—
Cyber crime is any illegal activity in which computers, smartphones, networks, online accounts, digital services, or the Internet are used as a target, a tool, or an important part of the crime.
It does not always involve a highly skilled hacker breaking into a computer.
A fake bank message, phishing email, stolen social-media account, malicious application, fraudulent investment scheme, ransomware attack, or scammer convincing someone to share sensitive information can all involve cyber crime.
The easiest way to understand it is:
Cyber Crime = Crime involving digital technology
Cyber criminals commonly target three things:
- Money
- Information
- Access
Understanding how these crimes work is one of the simplest ways to avoid becoming a victim.

—
Understanding Cyber Crime
What Makes Something a Cyber Crime?
Technology can play different roles in a crime.
Sometimes the computer or digital system itself is the target.
For example:
- Breaking into a server
- Stealing information from a database
- Infecting computers with ransomware
- Taking control of an online account
- Disrupting an online service
In other cases, technology is primarily the tool used to carry out a traditional crime.
For example:
- Running an online investment scam
- Impersonating someone on social media
- Sending fraudulent payment requests
- Stealing identity information
- Threatening or harassing someone online
A Simple Example
Imagine receiving this SMS:
“Your bank KYC expires today. Your account will be blocked. Update immediately using this link.”
The message creates urgency.
You click the link.
A website opens that looks similar to your bank’s website.
You enter your username and password.
The website, however, belongs to a criminal.
Cyber Crime Can Target Anyone
Cyber criminals may target:
- Individuals
- Students
- Senior citizens
- Employees
- Businesses
- Banks
- Hospitals
- Schools
- Government organizations
- Online services
Attackers may also automate their attacks and send thousands or millions of malicious messages instead of selecting one particular person.
—
How Cyber Crime Happens
Although cyber crimes differ greatly, many attacks can be understood using a simple sequence.
Step 1 — Find or Reach a Target
The criminal first needs a target or a way to reach potential victims.
Information may come from:
- Public websites
- Social media
- Previously leaked data
- Stolen contact lists
- Compromised accounts
- Random phone-number lists
- Email databases
Sometimes no research is required at all.
A scammer may simply send the same message to thousands of phone numbers.
Step 2 — Deliver the Attack
The attacker then uses a method such as:
- SMS
- Messaging application
- Phone call
- Fake website
- Social media
- Malicious software
- Stolen credentials
- Software vulnerability
Step 3 — Trigger an Action or Exploit a Weakness
The victim may be persuaded to:
- Click a link
- Open an attachment
- Install an application
- Scan a QR code
- Enter a password
- Reveal an OTP
- Approve a payment
- Transfer money
- Provide personal information
In more technical attacks, criminals may exploit vulnerable software or stolen credentials without requiring direct interaction with the victim.
Step 4 — Achieve the Objective
The attacker may then attempt to:
Steal Money → Steal Data → Take Over Account → Install Malware → Demand Ransom → Commit Further Fraud

—
Common Types of Cyber Crime
Cyber crime is a broad category. The following are some of the forms ordinary Internet users are most likely to encounter.
Phishing
Phishing uses fraudulent messages or websites to trick victims into revealing information or performing an unsafe action.
A message may pretend to come from:
- Bank
- Employer
- Courier company
- Government service
- Social-media platform
- Online shopping service
- Friend or colleague
For example:
“Your parcel could not be delivered. Pay ₹25 to reschedule delivery.”
The amount looks small and believable.
However, the payment page may actually be designed to steal financial information.
CERT-In specifically warns users to be cautious about unknown links and attachments and notes that scammers may create fake websites to collect banking, card and personal information.
Smishing and Vishing
Phishing is not limited to email.
| Method | Meaning | Example |
|---|---|---|
| Phishing | Fraud mainly through deceptive digital messages, commonly email | Fake password-reset email |
| Smishing | Phishing through SMS/text messages | Fake bank KYC SMS |
| Vishing | Voice-based phishing | Fraudulent bank-support call |
The delivery method changes, but the objective is similar:
Convince the victim to trust the attacker.
Online Financial Fraud
Cyber criminals frequently attempt to steal money using digital payment and banking services.
Examples include:
- Fake investment schemes
- UPI fraud
- QR-code scams
- Fake online stores
- Job scams
- Loan scams
- Lottery scams
- Refund scams
- Customer-support scams
- Impersonation scams
Identity Theft
Identity theft occurs when another person obtains and misuses someone’s personal information.
Stolen information could include:
- Name
- Phone number
- Email address
- Identification information
- Login credentials
- Financial information
- Personal documents
The information may then be used for impersonation, fraud, unauthorized accounts, or other illegal activity.
Account Hacking and Account Takeover
Criminals may attempt to gain unauthorized access to:
- Social media
- Banking
- Cloud services
- Gaming accounts
- Business accounts
Passwords may be obtained through:
- Phishing
- Malware
- Data breaches
- Password reuse
- Credential stuffing
- Social engineering
Malware
Malware means malicious software.
It is software designed to perform harmful or unauthorized activity.
Examples include:
- Trojan
- Spyware
- Keylogger
- Infostealer
- Worm
- Ransomware
Malware may attempt to:
Steal Data → Monitor Activity → Capture Credentials → Damage Files → Control Device
Ransomware
Ransomware is malware that denies access to data or systems, commonly by encrypting files, and demands payment.
Some ransomware operations also steal information before encryption and threaten to publish it.
A simplified example is:
Malicious Email → Attachment Opened → Malware Executes → Files Encrypted/Stolen → Ransom Demand

Data Theft and Data Breaches
Attackers may target databases and systems containing sensitive information.
For example:
Company Database → Unauthorized Access → Customer Information Stolen → Information Misused or Sold
The stolen information might include:
- Names
- Email addresses
- Passwords
- Customer records
- Financial information
- Business information
Online Impersonation and Scams
A cyber criminal may pretend to be:
- Bank employee
- Police officer
- Government official
- Customer-support representative
- Recruiter
- Manager
- Friend
- Relative
- Buyer or seller
The attacker wants the victim to believe the false identity long enough to perform the requested action.
Cyberstalking and Online Harassment
Technology can also be used to repeatedly monitor, threaten, impersonate or harass another person.
Depending on the conduct and applicable law, such behaviour can involve criminal offences.
—
Cyber Crime, Cyberattack and Cybersecurity
These terms are related but should not be treated as identical.
| Term | Simple Meaning | Example |
|---|---|---|
| Cyber Crime | Illegal activity involving digital technology | Stealing money through a phishing website |
| Cyberattack | Attempt to compromise, disrupt or damage digital systems or data | Deploying malware against a server |
| Cybersecurity | Protection of systems, networks, applications and information | MFA, firewalls, patching and monitoring |
Simple Way to Remember
Cyber Crime = Illegal Activity
Cyberattack = Possible Attack Method
Cybersecurity = Protection
—
Warning Signs of Cyber Crime and Online Scams
Recognizing suspicious behaviour early can prevent many attacks.
Unexpected Urgency
Be suspicious of messages such as:
- “Account will be blocked today.”
- “Pay immediately.”
- “Your SIM will be disconnected.”
- “Your KYC has expired.”
- “Respond within 10 minutes.”
- “Your parcel is waiting.”
- “You have won a prize.”
Urgency is frequently used to reduce the time available for careful thinking.
Requests for Sensitive Information
Treat unexpected requests for the following information very carefully:
- Password
- PIN
- OTP
- CVV
- Banking credentials
- Identification documents
- Recovery codes
Suspicious Links
For example:
Expected
https://www.examplebank.com/
Suspicious
https://examplebank-verify-login.xyz/
A familiar company name somewhere in a URL does not prove that the website belongs to that company.
Unexpected Login Alerts
Pay attention to:
- Login from unknown location
- Unknown device
- Password-reset request you did not make
- Changed recovery email
- Changed phone number
- MFA notification you did not initiate
Offers That Are Too Good to Be True
Be cautious when someone promises:
- Guaranteed investment returns
- Huge discounts
- Easy money
- Lottery winnings
- High-paying jobs without normal recruitment
- Free expensive products
—
How to Protect Yourself from Cyber Crime
There is no single tool that can prevent every cyber crime.
Good protection combines technology + awareness + safe habits.
Use Unique Passwords
Avoid using one password everywhere.
Use different passwords for important accounts, particularly:
- Banking
- Social media
- Cloud services
A password manager can help maintain unique passwords.
Enable Multi-Factor Authentication
Enable MFA wherever available.
MFA provides an additional authentication step beyond the password.
CERT-In recommends strong, unique passwords and MFA as important account-protection measures.
Think Before Clicking
Before opening an unexpected link or attachment, ask:
Was I expecting this?
Do I know the sender?
Why am I being asked to act urgently?
Can I verify this another way?
Verify Financial Requests Independently
Suppose someone calls claiming to represent your bank.
Do not rely only on the number displayed on your phone.
End the call and contact the bank using its official application, website, card, or other trusted contact method.
Keep Devices Updated
Regularly update:
- Operating system
- Browser
- Applications
- Mobile device
- Security software
- Network devices
Security updates often fix known vulnerabilities.
Install Software from Trusted Sources
Be cautious with unknown:
- APK files
- Browser extensions
- Cracked software
- Email attachments
- Remote-access tools
- Download websites
Maintain Backups
Important information should be backed up regularly.
Backups can be especially useful after:
- Ransomware
- Device failure
- Accidental deletion
- Data corruption
At least one important backup should not remain permanently accessible from the device or system it protects.
Review Your Accounts
Regularly check important accounts for:
- Unknown transactions
- Unknown devices
- Suspicious login activity
- Changed recovery settings
- Messages you did not send

—
What to Do If You Become a Victim
Discovering a cyber crime can be stressful, but taking structured action is more useful than panicking.
For Financial Fraud — Act Quickly
If money has been fraudulently transferred or a financial account may be compromised:
- Contact the relevant bank or payment provider immediately.
- Block or secure affected cards/accounts where appropriate.
- Preserve transaction information.
- Report the incident through the appropriate official channel.
In India, the National Cyber Crime Reporting Portal currently directs victims of cyber financial fraud to call 1930 for immediate reporting.
Secure Compromised Accounts
If an online account has been compromised:
- Change its password from a trusted device.
- Sign out unknown sessions.
- Enable MFA.
- Review recovery information.
- Check recent account activity.
- Change reused passwords on other services.
Preserve Evidence
Do not immediately delete everything.
Useful information can include:
- Screenshots
- SMS messages
- Emails
- Phone numbers
- Website addresses
- Social-media profiles
- Chat history
- Transaction ID
- UTR number
- Payment details
- Dates and times
India’s National Cyber Crime Reporting Portal specifically asks complainants to keep incident details, relevant evidence, and—for financial fraud—bank/wallet/merchant information, transaction/UTR details, date and fraud amount available.
Report Cyber Crime in India
Cyber crime complaints can be submitted through the Government of India’s:
For immediate reporting of cyber financial fraud:
Call 1930
The portal supports categories including financial fraud and other cyber crime complaints, and complaints are handled by the relevant law-enforcement agencies based on the information provided.
The portal also provides a facility for reporting suspicious identifiers such as website URLs, phone numbers, email addresses, SMS headers and certain social-media identifiers.
—
Key Takeaways
1. Cyber crime is illegal activity involving computers, mobile devices, networks, data or online services.
2. Cyber crime is not limited to technical hacking.
3. Criminals frequently use phishing and social engineering to manipulate victims.
4. Money, personal information and account access are common targets.
5. Phishing can arrive through email, SMS, messaging platforms, fake websites or voice calls.
6. Reusing passwords increases the impact of stolen credentials.
7. Strong unique passwords and MFA provide important account protection.
8. Unexpected requests involving money, OTPs or urgent action should always be verified.
9. Keeping software updated and maintaining backups reduces risk and improves recovery.
10. If financial cyber fraud occurs in India, quick reporting can be important.
CERT-In’s current awareness guidance similarly emphasizes strong unique passwords, MFA, caution with unsolicited links and attachments, independent verification of urgent financial requests, software updates and protection of sensitive information.
—
Useful Links and References
SanchitGurukul Static Resources
Official External References
Your feedback matters
Was this post helpful?
Discussion
0 approved comments
No approved comments yet. You can start the discussion below.
Leave a Comment
No login is required. Name and email are used for moderation/security. Your email is never displayed publicly. All comments require administrator approval.
Discover more from SanchitGurukul
Subscribe to get the latest posts sent to your email.