Digital Arrest Scam: How It Works and How Banks Stop It (Cyber Crime)
Imagine a video call where a man in police uniform tells you that you are under digital arrest and cannot hang up, step outside, or contact anyone until you pay to clear your name. This is the digital arrest scam, one of the fastest-growing digital payment frauds hitting Indian bank customers in 2026. There is no such thing as a digital arrest scam under any Indian law — the term itself is the fraudster's invention, built entirely on fear, isolation and speed. For bank staff studying Prevention of Cyber Crime, understanding the digital arrest scam modus operandi, the fake CBI and courier-call scripts, and the transaction-level red flags is now core exam and job material.
🎭 What Is a Digital Arrest Scam and How It Starts
A digital arrest scam almost always opens with a routine-sounding call: a courier company says a parcel booked in the victim's name contains banned items, drugs, or fake passports. The caller then "transfers" the victim to a fake police or customs officer, who claims a case is registered against them under the victim's Aadhaar or mobile number.
Within minutes the fraudster moves to a video call on WhatsApp or Skype, dressed in a police or CBI uniform, sitting in front of a mocked-up government office backdrop with a national emblem. The victim is told they are now under "digital arrest" — ordered to stay on camera, not disconnect, not step outside, and not tell family, or face a real arrest.
The entire performance is designed around the channels of cyber crime that let one criminal reach thousands of victims at near-zero cost — spoofed caller IDs, cloned government letterheads, and fake e-FIRs shown on screen. No genuine Indian investigating agency ever conducts an arrest, interrogation, or bail process over a video call, and no law empowers anyone to detain a person virtually. Once a candidate internalises this single fact, most of the scam's psychological pressure collapses.

📞 Fake CBI, Court and Courier Call Scripts
The scam script is layered so each call reinforces the last. A courier-fraud opener hands off to a "police station," which hands off to a fake CBI or Enforcement Directorate officer, and finally to a bogus "judge" who appears on screen to read out an intimidating but meaningless order. Victims are shown doctored arrest warrants, RBI-style seals, or forged Supreme Court letterheads to look authentic.
⚠️ Common Mistake: Candidates often assume digital arrest scams only target the elderly or technologically naive. In practice, doctors, retired bankers, and even serving government officers have lost lakhs — the scam works on authority and urgency, not on lack of education.
The fraudsters demand the victim stay under constant video surveillance — sometimes for hours — while being told their bank accounts are under "investigation" for money laundering and must be verified by transferring the full balance to a "RBI verification account" or "government safe account." This is the pivot point where the scam becomes a banking-channel fraud rather than just a scare call.
Because the victim is coached to lie if a bank official asks questions, tellers and call-centre staff trained under computer fraud protection practices are often the last line of defence before funds leave the account.

💰 Mule Routing: Where the Money Actually Goes
Once a victim transfers funds, the money almost never sits in one account. It is routed within minutes through a chain of mule accounts — bank accounts opened using rented, purchased, or stolen KYC documents, often belonging to people who were paid a small commission or tricked into handing over their credentials.
The layering pattern typically looks like: victim account → first-layer mule account → rapid split into several second-layer accounts → conversion into UPI wallets, prepaid cards, or crypto off-ramps, all completed before the victim even ends the video call. Interbank and inter-state routing is deliberate — it slows down the freeze-and-trace process for the bank and police handling the complaint.
Investigators use bank statements, IP logs, and device fingerprints to reconstruct this chain, which is why every rupee that can be frozen in the first hour matters far more than what can be recovered weeks later. This mule-layering pattern is also central to how the police classify a case, and candidates should be able to distinguish it from card-present or skimming fraud when the exam asks for the correct fraud type.
💡 Exam Tip: If a question describes multiple rapid transfers across unrelated accounts immediately after a large deposit, the answer is almost always "mule account layering," not "identity theft" or "card cloning."
🚩 Bank-Side Red Flags and Detection Controls
Banks cannot see the video call, but they can see the transaction pattern it produces, and this is where fraud-monitoring systems earn their place in the exam syllabus. A large, first-time, high-value transfer initiated soon after a beneficiary is newly added, especially outside the customer's usual transaction hours or geography, should trigger a rules-based alert.
Branch staff are trained to watch for behavioural cues too: a customer on a video call while transacting, visibly anxious or repeating scripted phrases like "I cannot disclose why," refusing a callback, or insisting the transfer is extremely urgent and confidential. Cooling-off periods on new beneficiaries and step-up authentication for large first-time transfers are two of the simplest controls that blunt this fraud.
The table below maps the scam's stages against what a bank's systems and staff can realistically catch.
| Stage of the Scam | What the Fraudster Does | Bank Detects at This Stage |
|---|---|---|
| Initial courier/police call | Builds fear, no banking channel touched yet | ❌ No |
| Fake video "arrest" and coercion | Victim isolated, told to hide the reason | ❌ No |
| New beneficiary added + large transfer | Victim moves funds to a "verification account" | ✅ Yes — rule-based alert |
| Video call visible during branch/app transaction | Victim coached in real time, refuses questions | ✅ Yes — staff/behavioural flag |
| Mule-to-mule layering post-transfer | Funds split and moved across accounts fast | ✅ Yes — post-transaction analytics |
Robust internal segregation, including network segmentation in banks, ensures that even if a mule account is opened through a compromised onboarding channel, the core payment systems still run independent fraud-scoring checks before funds are released.

📱 Reporting a Digital Arrest Scam: Act in the Golden Hour
Every minute counts once a digital arrest scam payment leaves the victim's account. The victim or the bank should call the national cyber crime helpline number 1930 immediately — this connects to a citizen financial cyber fraud reporting system that can trigger a freeze request to the receiving bank before the funds are laundered further.
Complaints can also be filed online at the National Cyber Crime Reporting Portal, cybercrime.gov.in, which routes the case to the relevant state cyber cell and logs it for coordinated multi-bank freeze action. Bank staff handling such a call should capture the transaction UTR/reference number, beneficiary account and bank, and exact time of transfer, since these details decide whether a freeze request succeeds.
Good incident management practice inside the bank means routing such calls straight to the fraud risk desk rather than a generic complaint queue, and never asking the customer to "wait and see if it resolves." Customers should also be counselled that real agencies never demand money over a call or video call to avoid arrest, and never ask for OTPs, PINs, or full card details under any circumstance.
📌 Remember: No court, police station, or RBI office in India conducts hearings or verifications over WhatsApp video call. Hanging up and calling the bank's fraud helpline is always the correct first action.
✅ Conclusion: Awareness Is the Strongest Control
A digital arrest scam succeeds because it compresses fear and urgency into minutes, leaving the victim no time to verify the story with family, colleagues, or the bank. For IIBF candidates, the exam-relevant takeaway is simple: no lawful "digital arrest" exists, mule-account layering is the giveaway transaction pattern, and the 1930 helpline plus cybercrime.gov.in are the fastest recovery paths once money moves. Browse more Prevention of Cyber Crime study material, and revise related ground with our notes on phishing, vishing and smishing and the IT Act 2000 sections for cyber crime.
Ready to test yourself? Take a free chapter-wise mock test on iibf.store →
🧠 Practice MCQs: Digital Arrest Scam
Q1. Under Indian law, which authority can legally conduct a "digital arrest" of a citizen over video call? (a) CBI (b) Local police station (c) RBI (d) None — no such legal power exists
Answer: (d) — "Digital arrest" is not a legal power under any Indian statute; it is a fear tactic invented by fraudsters.
Q2. In a digital arrest scam, why do fraudsters keep the victim on a continuous video call? (a) To verify the victim's identity (b) To isolate the victim and prevent them from consulting family or the bank (c) To record evidence for a real case (d) To comply with RBI KYC norms
Answer: (b) — Continuous video contact is a coercion tool to stop the victim from seeking a second opinion before transferring funds.
Q3. Which transaction pattern is the strongest bank-side red flag for a digital arrest scam? (a) Small recurring bill payments (b) A large transfer to a newly added beneficiary soon after account opening (c) Salary credit on the first of the month (d) ATM withdrawal within the home city
Answer: (b) — A large, first-time transfer to a freshly added beneficiary, often outside normal patterns, is the classic red flag banks monitor for.
Q4. What typically happens to funds immediately after a victim transfers money in a digital arrest scam? (a) They remain in a single savings account for weeks (b) They are rapidly layered across multiple mule accounts and converted to UPI/crypto (c) They are automatically refunded by the bank (d) They are moved only after 30 days
Answer: (b) — Rapid multi-account mule layering is used to move and convert funds before a freeze request can catch up.
Q5. A customer calls the bank in panic about a "digital arrest" video call demanding money. What is the correct first action? (a) Advise them to keep paying until the case is "cleared" (b) Tell them to stay on the video call and follow the officer's instructions (c) Advise them to disconnect and report immediately via the 1930 helpline or cybercrime.gov.in (d) Ask them to visit the police station shown on the video call
Answer: (c) — The correct response is to end the call and report through the official 1930 helpline or the national cyber crime portal without delay.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
Is a digital arrest scam a real legal procedure in India?
No. No Indian law allows police, CBI, or any agency to arrest or hold a person under investigation over a video call. It is entirely a fraud script designed to pressure victims into transferring money.
What should a bank customer do if they are on a "digital arrest" video call and asked to transfer funds?
They should disconnect immediately, avoid sharing OTPs, PINs, or card details, and call the 1930 national cyber crime helpline or file a complaint at cybercrime.gov.in as soon as possible.
How quickly must a digital arrest scam be reported for a bank to freeze the funds?
As fast as possible. Funds are typically layered across mule accounts within minutes, so reporting within the first hour gives the bank and cyber cell the best chance of a freeze before conversion to UPI, wallets, or crypto.
What is the most useful red flag banks use to catch a digital arrest scam transaction?
A large, unusual transfer to a newly added beneficiary, especially combined with the customer appearing distressed or on a live video call during the transaction, is the strongest combined signal.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.