How the other half scams

Years ago, when landlines were still common and Internet shopping was not, I got a phone call from a policeman, who said he was in Selfridges and did I know where my credit card was? Suppressing the triggered memories of It’s 10 PM. Do you know where your children are?, I said, yes, yes, I did. He pressed on. Was I sure? Because someone in Selfridges was trying to use it. Could I go look? Laziness and certainty led me to balk. I also puzzled over this unlikelihood: a policeman in central London is looking me up in the phone book? Wouldn’t he call the bank, if anyone? “I’m sure,” I said. And then, on a whim, “Which bank is it?” “Lloyds.” “Wrong! But thanks for playing.” End of call.

The scam with which Mumbai-based finance and technology journalist and podcaster Soumya Gupta opens her investigation of India’s scam economy, Bharat Bluff: Inside the Cons of India’s Internet Revolution also starts with a call from a “policeman” but heads rapidly for terrifying. The policeman who calls a 20-something male software engineer claims to have a parcel he sent containing illegal goods, and says he’s under investigation. Trying to prove they have the wrong guy, he gives them his correct identity information when what they read out is wrong. The calls escalate to add threats and the accusations become more serious. Fortunately, the panicked victim gets his mom, who calls their bluff: if it’s so serious, come arrest us. Nothing happens. His mother has saved him about $10,000. (So much for the cluelessness of mothers.)

The enabler of many of these scams, Gupta says, is the personal data everyone scatters freely, on which scammers – like magicians or psychic claimants doing cold readings – can build to intimidate their victims into supplying even more information and execute the scam. India’s Internet Freedom Foundation tracks the country’s data breaches, and reports that almost every Indian’s data has been sold online following many repeated data breaches – including the government’s Aadhaar database.

As Gupta writes, anyone can be a victim if caught at the wrong time. In a more elaborate digital arrest scam in 2024 that used WhatsApp, Skype, and a deepfake video of a well-known judge, the 80-plus-year-old businessman S.P. Oswal lost about $727,000 and spent several days locked in his house under video monitoring, believing he was being investigated for money laundering. After he brought himself to tell someone, the police retrieved most of the money. Common to all these scams: props, clothing, official looking badges and cards, and backgrounds meant to signal officialdom and generate fear that overwhelms rational decision making.

Gupta places digital arrest scams in the book’s section on “fear”. She devotes further sections to two more categories: “money” (cryptocurrency Ponzi schemes, fake loan apps, hijacked legitimate businesses) and “belief” (crowdfunding by fake charities and lying social influencers, young men lured to scam call centers by the promise of good jobs). In Gupta’s view, the first two – fear and money – are old scams reimagined but that belief is a largely-new creation of the “post-Internet society”. She studies all three with a combination of interviewees’ stories and background research.

In the book’s final section, Gupta goes on to consider the underlying enabling conditions. Only 0.5% of the population used credit cards in 2007, when Indian Amazon-equivalent, Flipkart (now owned by Walmart), launched, leading the company to embrace shipping COD, so people could be sure they received their goods before paying. India moved directly from cash to online payments, bypassing the West’s intermediate steps and its legacy thicket of institutions and regulations. Unemployment, particularly among young, educated men is high. Platforms are largely indifferent – or worse, profit. Gupta highlights Apple and Google’s failure to purge their app stores of fake loan apps, which often rank higher than legitimate ones, and the 2025 Reuters report that Meta’s own internal projects expected 10% of its 2024 revenues to come from scam ads. The trust people award these platforms is a problem, too; Gupta herself was taken in by a false number that turned up in a Google search for her local wine shop. The ease of looking online and trust in Google overrode their own local knowledge.

Gupta finds other factors besides the many leaks and breaches of Indians’ data. India has digitized rapidly through the adoption of the Aadhaar identity system and the Unified Payments Interface, the source of more than two million reported cases of fraud worth more than $112 million in 2024. Indians’ “Internet” is a highly centralized handful of apps and platforms, mostly from US Big Tech companies. Social media has normalized interacting with and trusting strangers. The covid pandemic turned courts virtual, and impoverished many while opening people’s hearts and wallets to the needs of those strangers. And, she writes, India’s culture of shame leads many victims to try to save face rather than seek redress.

None of these have easy fixes. Gupta doesn’t seem to think it will have much effect to pass laws or regulate platforms, especially with the prospect of AI generating scams at scale. For self-protection, she recommends learning to pause and reconsider, and identify moments of vulnerability and suggests crossing India’s many divisions to educate those who who lack online experience, such as older rural women. And: “Build a more just society.”

Illustrations: Bharat Bluff.

Also this week: TechGrumps episode 3.42, Three thefts don’t make a right.

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.

Change of plan

It feels like the beginning of an inflection point that plans for a gigantic data center are being abandoned after years of litigation trying to block it.

The story, as told by Etiido Uko at Tom’s Hardware, is that the last of several stakeholders has abandoned the Virginia Digital Gateway, which was going to be the world’s biggest data center. It died on a technicality: the public had not been properly notified before Prince William county’s Board of Supervisors ruled to rezone the site.

The 2,100-acre project, Elroy Fernandes says at Startup Fortune, would have occupied 22 million square feet – per the developers, the equivalent of 144 Walmart supercenters. It was opposed by historical societies and local residents because it abuts the Manassas Civil War battlefield.

The site, Fernandes writes, was meant to expand the Northern Virginia Data Center Alley, which processes 70% of global Internet traffic. He suggests that the case sets a precedent that “land use fights…can kill a fully approved project after years of sunk legal and engineering costs”, is a new bottleneck to add to access to power.

Protesters elsewhere may take heart. As Ed Zitron frequently rants, the cost, number, and size of data centers being planned is staggering, especially given their unpopularity. In Pennsylvania, where 66 data centers are planned or being built thanks in part to tax incentives, the Republican candidate opposing governor Josh Shapiro’s reelection is making a moratorium on data centers part of her platform. In London, the plan to convert an old brewery into a data center occupying 5,200 square meters to enable high-frequency trading is opposed by both residents and the local council, who would rather prioritize affordable housing. In Tennessee, Texas, and Seattle (where testifying Amazon employees say the company is investigating them), have passed moratorium bans to give local governments time to study the issues they raise.

Like Wall Street in 2011 (Occupy) and Google’s buses in 2016 (see Douglas Rushkoff’s Throwing Rocks at the Google Bus), data centers provide physical targets that consolidate the spreading anger over growing inequality, Silicon Valley values, climate change, and AI in general. This could be an unpleasant fight going forward: the US FBI is beginning to fret about anti-tech extremism.

***

It seems that two 15-year-old boys were having fun in a Waymo robotaxi in San Mateo, California, drinking alcohol and firing Orbeez out of the windows until they were detained by police. According to AP News, Waymo – presumably a remote human *at* Waymo – pulled the car into a parking lot and called the cops. The San Mateo police department said the car remained unlocked and the teens could have left the vehicle.

The reactions are many and varied. One friend calls it “kidnapping”. The Register calls the car a snitch. Another friend calls Waymo’s behavior entirely justified and says the teens got what they deserved. The Daily Mail calls the car a “tattle-tale”. A separate issue is the police response: four officers with guns drawn.

At The Register, Connor Jones notes the open question: how were the teens able to rent the car? This in itself is interesting because a few years back, everyone imagined that self-driving cars would open up unaccompanied car travel to people who can’t drive – like kids and visually impaired people.

The incident opens a box of worms. Waymo’s in-car cameras and mics enabled staff to detect what was happening, divert the car, and call police with its GPS coordinates. There will be much debate about finding the line between stopping dangerous behavior and violating passengers’ privacy. The discussions we’ve had for the last decade about social media will now find their analogue in the physical world.

***

In February 2007, I wrote about legal actions brought by a once-large company, the Santa Cruz Operation (SCO).for the Guardian summarizing the complex history because the case was about to end. SCO’s four-year-old claim – that IBM had infringed its copyrights on UNIX by contributing code to Linux – had spread to Red Hat and the now-defunct networking company Novell.

By August, it was over: the judge ruled that SCO had no claim to UNIX code.

And then it wasn’t. Instead…the sadly defunct Groklaw went on covering the case in detail until 2013. In 2016, I noted that somehow “SCO” (trying to follow “SCO” through mergers and owners is like trying to win the shell game) was paying Boies, Schiller, and Flexner to file yet another appeal. That appeal, Wikipedia says, was dismissed in 2018, and it was finally settled in 2021.

But hark! What’s this thing rising, clanking and covered with slime? On Monday, Simon Sharwood reported that by the 2021 settlement “SCO” had sold its software to Xinuos, and…somehow it’s all alive again. In a hearing on June 22 – 2026! – they argued about whether Xinuos has the right to litigate this at all. One assumes someone hopes that IBM or Red Hat could be forced to pay a lot of royalties *if* their versions of Linux are ever found guilty of infringement.

This is our modern Jarndyce and Jarndyce. As Dickens said, “a scarecrow of a suit”.

Illustrations: Manassas Battlefield National Park (via Wikimedia.)

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.

International relations

The US Supreme Court’s decision this week in Trump v. Slaughter, giving the US president the power to control supposed-to-be independent agencies set up and funded by Congress, may be as profound internationally as it is domestically. In his newsletter, the economist Paul Krugman calls the president’s new power “dictatorial”, and notes the Court’s exception for the Federal Reserve. Krugman highlights the importance to average citizens of the Federal Trade Commission, which oversees consumer protection and the US’s meager privacy law. It is one of the agencies Trump now fully controls.

At day later, at Euractiv, Claudie Moreau reported that as a direct result Max Schrems and his NGO, noyb, is preparing a legal challenge to the three-year-old EU-US Data Privacy Framework.

Quick recap. This is the third time Schrems, an Austrian citizen, is challenging a formal legal arrangement for permitting data flows from the EU to the US. The saga began in 1998, when the EU Data Protection Directive, passed in 1995, came into force. To enable data flows to the US, the EU and US negotiated the Safe Harbour agreement. Then came Edward Snowden’s 2013 revelations of US intelligence spying. A bunch of lawyering later, in 2015, the European Court of Justice struck down Safe Harbour. In 2016, the EU and US replaced it with Privacy Shield, based on the US passage of the 2015 Judicial Redress Act, which granted non-US citizens limited rights to access redress in US courts for illegal data transfers.

Days after arriving in office in 2017, Trump issued an executive order demanding that agencies ensure that their privacy policies exclude those who are not US citizens. In a flurry at the in-progress Computers, Privacy, and Data Protection, many asked, had he just killed Privacy Shield? Schrems’ second case was already underway, and in 2020 he won again, when the European Court of Justice struck down Privacy Shield.

“There must be no Schrems III,” the Dutch MEP Sophie int’ Veld said a few months later. That possibility pervaded CPDP 2022. Yet all agreed the big issue was and is lack of enforcement.

The 2023 adoption of the Framework was enabled by the US creation of the Privacy and Civil Liberties Oversight Board to handle complaints from and redress for foreigners whose privacy rights have been violated. Last year, again days after taking office, Trump gutted the PCLOB. Many wondered then if the Framework could survive. Schrems commented, “This deal was always built on sand.”

The SCOTUS ruling this week granting US presidents free rein to control independent agencies like the FTC, noyb writes in a press release / blog posting, “…the entire structure of the EU-US Data Privacy Framework has just collapsed”. It also notes that EU treaty law requires such agencies to be independent – and counts 259 times that the EU relies on the FTC in its data flow decision.

“Even in the European Commission’s logic, the basis for any EU-US data transfer deal is dead,” Schrems concludes. Because the Framework must be actively repealed or ruled illegal by the courts, noyb is both filing a lawsuit and asking the European Commission to repeal it.

And so begins Schrems III.

***

This week I presented the talk I did at Greenwich Skeptics in April for the Cambridge Skeptics. Titled “What We Talk About When We Talk About AI”, the talk was an attempt to disentangle the different things people mean when they say “artificial intelligence”. The AI we have – generative AI, image generators, scoring systems, surveillance systems – has little in common with the original idea mooted by Alan Turing in 1950 or the problems the Dartmouth workshop sought to solve over the summer of 1956.

The founders and CEOs of AI companies, however, seem quite happy for us to conflate the two, since it makes them sound more worth investing in. Demis Hassabis, for example, founded Deep Mind (since 2014, part of Google) with the mission statement, “Solve intelligence. Then use that to solve everything else.” With respect to at leaast some intractable problems this is obviously nonsense. We have long known what needs to be done about climate change. All the intelligence in the universe will not create the political will to do the things we already know need to be done.

Many of the things we want from AI – automation, helpers, guardians, (sadly) weapons, companions – are things humans have wanted as long as there have been humans and have many precursors. Some of these constructs, both fictional (Asimov’s Laws, Rosey the Robot), and non-fictional (Arthur C. Clarke’s Laws of Science) come up routinely in academic and legal conferences to this day. I personally don’t believe today’s “AI” paradigm will lead to a superintelligence or a new form of consciousness (as net.wars readers probably already know). But the evidence is clear that today’s “AI” can do plenty of damage to today’s people and places.

The talk ended with a few thoughts about how to respond: resist the inevitability narrative; change the framing; be specific about naming systems, their purposes and owners; and count the opportunity costs.

The talk was not recorded and is not online, but the references are.

Illustrations: Max Schrems, in 2024 (via Murielle Gerber and EPFL media library at Wikimedia.

Also this week: At Plutopia, we talk to computer security professor Steve Bellovin about his newly-released free book on home security Don’t Get Hacked!.

Wendy M. Grossman is an award-winning journalist. Her Web site has an extensive archive of her books, articles, and music, and an archive of earlier columns in this series. She is a contributing editor for the Plutopia News Network podcast. Follow on Mastodon or Bluesky.