Posted on Leave a comment

Almost got “digitally arrested.” India needs Singapore’s playbook before the next scam call

Over a year ago, I received a call from someone claiming that an illegal parcel containing drugs was intercepted in my name. The call sounded so genuine that he managed to trap me on a continuous video call. Within minutes, I found myself under virtual arrest by a high-ranking officer of the “Mumbai Police.” I would need to stay on video call, hand over my banking details, and cooperate immediately, or face real, physical arrest.

For a few minutes, I was terrified. The voice was authoritative, the threats were specific, and the pressure was relentless. It is only because the caller made a procedural slip-up midway through the script that I realised something was off. I disconnected the call and blocked the number. I got lucky.

Also Read: Inside the dark economy of crypto scams: 2024’s most lucrative fraud tactics

Weeks later, my luck was tested again; this time on WhatsApp. A message arrived late in the evening from a US number, with the display picture showing the face of Mohan Belani, the CEO of e27.co, the company I work for. “Mohan” needed a favour: could I urgently purchase gift cards worth roughly US$600 (INR 50,000) and send him the codes? The tone, the urgency, even the manner of writing felt eerily familiar. But I paused, called the real Mohan Belani directly, and confirmed within minutes that no such request had been made. Scam averted, again.

I share these episodes not for sympathy, but because they illustrate something regulators in India can no longer afford to ignore: scams have industrialised, and they are coming through the exact same apps, the exact same DMs, the exact same marketplaces that hundreds of millions of Indians use every single day.

A crisis hiding in plain sight

Until recently, “digital arrest” scams were a full-blown national headache for Indian law enforcement. Victims ranged from ordinary citizens to a sitting High Court judge, with losses running into multiple millions of rupees. Investment scams, WhatsApp impersonation frauds, fake e-commerce listings and phishing calls dressed up as courier or customs “issues” have become so common that most Indians now know someone — a parent, a colleague, a friend — who has been targeted, if not defrauded outright.

And yet, unlike Singapore, India still does not have a binding, platform-specific regulatory framework that compels messaging apps, social media platforms and e-commerce marketplaces to proactively design against scams, rather than merely respond to them after users have already lost money.

What Singapore just did

The Singapore Police Force (SPF) recently issued new and updated Codes of Practice (COPs) for “designated online services,” to be complied with by January 31, 2027. The rules are notable precisely because they target platform design, not just takedown speed.

Messaging apps such as WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Messages and Google Meet will need to secure user consent before unknown contacts can add them to groups or channels, display contextual risk indicators for suspicious accounts, and give users tools to block or filter unknown numbers. SPF data shows messaging platforms accounted for about 23 per cent of total scam cases in Singapore in 2025, with roughly 18 per cent of government-impersonation scams occurring on WhatsApp alone.

Also Read: Phishing threats: Protecting your online shopping and banking

Social media platforms, such as Facebook, Instagram and TikTok, accounted for about 30 per cent of scam cases, with Facebook alone responsible for around 18 per cent. Under the new Social Media Code, platforms must proactively screen out ads suspected of furthering scams, verify advertisers’ identities against government records, and block financial-services ads unless the advertiser is licensed by the Monetary Authority of Singapore.

E-commerce platforms such as Carousell and Facebook Marketplace face tighter device-login consent requirements to curb account takeovers, plus the same advertising safeguards applied to social media.

Crucially, Singapore has backed these codes with real teeth: penalties of up to SGD 10 million (~US$7.83 million) per instance of non-compliance under the Online Criminal Harms Act, criminal liability for repeated breaches, and daily fines of roughly SGD 300,000 (~US$235,000) for continuing offences. Between 2024 and 2025, scam cases on designated platforms in Singapore fell by about 37 per cent — evidence that regulatory pressure on platform design actually works.

Why India needs the same medicine

India’s scam economy dwarfs Singapore’s in raw scale. We have over 850 million internet users, the largest WhatsApp user base in the world, and a booming digital payments ecosystem via UPI that scammers have learned to exploit with alarming sophistication.

Yet India’s regulatory response has largely been reactive: helplines like 1930, the Indian Cyber Crime Coordination Centre (I4C), SIM-blocking drives via the Sanchar Saathi platform, and periodic advisories from the RBI and TRAI.

These are useful, but they all operate downstream — after the scam call has already been placed, after the fraudulent ad has already run, after the fake gift-card request has already landed in someone’s WhatsApp inbox at 11 pm. What India lacks is a Singapore-style, legally binding Code of Practice that forces platforms to build friction upstream, at the point where scams originate.

Concretely, India’s Ministry of Electronics and IT (MeitY), in coordination with the Department of Telecommunications and RBI, could mandate that:

  • Messaging platforms require consent before unknown numbers can add users to groups, a direct countermeasure against the “investment tips” and fake trading groups that lure victims through unsolicited WhatsApp adds.
  • Platforms display verified indicators for government, police and judiciary-linked accounts or callers, specifically to blunt digital-arrest and government-impersonation scams like the one I encountered.
  • Social media platforms verify advertiser identity against government ID databases before allowing financial-services or investment ads to run, closing the loophole that scammers currently exploit with impunity.
  • E-commerce marketplaces tighten device-login consent to prevent account takeovers, a growing vector for fraud on Indian classifieds and resale platforms.
  • Non-compliance carries meaningful financial penalties, not just advisories that platforms can quietly ignore.

The human cost is the real argument

Statistics on millions lost and per centages of scam cases matter for policymakers. But what stays with me is the an hour of genuine fear I felt believing I was under “digital arrest,” and the split-second decision that separated me from becoming another gift-card fraud statistic. Multiply that moment by hundreds of millions of Indians online, many far less digitally literate than a tech journalist who covers scams for a living, and the scale of the problem becomes obvious.

Also Read: AI phishing is turning trust into APAC cybersecurity’s weakest link

Singapore has shown that platform-level accountability, backed by real penalties, can bend the curve on scams within a single year. India’s Digital Personal Data Protection framework and IT Rules already establish that platforms operating in the country can be compelled to act.

What is missing is the specific, enforceable Code of Practice that tells WhatsApp, Meta, Google and Indian e-commerce players exactly what “acting” means — before the next call, the next ad, the next impersonation message reaches someone who isn’t as lucky as I was.

The post Almost got “digitally arrested.” India needs Singapore’s playbook before the next scam call appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *