The Role of Banks in Controlling Cybercrime: It Is Now Time to Fix Accountability
India is rapidly moving towards a digital economy. Today, crores of people are using internet banking, UPI, mobile banking, and digital payments. But along with this, there has also been a rapid increase in cases of cyber fraud, fake accounts, money mule accounts, online scams, and financial crimes. The hard-earned money of lakhs of people reaches the accounts of cybercriminals within just a few minutes, and is later withdrawn or transferred through different accounts.
In such a situation, the most important question is: what exactly is the role of the banking system? When almost every cybercrime involves the use of one or more bank accounts, is it enough to simply catch the criminals, or should the banking system also be made more accountable?
The Connection Between Cybercrime and Bank Accounts
Today, fake or suspicious bank accounts are used in most cybercrimes. Money obtained through online fraud is first deposited into these accounts and is then transferred through multiple accounts. If banks can identify such accounts at the initial stage, a large number of cybercrimes can be prevented.
The problem is that when an account is opened, there is often not enough verification of the customer’s background, source of income, business, and expected transaction pattern. As a result, such accounts become an easy channel for criminals to operate through.
Not Just KYC, But Effective KYC Is Needed
At present, KYC, or Know Your Customer, has largely become a formality when opening a bank account. There is a need to make it a continuous system rather than a one-time process.
The RBI should ensure regular re-KYC of all savings accounts so that the address, mobile number, business, source of income, and estimated annual income remain updated.
If transactions worth lakhs of rupees suddenly start taking place in an account that has declared a much lower income, it should automatically become a matter for investigation.
Income-Based Transaction Profiling
The banking system should create an income- and business-based transaction profile for every savings account.
For example, if a person declares a monthly income of ₹40,000 and suddenly ₹5–10 lakh is deposited into their account, the bank should automatically receive an alert and verify the source of the funds with the account holder.
The purpose should not be to harass ordinary customers, but to identify suspicious financial activity at an early stage.
Real-Time Transaction Monitoring Should Be Made Mandatory
Today, most banks are technologically capable enough to identify unusual activities immediately. Even then, there are many cases where money linked to cybercrime is transferred through several accounts within a few hours and eventually disappears.
Banks should implement real-time monitoring systems based on Artificial Intelligence and data analytics. These systems should automatically generate alerts in situations such as:
- Sudden large transactions
- Repeated transfers within a short period
- Activity in accounts being operated from different states
- Large transactions suddenly taking place in an account that had remained inactive for a long period
- Suspicious UPI and IMPS transactions
In such cases, a system can be developed under which the funds are held for a limited period and verification is carried out.
Identifying Money Mule Accounts
A large number of cybercrimes involve so-called “money mule” or rented bank accounts. These are accounts that some people allow others to use in exchange for a commission.
Banks should develop special algorithms to identify such accounts.
Accounts where money continuously comes in from different sources and is immediately transferred elsewhere should automatically be placed in a high-risk category and investigated.
Bank Employees Must Also Be Held Accountable
The credibility of the banking system can remain intact only when employee accountability is clearly defined.
If negligence or collusion by a bank employee is found in the opening of a fake account, suspicious account, or an account connected with cybercrime, strict departmental and legal action should be taken against that employee.
The following system can be implemented:
- A digital record of the employee who opened each account should be securely maintained.
- Whenever a suspicious account is identified, the role of the concerned employee should be investigated.
- If an employee deliberately ignores banking rules, they should be prohibited from working in the banking sector for a defined period.
- In serious cases, criminal proceedings should be initiated.
Aadhaar-Based Integrated Banking Monitoring
At present, a person can operate multiple accounts across different banks. This makes it difficult to track the financial transactions of cybercriminals.
The RBI and banks should develop a secure and regulatorily coordinated system for accounts linked with Aadhaar and PAN. If one account is found to be involved in cybercrime, the other accounts of the same person in different banks should also be immediately examined so that suspicious transactions can be identified in time.
Similarly, if a businessman takes a loan of ₹10 crore or more from a bank, under RBI rules, payment facilities on their other bank accounts are restricted and their deposits are transferred to the lending bank according to the prescribed system.
When such a coordinated banking mechanism is possible for large loan accounts, a secure inter-bank coordination system for savings accounts can also be developed, subject to appropriate legal provisions, privacy safeguards, and regulatory controls.
This would help prevent fraudulently obtained money from being rapidly transferred across different accounts and would make it possible to control cybercrime more effectively.
Re-Verification of POS Machines and Merchant Accounts
The misuse of POS machines and merchant accounts has also been seen in several cybercrime cases. Therefore, banks should physically verify them from time to time.
- POS machines should only be issued to accounts that have genuine business activities.
- The merchant’s business should be verified.
- Inactive or suspicious POS machines should be immediately deactivated.
- POS machines should primarily be linked to current accounts.
Centralized Cyber Fraud Response System
The first few hours are the most critical in a cybercrime case. If the fraudulent money is stopped immediately, the victim can get relief.
For this, there should be an integrated real-time response system connecting banks, the RBI, police, the Income Tax Department, and the cybercrime portal. This would ensure that information about suspicious transactions immediately reaches the relevant agencies and that further transfer of the money can be stopped.
Money obtained through cyber fraud can reach multiple bank accounts, and sometimes even foreign countries, within just a few minutes.
Therefore, when there is an unusual foreign transfer or a large amount suddenly enters an inactive account, additional verification, a temporary hold, and time-bound investigation should be made mandatory.
The responsibility of both the sending bank and the receiving bank should be clearly defined. RBI guidelines, AI-based fraud monitoring, and better inter-bank coordination must be strictly followed.
Compared to India’s population and the scale of modern criminals, the strength of the police force is considerably inadequate. There is a need to increase the strength of the police in India to a level that is even higher than international standards.
At the same time, their modernization is extremely important, both in terms of technology and weapons, along with continuous training.
Banks and mobile service provider companies are also equally responsible for preventing cybercrime.
Banks must strictly follow RBI rules, while mobile companies have access to important information such as SIM location, international roaming, and device changes.
If negligence by these institutions is found in any cybercrime case, the responsibility of the concerned officials should be fixed and an impartial investigation should be conducted.
Cybercrime has now taken the form of a cancer and a serious social menace. If strict action is not taken against it, the day is not far when the lifelong savings of people in India, particularly senior citizens, will continue to be transferred abroad on a large scale through cyber fraud.
Conclusion
If banks and mobile service provider companies are made more proactive, accountable, and technologically capable, cyber fraud cases can be reduced significantly. At the same time, this will further strengthen public trust in the digital economy.
Rotarian Suneel Dutt Goyal
Director General, Imperial Chamber of Commerce and Industry
Ex. Vice President, Jaipur Stock Exchange Limited
Jaipur, Rajasthan
साइबर अपराधों पर लगाम लगाने में बैंकों की भूमिका: अब जवाबदेही तय करने का समय
भारत तेजी से डिजिटल अर्थव्यवस्था की ओर बढ़ रहा है। आज करोड़ों लोग इंटरनेट बैंकिंग, यूपीआई, मोबाइल बैंकिंग और डिजिटल भुगतान का उपयोग कर रहे हैं। लेकिन इसी के साथ साइबर धोखाधड़ी, फर्जी खातों, मनी म्यूल (Money Mule) खातों, ऑनलाइन ठगी और आर्थिक अपराधों के मामलों में भी तेज़ी से वृद्धि हुई है। लाखों लोगों की मेहनत की कमाई कुछ ही मिनटों में साइबर अपराधियों के खातों में पहुंच जाती है और बाद में उसे विभिन्न खातों के माध्यम से निकाल लिया जाता है।
ऐसी स्थिति में सबसे महत्वपूर्ण प्रश्न यह है कि आखिर बैंकिंग प्रणाली की भूमिका क्या है? जब लगभग हर साइबर अपराध में किसी न किसी बैंक खाते का उपयोग होता है, तो क्या केवल अपराधियों को पकड़ना पर्याप्त है या बैंकिंग व्यवस्था को भी अधिक जवाबदेह बनाया जाना चाहिए?
साइबर अपराध और बैंक खातों का संबंध
आज अधिकांश साइबर अपराधों में फर्जी या संदिग्ध बैंक खातों का उपयोग होता है। ऑनलाइन ठगी की राशि पहले इन्हीं खातों में जमा होकर बाद में कई खातों के माध्यम से स्थानांतरित कर दी जाती है। यदि बैंक प्रारंभिक स्तर पर ऐसे खातों की पहचान कर लें, तो बड़ी संख्या में साइबर अपराध रोके जा सकते हैं। समस्या यह है कि खाता खोलते समय ग्राहक की पृष्ठभूमि, आय के स्रोत, व्यवसाय और संभावित लेन-देन का पर्याप्त सत्यापन नहीं होता, जिससे ऐसे खाते अपराधियों के लिए आसान माध्यम बन जाते हैं।
केवल केवाईसी नहीं, प्रभावी केवाईसी की आवश्यकता
वर्तमान में बैंक खाता खोलते समय केवाईसी (Know Your Customer) केवल औपचारिकता बनकर रह जाती है। आवश्यकता है कि इसे एक बार की प्रक्रिया नहीं, बल्कि निरंतर व्यवस्था बनाया जाए। आरबीआई को सभी बचत खातों की नियमित री-केवाईसी सुनिश्चित करनी चाहिए, ताकि पता, मोबाइल नंबर, व्यवसाय, आय का स्रोत और अनुमानित वार्षिक आय अद्यतन रहें। यदि घोषित आय के विपरीत खाते में अचानक लाखों रुपये का लेन-देन होने लगे, तो वह स्वतः जांच का विषय बनना चाहिए।
आय आधारित ट्रांजैक्शन प्रोफाइलिंग
बैंकिंग प्रणाली में प्रत्येक बचत खाते के लिए आय और व्यवसाय आधारित ट्रांजैक्शन प्रोफाइल बनाई जानी चाहिए। यदि ₹40,000 मासिक आय घोषित करने वाले व्यक्ति के खाते में अचानक ₹5–10 लाख जमा हों, तो बैंक को स्वतः अलर्ट मिले और खाताधारक से धन के स्रोत की पुष्टि की जाए। इसका उद्देश्य सामान्य ग्राहकों को परेशान करना नहीं, बल्कि संदिग्ध वित्तीय गतिविधियों की समय रहते पहचान करना होना चाहिए।
रियल–टाइम ट्रांजैक्शन मॉनिटरिंग अनिवार्य बने
आज अधिकांश बैंक तकनीकी रूप से इतने सक्षम हैं कि वे असामान्य गतिविधियों को तुरंत पहचान सकते हैं। फिर भी कई बार साइबर अपराध से जुड़ी राशि कुछ घंटों में ही कई खातों में स्थानांतरित होकर गायब हो जाती है।
बैंकों को आर्टिफिशियल इंटेलिजेंस और डेटा एनालिटिक्स आधारित रियल-टाइम मॉनिटरिंग सिस्टम लागू करना चाहिए जो निम्न स्थितियों में स्वतः अलर्ट जारी करे—
- अचानक बड़े लेन-देन
- कम समय में बार-बार ट्रांसफर
- अलग-अलग राज्यों से संचालित खातों में गतिविधि
- लंबे समय तक निष्क्रिय रहे खाते में अचानक भारी ट्रांजैक्शन
- संदिग्ध यूपीआई और आईएमपीएस लेन-देन
ऐसे मामलों में राशि को सीमित अवधि के लिए होल्ड करने तथा सत्यापन की व्यवस्था विकसित की जा सकती है।
मनी म्यूल खातों की पहचान
साइबर अपराधों में बड़ी संख्या में तथाकथित “मनी म्यूल” या किराए के बैंक खातों का उपयोग होता है, जिन्हें कुछ लोग कमीशन के लालच में दूसरों को इस्तेमाल करने देते हैं। ऐसे खातों की पहचान के लिए बैंकों को विशेष एल्गोरिदम विकसित करने चाहिए। जिन खातों में लगातार विभिन्न स्रोतों से धन आए और तुरंत आगे भेज दिया जाए, उन्हें स्वतः उच्च जोखिम श्रेणी में रखकर जांच की जानी चाहिए।
बैंक कर्मचारियों की जवाबदेही तय हो
बैंकिंग प्रणाली की विश्वसनीयता तभी बनी रह सकती है जब कर्मचारियों की जवाबदेही स्पष्ट हो।
यदि किसी फर्जी खाते, संदिग्ध खाते या साइबर अपराध से जुड़े खाते के खुलने में किसी कर्मचारी की लापरवाही या मिलीभगत सामने आती है, तो उसके खिलाफ सख्त विभागीय और कानूनी कार्रवाई होनी चाहिए।
इसके लिए निम्न व्यवस्था लागू की जा सकती है –
- प्रत्येक खाते को खोलने वाले कर्मचारी का डिजिटल रिकॉर्ड सुरक्षित रखा जाए।
- संदिग्ध खाते मिलने पर संबंधित कर्मचारी की भूमिका की जांच हो।
- जानबूझकर नियमों की अनदेखी करने पर बैंकिंग क्षेत्र में निश्चित अवधि तक कार्य करने पर प्रतिबंध लगाया जाए।
- गंभीर मामलों में आपराधिक मुकदमा चलाया जाए।
आधार आधारित समेकित बैंकिंग निगरानी
वर्तमान में एक व्यक्ति विभिन्न बैंकों में कई खाते संचालित कर सकता है, जिससे साइबर अपराधियों के वित्तीय लेनदेन को ट्रैक करना कठिन हो जाता है। आरबीआई और बैंकों को आधार एवं पैन से जुड़े खातों का सुरक्षित, नियामकीय समन्वित तंत्र विकसित करना चाहिए, ताकि किसी एक खाते के साइबर अपराध में शामिल पाए जाने पर उसके अन्य बैंकों में खुले खातों की भी तुरंत जांच हो सके और संदिग्ध लेनदेन की समय रहते पहचान की जा सके।
इसी प्रकार, यदि कोई व्यापारी किसी बैंक से ₹10 करोड़ या उससे अधिक का ऋण लेता है, तो आरबीआई के नियमों के तहत उसके अन्य बैंक खातों पर भुगतान सुविधा सीमित कर दी जाती है तथा उसकी जमा राशि निर्धारित व्यवस्था के अनुसार ऋणदाता बैंक को स्थानांतरित की जाती है। जब बड़े ऋण खातों के लिए ऐसी समन्वित बैंकिंग व्यवस्था संभव है, तो उपयुक्त कानूनी प्रावधानों, गोपनीयता सुरक्षा और नियामकीय नियंत्रणों के साथ बचत खातों के लिए भी सुरक्षित इंटर-बैंक समन्वय प्रणाली विकसित की जा सकती है। इससे ठगी की राशि को विभिन्न खातों में तेजी से स्थानांतरित करने पर रोक लगेगी और साइबर अपराधों पर प्रभावी नियंत्रण संभव होगा।
पीओएस मशीन और व्यापारी खातों का पुनः सत्यापन
कई साइबर अपराधों में पीओएस मशीनों और व्यापारी खातों का दुरुपयोग भी सामने आया है। इसलिए बैंकों को समय-समय पर इनका भौतिक सत्यापन करना चाहिए।
- पीओएस मशीन केवल वास्तविक व्यापारिक गतिविधियों वाले खातों को जारी की जाए।
- व्यापारी के व्यवसाय का सत्यापन किया जाए।
- निष्क्रिय या संदिग्ध पीओएस मशीनों को तत्काल बंद किया जाए।
- पीओएस मशीनों को प्राथमिक रूप से करंट अकाउंट से जोड़ा जाए।
केंद्रीकृत साइबर फ्रॉड रिस्पॉन्स सिस्टम
साइबर अपराध में शुरुआती कुछ घंटे सबसे महत्वपूर्ण होते हैं। यदि ठगी की राशि तुरंत रोकी जाए, तो पीड़ित को राहत मिल सकती है। इसके लिए बैंकों, आरबीआई, पुलिस, आयकर विभाग और साइबर क्राइम पोर्टल के बीच एकीकृत रियल-टाइम रिस्पॉन्स सिस्टम होना चाहिए, ताकि संदिग्ध लेनदेन की सूचना तुरंत संबंधित एजेंसियों तक पहुंचे और राशि के आगे स्थानांतरण को रोका जा सके।
साइबर ठगी का पैसा कुछ ही मिनटों में कई बैंक खातों और कई बार विदेशों तक पहुंच जाता है। इसलिए असामान्य विदेशी ट्रांसफर या निष्क्रिय खातों में अचानक बड़ी राशि आने पर अतिरिक्त सत्यापन, अस्थायी रोक और समयबद्ध जांच अनिवार्य होनी चाहिए। भेजने और प्राप्तकर्ता दोनों बैंकों की जिम्मेदारी तय हो तथा आरबीआई के दिशा-निर्देशों, AI आधारित फ्रॉड मॉनिटरिंग और बेहतर इंटर-बैंक समन्वय का कड़ाई से पालन किया जाए।
भारत की आबादी एवं आधुनिक अपराधियों के मुकाबले में पुलिस के संख्या बल में काफी कमी है। आवश्यकता है कि पुलिस की संख्या में वृद्धि अंतरराष्ट्रीय मानकों से भी अधिक भारत में की जाए। साथ ही उनका अत्याधुनिकीकरण, चाहे वह तकनीक के हिसाब से हो या हथियारों के, तथा उनकी लगातार ट्रेनिंग देते रहना बहुत आवश्यक है।
साइबर अपराधों की रोकथाम में बैंक और मोबाइल सेवा प्रदाता कंपनियां भी समान रूप से जवाबदेह हैं। बैंकों को आरबीआई के नियमों का कड़ाई से पालन करना चाहिए, जबकि मोबाइल कंपनियों के पास सिम की लोकेशन, इंटरनेशनल रोमिंग और डिवाइस परिवर्तन जैसी महत्वपूर्ण जानकारी उपलब्ध होती है। किसी भी साइबर अपराध में इन संस्थाओं की लापरवाही पाए जाने पर संबंधित अधिकारियों की जवाबदेही तय कर निष्पक्ष जांच होनी चाहिए।
साइबर क्राइम अब कैंसर और नासूर का रूप ले चुका है। यदि इस पर कठोर कार्रवाई नहीं हुई, तो वह समय दूर नहीं जब साइबर ठगी के माध्यम से भारत, विशेषकर बुजुर्गों की जीवनभर की बचत, बड़े पैमाने पर विदेशों में पहुंचती रहेगी।
निष्कर्ष
यदि बैंकिंग एवं मोबाइल सेवा प्रदाता कंपनियों को सक्रिय, जवाबदेह और तकनीकी रूप से अधिक सक्षम बनाई जाए, तो साइबर ठगी के मामलों में उल्लेखनीय कमी लाई जा सकती है और डिजिटल अर्थव्यवस्था में जनता का विश्वास और अधिक मजबूत होगा।
रोटेरियन सुनील दत्त गोयल
महानिदेशक, इम्पीरियल चैंबर ऑफ़ कॉमर्स एंड इंडस्ट्री,
पूर्व उपाध्यक्ष, जयपुर स्टॉक एक्सचेंज लिमिटेड,
जयपुर, राजस्थान


















