முக்கிய விஷயங்கள்
- பதிவுசெய்யப்படாத 3 மில்லியன் 'mule' கணக்குகள் கண்டுபிடிக்கப்பட்டு, Rs 25,000 கோடி மதிப்புள்ள fraud attempts decline ஆகின.
- இது காப்பாற்றப்பட்ட பணம் அல்ல; money-அ land பண்ணாம, moment-லேயே block செய்வதால் தான் இந்த number.
- UPI மற்றும் IMPS settlement routes-அ முதன்மை target-ஆ வெச்சிருக்காங்க. Digital platforms-ல pattern-match செய்ய Jio, Flipkart-adjacency data use செய்யப்பட்டிருக்கு.
- Unified payment stack legacy banking-அ விட harder fraud boundary-ஆ இருக்கு.
- Decline-க்கு பிறகான intelligence pipeline public-க்கு தெரியாம ஒரு 'black box'-ஆ தான் இருக்கு.
�ன்ன நடந்தது?
Rs 25,000 கோ�ி fraud, decline ஆகிவிட்டது, அப்படின்னு posters அப்புறம் news channels-ல celebrate பண்�ுவாங்க. ஆனால் இந்த arithmetic-அ simple-ஆ எடுத்துக்கணும். இது ஒரு single heist-அ reduce பண்ண result அல்ல. Thousands of micro-attempts-அ aggregate செஞ்ச aggregate தான். ஒரு குறுகிய period-ல நடந்த UPI handlers, credit-card swipes, net-banking logins-ல இருந்து இந்த number derive ஆகிருக்கு. அதாவது, ஒரே time-ல சின்ன small amounts-ஆ transfer பண்ணி, system-அ overload பண்றதுதான் strategy.
அந்த 3 மில்லியன் flagged mule accounts—அவங்க high-net-worth targets கிடையாது. அவங்க scaffolding தான். ஒவ்வொரு account-க்கும் பெரிய balance தேவைப்படலை. Chain-ல ஒரு link-ஆ மட்டும் இருந்தாலே போதும். Chain-அ break பண்ணிட்டா, money never accrued interest. அதாவது, fraudster-க்கு முடிக்க வச்ச money actually land ஆகலை. இது ஒரு city-level phishin� bust-உம் கிடையாது. Nationwide sensor-net detection-ஆவே இருக்கு. Fraud ring-கள் scattered opportunists கிடையாது; organized bot-driven fraud infrastructure.
Fraud ring-கள் KYC fraud-அ scratch-ல இருந்து fortify பண்ணலை; existing digital infrastructure-அ reuse பண்ணியிருக்காங்க. Banks மற்றும் payment apps AI layers-அ apply பண்ணதும், honeypot fill ஆயிடுச்சு. அதாவது, system-ல alreadyy இருக்கும் loopholes-அ capture பண்ணி, monitored zone-க்குள்ள spark பண்ணியிருக்காங்க.
Rs 25,000 கோடி number-அ law enforcement-உம் magic wand மாதிரி use பண்றாங்க. 'We saved this much!' அப்படின்னு headlines padikka ஆசைப்படலாம். ஆனால் இது true சாட்சி கிடையாது. Declined-ங்கிறது detect ஆகி block ஆன transaction attempts. Settlement-அ complete பண்ணாம, pipeline-லேயே cut பண்ணிட்டாங்க.
Migrant data-வ pattern-அ analyze பண்ணும்போது ஒரு விஷயம் தெரியும்: fraud surface simply-ஆ expand ஆகிட்டே இருக்கு. UPI volume-அ leverage பண்ணி, low-value high-frequency transactions-அ move பண்றதுதான் new playbook. அதுக்கு முன்னாடி, card skimmers-அ, physical tampering-அ use பண்ணுவாங்க. இப்போ அந்த இல்லாமலேயே digital-ஆ seep ஆயி�ுங்க.
இது என்ன / �ப்படி வேலை செய்யும்?
mule account-ங்கன்னா என்ன தெரியுமா? Compromised bank accounts. சில சமயம் உண்மையான human-அ hoodwinked பண்ணி create பண்ணுவாங்க. ஒரு lead-அ reward promise பண்ணி, bank credentials-அ harvest பண்ணுவாங்க. சில சமயம் purely synthetic-ஆ இருக்கும். அதாவது, fake Aadhaar, fake PAN, அப்புறம் fake phone number-ல இருந்து entry create பண்ணுவாங்க. Tissue paper bucket-னு நினைச்சுக்கொள்ளுங்கள்: மலிவானது, disposable, leak ஆகும் வரை யாருக்கும் தெரியாது.
India-ல UPI wallets-அ offboard பண்ணதுனால, security model shift ஆயிருச்சு. Bulk card skimmers-அ விட்டுட்டு, low-value digital transfers-அ use பண்றாங்க. Rapid-ஆ pretend legitimate UPI usage-ஆ send பண்�ி victim-ோட bank balance-அ drain பண்�ிடுவாங்க. Pattern obvious-ஆ தெரியணும், அதுக்குள்ள damage ஆகிடும்.
Hydra model-ல, ஒரு Virtual Payment Address-அ block பண்ணினா, மூணு புதுசா sprout ஆகும். New device IDs, new browser fingerprints, new IP pools-ல entry create பண்ணுவாங்க. AI sandbox-ல flag ஆனாலும், next cycle-ல different behaviour vector-ஆ use பண்ணும். It is a cat-and-mouse game.
KYC friction-உம் fraud-அ control பண்�ுது. Bank-கள் biometric-அ strict-ஆ apply பண்றதுனால, real-ஆ identity verify பண்ணாம account open பண்றது costlier. But fraud ring-கள் synthetic-அ prep பண்ணி already address பண்ணியிருப்பாங்க.
Criminal economies-ல, these mule accounts live for very short window. 24 to 72 hours-க்குள்ள fund-அ cycle பண்ணி closure கொடுப்பாங்க. அதாவது, account-அ active-ல வெச்சி, convert பண்ணிட்டு அப்புறம் recycle பண்ணுவாங்க. Lifetime value-அ maximum-ஆ extract பண்�ுவாங்க.
இந்தியாவுக்கு என்ன?
UPI மற்றும் IMPS settlement rails-அ primary-ஆ target பண்ணியிருக்காங்க. Attacker-களுக்கு real-time monitoring sharp-ஆ இருக்குற இடங்கள் கிடைக்குது. But blind spots எங்க இருக்குனு public-க்கு தெரியாது. Telco signals-அ e-commerce behaviour-உட tie பண்ணி pattern-matching sharpen பண்ணுது. Jio-வோ, Airtel-வோ transaction behaviour-ல sudden spike-அ flag பண்ணுவாங்க.
Jio மற்றும் Flipkart-adjacency behavioural datasets-ல இருந்து suspicious account-கள identify பண்ணியிருக்காங்க. அதாவது, telco call patterns, browser history, device ID, transaction frequency, link-அ analysis பண்ணி, banking fraud ring-கள catch பண்ணியிருக்காங்க. Italy-level privacy-அ இங்கே sell பண்றது போன்ற ஒரு mixed ecosystem இது. Telco-கூட cloud infrastructure share பண்றதும் backend-ல benefit.
Legacy banking-அ விட India-ோட unified payment stack harder fraud boundary-ஆ இருக்கு. காரணம், same real-time settlement. Attackers detect ஆகாம fast-ஆ transact பண்ண முடியுதான்னு பாக்குறாங்க. Cohort-based risk scoring, anomaly detection vectorized APIs, behavior biometrics—இவையெல்லாம் backend-ல run ஆகுது. But frontend-ல moni-tored zones kuppetta loopholes இருக்கத்தான் chance.
Full-stack attribution-அ digital forensics-ல embed பண்றது watch-out moment-ஆ இருக்கு. அதாவது, Telco-level dataset-அ bank-level fraud schema-ட்க tie பண்ணும்போது, attack surface shrink ஆகும். But data-sharing agreements-ல privacy trade-offs strong-� இருக்கு. Customer consent-அ bypass பண்ணி data merge பண்ணுவது borderline scratch-ஆ இருக்கு. Law-age grey zone-ல இருக்கு.
PhonePe, Google Pay, Paytm-அ போல large intermediaries-கூட granular signal-அ data pipeline-ல கொடுக்க முடியும். அப்புறம் AI engine-அ real-time-ல train பண்ண முடியும். அதாவது, fraud ring-கோட current scheme-அ block பண்றத விட, next scheme-அ predict பண்றது higher ROI. But that prediction engine-அ public-ஆ disclose பண்றது competitive risk-ஆ இருக்கு.
நமக்கெ என்ன தெரிஞ்சுக்கணும்?
Blocker-ங்க work பண்றாங்க, volume decline பண்றாங்க. ஆனால் hydra model-ல attackers வேற gate open பண்ணியிருக்கலாம். எவ்வளவு late-ஆ detect-�குதோ, அவ்வளவு downstream damage. Decline-க்கு பிறகான intelligence pipeline—அதாவது decline-க்கு அப்புறம் data-வ analyze பண்�ி, future-ல இதே pattern-அ எப்படி predict பண்றதுனு—public-க்கு ஒரு 'black box'-ஆ தான் இருக்கு.
Step-ன் step-ஆ எளியா சொல்லணும்: ecosystem fast-ஆ adapt ஆகுது. 2007-8-ல phishers-கிட்ட இருந்து 2015-16-ல current accounts-க்கு, 2020-ல UPI hijacks-க்கு. இப்போ AI-generated VPA farms, synthetic identity modules, and LLM-driven social engineering-அ reach பண்ணியிருக்காங்க. India's digital economy scale-அ attack surface-உம் proportionally large-ஆ இருக்கு.
Unified payment stack, real-time settlement, அப்புறம் AI monitoring—இவையெல்லாம் defensive boundary-ஆ work பண்றது உண்மை. ஆனால் downstream method change-அ predict பண்ற capability public-ஆ share ஆகல. Fraud decline-அ celebrate பண்றதை விட, post-block monitoring-அ transparent-ஆ announce பண்�ுவது நல்லது. அப்பதான் public-க்கு actual risk perception-உம் value புரியும்.
Individual user-களுக்கு என்ன warning? Unexpected SMS link-அ click பண்ணாதீங்க. Small account-ஓட fund-அக்கி�்கூட risky third-party app-ல deposit பண்றதை avoid பண்ணுங்க. KYC-அ social media-ல overshare பண்�ாதீங்க. Digital discipline-அ follow பண்ணுவது alone 70% defense. Remaining 30% infrastructure-level monitoring-அ work ஆகட்டும். It is a shared responsibility.




கருத்துகள் (0)
Be the first to comment!