Fake CERT-In Ransomware Audit Compliance Scam — How to Identify & Stay Safe
INDIA — By BharatSecure Threat Intelligence Team ·
Severity: Critical | View Full Scam Details
🛡️ Want to check if you've received this scam?
Check This Scam on BharatSecure →Beware the Fake CERT-In Ransomware Audit Compliance Scam in India (2026)
A rising cybercrime trend in India involves fraudsters impersonating CERT-In officials to trick businesses into ransomware audit compliance scams, risking severe financial and data losses.
What Is the Fake CERT-In Ransomware Audit Compliance Scam?
The Fake CERT-In Ransomware Audit Compliance Scam targets small and medium enterprises (SMEs) and startups across India. Scammers pretend to be officials from CERT-In (Indian Computer Emergency Response Team), a government agency responsible for cybersecurity incident handling and advisories. They claim the company has failed an urgent ransomware vulnerability audit required by recent Indian cybersecurity compliance regulations. Given growing government focus on ransomware and data protection, many businesses are anxious about meeting CERT-In’s cyber hygiene standards, which these fraudsters exploit.
This scam is increasingly reported in sectors that heavily use online payments, cloud services, and sensitive customer data — such as fintech, insurance, healthcare, and IT startups. Victims come from across India, including metros and tier 2 cities, reflecting the expanding reach of digital business. The scam leverages UPI transactions and WhatsApp communications to establish contact, making it particularly critical since India’s Unified Payments Interface (UPI) ecosystem is deeply intertwined with digital financial flows.
While specific official advisories on this fake CERT-In ransomware audit scam are yet to be published, CERT-In and the Indian government have broadly warned about phishing, social engineering, and fraudulent impersonations. The RBI and agencies under the Ministry of Electronics and Information Technology (MeitY) continue urging vigilance against such cyber threats.
How This Scam Works — Step by Step
Identifying the Target: Scammers scan social media platforms like LinkedIn and business forums to find SME and startup profiles, especially those listing services in finance, insurance, and IT.
Initial Contact: They send a well-crafted WhatsApp or LinkedIn message, claiming to be CERT-In cybersecurity officials conducting mandatory ransomware vulnerability audits under new government guidelines.
Creating Urgency: The message or call alleges the company failed a recent security scan, and non-compliance could lead to fines, legal penalties, or blocking of UPI payment services linked to the business.
Verification Request: The fraudsters ask the victim to share KYC documents such as Aadhaar scans, PAN cards, and business registration certificates, claiming this is needed to verify compliance and schedule a follow-up audit.
Installing “Audit Software”: Next, they request permission to install remote access software or specialized “audit tools” on the victim’s computer to “fix” vulnerabilities. This is often accompanied by instructions to disable antivirus and firewall protections temporarily.
Monetary Demand: Once remote access is granted, the scammers access bank account details or UPI-linked apps and request “processing fees” or “penalties” to complete the audit. Payments are requested via UPI apps or directed to fake digital wallets.
Data Theft and Financial Loss: By this stage, sensitive documents and personal data are copied. Fraudsters may also initiate unauthorized UPI transactions or trick company managers into transferring money to fraudulent accounts.
Real Warning Signs to Watch For
- Messages or calls claiming official CERT-In identity but originating from personal WhatsApp numbers or non-official email domains.
- Urgent language pressuring immediate payment or document sharing.
- Requests for Aadhaar, PAN, or bank details outside official government portals.
- Instructions to disable antivirus or firewall software.
- Calls arranged through social media platforms instead of formal government communication channels.
- Demands for payments via UPI to unknown or unverifiable IDs.
- Requests for installing remote access software without prior official verification.
What Happens to Victims
Victims often suffer significant financial losses as UPI payments cannot always be reversed once completed. Fraudulent UPI transactions may siphon off company funds before the business realizes the theft. Moreover, exposure of Aadhaar or PAN details can lead to long-term identity misuse and compromised compliance with tax or cybersecurity regulations. Victims face the daunting task of freezing accounts, filing FIRs, and mitigating reputational damage within their business sectors. Emotional stress and loss of trust in digital payment ecosystems are common repercussions.
What RBI and CERT-In Say
The Reserve Bank of India (RBI) regularly issues guidelines on secure digital payments, emphasizing that merchants should never share sensitive OTPs or authentication details. CERT-In, under MeitY, provides cybersecurity alerts and encourages businesses to verify any ransomware or audit-related notices directly through official government websites.
For instance, the 1930 cybercrime helpline registered by the Ministry of Home Affairs is available for reporting such fraudulent calls and messages. RBI's customer grievance helpline also advises users to immediately report suspicious transactions and block compromised UPI IDs or bank accounts.
While no specific advisory currently exists for this exact scam variant, the broader framework mandates strict data protection and incident reporting for ransomware and cybersecurity breaches. CERT-In encourages advanced multi-factor authentication and cautions against sharing KYC data over unsecured channels.
How to Protect Yourself
Verify Official Communications: Always cross-check any CERT-In or government audit notice by contacting CERT-In directly through official portals or phone numbers.
Never Share KYC Details over WhatsApp or Social Media: Only submit such documents via secure, government-approved websites or in-person if requested.
Reject Immediate Payment Requests: Legitimate audits do not demand instant UPI or digital wallet payments over messages or calls.
Avoid Installing Remote Access Software from Unknown Contacts: Only certified vendors should conduct such audits after verified appointment.
Update Antivirus and Firewall Software Regularly: Do not disable these protections on unverified requests.
Enable Multi-Factor Authentication on UPI and Bank Apps: This adds an extra security layer to prevent unauthorized transactions.
Report Suspicious Calls or Messages Immediately: Use the 1930 helpline or file complaints with cybercrime.gov.in.
What to Do If You’ve Been Targeted
- Immediately disconnect and stop all communication with the suspicious caller or message sender.
- Contact your bank or payment service provider to freeze and monitor your UPI-linked accounts.
- File a police complaint at your local cybercrime police station or online at cybercrime.gov.in.
- Call the 1930 cybercrime helpline for guidance and to report the incident.
- Change all passwords and enable two-factor authentication on all business-related digital accounts.
- Monitor your Aadhaar and PAN linked services for unauthorized activity.
- Inform CERT-In and RBI through their official channels, so they can trace and possibly warn others.
Frequently Asked Questions
Q1: Can CERT-In officials contact businesses on WhatsApp or social media for audits?
Official CERT-In communication does not typically occur via WhatsApp or social media direct messages. Businesses should expect formal notices through registered emails or government portals.
Q2: What should I do if I mistakenly shared my KYC documents with a suspected scammer?
Immediately alert your bank, file a police report, and notify the UIDAI (Aadhaar) and PAN authorities to flag potential misuse. Monitor your accounts carefully.
Q3: Are UPI payments reversible if I send money to scammers posing as CERT-In?
UPI transactions are generally final and instant. Unless the recipient voluntarily refunds, reversing fraudulent payments is difficult and requires immediate bank intervention and police complaints.
For your safety, always verify suspicious messages or calls claiming to be from CERT-In or other authorities at BharatSecure.app. If you encounter such fraud, report it promptly using the 1930 cybercrime helpline.
Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.
Related Scams in Our Database
- Confinement and Forced Scam Labour Abroad — Severity: CRITICAL
- Thailand Transit to Cyber Trafficking Scam — Severity: CRITICAL
- Kidnapping Threat With AI-Cloned Voice — Severity: CRITICAL
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app.