August 1, 2025
From Roswell To Real Time Cybercrime
Fifty years after the world’s first documented cybercrime, digital deception has grown bolder, leaving even the most cautious vulnerable in…
By Gautam Mengle
4 min read
Fifty years after the world's first documented cybercrime, digital deception has grown bolder, leaving even the most cautious vulnerable in a landscape where every foolproof system finds its match
The first documented instance of a cybercrime in modern history is regarded to be the case of Roswell Steffen in 1973, a teller with the Union Dime Savings Bank in the USA, who used his inside knowledge of the bank's finances and manipulated the records to steal more than $1.5 million.
Unbelievably, he got off with a light sentence and even wrote an article about his heist in a magazine a year later describing his feat. The term 'cybercrime' hadn't been invented yet, but a quote frequently attributed to him is, "For every foolproof system, there is a method for beating it."
Cut to 2025, where the names and modus operandi have evolved. But the underlying principle remains the same.
Let's look at it through the prism of some of the most prevalent cybercrimes in today's day and age.
Digital Arrest
Digital arrest is the top challenge that India is facing in terms of cybercrime, with fraudsters getting more creative, more aggressive and more audacious with each passing day. It began as a simple scam, where scammers would call you up and tell you that drugs had been found in your package sent or received via FedEx and demand money to 'settle' the matter, or as fines.
Today, the perpetrators impersonate police officials, to the point of using names of actual serving policemen and their postings, insist on video calls, make the victims install remote access apps to get more information and surveil them in real time, and have invented an entire fictitious legal process called digital arrest.
In one of the most shocking recent cybercrime cases, an 86-year-old woman from Mumbai was manipulated into transferring over Rs 20.25 crore to fraudsters over 68 days. The scam began on December 26, 2024, when criminals posing as police officers falsely accused her of money laundering, claiming her Aadhaar details had been used to open a fraudulent account. Under intense psychological pressure, she transferred the money in multiple installments, even borrowing from friends and family. The fraud came to light when her maid alerted the woman's daughter, who contacted the police. The Mumbai Police have since arrested three individuals, including a member of an international cyber fraud syndicate that used Telegram to target wealthy Indians.
To go back to our earlier case study, "For every foolproof system, there is a method for beating it." Our earlier awareness strategies were dependent on making people aware that drugs-in-parcel is a scam. Cybercriminals found a way to beat it by impersonating the one person anyone would believe — a policeman.
Phishing
We all remember those emails from supposed kings of far-off countries who claimed they wanted to give us a share of their wealth. This was one of the earliest forms of phishing, which is similar to casting a wide net in the sea and catching as many fish as possible. Today, this has become one of the biggest cybercrime ecosystems.
In 2024, phishing attacks remained a major threat to businesses in India. Cybersecurity firm Kaspersky reported over 1.99 lakh financial phishing attempts targeted at Indian businesses last year. These attacks impacted both small enterprises and large corporations alike.
Earlier, imperfect grammar used to be a sureshot giveway for phishing messages and emails. Today, we have AI-based language models that can edit your writing for you. And even if mainstream AI models like ChatGPT have ethical guardrails designed to prevent them from participating in a crime, these can be overridden with the right prompts.
Further, there are malicious AI models now. GhostGPT is an AI model that is used regularly by cybercriminals to craft phishing emails as per requirements. DeepSeek, the much-hyped Chinese competitor to ChatGPT, has zero ethical guardrails. Last month, a group of researchers entered prompts into DeepSeek, asking for everything from phishing emails to hate speech campaigns, and achieved a 100 per cent success rate!
Again, "For every foolproof system, there is a method for beating it."
Stock market advisory and part time job scams
In Mumbai alone last year, the police have registered 355 investment-related frauds in May 2024, with 91 arrests and 76 ongoing investigations, with over ₹1,420 crore lost to stock market scams.
The majority of these scams are "pig-butchering" schemes, where fraudsters pose as stock market experts and promise guaranteed returns. Victims are often targeted via social media or messaging platforms like WhatsApp and Telegram, where scammers use fake endorsements, including deep fake videos of financial influencers.
These scams began with a random number adding you to a WhatsApp group, promising 'expert advice' to make crores in the stock market. Today, they have evolved beyond our traditional awareness strategies. They pick pictures of actual advisors off the internet and design posters. These posters are then posted as paid ads on social media to hook victims. The pictures give a touch of authenticity to the scams, and the desperation of the targets to make a quick buck does the rest.
Similarly, a woman from the Gorai area in Mumbai responded to an Instagram ad promoting a part-time job that promised easy money for simple tasks, like liking videos. She was redirected to a Telegram group where scammers posed as job coordinators. Initially, the victim completed small tasks and received small payments, which encouraged her to invest in higher-paying tasks. Convinced by the initial payouts, she transferred ₹6.37 lakh in three installments.
This is just one of the many such scams that are active today. Many of these depend on convincing the victims that they are investing in cryptocurrency. For this, the scammers design bogus apps that let the victims supposedly invest, while the money is actually going into the scammers' accounts.
Which means while we are spreading awareness saying, "no job offer requires you to pay money", scammers are faking entire apps to capitalize on the current curiousity around cryptocurrency and the greed for quick money. Again, "For every foolproof system, there is a method for beating it."
The basic framework of cybercrimes that have become the biggest challenges today as not much different from the principles used by Roswell Steffen in 1973. Hence, it is high time we stopped playing catch up with the bad guys and took the fight to them instead.
Continuous intelligence gathering, both on and off the web, an increased emphasis on reporting every crime so that our knowledge base increases, and an out-of-the-box approach towards awareness can all contribute towards a strategy that is more proactive and less reactive.