The Digital Exposure Report · India · 2026 · First Edition

Collected

How the wealthy in India are studied and assembled long before anything happens to them.

Published August 2026 About fifteen minutes

On 6 June this year, our intelligence team found a server running a complete fraud operation. Not a fake login page. A single control panel holding ready-made impersonations of the services you use every day, alongside tools for gathering addresses, checking which ones were live, sending in volume, and keeping hold of a session after it had been taken.

On 27 June, the server was gone.

For the three weeks it was running, none of the security vendors we checked had flagged it as anything at all.

This report is about what happens before anything happens to you.

A note on method

The Indian figures here come from the Ministry of Home Affairs, the Indian Cyber Crime Coordination Centre, and the National Cyber Crime Reporting Portal. The Indian cases are drawn from police complaints reported in the press, and from public statements made by the people involved. Where no Indian research exists on a question, we say so and use the closest international work available, marked as such.

Two findings are our own, from our intelligence team's investigations in June and July 2026. Both are dated in the text.

We are not presenting a survey of our clients, and we have not counted anything we cannot show. Where the honest answer is that nobody knows, that is the answer given.

I

The size of it

Indians lost ₹22,495 crore to cyber fraud in 2025, across 28.15 lakh reported cases. The number of cases rose by roughly a quarter over the previous year.

Four years earlier, in 2021, the figure reported through the national portal was ₹551 crore.

Investment fraud accounts for the majority of it: 76% of all money lost, from 35% of cases. That ratio is worth sitting with. Investment fraud is a third of the incidents and three quarters of the damage, which tells you it is not the crime of opportunity. It is the one that gets planned.

Digital arrest, the scheme in which someone is held on a video call for hours by a person posing as an official, accounted for 9% of losses in 2025. Across 2022 to 2025, India recorded 241,537 such cases and ₹3,012 crore lost.

The state's response has scaled: 459 dedicated cybercrime police stations, up from 169 in 2020, and in 2025 alone 1.2 million SIM cards deactivated and 1.33 million mule accounts frozen.

All of these figures undercount. They record what was reported to a portal, and a great deal is never reported, particularly by people with reputations attached to their names.

Figure 1 — Reported cyber fraud losses in India
2021 · ₹551 crore 2024 · ₹22,845 crore 2025 · ₹22,495 crore 2022 AND 2023 OMITTED
Losses reported through the National Cyber Crime Reporting Portal.
Figure 2 — Where the money goes, 2025
Investment fraud 76% Digital arrest 9% Sextortion 4% All other categories 11%
Share of total reported financial loss, India, 2025.
II

Why the visible are different

Most of that ₹22,495 crore was taken from people nobody was looking for.

Volume crime is indiscriminate. It goes out to millions and takes whoever answers, and the individual victim was never the point. The defense against it is ordinary care, and ordinary care mostly works.

Targeted work is a different activity. The effort someone will spend on a person is proportional to what that person is worth, and above a certain threshold it becomes worth weeks of somebody's time. At that point the attempt stops looking like a scam. It arrives knowing your assistant's name, the name of the school your children attend, the deal you closed last month, and the way you write when you are in a hurry.

This is the distinction that makes exposure meaningful or meaningless. A person with a large public footprint and nothing worth taking is broadly safe, because no one has a reason to spend the time. A person with a modest footprint and significant assets is not, because someone does.

There is no Indian study of how often the wealthy here are targeted specifically. The international picture is clear enough to be indicative. Research on Western executives puts the C-suite at many times the targeting rate of other employees, and around half of large organizations report that their leaders' personal lives were directly attacked in the past two years.

If you are reading this because your name means something in your industry or your city, the rest of this report describes what has probably already been done, quietly, without your knowledge, and without anything you would recognize as an attack.

III

The anatomy of collection

Almost nothing is broken into.

The picture of a targeted person is assembled from material that is published, purchasable, or simply lying open. Most of the work is legal. All of it can be done without ever touching the person it describes. And it is increasingly automated, which means it costs almost nothing and can be done to many people at once.

There are six places it comes from.

Public record and the brokers

Property records, corporate filings, directories, old registrations, and the data broker industry that consolidates and resells all of it.

No study of Indian executives exists. The closest work analyzed 750 executives in the United States and found nearly all of them listed on three dozen or more broker sites, with many on more than a hundred. Around seven in ten profiles carried social media details and photographs. Ninety-five percent contained information about family members, relatives, and neighbors. Four in ten brokers held the IP address of the executive's home network.

The Indian picture is unlikely to be better. Removal mechanisms here are weaker, the right to have data deleted is newer and less tested, and property and corporate records are broadly open. We say this as an expectation and not as a finding, because the research has not been done.

Credentials that never expire

An old password is not history. It is inventory.

The research is consistent on this. Around 60% of the breach datasets circulating are recycled compilations of older material, and only a small fraction represent genuinely new events. Roughly two thirds of exposed credentials now appear in plain text rather than as hashes, because software that steals from a browser takes the password after it has been typed, before any protection applies. In 2025, more than 51 million such stolen credential packages were processed by one intelligence firm, a rise of 72% in a year.

The consequence is simple. A password you retired in 2019 is still in circulation, still being sold, and still being tried, and it is being tried alongside your email address, your phone number, your date of birth, and your mother's maiden name from a different breach entirely.

The people around you

Nobody attacks a careful person directly if there is a less careful person nearby.

Your spouse's account settings. A teenager who tags a location. A parent who accepts every request. A member of household staff who has been on the payroll for eleven years and would never question an instruction that sounds like you. An assistant whose professional profile lists exactly who she works for and exactly what she has access to.

The approach usually arrives through one of them, and it usually works because there is no agreed way to check. Almost no household has one.

Movement and routine

Not where you are on a given day. Where you reliably are, and roughly when.

The gym on the same three mornings. The restaurant you return to. The route the driver takes. The lobby visible behind you in a photograph. The flight posted from the lounge rather than after landing. Each item is trivial and each is published willingly, most often by other people. Together they produce a pattern, and a pattern is what someone needs in order to be somewhere at the same time as you.

The connected home

A house now runs on somewhere between thirty and a hundred connected devices, most installed by whoever was available, none of them anyone's responsibility afterward, and many never updated again.

Cameras are the pointed case. In July our team examined a collection of attack tools that included operational files showing access to internet-exposed cameras and video recorders, with saved screenshots of the management interfaces. Among the camera flaws the collection was equipped to exploit was one first disclosed publicly in 2017.

A camera bought for security becomes, unattended, a way to watch the inside of a house and learn its routine. That is the full extent of the irony and we will leave it there.

Face and voice

The five sources above can all be reduced. This one cannot, which is what makes it different.

If you speak at conferences, give interviews, appear on video, or record anything at all, the material required to reproduce your face and your voice is already public, and the tools to do it are ordinary now. What follows is a class of harm that lands mostly on other people while carrying your name.

The Indian cases are documented. In late 2024, two Bengaluru residents lost between them in the region of ₹95 lakh after seeing fabricated videos of two of India's best-known industrialists endorsing a trading platform; one of the two, a 57-year-old woman, lost ₹67.1 lakh. In January 2025 a Bengaluru chartered accountant, a professionally skeptical reader of financial claims, filed a complaint after losing ₹23.20 lakh to the same category of video. Between February and May 2025 a 59-year-old man in Pune lost ₹43 lakh to a fabricated endorsement of an AI trading platform. In October 2024 a telecom chairman disclosed publicly that his voice had been cloned and used to call a senior executive in Dubai and request a transfer; the executive's own caution stopped it.

The National Stock Exchange has issued a public warning that videos of business figures recommending stocks are fabricated. The national computer emergency response team issued an advisory in November 2024 on AI-generated media being used for impersonation and social engineering. At least one of the industrialists concerned has publicly warned the country not to believe videos of him.

None of these men lost money. What they lost was the reliability of their own name, and there is no removal request that restores it.

Figure 3 — The six sources
PUBLIC RECORD AND BROKERS CREDENTIALS FACE AND VOICE THE PEOPLE AROUND YOU THE CONNECTED HOME MOVEMENT AND ROUTINE
What is assembled, and where it comes from.

If you want an honest reading of which of these six already applies to you, our self-assessment takes about two minutes and sends nothing anywhere.

IV

What it looks like from the other side

Everything above describes what is collected. This is what the collecting looks like when you find it.

The control panel

On 6 June 2026, during routine intelligence work, our team identified an openly accessible server hosting a phishing operation run from a single web interface.

It was not a page. It was an operation. The panel held ready-made impersonations of Microsoft 365, Facebook, LinkedIn, Gmail, and PayPal, each written around an ordinary and unalarming pretext: your password expires today, someone viewed your profile, your mailbox is full, your account has been limited. Alongside them sat the working parts: a tool for extracting email addresses, a second for checking which of them were live, a third for sending in volume, a fourth for generating the message itself, and modules for handling session cookies and reaching mailboxes.

By 27 June the server was unreachable.

At the time we examined it, the address it ran from was not identified as malicious by any of the security vendors we checked.

Two things follow, and they matter more than the technical detail.

The first is that this work no longer requires skill. Assembled into one interface, with the templates written and the lures generated, the operator needs no particular ability. The barrier that used to keep this kind of operation rare has been removed, and what is left is a product.

The second concerns the module for handling session cookies. A session cookie is what your browser holds after you have logged in, and it is what tells a service that you are still you. Taken intact, it can be used without your password and without the code from your phone, because the login already happened. This is the quiet gap in the reassurance most people are given. Two-factor authentication is worth having. It is not the wall it is described as.

The repository

On 28 July 2026 our team identified a second open directory, this one holding hundreds of offensive tools: scanning templates for finding vulnerable systems at scale, web shell utilities, a command-and-control framework, tunneling software, and exploit code for a range of disclosed vulnerabilities. It also contained artifacts indicating that AI assistance had been used in developing the exploits themselves.

And it held the operational files described earlier, showing access to internet-connected cameras and video recorders.

By 1 August the server was gone.

Figure 4 — Inside one control panel
IMPERSONATIONS Microsoft 365 Facebook LinkedIn Gmail PayPal WORKING PARTS Email extractor Email validator Bulk sender Lure generator Session cookie handling Mailbox access ONE INTERFACE
Observed 6 June 2026.
Figure 5 — How long each server existed
Server one · 6 June to 27 June 2026 21 DAYS Server two · 28 July to 1 August 2026 4 DAYS 1 JUN 1 JUL 1 AUG
The first server was unflagged by the security vendors we checked while it was running.
V

Why the warning arrives late

Twenty-one days. Four days.

Neither server was flagged while it was running. Both had done whatever they were built to do before anyone catalogued them.

This is not a failure of the tools. It is their design. Reputation lists, threat feeds, and signature-based detection work by recognizing what has already been identified, which means they are accurate about the past and structurally behind the present. Infrastructure that exists for three weeks is gone before it is known, and the operator has already moved to the next server.

The same lateness runs through everything in section III.

Removal from broker sites decays. The information is republished from upstream sources, and a list cleared in March is repopulated by September. Removal done once is a snapshot; the exposure is a subscription.

Breached credentials never expire. There is no process by which a leaked password is recalled. It circulates permanently, is recombined with newer material, and becomes more useful over time rather than less, because each new breach adds another attribute to the same person's profile.

And the collection itself leaves no trace. Nothing alerts when a property record is looked up, a profile is scraped, or a family member's account is read. By the time there is anything to detect, the study is finished and the approach is already being made.

Which leaves an uncomfortable position for anyone relying on ordinary defenses. The exposure accumulates continuously, the tools that watch for it look backward, and the only moment they reliably notice anything is after it has happened.

VI

What actually closes it

The hard part was never the knowledge. What follows is what we would tell anyone, client or not.

Reduce what can be collected, and treat it as maintenance. Property held out of your personal name where that is lawful and practical. A phone number that is not attached to your public identity. Removal requests to the broker sites, filed and then filed again, on a schedule, because they will be repopulated. Old accounts closed rather than abandoned. Street imagery of your home blurred, which most mapping services will do on request. None of this is difficult. It fails only when it is done once.

Assume what has been collected will be used, and make it useless. Unique passwords everywhere, which is now a solved problem for anyone willing to use a password manager. Codes from a hardware key or an app rather than by text message, because a phone number can be transferred to another SIM by someone who convinces a shop assistant. Then the step almost nobody takes: protect the recovery path. One email address and one phone number sit behind everything else you own, and they are usually the least defended things you have. And since sessions can be stolen intact, sign out of what you are not using and review active sessions occasionally.

Agree on a way to verify, before you need one. The most effective single measure available to a household costs nothing. Decide, out loud, that any instruction involving money or access is confirmed through a second channel, no matter who it appears to come from, no matter how urgent it sounds, and with no social cost to the person who checks. Tell your assistant that you would rather be interrupted than obeyed. Most successful attacks on wealthy people in India would fail against one phone call, and the call does not get made because nobody has been told they are allowed to make it.

Treat the household as the unit. Your family and your staff share your exposure whether or not they have any say in it. Doing this alone protects the least reachable person in the house.

Watch the collectors, not only the collection. This is the one that cannot be done alone, and we would rather say that plainly than pretend otherwise. Scanning for your own exposure tells you what has already happened. Watching the infrastructure being built, the campaigns being prepared, and the tools being staged is what puts you in front of it. That is what our two June and July findings were: not alerts about someone's data, but observations of an operation being assembled, weeks before it would have reached anyone.

VII

Where protection itself should live

There is a last question this report leads to, and it applies to us as much as to anyone.

If the problem is that your private life accumulates, continuously and invisibly, in places you neither see nor control, then the shape of the problem is not really theft. It is accumulation. Every list, every profile, every dataset that holds a version of you is somewhere your life exists without your knowledge, and each one is only as safe as the least careful custodian on it.

Which makes the standard answer strange when you look at it directly. Nearly every service built to protect a person like you begins by gathering everything about them, storing it, monitoring it, and holding it on the company's own systems. The protection creates one more accumulation, one more custodian, one more copy of your private world in a building you have never visited.

So the question worth asking any firm you consider, including this one, is where their data about you lives, and who can open it.

Valcryst was built around that question. Your protection runs from a dedicated machine installed inside your own home. Your data stays there, behind a door only you hold the key to. We watch what moves against you and we act when it matters, and we never hold what we are protecting.

You are not asked to trust us with it, because we never have it.

If your name is public and your assets are real, some of this has already happened. Most of it is reversible. The part that isn't can be watched.

Request a private consultation

A confidential conversation. We respond within 24 hours.

A vault only you can open.

Sources

Ministry of Home Affairs, Indian Cyber Crime Coordination Centre, and National Cyber Crime Reporting Portal figures for 2021 to 2025, as reported to Parliament and in official releases.

Data broker analysis of 750 executives: BlackCloak research, United States.

Executive targeting rates and organizational reporting: BlackCloak, 2026.

Credential and breach dataset figures: Constella Intelligence, 2026 Identity Breach Report.

Indian impersonation cases: complaints registered with Bengaluru and Pune police as reported in the press between November 2024 and 2025; public statements by the individuals concerned; National Stock Exchange investor warning; CERT-In advisory, November 2024.

Control panel investigation: our intelligence team, server identified 6 June 2026, unreachable 27 June 2026.

Exploit repository investigation: our intelligence team, server identified 28 July 2026, unreachable 1 August 2026.