News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

SIM Hijacking: Silent Cybercrime Draining Bank Accounts
Social Engineering

SIM Hijacking: Silent Cybercrime Draining Bank Accounts

Fraudsters are exploiting SIM card hijacking to gain unauthorized access to bank accounts and drain funds silently. Attackers convince telecom providers to transfer victims' phone numbers to new SIM cards through social engineering tactics. Once in control, criminals receive OTPs meant for the account holder, bypassing two-factor authentication and gaining complete access to financial accounts. This sophisticated crime targets customers across major Indian banks. Victims often discover the theft only after substantial amounts have been transferred. Experts recommend enabling additional security layers beyond OTP-based verification and remaining vigilant about unsolicited telecom calls. Source: The Indian Express.

via GoogleNews: SIM swap fraudRead source
Will SIM-binding Truly Stop India's Fraud Problem?
Identity Theft

Will SIM-binding Truly Stop India's Fraud Problem?

India's push to implement SIM-binding technology aims to prevent unauthorized access to mobile services and reduce fraud-related crimes. The measure requires linking SIM cards more securely to user identities, potentially blocking scammers from hijacking numbers for phishing attacks and financial fraud. However, experts question whether this alone solves the broader cybercrime landscape in India. While SIM-binding may raise barriers for fraudsters, concerns remain about implementation gaps, authentication vulnerabilities, and evolving attack methods that bypass traditional protections. Security analysts suggest complementary measures including stronger password protocols, two-factor authentication, and user awareness are equally essential. The initiative represents a step forward in mobile security but requires comprehensive strategy to truly combat India's rising cyber fraud epidemic. Source: Communications Today.

via GoogleNews: SIM swap fraudRead source
Russian Hackers Exploit Router Flaws to Steal Microsoft Tokens
Data Breaches

Russian Hackers Exploit Router Flaws to Steal Microsoft Tokens

Security experts have reported that Russian military intelligence-linked hackers are exploiting vulnerabilities in older internet routers to obtain authentication tokens from Microsoft Office users. This advanced spying campaign has affected over 18,000 networks globally, allowing hackers to extract these tokens without the need for malicious software. As a result, users’ credentials can be compromised, posing a significant threat to organizational and personal data security. Awareness and proactive security measures are essential for users to protect themselves against such targeted attacks. Source: CyberSathi.in.

via Krebs on SecurityRead source
Bengaluru man loses ₹2.51 crore in fake IPO scheme via Facebook ad
Investment Fraud

Bengaluru man loses ₹2.51 crore in fake IPO scheme via Facebook ad

An 80-year-old Bengaluru resident fell victim to an investment fraud after clicking on a Facebook advertisement promising returns through a fake Initial Public Offering (IPO). The scammers convinced him to invest ₹2.51 crore, claiming high profit potential. The fraudsters used social engineering tactics and fabricated investment documents to appear legitimate. This case highlights how cybercriminals exploit elderly citizens through social media platforms and investment-related schemes. Authorities have been alerted to investigate the incident. Users are advised to verify investment opportunities through official channels and avoid clicking suspicious ads on social media platforms. Source: The Hindu.

via GoogleNews: investment scam IndiaRead source
German Authorities Identify Leader of Notorious Russian Ransomware Gangs
Ransomware

German Authorities Identify Leader of Notorious Russian Ransomware Gangs

German law enforcement has identified Daniil Maksimovich Shchukin, a 31-year-old Russian, as the mastermind behind the infamous ransomware groups GandCrab and REvil. Shchukin is reported to have orchestrated over 130 cyberattacks between 2019 and 2021, targeting various victims for extortion and computer sabotage. This revelation sheds light on the activities of Russian cybercriminals and underscores the ongoing efforts of international authorities to combat ransomware threats. The identification of Shchukin is a significant step in addressing cybercrime on a global scale, as it can lead to increased cooperation among law enforcement agencies. Source: [publication name].

via Krebs on SecurityRead source
Wiper Malware Targets Systems in Iran Amid Ongoing Conflict
Malware

Wiper Malware Targets Systems in Iran Amid Ongoing Conflict

A new malware called 'CanisterWorm' has emerged, targeting systems in Iran for data destruction. This worm is spread through insecure cloud services and specifically aims at computers set to Iranian time zones or using Farsi as the default language. The group behind this attack seems to be motivated by financial gain and appears to be trying to capitalize on the current tensions in Iran. Organizations and users in affected regions are advised to enhance their security measures to protect against such threats. Regular data backups and system updates are recommended to mitigate potential damage. Source: [publication name].

via Krebs on SecurityRead source
US and Allies Disrupt Major IoT Botnets Behind DDoS Attacks
Malware

US and Allies Disrupt Major IoT Botnets Behind DDoS Attacks

The U.S. Justice Department, alongside Canadian and German authorities, has successfully dismantled the infrastructure of four significant botnets that had compromised over three million Internet of Things (IoT) devices, including routers and web cameras. The botnets, named Aisuru, Kimwolf, JackSkid, and Mossad, were responsible for a series of powerful distributed denial-of-service (DDoS) attacks that could incapacitate a wide range of targets. This operation marks a significant effort to enhance cybersecurity and mitigate the risks associated with such large-scale attacks. Internet users are urged to secure their IoT devices to prevent future compromises. Source: [publication name].

via Krebs on SecurityRead source
Iran-Backed Group Claims Cyber Attack on Medical Firm Stryker
Malware

Iran-Backed Group Claims Cyber Attack on Medical Firm Stryker

An Iranian-linked hacktivist group has announced it carried out a wiper attack on Stryker, a prominent medical technology company headquartered in Michigan. Reports indicate that Stryker’s largest facility outside the U.S., located in Ireland, has temporarily sent its workforce of over 5,000 employees home due to the incident. Additionally, an automated message at the company’s U.S. headquarters alerts that they are facing an emergency situation in the building. These developments highlight growing concerns over the vulnerability of critical infrastructure to cyberattacks. Authorities are likely to investigate the extent of the breach and ensure that measures are put in place to safeguard sensitive information. Source: [publication name].

via Krebs on SecurityRead source
Major Crypto Fraud Accused Arrested Attempting Sri Lanka Escape
Crypto Scams

Major Crypto Fraud Accused Arrested Attempting Sri Lanka Escape

Authorities apprehended a key suspect in a massive cryptocurrency fraud case involving approximately Rs 20,000 crore while he was attempting to flee to Sri Lanka. The arrest marks a significant development in one of India's largest crypto-related financial crimes. Investigators have been tracking the accused's movements as part of their ongoing probe into the elaborate scheme. The case highlights the growing menace of cryptocurrency-based frauds targeting Indian investors and the need for enhanced border vigilance to prevent accused criminals from absconding. Further details about the investigation and the accused's role in the scam are expected to emerge as authorities continue their inquiry. Source: NDTV.

via GoogleNews: cryptocurrency scamRead source
Microsoft Issues March 2026 Security Updates for Windows and Software
Malware

Microsoft Issues March 2026 Security Updates for Windows and Software

Microsoft has released its March 2026 security updates, addressing 77 vulnerabilities across its Windows operating systems and additional software applications. Unlike previous months, there are no critical 'zero-day' vulnerabilities reported this time. However, organizations using Windows should prioritize some of these patches due to potential risks. It's important for users and IT administrators to stay informed about the updates to ensure their systems remain secure against possible cyber threats. Regular application of patches can help maintain the safety of user data and enhance overall cybersecurity posture. Source: CyberSathi.in.

via Krebs on SecurityRead source
AI Assistants Influencing Cybersecurity Landscape
Malware

AI Assistants Influencing Cybersecurity Landscape

Artificial Intelligence-based assistants are becoming increasingly popular among developers and IT professionals. These autonomous programs can access a user's computer, files, and online services to automate various tasks. However, their rapid adoption is raising new security concerns for organizations. The use of these tools is reshaping security priorities and creating challenges in distinguishing between trusted colleagues and potential insider threats. This blurring of roles is further complicated by the varying levels of expertise among users, from advanced hackers to beginners. As AI becomes more integrated into workplace processes, it is crucial for organizations to address these emerging risks. Source: [publication name].

via Krebs on SecurityRead source
Bank Fraud Cases in India Rise Over 16 Years
Investment Fraud

Bank Fraud Cases in India Rise Over 16 Years

A statistical analysis spanning 2008 to 2024 documents the growing trend of bank fraud cases across India. The data reveals how fraudulent activities targeting financial institutions have evolved over this 16-year period, reflecting changing tactics used by cybercriminals and fraudsters. This comprehensive overview helps understand the scale of banking sector vulnerabilities in the country. The statistics underscore the importance of strengthened security measures, customer awareness, and regulatory oversight to combat fraud. Banks and customers alike must remain vigilant against evolving threats including phishing, identity theft, and unauthorized transactions. The data serves as a crucial reference point for policymakers and financial institutions working to reduce fraud incidents and protect depositors' interests. Source: Statista.

via GoogleNews: bank fraud IndiaRead source