The most dangerous threat to Indian democracy may not arrive as a fabricated post written in the basement of a foreign intelligence agency. It may begin with an ordinary-looking transaction in an online marketplace: a batch of mature social media accounts, verified Indian mobile numbers, stolen know-your-customer documents, access to a compromised server, or a database containing names, addresses, languages, and payment histories. Each item has a legitimate digital shadow. Assembled by a hostile operator, they become the raw material of an influence campaign.
For years, democracies treated influence operations largely as a content problem. They searched for false claims, checked facts, labelled inauthentic accounts, and removed manipulated videos. These measures remain necessary, but they intervene after the machinery has already been built. By the time a lie appears on a citizen’s screen, someone has usually obtained identities, infrastructure, money-moving channels, targeting data, and a distribution network. The visible post is the last link in a much longer chain.
That demands a change in doctrine. A modern influence operation is not only propaganda; it is also a commercial supply chain. At one end sits an actor seeking to erode confidence, sharpen communal fault lines, or disrupt a national decision. At the other is a fluid market of cybercriminals who sell access, anonymity, automation, and scale. The buyer need not build every capability. It can rent the parts, combine them quickly, and discard them when exposed.
India has particular reason to grasp this shift. Its digital transformation has connected hundreds of millions of people to government services, banking, commerce, and public debate. That achievement has made the country more accessible and productive. It has also created an immense attack surface in which a stolen identity can become a bank account, a SIM card can become a broadcast tool, and a leaked database can become a map of social vulnerability. The challenge is not to retreat from digitisation, but to defend the trust on which it depends.
India has already paid the price when falsehood became action
This is not a speculative danger. In August 2012, amid violence in Assam, doctored or miscaptioned images and videos circulated alongside threats of retaliation. Thousands of students and workers from the Northeast rushed to leave Bengaluru, Mumbai, and other cities, crowding railway stations in fear. The Union government ordered 245 webpages and social media links blocked. Whatever the origin of each item, the episode demonstrated that digital content could trigger a rapid, physical movement of people across the country.
The lesson is not that the internet alone created the crisis; the underlying violence and anxieties were real. Rather, digital networks collapsed the distance between rumour and action. They gave decontextualised images the authority of eyewitness evidence, allowed threats to travel through trusted personal groups, and generated a sense that everybody else already knew danger was imminent. This happened before generative artificial intelligence made fabrication cheap and multilingual.
Muzaffarnagar in 2013 offered an even graver warning. An old video from Pakistan showing two young men being assaulted was circulated as if it depicted the killing of local youths in Kawal. It entered an environment already charged by anger, mobilisation and inflammatory speech. The subsequent communal violence killed more than 60 people and displaced tens of thousands. The clip was not the sole cause, but its misuse shows how a borrowed image can supply apparent proof for a local narrative and accelerate an existing conflict.
During the 2024 Lok Sabha election, the same logic appeared in a more technically sophisticated form. Deepfake videos falsely showed actors Aamir Khan and Ranveer Singh criticising Prime Minister Narendra Modi and supporting the Opposition. An altered video of Home Minister Amit Shah misrepresented his remarks on reservations, prompting police cases and arrests. These examples did not determine the election. They did, however, reveal how synthetic or deceptively edited media can exploit celebrity recognition, partisan loyalty, and the speed of campaign communication.
These incidents are not identical, and not all were directed by a nation-state. That is precisely the point. Infrastructure developed for profit, party competition, or local incitement can also be acquired by a foreign intelligence service, a proxy group, or an ideological network. The strategic risk lies in the shared ecosystem: stolen data, false personas, emotionally charged content, trusted channels, and weak points in crisis communication.
Cyber fraud is a training ground for influence operations
So-called “digital arrest” frauds show how thoroughly online crime has absorbed the methods of psychological operations. Impersonators pose as police officers, Central Bureau of Investigation officials, Reserve Bank of India representatives, or other authorities. They place victims under prolonged video surveillance, manufacture urgency, isolate them from family, and demand transfers to supposedly safe accounts. The technical tools are ordinary. The decisive capability is behavioural: creating fear, borrowing institutional legitimacy, and controlling the victim’s information environment.
In late August 2026, the Directorate of Enforcement said an investigation that began with a Goa resident who lost more than ₹2.6 crore in such a fraud had uncovered bank-account trails linked to 163 first information reports across 20 states and union territories. One victim’s case was therefore not a self-contained episode; it was an entry point into a distributed national network. This is the organisational pattern that also makes influence operations difficult to attribute and disrupt.
The scale is national, not anecdotal. By 30 June 2026, the government said it had blocked 15.75 lakh SIM cards and 5.77 lakh handset IMEIs associated with cybercrime-related activity. Those numbers are a measure of enforcement but also of industrial capacity. A market able to provision identities and devices at that volume can support fraud today and coordinated political manipulation tomorrow.
Illegal digital lending offers another warning. A 2021 RBI working group noted that a sweep of more than 80 app stores had identified around 1,100 digital lending apps available to Indian Android users, about 600 of them illegal. Many predatory apps sought access to contact lists, photographs, location data and device information, then used that data to harass or shame borrowers. The business model turned personal information into leverage.
For national security planners, the significance extends beyond financial loss. The operator of an illicit lending network may hold verified phone numbers, family relationships, preferred languages, employment details, photographs, and indicators of financial stress. That dataset can be repurposed to craft convincing messages, select susceptible targets, impersonate trusted contacts, or identify communities most likely to react to a rumour. Cybercrime is therefore not merely adjacent to influence activity. It is a laboratory for its techniques and a marketplace for its inputs.
The supply chain behind the lie
Consider how a combined operation might unfold during a border crisis, terrorist attack, or election. Partial information is stolen from a government contractor. A genuine document is released beside one that has been subtly altered. Indian mobile numbers and aged social media accounts seed the material in several languages. Paid creators and automated accounts manufacture visibility. Fraudulent news portals give the claim a searchable history. Mule accounts and cryptocurrency pay suppliers, while denial-of-service attacks slow official websites at the moment citizens seek confirmation.
Such an operation has five interlocking layers. The first is access to authentic stolen or leaked material. The second is identity, supplied through established accounts, local numbers, and forged documents. The third is distribution through groups, influencers, advertising tools, and automated amplification. The fourth is finance through mules, prepaid instruments, and opaque digital payments. The fifth is narrative: the message designed to exploit a real grievance or uncertainty. Remove one layer, and the attack becomes slower, costlier, and less credible.
Artificial intelligence does not create this threat, but it accelerates it. It can produce text, images, cloned voices, and videos rapidly in many languages. Yet even the most persuasive fake still needs a path to the public, a plausible identity behind it and money to sustain its spread. Distribution, identity, and finance remain bottlenecks. They are also areas in which intelligence-led law enforcement can often act more objectively than it can when judging the truth or political acceptability of speech.
In this kind of operation, a computer intrusion is only the opening move. The ultimate target is public trust in government, the armed forces, the police, the media, the electoral process, and India’s capacity to live with difference. A cyber incident becomes a national security event when stolen access is converted into manipulated behaviour. India must therefore protect not only systems and data but also the decision-making environment of its citizens.
Defending India without weakening democracy
The first requirement is to stop managing each threat in a separate institutional drawer. Cyber fraud, espionage, sabotage, and influence activity may be different phases of the same campaign. India needs a standing mechanism that connects the Indian Computer Emergency Response Team, the Indian Cyber Crime Coordination Centre, the Election Commission of India, the RBI, the telecommunications authorities, state police forces, intelligence agencies, and major technology platforms. Its purpose should be operational fusion: seeing patterns early enough to intervene.
An effective warning system would correlate indicators that are usually examined apart: a sudden surge in SIM procurement, new mule accounts, domains imitating official websites, a leak from a public database, compromised verified accounts, and coordinated multilingual posts. No single indicator proves an influence operation. Their convergence, especially around a sensitive event, may justify a rapid technical and investigative response.
The second requirement is to move from chasing individual posts to disrupting the infrastructure that can deliver them to millions. Authorities should map and target bulletproof hosting providers, residential proxy networks, SIM farms, stolen-account brokers, malicious app distributors, and payment laundries. Asset seizures, domain suspensions, number blocking, and action against repeat facilitators can deny capability without making the government the arbiter of every contested political claim.
India must also treat personal data as a national security asset. A breached database is not only a privacy failure. Phone numbers, addresses, preferred languages, workplaces, and usage patterns allow an attacker to make a message feel intimate and credible. Data minimisation, stronger security obligations, prompt breach reporting, and meaningful penalties are therefore part of democratic resilience, not merely regulatory compliance.
Every public institution and critical operator should maintain authenticated, redundant channels for crisis communication. If a website is unavailable, an account is compromised or a forged order circulates in an authority’s name, citizens must know where to verify it. Pre-announced channels, digitally signed bulletins, consistent visual identifiers, and trained multilingual spokespeople can shorten the dangerous interval in which a rumour faces no authoritative competition.
Election periods require a specific protocol for synthetic media. The Election Commission should be able to convene a rapid-response cell with forensic specialists, platform representatives, and multilingual communicators. When a suspicious video emerges, the priorities should be to preserve evidence, determine whether it is manipulated, notify affected parties, and issue a clear public assessment. Speed matters, but so do transparency, due process, and a record that can be reviewed after polling.
India’s federal character makes local capacity indispensable. A harmful message in Assamese, Bengali, Marathi, Tamil, or another Indian language may not be recognised quickly in New Delhi. State cyber units need stronger forensic and analytical capabilities; district administrations need practiced crisis-communication plans; and local journalists and civil-society groups need trusted points of contact. Resilience is strongest when the first credible response comes from an institution the affected community already knows.
There is an important democratic advantage to this approach. Content moderation inevitably raises legitimate questions about free expression and the state’s power to define truth. Action against identity theft, criminal servers, fraudulent payment chains, unauthorised access and coordinated impersonation rests on clearer evidence of unlawful conduct. The aim should be to constrain deceptive capability while protecting vigorous political argument, criticism, and satire.
No country can do this alone. The server may be in one jurisdiction, the payment processor in a second, the account operator in a third, and the victims in India. New Delhi should deepen rapid evidence sharing, asset tracing, and joint disruption with trusted partners. India–Israel cooperation can contribute expertise in threat intelligence, cyber forensics, and protection of critical infrastructure, while broader regional and multilateral arrangements are essential for reach and legitimacy.
The objective is not the illusion of eliminating the threat. It is to change its economics: raise costs, reduce scale, slow mobilisation and weaken trust between buyers and sellers. Seizing assets, poisoning criminal marketplaces with uncertainty, blocking cash-out routes, and prosecuting enabling brokers can make an operation less reliable at the moment a hostile actor needs it most.
The next battle for India’s public consciousness may not announce itself as warfare. It may arrive as a package of services purchased online, paid for through concealed channels, and activated through identities stolen from ordinary citizens. India’s most effective defence will therefore begin before the first viral falsehood appears—by dismantling the market that gives a lie its identity, infrastructure, financing, and reach. Protecting that ecosystem of trust is now as central to national security as protecting the network itself.
