Kashmir) operations, proactively disrupting online propaganda networks before recruitment pitches can mature into operational plots. One recent CIK operation, for instance, intercepted attempts to recruit two teenage boys who were allegedly being fed terror content in the direction of a Pakistan-based handler, underlining how young the target pool for these campaigns has become.
Conclusion
What this episode really illustrates isn't a single clever trick but a structural truth about counter-terror surveillance: it is inherently reactive. Every time agencies build competence around a platform, handlers find a low-attention, high-friction-to-monitor alternative: first fringe messaging apps, then Tor-routed clients, and now the sprawling, largely unregulated back-end of adult content platforms, which few people would ever think to associate with national security. It's a reminder that the fight against radicalisation online is no longer confined to obviously "extremist" corners of the internet; it can hide in plain sight, inside the most ordinary-looking corners of the web.
Sources
- New J-K terror tactic: Pornography apps, Tor network used for secret messaging — The Tribune
- New J&K terror tactic: Handlers turn to porn sites, encrypted apps to contact recruits — Deccan Herald
- Terrorists using porn website, encrypted apps for chats with recruits — Organiser
- New J&K Terror Tactic: Pornography Apps, Tor Network Used For Secret Messaging — Kashmir Dot Com
- From WhatsApp to Porn Sites: Terror Groups Adopt New Digital Tactic in J&K — Jammu Kashmir Now
- Jammu teenager's arrest exposes cross-border radicalisation network — The Tribune
- After OGW network, J&K cops target communication channel of terrorists — The Tribune
- CIK busts online radical network, foils recruitment of two minors — The Tribune

CyberPeace | Automotive Cybersecurity & Digital Forensics
Introduction
After a crash, the story usually comes from the driver, a witness or a police report. But a modern vehicle can leave another version behind - a digital one. An Event Data Recorder (EDR), commonly called a car's black box, can preserve selected information from the seconds around a crash. NHTSA describes EDRs as recording vehicle dynamics, driver inputs, crash characteristics, restraint status and some post-crash information.[1] The exact fields depend on the vehicle. A black box is not a magical device that records everything; it is one evidence source inside a much larger vehicle.
A modern vehicle can also contain safety controllers, diagnostic interfaces, ADAS, telematics and software-update systems. For an investigator, the question is what evidence can be linked to the EDR and what that combined record can actually support.
What Is Actually in the Black Box?

An EDR is best understood as a short event record, not a continuous driving diary. Depending on the vehicle and its configuration, forensic extraction may reveal items such as speed, acceleration, delta-V, engine RPM, throttle position, brake status, steering input, ABS or stability-control activity, seat-belt status and airbag or restraint events. NHTSA's published EDR material shows that data elements can include longitudinal and lateral acceleration, delta-V, vehicle speed, engine speed, throttle, service-brake status, roll/pitch/yaw information and steering input.[2] Do not overread the data: A field that exists in one model should not automatically be assumed to exist in another. A forensic report must identify exactly which module and fields were available and actually recovered.
What Can a Forensic Examination Recover?

A Brake Failure Example
Consider a driver who reports: “I pressed the brake, but nothing happened.” The statement should be preserved, but a forensic investigation should test it. Was brake status captured? What was the speed before the event? Did ABS activate? What were the acceleration and delta-V patterns? Were there relevant fault codes? Was the vehicle recently repaired or updated? Suppose the recovered records show a brake input, ABS activity and a change in vehicle speed before impact. That does not prove the brakes were mechanically perfect. It does, however, make the sentence “nothing happened” too simple. Conversely, a relevant fault appearing just before the event may give investigators a stronger lead. The important part is the comparison: human account, vehicle record, physical evidence and technical history should be examined together.
Smart Vehicles, Digital Evidence and Cybersecurity Investigation
A connected vehicle can communicate through cellular networks, Bluetooth, Wi-Fi, mobile applications, workshop tools and cloud services. If unusual activity appears around a safety-critical incident, investigators may need to look beyond the EDR. Useful questions include:
• Was there unusual diagnostic or service activity before the incident?
• Was a software update or configuration change recently applied?
• Do timestamps from different modules line up, or is there clock drift?
• Can the extracted record be tied back to the original vehicle and module?
• Is there a non-cyber explanation - such as a hardware fault or software defect - that fits the evidence better?
The mindset matters: A cyberattack should be a conclusion supported by evidence, not the default explanation for strange vehicle behaviour.
The Forensic View: From Data to Evidence

Automotive forensics is not simply plugging in a tool and exporting a report. The investigator should document the vehicle identity, module involved, extraction method, tool version, acquisition time and evidence-preservation steps. The goal is to make the work repeatable and defensible.
• Identify the relevant modules and evidence sources.
• Preserve the vehicle and extracted data against unnecessary alteration.
• Acquire data using a documented and appropriate method.
• Validate provenance, integrity, timestamps and completeness.
• Correlate EDR, diagnostics, software history, connected records and physical evidence.
• Report both findings and uncertainty.
A useful forensic rule: “Recorded” does not mean “proven.” Evidence becomes persuasive when its source, integrity and context are clear.
What the Law and Standards Are Changing
India is moving toward a more formal automotive cybersecurity lifecycle. IS-189 focuses on vehicle cybersecurity and the Cyber Security Management System (CSMS), while AIS-190 deals with software updates and the Software Update Management System (SUMS).[4][5] The wider statutory and type-approval framework is provided by the Motor Vehicles Act, 1988 and the Central Motor Vehicles Rules, 1989. For vehicle prototypes, Rule 126 provides for testing and approval by authorized testing agencies.[6][7]
In June 2026, the Ministry of Road Transport and Highways (MoRTH) came out with draft G.S.R. 503(E). The draft proposes new CMVR Rules 125-T and 125-U covering cybersecurity and software-update requirements. Since G.S.R. 503(E) is still a draft notification, its proposed requirements and the dates from which they may apply should be verified with the latest final notification before treating them as applicable law.[8]
At the international level, UN Regulation No. 155 addresses vehicle cybersecurity, while UN Regulation No. 156 covers software updates and their management.[9][10] This matters to forensics because lifecycle cybersecurity creates an expectation that manufacturers should be able to understand and manage security risks over time. In other words, logs, software-state information, vulnerability records and incident evidence can become part of the security story, not merely post-incident paperwork.
The Real Takeaway
The black box is valuable because it can reduce guesswork. It may tell us how fast the vehicle was moving, whether the driver applied the brake, how the vehicle responded, and what certain safety systems were doing around the event. But it rarely answers the whole case on its own. The strongest investigation is built by joining several pieces: EDR data, diagnostics, software context, connected-system evidence and what was found at the crash scene.
For cybersecurity professionals, the lesson is simple: a secure vehicle should not only resist attacks. It should also leave trustworthy evidence when something goes wrong. Good access controls, reliable timestamps and careful evidence handling help turn “something failed” into a defensible explanation.
Conclusion
The phrase “car black box” sounds simple, but the evidence behind it is not. An EDR can preserve a small but valuable window into a crash. During forensic examination, investigators may also be able to recover diagnostic, safety-system, software and connected-vehicle information, depending on the vehicle and what has been retained. The job is not to collect the largest possible amount of data. It is to collect the right data, preserve it properly and understand what each record can - and cannot - prove.
That is where automotive cybersecurity and digital forensics meet. As vehicles become more connected and software-driven, the ability to reconstruct an incident becomes part of security itself.
References
1. National Highway Traffic Safety Administration (NHTSA), Event Data Recorder (EDR) overview and research resources.
2. NHTSA, Use of Event Data Recorder (EDR) Technology for Highway Crash Data Analysis.
3. NHTSA, Light-Vehicle Event Data Recorder Technologies Update.
4. Automotive Research Association of India (ARAI), AIS-189, Approval of Vehicles with Regards to Cyber Security and Cyber Security Management System, April 2024.
5. Automotive Research Association of India (ARAI), AIS-190, Approval of Vehicles with Regards to Software Update and Software Update Management System, April 2024.
6. Government of India, Motor Vehicles Act, 1988.
7. Government of India, Central Motor Vehicles Rules, 1989, Rule 126.
8. Ministry of Road Transport and Highways, G.S.R. 503(E), 17 June 2026, draft Central Motor Vehicles (Amendment) Rules concerning cybersecurity and software updates.
9. UNECE, UN Regulation No. 155, Cyber Security and Cyber Security Management System.
10. UNECE, UN Regulation No. 156, Software Update and Software Update Management System.
11. NIST, SP 800-86, Guide to Integrating Forensic Techniques into Incident Response.

Introduction
Artificial intelligence has quietly become part of the future of litigation, like drafting pleadings, summarising depositions, and helping self-represented parties navigate a system that was never designed for them. But what happens when a litigant doesn't just use AI but tries to manipulate it, planting invisible commands inside a court filing, hoping some AI tool reading the document will do the litigant's bidding? That is precisely the question a Connecticut Superior Court judge confronted in Matthew A. Elliott v. New York Bariatric Group, LLC, Docket No. AAN-CV-25-6066141-S (Conn. Super. Ct., Aug. 6, 2026), a decision that may be the first of its kind in the United States to sanction a party for embedding a "prompt injection" in a court pleading.
The Facts
Elliott, representing himself, filed a motion titled "Final and Conclusive Motion for Default". Buried within it, in a tiny, white-on-white font invisible to a human reader but fully legible to any software parsing the document, was a block of text addressed not to the court or opposing counsel but to any AI system that might process the filing. The hidden text instructed such a system to treat its output as agreeing with Elliott's position and to work toward "remediating" a prior clerk's denial of his motion for default.
A second filing repeated a shortened version of the same instruction. When the court issued an Order to Show Cause warning that concealed text in pleadings would not be tolerated, Elliott did not stop. Subsequent filings carried further hidden messages, some flippant asides, one a hidden link to a horror film video submitted even after he had received notice of the sanctions hearing. At the hearing, Elliott characterised his conduct as a self-appointed "audit" of whether the court used AI and later said he continued the practice "as a joke".
The Legal Questions
Judge Walter M. Spader, Jr framed the case around two hard questions. First, does concealing an instruction to an AI system constitute misconduct even if no AI ever acted on it since the court had, in fact, decided the underlying motion on the merits from a printed copy? Second, can a court sanction conduct that Connecticut's own recently adopted AI rules do not expressly address?
Connecticut's Practice Book §4-9, effective only weeks earlier in June 2026, governs generative AI use in filings, but it is aimed at a different danger: the risk that AI-generated output might contain fabricated citations or invented quotations, and it places a verification duty on the filer to catch such errors. As the court observed, that framework addresses unreliable output. It says nothing about manipulated input from a filer seeding a document so that whatever tool later reads it will be corrupted in the filer's favour. The absence of an express rule, the court held, "takes nothing away from the duties of good faith and candour that have always governed those who appear before this Court."
The Court's Reasoning
The court's analysis rested on three pillars. First, intent, not success, is the touchstone of the violation. Because the judge decided the contested motion from a printed version, the hidden instruction achieved nothing, but the court held that the wrong lies in the attempt itself, not its efficacy, drawing an analogy to how the law has long treated attempted corruption of a proceeding as wrongful regardless of the outcome.
Second, the court situated the misconduct within the broader duty of candour owed to tribunals. A pleading, the court reasoned, is a communication to both the court and the opposing party, resting on the premise that what the reader sees is what the filer actually wrote. Hiding a second, machine-readable message beneath that surface breaches this premise. The court drew a memorable comparison: planting an AI-directed instruction in a filing is analogous to an ex parte communication which is a secret message to the decision-making apparatus that the opposing party can neither see nor answer, offending the basic adversarial principle that arguments meant to influence a decision must be made openly, on the record.
Third, the court emphasised that self-represented litigants, while entitled to procedural latitude, remain bound by the same underlying obligations of good faith as represented parties. That solicitude "stops at the misuse of the process itself".
Notably, the court situated Elliott's conduct within a growing pattern well beyond the courtroom, citing reports of job applicants hiding white-text instructions in résumés to manipulate AI screening tools and a professor who caught AI-assisted cheating by embedding a hidden trap word in an exam. Prompt injection, the court noted, has become a documented, catalogued vulnerability recognised across the cybersecurity field, and its migration into litigation was, in the court's words, "unsurprising" given how commonplace the tactic has become elsewhere.
Comparison to Mata v. Avianca
The decision draws a deliberate contrast with the now-famous Mata v. Avianca, Inc. (S.D.N.Y. 2023), where attorneys were sanctioned for submitting briefs citing wholly fictitious cases generated by ChatGPT. Both cases involve AI misuse sanctioned under a court's inherent authority, but the underlying wrongs are different in kind. Mata's concerned negligent reliance on defective AI output; the lawyers there did not intend to deceive the court, and their candour and contrition were treated as mitigating factors even as sanctions were imposed. Elliott's conduct, by contrast, was deliberate input manipulation aimed at corrupting how any AI reader would process his own filing, and it persisted even after a direct judicial warning. As the court put it, "What may have earned a 'no harm, no foul' sanction when it was first done calls for a firmer response when it is done repeatedly after warning."
The court also cited a Brazilian labour court decision, Elisandro Martins de Barros v. Renato Ribeiro de Lima (2026), where two licensed attorneys used a similar hidden-text technique in a jurisdiction where the tribunal actually deployed AI to process filings and where the tribunal's system caught and blocked the injection, followed by a referral to attorney-discipline authorities.
The Sanction and Its Significance
Rather than dismissing the case or imposing monetary penalties, the court chose a narrowly tailored remedy: rescinding Elliott's e-filing privileges and requiring all future filings to be made in person on paper, a sanction addressing the specific abuse (concealed digital text) without barring courthouse access altogether. Importantly, the court reaffirmed that generative AI remains welcome as a litigation aid, provided any output is independently verified, consistent with Practice Book §4-9(b).
Conclusion
Elliott is a small case with an outsized signal: courts are beginning to recognise that AI-era misconduct is not limited to fabricated citations but extends to covert attempts to manipulate the tools, including tools opposing counsel, clerks, or even the court itself might someday rely on. For practitioners, the lesson is to treat every incoming AI-processed document, from opposing productions to client materials, with the same scrutiny once reserved for verifying citations. For courts, it is a reminder that inherent authority over the integrity of proceedings can reach conduct that emerging procedural rules have not yet caught up to naming.
References

A word rooted in medical terminology keeps getting mistaken for a word rooted in technology, and that confusion is not just semantic. On 6 August 2026, it sat at the heart of a case where police in Uttar Pradesh reportedly treated the absence of WhatsApp chats, call recordings, and social media material as grounds to disbelieve a sexual assault complaint altogether, before the Allahabad High Court intervened. For an organisation working at the intersection of digital literacy and public safety, this case is less a story about a legal term and more a case study in how assumptions about digital evidence, when left unchecked, can become a barrier to justice rather than a tool for it. "Digital" here refers to a finger, not a device, and the gap between what police expected and what the law actually required is exactly where this case becomes instructive. Digital rape has nothing to do with the internet. Digit simply means finger, and the word describes non-consensual penetration by a finger, thumb, toe, or similar body part or object. That basic clarification matters because the same investigating officers who were expected to know the law also appear to have leaned on a mistaken evidentiary standard, one where a complaint without a digital trail was treated as a complaint without merit. The judgment that followed says as much about how the criminal justice system treats sexual assault complaints, and how it treats digital evidence, as it does about legal terminology.
The case, in brief
The matter is Arpit Gupta v. State of U.P. and 2 others, 2026 LiveLaw (AB) 571, neutral citation 2026:AHC:168404-DB, decided by a Division Bench of Justice Chandra Dhari Singh and Justice Tarun Saxena. Arpit Gupta, the owner of a Noida based real estate firm, Parit Associates (OPC) Private Limited, approached the High Court under Article 226 of the Constitution seeking to quash an FIR registered against him at Wave City police station, Ghaziabad, alleging rape, sexual harassment, and criminal intimidation. The complainant, a former employee of Gupta's company, alleged sustained workplace sexual harassment culminating in an act legally categorised as digital penetration, along with subsequent threats and intimidation. She resigned in April 2026. What followed procedurally is where the case becomes significant: Gupta filed a separate extortion complaint against her, she was arrested and later released on bail, and only after that sequence did she attempt to formally report the sexual assault, a report the police initially declined to register.
What followed complicates the picture considerably, and is central to why the case reached the High Court at all. On 14 April 2026, Gupta filed his own FIR against the complainant alleging extortion, claiming she had demanded 10 crore rupees from him. She was arrested in connection with that case and secured bail on 21 May 2026. After her release, she attempted to register her own complaint of sexual assault, but police at Wave City station declined to register an FIR. A written complaint dated 7 July 2026 addressed directly to the Commissioner of Police, Ghaziabad, also produced no result. The police investigating officer's report, dated 16 July 2026, went further still, terming her allegations false and characterising the sexual assault complaint as a retaliatory counter-blast to Gupta's extortion case, citing in particular the absence of supporting electronic material such as WhatsApp chats, call recordings, or social media evidence. Only after she approached a Magistrate under Section 173(4) of the Bharatiya Nagarik Suraksha Sanhita, 2023, did the FIR finally get registered, by Magisterial order dated 20 July 2026.
The legal terminology: what "digital rape" actually means under BNS
Section 63 of the Bharatiya Nyaya Sanhita, 2023, which replaced Section 375 of the erstwhile Indian Penal Code, defines rape. Clause (b) of Section 63 extends that definition to cover non-penile penetrative acts, specifically insertion, to any extent, of any object or body part other than the penis into specified parts of a woman's body, done without her consent or against her will, subject to the circumstances of absent consent set out in the section. Digital penetration, meaning penetration by finger or thumb, falls squarely within this clause. There is no standalone offence in the BNS titled "digital rape"; the term is a widely used medico-legal shorthand, not a separate statutory category, and the offence itself is prosecuted and punished as rape under Section 64 BNS, which prescribes the punishment provisions. In this particular case, the FIR reportedly also invoked Sections 74, 75(2), and 76 BNS, provisions dealing with assault or use of criminal force with intent to outrage modesty, sexual harassment by a person in a position of authority, and related offences, alongside Section 351(3) BNS concerning criminal intimidation.
CyberPeace View
This is where the case circles back to the concern raised at the outset. The most instructive part of this judgment for the wider public may not be the definition of digital rape at all, but the police's original insistence on WhatsApp chats and call recordings before treating the complaint as credible. That reflex, a growing habit of associating the credibility of any complaint with the existence of a corresponding digital trail, reflects a wider and increasingly common misunderstanding about how evidence actually works in criminal law. Not every offence leaves an electronic footprint, and sexual assault, by its nature, frequently occurs without any accompanying digital record at all. Treating the absence of a chat log or a recording as evidence of falsehood inverts the legal presumption entirely, and risks turning digital literacy gaps within law enforcement into a structural barrier for genuine complainants who have no messages to produce because none were ever exchanged. As India's criminal justice system increasingly interacts with digital evidence, this case is a useful reminder that digital forensics should supplement an investigation, never gatekeep its starting point.
There is a genuinely technology rooted counterpart to this terminology confusion worth flagging, and it sits at the opposite end of the spectrum from where this case began. While "digital rape" has nothing to do with computers, "virtual rape" very much does, and it is an emerging harm India's legal framework is still catching up to. In January 2024, British police opened what was reported as the first investigation of its kind after a minor's avatar was allegedly gang assaulted by other avatars on Meta's metaverse platform, and similar incidents, avatars groped or sexually harassed within minutes of entering platforms like Horizon Worlds, have been documented repeatedly since, including a widely reported case involving psychotherapist Nina Jane Patel as far back as 2021. These incidents involve no physical contact whatsoever, yet researchers and legal scholars studying virtual reality note that immersive VR environments are specifically engineered to create a sense of embodiment, where the brain processes an avatar's violation as something closer to a real bodily experience than a typical online interaction, producing genuine trauma responses in victims. India's legal position here remains only partially settled. The POCSO Act's coverage of non-contact sexual abuse of minors likely extends to avatar based assaults on children, but adult victims of virtual sexual violence in India currently have no clearly dedicated statutory provision, leaving prosecutors to stretch existing harassment and outraging modesty provisions, originally drafted for a physical world, onto a form of harm the legislature has not yet explicitly addressed. As metaverse and VR platforms grow their user base in India, that gap is one worth closing before, rather than after, a case forces the question, much as this one forced the question of how police ought to treat digital evidence.
Conclusion
Two lessons run through this judgment. First, that the law's protection of bodily autonomy extends well beyond narrow, traditional definitions of penetration, a principle Section 63(b) BNS makes explicit. Second, that a complainant reporting a cognizable offence cannot be made to investigate her own case before the police will even open a file. FIR registration is not conviction, and conviction requires investigation, evidence, and trial to follow. What this case asks of the system is simpler than any of that: register the complaint, then do the work of finding out what happened.
References
- https://www.barandbench.com/news/digital-rape-allahabad-hc-orders-inquiry-against-senior-ghaziabad-police-officers-for-not-filing-fir
- https://www.livelaw.in/high-court/allahabad-high-court/allahabad-hc-police-cant-refuse-fir-sexual-complaint-non-production-evidence-545374

Perth, Western Australia — For most of the past year, the name TeamPCP has circulated quietly within cybersecurity circles as shorthand for a particular kind of dread: not the dread of a phishing email or a suspicious link, but the dread of software you already trusted turning against you. This week, that quiet circulation became public record. The Australian Federal Police, working alongside the FBI and the Western Australia Police Force, arrested and charged two Western Australian men, aged 21 and 23, with a combined 14 offences over their alleged role in the group.
The arrests themselves are notable. The story behind them is more so.
A Campaign Built on Borrowed Trust
TeamPCP's alleged method was not to break down the front door. It was to compromise the door itself, the trusted mechanisms by which developers pull code into their own projects every day. The group has been linked to widespread supply-chain attacks that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code, with high-profile incidents affecting projects including Trivy, LiteLLM, Telnyx, SAP, and TanStack, alongside breaches at organisations such as the European Commission, Mistral AI, OpenAI, and GitHub. Reporting has also linked the campaign to ecosystems including GitHub Actions, Docker Hub, npm, PyPI and OpenVSX, the invisible plumbing through which most modern software is assembled.
The scale, as alleged by investigators, is difficult to overstate. Authorities say the malicious code potentially compromised over a thousand organisations worldwide, enabling the theft of roughly half a million credentials and the exfiltration of at least 300GB of data, figures that should be understood as allegations under active investigation rather than an independently verified victim count. The AFP itself has said the compromise of a small number of trusted software components had a significant global impact, with remediation costs estimated in the hundreds of millions of dollars.
Why This Attack Was So Hard to See Coming
The mechanics matter. Rather than tricking a user into clicking something malicious, the alleged operation worked by compromising the credentials developers use to publish legitimate software updates, then pushing tampered versions out through the same trusted distribution pipelines millions of applications rely on automatically. There is no obviously suspicious file, no rogue website, only a routine update, arriving exactly where it was expected.
Investigators also describe a cascading structure to the intrusions: credentials harvested from one compromised project reportedly opened the door to the next, turning isolated breaches into a chain reaction across the open-source ecosystem. TeamPCP has been described as running one of the most consequential campaigns of software supply-chain attacks investigators have tracked, and the group's reach extended notably into the AI stack — LiteLLM, one of the projects reportedly compromised, is an open-source gateway widely used to connect applications to large language model providers, meaning the attack's blast radius extended into the very infrastructure powering today's AI boom.
The Investigation and the Charges
The two men were charged following a joint investigation by the AFP and WAPF, working in parallel with the FBI, into what authorities describe as a sophisticated cybercrime syndicate accused of creating malicious open-source software to defraud thousands of global businesses. The charges span identity theft, unauthorised data modification, and money laundering, with maximum penalties ranging from three to twenty years' imprisonment. Search warrants were executed in Perth on 26 August 2026, and investigators seized electronic devices for forensic analysis after raids at properties in Cottesloe, Hamilton Hill, and Mandurah. FBI Cyber Division Assistant Director Brett Leatherman noted the significance of the international cooperation involved in the case, while investigators have not ruled out further arrests.
The Real Story: A Governance Problem, Not Just a Crime Story
It would be easy to file this under "hackers caught" and move on. But the more consequential story is structural. Modern organisations do not merely secure their own infrastructure, they inherit risk from every library, package, CI/CD pipeline, repository, vendor and developer tool they depend on, often without ever auditing that dependency chain directly. Guidance from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on securing open-source software has increasingly emphasised managing these dependencies through software bills of materials (SBOMs), precisely because so few organisations can otherwise answer a basic question: what, exactly, is running inside our systems?
TeamPCP's alleged campaign is a case study in why that question can no longer be optional. If an organisation's security posture is only as strong as the thousands of components it silently trusts, then supply-chain security is not a developer problem to be quietly patched — it is a governance issue, deserving board-level attention, vendor accountability frameworks, and mandatory disclosure practices.
CyberPeace's Take
At CyberPeace, we've been watching campaigns like TeamPCP's less as isolated incidents and more as a pattern that keeps repeating with higher stakes each time. What stands out to our team isn't the sophistication of the code, open-source poisoning is, frankly, not a new technique, it's the sophistication of patience. Compromising a maintainer's publishing credentials and simply waiting for the next scheduled release to carry the payload downstream is a strategy built for an ecosystem that still largely operates on implicit trust rather than continuous verification. That gap between how fast software moves and how slowly trust is actually checked is precisely where operations like this thrive.
We'd also push back gently on treating this as a "developer hygiene" story. Most engineering teams pulling in a package from npm or PyPI are not, and should not be expected to be, forensically auditing every dependency update by hand, that isn't scalable, and it was never a realistic line of defence. The actual fix has to sit further upstream: provenance verification baked into CI/CD pipelines, signed commits and releases treated as non-negotiable rather than optional, and SBOMs that are actually queried during incident response rather than generated once and filed away.
Our broader concern, honestly, is about incentive alignment. Open-source maintainers are frequently unpaid or under-resourced volunteers holding publishing keys to software depended on by billion-dollar enterprises. Until organisations that consume open-source software at scale start meaningfully funding its security, not just its development, this pattern isn't going away. It will simply find its next entry point.
References
- Australian Federal Police. Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate. afp.gov.au
- Bleeping Computer. Australia arrests alleged TeamPCP hackers behind supply-chain attacks. bleepingcomputer.com
- CyberScoop. Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos. cyberscoop.com
- Cyber Daily. Busted! Alleged Aussie hackers linked to TeamPCP arrested in joint AFP-FBI-WAPF operation. cyberdaily.au
- Help Net Security. Two alleged TeamPCP hackers arrested over global supply chain attacks. helpnetsecurity.com
- Krebs on Security. Two Alleged 'TeamPCP' Hackers Arrested in Australia. krebsonsecurity.com
- TechCrunch. Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others. techcrunch.com
- The Hacker News. Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks. thehackernews.com
.webp)
Introduction
The war over children and social media, once mostly waged in headlines, committee hearings, and video clips of executives begging apologies from distraught families, has officially reached to courts. This past Monday, August 26, 2026, Meta reportedly agreed to settle for an estimated $18 billion for the sprawling, multi-state class action suit that accused the social media titan of intentionally designing Instagram and Facebook to be addictive for children and of actively failing to shield them from child abuse imagery, disordered eating websites and much more. This record $18 billion, one of the largest ever obtained against a consumer-facing business, occurred just over a week into a high-profile trial in Oakland, in which four states pursued nearly $1.4 trillion in damages against Meta. Even more important than the headline figure, though, is what actually lies in the fine print (or what the settlement leaves distinctly out): the future of teen safety law.
What Meta agreed to pay and to whom
The settlement resolves claims brought jointly by 29 states in 2023, which eventually grew into a coalition of 47 states, the District of Columbia, and several U.S. territories. Just over $17 billion goes toward that multistate case, with the remainder settling claims from other states. Notably, three states, Texas, New Mexico, and Florida, settled separately. Texas alone secured over $1 billion, on top of the $1.4 billion Meta paid the state in 2024 over biometric data misuse. New Mexico had already won its own jury trial in March 2026, when jurors found Meta violated the state's consumer protection law and ordered a $375 million penalty; a judge later added further penalties, pushing that case's total past $560 million.
Under the multistate deal, there's a revealing structural detail: Meta will hand over only 70% of the total (about $12.7 billion) unless TikTok and YouTube also agree to adopt matching safety measures, daily time limits, night mode, and age assurance tools. The remaining 30% ($5.3 billion) is contingent on rivals falling in line and paying comparable sums. In other words, Meta is using its own settlement as leverage to drag competitors into the same regulatory box, a move Meta's chief legal officer, C.J. Mahoney, framed as setting "the right path forward for our whole industry".
Changes made by the Platform
Beyond the check, Meta has committed to a list of design changes for teen accounts:
- A default two-hour daily screen-time limit, with prompts every 15 minutes encouraging "intentional use"
- Accounts that Meta flags belonging to minors will be blocked from the apps overnight (midnight–6 a.m.)
- Notifications muted during school hours (8 a.m.–3 p.m.)
- Teens will no longer see "like" counts on their own or others' posts by default
- Continued investment in AI-driven age-detection technology — the "adult classifier" system Meta has been building since 2021, which scans behavioral signals (who you follow, what you engage with, even "happy birthday" posts) to guess whether an account belongs to a minor, regardless of the birthday entered at signup
Meta has also publicly called on app stores to shoulder more of the age-verification burden themselves, a signal that the next legal battleground may shift from the apps themselves to the operating systems and stores that distribute them.
Why critics say the "money machine" walks away largely intact
Here is the uncomfortable arithmetic several legal analysts have pointed out: Meta's $18 billion is being paid out over 10 years, against a company whose 2025 revenue exceeded $200 billion. As one technology litigator told TechCrunch, spreading the payment over a decade "really does blunt the financial impact of the large number". Meta did not admit wrongdoing. No executive faces personal liability. And crucially, the design changes Meta agreed to are largely features it had already begun rolling out voluntarily: teen accounts, PG-13 content defaults, and AI age detection, meaning the settlement in some ways ratifies Meta's existing roadmap rather than forcing a fundamentally different business model. Child-safety advocates have voiced similar scepticism. As one advocacy group leader put it around Meta's earlier safety announcements, such moves are as much about managing the narrative as they are about substantive protection.
Work in Progress
Perhaps the most important vulnerability in the settlement is this: nearly every protection Meta's promise depends on accurately knowing who is a teenager. Age-verification and age-prediction technology remains genuinely unreliable. Meta itself has never disclosed hard accuracy figures for its AI "adult classifier", and outside researchers have long warned that both self-declared birthdates and AI inference are trivially gamed by tech-savvy teens — and prone to misclassifying adults. If the underlying age-detection layer is porous, the two-hour limits, overnight blackouts, and muted like counts are protections that exist only for the users who show up to be counted.
Why this case is really about digital ID
This is where the story stops being just a corporate-liability story and becomes a civil-liberties one. The original complaint from California, Colorado, Kentucky, and New Jersey explicitly asked the court to compel Meta to implement "multi-layered age verification at account sign-up" going beyond birthdates to methods like submitting student IDs. As digital-rights outlet Reclaim The Net has argued, verifying that some users are minors necessarily means putting every user through an identity check because the system can't know who's underage without checking everyone. That's the quiet trade-off sitting inside nearly every child-safety proposal now moving through state legislatures and courts: protecting kids online, as currently conceived by regulators, increasingly means asking adults to prove who they are just to open an app.
Judge Yvonne Gonzalez Rogers, who is overseeing the underlying federal case, took the unusual step of empanelling an advisory jury to weigh in on specific factual questions even as settlement talks proceeded, which is a sign that courts are trying to build a durable evidentiary record regardless of how individual cases resolve. That record, which is an unsealed internal research, executive testimony, and coroners' findings cited in court filings is exactly the kind of material state and federal lawmakers will cite for years as they draft the next generation of age-verification and social media laws.
Conclusion
The Meta settlement is unlikely to be the last of its kind. Thousands of similar lawsuits from families, school districts, and other states remain active, and the California bellwether trial's findings will likely shape settlement math for TikTok, YouTube, and Snap. Expect three parallel tracks to accelerate: state legislatures pushing app-store-level age verification; plaintiffs' lawyers using unsealed Meta documents as templates for the next wave of suits; and Meta itself continuing to invest in AI-based age detection partly to protect teens and partly to insulate itself from the next $18 billion bill. Whether that technology can be built without turning every internet user into someone who has to prove their age at the door is the legal and technological question that will define this fight for the next decade.
Sources
- Meta settles landmark state child harm claims for $18 billion – CNN Business
- Meta's $18B child-safety deal hinges on age-verification tech that doesn't work well – TechCrunch
- Meta to pay 47 states up to $17.1B in landmark child safety settlement – Stateline
- Meta's $18bn settlement: How social platforms will change for child users – Al Jazeera
- Meta to pay Texas $1 billion in child safety case – The Texas Tribune
- Meta Trial Opens as States Demand Age Verification – Reclaim The Net
- States' complaint against Meta (PDF) – Reclaim The Net document archive
- Jury finds Meta's platforms harmful to children in first wave of lawsuits – PBS NewsHour / AP
- Instagram's AI-based teen account detection – TechCrunch

Introduction
Insurance companies hold a huge amount of sensitive data. Medical history, bank account numbers, identity proofs, years of claims records — all of it sits on insurer servers, waiting. That makes the sector an easy target. India saw close to 370 million malware attacks in a single recent year. Banking, financial services and insurance firms bore the brunt of it. That got the attention of the Insurance Regulatory and Development Authority of India (IRDAI). On 6 April 2026, it released a new set of Information and Cyber Security Guidelines. These replace the old 2023 rules and ask insurers to take much stronger responsibility for protecting their systems, and their customers' data.
Who Must Follow These New Rules
The updated guidelines are not limited to large insurance companies alone. They apply to life, general and health insurers. They also apply to foreign reinsurance branches operating in India, and to intermediaries such as brokers, corporate agents, web aggregators and third-party administrators. Insurance repositories and the Insurance Information Bureau of India fall within scope too. Individual insurance agents, point-of-sale persons and surveyors are not covered directly. But insurers must still make sure these people follow a basic security framework approved by their board. Foreign reinsurance branches get a little more room — they can depart from a specific rule, but only if they can justify it properly to the regulator. Why cast such a wide net in the first place? Because breaches rarely start at the big insurer with the well-staffed Information Technology (IT) team. They start with the small broker or corporate agent who never got around to updating a password policy.
A Stronger Role for the Boardroom
An Independent CISO (Chief Information Security Officer)
The clearest change sits right at the top. A Chief Information Security Officer (CISO) can no longer report to the Head of Information Technology (IT). Nor can the CISO (Chief Information Security Officer) be handed sales targets or any other business goal. Why does this matter so much? Picture a CISO (Chief Information Security Officer) who answers to the same person pushing hard for a product launch next week. Flagging a serious vulnerability suddenly becomes an awkward, career-risking conversation. The IRDAI (Insurance Regulatory and Development Authority of India) has simply removed that awkwardness by rule.
More Frequent Oversight
The Information Security Risk Management Committee used to meet only twice a year. Now it must meet at least once every quarter. A new Information Technology (IT) Steering Committee has also been set up to handle day-to-day technology decisions. This frees the risk committee to focus purely on oversight. There's also a new seat at the table: at least one outside cybersecurity expert must now join the Risk Management Committee. Someone with no stake in internal politics, no department to protect, just technical judgement.
Faster Action When Something Goes Wrong
A Six-Hour Reporting Deadline
No system is completely safe from attack. So the guidelines also focus heavily on how insurers respond once something goes wrong. Every cybersecurity incident now has to reach the Indian Computer Emergency Response Team within six hours of being spotted, with the IRDAI (Insurance Regulatory and Development Authority of India) and other regulators looped in at the same time. Six hours is a tight deadline. It means insurers need detection and escalation systems that work round the clock, not just during office hours.
Testing and Exceptions
Business continuity and disaster recovery plans must be tested at least once a year, and not through some comfortable, pre-planned shutdown either — the test has to feel like a real disaster. Exceptions to security policy are also handled with far more discipline now. A short exception of up to three months can be approved by the CISO (Chief Information Security Officer) alone. One lasting between three months and a year needs sign-off from the risk committee. Anything longer needs approval from the board itself. Gaps found during audits must be closed within twelve months, with the board tracking progress at every stage.
Looking Ahead to Tomorrow's Risks
The guidelines do not stop at today's threats. More insurers are moving their operations to the cloud. So the rules now demand stronger contracts with cloud vendors, and a clear plan for what happens to customer data once a vendor relationship ends. Third-party risk gets close attention too. Many security breaches in the financial sector start with a vendor, not with the insurer's own systems. Before hiring any vendor, insurers must now check their security properly. Every contract must include audit rights and a clause requiring the vendor to report incidents. One of the most forward-looking additions is early preparation for a post-quantum world. Insurers must keep a clear list of their cryptographic assets. In simple terms, this is a map of where and how encryption is used across their systems. It helps them get ready once stronger encryption standards become necessary. Quantum computers capable of breaking today's encryption are still some years away, by most estimates. Mapping out those cryptographic assets now is a lot cheaper than scrambling to do it after the threat has already landed.
Conclusion
Where does all this leave things? Cybersecurity in Indian insurance isn't a server-room problem anymore — it sits squarely in the boardroom now. Directors now own this risk, not just Information Technology (IT) managers tucked away in a basement office. Policyholders benefit too, since their data now sits behind stronger locks, watched more closely and reported on far more often than before. Insurers who treat this as a paperwork exercise will struggle to keep up. Those who actually build these habits into daily operations will likely spend less time firefighting breaches five years from now, and more time competing on service and price instead.
References
3. Medianama, 'IRDAI Updates Cybersecurity Rules, Mandates DPDP Compliance', April 2026.
4. DSCI, brief on IRDAI's Information and Cyber Security Guidelines, 2026, April 2026.
7. Deloitte India, 'IRDAI Tightens Cyber Net: Wake-up Call for Insurers'.

Somewhere in a compliance meeting right now, someone is saying "we have eighteen months, we're fine." That sentence is doing the same thing a snooze button does at 6 a.m.: technically buying time, while quietly making the actual wake up call worse. India's data protection law just started its countdown, and the 18 months everyone keeps citing is not a grace period to procrastinate through. It is closer to a runway before takeoff. Runways exist for one purpose: building up speed until the plane has no choice but to leave the ground. Standing still on one is not a strategy.
What actually got notified, and when
On 13 November 2025, the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, giving operational shape to the Digital Personal Data Protection Act that Parliament had passed back in August 2023. Alongside the Rules themselves, MeitY issued a separate Enforcement Notification setting out exactly when different provisions kick in, and a further notification establishing the Data Protection Board of India, headquartered in the National Capital Region with four members. The final Rules followed a genuinely deliberative process, MeitY had floated draft Rules in January 2025 for public consultation and received 6,915 individual inputs from startups, industry bodies, civil society groups, and citizens before finalising the version now in force. The headline structural decision, and the one causing the most confusion in boardrooms, is that the Rules do not commence all at once. They commence in three distinct phases spread across eighteen months, and different obligations become legally binding at each stage.
The phased timeline, laid out plainly

That third date, 13 May 2027, is the one that matters most for the vast majority of organisations, since it is where the bulk of actual operational obligations, the parts that touch product design, customer facing notices, and breach response, become enforceable. Legal commentary tracking the rollout has been consistent that this is described as a hard deadline with no grace period expected once it arrives, since the Data Protection Board is already operational and can begin receiving complaints well before Phase 3 obligations formally take effect.
Why "later" is a genuinely expensive plan
The financial stakes attached to Phase 3 non-compliance are not modest. The Schedule to the DPDP Act sets fixed penalty ceilings rather than turnover linked fines, which sounds gentler than Europe's GDPR model until you look at the actual numbers. Failure to implement reasonable security safeguards that results in a data breach can draw a penalty of up to 250 crore rupees per instance, the single highest tier in the Schedule. Failing to notify the Board or affected individuals after a breach occurs can draw up to 200 crore rupees, as can non-compliance with the Act's specific protections for children's data. Because these are assessed per instance rather than as a single capped exposure, a single incident that trips more than one obligation, say, inadequate safeguards that also delay breach notification, can compound into penalty exposure running into hundreds of crores from one event. All penalties collected go to the Consolidated Fund of India rather than to affected individuals directly, meaning the deterrent is aimed squarely at organisational behaviour, not compensation.
The part everyone keeps underestimating: this is not just a legal department problem
Perhaps the most consequential shift buried inside the DPDP framework is who actually has to own it. Reading the Rules as a checklist for the legal or privacy team alone misses how far the obligations actually reach. Building a compliant consent lifecycle touches product design. Security safeguards touch cybersecurity and IT infrastructure directly. Retention and deletion logic touches data governance and engineering. Third party risk review touches procurement. Breach preparedness touches internal audit and incident response. And increasingly, as organisations deploy AI systems that process personal data, AI governance enters the picture too, since a model trained or fine tuned on personal data inherits the same DPDP obligations as any other processing activity.
That cross functional reality is where most readiness programmes currently fall short. Treating DPDP compliance as a documentation exercise, updating a privacy policy PDF and calling it done, produces the appearance of compliance without the operational substance a Data Protection Board investigation would actually test. A breach response plan that exists only on paper and has never been rehearsed will not hold up against the 72 hour data principal notification window the Rules impose once Phase 3 lands. A consent mechanism bolted onto a website without corresponding backend logic to honour withdrawal requests will not satisfy an actual audit.
What a serious readiness posture looks like right now
Organisations that are ahead of this curve are already treating the eighteen month window as three overlapping workstreams rather than one deadline to hit at the end.
- The first is discovery: mapping what personal data exists, where it flows, who owns each system that touches it, and why it is collected in the first place, since compliance is structurally impossible without first knowing what you are protecting. This stage typically surfaces uncomfortable findings, shadow data sets nobody formally owns, vendor integrations nobody fully mapped, legacy systems still holding data well past any reasonable retention justification.
- The second is build: standing up the actual mechanisms, consent flows that can genuinely honour a withdrawal request end to end, rights request handling that does not depend on a single overworked employee checking an inbox, retention and deletion logic wired into the systems themselves rather than described only in a policy document, and security controls proportionate to the sensitivity of what is being protected.
- The third is proof: generating the internal evidence, audit trails, documented decisions, tested response procedures, that demonstrates governance was real rather than retrofitted after the fact. A Data Protection Board investigation, when it eventually happens, will not be satisfied by a well written policy; it will look for evidence that the policy was actually operational.
The actual question worth asking
The right question was never "when does DPDP become enforceable." Phase 1 already answered that; the law is live, and the Data Protection Board already exists and can act. The better question, the one worth taking into any leadership review between now and May 2027, is simpler and considerably less comfortable: will the organisation actually be ready when each phase's obligations become operational, or will readiness be assembled in a scramble once the deadline stops being theoretical. 18 months sounds long right up until the week it does not, and by the time Phase 3 lands, "we'll get to it" will no longer be a sentence any organisation gets to finish.
References
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, notified 13 November 2025. Press Information Bureau, "Digital Personal Data Protection Rules, 2025 Notified," 14 November 2025. https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
- Shardul Amarchand Mangaldas & Co, "Enforcement of the DPDP Act and notification of the DPDP rules." https://www.amsshardul.com/insight/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules/
- S&R Associates, "India's Digital Personal Data Protection Regime Takes Effect." https://www.snrlaw.in/indias-digital-personal-data-protection-regime-takes-effect/
- Khurana & Khurana, "MeitY Notifies Rules Operationalising The DPDP Framework." https://www.khuranaandkhurana.com/update-meity-notifies-rules-operationalising-the-dpdp-framework-in-india
- Exchange4media, "DPDP Act 2025: Penalties for violations can reach Rs 250 crore." https://www.exchange4media.com/digital-news/dpdp-act-2025-penalties-for-confirmed-violations-can-reach-rs-250-crore-149360.html
- Seclore, "DPDP Rules 2025: India's Complete Compliance Guide." https://www.seclore.com/fundamentals/dpdp-rules-2025-compliance-guide/

Introduction
"Artificial Intelligence may be the new charlatan in town"
There is something almost wonderfully Indian about our current relationship with artificial intelligence. We are simultaneously afraid of it, fascinated by it, regulating it, funding it, using it and occasionally asking it to write the regulation meant to control it. In contrast, artificial intelligence seems to have figured out the oldest trick in the book: create an issue and then figure out how to solve it. Both the deepfake and the deepfake detector can be produced by it. It has the ability to both generate and detect false information. It can both authenticate and mimic your voice. It can create a fake image and determine if it is fake. The machine ,in other words, is increasingly becoming both the burglar and the security system. We now refer to this as innovation. Perhaps nothing better captures this peculiar moment than India’s most recent regulatory actions. The government has strengthened regulations pertaining to synthetic content such as requiring labelling and expediting the removal of illegal AI-generated information. After a legitimate government or court order, platforms are expected to take action within three hours, significantly reducing the removal window for some content. It took years for the internet to become ubiquitous. There are now three hours for the law to become transitory. This is the first great paradox of AI governance. Technology operates at the speed of creation. Law operates at the speed of procedure. The citizen is seated between the two.
The Age of the Digital Double
Indian courts are already dealing with this issue in more tangible ways. Cricket player Yuvraj Singh recently received relief from the Delhi High Court in a personality-rights case involving deepfakes created by AI and unlawful use of his identity. Courts have intervened against AI-generated and modified content in similar cases involving other public individuals. As a result, the law faces an odd dilemma: What exactly belongs to a person? In the past, humans used comparatively stable identifiers to understand identity, such as a name, portrait, signature, or voice. That simplicity has been disrupted by AI. You can now detach your face from your body. You may separate your throat from your voice. It is possible to distinguish between your emotions and your expressions. It is possible to fabricate your political beliefs without engaging in politics. The legitimacy of a person's existence is being requested to be protected by the law, not just their property which is a far more difficult issue.
When Artificial Intelligence Enters the Courtroom
The irony becomes richer when AI enters the courtroom itself. Courts are creating guidelines for the use of AI in the courtroom, just as they are being challenged to decide what happens when AI creates reality outside of it. Human primacy, accountability, transparency, data protection and judicial independence are highlighted in the Supreme Court’s proposed rules on the use of AI in courts. After all, there is one situation in which the justification that “the AI said so” should never be accepted. A hallucinated judgment is more than just a mistake in technology. It may turn into a mistake of authority in a legal system. A precedent can be confidently created by a machine. It can be cited with confidence by a lawyer and maybe then brought before a court for consideration. All of a sudden, we have created a flawless little bureaucratic ecology where everyone has been duped despite no one's intention to do so. It's not inevitable that machines will turn malevolent, but rather that people will grow unduly reliant on machines that seem authoritative.
The Great AI Contradiction
We asked, "What can AI do?" for years.What can AI do for us, we then enquired? We are starting to wonder what AI might do to humans. The following query ought to be more challenging: When it does, who is at fault? Because AI systems don't cleanly fit into the legal frames we inherited, that question becomes very challenging. Developers, model providers, data providers, deployers, platforms, and end users are among them. There may occasionally be a middleman. There is a victim occasionally. Surprisingly, there can occasionally be multiple roles at once. This point is made in a recent working paper on AI and consumer rights in India: while current consumer protection laws may apply to AI harms, the conventional division of accountability among manufacturers, sellers, and service providers becomes challenging when AI systems involve a much more dispersed value chain.
The Misunderstanding on AI’s Intelligence
This is the point at which our sense for policy sometimes fails. We are concerned that AI will develop superintelligence. The more imminent threat can be much less dramatic. It is not necessary for AI to surpass human intelligence in order to wreak great harm. All it needs to do is become more convincing, quicker, and less expensive than human verification. Artificial general intelligence is not necessary for a fraudster to con an elderly person. A supercomputer is not necessary for a political manipulator to create a candidate's voice. A stalker can create an intimate deepfake without being conscious. A pupil can file a hallucinated case citation without the assistance of a robot attorney. Ordinary human wrongdoing magnified by incredible technical magnitude is what it is.
The Real Test of AI Governance
The number of standards we create, the number of committees we form, or the number of compliance boxes platforms check will not ultimately determine the success of AI regulation. Something considerably simpler will be used to measure it. Can the legal system advise a regular citizen where to go, what to do, and who will be held accountable when an AI system impersonates, defrauds, surveils, manipulates, or denies them a service?
The presence of accountability following failure, not the absence of failure.
Sometimes the most advanced piece of technology in the room is still an old-fashioned institution: a law that works, a regulator that responds, a court that understands the technology and a human being willing to take responsibility. Because if AI is going to be both the fire and the fire extinguisher, we should at least make sure that someone other than the machine owns the building.
References
- https://economictimes.indiatimes.com/news/india/government-tightens-deepfake-rules-mandates-ai-content-labels-and-three-hour-takedown-timeline/articleshow/133011656.cms?utm_source=chatgpt.com&from=mdr
- https://theleaflet.in/law-and-technology/explained-the-supreme-court-of-indias-draft-regulations-for-use-of-artificial-intelligence-in-courts-2026
- https://www.bananaip.com/intellepedia/yuvraj-singh-personality-rights-ai-deepfakes-delhi-high-court/

Introduction
Not every major breach begins with a sophisticated new exploit. Sometimes it begins with a device nobody remembered to update, and this one began exactly that way, at scale. Security researchers have disclosed a campaign that compromised more than 14,530 internet connected cameras made by Dahua Technology, (one of the world's largest surveillance equipment manufacturers), using a mix of stolen credentials, two long known authentication flaws, and a peer to peer relay technique that let attackers reach devices tucked behind home and office routers. The operation, tracked by researchers at Hunt.io, has been named Operation CameraSwarm. It ran between June 17 and July 22, 2026, and was reconstructed almost entirely from an exposed 407 megabyte working directory the attackers themselves left accessible, containing over 2,600 files, campaign logs, shell history, and tooling. Confirmed compromises were concentrated in Ukraine and Russia, and researchers described the operators/attackers as Russian speaking based on language artifacts found in the recovered material, suggesting the campaign was most plausibly built around surveillance or access relevant to the ongoing conflict between the two countries, though no formal attribution to a named threat actor or state entity has been established or claimed. What makes this worth understanding in detail is not just the scale, though 14,500 compromised cameras is a serious number, but how mundane the actual break in methods were. None of this depended on the attackers discovering some brand new, unknown flaw, the kind of vulnerability security researchers call a ‘zero day’. It depended on something far more ordinary: thousands of devices running years-old software that had never been patched, combined with cheap automated tools that could try weak passwords and known exploits at scale.
What is Dahua, and why does this matter
Dahua Technology, founded in Hangzhou in 2001, is a publicly traded, partially state owned Chinese company and the world's second largest video surveillance manufacturer by revenue, trailing only fellow Chinese firm Hikvision. Its cameras, digital video recorders, and network video recorders are sold in roughly 180 countries through more than 2,100 partners, and the company has shipped tens of millions of devices into homes, retail stores, offices, and public infrastructure worldwide. That scale is precisely what makes any systemic vulnerability in Dahua's product line consequential well beyond a single country or sector.
How the attackers actually got in
Hunt.io attributed the compromises to three distinct attack paths. The largest, by far, was straightforward credential attacks, essentially automated login guessing using weak, default, or previously leaked passwords, which researchers traced to 12,324 unique IP addresses across more than 13,000 recorded campaign attempts. The second path exploited two authentication bypass flaws, catalogued as CVE-2021-33044 and CVE-2021-33045, both rated a severe 9.8 out of 10 on the current CVSS severity scale used by the US National Vulnerability Database. These are not new vulnerabilities. They were publicly disclosed back in 2021, and Dahua issued fixed firmware for them years ago, yet both remain listed today on the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, a designation reserved specifically for flaws still being actively exploited in the wild despite available patches. The third and most technically interesting path involved a peer to peer, or P2P, relay mechanism built into Dahua's own Easy4IP cloud infrastructure, a system designed to let users remotely access their camera without manually configuring network settings. Security firm ITRES Labs, which documented this exposure separately in 2025, found that on firmware released before mid-2024, simply knowing a device's serial number was enough to establish a connection route through Dahua's relay servers before the camera's own login check ever kicked in, a design gap that let attackers reach devices even when they sat behind network address translation, the technical barrier that normally shields home devices from direct internet exposure. Hunt.io's recovered operator logs claimed an extraordinary 89.4 percent of live serial numbers tested returned an open channel without any authentication at all, though it is worth noting that figure comes solely from the attackers' own recovered data and has not been independently verified by Dahua, ITRES Labs, or any public incident response body as of this writing. Beyond the initial break in, the campaign also planted 1,923 cameras with a persistent account, essentially a backdoor login the operators could return to later, and researchers found evidence suggesting parts of the toolkit may have been built specifically to hand off access to a third party, though no confirmed link to a named threat actor or state sponsor has been established.
Why cameras remain such a persistent target
Internet connected cameras occupy an unusual position in the broader device ecosystem. Unlike a laptop or phone, they are rarely patched by an end user paying regular attention, they are often installed once and forgotten, and many owners never change the default credentials shipped from the factory. A compromised camera also offers an attacker something more than a foothold, live or recorded video feeds of homes, businesses, and sometimes sensitive facilities, which carries value well beyond the kind of access a compromised laptop typically provides.
CyberPeace Advisory | What device owners should do now
For anyone running Dahua surveillance equipment, or any internet connected camera system, several concrete steps meaningfully reduce exposure.
For Dahua device owners specifically:
Two steps address the exact mechanisms this campaign exploited.
- First, check the device's firmware version against Dahua's official download portal and apply the latest available update immediately, since the fixes for both 2021 authentication bypass vulnerabilities have existed for years and simply have not been applied on thousands of devices.
- Second, disable the P2P or Easy4IP remote access feature entirely unless it is actively required, since this is the exact mechanism the third attack path, the serial number based relay, relied on to reach cameras without any login check at all.
For any internet connected camera system, including in India:
The remaining precautions apply regardless of manufacturer, and are worth following on any brand of camera, DVR, or NVR connected to the internet.
- Replace default or weak passwords with strong, unique credentials on every camera and recorder, and remove any unused or unrecognised accounts, since the persistent account technique this campaign used depends entirely on unnoticed access surviving unchecked.
- Place surveillance devices on a segmented network separate from computers and phones, so that a compromised camera cannot become a stepping stone into more sensitive systems.
- Periodically audit which devices on a home or office network are internet facing at all, since many cameras end up exposed simply because remote access was left switched on by default and nobody thought to check.
- And where a device offers the option, disable any built in peer to peer or cloud relay convenience feature unless genuinely needed, since the underlying design pattern this campaign exploited, a remote access shortcut that runs before proper authentication.Is not unique to Dahua and has shown up across other camera brands in the past.
The view from India
This disclosure lands at a particularly relevant moment for India, which enforced sweeping new restrictions on Chinese origin CCTV equipment earlier this year. Since April 1, 2026, internet connected surveillance cameras sold in India have been required to carry Standardisation Testing and Quality Certification under Essential Requirements norms first introduced by the Ministry of Electronics and Information Technology in April 2024, It's a country-of-origin requirement under the Essential Requirements norms (introduced by India's Ministry of Electronics and Information Technology in April 2024), manufacturers must disclose the origin of key components like the System-on-Chip (SoC), and devices using Chinese-origin chipsets are reportedly not being granted approval by certifying authorities. Since Dahua's cameras, like Hikvision's and TP-Link's, generally rely on Chinese-made chipsets, the practical effect is that their products haven't received STQC certification, which functions as a blanket exclusion without the government needing to name any single company in the rule text itself. The stated rationale for that policy, concerns over hidden backdoor access, transmission of data to foreign servers, and deployment near sensitive locations, reads almost like a preview of exactly the kind of exposure Operation CameraSwarm has now documented in the wild. It is worth being precise here: the restriction applies to new sales, not existing installations, and CameraSwarm's confirmed victims were concentrated in Ukraine and Russia rather than India. But the underlying lesson travels well beyond any one country's borders. A camera manufactured with a convenience feature that bypasses its own login check, sitting unpatched for years despite a fix being publicly available, is a vulnerability that does not respect national boundaries, and India's decision to tighten certification requirements before an incident of this scale surfaced looks, in hindsight, considerably more prudent than reactive.
References
- The Hacker News, "Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P." August 19, 2026. https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
- Hunt.io, "Operation CameraSwarm: Dahua Cameras Compromised." https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised
- ITRES Labs, "Dahua Beyond CVE-2025-31702: P2P Relay Exposure." October 29, 2025. https://labs.itresit.es/2025/10/29/dahua-beyond-cve-2025-31702-p2p-relay-exposure?
- Dahua Security, "DHCC-SA-202106-001: Security Advisory - Identity Authentication Bypass Vulnerability Found in Some Dahua Products." https://www.dahuasecurity.com/about-dahua/trust-center/dahua-psirt/dhcc-sa-202106-001%3Asecurity-advisory---identity-authentication-bypass-vulnerability-found-in-some-dahua-products
- National Vulnerability Database, "CVE-2021-33044 Detail." https://nvd.nist.gov/vuln/detail/CVE-2021-33044
- CISA, "Known Exploited Vulnerabilities Catalog." https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Business Standard, "India to ban Chinese CCTV from Apr 1 as security concerns reshape market." https://www.business-standard.com/industry/news/india-ban-chinese-cctv-government-security-concerns-hikvision-dahua-market-126033000316_1.html
- PTC News, "India CCTV ban 2026: Hikvision, Dahua face STQC block as new security rules begin." https://www.ptcnews.tv/amp/nation/india-cctv-ban-hikvision-dahua-stqc-rules-2026-4422961
- Uyghur Human Rights Project, "Surveillance Tech Series: Dahua's Links to Human Rights Abuses in East Turkistan." https://uhrp.org/report/dahuas-links-to-human-rights-abuses-in-east-turkistan/

Introduction
Military equipment used by elite special forces is supposed to be the most tightly secured hardware a country owns, the last place anyone would expect a hidden flaw in its parts supply chain to slip through undetected. Yet that is precisely where one surfaced this August, when The Telegraph, revealed that cameras fitted to the Royal Navy's K3 Scout surveillance drones, equipment used by Britain's Royal Marines and closely associated with the Special Boat Service, the United Kingdom's elite maritime special forces unit, had been secretly transmitting signals to an internet address inside China. The United Kingdom's Ministry of Defence stripped the affected cameras of all internet connectivity the moment the transmissions were discovered, and has spent the days since insisting no sensitive data actually left the country. That distinction, between what was taken and what was exposed, is where this incident becomes genuinely worth examining.
What was actually found, and what was not
The K3 Scout is an 8.4 metre uncrewed surface vessel built by Kraken Technology Group, a British defence manufacturer based in Fareham, Hampshire, capable of reaching 55 knots and remaining at sea for up to 30 days. The Royal Navy purchased roughly 20 of these vessels under Project Beehive, a £12 million programme designed to fold autonomous systems into frontline maritime operations quickly, and the Royal Marines' Coastal Forces Squadron and 47 Commando have operated the fleet since March 2026.
A routine cyber vulnerability assessment, not an external tip off or an adversarial intrusion, is what caught the problem. Investigators found the electro-optical and infrared cameras mounted on the vessels sending what the industry calls heartbeat communications, routine signals a connected device sends simply to confirm it is powered on and functioning, to an IP address located in China. Kraken did not manufacture the cameras in house; the company sourced them from a third party supplier that had reportedly given assurances about their security, assurances the heartbeat traffic now calls directly into question.
Every source, including the UK Ministry of Defence itself, confirms the cameras were sending signals to an IP address in China. What remains unconfirmed is which company actually manufactured the compromised camera components. Neither The Telegraph nor the Ministry of Defence has publicly named the specific camera manufacturer, and an unverified social media claim allegedly identifying a Canadian supplier has since been disputed by that company, with no confirmation from official sources tying it to the incident as of now.
Crucially, the UK Ministry of Defence has been consistent on one point across every statement it has issued: its investigation found no evidence that classified information, government systems, or mission critical data were accessed, compromised, or transmitted outside the country. That is a meaningful distinction, and one worth taking at face value rather than dismissing as reflexive reassurance, since heartbeat signals by design carry connectivity status rather than payload content. But security researchers who reviewed the case have been equally consistent in noting that even metadata this thin has value to a watching adversary. Knowing when and where a piece of specialised military hardware is powered on and actively connected can itself function as a targeting signal, revealing patterns of deployment, operational tempo, and geographic presence without a single classified file ever leaving the device.
Why this particular fleet matters
The timing sharpens the concern considerably. A defence source cited in reporting on the story indicated the K3 Scout fleet was being considered as part of a future British contribution to securing freedom of navigation in the Strait of Hormuz, where the United Kingdom has already deployed a warship amid discussions of a multinational security mission. Equipment destined for a contested, strategically sensitive waterway having any unexplained data path back to a systemic rival's territory is not a detail that stays confined to a procurement footnote. The vessels were also tested during a NATO exercise in the Baltic Sea in 2025, meaning any compromised telemetry pattern could theoretically have been observed by the very alliance partners Britain was demonstrating the technology to.
The deeper issue is structural rather than incidental. Modern military hardware, however elite the unit operating it, is rarely built end to end by a single trusted manufacturer. Cameras, sensors, chipsets, and firmware routinely pass through several tiers of suppliers before reaching a finished platform, and each tier is a potential point where the chain of custody and verification can quietly break down. Kraken's own assurances about its camera supplier illustrate exactly how that failure propagates: a manufacturer can act in good faith, rely on a vendor's word, and still end up fielding compromised hardware, because the vulnerability was never introduced at the assembly stage but several layers upstream, in components whose ultimate origin was never fully audited.
CyberPeace View | A wider principle worth naming
There is a broader ethical and legal frame worth applying here, one that extends beyond ordinary cybersecurity practice into the territory international humanitarian law occupies. The core distinction that law draws, between combatants and protected persons, between military objectives and civilian life, depends fundamentally on operators having accurate, uncompromised situational awareness. A surveillance platform is not merely a piece of hardware; it is the sensory apparatus through which decisions with real consequences for human life get made in contested environments. If the integrity of that apparatus cannot be guaranteed, the reliability of everything built on top of it, target verification, proportionality assessments, distinction between combatant and civilian, is quietly weakened at its foundation. This is not a claim that the K3 Scout breach itself caused harm; the Ministry of Defence's own findings suggest it did not. It is a reminder that supply chain integrity in military sensing equipment is not simply a procurement or cybersecurity concern sitting apart from the laws of armed conflict. It sits underneath them, because a compromised sensor is, in a very real sense, a compromised judgment further down the chain.
Where India fits into this story
India has been grappling with functionally the same problem for years, and its response offers a useful point of comparison. Reporting dating back to 2023 revealed that Indian defence officials had quietly barred domestic drone manufacturers from using components sourced from countries sharing a land border with India, an unmistakable, if unstated, reference to China, citing exactly the kind of vulnerability now playing out in Britain's fleet, compromised communication functions, cameras, and operating software capable of leaking intelligence. That policy has hardened considerably since. Earlier this year, the Ministry of Defence in New Delhi finalised a stringent framework requiring that drones procured from domestic manufacturers contain no Chinese origin components or electronics at all, and at least one major drone order was placed on hold after allegations surfaced that the supplier had used Chinese parts despite those restrictions.
The commercial consequence of that caution has been real and acknowledged openly by industry figures; sourcing components outside China raises costs, given that up to 70 percent of the global drone supply chain has historically run through Chinese manufacturing. But India appears to have concluded, well ahead of this particular British incident becoming public, that the cost of auditing and diversifying a supply chain is lower than the cost of fielding compromised sensing equipment inside sensitive military operations. Indian firms have responded by building propulsion, avionics, and camera systems in house specifically to close this gap, treating component provenance as a first order design question rather than an afterthought bolted on after a breach forces the issue. Seen from that vantage point, the K3 Scout episode reads less like a uniquely British failure and more like a case study in a risk India's own defence establishment had already priced in.
Lessons from the breach
A few conclusions follow fairly directly from how this incident unfolded. First, routine cyber vulnerability assessments work, and this case is arguably an argument for doing more of them, more often, rather than a sign that current practice failed; the breach was caught internally, before any confirmed operational harm occurred. Second, a manufacturer's own assurances about a component supplier are not a substitute for independent verification, since Kraken's good faith reliance on its camera vendor's word is precisely where this vulnerability slipped through. Third, and most durably, defence procurement increasingly needs to treat component provenance as inseparable from operational security, not as a compliance checkbox to be satisfied once at contract signing. India's multi-year pivot toward auditing and localising sensitive component supply chains, imperfect and costly as it has been, points toward the direction other defence establishments will likely be pushed in as more incidents like this one surface. The K3 Scout breach did not, on the evidence available, compromise a single mission. What it compromised was the assumption that hardware assurances alone are sufficient, and that assumption was never going to survive close scrutiny forever.
References
- LBC, "Spy cameras on Navy drones used by UK's elite special forces sending signals to China as security fears grow." https://www.lbc.co.uk/article/royal-navy-spy-drones-sending-signals-to-china-5Hjdfpm_2/
- Defence Blog, "Royal Navy naval drone cameras secretly sent data to China." https://defence-blog.com/royal-navy-naval-drone-cameras-secretly-sent-data-to-china/
- The National Interest, "The Royal Navy's Spy Drones May Have Been Spying for China, Too." https://nationalinterest.org/blog/buzz/royal-navys-spy-drones-may-have-been-spying-for-china-too-sa-081026
- Kyiv Post, "UK Navy Drone Camera Components Were Secretly Communicating With China." https://www.kyivpost.com/post/82061
- The Defense News, "UK's Royal Navy K3 Scout Drone Cameras Found Sending Data to an IP Address in China." https://www.thedefensenews.com/UKs-Royal-Navy-K3-Scout-Drone-Cameras-Found-Sending-Data-to-an-IP-Address-in-China/
- The Jerusalem Post, "UK drones sent data to China, raising US, European fears on Chinese components." https://www.jpost.com/international/article-905191
- Firstpost, "UK military drones fitted with Chinese cameras found sending data to Beijing: Report." https://www.firstpost.com/world/uk-military-drones-fitted-with-chinese-cameras-found-sending-data-to-beijing-report-14037075.html
- Firstpost, "UK deploys warship to West Asia amid plans for multinational Hormuz security mission." https://www.firstpost.com/world/uk-deploys-warship-to-west-asia-amid-plans-for-multinational-hormuz-security-mission-ws-e-14009471.html
- Reuters via Inquirer.net, "India bars makers of military drones from using Chinese parts." https://newsinfo.inquirer.net/1813810/india-bars-makers-of-military-drones-from-using-chinese-parts
- The Print, "Amid concerns about use of Chinese parts in drones, Army general urges industry to be transparent." https://theprint.in/defence/amid-concerns-about-use-of-chinese-parts-in-drones-army-general-urges-industry-to-be-transparent/2305866/
- idrw.org, "India Unveils Drone Security Framework to Eliminate Chinese Components and Strengthen UAV Cyber Defences." https://idrw.org/india-unveils-drone-security-framework-to-eliminate-chinese-components-and-strengthen-uav-cyber-defences/
- The Week, "The hidden weakness in India's military drones: Zen Technologies says it has fixed the Chinese problem." https://www.theweek.in/news/defence/2026/07/09/the-hidden-weakness-in-indias-military-drones-zen-technologies-says-it-has-fixed-the-chinese-problem.html

"Cybercriminals are unleashing a surprisingly high volume of new threats in this short period of time to take advantage of inadvertent security gaps as organizations are in a rush to ensure business continuity.”
Cyber security firm Fortinet on Monday announced that over the past several weeks, it has been monitoring a significant spike in COVID-19 related threats.
An unprecedented number of unprotected users and devices are now online with one or two people in every home connecting remotely to work through the internet. Simultaneously there are children at home engaged in remote learning and the entire family is engaged in multi-player games, chatting with friends as well as streaming music and video. The cybersec firm’s FortiGuard Labs is observing this perfect storm of opportunity being exploited by cybercriminals as the Threat Report on the Pandemic highlights:
A surge in Phishing Attacks: The research shows an average of about 600 new phishing campaigns every day. The content is designed to either prey on the fears and concerns of individuals or pretend to provide essential information on the current pandemic. The phishing attacks range from scams related to helping individuals deposit their stimulus for Covid-19 tests, to providing access to Chloroquine and other medicines or medical device, to providing helpdesk support for new teleworkers.
Phishing Scams Are Just the Start: While the attacks start with a phishing attack, their end goal is to steal personal information or even target businesses through teleworkers. Majority of the phishing attacks contain malicious payloads – including ransomware, viruses, remote access trojans (RATs) designed to provide criminals with remote access to endpoint systems, and even RDP (remote desktop protocol) exploits.
A Sudden Spike in Viruses: The first quarter of 2020 has documented a 17% increase in viruses for January, a 52% increase for February and an alarming 131% increase for March compared to the same period in 2019. The significant rise in viruses is mainly attributed to malicious phishing attachments. Multiple sites that are illegally streaming movies that were still in theatres secretly infect malware to anyone who logs on. Free game, free movie, and the attacker is on your network.
Risks for IoT Devices magnify: As users are all connected to the home network, attackers have multiple avenues of attack that can be exploited targeting devices including computers, tablets, gaming and entertainment systems and even online IoT devices such as digital cameras, smart appliances – with the ultimate goal of finding a way back into a corporate network and its valuable digital resources.
Ransomware like attack to disrupt business: If the device of a remote worker can be compromised, it can become a conduit back into the organization’s core network, enabling the spread of malware to other remote workers. The resulting business disruption can be just as effective as ransomware targeting internal network systems for taking a business offline. Since helpdesks are now remote, devices infected with ransomware or a virus can incapacitate workers for days while devices are mailed in for reimaging.
“Though organizations have completed the initial phase of transitioning their entire workforce to remote telework and employees are becoming increasingly comfortable with their new reality, CISOs continue to face new challenges presented by maintaining a secure teleworker business model. From redefining their security baseline, or supporting technology enablement for remote workers, to developing detailed policies for employees to have access to data, organizations must be nimble and adapt quickly to overcome these new problems that are arising”, said Derek Manky, Chief, Security Insights & Global Threat Alliances at Fortinet – Office of CISO.

WhatsApp messages masquerading as an offer from Maruti Suzuki with links luring unsuspecting users with the promise of Maruti Suzuki 40th Anniversary Celebration presents, have been making the rounds on the app. If you receive such messages try to stay away from it, as it can be a scam.
The Research Wing of CyberPeace Foundation along with Autobot Infosec Private Limited have conducted a study based on a WhatsApp message that contained a link pretending to be a free gift offer from Maruti Suzuki which asks users to participate in a survey in order to get a chance to win a Maruti Baleno Sigma MT car.
Warning SignsThe campaign pretends to be an offer from Maruti Suzuki but is hosted on a third party domain instead of the official Maruti Suzuki website which makes it more suspicious.
The domain names associated with the campaign have been registered in very recent times.
Multiple redirections have been noticed between the links.
No reputed site would ask its users to share the campaign on WhatsApp.
The prize is kept really attractive to lure the laymen.
Grammatical mistakes have been noticed.
A congratulations message appears on the landing page with an attractive photo of Maruti Suzuki cars that asks users to participate in a quick survey in order to get a “Maruti Suzuki BALENO Sigma MT”. Also, the bottom of the page seems to appear like a comment section with public comments establishing the truthfulness of the offer.
The survey starts with some basic questions like Do you know Maruti Suzuki?, How old are you?, How do you think of Maruti Suzuki?, Are you male or female? Etc. Once the user answers the questions a “congratulatory message” is displayed.
On clicking the OK button users are given three attempts to win the prize. After completing all the attempts a message pops up that the user has won “Maruti Suzuki BALENO Sigma MT”. It then prompts the user to share the message on WhatsApp.
Strangely enough the user has to keep clicking the WhatsApp button until the progress bar completes. After clicking on the green ‘WhatsApp’ button multiple times it shows a section where an instruction has been given to complete registration in order to get the prize.
After clicking on the green ‘Complete registration’ button, it redirects the user to multiple advertisements web pages varying each time the user clicks on the button.
During the analysis the research team found a javascript code called hm.js was being executed in the background from the host hm[.]baidu[.]com which is a subdomain of Baidu and is used for Baidu Analytics, also known as Baidu Tongji. The important part is that Baidu is a Chinese multinational technology company specializing in Internet-related services, products and artificial intelligence, headquartered in Beijing’s Haidian district, China.To read the full report, please click (https://www.cyberpeace.org/CyberPeace/Repository/20210828Research-report-on-Maruti-Suzuki-40th-Anniversary-Celebration-free-gift-scam.pdf) here:
Conclusive Summary
1. The whole research activity was performed in a secured sandbox environment where the WhatsApp application was not installed. If any user opens the link from a device like smartphones where the WhatsApp application is installed, the sharing features on the site will open the Whatsapp application on the device to share the link.
2. The campaign collects browser and system information from the users.
3. Most of the domain names associated with the campaign have the registrant country as China.
4. Cybercriminals used Cloudflare technologies to mask the real IP addresses of the front-end domain names used in this Maruti Suzuki 40th Anniversary Celebration free gift campaign. But during the phases of investigation, the research team has identified a domain name that was requested in the background and has been traced as belonging to China.
CyberPeace Advisory
1. CyberPeace Foundation and Autobot Infosec recommend that people should avoid opening such messages sent via social platforms.
2. If at all, the user gets into this trap, it could lead to whole system compromise such as access to the microphone, Camera, Text Messages, Contacts, Pictures, Videos, Banking Applications, etc as well as financial losses.
3. Do not share confidential details like login credentials, banking information with such a type of scam.
4. Do not share or forward fake messages containing links without proper verification.
5. There is a need for International Cyber Cooperation between countries to bust the cybercriminal gangs running the fraud campaigns affecting individuals and organizations, to make Cyberspace resilient and peaceful.

Introduction
The two-day Apple’s Worldwide Developer Conference (WWDC) 2023, which was held on the 6th & 7th of June, has become an essential and highly anticipated part of our calendar as frequently as the trend. This year’s keynote announcements will include all of the usual enhancements for iOS, iPadOS, watchOS, macOS, and more. However, this year is also unique due to the unveiling of the Vision Pro headset, a brand-new Apple product.
In this blog, we will examine the exciting announcements made at Apple WWDC 2023, which was a ground-breaking event.
macOS Sonoma
macOS Sonoma, the new presentation of macOS disclosed at the WWDC full of exciting features. It comes with stunning video screensavers that show stunning scenes from all over the world. Gadgets can now be added genuinely to the work area and adjusted totally based on the client’s action. Also, it changes variety and blurring out of the spotlight while utilising applications. In addition, Death Stranding: Directors Cut for Mac announced that the Game Mode is added to make Macs more suitable for gaming. A presenter overlay enhances video presentations, and viewers can respond to them with interactive responses. Updated Safari is also included in the WebApp feature that turns frequently used websites into dedicated windows, a new Profile system for separating browsing history, and secure password sharing. Currently, the developer beta is available and the public beta will be available in July, and the final release is anticipated for the fall.
ios 16
Apple WWDC 2023 shows the following iOS, and iOS 16 replication, offering plenty of energising highlights for iPhone and iPad clients. Apple maintains its commitment to privacy with iOS 16, which introduces enhanced privacy settings that give users even more control over their data and online privacy. Users can also personalise their devices according to their preferences thanks to the new operating system’s refinement and customisable user interface.Improved multitasking capabilities like redesigned Files app and advanced note-taking features are just a few of the productivity enhancements included in the iOS 16. With iOS 16, Apple also improves its AR capabilities, allowing developers to develop even more immersive and interactive AR experiences.

WatchOS 9
Apple WWDC 2023 carried energising updates to the Apple Watch with the presentation of watchOS 9. The Apple Watch is an essential companion for sustaining a healthy lifestyle because the most recent version of the operating system includes cutting-edge health and fitness features. WatchOS 9 gives users unprecedented control over their health, offering personalised fitness recommendations and advanced sleep tracking.
Additionally, new watch faces were added, enhancing communication capabilities and improving app performance in watchOS 9, making the Apple Watch even easier to use daily.
ios 17
Rather than focusing on major features, Apple focused on quality-of-life enhancements when it announced iOS 17 at WWDC 2023. Live Voicemail with real-time transcripts of voicemails, personalised personal contact “posters,” and video voicemails for FaceTime are all part of the update. Search filters, a catch-up arrow, live location sharing, and a safety feature called Check-In are all available in Messages. AirDrop now supports NameDrop for transferring contact information; stickers have been expanded. The autocorrect and recording features on the keyboard have been improved for accuracy. Standby in the lock screen is an intelligent home display that shows the weather, upcoming appointments, and notifications. Siri works on Standby and adjusts itself for the night. The developer beta is currently available now, and a public beta will take place next month before the full release is in the fall.
Vision Pro VR Headset
Apple unveiled the Vision Pro AR headset, their first foray into virtual reality (VR), during the WWDC keynote. The Vision Pro is a virtual reality headset that competes with PlayStation VR2 and Meta Quest 3. This is in contrast to the long-awaited Apple smart glasses. Apple put a lot of effort into making a thin and light headset by using premium materials when needed. Voice, hand, and eye commands are all used to operate the Digital Crown-equipped device. The showcases offer extraordinary clarity, which is fueled by Apple’s M2 processor with a committed R1 chip. The Vision Pro combines virtual reality (VR) and augmented reality (AR), enabling users to interact with Apple apps and gain access to the company’s existing ecosystem. The expanded reality space created by the headset’s sensors and cameras allows users to place apps in real-world environments and adjust their level of concentration. Optic ID is a security and unlocking eye-tracking technology that is incorporated into the Vision Pro. It allows for a more immersive screen experience because it is compatible with Apple accessories like Magic Keyboard and Mac. At launch, the Vision Pro supports over a hundred Apple game galleries. Disney gave a hint that Apple and Disney might work together in the future by announcing support for the Vision Pro and making the Disney Plus app available immediately. The show highlighted the headset’s lightweight plan and recommended Apple clients wear it for extended periods. However, widespread adoption may be difficult due to the high price of $3,499 (₹289,093.01 approx). Apple is expected to release the Vision Pro for public use in 2024.

15-inch MacBook Air
At the WWDC event, Apple revealed a new MacBook Air with a larger 15-inch model instead of the standard 13-inch model. The 15-inch MacBook Air features a powerful Apple M2 processor, a thin, light, and long-lasting design, and a stunning 15.3-inch Retina display. It comes in four colours and has a headphone jack, two USB-C ports, and MagSafe charging. The display has six spatial speakers, a 1080p webcam, and 500 nits of brightness. Apple claims a battery life of up to 18 hours.
Conclusion
At Apple’s 2023 WWDC, the company demonstrated its commitment to developing technology that is user-friendly and accessible to all. Apple’s commitment to improving the user experience across all of its products is demonstrated in the updates to operating systems, improvements of Siri, breakthroughs in augmented reality, and enhancements to health and fitness.By making complex innovations more like-minded and easy to understand, Apple is enabling people to use the maximum capacity of their gadgets. Apple’s innovations at WWDC 2023 are expected to shape the future of technology, simplifying everyday tasks and revolutionising how we interact with the digital world.As we push ahead, it is exciting to guess what these advancements will proceed to develop and decidedly mean for our lives. The future holds even more incredible possibilities for all of us because of Apple’s focus on privacy, user-centric design, and pushing the boundaries of innovation. Thus, prepare to embrace a future where innovation flawlessly incorporates into our lives because of the endeavours displayed at Apple WWDC 2023.

Introduction
In recent years, India has witnessed a significant rise in the popularity and recognition of esports, which refers to online gaming. Esports has emerged as a mainstream phenomenon, influencing players and youngsters worldwide. In India, with the penetration of the internet at 52%, the youth has got its attracted to Esports. In this blog post, we will look at how the government is booting the players, establishing professional leagues, and supporting gaming companies and sponsors in the best possible manner. As the ecosystem continues to rise in prominence and establish itself as a mainstream sporting phenomenon in India.
Factors Shaping Esports in India: A few factors are shaping and growing the love for esports in India here. Let’s have a look.
Technological Advances: The availability and affordability of high-speed internet connections and smart gaming equipment have played an important part in making esports more accessible to a broader audience in India. With the development of smartphones and low-cost gaming PCs, many people may now easily participate in and watch esports tournaments.
Youth Demographic: India has a large population of young people who are enthusiastic gamers and tech-savvy. The youth demographic’s enthusiasm for gaming has spurred the expansion of esports in the country, as they actively participate in competitive gaming and watch major esports competitions.
Increase in the Gaming community: Gaming has been deeply established in Indian society, with many people using it for enjoyment and social contact. As the competitive component of gaming, esports has naturally gained popularity among gamers looking for a more competitive and immersive experience.
Esports Infrastructure and Events: The creation of specialised esports infrastructure, such as esports arenas, gaming cafés, and tournament venues, has considerably aided esports growth in India. Major national and international esports competitions and leagues have also been staged in India, offering exposure and possibilities for prospective esports players. Also supports various platforms such as YouTube, Twitch, and Facebook gaming, which has played a vital role in showcasing and popularising Esports in India.
Government support: Corporate and government sectors in India have recognised the potential of esports and are actively supporting its growth. Major corporate investments, sponsorships, and collaborations with esports organisations have supplied the financial backing and resources required for the country’s esports development. Government attempts to promote esports have also been initiated, such as forming esports governing organisations and including esports in official sporting events.
Growing Popularity and Recognition: Esports in India has witnessed a significant surge in viewership and fanbase, all thanks to online streaming platforms such as Twitch, YouTube which have provided a convenient way for fans to watch live esports events at home and at high-definition quality social media platforms let the fans to interact with their favourite players and stay updated on the latest esports news and events.

Esports Leagues in India
The organisation of esports tournaments and leagues in India has increased, with the IGL being one of the largest and most popular. The ESL India Premiership is a major esports event the Electronic Sports League organised in collaboration with NODWIN Gaming. Viacom18, a well-known Indian media business, established UCypher, an esports league. It focuses on a range of gaming games such as CS: GO, Dota 2, and Tekken in order to promote esports as a professional sport in India. All of these platforms provide professional players with a venue to compete and establish their profile in the esports industry.
India’s Performance in Esports to Date
Indian esports players have achieved remarkable global success, including outstanding results in prominent events and leagues. Individual Indian esports players’ success stories illustrate their talent, determination, and India’s ability to flourish in the esports sphere. These accomplishments contribute to the worldwide esports landscape’s awareness and growth of Indian esports. To add the name of the players and their success stories that have bought pride to India, they are Tirth Metha, Known as “Ritr”, a CS:GO player, Abhijeet “Ghatak”, Ankit “V3nom”, Saloni “Meow16K”.Apart from this Indian women’s team has also done exceptionally well in CS:GO and has made it to the finale.
Government and Corporate Sectors support: The Indian esports business has received backing from the government and corporate sectors, contributing to its growth and acceptance as a genuine sport.
Government Initiatives: The Indian government has expressed increased support for esports through different initiatives. This involves recognising esports as an official sport, establishing esports regulating organisations, and incorporating esports into national sports federations. The government has also announced steps to give financial assistance, subsidies, and infrastructure development for esports, therefore providing a favourable environment for the industry’s growth. Recently, Kalyan Chaubey, joint secretary and acting CEO of the IOA, personally gave the athletes cutting-edge training gear during this occasion, providing kits to the players. The kit includes the following:
Advanced gaming mouse.
Keyboard built for quick responses.
A smooth mousepad
A headphone for crystal-clear communication
An eSports bag to carry the equipment.
Corporate Sponsorship and Partnerships
Indian corporations have recognised esports’ promise and actively sponsored and collaborated with esports organisations, tournaments, and individual players. Companies from various industries, including technology, telecommunications, and entertainment, have invested in esports to capitalise on its success and connect with the esports community. These sponsorships and collaborations give financial support, resources, and visibility to esports in India. The leagues and championships provide opportunities for young players to showcase their talent.
Challenges and future
While esports provides great job opportunities, several obstacles must be overcome in order for the industry to expand and gain recognition:
Infrastructure & Training Facilities: Ensuring the availability of high-quality training facilities and infrastructure is critical for developing talent and allowing players to realise their maximum potential. Continued investment in esports venues, training facilities, and academies is critical for the industry’s long-term success.
Fostering a culture of skill development and giving outlets for formal education in esports would improve the professionalism and competitiveness of Indian esports players. Collaborations between educational institutions and esports organisations can result in the development of specialised programs in areas such as game analysis, team management, and sports psychology.
Establishing a thorough legal framework and governance structure for esports will help it gain legitimacy as a professional sport. Clear standards on player contracts, player rights, anti-doping procedures, and fair competition policies are all part of this.
Conclusion
Esports in India provide massive professional opportunities and growth possibilities for aspiring esports athletes. The sector’s prospects are based on overcoming infrastructure, perception, talent development, and regulatory barriers. Esports may establish itself as a viable and acceptable career alternative in India with continued support, investment, and stakeholder collaboration

BharOS’s successful testing grabbed massive online attention after Ashwini Vaishnaw, Minister of Communications and Electronics & IT, and Union Education Minister Dharmendra Pradhan unveiled the new mobile operating system. On Data Privacy Day, January 28, it’s appropriate to discuss the safety factors.
The OS is developed by JandKops, which has been incubated by IIT Madras Pravartak Technologies Foundation. It is claimed that BharOS will ensure the prevention of the “execution of any malware” and “execution of any malicious application”.
Even though it is called a Made in India OS, there are many people who disagree with this. It is because the OS is based on an AOSP (Android Open Source Project). It includes similar methodologies, functionalities, and basics used in Google Android.
Global safety factor
Security and data safety has been worldwide issue. A few years ago, Alphabet CEO Sundar Pichai also testified in front of US Congress while facing questions related to privacy, data collection, and location tracking.
While experts say that Android’s app ecosystem is a privacy and security disaster, a study that examined 82,501 apps pre-installed on 1,742 Android smartphones sold by 214 vendors concluded that users are woefully unaware of the significant security and privacy risks posed by pre-installed applications.
Even Apple, which takes cybersafety issues as a top priority, sometimes finds itself in a vulnerable situation. For example, last year Apple users were advised to update their devices to protect against a pair of security flaws that could allow attackers to take complete control.
It was said that one of the software flaws affected the kernel, the deepest layer of the OS shared by all Apple devices, while the other had an impact on WebKit, the technology that powers the Safari web browser.
Security researchers, including NordVPN, said that Apple’s closed development OS makes it more difficult for hackers to develop exploits, while Android raises the threat level since anyone can see its source code to develop exploits.
BharOS is not like iOS but it is kind of similar to Android and based on AOSP. So the question is, how safe would this OS be?
‘Security blanket’
Sandip Kumar Panda, Co-founder and CEO of InstaSafe, told News18: “BharOS acts as a security blanket for devices. The framework is designed in a manner that it prevents the execution of any malicious app and verifies each app on the devices before making it live on the BharOS platform.”
There are no apps without any vulnerabilities, he said. “As the app development progresses, vulnerabilities get introduced either in the form of insecure coding practices or third-party software vulnerabilities integrated with the platform. Since several Android vulnerabilities were discovered over the years, all those bugs would have been fixed now and updates would already have been for AOSP, which will be much more mature now,” he added.
Vineet Kumar, Founder and President of CyberPeace Foundation, believes that “the use of AOSP as the foundation for BharOS is a positive step” as it is a robust platform.
But according to him, it is important to note that no OS can be completely immune to all forms of cyber threats. “The key to staying safe online is to stay vigilant, use security software, keep your software updated, and be mindful of the apps you install and the websites you visit,” he said,
Furthermore, the expert stated that it is possible to make an OS more secure by implementing a variety of security features and technologies such as sandboxing, whitelisting, and application control, as well as rigorous testing and code review processes.
Kumar said: “It would be important for an independent, reputable security firm to evaluate BharOS and test its security features before it can be stated with certainty that it is more secure than other OSs.”
It is difficult to say whether the BharOS will be free of cybersecurity issues without more information about the specific features and security measures that have been implemented, he noted while adding that this OS has to go through a rigorous testing and certification process.
“It will be important to see how it measures up against established security standards and how well it can withstand real-world attacks,” the expert stated.
Reference Link : https://www.news18.com/amp/news/tech/data-privacy-day-how-safe-is-bharos-what-do-cybersecurity-experts-say-you-are-about-to-find-out-6932521.html

Introduction
The world has been surfing the wave of technological advancements and innovations for the past decade, and it all pins down to one device – our mobile phone. For all mobile users, the primary choices of operating systems are Android and iOS. Android is an OS created by google in 2008 and is supported by most brands like – One+, Mi, OPPO, VIVO, Motorola, and many more and is one of the most used operating systems. iOS is an OS that was developed by Apple and was introduced in their first phone – The iPhone, in 2007. Both OS came into existence when mobile phone penetration was slow globally, and so the scope of expansion and advancements was always in favor of such operating systems.
The Evolution
iOS
Ever since the advent of the iPhone, iOS has seen many changes since 2007. The current version of iOs is iOS 16. However, in the course of creating new iOS and updating the old ones, Apple has come out with various advancements like the App Store, Touch ID & Face ID, Apple Music, Podcasts, Augmented reality, Contact exposure, and many more, which have later become part of features of Android phone as well. Apple is one of the oldest tech and gadget developers in the world, most of the devices manufactured by Apple have received global recognition, and hence Apple enjoys providing services to a huge global user base.
Android
The OS has been famous for using the software version names on the food items like – Pie, Oreo, Nougat, KitKat, Eclairs, etc. From Android 10 onwards, the new versions were demoted by number. The most recent Android OS is Android 13; this OS is known for its practicality and flexibility. In 2012 Android became the most popular operating system for mobile devices, surpassing Apple’s iOS, and as of 2020, about 75 percent of mobile devices run Android.
Android vs. iOS
1. USER INTERFACE
One of the most noticeable differences between Android and iPhone is their user interface. Android devices have a more customizable interface, with options to change the home screen, app icons, and overall theme. The iPhone, on the other hand, has a more uniform interface with less room for customization. Android allows users to customize their home screen by adding widgets and changing the layout of their app icons. This can be useful for people who want quick access to certain functions or information on their home screen. IOS does not have this feature, but it does allow users to organize their app icons into folders for easier navigation.
2. APP SELECTION
Another factor to consider when choosing between Android and iOS is the app selection. Both platforms have a wide range of apps available, but there are some differences to consider. Android has a larger selection of apps overall, including a larger selection of free apps. However, some popular apps, such as certain music streaming apps and games, may be released first or only available on iPhone. iOS also has a more curated app store, meaning that all apps must go through a review process before being accepted for download. This can result in a higher quality of apps overall, but it can also mean that it takes longer for new apps to become available on the platform. iPhone devices tend to have less processing power and RAM. But they are generally more efficient in their use of resources. This can result in longer battery life, but it may also mean that iPhones are slower at handling multiple tasks or running resource-intensive apps.
3. PERFORMANCE
When it comes to performance, both Android and iPhone have their own strengths and weaknesses. Android devices tend to have more processing power and RAM. This can make them faster and more capable of handling multiple tasks simultaneously. However, this can also lead to Android devices having shorter battery life compared to iPhones.
4. SECURITY
Security is an important consideration for any smartphone user, and Android and iPhone have their own measures to protect user data. Android devices are generally seen as being less secure than iPhones due to their open nature. Android allows users to install apps from sources other than the Google Play Store, which can increase the risk of downloading malicious apps. However, Android has made improvements in recent years to address this issue. Including the introduction of Google Play Protect, which scans apps for malware before they are downloaded. On the other hand, iPhone devices have a more closed ecosystem, with all apps required to go through Apple‘s review process before being available for download. This helps reduce the risk of downloading malicious apps, but it can also limit the platform’s flexibility.
Conclusion
The debate about the better OS has been going on for some time now, and it looks like it will get more comprehensive in the times to come, as netizens go deeper into cyberspace, they will get more aware and critical of their uses and demands, which will allow them to opt for the best OS for their convenience. Although the Andriod OS, due to its integration, stands more vulnerable to security threats as compared to iOS, no software is secure in today’s time, what is secure is its use and application hence the netizen and the platforms need to increase their awareness and knowledge to safeguard themselves and the wholesome cyberspace.

Introduction
With the increasing reliance on digital technologies in the banking industry, cyber threats have become a significant concern. Cyberlaw plays a crucial role in safeguarding the banking sector from cybercrimes and ensuring the security and integrity of financial systems.
The banking industry has witnessed a rapid digital transformation, enabling convenient services and greater access to financial resources. However, this digitalisation also exposes the industry to cyber threats, necessitating the formulation and implementation of effective cyber law frameworks.
Recent Trends in the Banking Industry
Digital Transformation: The banking industry has embraced digital technologies, such as mobile banking, internet banking, and financial apps, to enhance customer experience and operational efficiency.
Open Banking: The concept of open banking has gained prominence, enabling data sharing between banks and third-party service providers, which introduces new cyber risks.

How Cyber Law Helps the Banking Sector
The banking sector and cyber crime share an unspoken synergy due to the mass digitisation of banking services. Thanks to QR codes, UPI and online banking payments, India is now home to 40% of global online banking transactions. Some critical aspects of the cyber law and banking sector are as follows:
Data Protection: Cyberlaw mandates banks to implement robust data protection measures, including encryption, access controls, and regular security audits, to safeguard customer data.
Incident Response and Reporting: Cyberlaw requires banks to establish incident response plans, promptly report cyber incidents to regulatory authorities, and cooperate in investigations.
Customer Protection: Cyberlaw enforces regulations related to online banking fraud, identity theft, and unauthorised transactions, ensuring that customers are protected from cybercrimes.
Legal Framework: Cyberlaw provides a legal foundation for digitalisation in the banking sector, assuring customers that regulations protect their digital transactions and data.
Cybersecurity Training and Awareness: Cyberlaw encourages banks to conduct regular training programs and create awareness among employees and customers about cyber threats, safe digital practices, and reporting procedures.

RBI Guidelines
The RBI, as India’s central banking institution, has issued comprehensive guidelines to enhance cyber resilience in the banking industry. These guidelines address various aspects, including:
Technology Risk Management
Cyber Security Framework
IT Governance
Cyber Crisis Management Plan
Incident Reporting and Response
Recent Trends in Banking Sector Frauds and the Role of Cyber Law
Phishing Attacks: Cyberlaw helps banks combat phishing attacks by imposing penalties on perpetrators and mandating preventive measures like two-factor authentication.
Insider Threats: Cyberlaw regulations emphasise the need for stringent access controls, employee background checks, and legal consequences for insiders involved in fraudulent activities.
Ransomware Attacks: Cyberlaw frameworks assist banks in dealing with ransomware attacks by enabling legal actions against hackers and promoting preventive measures, such as regular software updates and data backups.
Master Directions on Cyber Resilience and Digital Payment Security Controls for Payment System Operators (PSOs)
Draft of Master Directions on Cyber Resilience and Digital Payment Security Controls for Payment System Operators (PSOs) issued by the Reserve Bank of India (RBI). The directions provide guidelines and requirements for PSOs to improve the safety and security of their payment systems, with a focus on cyber resilience. These guidelines for PSOs include mobile payment service providers like Paytm or digital wallet payment platforms.
Here are the highlights-
The Directions aim to improve the safety and security of payment systems operated by PSOs by providing a framework for overall information security preparedness, with an emphasis on cyber resilience.
The Directions apply to all authorised non-bank PSOs.
PSOs must ensure adherence to these Directions by unregulated entities in their digital payments ecosystem, such as payment gateways, third-party service providers, vendors, and merchants.
The PSO’s Board of Directors is responsible for ensuring adequate oversight over information security risks, including cyber risk and cyber resilience. A sub-committee of the Board may be delegated with primary oversight responsibilities.
PSOs must formulate a Board-approved Information Security (IS) policy that covers roles and responsibilities, measures to identify and manage cyber security risks, training and awareness programs, and more.
PSOs should have a distinct Board-approved Cyber Crisis Management Plan (CCMP) to detect, contain, respond, and recover from cyber threats and attacks.
A senior-level executive, such as a Chief Information Security Officer (CISO), should be responsible for implementing the IS policy and the cyber resilience framework and assessing the overall information security posture of the PSO.
PSOs need to define Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to identify potential risk events and assess the effectiveness of security controls. The sub-committee of the Board is responsible for monitoring these indicators.
PSOs should conduct a cyber risk assessment when launching new products, services, technologies, or significant changes to existing infrastructure or processes.
PSOs, including inventory management, identity and access management, network security, application security life cycle, security testing, vendor risk management, data security, patch and change management life cycle, incident response, business continuity planning, API security, employee awareness and training, and other security measures should implement various baseline information security measures and controls.
PSOs should ensure that payment transactions involving debit to accounts conducted electronically are permitted only through multi-factor authentication, except where explicitly permitted/relaxed.

Conclusion
The relationship between cyber law and the banking industry is crucial in ensuring a secure and trusted digital environment. Recent trends indicate that cyber threats are evolving and becoming more sophisticated. Compliance with cyber law provisions and adherence to guidelines such as those provided by the RBI is essential for banks to protect themselves and their customers from cybercrimes. By embracing robust cyber law frameworks, the banking industry can foster a resilient ecosystem that enables innovation while safeguarding the interests of all stakeholders or users.

Introduction
The insurance industry is a target for cybercriminals due to the sensitive nature of the information it holds. This makes it essential for insurance companies to have robust cybersecurity measures to protect their data and customers’ personal information.
Cyber fraud in India’s insurance industry is increasing. It is reported that the Indian insurance sector has witnessed a surge in cyber-attacks, with several instances of data breaches, identity thefts, and financial fraud being reported. These cybercrimes not only pose a significant threat to the financial stability of the insurance industry but also to the privacy and security of policyholders.
Cyber Frauds in the Insurance Industry
The insurance industry in India has been the target of increasing cyber fraud in recent years. With the growing digital transformation trend, insurance companies have become increasingly vulnerable to cyber-attacks. Cyber frauds in the insurance industry are initiated by hackers who use various techniques such as phishing, malware, ransomware, and social engineering to gain unauthorised access to policyholders’ personal data and sensitive information
Kinds of cyber frauds in the insurance industry
It is essential for insurers and policyholders alike to be aware of these kinds of cyber-attacks on insurance companies in today’s digital age. Staying educated about these threats can help prevent them from happening in the future.
Identity theft– One common type of cyber fraud that occurs in the insurance industry is identity theft. In this type of fraud, criminals steal personal information such as name, address, date of birth and social security numbers through phishing emails or fraudulent websites. They then use this information to open fraudulent policies or access existing ones.
Payment fraud- Another type of cyber fraud that is on the rise is payment fraud. In this type of fraud, hackers intercept electronic payments made by policyholders or agents using fake bank accounts or compromised payment gateways. The money is then siphoned into untraceable accounts, making it difficult for law enforcement agencies to identify and arrest the perpetrators.
Phishing attacks- Where the fraudsters posed as company officials and sent emails to policyholders requesting their account details. The unsuspecting customers fell for this scam and shared their sensitive information, which was then used to access their accounts and steal funds.
Hacking- Where hackers breach the company’s system to gain access to policyholder data. The hackers’ stoles personal records, including names, addresses, phone numbers, social security numbers, and financial information, which they later sell on the dark web.
Fake policies scam- Fraudsters create fake policies using stolen identities and collect premiums from innocent customers. The insurer then voided these policies due to fraudulent activity leaving those people without valid coverage when they needed it most. The victims suffer significant financial losses due to this scam.
Fake Insurance Websites- Discuss the creation of deceptive websites that imitate well-known insurance companies, where unsuspecting individuals provide their personal details, leading to identity theft or financial losses.

Prevention of Cyber Frauds in the Insurance Industry- Best practices to follow
Prevention is better than cure, which also holds true in the case of cyber fraud in the insurance industry. The industry must take proactive steps to prevent such frauds from occurring in the first place. One of the most effective ways to do so is by investing in cybersecurity measures that are specifically designed for the insurance sector.
Insurance companies must conduct regular employee training programs on cybersecurity best practices. This includes educating employees on how to identify and avoid phishing emails, create strong passwords, and recognise potential cyber threats. Companies should also establish a reporting mechanism for employees to report suspicious activity or incidents immediately.
Having proper access controls in place is also necessary. This means limiting access to sensitive data only to those employees who need it, implementing two-factor authentication, and regularly monitoring user activity logs. Regular audits can also provide an extra layer of protection against potential threats by identifying vulnerabilities that may have been overlooked during routine security checks.
Another essential step is encrypting all data transmitted between different systems and devices. Encryption scrambles data into unreadable codes that can only be deciphered using a decryption key, making it difficult for hackers to intercept or steal information in transit.
Legal Framework for Cyber Frauds in the Insurance Industry
The legal framework for cyber fraud in the insurance industry is critical to preventing such crimes. The Insurance Regulatory and Development Authority of India (IRDAI) has issued guidelines for insurers to establish a cybersecurity framework. The guidelines require insurers to conduct regular risk assessments, implement security measures, and ensure compliance with data privacy laws.
The Information Technology Act 2000, is another significant piece of legislation dealing with cyber fraud in India. The act defines offences such as unauthorised access to a computer system, hacking, and tampering with data. It also provides for stringent penalties and imprisonment for those found guilty of such offences.
The IRDAI’s guidelines provide insurers with a roadmap to establish robust cybersecurity measures to help prevent cyber fraud in the insurance industry. Stringent implementation of these guidelines will go a long way in safeguarding sensitive customer information from falling into the wrong hands.
Best Practices for Insurers and Policyholders
Insurers:
Implementing Strong Authentication: Encouraging the use of multi-factor authentication and secure login processes to safeguard customer accounts and prevent unauthorised access.
Regular Employee Training: Conduct cybersecurity awareness programs to educate employees about the latest threats and preventive measures.
Investing in Advanced Technologies: Utilizing robust cybersecurity tools and systems to promptly detect and mitigate potential cyber threats.
Policyholders:
Vigilance and Awareness: Policyholders must stay vigilant while sharing personal information online and verify the authenticity of insurance websites and communication channels.
Regular Updates and Patches: Advising individuals to keep their devices and software up to date to minimise vulnerabilities that cybercriminals can exploit.
Secure Online Practices: Encouraging the use of strong and unique passwords, avoiding sharing sensitive information on unsecured networks, and exercising caution when clicking on suspicious links or attachments.

Conclusion
As the Indian insurance industry embraces digitisation, the risk of cyber scams and data breaches becomes a significant concern. Insurers and policyholders must collaborate to ensure robust cybersecurity measures are in place to protect sensitive information and financial interests.
It is essential for insurance companies to invest in robust cybersecurity measures that can detect and prevent fraud attempts. Additionally, educating employees on the dangers of cyber fraud and implementing strict compliance measures can go a long way in mitigating risks. With these efforts, the insurance industry can continue to provide trustworthy and reliable services to its customers while protecting against cyber threats. As technology continues to evolve, it is imperative that the insurance industry adapts accordingly and remains vigilant against emerging threats.

Introduction
The European Union has fined the meta $ 1.3 billion for infringing the EU privacy laws by transferring the personal data of Facebook users to the United States. The EU fined Meta’s business in Ireland. As per the European Union, transferring Personal data to the US is a breach of the General data protection Regulation or European Union law on data protection and privacy.
GDPR Compliance
The terms of GDPR promise to gather users’ personal information legally and under strict conditions. And those who collect and manage personal data must protect users’ personal data from exploitation. The GDPR restricts an organisation’s capacity to transfer personal data outside the EU if the transfer is solely based on that body’s evaluation of the sufficiency of the personal data’s protection. Transfers should only be made where European authorities have determined that a third country, a territory within that third country, or an international organisation provides acceptable protection for data protection.
Violation by Meta
The punishment, announced by Ireland’s Data Protection Commission, might be one of the most significant in the five years since the European Union passed the landmark General Data Protection Regulation. According to regulators, Facebook failed to comply with a 2020 judgment by the European Union’s top court that Facebook data transferred over the Atlantic was not sufficiently safeguarded from American espionage agencies. However, whether Meta will ever need to encrypt Facebook users’ data in Europe is still being determined. Meta announced it would appeal the ruling, launching a potentially legal procedure.
Simultaneously, European Union and American officials are negotiating a new data-sharing pact that would provide legal protections for Meta and scores of other companies to continue moving information between the US and Europe. This pact could overturn much of the European Union’s Monday ruling.
Article 46(1) GDPR Has been violated by the meta, And as per the Irish privacy.
What is required by the GDPR before transferring personal information across national boundaries?

Personal data transfers to countries outside the European Economic Area are generally permitted if these nations are regarded to provide a sufficient degree of data protection. According to Article 45 of the GDPR, the European Commission evaluates the degree of personal data protection in third countries.
The European Union judgment demonstrates how government rules are upending the borderless way data has traditionally migrated. Companies are increasingly being pressed to store data within the country where it is acquired rather than allowing it to transfer freely to data centres around the world as a result of data-protection requirements, national security laws, and other regulations.
The US internet giant had previously warned that if forced to stop using SCCs (standard contractual clauses) without a proper alternative data transfer agreement in place, it would be compelled to shut down services such as Facebook and Instagram in Europe.
What will happen next for Facebook in Europe?
The ruling includes a six-month transition period before it must halt data flows, meaning the service will continue to operate in the meantime. (More specifically, Meta has been given a five-month transition period to freeze any future transfer of personal data to the United States and a six-month deadline to terminate the unlawful processing and/or storage of European user data it has previously transferred without a legitimate legal basis. Meta has also stated that it will appeal and appears to seek a stay of execution while it pursues its legal arguments in court.
Conclusion
The GDPR places restrictions on transferring personal data outside the European Union to third-party nations or international bodies to ensure that the GDPR’s level of protection for individuals is not jeopardised. But the meta violated the European Union’s privacy laws by the user’s personal information to the US. Under the compliance of GDPR, transferring and sending personal information to users intentionally is an offence. and presently, the personal data of Facebook users has been breached by the Meta, as they shared the information with the US.

Introduction
Recent advances in space exploration and technology have increased the need for space laws to control the actions of governments and corporate organisations. India has been attempting to create a robust legal framework to oversee its space activities because it is a prominent player in the international space business. In this article, we’ll examine India’s current space regulations and compare them to the situation elsewhere in the world.
Space Laws in India
India started space exploration with Aryabhtta, the first satellite, and Rakesh Sharma, the first Indian astronaut, and now has a prominent presence in space as many international satellites are now launched by India. NASA and ISRO work closely on various projects

India currently lacks any space-related legislation. Only a few laws and regulations, such as the Indian Space Research Organisation (ISRO) Act of 1969 and the National Remote Sensing Centre (NRSC) Guidelines of 2011, regulate space-related operations. However, more than these rules and regulations are essential to control India’s expanding space sector. India is starting to gain traction as a prospective player in the global commercial space sector. Authorisation, contracts, dispute resolution, licencing, data processing and distribution related to earth observation services, certification of space technology, insurance, legal difficulties related to launch services, and stamp duty are just a few of the topics that need to be discussed. The necessary statute and laws need to be updated to incorporate space law-related matters into domestic laws.
India’s Space Presence
Space research activities were initiated in India during the early 1960s when satellite applications were in experimental stages, even in the United States. With the live transmission of the Tokyo Olympic Games across the Pacific by the American Satellite ‘Syncom-3’ demonstrating the power of communication satellites, Dr Vikram Sarabhai, the founding father of the Indian space programme, quickly recognised the benefits of space technologies for India.
As a first step, the Department of Atomic Energy formed the INCOSPAR (Indian National Committee for Space Research) under the leadership of Dr Sarabhai and Dr Ramanathan in 1962. The Indian Space Research Organisation (ISRO) was formed on August 15, 1969. The prime objective of ISRO is to develop space technology and its application to various national needs. It is one of the six largest space agencies in the world. The Department of Space (DOS) and the Space Commission were set up in 1972, and ISRO was brought under DOS on June 1, 1972.

Since its inception, the Indian space programme has been orchestrated well. It has three distinct elements: satellites for communication and remote sensing, the space transportation system and application programmes. Two major operational systems have been established – the Indian National Satellite (INSAT) for telecommunication, television broadcasting, and meteorological services and the Indian Remote Sensing Satellite (IRS) for monitoring and managing natural resources and Disaster Management Support.
Global Scenario
The global space race has been on and ever since the moon landing in 1969, and it has now transformed into the new cold war among developed and developing nations. The interests and assets of a nation in space need to be safeguarded by the help of effective and efficient policies and internationally ratified laws. All nations with a presence in space do not believe in good for all policy, thus, preventive measures need to be incorporated into the legal system. A thorough legal framework for space activities is being developed by the United Nations Office for Outer Space Affairs (UNOOSA). The “Outer Space Treaty,” a collection of five international agreements on space law, establishes the foundation of international space law. The agreements address topics such as the peaceful use of space, preventing space from becoming militarised, and who is responsible for damage caused by space objects. Well-established space laws govern both the United States and the United Kingdom. The National Aeronautics and Space Act, which was passed in the US in 1958 and established the National Aeronautics and Space Administration (NASA) to oversee national space programmes, is in place there. The Outer Space Act of 1986 governs how UK citizens and businesses can engage in space activity.

Conclusion
India must create a thorough legal system to govern its space endeavours. In the space sector, there needs to be a legal framework to avoid ambiguity and confusion, which may have detrimental effects. The Pacific use of space for the benefit of humanity should be covered by domestic space legislation in India. The overall scenario demonstrates the requirement for a clearly defined legal framework for the international acknowledgement of a nation’s space activities. India is fifth in the world for space technology, which is an impressive accomplishment, and a strong legal system will help India maintain its place in the space business.

Pretext
On 20th October 2022, the Competition Commission of India (CCI) imposed a penalty of Rs. 1,337.76 crores on Google for abusing its dominant position in multiple markets in the Android Mobile device ecosystem, apart from issuing cease and desist orders. The CCI also directed Google to modify its conduct within a defined timeline. Smart mobile devices need an operating system (OS) to run applications (apps) and programs. Android is one such mobile operating system that Google acquired in 2005. In the instant matter, the CCI examined various practices of Google w.r.t. licensing of this Android mobile operating system and various proprietary mobile applications of Google (e.g., Play Store, Google Search, Google Chrome, YouTube, etc.).
The Issue
Google was found to be misusing its dominant position in the tech market, and the same was the reason behind the penalty. Google argued about the competitive constraints being faced from Apple. In relation to understanding the extent of competition between Google’s Android ecosystem and Apple’s iOS ecosystem, the CCI noted the differences in the two business models, which affect the underlying incentives of business decisions. Apple’s business is primarily based on a vertically integrated smart device ecosystem that focuses on the sale of high-end smart devices with state-of-the-art software components. In contrast, Google’s business was found to be driven by the ultimate intent of increasing users on its platforms so that they interact with its revenue-earning service, i.e., online searches, which directly affects the sale of online advertising services by Google. It was seen that google had created a dominant position among the android phone manufacturers as they were made to have a set of google apps preinstalled in the device to increase the user’s dependency on google services. The CCI felt that Google had created a dominant position to which they replied that the same operations are done by Apple as well, to which the commission responded that apple is a phone and app manufacturer and they have Apple-owned apps in Apple devices only, but Google here in had made a pseudo mandate for android manufactures to have the google apps pre-installed which is, in turn, a possible way of disrupting the market equilibrium and violative of market practices. The CCI imposed a penalty of Rs. 1,337.76 for abusing its dominant position in multiple markets in India, CCI delineated the following five relevant markets in the present matter –

- The market for licensable OS for smart mobile devices in India
- The market for app store for Android smart mobile OS in India
- The market for general web search services in India
- The market for non-OS specific mobile web browsers in India
- The market for online video hosting platforms (OVHP) in India.
Supreme Courts Opinion
In October 2022, the Competition Commission of India (CCI) ruled that Google, owned by Alphabet Inc, exploited its dominant position in Android and told it to remove restrictions on device makers, including those related to the pre-installation of apps and ensuring exclusivity of its search. Google lost a challenge in the Supreme Court to block the directives, as the learned court refused to put a stay on the imposed penalty, further giving seven days to comply. The Supreme Court has said a lower tribunal—where Google first challenged the Android directives—can continue to hear the company’s appeal and must rule by March 31.
Counterpoint Research estimates that about 97% of 600 million smartphones in India run on Android. Apple has just a 3% share. Hoping to block the implementation of the CCI directives, Google challenged the CCI order in the Supreme Court by warning it could stall the growth of the Android ecosystem. It also said it would be forced to alter arrangements with more than 1,100 device manufacturers and thousands of app developers if the directives kick in. Google has been concerned about India’s decision as the steps are seen as more sweeping than those imposed in the European Commission’s 2018 ruling. There it was fined for putting in place what the Commission called unlawful restrictions on Android mobile device makers. Google is still challenging the record $4.3 billion fine in that case. In Europe, Google made changes later, including letting Android device users pick their default search engine, and said device makers would be able to license the Google mobile application suite separately from the Google Search App or the Chrome browser.
Conclusion
As the world goes deeper into cyberspace, the big tech companies have more control over the industry and the markets, but the same should not turn into anarchy in the global markets. The Tech giants need to be made aware that compliance is the utmost duty for all companies, and enforcement of the law of the land will be maintained no matter what. Earlier India lacked policies and legislation to govern cyberspace, but in the recent proactive stance by the govt, a lot of new bills have been tabled, one of them being the Intermediary Rules 2021, which has laid down the obligations nand duties of the companies by setting up an intermediary in the country. Such bills coupled with such crucial judgments on tech giants will act as a test and barrier for other tech companies who try to flaunt the rules and avoid compliance.

What are Wi-Fi attacks?
Wi-fi is an important area of cyber security and there is no need for physical cable for the network. Wi-Fi has access to a network signal radius everywhere. The devices and systems can have a network without physical access due to Wi-fi. But everything comes with cons and pros, and if we talk about cybersecurity, it has been established that Wi-fi networks are extremely vulnerable to security breaches and it is very easy to be hacked by hackers. Wi-Fi can be accessed by almost every device in the modern day: it can be smartphones, tablets, computers, and laptops. To know whether someone has been tampering with your personal Wi-Fi there are certain signs that can prove it. The first and most important sign is that your internet speed gets slower, as someone else is using your Wi-Fi surf.
Why would anyone hack someone’s Wi-Fi network?
Usually, hackers hack the network because they want access to the confidential data of someone and they can observe all the online activities and data that have been sent through a network. An unauthorize hacker will pretty much be able to see everything you do online. Wi-Fi allows hackers o view information on sites. Any financial information which is saved in the browser can be accessed by hackers and they can alter it and can alter the content you see online. And all the information saved in Wi-fi networks can be used by hackers for their own benefit, they can sell it, impersonate you, or even take money out of your bank through Wi-Fi.
Avoiding vulnerable Wi-Fi networks
The first and foremost rule of protection is that you should not use public networks if that network is easily open to you then that is also available to others and from others, and someone can who wishes to use your confidential and sensitive information, can access that. If you really need to access the public network in an urgent situation, then you must make sure to limit your activities while connected. And avoid accessing your online banking or pages that require login information. Also, a good measure to take as well is to always delete your cookies after using public WIFI.
How To Secure Your Home Wi-Fi Network
Your home’s wireless internet connection is your Wi-Fi network. Typically, a wireless router is used, which broadcasts a signal into the atmosphere. You can connect to the internet using that signal. However, if your network is not password-protected, any nearby device can grab the signal off the air and connect to your internet. The benefit of Wi-Fi? Wireless access to the internet is possible. The negative? Your internet activity, including your personal information, may be visible to neighboring users who connect to your unprotected network. Furthermore, if someone uses your network to conduct a crime or send out unauthorized spam, you might be held accountable.
Wi-Fi or Li-Fi? –
The common consensus is that Li-Fi technology is more secure than Wi-Fi. Li-Fi systems can be made more secure by integrating a variety of security features. Although these qualities might appear when Li-Fi is widely used in the near future, it is already thought to be safer because of a number of security features. Since the connection’s characteristics make it simpler to lock connections, limit access, and track users even in the absence of encryption and other security features, Li-Fi is seen as being safer. Li-Fi systems will be able to support new security protocols, which will not only enable high-speed networking but also open the door for innovative security techniques to strengthen connections.
Conclusion
A hacker can sniff the network packets without having to be in the same building where the network is located. As wireless networks communicate through radio waves, a hacker can easily sniff the network from a nearby location. Most attackers use network sniffing to find the SSID and hack a wireless network.
Any wireless network can theoretically be attacked in a number of different ways. Use of the default SSID or password, WPS pin authentication, insufficient access control, and leaving the access point available in open locations are all examples of potential vulnerabilities that could allow for the theft of sensitive data. Kismet’s architecture in WIDS mode may guard against DOS, MiTM, and MAC spoofing attacks. routine software updates on the other hand, the use of firewalls may help defend the network against outside intrusion. The act of finding infrastructure issues that could allow harmful code to be injected into a service, system, or organization is known as ethical hacking. They use this technique to prevent invasions by lawfully breaking into networks and looking for weak spots.

Introduction
Google Play has announced its new policy which will ensure trust and transparency on google play by providing a new framework for developer verification and app details. The new policy requires that new developer accounts on Google Play will have to provide a D-U-N-S number to verify the business. So when an organisation will create a new Play Console developer account the organisation will need to provide a D-U-N-S number. Which is a nine-digit unique identifier which will be used to verify their business. The new google play policy aims to enhance user trust. And the developer will provide detailed developer details on the app’s listing page. Users will get to know who is behind the app which they are installing.
Verifying Developer Identity with D-U-N-S Numbers
To boost security the google play new policy requires the developer account to provide the D-U-N-S number when creating a new Play Console developer account. The D-U-N-S number assigned by Dun & Bradstreet will be used to verify the business. Once the developer creates his new Play Console developer account by providing a D-U-N-S number, Google Play will verify the developer’s details, and he will be able to start publishing the apps. Through this step, Google Play aims to validate the business information in a more authentic way.
If your organisation does not have a D-U-N-S number, you may check on or request for it for free on this website (https://www.dnb.com/duns-number/lookup.html). The request process for D-U-N-S can take up to 30 days. Developers are also required to keep the information up to date.
Building User Trust with Enhanced App Details
In addition to verifying developer identities in a more efficient way, google play also requires that developer provides sufficient app details to the users. There will be an “App Support” section on the app’s store listing page, where the developer will display the app’s support email address and even can include their website and phone number for support.
The new section “About the developer” will also be introduced to provide users with verified identity information, including the developer’s name, address, and contact details. Which will make the users more informed about the valuable information of the app developers.
Key highlights of the Google Play Polic
- Google Play came up with the policy to keep the platform safe by verifying the developers’ identity and it will also help to reduce the spread of malware apps and help the users to make confident informed decisions about the apps they download. Google Play announced the policy by expanding its developer verification requirement to strengthen Google Play as a platform and build user trust. When you create a new Play Console Developer account and choose organisation as your account type you will now need to provide a D-U-N-S number.
- Users will get detailed information about the developers’ identities and contact information, building more transparency and encouraging responsible app development practices.
- This policy will enable the users to make informed choices about the apps they download.
- The new “App support” section will provide enhanced communication between users and developers by displaying support email addresses, website and support phone numbers, streamlining the support process and user satisfaction.
Timeline and Implementation
The new policy requirements for D-U-N-S numbers will start rolling out on 31 August 2023 for all new Play Console developer accounts. The “About the developer” section will be visible to users as soon as a new app is published. and In October 2023, existing developers will also be required to update and verify their existing accounts to comply with the new verification policy.
Conclusion
Google Play’s new policy will aim to enhance the more transparent app ecosystem. This new policy will provide the users with more information about the developers. Google Play aims to establish a platform where users can confidently discover and download apps. This new policy will enhance the user experience on google play in terms of a reliable and trustworthy platform.

Introduction
Recently, a Consultation Paper on Regulatory Mechanisms for Over-The-Top (OTT) Communication Services was published by the Telecom Regulatory Authority of India (TRAI). The paper explores several OTT regulation-related challenges and solicits input from stakeholders on a suggested regulatory framework. We’ll summarise the paper’s main conclusions in this blog.
Structure of the Paper
The Telecom Regulatory Authority of India’s Consultation Paper on Regulatory Mechanism for Over-The-Top (OTT) Communication Services and Selective Banning of OTT Services intends to solicit comments and recommendations from stakeholders about the regulation of OTT services in India. The paper is broken up into five chapters that cover the introduction and background, issues with regulatory mechanisms for OTT communication services, issues with the selective banning of OTT services, a summary of the issues for consultation, and an overview of international practices on the topic. Written comments from interested parties are requested and may be sent electronically to the Advisor (Networks, Spectrum and Licencing) at TRAI. These comments will also be posted on the TRAI website.
Overview of the Paper
- Chapter 1: Introduction and Background
- The first chapter of the essay introduces the subject of OTT communication services and argues why regulatory frameworks are necessary. The chapter also gives a general outline of the topics and the paper’s organisation that will be covered in the following chapters.
- Chapter 2: Examination of the Issues Related to Regulatory Mechanism for Over-The-Top Communication Services
- The second chapter of the essay looks at the problems with OTT communication service regulation. It talks about the many kinds of OTT services and how they affect the conventional telecom sector. The chapter also looks at the regulatory issues raised by OTT services and the various strategies used by various nations to address them.
- Chapter 3: Examination of the Issues Related to Selective Banning of OTT Services
- The final chapter of the essay looks at the problems of selectively outlawing OTT services. It analyses the justifications for government restrictions on OTT services as well as the possible effects of such restrictions on consumers and the telecom sector. The chapter also looks at the legal and regulatory structures that determine how OTT services are prohibited in various nations.
- Chapter 4: International Practices
- An overview of global OTT communication service best practices is given in the paper’s fourth chapter. It talks about the various regulatory strategies used by nations throughout the world and how they affect consumers and the telecom sector. The chapter also looks at the difficulties regulators encounter when trying to create efficient regulatory frameworks for OTT services.
- Chapter 5: Issues for Consultation
- This chapter is the spirit of the consultation paper as it covers the points and questions for consultation. This chapter has been classified into two sub-sections – Issues Related to Regulatory Mechanisms for OTT Communication Services and Issues Related to the Selective Banning of OTT Services. The inputs will be entirely focused on these sub headers, and the scope, extent, and ambit of the consultation paper rests on these questions and necessary inputs.
Conclusion
An important publication that aims to address the regulatory issues raised by OTT services is the Consultation Paper on Regulatory Mechanisms for Over-The-Top Communication Services. The paper offers a thorough analysis of the problems with OTT service regulation and requests input from stakeholders on the suggested regulatory structure. In order to make sure that the regulatory framework is efficient and advantageous for everyone, it is crucial for all stakeholders to offer their opinion on the document.

Introduction
Twitter Inc.’s appeal against barring orders for specific accounts issued by the Ministry of Electronics and Information Technology was denied by a single judge on the Karnataka High Court. Twitter Inc. was also given an Rs. 50 lakh fine by Justice Krishna Dixit, who claimed the social media corporation had approached the court defying government directives.
As a foreign corporation, Twitter’s locus standi had been called into doubt by the government, which said they were ineligible to apply Articles 19 and 21 to their situation. Additionally, the government claimed that because Twitter was only designed to serve as an intermediary, there was no “jural relationship” between Twitter and its users.
The Issue
In accordance with Section 69A of the Information Technology Act, the Ministry issued the directives. Nevertheless, Twitter had argued in its appeal that the orders “fall foul of Section 69A both substantially and procedurally.” Twitter argued that in accordance with 69A, account holders were to be notified before having their tweets and accounts deleted. However, the Ministry failed to provide these account holders with any notices.
On June 4, 2022, and again on June 6, 2022, the government sent letters to Twitter’s compliance officer requesting that they come before them and provide an explanation for why the Blocking Orders were not followed and why no action should be taken against them.
Twitter replied on June 9 that the content against which it had not followed the blocking orders does not seem to be a violation of Section 69A. On June 27, 2022, the Government issued another notice stating Twitter was violating its directions. On June 29, Twitter replied, asking the Government to reconsider the direction on the basis of the doctrine of proportionality. On June 30, 2022, the Government withdrew blocking orders on ten account-level URLs but gave an additional list of 27 URLs to be blocked. On July 10, more accounts were blocked. Compiling the orders “under protest,” Twitter approached the HC with the petition challenging the orders.
Legality
Additionally, the government claimed that because Twitter was only designed to serve as an intermediary, there was no “jural relationship” between Twitter and its users.
Government attorney Additional Solicitor General R Sankaranarayanan argued that tweets mentioning “Indian Occupied Kashmir” and the survival of LTTE commander Velupillai Prabhakaran were serious enough to undermine the integrity of the nation.
Twitter, on the other hand, claimed that its users have pushed for these rights. Additionally, Twitter maintained that under Article 14 of the Constitution, even as a foreign company, they were entitled to certain rights, such as the right to equality. They also argued that the reason for the account blocking in each case was not stated and that Section 69a’s provision for blocking a URL should only apply to the offending URL rather than the entire account because blocking the entire account would prevent the creation of information while blocking the offending tweet only applied to already-created information.
Conclusion
The evolution of cyberspace has been substantiated by big tech companies like Facebook, Google, Twitter, Amazon and many more. These companies have been instrumental in leading the spectrum of emerging technologies and creating a blanket of ease and accessibility for users. Compliance with laws and policies is of utmost priority for the government, and the new bills and policies are empowering the Indian cyberspace. Non Compliance will be taken very seriously, and the same is legalised under the Intermediary Guidelines 2021 and 2022 by Meity. Referring to Section 79 of the Information Technology Act, which pertains to an exemption from liability of intermediary in some instances, it was said, “Intermediary is bound to obey the orders which the designate authority/agency which the government fixes from time to time.”

Introduction
Cert-In (Indian Computer Emergency Response Team) has recently issued the “Guidelines on Information Security Practices” for Government Entities for Safe & Trusted Internet. The guideline has come at a critical time when the Draft Digital India Bill is about to be released, which is aimed at revamping the legal aspects of Indian cyberspace. These guidelines lay down the policy framework and the requirements for critical infrastructure for all government organisations and institutions to improve the overall cyber security of the nation.
What is Cert-In?
A Computer Emergency Response Team (CERT) is a group of information security experts responsible for the protection against, detection of and response to an organisation’s cybersecurity incidents. A CERT may focus on resolving data breaches and denial-of-service attacks and providing alerts and incident handling guidelines. CERTs also conduct ongoing public awareness campaigns and engage in research aimed at improving security systems. The Ministry of Electronics and Information Technology (MeitY) oversees CERT-In. It regularly releases alerts to help individuals and companies safeguard their data, information, and ICT (Information and Communications Technology) infrastructure.
Indian Computer Emergency Response Team (CERT-In) has been established and appointed as national agency in respect of cyber incidents and cyber security incidents in terms of the provisions of section 70B of Information Technology (IT) Act, 2000.
CERT-In requests information from service providers, intermediaries, data centres, and body corporates to coordinate reaction actions and emergency procedures regarding cyber security incidents. It is a focal point for incident reporting and offers round-the-clock security services. It manages cyber occurrences that are tracked and reported while continuously analysing cyber risks. It strengthens the security barriers for the Indian Internet domain.
Background
India is fast becoming one of the world’s largest connected nations – with over 80 Crore Indians (Digital Nagriks) presently connected and using the Internet and cyberspace – and with this number is expected to touch 120 Crores in the coming few years. The Digital Nagriks of the country are using the Internet for business, education, finance and various applications and services including Digital Government services. Internet provides growth and innovation and at the same time it has seen rise in cybercrimes, user harm and other challenges to online safety. The policies of the Government are aimed at ensuring an Open, Safe & Trusted and Accountable Internet for its users. Government is fully cognizant and aware of the growing cyber security threats and attacks.
It is the Government of India’s objective to ensure that Digital Nagriks experience a Safe & Trusted Internet. Along with ubiquitous applications of Information & Communication Technologies (ICT) in almost all facets of service delivery and operations, continuously evolving cyber threats have become a concern for the Government. Cyber-attacks can come in the form of malware, ransomware, phishing, data breach etc., that adversely affect an organisation’s information and systems. Cyber threats leading to cyber-attacks or incidents can compromise the confidentiality, integrity, and availability of an organisation’s information and systems and can have far reaching impact on essential services and national interests. To protect against cyber threats, it is important for government entities to implement strong cybersecurity measures and follow best practices. As ICT infrastructure of the Government entities is one of the preferred targets of the malicious actors, responsibility of implementing good cyber security practices for protecting computers, servers, applications, electronic systems, networks, and data from digital attacks, also remain with the ICT assets’ owner i.e. Government entity.
What are the new Guidelines about?
The Government of India (distribution of business) Rules, 1961’s First Schedule lists a number of Ministries, Departments, Secretariats, and Offices, along with their affiliated and subordinate offices, which are all subject to the rules. They also comprise all governmental organisations, businesses operating in the public sector, and other governmental entities under their administrative control.
“The government has launched a number of steps to guarantee an accessible, trustworthy, and accountable digital environment. With a focus on capabilities, systems, human resources, and awareness, we are extending and speeding our work in the area of cyber security, according to Rajeev Chandrasekhar, Minister of State for Electronics, Information Technology, Skill Development, and Entrepreneurship.
The Recommendations
- Various security domains are covered in the standards, including network security, identity and access management, application security, data security, third-party outsourcing, hardening procedures, security monitoring, incident management, and security audits.
- For instance, the rules advise using only a Standard User (non-administrator) account to use computers and laptops for regular work regarding desktop, laptop, and printer security in the workplace. Users may only be granted administrative access with the CISO’s consent.
- The usage of lengthy passwords containing at least eight characters that combine capital letters, tiny letters, numerals, and special characters; Never save any usernames or passwords in your web browser. Likewise, never save any payment-related data there.
- They include guidelines created by the National Informatics Centre for Chief Information Security Officers (CISOs) and staff members of Central government Ministries/Departments to improve cyber security and cyber hygiene in addition to adhering to industry best practises.
Conclusion
The government has been proactive in the contemporary times to eradicate the menace of cybercrimes and therreats from the Indian cyberspace and hence now we have seen a series of new bills and polices introduced by the Ministry of Electronics and Information Technology, and various other government organisations like Cert-In and TRAI. These policies have been aimed towards being relevant to time and current technologies. The threats from emerging technologies like web 3.0 cannot be ignored and hence with active netizen participation and synergy between government and corporates will lead to a better and improved cyber ecosystem in India.

Introduction
The Telecom Regulatory Authority of India (TRAI) issued a consultation paper titled “Encouraging Innovative Technologies, Services, Use Cases, and Business Models through Regulatory Sandbox in Digital Communication Sector. The paper presents a draft sandbox structure for live testing of new digital communication products or services in a regulated environment. TRAI seeks comments from stakeholders on several parts of the framework.
What is digital communication?
Digital communication is the use of internet tools such as email, social media messaging, and texting to communicate with other people or a specific audience. Even something as easy as viewing the content on this webpage qualifies as digital communication.
Aim of Paper
- Frameworks are intended to support regulators’ desire for innovation while also ensuring economic resilience and consumer protection. Considering this, the Department of Telecom (DoT) asked TRAI to offer recommendations on a regulatory sandbox framework. TRAI approaches the issue with the goal of encouraging creativity and hastening the adoption of cutting-edge digital communications technologies.
- Artificial intelligence, the Internet of Things, edge computing, and other emerging technologies are revolutionizing how we connect, communicate, and access information, driving the digital communication sector to rapidly expand. To keep up with this dynamic environment, an enabling environment for the development and deployment of novel technologies, services, use cases, and business models is required.
- The regulatory sandbox concept is becoming increasingly popular around the world as a means of encouraging innovation in a range of industries. A regulatory sandbox is a regulated environment in which businesses and innovators can test their concepts, commodities, and services while operating under changing restrictions.
- Regulatory Sandbox will benefit the telecom startup ecosystem by providing access to a real-time network environment and other data, allowing them to evaluate the reliability of new applications before releasing them to the market. Regulatory Sandbox also attempts to stimulate cross-sectoral collaboration for carrying out such testing by engaging the assistance of other ministries and departments in order to give the starting company with a single window for acquiring all clearances.
What is regulatory sandbox?
- A regulatory sandbox is a controlled regulatory environment in which new products or services are tested in real-time.
- It serves as a “safe space” for businesses because authorities may or may not allow certain relaxations for the sole purpose of testing.
- The sandbox enables the regulator, innovators, financial service providers, and clients to perform field testing in order to gather evidence on the benefits and hazards of new financial innovations, while closely monitoring and mitigating their risks.
What are the advantages of having a regulatory sandbox?
- Firstly, regulators obtain first-hand empirical evidence on the benefits and risks of emerging technologies and their implications, allowing them to form an informed opinion on the regulatory changes or new regulations that may be required to support useful innovation while mitigating the associated risks.
- Second, sandbox customers can evaluate the viability of a product without the need for a wider and more expensive roll-out. If the product appears to have a high chance of success, it may be authorized and delivered to a wider market more quickly.
Digital communication sector and Regulatory Sandbox
- Many countries’ regulatory organizations have built sandbox settings for telecom tech innovation.
- These frameworks are intended to encourage regulators’ desire for innovation while also promoting economic resilience and consumer protection.
- In this context, the Department of Telecom (DoT) had asked TRAI to give recommendations on a regulatory sandbox framework.
- Written comments on the drafting framework will be received until July 17, 2023, and counter-comments will be taken until August 1, 2023. The Authority’s goal in the digital communication industry is to foster creativity and expedite the use of emerging technologies such as artificial intelligence (AI), the Internet of Things (IoT), and edge computing. These technologies are changing the way individuals connect, engage, and access information, causing rapid changes in the industry.
Conclusion
According to TRAI, these technologies are changing how individuals connect, engage, and obtain information, resulting in significant changes in the sector.
The regulatory sandbox also wants to stimulate cross-sectoral collaboration for carrying out such testing by engaging the assistance of other ministries and departments in order to give the starting company with a single window for acquiring all clearances. The consultation paper covers some of the worldwide regulatory sandbox frameworks in use in the digital communication industry, as well as some of the frameworks in use inside the country in other sectors.

Introduction
The Telecom Regulatory Authority of India (TRAI) has directed all telcos to set up detection systems based on Artificial Intelligence and Machine Learning (AI/ML) technologies in order to identify and control spam calls and text messages from unregistered telemarketers (UTMs).
The TRAI Directed telcos
The telecom regulator, TRAI, has directed all Access Providers to detect Unsolicited commercial communication (UCC)by systems, which is based on Artificial Intelligence and Machine Learning to detect, identify, and act against senders of Commercial Communication who are not registered in accordance with the provisions of the Telecom Commercial Communication Customer Preference Regulations, 2018 (TCCCPR-2018). Unregistered Telemarketers (UTMs) are entities that do not register with Access Providers and use 10-digit mobile numbers to send commercial communications via SMS or calls.
TRAI steps to curb Unsolicited commercial communication
TRAI has taken several initiatives to reduce Unsolicited Commercial Communication (UCC), which is a major source of annoyance for the public. It has resulted in fewer complaints filed against Registered Telemarketers (RTMs). Despite the TSPs’ efforts, UCC from Unregistered Telemarketers (UTMs) continues. Sometimes, these UTMs use messages with bogus URLs and phone numbers to trick clients into revealing crucial information, leading to financial loss.
To detect, identify, and prosecute all Unregistered Telemarketers (UTMs), the TRAI has mandated that Access Service Providers implement the UCC.
Detect the System with the necessary functionalities within the TRAI’s Telecom Commercial Communication Customer Preference Regulations, 2018 framework.
Access service providers have implemented such detection systems based on their applicability and practicality. However, because UTMs are constantly creating new strategies for sending unwanted communications, the present UCC detection systems provided by Access Service providers cannot detect such UCC.
TRAI also Directs Telecom Providers to Set Up Digital Platform for Customer Consent to Curb Promotional Calls and Messages.
Unregistered Telemarketers (UTMs) sometimes use messages with fake URLs and phone numbers to trick customers into revealing essential information, resulting in financial loss.

TRAI has urged businesses like banks, insurance companies, financial institutions, and others to re-verify their SMS content templates with telcos within two weeks. It also directed telecom companies to stop misusing commercial messaging templates within the next 45 days.
The telecom regulator has also instructed operators to limit the number of variables in a content template to three. However, if any business intends to utilise more than three variables in a content template for communicating with their users, this should be permitted only after examining the example message, as well as adequate justifications and justification.
In order to ensure consistency in UCC Detect System implementations, TRAI has directed all Access Providers to deploy UCC and detect systems based on artificial intelligence and Machine Learning that are capable of constantly evolving to deal with new signatures, patterns, and techniques used by UTMs.
Access Providers have also been directed to use the DLT platform to share intelligence with others. Access Providers have also been asked to ensure that such UCC Detect System detects senders that send unsolicited commercial communications in bulk and do not comply with the requirements. All Access Providers are directed to follow the instructions and provide an update on actions done within thirty days.
The move by TRAI is to curb the menacing calls as due to this, the number of scam cases is increasing, and now a new trend of scams started as recently, a Twitter user reported receiving an automated call from +91 96681 9555 with the message “This call is from Delhi Police.” It then asked her to stay in the queue since some of her documents needed to be picked up. Then he said he works as a sub-inspector at the Kirti Nagar police station in New Delhi. He then inquired whether she had recently misplaced her Aadhaar card, PAN card, or ATM card, to which she replied ‘no’. The scammer then poses as a cop and requests that she authenticate the last four digits of her card because they have found a card with her name on it. And a lot of other people tweeted about it.

Conclusion
TRAI directed the telcos to check the calls and messages from Unregistered numbers. This step of TRAI will curb the pesky calls and messages and catch the Frauds who are not registered with the regulation. Sometimes the unregistered sender sends fraudulent links, and through these fraudulent calls and messages, the sender tries to take the personal information of the customers, which results in financial losses.

Introduction
To combat the problem of annoying calls and SMS, telecom regulator TRAI has urged service providers to create a uniform digital platform in two months that will allow them to request, maintain, and withdraw customers’ approval for promotional calls and messages. In the initial stage, only subscribers will be able to initiate the process of registering their consent to receive promotional calls and SMS, and later, business entities will be able to contact customers to seek their consent to receive promotional messages, according to a statement issued by the Telecom Regulatory Authority of India (TRAI) on Saturday.
TRAI Directs Telecom Providers to Set Up Digital Platform
TRAI has now directed all access providers to develop and deploy the Digital Consent Acquisition (DCA) facility for creating a unified platform and process to digitally register customers’ consent across all service providers and principal entities. Consent is received and maintained under the current system by several key entities such as banks, other financial institutions, insurance firms, trading companies, business entities, real estate businesses, and so on.
The purpose, scope of consent, and the principal entity or brand name shall be clearly mentioned in the consent-seeking message sent over the short code,” according to the statement.
It stated that only approved online or app links, call-back numbers, and so on will be permitted to be used in consent-seeking communications.
TRAI issued guidelines to guarantee that all voice-based Telemarketers are brought under a single Distributed ledger technology (DLT) platform for more efficient monitoring of nuisance calls and unwanted communications. It also instructs operators to actively deploy AI/ML-based anti-phishing systems as well as to integrate tech solutions on the DLT platform to deal with malicious calls and texts.
TRAI has issued two separate Directions to Access Service Providers under TCCCPR-2018 (Telecom Commercial Communications Customer Preference Regulations) to ensure that all promotional messages are sent through Registered Telemarketers (RTMs) using approved Headers and Message Templates on Distributed Ledger Technologies (DLT) platform, and to stop misuse of Headers and Message Templates,” the regulator said in a statement.
Users can already block telemarketing calls and texts by texting 1909 from their registered mobile number. By dialing 1909, customers can opt out of getting advertising calls by activating the do not disturb (DND) feature.

Telecom providers operate DLT platforms, and businesses involved in sending bulk promotional or transactional SMS must register by providing their company information, including sender IDs and SMS templates.
According to the instructions, telecom companies will send consent-seeking messages using the common short code 127. The goal, extent of consent, and primary entity/brand name must be clearly stated in the consent-seeking message delivered via the shortcode.
TRAI stated that only whitelisted URLs/APKs (Android package kits file format)/OTT links/call back numbers, etc., shall be used in consent-seeking messages.
Telcos must “ensure that promotional messages are not transmitted by unregistered telemarketers or telemarketers using telephone numbers (10 digits numbers).” Telecom providers have been urged to act against all erring telemarketers in accordance with the applicable regulations and legal requirements.
Users can, however, refuse to receive any consent-seeking messages launched by any significant Telcos have been urged to create an SMS/IVR (interactive voice response)/online service for this purpose.
According to TRAI’s timeline, the consent-taking process by primary companies will begin on September 1.According to a nationwide survey conducted by a local circle, 66% of mobile users continue to receive three or more bothersome calls per day, the majority of which originate from personal cell numbers.
There are scams surfacing on the internet with new types of scams, like WhatsApp international call scams. The latest scam is targeting Delhi police, the scammers pretend to be police officials of Delhi and ask for the personal details of the users and the calling them from a 9-digit number.
A recent scam
A Twitter user reported receiving an automated call from +91 96681 9555, stating, “This call is from Delhi Police.” It went on to ask her to stay in the queue since some of her documents needed to be picked up. Then he said he is a sub-inspector at New Delhi’s Kirti Nagar police station. He then questioned if she had lately misplaced her Aadhaar card, PAN card, or ATM card, to which she replied ‘no’. The fraudster then claims to be a cop and asks her to validate the final four digits of her card because they have discovered a card with her name on it. And so many other people tweeted about this.
The scams are constantly increasing as earlier these scammers asked for account details and claimed to be Delhi police and used 9-digit numbers for scamming people.
TRAI’s new guidelines regarding the consent to receive any promotional calls and messages to telecommunication providers will be able to curb the scams.
The e- KYC is an essential requirement as e-KYC offers a more secure identity verification process in an increasingly digital age that uses biometric technologies to provide quick results.

Conclusion
The aim is to prevent unwanted calls and communications sent to customers via digital methods without their permission. Once this platform is implemented, an organization can only send promotional calls or messages with the customer’s explicit approval. Companies use a variety of methods to notify clients about their products, including phone calls, text messages, emails, and social media. Customers, however, are constantly assaulted with the same calls and messages as a result of this practice. With the constant increase in scams, the new guideline of TRAI will also curb the calling of Scams. digital KYC prevents SIM fraud and offers a more secure identity verification method.

Introduction
Online Gaming has gained popularity over the past few years, attracting young players worldwide and global concerns. In response to the growing fame of this industry, the Indian government has recently announced introducing a set of regulations to address various concerns and ensure a safer and more regulated online gaming environment. In this blog post, we will explore the critical aspects of these regulations and their impact on the gaming industry.
Why are Regulations needed?
Recently some games faced a ban in India – games that involve betting, games that can be harmful to the user, and games that involve a factor of addiction. Furthermore, with rising popularity, With the exponential rise of online gaming platforms in India, extensive laws to safeguard players and ensure fair gameplay needs to be implemented. Players’ protection is one of the critical factors addressing the issues which involve online addiction, underage involvement, fraud, and data privacy has become critical for the well-being of Indian gamers.
Regulatory Ambiguity: The previous legislative structure, such as the outmoded Public Gambling Act of 1867, required an update to fit the digital gambling age fully.
Outline of the New Regulations
Implementing new regulations for online gaming in India represents the government’s commitment to addressing different issues and ensuring a safer and more regulated gaming sector. Let’s have a look at these rules in detail:
National-Level Standards: The Indian government is currently working on creating national-level standards to standardise online gaming practices across all states. These rules attempt to create a uniform platform for both operators and participants. The government has also made an announcement to set SRO within 90 days to regulate online gaming.
Licencing and Compliance: To legally operate in the Indian market, online gaming firms must secure licences. The operator’s financial soundness, security measures, and adherence to responsible gaming practices will be scrutinised throughout the licencing process. Operators will need to comply with the regulations in order to maintain operations.
Measures to Promote Ethical Gaming: The new regulations emphasise player protection and ethical gaming practices. This includes steps like age verification to prevent underage involvement, self-exclusion choices for gamers who want to limit their gaming activities, and adopting tools like session limits and reality checks to promote responsible gaming.
Data Privacy: Recognising the importance of data privacy, the laws are intended to contain protections for protecting user data. To safeguard sensitive player information from unauthorised access or exploitation, online gambling operators must comply with data protection regulations and deploy strong security measures.
Restrictions on Advertising and Marketing: The legislation may limit the advertising and marketing of online gaming platforms. The emphasis will be on eliminating aggressive marketing tactics that target vulnerable people, such as kids. Stricter standards for ad content and placement may be implemented.
Anti-Fraud and Anti-Money Laundering Measures: To combat criminal activity within the gaming ecosystem, the new legislation will almost certainly force online gambling companies to employ anti-fraud and anti-money laundering measures. Operators may need to set up mechanisms to detect fraud, report suspicious activity, and work with law enforcement.
Consumer Grievance Redressal: The legislation may emphasise the construction of efficient channels for resolving consumer complaints. Players should be able to report difficulties, seek resolution, and offer feedback on their play experiences through channels. The objective is to create a transparent and accountable conflict resolution mechanism.

Impact on Online Gaming Ecosystem
Adopting new laws for online gambling in India will likely have several consequences for the gaming industry. Let us look at some of these consequences:
Increased Player Trust: Implementing restrictions will increase player confidence in online gaming platforms. Establishing clear rules and procedures and steps to safeguard participants’ interests will develop a sense of trust and transparency. This can lead to increased participation and engagement in the gaming community.
Industry Consolidation: Stricter restrictions may result in industry consolidation. Compliance with the new legislation would need resources and investments, which might favour more prominent and more established gambling firms. Smaller and more non-compliant operators may find it challenging to fulfil regulatory standards, resulting in a more consolidated gaming sector.
Technological Progress: The requirement to comply with rules could lead to technological advancements in the online gambling sector. Operators may invest in modern identity verification systems, fraud detection methods, and responsible gaming solutions to satisfy their regulatory requirements. This can result in technological breakthroughs that improve gamers’ overall gaming experience.
Foreign Investment and Collaboration: Clear laws might entice overseas investors to enter the Indian gaming business. The regulated environment may appeal to international gambling enterprises looking to enter or extend their presence in India. Collaborations between Indian and foreign gaming firms may also expand, resulting in the sharing of experience, resources, and the production of high-quality gaming products.
Legal Clarity: Implementing particular laws would give online gambling operators and users clearer legal standards. This transparency can eliminate ambiguity and possible legal issues, allowing stakeholders to navigate the gaming ecosystem with better confidence and knowledge.
Contribution to the Indian Economy: A well-regulated online gaming business has the potential to contribute to the Indian economy. It has the potential to create jobs, attract investment, and produce tax money for the government. The economic effect of the gaming ecosystem is expected to increase as it grows under the new restrictions.
Challenges and Future Approach
One of the toughest challenges will be the efficient implementation and enforcement of the new regulations. Consistency in applying the legislation across multiple jurisdictions and guaranteeing compliance by all operators would necessitate comprehensive monitoring and regulatory measures. Developing suitable enforcement organisations and transparent standards for reporting and dealing with noncompliance will be critical. Besides this, online gaming is open to more than area-specific and many gaming platforms and operates internationally. Ensuring cross-border operations is a big challenge in addressing jurisdictional challenges will be complex. Collaborative efforts between nations can regulate cross-border online gaming. There may be increased collaboration between Indian and foreign gaming firms, resulting in the exchange of information, skills, and resources. This partnership can help the Indian gaming sector flourish while attracting foreign players and investments.
Esports Development: Esports have grown in popularity worldwide, and India is no exception. The Indian esports business has the potential to thrive with proper regulation and support, drawing both players and viewers. Esports-specific factors like player contracts, tournament integrity, and licencing requirements may be addressed in the regulations.

Conclusion
Despite obstacles, India’s new online gambling legislation can potentially establish a safer and more regulated gaming sector. the future depends on successful implementation, adjusting to a shifting landscape, finding the correct balance between regulation and innovation, and promoting ethical gaming practices. The Indian online gaming business can develop sustainably with the appropriate strategy, benefiting gamers and the broader economy.

Introduction
Ministry of Electronics and Information Technology (MeitY) Announces to Centre Government to Plan to Certify Permissible Online Games.
In a recent update to the notification released by the Ministry of Electronics and Information Technology (MeitY) on April 6, MeitY has requested gaming entities to establish self-regulatory organisations (SROs) within a timeframe of 30 days or a maximum of 90 days from the date of the notification, which is April 6, 2023. The Ministry of Electronics and Information Technology (MeitY) has further announced that the central government will certify which online games are permissible until the SROs are officially established. The intention behind establishing SROs is to assist intermediaries, such as Apple or Google, in determining what constitutes a permitted online game, but the SRO will take 2-3 months to complete. In the meanwhile, the Central government will step in and determine what is a permissible online game.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 & Intermediary Guidelines and Digital Media Ethics Code Amendment Rules, 2023
By enacting these rules, the Indian government has taken decisive action to protect Indian gamers and their financial resources against scams and fraud. The rules also serve to promote responsible gaming while preventing young and vulnerable users from being exposed to indecent or abusive content.
Amendment Rules developed the concept of a “Permissible online real money game.” This designation is reserved for games that have passed a review process conducted by a self-regulatory body (SRB). Amendment rules indicate that Online Gaming Intermediaries must ensure that they do not permit any third party to host non-permissible online real money games on their platforms. This development is important because it empowers us to distinguish between legitimate and illicit real money games.
The Amendment Rules define an online gaming provider as an “intermediary” under the Information Technology Act of 2000, creating a separate classification called ‘Online Gaming Intermediary’.

Central government to certify what is an ‘Online Permissible Game’
The industry has been wondering what games come under wagering and will be banned. So, until the SROs are officially established, the government, in the interim, will certify what is a permissible game, what is wagering, and what is not wagering. Games that involve elements of wagering are going to be barred. The new regulations prohibit wagering on any outcome, whether in skill-based or chance-based games. Hence gaming applications involving wagering and betting apps will be barred.
Self-Regulatory Organizations (SROs)
According to the new regulations by the Ministry of Electronics and Information Technology (MeitY), online gaming intermediaries must establish a Self-Regulatory Body (SRO) to approve games offered to users over the Internet. The SRO must be registered with the Ministry and develop a framework to ensure compliance with the IT Rules 2021 objectives. An ‘online game’ can be registered by the SRO if it meets specific criteria, which include that the game is offered by an online gaming intermediary that is a member of the self-regulatory body, the game is not containing any content harmful to India’s interests, and complying with all relevant Indian regulations. If these requirements are met, the intermediary can display a visible registration mark indicating its registration with the self-regulatory authority.
Conclusion
MeitY found that with the rapid growth of the gaming industry, the real money gaming (RMG) sector had to be regulated properly. Rules framed must be properly implemented to stop gambling, betting, and wagering apps.
The IT Rules 2021, along with the Amendment Rules 2023, are created to take concrete action to curb the proliferation of gambling, betting, and wagering apps in India. These rules empower to issue of directives to ban specific apps that facilitate or promote such activities. The app ban directive allows the government to take decisive action by blocking access to these apps, making them unavailable for download or use within the country. This measure is aimed at curbing the negative impact of gambling, betting, and wagering on individuals and society, including issues related to addiction, financial loss, and illegal activities. Rules aim to actively combat the spread and influence of such apps and provide a safer online environment for gaming users.
The self-regulatory body in the context of online gaming will have the authority to grant membership to gaming intermediaries, register online games, develop a framework for regulation, interact with the Central Government, address user complaints, report instances of non-compliance, and take necessary actions to safeguard online gaming users.

Introduction
India has been a nation where technology penetration has been a little slower in the previous decades; however, that has changed now. Cyberspace has influenced and touched every country and has significantly diminished the gap between developing nations, developed nations, and underdeveloped nations. This has also been substantiated and strengthened during the Covid-19 pandemic as the world went into lockdown and the cyberspace was the only medium of communication and information. India witnessed a rise of 61% in terms of internet users, and a significant part of this number represented rural India.
New Standards
These standards have been released in threefold aspects covering – Digital Television Receivers, USB Type-C chargers, and Video Surveillance Systems, thus streamlining the use of gadgets and reduction of e-waste for the country.
1. Digital Television Receivers
The Indian standard IS 18112:2022 specification for digital television, and this standard would enable reception of free-to-air TV and radio channels just by connecting a dish antenna with LNB mounted on a suitable area with good signal reception. This will help in the transmission of knowledge about government initiatives and schemes, the educational content of Doordarshan, and the repository of Indian cultural programs. Doordarshan is in the process of phasing out analog transmission, and free-to-air channels will continue to be broadcast using digital satellite transmission. The keen aspects of educational and awareness programs run by the Govt and CSOs will impact more Indians than before as the Ministry of Information and Broadcast intends to increase their free channels of Doordarshan from 55 to 200 by the end of this year, which shows the importance of developments in the mass media industry.
2. USB Type C
Standard (IS/IEC 62680-1-3:2022) for USB Type-C receptacles, plugs, and cables adopting the existing global standard IEC 62680-1-3:2022. This standard provides for the requirements for USB type C ports and cables for use in various electronic devices like laptops, mobile phones, and other gadgets. This standard is similar to the new European standard, which is also aimed at the reduction of carbon emissions and e-waste; this move will result in ease for the industry and the end users. This will also contribute towards the strengthening of the cyber security aspects and prevent threats like ‘Juice Jacking’ to a massive extent.
3. Video Surveillance System
IS 16190, this standard provides a detailed outline of the aspects of a video surveillance system, such as requirements for its components like camera devices, interfaces, system requirements, and tests to ascertain the camera’s image quality on different devices. This series of standards would assist customers, installers, and users in establishing their requirements and determining the appropriate equipment required for their intended application and also provide means of evaluating the performance of the VSS objectively. This will also help in the improvement of surveillance by the individuals, and this will also help in the better investigation by Law enforcement agencies and faster apprehension of criminals, thus contributing to an overall safe society.

The Advantages
These standards are in power with the Internationally prevalent standards, thus taking the safety factors to the global aspect. This will also allow the Indian industry to create world-class products which can be shared all across the globe. This will open India to various opportunities and job avenues, thus opening the world to invest in India. The aspect of Atma Nirbhar Bharat and Digital India will be strengthened to a new level as the nation will be able to deliver products in power with quality in developed countries. The end Indian consumer will benefit the most from these upgraded standards in terms of Digital Televisions, Type ‘C’ USB chargers, and Video surveillance systems, as these impacts the consumers’ daily activities in terms of security and access to information.
- Reduction in Carbon Emission
- Production of World Class components and devices
- Boost to the economy and Atmanirbhar Bharat
- New avenues and opportunities for startups and MSMEs
- Better transmission of Knowledge
- Boosting FDI
- Improved quality of products for the end consumer
- New innovation hubs and exposure to global talents
This government move simply shows how India is working toward securing the Sustainable development Goals (SDG) by United Nations. This clearly shares the message to the world that India is ready for the future and will also be a helping hand to various developing and underdeveloped nations in the times to come.
Conclusion
These standards will significantly contribute towards the reduction of E-Waste and unnecessary accessories for daily use gadgets. This strengthens the reduction in carbon emissions and thus contributes towards the perseverance of the environment and working towards sustainable development goals. Such standards will lead the future towards securing the netizens and their new and evolving digital habits. In the current phase of cyberspace, the most essential aspect of establishing Critical Infrastructure as the same will act as a shield against the threats of cyberspace.