Bogus CERT-In Ransomware Recovery Support Scam
INDIA — By BharatSecure Threat Intelligence Team ·
Category: UPI, WhatsApp, Remote Access
Verdict Summary
Bogus CERT-In Ransomware Recovery Support Scam shows strong scam indicators common in fraud targeting Indian users. Do not share OTPs, passwords, or payments — verify the source independently.
Risk score: 8/10 · Severity: High · Verdict: Suspicious
Scam Intelligence: Bogus CERT-In Ransomware Recovery Support Scam
Proprietary signals from BharatSecure's scam-tracking database.
| Top affected regions | Tamil Nadu, India, small_business, urban |
| Last reported | May 07, 2026 |
How Bogus CERT-In Ransomware Recovery Support Scam Works
Overview: With ransomware attacks making headlines in India, scammers are now posing as CERT-In-supported cybersecurity experts to "help" victims recover their files—at a steep cost. These criminals call or message businesses and individuals, claiming to have detected dangerous AI-based threats on their networks or devices. They seem credible by citing official-sounding botnet names and stats shared by the government. The scam is dangerous because victims are not only tricked into paying for non-existent ‘cleanup’ but also risk having actual ransomware or spyware installed on their systems by the attackers. How It Works: The fraudster reaches out, usually after a widely publicised ransomware alert or incident. They claim your device or company network has been flagged during a government cyber sweep or 'CSK botnet detection' operation. Offering an urgent "free scan," they insist on remote access to your computer via tools like AnyDesk or TeamViewer. During this fake scan, the scammer points out ‘infections’ and pressures you to make payment, often ranging from ₹10,000 to as much as ₹1 lakh, promising official "decryption" or threat removal. Payment is usually demanded via UPI, and sometimes followed by a second wave of extortion once your files are held hostage by ransomware the scammer themselves has installed. India Angle: Scammers use India-specific references like CERT-In, official advisories, and recent cyber events to sound legitimate. These tactics are widespread across metros and in firms with limited technical expertise (e.g., hospitals, small factories, and NGOs), as well as among individual professionals who use digital payments. Fraud pitches are often in multiple Indian languages for broader reach, and calls may use AI to mimic local or official government accents. Real Examples: A Chennai-based manufacturing unit gets a call: “Sir, this is CERT-In botnet detection team. Your OT system is under attack by Mythos AI virus. Please allow remote access for immediate scan—no charges for first review! Later, you must pay ₹65,000 for threat removal, failure to act will permanently encrypt data.” Another: An auditor receives a WhatsApp: “CERT-In identified malware on your network. Download cleaner via link and pay for secure restoration.” Red Flags: 1. Calls claiming mandatory ‘free scans’ after a government detection. 2. Pressure to install remote access apps you did not initiate. 3. Demanding payment upfront for ransomware ‘decryption’ or file retrieval. 4. Quoting exaggerated stats (“29 lakh cases found!”) to push panic. 5. Repeated calls with heavy urgency and threats of permanent loss. Protective Measures: Never give remote access to unknown callers, no matter how urgent they sound. Remember, CERT-In does not offer individual paid support or ask for fees for recovery services. Isolate compromised devices and use only trusted IT professionals. If hit by ransomware, report directly to CERT-In, 1930, or go to cybercrime.gov.in. Back up your data regularly and use strong, unique passwords. If Victimised: Immediately disconnect compromised devices from networks. Change all relevant passwords, contact your bank if payment was made, and file a report with 1930 and cybercrime.gov.in. Inform local police as may be required. Seek help from a certified cybersecurity professional to assess further damage. Related Scams: Fake tech support calls claiming to be from Microsoft or Apple are similar in methodology, as are insurance ‘loss recovery’ cons where payment is required for fictitious services.
How This Scam Works — Detailed Explanation
Scammers are increasingly sophisticated in the way they target victims in India, especially in the context of ransomware. They often launch attacks through platforms like WhatsApp or phone calls, claiming to be affiliated with CERT-In, India's premier cybersecurity agency. These scammers gather personal information about their targets—be it through data breaches, social engineering, or online profiling—creating a facade of credibility. They may even reference recent security breaches affecting businesses in the same sector to garner trust, making them appear as 'heroes' ready to help those in distress.
Once they have the victim's attention, these scammers employ various psychological tactics to create a sense of urgency and fear. They might say something like, 'Your system has been compromised by deadly AI malware, and immediate action is required!' Such statements lead victims to panic, fearing for their data’s security or potential financial ramifications. Additionally, they often quote alarming statistics about ransomware attacks derived from credible sources or pretend to have the latest government insights. This boosts their legitimacy and causes victims to act impulsively rather than rationally, often leading them to comply with the scammer's demands.
Victims usually experience a harrowing step-by-step process following the initial contact. First, a follow-up call or message is received, where scammers ask to perform a diagnostic check on their device, requesting the installation of remote access tools like AnyDesk or TeamViewer to 'fix' the issue. Once they get access to the victim's device, they may encrypt files or manipulate existing files to create further chaos. A common tactic often involves asking for a fee—ranging from a few thousand to several lakhs—in exchange for supposedly recovering files or cleaning up their system. Many have reported losing substantial amounts of money, with the cumulative losses from such scams amounting to over ₹300 crore nationwide this year alone.
The impact of these scams in India cannot be overstated. Major organizations and individuals alike have found themselves scrambling to recover losses or mitigate damages. The Ministry of Home Affairs (MHA) and the Reserve Bank of India (RBI) have issued stern advisories regarding such fraudulent activities, reminding the public that no operational or legitimate IT entity will request remote access to your device or ask for upfront payment against cyber threats. A significant factor in these scams is the ease with which the scammers can manipulate trust and credibility, exploiting the fears associated with ransomware, particularly given the spike in such incidents reported by CERT-In recently.
Lastly, it’s crucial to learn how to distinguish between legitimate CERT-In communications and scams. Authentic representatives will never contact you unsolicited or demand payments. If contacted, verify through official channels such as visiting the CERT-In website directly or calling verified helplines. Additionally, reviewing any claims about your cybersecurity standing through direct consultations or inquiring with your service provider can clarify misinformation and provide much-needed peace of mind.
Visual Intelligence:
BharatSecure's AI has identified this as a used in scams targeting Indian users.
Who Does Bogus CERT-In Ransomware Recovery Support Scam Target?
General public across India
Red Flags — How to Identify Bogus CERT-In Ransomware Recovery Support Scam
- Caller offers unsolicited 'CERT-In recovery support' after a cyber event
- Requests installation of remote access tools (AnyDesk/TeamViewer)
- Quotes government stats or fake malware findings
- Demands payment for decryption or file cleanup
- Poor grammar or awkward language in communication
What To Do If You Encounter Bogus CERT-In Ransomware Recovery Support Scam
- Report any suspicious calls or messages to the cybercrime helpline at 1930 or via cybercrime.gov.in.
- Do not install any remote access software under any circumstances until you verify the legitimacy of the request.
- If you have responded to a scammer, immediately change your passwords for important accounts like banking and UPI.
- Contact your bank immediately using official helplines (e.g., SBI: 1800-11-1109, HDFC: 1800-202-6161) and report any unauthorized transactions.
- Inform your employer or relevant organization if the scam relates to business data or employee information.
- Stay updated on cybersecurity advisories from CERT-In to recognize the latest scams.
How to Report Bogus CERT-In Ransomware Recovery Support Scam in India
- Call 1930 — National Cyber Crime Helpline (24x7)
- File a complaint at cybercrime.gov.in
- Contact your bank immediately if money was lost
- Call RBI helpline: 14440 for banking fraud
Frequently Asked Questions
- What to do if I shared my OTP in a UPI scam?
- Immediately contact your bank's customer service (e.g., SBI: 1800-11-1109) to report the incident. Request them to freeze your account and monitor for unauthorized transactions.
- How can I identify a CERT-In scam?
- Look for unsolicited calls requesting remote access to your device or demanding payment for services that should be free or handled directly through official channels.
- How do I report this type of scam in India?
- Report the incident to the cybercrime helpline at 1930, or visit cybercrime.gov.in to file an online complaint.
- What are the recovery steps after being scammed?
- Immediately change passwords for banking and online accounts, contact your bank to report any suspicious activity, and consider monitoring your credit report for any unusual activity.
How This Scam Works — BharatSecure AI
Spreading fastA plain-language breakdown based on 100 real reported scams of this type.
| How they reach you | Observed primary contact occurs via unsolicited phone calls, WhatsApp/SMS messages, and social media/dating platforms, where fraudsters impersonate bank officials, customer support, government agents, |
| How they gain your trust | Trust is reportedly established through impersonation of authority (banks, RBI, PM-Kisan, army officers) or emotional bonding (love-bombing, family/friend impersonation), often reinforced by AI deepfa |
| How they take your money | UPI is the dominant rail across all records, primarily via disguised 'collect/request money' notifications tricking victims into entering their PIN, d |
| Who they target | Documented targets span the general population but concentrate on the elderly and digitally inexperienced (often via caregiver dependency), urban professionals, students, homemakers, small business ow |
- authority bias (impersonating banks/government/officials)
- urgency and scarcity (account frozen, limited-time offer, emergency)
- trust/reciprocity exploitation (familiar voices, love-bombing, small initial payouts)
- Receiving a UPI 'collect/request money' notification and being asked to enter your PIN to 'receive' funds (PIN is never needed to receive money)
- Unsolicited calls/messages claiming account freeze, KYC expiry, or suspicious transaction, pressuring you to share OTP, UPI PIN, or click a link
- Requests to install remote-access/screen-sharing apps (AnyDesk, TeamViewer) for 'support' or 'refund' assistance
- Mismatched or misleading recipient names/VPAs (e.g., 'Verified Merchant', 'Bank Refund Dept') or slightly altered UPI IDs
- Pressure via emotional urgency, deepfake voice/video of familiar people, forged payment screenshots, or too-good-to-be-true offers (free recharge, prizes, grants, loans, high-return investments)
Related Scams in India
Verify Any Suspicious Message
Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.