Report pp. 1–5
01 / 91

Cyber Fraud & Digital Risk

Indian Higher Education · 2021–2025

Report pp. 19, 21–37
02 / 91

The most valuable asset in a university

is trust.

Report pp. 22–23
Pay your admission fee here
Pay now
03 / 91

A student receives a message.

“Pay your admission fee here.”

Report pp. 23, 28
Payment successful
Recipient: Unknown beneficiary
04 / 91

The payment succeeds.

The university never receives it.

Report pp. 19, 22–23
serverreputation
05 / 91

The university was not hacked.

Its reputation was.

Report p. 4
06 / 91

Now the scale.

Report p. 12
07 / 91

2,944,248

cyber incidents observed by CERT-In in 2025.

Derived from 2,944,248 CERT-In incidents in 2025 · Report p. 12
11 sec
average spacing
08 / 91

One incident every eleven seconds.

That is what 2.94 million means when the year becomes a clock.

Report p. 12
09 / 91

+109.9%

CERT-In incident growth from 2021 to 2025.

Report p. 12
10 / 91

2021 → 2025

the national cyber-risk curve doubled.

Report p. 13
11 / 91

2,402,579

financial cyber-fraud complaints in 2025.

Derived from 2,402,579 financial-fraud complaints in 2025 · Report p. 13
13 sec
between complaints
12 / 91

One financial-fraud complaint every thirteen seconds.

Not an annual number. A continuous rhythm.

Report p. 13
13 / 91

9.14×

more financial-fraud complaints than 2021.

Reported amount is not final confirmed loss · Report p. 14
14 / 91

₹22,495 crore

reported amount in 2025 complaints.

Derived from ₹22,495 crore reported amount across 2025 complaints · Report p. 14
₹61.6 cr
every day
15 / 91

The number is annual. The pressure is daily.

Reported amount is not confirmed final loss — but the payment surface is visibly exposed.

Report p. 14
attemptimpact
16 / 91

Not loss.

Reported amount.

Report p. 10
17 / 91

101,928

registered cybercrime cases in 2024.

Derived from 101,928 registered cybercrime cases in 2024 · Report p. 10
18 / 91

Two hundred seventy-nine registered cybercrime cases every day.

Every bar is one day. Every day is already crowded.

Report p. 11
19 / 91

29,758

cybercrime cases under the Fraud head in 2024.

Report p. 11
20 / 91

+186.3%

growth in Fraud-head cybercrime cases, 2020–2024.

Report pp. 15, 19, 21–29
paymentsadmissionsidentityresearchmarksvendorsbrandstudents
21 / 91

This is not only malware.

It is money, identity and trust.

Report p. 18
22 / 91

49,535

universities and colleges in the attack surface.

AISHE 2023–24 universities + colleges · Report p. 18
23 / 91

49,535 is not a list. It is a national surface.

Each tiny square is roughly one hundred institutions.

Report p. 18
24 / 91

1,289

universities and university-level institutions.

Report p. 18
25 / 91

This is not a statistic.

It is pressure.

Report p. 18
26 / 91

One institution is small.

49,535 is a national surface.

Report p. 19
27 / 91

Why universities?

Identity churn.

Report p. 19
28 / 91

Why universities?

Open by design.

Report p. 19
29 / 91

Why universities?

Predictable payment moments.

Report p. 19
30 / 91

Why universities?

Distributed authority.

Report p. 19
31 / 91

Why universities?

High-value data.

Report p. 19
32 / 91

Why universities?

Academic integrity assets.

Report p. 19
33 / 91

Why universities?

Inherited third-party risk.

Report p. 19
34 / 91

Why universities?

Public brand trust.

Vendor telemetry measures attempts, not breaches · Report p. 20
35 / 91

8,487

weekly attack attempts per education/research organisation in selected 2025 India telemetry.

Derived from 8,487 weekly attack attempts in selected 2025 India education/research telemetry · Report p. 20
36 / 91

Fifty knocks every hour.

For one organisation. Week after week.

Report p. 20
attemptimpact
37 / 91

Thousands of knocks.

Not thousands of break-ins.

Report p. 20
38 / 91

This is not a hacker.

It is a storm.

Modeled estimate, not official statistic · Report pp. 4, 70–72
39 / 91

~90%

central annual exposure estimate.

Central annual exposure estimate, scenario model · Report pp. 4, 70–72
40 / 91

In a room of ten universities, nine should assume exposure.

The tenth should verify before feeling safe.

Report pp. 4, 70–72
41 / 91

85–95%

defensible planning range for annual exposure.

Scenario estimate based on AISHE frame · Report p. 4
42 / 91

44,582

central estimate of institutions encountering an attempt.

Derived from central ~90% exposure estimate applied to 49,535 AISHE universities + colleges · Report p. 4
43 / 91

44,582 institutions. One planning assumption.

This is what exposure looks like when it becomes a campus map.

Report pp. 4, 70–72
44 / 91

Which one are you?

90 out of 100 light up.

Report p. 6
attemptimpact
45 / 91

Exposure ≠ compromise.

Precision is credibility.

Report p. 6
ExposureCompromiseOutcomeMaterial harm
46 / 91

Four layers.

Exposure. Compromise. Outcome. Material harm.

Report p. 6
01
47 / 91

01

Was the institution targeted?

Report p. 6
02
48 / 91

02

Was access gained?

Report p. 6
03
49 / 91

03

Was there an outcome?

Report p. 6
04
50 / 91

04

Was there material harm?

Report pp. 2, 6–9
FactsEstimates
51 / 91

India has no national HE prevalence survey.

So the dossier separates evidence from estimates.

UK official benchmark, not India statistic · Report pp. 59–62
98%
52 / 91

98%

of UK higher-education institutions identified a breach or attack in the previous 12 months.

UK official benchmark; not an India statistic · Report pp. 59–62
53 / 91

Only two in a hundred did not identify one.

That is the UK higher-education benchmark.

Report pp. 59–62
54 / 91

96%

of affected UK further/higher-education institutions saw phishing.

Report pp. 59–62
55 / 91

79%

saw impersonation.

Report pp. 59–62
56 / 91

49%

experienced a negative system outcome.

UK affected FE/HE negative system outcome benchmark · Report pp. 59–62
1 in 2
experienced a negative system outcome
57 / 91

Half is not a footnote.

It is what turns exposure into institutional consequence.

Verizon DBIR benchmark · Report p. 63
$
58 / 91

88%

of US Educational Services breaches were financially motivated.

IBM cross-sector context · Report p. 68
59 / 91

₹22.0 crore

average breach cost in India across sectors.

Report pp. 38–58
60 / 91

The Indian case register is not one story.

It is many attack classes.

Report p. 21
61 / 91

Phishing

steals the key.

Report p. 21
62 / 91

Account takeover

turns one identity into a bridge.

Report p. 22
63 / 91

Impersonation

borrows the institution’s voice.

Report p. 23
64 / 91

Fake admissions

weaponise urgency.

Report p. 28
StudentScammerUniversity
65 / 91

Payment diversion

moves trust into the wrong account.

Report p. 24
66 / 91

Fake universities

exploit recognition and aspiration.

Report p. 25
00:59
67 / 91

Ransomware

attacks time itself.

Report p. 26
68 / 91

Data exposure

turns records into leverage.

Report p. 27
A+
69 / 91

Marks manipulation

attacks the truth of the institution.

Report p. 29
70 / 91

Supply chain

expands the blast radius.

Report pp. 74–86
71 / 91

The answer is not more tools.

It is one operating model.

Report pp. 74–86
72 / 91

Identity security.

Report pp. 74–86
73 / 91

Brand and domain monitoring.

Report pp. 74–86
74 / 91

Verified payments.

Report pp. 74–86
75 / 91

Attack detection.

Report pp. 74–86
76 / 91

Incident response.

Report pp. 74–86
77 / 91

Backup resilience.

Report pp. 74–86
78 / 91

Vendor governance.

Report pp. 74–86
79 / 91

Student and staff awareness.

Report pp. 89–91
306090
80 / 91

90 days

to move from assumption to evidence.

Report pp. 89–91
81 / 91

First 30

Know the crown jewels.

Report pp. 89–91
82 / 91

Days 31–60

Close the obvious gaps.

Report pp. 89–91
83 / 91

Days 61–90

Prove response and recovery.

Report p. 88
84 / 91

Ten signals.

One board dashboard.

Report pp. 75–88
?
85 / 91

Can we see it?

Can we prove it?

Report pp. 75–88
?
86 / 91

Can we contain it?

Can we recover?

Report p. 132
87 / 91

No longer whether.

Whether trust survives.

Report pp. 2, 7–9, 120–131
88 / 91

Auditable.

Facts, telemetry, cases and estimates stay separate.

Closing synthesis from report pp. 2, 4–6, 132
89 / 91

Trust is not a server setting.

It is the institution itself.

Closing synthesis from report pp. 74–91, 132
90 / 91

The cost of prevention is measurable.

Budgets. Controls. Response time. Recovery evidence.

Report p. 132
91 / 91

The cost of lost trust is not.

tap · swipe · press F