India cybercrime regulation

India's Supreme Court Escalates Digital-Arrest Fixes From Advisory to Deadline — But the Call 'Kill Switch' Still Needs a Feasibility Study, Not a Mandate

A four-week RBI deadline repeats an unmet February order, while MeitY and DoT are told only to study — not build — a call kill switch.

India's Digital-Arrest Crackdown, By the Numbers People of Internet Research · India 123,672 → 16,377 Complaints, 2024 vs mid-2026 Digital-arrest complaints fell fro… ₹18.05 crore Restored across 36,290 cases Money restored to victims through … 26 of 53 banks Adopted MuleHunter AI tool Uptake of RBI's AI mule-detection … 4 weeks RBI's second SOP deadline The August 2026 order repeats a Fe… peopleofinternet.com
India's Digital-Arrest Crackdown, By t… People of Internet Research · India 123,672 → 16,377 Complaints, 2024 vs mid-2026 ₹18.05 crore Restored across 36,290 cases 26 of 53 banks Adopted MuleHunter AI to… 4 weeks RBI's second SOP deadline peopleofinternet.com

Key Takeaways

A second deadline for the same SOP

On 4 August 2026, a three-judge Supreme Court bench — Chief Justice Surya Kant, Justice Joymalya Bagchi and Justice V. Mohana — issued interim directions in In Re: Victims of Digital Arrest Related to Forged Documents (2026 SCC OnLine SC 1532), the suo motu case the Court opened after a 73-year-old Ambala couple were extorted of ₹1.05 crore by callers using forged Supreme Court and Enforcement Directorate documents. The Court ordered the RBI to formally circulate, within four weeks, a Standard Operating Procedure letting banks place temporary debit holds on accounts linked to mule activity and cyber fraud, with copies to India's Cyber Crime Coordination Centre (I4C) and every High Court's Registrar General (SCC Online).

What's easy to miss is that this is not a new ask. The Court gave RBI the identical instruction on 9 February 2026, after being told roughly half of India's 53 major banks had adopted the AI-based MuleHunter mule-detection tool (AMLegals). Six months later, the SOP still doesn't exist as a formal, circulated instrument — only as an internal draft. The August order upgrades an informational request into a binding directive with a hard deadline. That escalation is itself the story: judicial patience for voluntary compliance from the banking regulator has run out.

The case for a debit-hold SOP — and its limits

The steelman here is straightforward. Mule accounts are the laundering layer that makes digital-arrest fraud work: money moves through several accounts within minutes, often before a victim realises the "arrest" was fake. RBI's own KYC and anti-money-laundering framework already treats "money mules" as a named typology, requiring banks to flag accounts opened for pass-through transfers and to escalate unusual turnover (RBI KYC/AML guidance). A standardised, mandatory freeze-and-notify procedure closes an obvious gap between detection and action.

But a debit hold is a blunt instrument applied to accounts that are, at the moment of freezing, only suspected — sometimes wrongly, since layer-two and layer-three mule accounts can belong to unwitting people whose credentials were stolen or sold. The genuine test of this SOP won't be whether RBI issues it by the new deadline; it'll be whether the final text builds in fast, low-friction appeal for account holders who are frozen in error, and a real time limit on the hold itself. A parliamentary standing committee reviewing cybercrime policy has already flagged that KYC alone hasn't stopped mule accounts and that supervision — not just new paperwork — is the missing piece; it also noted RBI's own October 2025 deadline for banks to migrate to verified .bank.in domains had, as of its review, been met by zero banks (PRS India, Cyber Crime: Ramifications, Protection and Prevention). A repeated deadline is not self-executing; enforcement capacity is the real variable.

The kill switch is a study, not a mandate — and that distinction matters

The more consequential-sounding direction — that MeitY, DoT and I4C examine a time-based "kill switch" for audio and video calls — is narrower than headlines suggest. The amicus curiae, Senior Advocate N.S. Nappinai, proposed a two-stage design: a fraud-warning pop-up at the two-to-three-hour mark, then automatic disconnection after six to twelve hours, on the reasoning that no legitimate personal or work call runs that long (The Print). The Court did not order platforms to build this. It ordered the two ministries and I4C to assess technical feasibility, efficacy and safeguards — a study mandate, not a deployment mandate, with the next status report due 16 September 2026.

That caution is warranted, and the steelman for it deserves airing: digital-arrest calls are genuinely anomalous in duration and structure, kept deliberately unbroken so the victim never has time to verify the caller's claims independently. A duration-based circuit-breaker targets that specific pattern rather than call content. But the same government reportedly declined an earlier, more invasive proposal — real-time law-enforcement alerting on suspect calls — over surveillance concerns (Bar and Bench), which is the right instinct to apply here too. Any duration cap that becomes infrastructure — rather than a temporary, narrowly targeted circuit-breaker — will also cut off legitimate long calls: telemedicine consultations, NRI family calls across time zones, elder-care check-ins, enterprise conferencing. A kill switch built into telecom or platform rails, once it exists, is trivially repurposable for other categories of "undesirable" speech — the standard slippery-slope risk with any communications infrastructure regulators build for one narrow purpose. The Court keeping this at "study feasibility" rather than "implement" is the correct posture; it should stay there unless the feasibility study can show the mechanism can be scoped tightly enough to avoid becoming general-purpose call-monitoring infrastructure.

Coordination infrastructure is the least controversial — and most useful — piece

The order's least glamorous elements are probably its most defensible: states must operationalise Cybercrime Coordination Centres and adopt the jurisdiction-free e-Zero FIR mechanism within four weeks, with I4C's assistance. This is pure state-capacity building, and the Court noted real progress — ₹18.05 crore restored across 36,290 cases through 57 banks, with the CBI tracing 67 first-layer accounts through 93 searches in 16 states (LiveLaw). Complaints have also fallen sharply — from 1,23,672 in 2024 to 58,239 in 2025 and 16,377 through 30 June 2026 — evidence that awareness campaigns and faster freezing are working, even before this order's new deadlines bite.

The pattern across all three tracks is consistent: build fast money-recovery and reporting rails now, treat the communications-layer intervention as provisional and reviewable, and hold every ministry to the same deadline discipline RBI is now facing for the second time.

Sources & Citations

  1. LiveLaw — SC directions on prevention, compensation, grievance redressal
  2. SCC Online — interim directions summary and case citation
  3. The Print — amicus kill-switch proposal
  4. Bar and Bench — separate offence, surveillance-concerns context
  5. AMLegals — RBI SOP timeline and MuleHunter AI adoption
  6. RBI — KYC norms / anti-money-mule guidance
  7. PRS India — Cyber Crime: Ramifications, Protection and Prevention