CERT-In Directions & Digital Arrest Scams (2026)

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 06 July 2026 · Updated 19 Aug 2026 · 7 min read · 35 views
CERT-In Directions & Digital Arrest Scams (2026)

The CERT-In directions issued under Section 70B of the IT Act — first notified in 2022 and progressively tightened since — have become the operational backbone of cyber-incident response for every bank and payment operator in India. For candidates preparing the IIBF Certificate in Prevention of Cyber Crime in 2026, these directions are unavoidable: they set the six-hour reporting clock, the log-retention mandate, and the synchronised-time-source rule that shape how your institution reacts the moment a breach, ransomware detonation or mule-account cluster is detected. This article moves past the over-covered phishing and IT Act 2000 basics to focus squarely on the CERT-In directions and the fast-rising threats of digital arrest scams and mule accounts.

You will learn the exact obligations the CERT-In directions impose, how they interlock with the RBI cyber-security framework, and how modern social-engineering frauds like "digital arrest" exploit gaps that compliance alone cannot close. Expect scenario questions that ask you to sequence an incident response correctly under the six-hour rule.

What the CERT-In directions actually mandate

The CERT-In directions issued under Section 70B(6) of the Information Technology Act, 2000 create binding obligations on service providers, intermediaries, data centres, body corporates and government organisations. The headline requirements a cyber-crime candidate must know cold are:

  • Six-hour reporting: any of the specified reportable incidents — ransomware, data breaches, unauthorised access, identity theft, attacks on critical systems — must be reported to CERT-In within six hours of noticing or being made aware of them.
  • Log retention: service providers must enable and securely maintain logs of ICT systems for a rolling period of 180 days within Indian jurisdiction.
  • Synchronised time: all systems must sync to the NTP servers of NIC or NPL (or traceable equivalents) so forensic timelines line up across institutions.
  • KYC and record retention for data centres, VPS, cloud and VPN providers: subscriber records must be maintained for at least five years.

For banks, these overlay the RBI cyber-security framework and the Master Direction on IT Governance. Reinforce the reporting sequence with timed practice on the iibf.store mock tests, where incident-response ordering is a favourite question type.

Ransomware and the incident-response lifecycle

Ransomware is the incident the CERT-In directions were sharpened to address, and it is the case study most likely to anchor an exam scenario. A defensible response follows a clear lifecycle: preparation, detection and analysis, containment, eradication, recovery, and post-incident review. Containment means isolating affected segments and disabling lateral-movement paths before the encryption spreads; eradication removes the payload and closes the entry vector; recovery restores from immutable, offline backups rather than paying the ransom, which regulators and CERT-In strongly discourage.

The prevention side leans on layered controls: patch management to close known vulnerabilities, network segmentation to limit blast radius, endpoint detection and response, principle-of-least-privilege access, and immutable backups tested for restorability. A bank that has practised its playbook can meet the six-hour reporting deadline and preserve logs for the mandated 180 days without scrambling. These themes connect to the broader technology syllabus you can deepen through the CAIIB curriculum, and to real-world circulars tracked on iibf.store news.

Key Concepts — Prevention of Cyber Crime
Key Concepts — Prevention of Cyber Crime

Digital arrest scams and mule-account networks

The most damaging social-engineering fraud of the 2020s in India is the "digital arrest" scam. Fraudsters impersonate police, CBI, ED or courier officials over video call, claim the victim's identity is linked to a crime or a seized parcel, and keep them under continuous "surveillance" until they transfer funds to "verify" innocence. The psychological pressure — fake arrest warrants, spoofed uniforms, threats of immediate arrest — bypasses rational scrutiny. RBI and the I4C (Indian Cyber Crime Coordination Centre) have repeatedly warned that no genuine law-enforcement agency conducts arrests over video call or demands money for "clearance".

The stolen money almost always flows through mule accounts — accounts opened by, or rented from, individuals who let their credentials be used to receive and forward fraud proceeds. Banks counter this with transaction-monitoring rules that flag rapid pass-through activity, sudden activation of dormant accounts, structuring just below reporting thresholds, and links to accounts already reported on the National Cybercrime Reporting Portal. Freezing the first hop quickly is the single most effective recovery lever, which is why the 1930 helpline and inter-bank coordination matter. Drill the red-flag indicators with the match-the-concept game to make them second nature.

The regulatory response has hardened considerably. Banks are now expected to run near-real-time mule-account detection, deploy name-and-device-based deduplication to spot serial account-openers, and share intelligence through inter-bank fraud registries so that a mule flagged at one bank cannot simply move to another. On the customer side, the layered-defence philosophy means a single control is never trusted alone: transaction limits, cooling-off periods on newly added beneficiaries, step-up authentication for high-value transfers, and behavioural analytics all combine to break the fraud chain at multiple points. For the exam, be ready to explain why a cooling-off period on a newly added payee specifically defeats the urgency that digital-arrest fraudsters manufacture — the delay gives the victim time to escape the manipulation.

Aligning with the RBI framework and CERT-In

Compliance is strongest when the CERT-In directions, the RBI cyber-security framework and internal fraud-risk management operate as one system. RBI expects a board-approved cyber-security policy, a Security Operations Centre with continuous monitoring, cyber-crisis management plans, and prompt reporting of unusual incidents — obligations that dovetail with CERT-In's six-hour rule. Customer-facing prevention, meanwhile, depends on awareness: teaching customers that banks never ask for OTPs, that "digital arrest" is always a scam, and that renting out an account is a punishable offence.

You should read the primary source directly; the authoritative directions and advisories are published by CERT-In.

Keep current on RBI's evolving expectations and rate circulars through the RBI resources page, because examiners increasingly reward candidates who cite the current framework rather than outdated 2016-era guidance. Bringing these strands together — technical controls, regulatory reporting and human-factor defence — is exactly the integrated thinking the certificate is designed to test.

Process & Framework — Prevention of Cyber Crime
Process & Framework — Prevention of Cyber Crime

Frequently asked questions

In Practice — Prevention of Cyber Crime
In Practice — Prevention of Cyber Crime

Related study material

Go deeper with the full chapter notes and the complete article hub for this subject:

What is the CERT-In six-hour reporting rule?

The CERT-In directions require organisations to report specified cyber incidents — such as ransomware, data breaches and unauthorised access — to CERT-In within six hours of noticing or being made aware of them, under Section 70B of the IT Act.

How long must logs be retained under the CERT-In directions?

Service providers must enable and securely maintain logs of their ICT systems for a rolling period of 180 days within Indian jurisdiction, and produce them to CERT-In when directed.

What is a digital arrest scam?

It is a social-engineering fraud where criminals impersonate law-enforcement officials over video call, falsely claim the victim is under investigation, and pressure them into transferring money. No genuine agency conducts arrests or demands payment over a video call.

What is a mule account in cyber fraud?

A mule account is a bank account used — often knowingly for a fee — to receive and forward the proceeds of fraud, layering the money across banks to frustrate recovery. Renting out an account is a punishable offence.

Conclusion: build the muscle memory before exam day

The CERT-In directions turn cyber-incident response from good practice into a legal obligation with a six-hour clock, and pairing that knowledge with an understanding of digital arrest scams and mule-account typologies covers the highest-yield territory in the 2026 certificate. Internalise the reporting timeline, the ransomware lifecycle and the mule-account red flags, then pressure-test yourself. Start a full cyber-crime prevention mock right now at iibf.store/tests and turn this framework into marks.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading