Cybersecurity & Compliance
Rs 110–125 Crore NICSI Messaging Deal Under Govt Review Following Bogus Certification Allegations
NEW DELHI: The government has initiated a review of documents submitted for a Rs 110–125 crore annual contract recently awarded by the National Informatics Centre Services Incorporated (NICSI) for SMS and messaging gateway services, following allegations that the winning vendor, OneXtel Ltd., may have submitted invalid or fraudulent certification.
Background of the Contract
In January 2026, OneXtel Ltd. was empaneled by NICSI to provide messaging services for central and state government departments, public sector undertakings, and autonomous bodies. The contract, initially spanning three years with a possible two-year extension, was expected to generate annual revenue of Rs 110–125 crore. Services under the contract include OTP-based authentication, transactional alerts, public awareness campaigns, emergency notifications, and Rich Communication Services (RCS).
NICSI, operating under the Ministry of Electronics and Information Technology (MeitY), manages government messaging infrastructure critical to large-scale citizen communication.
The Certification Controversy
The contract came under scrutiny after a whistleblower alleged that OneXtel submitted a CMMI Level 5 certification issued by UK Certification & Inspection Limited, a body not authorized by the CMMI Institute (now under ISACA) to grant such appraisals.
CMMI (Capability Maturity Model Integration) Level 5 is the highest maturity rating, indicating optimized and continuously improving processes, and serves as a key eligibility criterion for government tenders involving critical infrastructure. Only CMMI-authorized Lead Appraisers can issue valid certifications, which are publicly verifiable via the Published Appraisal Results System (PARS).
According to the complaint, neither OneXtel Ltd. nor the issuing body appears in the official CMMI partner registry or on PARS, raising questions about the certificate’s validity.
Official and Expert Insights
A senior bureaucrat, speaking on condition of anonymity, told The420.in that certifications like CMMI Level 5 are crucial for ensuring operational reliability, privacy protection, and legal compliance in government communications. Accepting an invalid certificate compromises procurement integrity, and agencies are expected to verify appraisals independently.
The officer likened reliance on unverifiable certifications to allowing someone with a fake driving license to operate a vehicle—posing legal and operational risks. Corrective actions in such cases can include disqualification, cancellation of empanelment, withholding purchase orders, or temporary debarment.
OneXtel’s Troubled Past
This probe follows previous regulatory action. In July 2024, the Department of Telecommunications (DoT) suspended OneXtel and another telemarketer, V-Con, for sending 55.5 million fraudulent or phishing SMSes to smartphone users. The suspensions followed complaints lodged on the Chakshu portal regarding malicious messaging practices.
Next Steps
The ongoing review focuses on verifying the authenticity of the CMMI certificate and assessing due diligence conducted during the empanelment process. If the allegations are substantiated, the findings could lead to contract reassessment and strengthen scrutiny of certification verification procedures in government procurement.
At the time of reporting, neither NICSI nor OneXtel Ltd. had issued an official statement regarding the complaint or the government review.
Cybersecurity
AI-Powered Cyber Threats Put India’s Financial Sector Under Growing Pressure, Report Warns
New security assessment highlights deepfakes, identity attacks, supply-chain risks and weaknesses beyond traditional compliance systems
India’s banking, financial services and insurance (BFSI) sector is facing a rapidly changing cyber threat environment as attackers increasingly use artificial intelligence, deepfake technology, identity manipulation and advanced digital techniques to target financial systems.
A new Digital Threat Report 2025-26 developed by SISA, CERT-In and CSIRT-Fin warns that cyber risks are evolving faster than many organisations can strengthen their defences. The report highlights that modern attacks are no longer limited to stealing information but are increasingly focused on disrupting transactions, compromising trust and exploiting digital infrastructure.
The assessment notes that several cyber trends predicted in the previous edition of the report have already become widespread, showing that the time between emerging threats and real-world attacks is becoming significantly shorter.
Deepfakes and AI Increase Sophistication of Financial Fraud
Artificial intelligence has become a major factor behind the growth of sophisticated cyber fraud campaigns. The report identifies AI-driven impersonation, deepfake videos, automated phishing and advanced social engineering as key challenges for financial institutions.
Criminal groups are increasingly using realistic fake identities, manipulated communications and AI-generated content to deceive employees and customers. Traditional verification methods based only on visual or voice recognition are becoming less reliable as attackers improve their ability to imitate trusted individuals.
The report also highlights rising risks from business email compromise, credential theft and session hijacking. Attackers are using stolen access details and legitimate user sessions to bypass security measures instead of directly breaking authentication systems.
Cyber incidents affecting India’s BFSI sector are estimated to be significantly higher than the global average, with reported incidents increasing substantially in recent years. The report stresses that organisations must focus on analysing user behaviour, device activity and transaction patterns rather than relying only on passwords or authentication checks.
Identity Protection Becomes a Critical Security Challenge
Cybercriminals are increasingly targeting digital identities after successful login attempts. The report warns that attackers are focusing on session tokens, application programming interface (API) keys, service accounts and cloud-based permissions.
In these situations, security systems may not detect a traditional authentication failure because attackers are operating through valid sessions or stolen credentials. Financial institutions are therefore being urged to strengthen identity monitoring and continuously review access privileges.
The report recommends improved management of non-human identities, stronger credential protection and better visibility into digital activity across applications and cloud environments.
Compliance Alone Cannot Guarantee Cyber Resilience
The report highlights a growing gap between meeting regulatory requirements and achieving real-world cybersecurity readiness.
While compliance frameworks help organisations establish security standards, they may not always reveal weaknesses that appear during active attacks. The report identifies issues such as outdated security practices, incomplete monitoring and gaps between designed controls and their actual operation.
For example, encryption may protect stored information but may not secure data while it is being processed. Multi-factor authentication can confirm identity but may not stop attackers who have already gained access through stolen sessions.
The report advises financial organisations to treat compliance as a starting point rather than a complete security solution. Continuous testing, threat simulations, behavioural monitoring and regular security reviews are recommended to strengthen resilience.
Business Logic Attacks and Hidden Threats Expand Risk
Modern attackers are increasingly exploiting weaknesses in how financial systems operate rather than simply attacking technical vulnerabilities.
The report warns that payment systems, transaction limits and verification workflows can be manipulated through unusual sequences of legitimate actions. Attackers may abuse authorised functions in ways that developers never intended, making such activities difficult to detect.
It also highlights threats from fileless malware, encrypted communication channels and incomplete monitoring systems. These techniques can allow attackers to remain hidden while moving through networks or extracting sensitive information.
Report Calls for Continuous Cyber Defence Strategy
The assessment outlines several major security challenges expected to shape the future threat landscape, including AI-powered fraud, identity compromise, payment manipulation, supply-chain attacks and risks affecting critical financial infrastructure.
To address these challenges, the report recommends an 18-month security improvement roadmap focused on strengthening basic protections, expanding monitoring capabilities and redesigning security architecture.
The report concludes that cybersecurity must become an ongoing business priority for financial organisations. In an environment where cyberattacks can scale rapidly through automation and AI, periodic security checks are no longer enough. Continuous protection, testing and adaptation will be essential to maintaining trust and stability in the financial sector.
Cybersecurity
Dell BIOS Flaw Lets Hackers Recover Admin Passwords Within Seconds
Firmware vulnerability allows rapid password recovery on affected Dell devices, raising concerns over enterprise hardware security
A newly disclosed security vulnerability in the BIOS firmware of several Dell devices could allow attackers to recover administrator and user BIOS passwords within seconds, according to cybersecurity researchers.
The flaw, identified as CVE-2026-40639 and documented in Dell’s security advisory DSA-2026-197, is linked to an insecure password storage method inside certain firmware components. Rather than exploiting weak passwords, attackers can take advantage of how BIOS credentials are encrypted and stored.
Although exploitation generally requires physical access to the affected device or low-level system access, successful attacks could bypass important firmware security protections that help secure the boot process.
Faulty Encryption Method Exposed BIOS Credentials
Researchers found that some Dell systems stored BIOS passwords using a weak repeating-key XOR encryption method instead of a stronger cryptographic protection mechanism.
The affected passwords are stored in the Dell Variable (DVAR) section of the SPI flash memory, where firmware settings are maintained. According to researchers, weaknesses in the encryption design allow sensitive key information to be recovered from stored password data.
The problem is particularly serious for shorter passwords because unused storage space in the encrypted password field can reveal portions of the encryption key. This enables attackers to recover passwords directly instead of attempting traditional password-cracking methods.
Even longer passwords may remain vulnerable because the system’s key-generation process relies on limited device-specific information, reducing the complexity required for recovery.
Researchers Identify Affected Dell Platforms
The vulnerability was discovered by security researchers Craig S. Blackie of MDSec and Darren McDonald of AmberWolf during an investigation into Dell UEFI firmware.
Their analysis identified issues in the SystemPwSmm firmware component, which is used across multiple Dell client systems. Testing confirmed exposure on devices including:
- Dell Latitude E7250
- Dell Latitude 7490
- Dell XPS 15 9560
- Dell Wyse 5070 thin client
Researchers noted that newer Dell platforms using the Security Information Vault Block design with SHA-256-based protection were not affected during testing.
The difference highlights that Dell has already implemented stronger firmware security methods on newer hardware, although some older systems remain dependent on the vulnerable design.
Attack Requires Access, But Impact Could Be Significant
The vulnerability is not considered a remote attack because hackers typically need physical access to a device or the ability to obtain a firmware image from the system.
However, once attackers gain access, recovering BIOS passwords can reportedly be performed without user interaction or authentication. This creates risks for corporate laptops, shared devices and systems used in environments where physical security cannot always be guaranteed.
BIOS passwords often protect settings related to Secure Boot, boot order changes and other pre-operating system controls. If compromised, attackers could potentially weaken security protections or interfere with systems protected by disk encryption technologies.
Security experts warn that firmware-level weaknesses are particularly dangerous because they operate beneath the operating system and can affect multiple layers of device security.
Dell Releases Updates and Advises Security Measures
The vulnerability was privately reported to Dell in March 2026. After reviewing the findings, Dell published its security advisory and began releasing firmware updates for affected product lines.
Initial updates covered several platforms, including Precision systems, Rugged Latitude devices, Embedded PCs and Edge Gateway products. Additional fixes for other affected models were expected as part of Dell’s broader remediation effort.
Cybersecurity
AI-Driven Deepfake Fraud Poses Rising Threat to India’s Banking Sector, Experts Warn
India’s banking and financial ecosystem is facing a rapidly evolving cyber threat as criminals increasingly deploy artificial intelligence (AI)-powered deepfake technology to carry out sophisticated fraud operations. Experts warn that synthetic voices, manipulated videos, and AI-generated identities are now being actively used to bypass security systems and deceive both institutions and customers.
Deepfakes Undermining Traditional Banking Verification Systems
Cybersecurity researchers report that deepfake-enabled fraud is becoming capable of defeating conventional authentication methods used by banks and financial service providers. These systems, which often rely on voice verification, facial recognition, or identity-based confirmation, are proving vulnerable to AI-generated replicas.
Criminal groups are now using advanced machine learning tools to create highly realistic imitations of individuals, including bank employees, relationship managers, and customers. These digital impersonations are being used to authorize fraudulent transactions, gain unauthorized account access, and manipulate real-time digital payment systems.
Experts warn that such attacks are not isolated incidents but part of a growing global trend that threatens the core trust infrastructure of digital banking.
Surge in Cyber Threat Volume and Malware Integration
Recent cybersecurity assessments indicate a sharp rise in AI-assisted cyberattacks over the past year. Between late 2024 and 2025, monitoring systems recorded hundreds of millions of threat detections, with alerts triggered every minute across financial networks.
A significant portion of these incidents involved malicious software such as Trojans and file-based infectors, often combined with social engineering tactics. These methods are increasingly being used alongside deepfake technology to enhance the credibility of fraudulent schemes.
Cybersecurity experts highlight that attackers are now combining stolen personal data with AI-generated content, making scams more convincing and harder to detect.
Experts Call for Stronger Behaviour-Based Security Systems
Security professionals are urging financial institutions to move beyond traditional password and OTP-based authentication methods. Instead, they recommend adopting advanced behavioural analytics and AI-driven monitoring systems capable of detecting unusual transaction patterns in real time.
Former Indian Police Service officer and cybercrime expert Prof. Triveni Singh emphasized that deepfake-driven fraud represents a fundamental shift in cybercrime methodology.
According to him, financial systems must evolve from static verification processes to dynamic, behaviour-based security frameworks that continuously assess risk during user activity.
He also stressed that cybercriminals are rapidly improving their techniques, making it essential for institutions to stay ahead through continuous technological upgrades.
Regulatory Pressure Under Data Protection Framework
The rise of AI-enabled fraud is also creating compliance challenges under India’s Digital Personal Data Protection (DPDP) Act, 2023, which mandates strict safeguards for handling personal data and securing digital transactions.
Banks and financial organisations face increased risks of regulatory penalties, reputational damage, and financial losses if they fail to prevent data breaches or fraudulent access attempts.
Experts believe that deepfake-based attacks are pushing regulators and institutions to rethink existing cybersecurity frameworks, as traditional compliance models may not be sufficient against AI-driven threats.
Growing Sophistication of Social Engineering Attacks
Security analysts note that deepfake technology is no longer experimental or limited to isolated cases. It has become a core tool in advanced social engineering campaigns targeting financial institutions.
Attackers typically gather personal information from data leaks, social media platforms, and public databases. This data is then used to create realistic fake identities, including voice clones and video impersonations, which are deployed to deceive victims into authorizing transactions or sharing sensitive information.
These methods are increasingly leading to large-scale financial losses and account takeovers.
India Strengthens Digital Defence Measures
India’s banking sector is currently upgrading its fraud detection and cybersecurity infrastructure in response to these emerging threats. Financial institutions are investing in AI-based monitoring tools, real-time transaction analysis systems, and multi-layer authentication mechanisms.
However, experts caution that technology alone may not be sufficient. They emphasize that cybercriminals are also evolving rapidly, creating a continuous arms race between attackers and defenders.
Global Rise of Deepfake Cybercrime
The issue is not limited to India. Around the world, governments, financial institutions, e-commerce platforms, and even public sector systems are increasingly being targeted by deepfake-enabled cybercrime.
Cybersecurity analysts describe this as a global digital security crisis, where AI is simultaneously enabling innovation and enabling new forms of fraud at an unprecedented scale.
Public Awareness Remains the Strongest Defence
Despite technological advancements, experts agree that user awareness remains a critical line of defence against deepfake scams. Individuals are advised to remain cautious of unsolicited calls, video messages, or banking instructions received through unofficial channels.
Authorities recommend verifying all financial requests directly with official bank communication channels before taking action.
As AI-generated content becomes increasingly indistinguishable from real media, experts warn that vigilance, verification, and digital literacy will play a key role in preventing financial fraud in the coming years.
-
Business3 years agoPot Odor Does Not Justify Probable Cause for Vehicle Searches, Minnesota Court Affirms
-
Business3 years agoNew Mexico cannabis operator fined, loses license for alleged BioTrack fraud
-
Business3 years agoAlabama to make another attempt Dec. 1 to award medical cannabis licenses
-
Business3 years agoWashington State Pays Out $9.4 Million in Refunds Relating to Drug Convictions
-
Business3 years agoMarijuana companies suing US attorney general in federal prohibition challenge
-
Business3 years agoLegal Marijuana Handed A Nothing Burger From NY State
-
Business3 years agoCan Cannabis Help Seasonal Depression
-
Blogs3 years agoCannabis Art Is Flourishing On Etsy
