Connect with us

AI & Technology

CERT-In’s AI Push Earns Praise in World Economic Forum’s Report on Cyber Fraud

Published

on

Phishing and cyber-enabled financial fraud have transformed from scattered criminal activity into a global economic threat. The World Economic Forum’s “Fighting Cyber Enabled Fraud 2025” report warns that advanced fraud networks now operate at industrial scale, exploiting cross-border digital infrastructure, AI-generated content, and anonymous domain services

The report calls for a systemic, multi-stakeholder defense model—one that starts with upstream prevention and extends through mitigation and international collaboration.

In this landscape, India’s CERT-In, under the leadership of Director General Dr. Sanjay Bahl, stands out not only for the magnitude of its data processing, but also for its shift toward proactive, automated fraud detection.

India’s Detection Engine: 9,800 Billion Queries and Counting

According to the WEF/IST paper, CERT-In used AI and situational awareness systems to analyse more than 9,800 billion DNS queries in 2024.
From this unprecedented pool of traffic, the agency was able to:

  • Detect 2.2 billion queries linked to malicious domains
  • Identify 128 million phishing-related domains
  • Mitigate 3,044 phishing sites that affected nearly 695,000 users
  • Share DNS-based threat intelligence with international partners in real time

This volume—highlighted on page 6 of the report—places India among the world’s most active national cyber-defense authorities, operating what security analysts describe as a “continental-scale early-warning system.”

A senior official familiar with the agency’s strategy noted that its rapid scaling was made possible by “a disciplined commitment to automation, global signal-sharing, and data-driven governance”—a remark widely interpreted as reflecting the operational philosophy at CERT-In’s helm.

Leadership Through Coordination, Not Visibility

While the WEF report does not single out individuals, government insiders and industry observers say the agency’s recent transformation owes much to a quiet but deliberate shift in leadership culture within CERT-In.

Instead of episodic interventions, the agency has adopted a framework built on:

  • AI-led prevention
  • Mass-scale monitoring
  • Coordinated response and inter-agency sharing
  • Global data exchange protocols

This approach has allowed CERT-In to move from reactive cyber-incident response to real-time systemic mitigation—a strategic pivot that experts say reflects “mature institutional stewardship.”

Several cybersecurity executives interviewed for this story attributed the shift to “consistent, low-visibility leadership focused on capacity building rather than public-facing announcements”—a sentiment repeated in multiple industry briefings.

A New Global Role for India’s Cyber Infrastructure

What makes CERT-In’s emergence notable is not just its domestic impact, but the global relevance of its data and threat intelligence.

The WEF paper cites India as a key contributor to safeguarding international DNS ecosystems, especially as phishing evolves into a transnational criminal enterprise. With 128 million phishing domains flagged, India is now a central contributor to worldwide fraud-mitigation workflows.

Global privacy-preserving indicator-sharing systems—highlighted in the mitigation section of the WEF report—are increasingly dependent on large, trustworthy national datasets. India’s scale, combined with CERT-In’s automation footprint, makes its threat intelligence uniquely valuable.

Security researchers say these developments suggest India is no longer merely responding to cybercrime trends, but helping shape global norms for digital safety.

What’s Next?

The WEF report calls on national agencies to adopt deeper upstream prevention, stronger domain-registration controls, and coordinated AI-assisted detection.
CERT-In, analysts say, is already moving in that direction, positioning India as a model for large-scale cyber-fraud mitigation.

As the digital ecosystem expands across payments, identity infrastructure, and AI-driven platforms, CERT-In’s role is likely to become even more central. The agency’s trajectory—shaped by a leadership approach that emphasizes capacity, infrastructure, and quiet institutional discipline—offers a template for nations seeking to counter the next decade of cyber-enabled fraud.

Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

AI & Technology

OTP Never Arrived, Savings Disappeared: Bengaluru Man Falls Victim to SIM Swap Fraud

Published

on

By

Bengaluru, June 18, 2026: A 62-year-old Bengaluru resident has allegedly lost more than ₹7.44 lakh in a sophisticated SIM swap fraud, exposing ongoing vulnerabilities in mobile-linked banking security systems and raising concerns about the growing threat of cybercrime.

According to a police complaint, the victim’s mobile number suddenly became inactive for nearly a week, preventing him from receiving calls, messages, or banking alerts. During this period, cybercriminals are believed to have gained unauthorized access to his bank account and carried out multiple transactions without his knowledge.

Mobile Number Inactive for Several Days

The incident reportedly occurred between May 31 and June 7, 2026. The victim noticed that his mobile connection had stopped working and initially suspected a technical issue. He approached his telecom service provider seeking assistance, but the disruption continued for several days.

Investigators suspect that fraudsters exploited this interruption to execute a SIM swap attack—a cybercrime technique that allows criminals to take control of a victim’s phone number. Once access is gained, they can intercept banking alerts, verification messages, and one-time passwords (OTPs) used for account authentication.

Fraud Discovered After Service Restoration

The alleged scam came to light when the victim regained access to his mobile number and attempted to log into his banking application. After encountering login problems, he visited an ATM to review his account activity.

The account statement reportedly revealed several unauthorized transactions. Alarmed by the findings, the victim immediately contacted his bank and reported the suspicious activity.

Bank officials later confirmed that ₹7,44,831 had been withdrawn or transferred from the account through transactions that the account holder claims he did not authorize.

Police Launch Cyber Fraud Investigation

Following the discovery, the victim lodged a complaint through the National Cyber Crime Helpline and submitted a formal report to law enforcement authorities. Police have since registered a case and initiated a detailed investigation.

Officials are examining bank records, telecom logs, and digital evidence to identify how the attackers gained access to the victim’s mobile number and banking credentials. Authorities have also sought information from the telecom operator regarding the status and handling of the SIM during the period of disruption.

How SIM Swap Frauds Work

Cybersecurity specialists explain that SIM swap scams typically involve fraudsters convincing telecom providers to transfer a victim’s mobile number to a new SIM card under their control. Once successful, criminals can receive OTPs and security notifications intended for the legitimate user, enabling them to bypass two-factor authentication safeguards.

This method allows cybercriminals to access banking applications and conduct fund transfers before victims become aware of the breach.

Experts Urge Greater Vigilance

The case has renewed concerns about reliance on OTP-based verification systems for financial transactions. Security experts recommend that users immediately report unexpected loss of mobile network service, monitor bank accounts regularly, and enable additional security features wherever possible.

Authorities have also advised citizens to remain cautious of suspicious calls, phishing messages, and requests for personal or banking information. Any prolonged mobile service disruption should be reported promptly to both telecom providers and financial institutions.

Investigators are exploring whether the incident may be connected to a broader cybercrime operation targeting multiple victims through coordinated SIM swap attacks. The probe remains ongoing.

Continue Reading

AI & Technology

Google Lawsuit Cites 9,000 Fake Websites Linked to Phishing Operation

Published

on

By

Google has launched a major legal offensive against an alleged international cybercrime operation accused of orchestrating large-scale phishing attacks that targeted internet users through fake websites, deceptive text messages, and artificial intelligence-powered scams.

According to the technology giant, the lawsuit is aimed at dismantling a sophisticated criminal network known as the “Outsider Enterprise,” which is allegedly responsible for stealing sensitive information, including passwords, payment card details, and personal data from victims across multiple regions.

Thousands of Fake Websites Identified

Google claims its security teams uncovered an extensive digital infrastructure supporting the operation. Investigators reportedly traced approximately 9,000 fraudulent websites and more than one million malicious URLs connected to the network.

The company alleges that the group distributes phishing toolkits that enable cybercriminals to launch convincing scams at scale. These fraudulent campaigns often impersonate trusted organizations and well-known brands, making it difficult for users to distinguish legitimate communications from malicious ones.

Google stated that the operation has already resulted in significant financial losses for consumers, amounting to millions of dollars.

AI and Messaging Platforms Used in Fraud Campaigns

The lawsuit alleges that the cybercrime network operates from China and uses messaging platforms to coordinate activities and distribute phishing resources.

Security investigators claim the group leveraged artificial intelligence technologies to enhance the effectiveness of its scams. By using AI-generated content and automated phishing tools, attackers were reportedly able to create more convincing messages and fake websites designed to trick users into revealing confidential information.

These campaigns primarily relied on text-message phishing, commonly known as “smishing,” where victims receive fraudulent messages containing links to counterfeit websites.

Millions of Suspicious Messages Detected

Google reported a sharp increase in phishing-related activity during a recent monitoring period. The company said Android users submitted reports of approximately 55,000 spam text messages within a two-week timeframe.

During the same period, security systems identified around 2.5 million text messages containing links associated with websites allegedly created by the Outsider Enterprise network.

The scale of the operation highlights the growing sophistication of cybercriminal groups that increasingly use automated technologies to expand their reach and target larger numbers of victims.

FBI Supports Ongoing Investigation

Google confirmed it is working closely with the Federal Bureau of Investigation (FBI) to disrupt the network and identify those responsible.

Cybersecurity officials have warned that criminals are rapidly adopting artificial intelligence tools to make online scams more believable and harder to detect. Law enforcement agencies believe stronger collaboration between technology companies, telecommunications providers, and government authorities is essential to combating these evolving threats.

An FBI Cyber Division representative noted that cybercriminal groups are increasingly building organized business models around impersonating trusted brands and exploiting consumer trust for financial gain.

Collaboration With Telecom Providers

Beyond legal action, Google is expanding partnerships with major telecommunications companies to strengthen protections against fraudulent messages and online scams.

The company said it will continue working with industry stakeholders to block malicious communications before they reach consumers and support legislative efforts aimed at improving long-term cybersecurity protections.

As phishing attacks become more sophisticated through the use of artificial intelligence and automated tools, cybersecurity experts continue to urge users to verify links, avoid sharing sensitive information through unsolicited messages, and report suspicious activity immediately.

Continue Reading

AI & Technology

AI-Enabled Cybercrime Raises Alarm Across India’s Banking Sector

Published

on

By

India’s banking industry is witnessing a sharp rise in sophisticated cyber fraud as criminals increasingly deploy artificial intelligence (AI) tools to execute advanced financial scams, according to a recent industry assessment. The report reveals that nearly 84% of banking leaders have experienced higher fraud-related losses over the past year, signaling an escalating threat to the country’s digital financial ecosystem.

Experts say the rapid expansion of digital banking, mobile payments, and online financial services has significantly widened the attack surface for cybercriminals.

AI, Deepfakes and Synthetic Identities Fuel New Wave of Fraud

The report highlights that attackers are now leveraging generative AI, deepfake technology, and automated social engineering tactics to target both customers and banking systems. These tools allow criminals to create highly convincing fake identities, replicate voices, and simulate realistic communication patterns.

Identity fraud, account takeovers, payment scams, and synthetic identity creation have emerged as some of the most common and damaging forms of cybercrime affecting financial institutions.

Security experts warn that AI-driven fraud is becoming increasingly difficult to detect using traditional cybersecurity systems, which were designed to counter more conventional threats.

Deepfake Technology Raises Serious Security Concerns

One of the most alarming trends is the growing use of deepfake audio and video content to impersonate individuals. Cybercriminals can now mimic bank officials, customers, or executives to manipulate verification systems and authorize unauthorized transactions.

Experts caution that such technology not only increases financial risk but also threatens the credibility of digital verification processes, which many banks rely on for customer authentication.

Banks Ramp Up Digital Defence Systems

In response to rising threats, financial institutions across India are investing heavily in advanced cybersecurity infrastructure. Banks are adopting AI-based fraud detection systems, behavioural analytics, real-time transaction monitoring, and enhanced identity verification tools.

Industry stakeholders believe that traditional security models are no longer sufficient and must be replaced with adaptive, intelligence-driven systems capable of detecting evolving threats.

Banks are also strengthening internal controls by introducing multi-factor authentication systems and expanding cybersecurity training for employees to reduce human error in fraud prevention.

Regulatory and Compliance Focus Intensifies

The report notes that regulatory compliance and data protection have become top priorities for the banking sector. Institutions are working closely with regulators to ensure stricter safeguards for sensitive financial data and digital transactions.

At the same time, banks are increasing awareness campaigns aimed at educating customers about phishing attacks, fraudulent calls, and AI-based scams.

Experts Warn of Growing Cyber Threat Landscape

Cybercrime specialist and former IPS officer Prof. Triveni Singh said that AI is reshaping the landscape of financial crime. He warned that cybercriminals are increasingly combining social engineering techniques with deepfake technology and synthetic identities to bypass security systems.

According to experts, the convergence of AI and cybercrime is creating a new generation of threats that require continuous innovation in cybersecurity strategies.

A Critical Phase for India’s Digital Banking Ecosystem

The findings suggest that India’s banking sector is entering a crucial phase where technological advancement and cybersecurity must evolve together. As digital adoption accelerates, financial institutions are expected to face more complex and automated cyberattacks.

Experts emphasize that the future of banking security will depend on how effectively institutions can integrate AI-driven defence systems while maintaining customer trust and operational resilience.

Continue Reading

Trending

Copyright © 2022 420 Reports Marijuana News & Information Website | Reefer News | Cannabis News