
Exposed digital arrest scam data — the personal details fraudsters already hold before they ever call — is now flowing out of routine HR and BGV processes across India. A senior professional in Bengaluru lost more than eleven crore rupees over a single month after scammers told him his Aadhaar had been linked to a money-laundering case, kept him on a video call for weeks, and instructed him not to tell his family. A retired officer in Lucknow and his hundred-year-old father lost over a crore in six days after a caller claiming to be from the CBI produced their personal details with unsettling accuracy. Fraudsters posing as ED and CBI officials defrauded a Mumbai businessman of fifty-eight crore rupees over two months, in what they called a digital arrest.
Every one of these cases relies on the same raw material: digital arrest scam data the fraudster already holds before dialling. That data has to come from somewhere. Increasingly, it comes from the hiring and verification pipeline HR teams run every single day.
This is not a scare tactic. It’s a data-handling problem hiding inside a fraud story, and it sits squarely in HR’s lap.
If your background verification process handles Aadhaar, PAN, and address proofs for hundreds of candidates a year, this article will change how you think about that data. Pietos runs a data-security-first BGV process built for exactly this risk — see how at the end of this piece.
What a Digital Arrest Scam Actually Is
A digital arrest scam is an extortion technique. Fraudsters call or video-call a target, impersonate a law enforcement officer from an agency such as the CBI, ED, customs, or local police, and claim the person is linked to a criminal case. They keep the victim on camera, isolate them from family, and pressure them into transferring money to “prove innocence” or avoid a fabricated arrest.
The Indian Cyber Crime Coordination Centre (I4C) has issued repeated public advisories on this exact pattern, stating plainly that no government agency arrests anyone over a video call. Yet the scam keeps working, because it opens with something the victim recognizes as true: their own PAN number, their own address, their own employer’s name, sometimes their own recent background check.
That opening line is not guesswork. Cybersecurity incident volumes in India rose from roughly 10.29 lakh cases in 2022 to 22.68 lakh in 2024. The Supreme Court has flagged digital arrest fraud specifically as a growing national concern, with estimated losses running into thousands of crores. The scale keeps growing because the supply of digital arrest scam data keeps growing.
Why the Psychology Works
The psychology behind the scam is well documented. It explains why even careful, senior professionals fall for it. The call opens with accurate personal details, which builds instant credibility fast. The scam escalates quickly, so the victim has no time to verify the claim. Fraudsters isolate the victim next, usually with an instruction not to tell family members, framed as protection rather than control. They also hold the victim on camera continuously, which prevents the pause needed to think clearly. Every one of these four levers depends on one thing: a credible fragment of the victim’s identity, held before the call even starts. That fragment is the part HR teams can actually control.
Who Scammers Actually Target
It also helps to be precise about who scammers target. Reported cases span senior IT professionals, retired government officers, business owners, and elderly parents of working professionals — in other words, exactly the population that passes through a corporate BGV or KYC cycle at some point, either directly or through a family member’s employer.
The Data Trail: Where Fraudsters Get Your Employees’ Details
Ask most HR leaders where a scammer could get a candidate’s Aadhaar number, and the honest answer is: several places, none of them tightly controlled. This is where digital arrest scam data actually originates — not in a server room, but in the ordinary hiring pipeline, a gap our DPDP rules for HR India guide covers in more depth.
Aadhaar and PAN Exposure During Background Checks
A standard BGV cycle in India touches Aadhaar, PAN, address proof, education certificates, and sometimes bank details. That’s normal. What’s not normal, at most companies, is how many hands that data passes through before the process ends — recruiters, HR coordinators, a BGV vendor, sometimes a sub-vendor the primary vendor never disclosed, and an HRMS that nobody has audited for access controls in years.
Every handoff is a potential leak point. None of them need to be malicious. A shared spreadsheet emailed to the wrong distribution list is enough.
Unsecured Vendor Handoffs
Many BGV vendors in India still collect documents over WhatsApp or unencrypted email, store them in generic cloud drives, and retain them indefinitely because nobody asked them to delete anything. If your vendor can’t tell you exactly where a candidate’s Aadhaar copy sits six months after onboarding, you don’t have a vendor problem. You have a data exposure problem with a vendor’s name on it.
Data That Outlives Its Purpose
Here’s the pattern that connects background verification to digital arrest scams most directly: candidate data collected for a one-time check often never gets deleted. It sits in inboxes, shared drives, and vendor systems for years after the hire — or after a rejected application. The longer sensitive data lives unmanaged, the larger the window for it to leak, get sold, or get scraped and used exactly the way digital arrest scammers use it: as the credible opening line of a fraud call.
Which Employees Are Most Exposed
Not every workforce segment carries equal risk, and understanding where your organisation sits helps prioritise where to act first.
| Workforce Segment | Why the Exposure Is Higher | Typical Data at Risk |
|---|---|---|
| NBFC and fintech employees | Handle sensitive financial data themselves, making them plausible “money laundering” targets | Aadhaar, PAN, bank verification records |
| Senior professionals and managers | Higher account balances make them more profitable targets | Full KYC set collected during onboarding or promotions |
| GCC and MNC staff | Cross-border reporting lines create confusion that scammers exploit | Passport data, international background check records |
| Recently onboarded hires | Freshly collected, often unencrypted data sits in inboxes and vendor systems | Aadhaar, PAN, address proof, education certificates |
| Retired employees and their families | Less familiar with current fraud patterns, targeted through family members’ HR records | Legacy records retained without a deletion policy |
None of these segments are risky because of who the employees are. They’re risky because of how much verified, credible personal data has accumulated about them across HR and BGV systems over time — and how little of that data has a defined expiry date. A five-year employee’s records are, in most companies, no better protected than the day they were collected, even though the original business purpose for holding them expired long ago.
Real Cases, Real Losses
The financial scale of digital arrest fraud in India is no longer a fringe statistic. Fraudsters posing as ED and CBI officials defrauded a Mumbai businessman of fifty-eight crore rupees over roughly two months, holding him under a fabricated investigation and moving the money through more than a dozen bank accounts to launder it. A Bengaluru software engineer transferred nearly twelve crore rupees over a month; fake Supreme Court hearing threats coerced him, and scammers told him his Aadhaar had funded a money-laundering operation. An elderly woman in Karnataka lost over three crore rupees across six months, wiring funds in instalments as the pressure escalated. In a separate Karnataka case, a senior IT professional lost over thirty-one crore rupees across nearly two hundred transactions before the fraud’s scale came to light.
These are not isolated retail-banking incidents. Several victims across reported cases have been salaried professionals, senior employees, and business owners — precisely the demographic HR teams onboard, verify, and hold sensitive records for, every single week.
What stands out across these cases is duration. Nobody scams victims in a single call. Fraudsters hold them for weeks, sometimes months, extracting money in instalments as the pressure compounds. That pattern only works if the fraudster can sustain credibility over time — and sustained credibility requires a steady supply of accurate personal detail, not a single leaked data point.
Every candidate record your team handles is a potential data point in someone else’s fraud script. A structured data-security audit shows you exactly where that exposure sits in your current BGV workflow — book a Pietos data security audit.
Why HR Is the Weakest Link, Not IT
Most companies route data-security conversations to IT or infosec. That’s a mistake when it comes to hiring data, because the exposure doesn’t start in a server room. It starts the moment a recruiter asks a candidate to email a PAN card scan.
Consent Without Control
Indian companies have gotten reasonably good at collecting consent for background checks. Far fewer have controls over what happens to that data afterward — who can access it, how long it’s retained, and whether it’s encrypted in transit and at rest. Consent answers a legal question. It doesn’t answer a security one.
The Multi-Vendor Blind Spot
A single BGV cycle often involves the primary vendor, a field-verification sub-agent, an education-verification API partner, and sometimes a database-check provider. Most HR teams can name their primary vendor. Few can map the full sub-vendor chain candidate data flows through, or confirm each link in that chain meets the same security bar.
This matters because liability doesn’t stop at the first vendor in that chain. If a sub-vendor three steps removed from your contract mishandles a candidate’s Aadhaar data, the exposure still traces back to your hiring process, whether or not your primary vendor disclosed that sub-vendor existed. Procurement teams routinely audit vendor pricing and SLAs. Very few audit the security posture of every party a vendor quietly subcontracts to.
No Data Retention Policy
Ask your team a simple question: how long does a rejected candidate’s Aadhaar copy stay in your systems? If nobody has a confident answer, that’s the gap. Data with no retention policy doesn’t expire. It just waits.
The Cost of Inaction for Employers
It’s worth naming what’s actually at stake when candidate and employee data sits unmanaged, because the risk isn’t abstract.
Regulatory exposure. The DPDP Act allows penalties that scale with breach severity. A breach traced to careless BGV data handling puts the company, not just the vendor, in the regulator’s line of sight.
Legal liability. Suppose an employee can show their data leaked from your hiring pipeline. Suppose it was later used against them in a fraud. That liability conversation shifts from theoretical to actual fast, especially where consent language never specified retention limits.
Trust erosion. Employees who learn their Aadhaar or PAN sat unprotected in a vendor’s inbox for two years don’t forget it. It shows up on employer review sites and in exit interviews. Candidates describe your hiring process this way long before they’ve even joined — and word travels fast in a market where BGV vendors are compared openly.
Operational cost of a breach response. Investigating a suspected leak takes time. Notifying affected employees takes more. Rebuilding vendor controls after the fact costs far more, in both time and reputation, than building them upfront. Employees can also report a suspected leak of their own data through the National Cyber Crime Reporting Portal, which puts the incident on record with authorities regardless of whether your company discloses it first.
None of this requires a company to slow down hiring. It requires treating candidate data with the same seriousness as financial data, because to a fraudster, it functions exactly the same way. A PAN number sitting in an unsecured inbox isn’t just a compliance gap on paper. It’s a live asset waiting for the next fraud call, whether or not anyone in HR ever finds out it was there.
What the DPDP Act Actually Requires of HR Teams
India’s Digital Personal Data Protection Act puts direct obligations on any organisation that collects and processes personal data — which includes every company running background checks. HR teams handling candidate Aadhaar, PAN, and address data are, in the law’s terms, acting as a data fiduciary for that information. Digital arrest scam data is, in the law’s terms, simply personal data your company failed to protect.
That means clear, specific consent notices; a defined purpose for collecting each piece of data; reasonable security safeguards against breach; and a duty to delete personal data once it has served its purpose, unless another law requires longer retention. Most companies satisfy the consent step and stop there. The security-safeguard and deletion obligations are where BGV data practices most often fall short — and where regulatory risk and fraud-enablement risk overlap almost exactly.
The Act also established the Data Protection Board of India to handle breach investigations and enforcement. For HR teams, the practical implication is straightforward: consent forms alone no longer satisfy the law, and they never fully addressed the fraud-enablement risk in the first place. A signed consent form doesn’t stop a scammer from using leaked Aadhaar data six months later. Only genuine security controls do that, a principle our NBFC background verification guide walks through for regulated employers specifically.
Five Things a DPDP-Ready BGV Process Needs
In practice, a DPDP-ready BGV process needs five things in place at once: a consent notice naming exactly what data recruiters collect and why; documented purpose limitation, so nobody repurposes Aadhaar collected for verification without fresh consent; encryption for data in transit and at rest; a named retention period with automated deletion; and a breach-notification process fast enough to meet the Act’s reporting expectations. Most HR teams have the first item. Few have all five, and the combination is what actually closes the fraud-enablement gap this article opened with.
A 7-Step Framework to Close the Digital Arrest Scam Data Gap
The steps below draw on the same consent-and-retention principles covered in our BGV consent whitepaper, applied specifically to fraud exposure rather than compliance alone.
- Map every place candidate data lives. HRMS, vendor portals, email, shared drives, WhatsApp threads. You cannot secure what you haven’t located, and most HR teams discover at least one forgotten storage point — an old shared drive, a departed employee’s inbox — the first time they run this exercise properly.
- Audit your BGV vendor’s sub-vendor chain. Ask for a written list of every party that touches candidate documents, not just the primary contract. Field-verification agents, education-check APIs, and database providers all count, and each one is a separate point of exposure your main contract may not even mention.
- Set a hard retention window. Define exactly how long Aadhaar, PAN, and address data is kept post-hire and post-rejection, then automate deletion rather than relying on someone remembering to do it manually.
- Require encrypted transfer as standard, not an add-on. No candidate document should move over unencrypted email or personal WhatsApp, regardless of how routine the request feels to the recruiter sending it.
- Limit access by role. Not every recruiter needs standing access to every candidate’s Aadhaar scan after a hire is closed. Access should expire when the business need for it does.
- Run a documented DPDP compliance check covering consent language, purpose limitation, and breach-response readiness, and repeat it annually rather than treating it as a one-time launch task.
- Choose verification partners who treat data security as core infrastructure, not a compliance afterthought bolted onto a fast-turnaround promise. Ask vendors directly how they’d respond to a breach, not just how fast they close a background check.
A Realistic Scenario: How the Leak Actually Happens
It helps to walk through how this plays out inside a normal, well-intentioned HR team, because the failure is rarely dramatic.
A mid-market NBFC hires forty people a quarter. Recruiters collect Aadhaar, PAN, and address proof by email because the applicant tracking system doesn’t have a secure upload feature built in. The BGV vendor picks up documents from a shared inbox, verifies them, and returns a report. Nobody deletes the original email thread, because nobody owns that task. Six months later, three of those hires are rejected mid-process for unrelated reasons, but their documents stay in the same inbox indefinitely, because the offboarding checklist only covers accepted hires.
Two years pass. The inbox gets added to a distribution list during a team restructure. A departing employee forwards old threads to a personal account before leaving, not maliciously, just to preserve records they think they might need. None of this looks like a breach from the inside. From the outside, it’s a pool of live Aadhaar and PAN numbers sitting in at least four places nobody is actively monitoring.
This is the mechanism, not a hypothetical. It doesn’t require a hacker. It requires the absence of a retention policy, a defined access boundary, and a single owner for candidate data hygiene. Most Indian mid-market companies, across sectors, have exactly this gap today, and most have never mapped it because nobody has asked them to.
What to Actually Look for in a Background Verification Partner
If you’re evaluating whether your current BGV process creates this exposure, four questions separate a data-security-first vendor from one that treats it as an afterthought. Our AI background verification guide covers how automation reduces several of these exposure points directly.
Four Questions to Ask Your Vendor
Where do documents get collected, and how? A vendor still requesting Aadhaar or PAN scans over WhatsApp or personal email is optimising for convenience over security. Secure upload portals with encryption in transit should be the baseline, not a premium feature.
Who else touches the data before the report reaches you? Every sub-vendor — field verification agents, education-check APIs, database providers — is a separate custody point. A vendor that can’t produce this list on request likely hasn’t mapped it internally either.
What happens to the data after the report is delivered? Ask for the exact retention period and deletion process, in writing. “We keep it securely” is not an answer. A specific number of days, with an automated deletion trigger, is.
How does the vendor handle a breach, not just prevent one? Every security programme eventually gets tested. A vendor with a documented breach-response process — who gets notified, within what timeframe, and how affected candidates are informed — signals a maturity level that a fast-turnaround sales pitch won’t reveal on its own.
Look at Your Own Process Too
These four questions matter more than turnaround time or price when the underlying risk is fraud enablement, not just process delay. A BGV partner that treats data custody as core to the service, not incidental to it, is the difference between closing this gap and quietly extending it.
It’s also worth asking these questions of your own internal process, not just external vendors. HR teams sometimes assume the risk sits entirely outside their walls, with the vendor. In practice, the internal handoff — the recruiter’s inbox, the shared drive, the HRMS export nobody has audited — is often the weakest link in the entire chain, regardless of vendor security. Fixing vendor practices without fixing internal ones only closes half the gap.
Common Objections, Answered
“We already have a BGV vendor — why change anything?” Most BGV vendors optimize for turnaround time and cost. Very few are audited specifically for data-handling practices. The two aren’t mutually exclusive, but they’re rarely the same conversation, and it’s worth asking the question directly.
“This feels like a low-probability risk for us.” Digital arrest scams have already cost Indian victims thousands of crores in losses reported through 2025 alone, and the numbers climb every quarter. The question isn’t whether fraud is happening at scale — it’s whether your candidate data is part of the pool that’s exposed.
“Isn’t this an IT problem, not an HR one?” IT secures infrastructure. HR decides what data gets collected, who it’s shared with externally, and how long it’s kept. Those are HR decisions, not IT ones, and they’re where most of the exposure actually originates.
“We’re a small team — an audit sounds like a big project.” A first-pass data-flow map usually takes days, not months, and it’s the single highest-leverage step on this list. Most companies find the biggest gaps in the first afternoon of looking.
Why Acting Early Here Is a Genuine Advantage
Security and compliance teams often describe data protection in terms of downside avoidance — fines to escape, breaches to prevent. That framing misses something HR leaders are well placed to see: candidates and employees increasingly notice how a company handles their personal information, well before any breach ever happens.
A hiring process that visibly protects Aadhaar and PAN data — secure upload instead of email, a stated retention policy instead of silence when asked — reads as more credible to a candidate evaluating an offer, not less. In a market where BGV turnaround times have become commoditised across vendors, data-handling maturity is one of the few differentiators left that candidates can actually feel.
The broader lesson from how digital arrest scams operate is that data security and fraud prevention are the same discipline wearing two names. A company that closes its BGV data gaps isn’t just reducing DPDP exposure. It’s removing itself, and its people, from the pool of easy targets that make this entire fraud category profitable in the first place. That’s a harder thing to quantify on a compliance checklist, but it’s the outcome that actually matters.
Key Takeaways
- Digital arrest scams work because fraudsters open with real personal data — Aadhaar numbers, PAN details, employer names.
- BGV and onboarding processes are a documented, recurring source of that data, often through vendor handoffs and unmanaged retention.
- The DPDP Act already requires purpose limitation, security safeguards, and deletion — most HR teams meet only the consent requirement.
- A seven-step audit, starting with a full data-flow map, closes the largest gaps without slowing down hiring.
- No HR or BGV brand in India has connected these dots publicly yet — acting early is a genuine differentiator, not just a compliance box.
FAQ
About the Scam
A digital arrest scam is a fraud technique where criminals impersonate law enforcement over a video call, falsely claim the victim is under investigation, and pressure them into transferring money to avoid a fabricated arrest. Exposed digital arrest scam data is what makes the opening claim sound credible.
Through leaks and unsecured handling across the hiring pipeline — unencrypted document transfers, undisclosed BGV sub-vendors, and indefinite retention of Aadhaar, PAN, and address records long after they served their original purpose. Related patterns show up in ghost employee fraud cases too, where weak HR data controls enable a different kind of exploit.
Reported cases skew toward senior professionals, NBFC and fintech staff, GCC employees, and retired individuals — groups whose data commonly passes through corporate BGV, KYC, or onboarding pipelines at some point.
About HR’s Obligations
Yes. Any company collecting candidate personal data for verification is a data fiduciary under the DPDP Act and carries obligations around consent, purpose limitation, security safeguards, and deletion once the purpose is met.
Yes. Any company collecting candidate personal data for verification is a data fiduciary under the DPDP Act and carries obligations around consent, purpose limitation, security safeguards, and deletion once the purpose is met.
Start by mapping every system, vendor, and channel candidate data currently passes through. Most companies are surprised by how many undisclosed touchpoints exist before they run this exercise.
Yes, if the vendor treats data security s core process design — encrypted handoffs, disclosed sub-vendor chains, defined retention windows — rather than an afterthought layered onto a fast-turnaround service
The Act allows financial penalties that scale with breach severity, and enforcement runs through the Data Protection Board of India. Beyond fines, companies also carry legal liability and reputational cost if a leak is traced to their hiring process.
Ready to Close the Digital Arrest Scam Data Gap?
Pietos builds background verification around secure data handling from the first document collected to the last record retained — encrypted transfer, disclosed sub-vendor chains, and defined deletion windows built in, not bolted on. Book a Pietos data security audit and see exactly where your current process stands before a fraudster finds the gap first.



