Bogus CERT-In Ransomware Recovery Support Scam — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: High | View Full Scam Details
🛡️ Want to check if you've received this scam?
Check This Scam on BharatSecure →Beware the Bogus CERT-In Ransomware Recovery Support Scam in India (2026)
Scammers posing as officials from CERT-In are targeting Indian internet users with fake ransomware recovery offers, aiming to steal money via UPI and gain remote access to devices.
What Is the Bogus CERT-In Ransomware Recovery Support Scam?
In 2026, a troubling cybercrime pattern has emerged across India involving fraudsters impersonating representatives of CERT-In (Indian Computer Emergency Response Team). These scammers claim they can help victims recover from ransomware attacks, but their true intent is to defraud individuals and businesses by accessing their bank accounts and personal data.
This scam primarily targets people who have interacted with cyber threat alerts or recently experienced hacking scares. Using sophisticated social engineering, scammers create an illusion of official support by referencing recent data breaches or cyber incidents reported in the victim's industry or locality. The scam has been reported in multiple Indian states, with clusters in metros where internet penetration and UPI usage are high.
Government agencies such as CERT-In and the Indian Cyber Crime Coordination Centre (I4C) have issued advisories warning the public about this fraudulent activity. The Reserve Bank of India (RBI) regularly cautions users against sharing UPI PINs or sensitive details over phone or messaging apps, reinforcing the need for vigilance.
How This Scam Works — Step by Step
Initial Contact: Victims receive a WhatsApp message or phone call claiming to be from CERT-In’s ransomware recovery support team. The call may appear official, using caller ID spoofing to mimic government numbers.
Building Credibility: The caller references recent cyberattacks hitting Indian businesses or government institutions, sometimes naming the victim’s workplace or sector to seem well-informed.
Creating Urgency: The scammer warns that the victim’s system or data is compromised and personal or financial information is at risk unless they act quickly.
Requesting Remote Access: To “fix” the problem, the scammer persuades the victim to install a remote access tool (like AnyDesk or TeamViewer) so they can “inspect” the device.
Extracting Sensitive Data: While connected, the scammer navigates the victim’s phone or computer, noting bank accounts and UPI-linked apps, and may ask the victim to enter OTPs or share UPI PINs citing recovery procedures.
Financial Theft: Using the collected details, scammers initiate unauthorized UPI transactions or transfer funds through fake loan or insurance platforms.
Follow-up Threats: Some victims report repeated calls demanding money or threatening to leak personal data, amplifying pressure to pay.
Real Warning Signs to Watch For
- Calls or messages claiming affiliation to CERT-In but asking for payment or sensitive credentials.
- Urgent warnings about security breaches that feel exaggerated or unclear.
- Requests to install remote access software unexpectedly.
- Demands to share UPI PINs, OTPs, or Aadhaar details over phone or chat.
- Use of official-looking but unverifiable phone numbers or WhatsApp accounts.
- References to recent, unrelated cyber incidents to gain trust.
- Pressure tactics emphasizing immediate action or threats of data leaks.
What Happens to Victims
Victims may suffer significant financial losses, often via quick UPI transactions that are hard to reverse once confirmed. Unlike credit card chargebacks, UPI payments are instant and generally final. This leaves many victims struggling to recover amounts ranging from a few thousand rupees to lakhs.
Beyond money, victims face emotional stress from the invasion of privacy and fear that Aadhaar or bank details could be misused for further fraud. Some victims report unauthorized SIM swaps following these scams, which worsen the impact by allowing scammers access to more authentication codes and accounts.
The fallout often disrupts daily life and work, especially for small business owners dependent on digital banking and payment apps.
What RBI and CERT-In Say
The RBI has repeatedly issued guidelines warning users never to share UPI PINs or OTPs with anyone over phone or messaging apps. They emphasize that no government agency, including CERT-In, will ever call unsolicited to ask for such information or remote access to devices.
CERT-In has released alerts cautioning against fraudsters impersonating its officials offering ransomware or malware recovery help. They ask citizens to verify any suspicious communication on official CERT-In channels and report threats via the Indian Cyber Crime Portal or the 1930 cybercrime helpline.
These advisories form part of India’s broader effort, under the Information Technology Rules 2021 and Cybercrime laws, to protect citizens from online fraud.
How to Protect Yourself
- Ignore unsolicited calls or WhatsApp messages claiming to be from CERT-In or similar agencies.
- Never share UPI PINs, OTPs, or Aadhaar details over phone or messaging apps.
- Do not install remote access software at a stranger’s request.
- Verify any suspicious message or call by visiting official CERT-In or RBI websites or calling their helplines.
- Use UPI transaction SMS alerts and promptly report unauthorized transactions to your bank.
- Block and report unknown numbers or WhatsApp contacts sending unsolicited security alerts.
- Regularly update device security settings and apps as recommended by official sources to reduce vulnerability.
What to Do If You've Been Targeted
- Immediately disconnect the device from the internet and uninstall any unfamiliar remote access apps.
- Contact your bank or UPI app support to block or freeze transactions connected to the incident.
- File a complaint on the National Cyber Crime Reporting Portal at cybercrime.gov.in.
- Lodge a FIR at your local police station with details of the scam.
- Report the incident to CERT-In through their official complaint channels.
- Call the 1930 cybercrime helpline for advice and support.
- Change all important passwords and monitor your financial accounts carefully for unusual activity.
Frequently Asked Questions
Q: Can CERT-In ever call me to ask for remote access or PINs?
A: No. CERT-In does not call individual users unsolicited or ask for sensitive information like UPI PINs, OTPs, or remote access to devices. Any such communication should be treated as suspicious.
Q: What should I do if I shared my UPI PIN or OTP with such callers?
A: Immediately contact your bank to block your UPI ID and review recent transactions. Report the incident on the cybercrime portal and call the 1930 helpline for guidance.
Q: How can I verify if a message or call from CERT-In is genuine?
A: Check CERT-In’s official website or contact their verified support lines. Genuine government communication will never ask for private credentials or remote access.
Help protect yourself and others—if you receive suspicious messages or calls about ransomware recovery, verify them first at BharatSecure.app and report fraud promptly at 1930.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Related Scams in Our Database
- Confinement and Forced Scam Labour Abroad — Severity: CRITICAL
- Thailand Transit to Cyber Trafficking Scam — Severity: CRITICAL
- Kidnapping Threat With AI-Cloned Voice — Severity: CRITICAL
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.