Bogus CERT-In Ransomware Recovery Support Scam — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: High | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

Beware the Bogus CERT-In Ransomware Recovery Support Scam in India (2026)

Scammers posing as officials from CERT-In are targeting Indian internet users with fake ransomware recovery offers, aiming to steal money via UPI and gain remote access to devices.

What Is the Bogus CERT-In Ransomware Recovery Support Scam?

In 2026, a troubling cybercrime pattern has emerged across India involving fraudsters impersonating representatives of CERT-In (Indian Computer Emergency Response Team). These scammers claim they can help victims recover from ransomware attacks, but their true intent is to defraud individuals and businesses by accessing their bank accounts and personal data.

This scam primarily targets people who have interacted with cyber threat alerts or recently experienced hacking scares. Using sophisticated social engineering, scammers create an illusion of official support by referencing recent data breaches or cyber incidents reported in the victim's industry or locality. The scam has been reported in multiple Indian states, with clusters in metros where internet penetration and UPI usage are high.

Government agencies such as CERT-In and the Indian Cyber Crime Coordination Centre (I4C) have issued advisories warning the public about this fraudulent activity. The Reserve Bank of India (RBI) regularly cautions users against sharing UPI PINs or sensitive details over phone or messaging apps, reinforcing the need for vigilance.

How This Scam Works — Step by Step

  1. Initial Contact: Victims receive a WhatsApp message or phone call claiming to be from CERT-In’s ransomware recovery support team. The call may appear official, using caller ID spoofing to mimic government numbers.

  2. Building Credibility: The caller references recent cyberattacks hitting Indian businesses or government institutions, sometimes naming the victim’s workplace or sector to seem well-informed.

  3. Creating Urgency: The scammer warns that the victim’s system or data is compromised and personal or financial information is at risk unless they act quickly.

  4. Requesting Remote Access: To “fix” the problem, the scammer persuades the victim to install a remote access tool (like AnyDesk or TeamViewer) so they can “inspect” the device.

  5. Extracting Sensitive Data: While connected, the scammer navigates the victim’s phone or computer, noting bank accounts and UPI-linked apps, and may ask the victim to enter OTPs or share UPI PINs citing recovery procedures.

  6. Financial Theft: Using the collected details, scammers initiate unauthorized UPI transactions or transfer funds through fake loan or insurance platforms.

  7. Follow-up Threats: Some victims report repeated calls demanding money or threatening to leak personal data, amplifying pressure to pay.

Real Warning Signs to Watch For

What Happens to Victims

Victims may suffer significant financial losses, often via quick UPI transactions that are hard to reverse once confirmed. Unlike credit card chargebacks, UPI payments are instant and generally final. This leaves many victims struggling to recover amounts ranging from a few thousand rupees to lakhs.

Beyond money, victims face emotional stress from the invasion of privacy and fear that Aadhaar or bank details could be misused for further fraud. Some victims report unauthorized SIM swaps following these scams, which worsen the impact by allowing scammers access to more authentication codes and accounts.

The fallout often disrupts daily life and work, especially for small business owners dependent on digital banking and payment apps.

What RBI and CERT-In Say

The RBI has repeatedly issued guidelines warning users never to share UPI PINs or OTPs with anyone over phone or messaging apps. They emphasize that no government agency, including CERT-In, will ever call unsolicited to ask for such information or remote access to devices.

CERT-In has released alerts cautioning against fraudsters impersonating its officials offering ransomware or malware recovery help. They ask citizens to verify any suspicious communication on official CERT-In channels and report threats via the Indian Cyber Crime Portal or the 1930 cybercrime helpline.

These advisories form part of India’s broader effort, under the Information Technology Rules 2021 and Cybercrime laws, to protect citizens from online fraud.

How to Protect Yourself

  1. Ignore unsolicited calls or WhatsApp messages claiming to be from CERT-In or similar agencies.
  2. Never share UPI PINs, OTPs, or Aadhaar details over phone or messaging apps.
  3. Do not install remote access software at a stranger’s request.
  4. Verify any suspicious message or call by visiting official CERT-In or RBI websites or calling their helplines.
  5. Use UPI transaction SMS alerts and promptly report unauthorized transactions to your bank.
  6. Block and report unknown numbers or WhatsApp contacts sending unsolicited security alerts.
  7. Regularly update device security settings and apps as recommended by official sources to reduce vulnerability.

What to Do If You've Been Targeted

Frequently Asked Questions

Q: Can CERT-In ever call me to ask for remote access or PINs?
A: No. CERT-In does not call individual users unsolicited or ask for sensitive information like UPI PINs, OTPs, or remote access to devices. Any such communication should be treated as suspicious.

Q: What should I do if I shared my UPI PIN or OTP with such callers?
A: Immediately contact your bank to block your UPI ID and review recent transactions. Report the incident on the cybercrime portal and call the 1930 helpline for guidance.

Q: How can I verify if a message or call from CERT-In is genuine?
A: Check CERT-In’s official website or contact their verified support lines. Genuine government communication will never ask for private credentials or remote access.

Help protect yourself and others—if you receive suspicious messages or calls about ransomware recovery, verify them first at BharatSecure.app and report fraud promptly at 1930.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.