Fake CERT-In Ransomware Audit Compliance Scam

INDIA — By BharatSecure Threat Intelligence Team ·

Suspicious Risk: 9/10 Severity: Critical BharatSecure Threat Intelligence

Category: UPI, WhatsApp, KYC

Verdict Summary

Fake CERT-In Ransomware Audit Compliance Scam shows strong scam indicators common in fraud targeting Indian users. Do not share OTPs, passwords, or payments — verify the source independently.

Risk score: 9/10 · Severity: Critical · Verdict: Suspicious

Scam Intelligence: Fake CERT-In Ransomware Audit Compliance Scam

Proprietary signals from BharatSecure's scam-tracking database.

Top affected regionsDelhi NCR, India, small_business, professionals
Last reportedMay 07, 2026

How Fake CERT-In Ransomware Audit Compliance Scam Works

Overview: This scam preys on Indian businesses’ anxiety about strict CERT-In (Indian Computer Emergency Response Team) compliance rules regarding ransomware attacks. Cybercriminals impersonate CERT-In auditors, warning that your company has failed a recent ransomware vulnerability scan and could face enormous fines – up to ₹1 crore. The targets are primarily small and medium enterprises (SMEs) in sectors like finance, insurance, and IT, as well as startups with limited in-house cybersecurity expertise. The danger lies not just in financial loss but also the potential for sensitive business data and credentials to be stolen. How It Works: Firstly, the scammers send urgent emails, WhatsApp, or SMS messages claiming non-compliance after a fake vulnerability scan (often mentioning seemingly official advisories such as CIWS-2026-3490 or CIAD-2026-0017). The message says immediate action is required to avoid regulatory fines. Impersonators, sometimes using titles like “KavachOne CERT-In Auditor,” then demand a "compliance fee" ranging from ₹50,000 to even ₹5 lakh via UPI, bank transfer, or sometimes cryptocurrency. Victims are provided links to highly convincing phishing websites that mimic the real CERT-In portals, where they are tricked into entering company credentials. Some variants include follow-up calls from spoofed numbers similar to CERT-In’s actual hotlines to reinforce legitimacy. India Angle: Scammers specifically exploit popular communication platforms such as WhatsApp and Gmail, as well as UPI for payments. Most targets are in metro and tier-2 cities, especially NCR, Bengaluru, Mumbai, Hyderabad, and Ahmedabad. The scam is tailored for India’s mandatory cybersecurity reporting regulations and RBI sector advisories. Fraudsters reference local rules (like the 6-hour reporting window) to make the threat feel urgent and real. Even the payment demand is often in rupees, through domestic digital wallets or UPI IDs to avoid detection. Real Examples: A Bengaluru finance firm receives a WhatsApp message: “Your institution has been flagged for non-compliance after CIWS-2026-3490 scan. Immediate compliance fix required – pay ₹95,500 to UPI ID: CERTIndia2026. Avoid ₹1 crore penalty. Link: cert-in-org-in[dot]com/secure.” Or a call stating, “This is Anirudh from CERT-In. Your systems failed latest ransomware audit. To remain compliant, pay the prescribed fee now.” Red Flags: 1. Unsolicited messages threatening hefty fines for failing imaginary scans. 2. Pressure for immediate payment via UPI or crypto to resolve compliance. 3. Email domains and links that look similar but do not match official CERT-In sites. 4. Spoofed caller IDs mimicking government numbers. 5. Demands for company credentials or login information via email or web form. Protective Measures: Always verify such compliance notifications by directly checking the official CERT-In website or contacting them via their published numbers (never those in the suspicious message). Do not click on links or download attachments from unknown sources. Never share business credentials or make payments to personal UPI IDs. Train staff to recognise typical phishing tactics and invest in reliable cybersecurity tools. Keep software and firewalls up to date. If Victimised: If you have paid or shared credentials, immediately inform your bank, freeze suspicious transactions, and report the incident to 1930 (the national cybercrime helpline) and cybercrime.gov.in. Businesses should also alert RBI and consider entering into an incident response process. Change all potentially compromised passwords. Related Scams: Similar scams include bogus RBI audit compliance frauds and fake GST penalty notices demanding payment. Another related variant is phishing for board-level identity details under the guise of “KYC revalidation.”

How This Scam Works — Detailed Explanation

Scammers often initiate the Fake CERT-In Ransomware Audit Compliance Scam by leveraging social media platforms like LinkedIn and business forums. They target small and medium enterprises (SMEs) and startups, identifying potential victims through their online presence, especially those that promote their services in sensitive sectors like finance, insurance, and IT. Once identified, these scammers craft personalized messages, portraying themselves as officials from the Indian Computer Emergency Response Team (CERT-In). They create a sense of urgency by claiming that the company has failed a mandatory ransomware vulnerability scan, thus playing on the anxiety prevalent among businesses regarding compliance with new cybersecurity regulations set by the government. This initial contact often includes professional-looking emails or instant messages that mimic genuine CERT-In communication styles, complete with logos and semi-authentic email addresses that almost mirror the official domain.

To make their deception more convincing, the scammers employ various psychological tricks. They often issue unexpected warnings about non-compliance, suggesting that large fines—ranging up to ₹1 crore—are imminent unless immediate action is taken. The pressure is further amplified with threats of operational disruption and legal consequences. Scammers may insist that payments for compliance audits be made instantly, pushing businesses to send funds via UPI or cryptocurrency to avoid penalties. This tactic is particularly effective against SMEs with limited cybersecurity knowledge and resources, as they feel trapped and vulnerable. The fear of legal repercussions often clouds their judgment, leading them to act hastily without proper verification or consultation.

Once victims have been ensnared, the scammers typically follow a systematic approach to extract funds. After making initial contact, they may guide the victims through a fake compliance process, including sending fabricated documentation and links to spoofed websites that look like the official CERT-In site. Victims are then coerced into making payments via UPI or are tricked into revealing sensitive details, such as Aadhaar numbers or bank account information, through these fake platforms. In real case scenarios, businesses have reported losing amounts ranging from ₹5 lakh to ₹50 lakh before they realize they have been scammed. Many end up reaching out to their banks—in some cases, HDFC at 1800-202-6161 or SBI at 1800-11-1109—to inquire about suspicious transactions, often learning too late that they have been tricked.

The impact of such scams on the Indian economy is alarming. According to reports from the Ministry of Home Affairs and the Reserve Bank of India, cybercrime losses in India due to scams like this have surged, with estimates indicating that ₹2,000 crore were lost to various online scams last year alone. Many of the victims of the Fake CERT-In Scam have faced not just financial losses but also reputational damage, which can be catastrophic for SMEs striving to establish credibility in their sectors. CERT-In has actively warned businesses to remain vigilant against fraudulent activities, extending guidelines that encourage companies to enhance their cybersecurity measures and employee training. The entire ecosystem is under pressure as businesses continue to invest heavily in compliance and security while still falling prey to malicious actors.

To differentiate this scam from legitimate communications, businesses must look for specific red flags. Genuine CERT-In communications usually include official government email addresses ending in '.gov.in' and will never demand immediate payments through unofficial channels like UPI or cryptocurrency. Authentic communications will also have traceable links and will provide clear information on how to verify compliance status. Further, they will typically allow for a reasonable timeframe for businesses to address concerns, unlike the aggressive, high-pressure tactics employed by scammers. By staying informed and recognizing these warning signs, companies can better protect themselves from falling victim to these elaborate schemes.

Visual Intelligence:

BharatSecure's AI has identified this as a used in scams targeting Indian users.

Who Does Fake CERT-In Ransomware Audit Compliance Scam Target?

General public across India

Red Flags — How to Identify Fake CERT-In Ransomware Audit Compliance Scam

  • Unexpected warning about 'non-compliance' or ransomware scan failure
  • Pressure to make instant UPI/crypto payment for compliance
  • Domains or emails nearly—but not exactly—matching official CERT-In addresses
  • Spoofed government phone numbers demanding money
  • Links to unfamiliar websites requesting credentials

What To Do If You Encounter Fake CERT-In Ransomware Audit Compliance Scam

  1. Report any suspicious communications to your local police or at the cybercrime helpline 1930.
  2. Verify email addresses and phone numbers by contacting CERT-In directly through their official website.
  3. Consult your bank immediately if you suspect any fraudulent transaction; contact SBI at 1800-11-1109 or HDFC at 1800-202-6161.
  4. Do not make immediate payments via UPI or cryptocurrency; take time to verify legitimacy.
  5. Educate your employees on identifying scams, emphasizing effective communication practices to validate any requests.
  6. Visit cybercrime.gov.in for resources on how to safeguard your business against cyber threats.

How to Report Fake CERT-In Ransomware Audit Compliance Scam in India

  • Call 1930 — National Cyber Crime Helpline (24x7)
  • File a complaint at cybercrime.gov.in
  • Contact your bank immediately if money was lost
  • Call RBI helpline: 14440 for banking fraud

Frequently Asked Questions

What to do if I shared my Aadhaar number with someone in a scam?
Immediately contact the Unique Identification Authority of India (UIDAI) helpline at 1947 to lock your Aadhaar number. Monitor your bank statements and report any suspicious activity to your bank.
How can I identify a genuine notice from CERT-In?
Genuine communications will come from email addresses ending in '.gov.in' and will not include urgent requests for payment through informal channels. Always verify through official contact numbers.
How do I report this type of scam in India?
You can report this scam by calling the cybercrime helpline at 1930, or by visiting cybercrime.gov.in to file an official complaint.
How can I recover money lost to this scam?
Immediately contact your bank to lodge a complaint and initiate a trace on the transaction. If the money was sent via UPI, ask for the bank's assistance in retrieving it. Document everything and report the incident via 1930.
🛡️

How This Scam Works — BharatSecure AI

Spreading fast

A plain-language breakdown based on 100 real reported scams of this type.

How they reach you Observed primary contact occurs via unsolicited phone calls, WhatsApp/SMS messages, and social media/dating platforms, where fraudsters impersonate bank officials, customer support, government agents,
How they gain your trust Trust is reportedly established through impersonation of authority (banks, RBI, PM-Kisan, army officers) or emotional bonding (love-bombing, family/friend impersonation), often reinforced by AI deepfa
How they take your money UPI is the dominant rail across all records, primarily via disguised 'collect/request money' notifications tricking victims into entering their PIN, d
Who they target Documented targets span the general population but concentrate on the elderly and digitally inexperienced (often via caregiver dependency), urban professionals, students, homemakers, small business ow
How they manipulate you
  • authority bias (impersonating banks/government/officials)
  • urgency and scarcity (account frozen, limited-time offer, emergency)
  • trust/reciprocity exploitation (familiar voices, love-bombing, small initial payouts)
Warning signs
  • Receiving a UPI 'collect/request money' notification and being asked to enter your PIN to 'receive' funds (PIN is never needed to receive money)
  • Unsolicited calls/messages claiming account freeze, KYC expiry, or suspicious transaction, pressuring you to share OTP, UPI PIN, or click a link
  • Requests to install remote-access/screen-sharing apps (AnyDesk, TeamViewer) for 'support' or 'refund' assistance
  • Mismatched or misleading recipient names/VPAs (e.g., 'Verified Merchant', 'Bank Refund Dept') or slightly altered UPI IDs
  • Pressure via emotional urgency, deepfake voice/video of familiar people, forged payment screenshots, or too-good-to-be-true offers (free recharge, prizes, grants, loans, high-return investments)

Related Scams in India

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app. BharatSecure uses AI to detect scams in real-time and protect Indian users.