
Fraud can cross districts and borders in seconds. The caller's claimed location is never proof of identity.
Cyber fraud hotspots India 2026 is not a simple list of villages where every scammer lives. It is a map of investigated networks, reusable scripts, suppliers of SIMs and accounts, and money trails that cross state and national borders. Jamtara became the best known symbol. Parts of Mewat, Bharatpur, Deeg, and Mathura later appeared repeatedly in police cases. Now Myanmar and Cambodia add a trafficking and forced labor dimension.
The central safety lesson is not to fear a location or stereotype its people. It is to recognize the industrial process behind a fraudulent call. Organized networks divide work, repeat persuasive scripts, and move stolen money through mule accounts. Once you see the process, the pressure tactics become much easier to interrupt.
The Geography of Indian Cybercrime
India cyber crime geography changes as police raid one cluster and operators relocate, recruit elsewhere, or sell tools remotely. MHA says I4C has created seven Joint Cyber Coordination Teams for hotspots and cross-jurisdiction problems, including teams for Mewat and Jamtara. That official structure confirms these areas matter operationally, but it does not mean most people there participate in crime.
The map is also more complicated than a call's phone number. Spoofed calls can display an Indian number while originating abroad. Scripts, phishing pages, SIMs, mule accounts, callers, and cash handlers may each sit in a different place. A modern Indian cybercrime hub 2026 is therefore better understood as a network node, not one headquarters.

Illustrative map based on locations repeatedly identified in police investigations and reporting. It is not a live crime heat map.
Jamtara, Jharkhand: India's Original Scam Village
How Jamtara Became Famous
Jamtara cyber crime India first became shorthand for phone phishing operations in rural Jharkhand. Callers posed as bank officers, told victims that an account or card would be blocked, and requested card details and OTPs. The Netflix series Jamtara: Sabka Number Ayega later took this story into popular culture.
The reality continued evolving after the older OTP script became familiar. In January 2025, The Indian Express documented the "DK Boss" investigation. Jamtara Police said six arrested suspects were linked to a syndicate distributing malicious Android apps that imitated banks and government schemes. Police connected the module with hundreds of complaints. That case shows why Jharkhand cyber fraud India can no longer be reduced to one person asking for an OTP.
The Jamtara Operation Model
To understand how scam networks operate India, think of a small supply chain. One participant collects or buys phone numbers. Another arranges SIM cards, fake documents, APK files, or phishing links. Callers follow a practiced script. Mule account recruiters provide bank accounts. Other members rapidly transfer or withdraw the proceeds.
- Choose a believable identity: bank support, police, courier, telecom provider, government scheme, or employer.
- Create a crisis: account suspension, parcel seizure, KYC expiry, arrest, or lost job opportunity.
- Isolate the victim: demand secrecy, keep the call active, or move the chat to WhatsApp or Telegram.
- Capture value: obtain an OTP, UPI PIN, card credential, remote access, app installation, or direct transfer.
- Layer the money: route funds through multiple mule accounts before cash withdrawal or further transfer.
The technology varies, but the psychology stays remarkably stable: authority, urgency, secrecy, and fear.
Mewat, Haryana and Rajasthan: The New Jamtara
Mewat cyber fraud India refers to cases traced across a cultural region that includes parts of Haryana and Rajasthan. In 2021, The Indian Express reported 412 complaints under investigation around two Nuh villages, with police describing a network that had allegedly collected about ₹6 crore during the lockdown period.
By 2024, attention had shifted further into Deeg and the wider Bharatpur range. India Today reported an I4C finding that 19 percent of fraud cases reported in February 2024 originated from Deeg. Police operations linked local modules to sextortion, fake customer care, marketplace scams, impersonation, and SIM supply. Treat this as a dated investigative snapshot, not a permanent share of national crime.
Why do clusters form? Police reporting points to peer recruitment, shared know-how, access to fraudulent SIMs and bank accounts, and the visibility of quick illegal income where legitimate opportunities can be limited. None of that excuses crime. It does explain how a technique can spread through social ties, much like any informal trade. It also explains why a raid may disrupt callers without eliminating the suppliers and money routes behind them.
Beyond India: The Southeast Asian Scam Compound Connection
Myanmar and Cambodia: Where Indian Workers Are Trafficked
The phrase Cambodia Myanmar scam India hides a crucial distinction: some Indians operating scams abroad are trafficking victims. In May 2026, the CBI said it was investigating an organized trafficking network that lured Indian nationals with high-paying jobs and sent them to scam compounds mainly in Myanmar and Cambodia. The agency described passport confiscation, restricted movement, physical and psychological abuse, forced cyber fraud, and ransom demands.
This was not a new warning. In 2022, the Ministry of External Affairs described Indians trapped near Myawaddy after fake data-entry job offers. It said victims were moved through Thailand, held under restricted conditions, and forced into digital and crypto scams. Some reported paying thousands of US dollars for release.
The Fake Job Offer to Scam Compound Pipeline
- A social media post or agent advertises a high salary for data entry, digital marketing, gaming support, or customer service.
- The recruiter conducts a quick online interview and asks the candidate to travel on a tourist or visit visa.
- Handlers move the worker across a border or into a controlled compound.
- Passports and phones may be seized, and daily scam targets are imposed.
- Workers are forced to build fake relationships, promote investments, or impersonate support agents.
Verify any overseas recruiter through official channels, insist on a lawful employment visa, and review the MEA advisory before travel. Read RakshaAI's fake job scam guide for the offer-letter and recruiter checks.
How Knowing This Protects You
Key cyber fraud hotspots in India and what investigated networks have been associated with:
- Jamtara, Jharkhand: phone phishing, bank impersonation, OTP theft, and malicious app distribution
- Mewat region in Haryana and Rajasthan: script-based impersonation, sextortion, marketplace, and phone fraud
- Bharatpur and Deeg, Rajasthan: fake customer care, sextortion, impersonation, and related fraud modules
- Urban call centers: investment, technical support, loan, and stock market fraud
- Myanmar and Cambodia compounds: transnational scams, including operations using trafficked workers
- Distributed online networks: tool sellers, SIM suppliers, mule recruiters, callers, and cash handlers working from different places
Understanding the operation model helps you recognize the scripts and tactics used against you. A location label cannot verify a caller. Your defense is behavioral: stop when anyone creates panic, requests secrecy, asks you to install an app, or demands an OTP, UPI PIN, screen share, or transfer.
If someone claims to be police, CBI, customs, or TRAI, end the call and contact the organization using a number from its official website. India has no lawful process called a digital arrest over a video call. If money has already moved, call 1930 immediately and file at cybercrime.gov.in.
What India Is Doing to Shut These Networks Down
MHA says I4C coordinates banks, payment intermediaries, telecom providers, and police through the Cyber Fraud Mitigation Centre. Its Joint Cyber Coordination Teams include Mewat and Jamtara. The Suspect Registry shares identifiers and mule-account intelligence with participating institutions, while 1930 and the financial fraud reporting system help institutions act on money trails.
The latest verified official snapshot available by this article's 9 July 2026 publication date reported more than 12.94 lakh SIM cards and 3.03 lakh IMEIs blocked by 31 January 2026. MHA also reported more than ₹8,690 crore saved across over 24.65 lakh complaints. Separately, 27.37 lakh Layer 1 mule accounts had been shared through the Suspect Registry, with ₹9,518.91 crore in declined transactions. These are different measures and should not be added together.

Editorial note: this supplied graphic combines figures from different government snapshots and labels them as 2025 results. Use the verified, dated figures in the paragraph above for current comparison.
Real Cases, Reporting, and Source Credits
- The Indian Express, 29 January 2025: the DK Boss investigation described a Jamtara module distributing fake bank and government Android apps, showing the shift from basic calls to malware-supported fraud.
- The Indian Express, 30 June 2021: police were investigating 412 complaints linked to two Nuh villages and alleged collections of roughly ₹6 crore during the lockdown period.
- India Today, 10 September 2024: a report on the Deeg crackdown cited I4C data and described links among criminal networks in Deeg, Jamtara, and other parts of Mewat.
- CBI via PIB, 6 May 2026: investigators said Indians were trafficked through false job offers to scam compounds mainly in Myanmar and Cambodia.
- MHA Lok Sabha reply, 24 March 2026: official figures for saved funds, shared mule accounts, declined transactions, blocked SIMs, and the Mewat and Jamtara coordination teams.
- I4C official portal and the National Cybercrime Reporting Portal: official prevention, coordination, and complaint channels.
Frequently Asked Questions
What is the Jamtara scam in India?
Jamtara is a district in Jharkhand that became widely associated with organized phone phishing. Networks linked to the area used bank impersonation, urgency, and requests for OTPs or credentials. The Netflix drama Jamtara: Sabka Number Ayega made the name familiar nationwide, but Jamtara is a real district whose residents should not be collectively stereotyped.
What is the Mewat cyber crime hub in India?
Mewat is a cultural region spanning parts of Haryana and Rajasthan. Police investigations have traced high volumes of impersonation, sextortion, marketplace, customer care, and OTP fraud to pockets of Nuh, Deeg, Bharatpur, Alwar, and nearby districts. This describes investigated networks, not the region or its population as a whole.
Are Indian cyber fraudsters operating from abroad?
Yes, but some Indian nationals in overseas scam compounds are trafficking victims rather than willing offenders. In May 2026, the CBI said false overseas jobs had been used to traffic Indians to compounds mainly in Myanmar and Cambodia, where passports may be seized and victims forced to commit cyber fraud.
Is India cybercrime getting worse despite crackdowns?
Fraud networks continue to adapt, but official interventions have also stopped substantial harm. MHA reported that by 31 January 2026, more than 12.94 lakh SIM cards and 3.03 lakh IMEIs had been blocked, while the financial fraud response system had saved more than ₹8,690 crore across over 24.65 lakh complaints.
How does knowing about scam hotspots help me stay safe?
The location itself cannot tell you whether a call is fraudulent. The useful lesson is that organized networks reuse scripts: impersonate authority, create urgency, demand secrecy, isolate the victim, and request money, an OTP, a UPI PIN, or screen access. Recognizing that sequence helps you stop the interaction and verify independently.
30 Second Instagram Reel Script
0 to 3 seconds, hook
"Jamtara is not the whole story. India's cyber fraud now has a much bigger map."
3 to 10 seconds, visual
"Jamtara became known for bank and OTP calls. Mewat, Bharatpur, and Deeg were linked to large script-based fraud networks."
10 to 19 seconds, reveal
"Then comes Myanmar and Cambodia, where the CBI says some Indians were trafficked by fake job recruiters and forced to run scams."
19 to 26 seconds, safety rule
"Different place, same script: authority, urgency, secrecy, then your OTP, PIN, app install, or money."
26 to 30 seconds, CTA
"End the call. Verify independently. Call 1930 if you paid. Save and share this map."
Visual plan: India heat map, phone warning, compound gate silhouette, four red-flag words, RakshaAI logo.
The script matters more than the caller's location
Pause, verify through an official channel, and never share an OTP or UPI PIN. Report suspicious details so other people can see the warning.
Check with RakshaAIMore from RakshaAI Blog
Stay Protected Online
Use RakshaAI to check websites, phone numbers, and UPI IDs for scams free, instant, no sign-up required.
RakshaAI is a private platform by Ehatech Services Pvt. Ltd. Not affiliated with any government body. Editorial policy


