Podcast Top News

The Smartest Man on Earth Never Uses a Smartphone”: Cyber Expert Krishna Sastry’s Alarming Warning

Krishna Sastri

Pendyala Krishna Sastry is a veteran cyber forensic expert with over 30 years of experience and a portfolio of 1,500+ cases, having served extensively in the Government of India’s intelligence and forensic wings,. He has been a pivotal figure in investigating national landmarks like the 2001 Parliament attack and the 26/11 Mumbai attacks, witnessing the evolution of forensics from paper documents to complex digital data.

In the interview, Sastry describes digital evidence as the modern “smoking gun,” explaining that almost every investigation today begins with a mobile phone because data stored as “zeros and ones” provides an undeniable trail of facts,. He highlights the critical role of the “Hash Value,” which acts as a digital fingerprint to ensure that evidence remains untampered with throughout the chain of custody. Sastry notes that while the internet used by the public is just 4% of the web, the remaining 96% the Deep and Dark Web has become a thriving marketplace for stolen Indian data, such as Aadhaar and bank details.

Sastry warns that hacking has become increasingly accessible through the weaponization of AI, where tools like “FraudGPT” allow criminals to generate perfect, highly personalized phishing emails without needing advanced coding skills. He points to the rise of “Zero-Click Malware,” which can infect a device without the user ever clicking a link, and the devastating psychological impact of “Digital Arrest” scams where victims are held hostage via video calls,. Ultimately, he advises that users must be extremely cautious, as Remote Access Trojans (RATs) can turn cameras and microphones into silent spies, prompting his observation that the “smartest man” is often the one who avoids using a smartphone for sensitive matters

Anchor (Radhika): Hello and welcome to Telugu Post, this is Radhika. We have a special guest today, cyber forensics expert Krishna Sastry Pendyala. He has experience dealing with over 1,500 cyber cases, and every word he shares is valuable information. Welcome, Mr. Krishna Sastry; thank you for giving us your time.
Krishna Sastry: Thank you.

Anchor (Radhika): You have seen the evolution from the early days of computers to modern Artificial Intelligence (AI). In your 30-year career, how did you enter the field of cyber forensics, and what was your first digital case?
Krishna Sastry: I joined the Government of India in 1990 as a Central Intelligence Officer Grade 1. I worked for 22 years in departments such as the Ministry of Home Affairs, the Intelligence Bureau, and the Directorate of Forensic Science. When we started in the 90s, investigations like Income Tax raids or police searches mostly yielded paper-based documents. However, under the Indian Evidence Act, the definition of a “document” expanded to include electronic records. Electronic evidence includes mobile phones, hard drives, and CCTV footage where data is stored in “zeros and ones,” which we call digital evidence.

Anchor (Radhika): What were some of your most important cases?
Krishna Sastry: A very prominent first case occurred on 13 December 2001, following the attack on the Indian Parliament. The laptop used by the terrorists was crucial electronic evidence and was one of the first major examinations we conducted. This case established the importance of electronic evidence in India.

Anchor (Radhika): How have terrorism activities evolved digitally since then?
Krishna Sastry: It has become common for terrorists and extremists to use internet and electronic gadgets. We refer to this electronic evidence as a “smoking gun”. Just as smoke indicates a gun has been fired, data like SMS, WhatsApp messages, and call logs now serve as the primary evidence in almost every investigation. Beyond the Parliament attack, major cases included the 26/11 Mumbai attacks and the Malegaon blast cases. In another instance from 2010-11, we investigated a major hospital fire in Kolkata where 89 people died. We extracted data from a memory chip in a fire alarm box to prove exactly when the fire started and identify delays in reporting the incident.

Anchor (Radhika): Does the digital evidence you find have a validity period?
Krishna Sastry: While a paper document can be stored in a cupboard for 10 years without much effect, electronic exhibits have a limited lifespan. Magnetic drives can demagnetise, and storage devices like “digital diaries” from the 90s rely on small batteries. If the batteries die, the memory is erased. In one case involving a seized digital diary, the delay in sending it to the lab resulted in the loss of critical addresses and phone numbers. Therefore, the time gap between a raid and forensic analysis must be very short.

Anchor (Radhika): During your service, did you ever face pressure or threats to manipulate evidence?
Krishna Sastry: No, forensic laboratories are neutral truth-finders. We are neither for the prosecution nor the defence. We maintain a strict “Chain of Custody”. We use a “Hash Value,” which is like a digital fingerprint for data. If even a single character is changed, the hash value changes, proving the evidence was tampered with.

Anchor (Radhika): What are the differences you see in cyber security between the private and public sectors?
Krishna Sastry: The nature of attacks varies. For example, North Korean hackers often target banking systems because they want money. Other groups might not care about money but target defence or space secrets (DRDO, ISRO) for national interests. In India, regulatory bodies like the RBI, SEBI, and IRDA have established strong security frameworks that organizations must implement.

Anchor (Radhika): Why do anti-virus systems sometimes fail to work?
Krishna Sastry: Approximately 9 to 10 lakh new computer viruses are created every day. An anti-virus can stop 99% of known threats, but it cannot stop a new virus that hasn’t been sequenced yet. Furthermore, with the advent of AI, hackers no longer need advanced coding skills to create malware.

Anchor (Radhika): Cyber complaint reporting rose from 6 lakhs in 2022 to 13 lakhs in 2023. Why is there such a huge increase?
Krishna Sastry: Post-COVID, digitalization and UPI transactions have surged, but public awareness of security remains low. We are now seeing “Zero-Click Malware” where your phone can be hacked without you clicking any link. We also see psychological traps like the “Digital Arrest” scam. In one case, a retired scientist was kept under “arrest” via video call for 10 days and lost his life savings.

Anchor (Radhika): What kind of codes do hackers use?
Krishna Sastry: Hackers look for an entry point, much like a thief looks for a door or window. On average, a hacker stays in a network for 186 days before being identified. They use social engineering and phishing emails to trick employees. Another major threat is “Supply Chain Risk”. For example, certain foreign-manufactured CCTV cameras have been found sending footage back to servers in their home country. This allows foreign entities to track the movements of individuals in real-time.

Anchor (Radhika): How safe are we when using our mobile phones daily?
Krishna Sastry: Your voice, face, and fingerprints are being captured. It is estimated that the biometric data of 30 crore Indians has already been compromised. Many people take phones into private spaces like washrooms or bedrooms, but RATs (Remote Access Trojans) can allow a hacker to remotely activate your camera or microphone. There is a saying that “the smartest man on earth is the one who never uses a smartphone”.

Anchor (Radhika): Does the mobile phone read our minds?
Krishna Sastry: It is “Psychological Pattern Mapping”. The technology links your browsing history and location to predict your thoughts. In Web 3.0, physical and virtual systems will interact even more based on these patterns.

Anchor (Radhika): What about the data held by companies like Google and Meta?
Krishna Sastry: India has introduced the DPDP (Digital Personal Data Protection) Act, which will be fully implemented by May 2027. Under this law, companies must obtain your consent to collect data and explain why they need it. If they use your data for unauthorized purposes, they can face penalties of up to 250 crores.

Anchor (Radhika): Tell us about the Dark Web.
Krishna Sastry: The Dark Web is a marketplace for everything from Aadhaar data and bank accounts to illegal weapons and drugs. Transactions are conducted via crypto assets for anonymity. It is difficult to track because hackers use proxies and anonymizers to hide their original IP addresses.

Anchor (Radhika): What are the future threats from AI?
Krishna Sastry: AI-based attacks are increasing in speed and personalization. Criminals now use “FraudGPT” to write perfect phishing emails without spelling mistakes. Techniques like “Click Fix” trick users into running commands that install info-stealers on their computers. In the future, we may see the creation of “Digital Twins” or avatars used to commit massive fraud.

(For article corrections, please email hyderabadmailorg@gmail.com or fill out the Grievance Redressal Form.)