News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

Digital Arrest Scams: Recognizing Tactics and Protecting Yourself
Social Engineering

Digital Arrest Scams: Recognizing Tactics and Protecting Yourself

Digital arrest scams continue to plague Indian citizens in 2026, with fraudsters impersonating law enforcement officials to extort money. Scammers use threatening calls, fake warrant claims, and intimidation tactics to coerce victims into immediate payments. Warning signs include unsolicited contact from unknown numbers, threats of legal action, and demands for verification through digital payments. Citizens should verify caller identity through official channels, never share personal or financial information with unverified callers, and report suspicious activity to local authorities. Understanding these manipulation techniques helps protect against financial loss and emotional distress. Source: Legal Service India.

via GoogleNews: OTP scamRead source
Fake Planning Commission Emails Target Grand Island Officials
Phishing

Fake Planning Commission Emails Target Grand Island Officials

Grand Island authorities have alerted residents to a fraudulent email scam impersonating the local planning commission. Cybercriminals are sending deceptive emails to trick recipients into clicking malicious links or revealing sensitive information. Officials urge the public to verify email authenticity by contacting the planning commission directly through official channels before responding to unexpected messages. Residents should avoid clicking suspicious attachments or links and report suspected phishing attempts to authorities. This type of social engineering attack commonly targets government agencies and citizens. Source: KSBN Local 4.

via GDELT: phishing scamRead source
FBI Alerts Users to Microsoft 365 Phishing Campaign
Phishing

FBI Alerts Users to Microsoft 365 Phishing Campaign

The FBI has issued a warning about an active phishing scam targeting Microsoft 365 account users. Cybercriminals are using fraudulent emails designed to appear legitimate, attempting to trick users into revealing their login credentials and sensitive information. Once compromised, attackers can gain unauthorized access to personal and corporate data. The FBI advises users to verify sender email addresses carefully, avoid clicking suspicious links, and enable multi-factor authentication on their accounts. Organizations should educate employees about recognizing phishing attempts and implement robust email security measures. Reporting suspected phishing attempts to the FBI's Internet Crime Complaint Center (IC3) is recommended. Source: Fox 10 Phoenix.

via GDELT: phishing scamRead source
Banks and Telcos Test Cybersecurity Defenses with AI Tools
Data Breaches

Banks and Telcos Test Cybersecurity Defenses with AI Tools

Indian banks and telecommunications companies are evaluating their cybersecurity readiness by testing public-facing systems using advanced AI models like Opus 4.7 and GPT 5.5. Organizations are also requiring suppliers to conduct security assessments and identify vulnerabilities. The Data Security Council of India (DSCI), operating under Nasscom, is assisting companies in preparing for these cybersecurity evaluations. This proactive approach aims to strengthen defenses against evolving digital threats and ensure robust protection of customer data and financial systems. Source: Economic Times.

via Economic Times TechRead source
Ransomware Gang Uses Social Engineering to Target Law Firms
Social Engineering

Ransomware Gang Uses Social Engineering to Target Law Firms

The FBI has issued a warning about the Silent Ransom Group, a cybercriminal organization targeting law firms across the United States. The gang employs social engineering tactics to gain unauthorized access to servers and databases containing sensitive client information. Rather than relying solely on malware, the actors are using deceptive techniques to manipulate employees into granting access to critical systems. Law firms are particularly attractive targets due to the confidential nature of their data, including client communications and financial records. The FBI's alert highlights the importance of employee security awareness training and strict access controls. Indian legal professionals should implement similar protective measures, including multi-factor authentication, regular security audits, and staff training on recognizing social engineering attempts. Source: FBI Advisory.

via RSS: Dark ReadingRead source
Delivery Worker Arrested in Nursing Job Scam Ring
Social Engineering

Delivery Worker Arrested in Nursing Job Scam Ring

Police have arrested a delivery worker as the third suspect in an ongoing nursing job scam investigation. The suspect allegedly posed as a recruitment official to defraud job seekers aspiring for nursing positions. Victims reportedly paid fees for placement promises that never materialized. Authorities are continuing their investigation to identify additional accomplices and recover fraudulently obtained funds. Job seekers are advised to verify recruitment agencies through official channels and avoid paying upfront fees for employment opportunities. Source: The Times of India.

via GoogleNews: job scam IndiaRead source
Cybercriminals Leak Uruguayan Citizens' Data
Data Breaches

Cybercriminals Leak Uruguayan Citizens' Data

A significant data breach has exposed approximately 5.8 million records belonging to Uruguayan citizens, marking another instance of cybercriminals targeting government institutions across Latin America. The stolen information is being leveraged for financial gain by threat actors. This incident highlights growing vulnerabilities in government cybersecurity infrastructure in the region, where personal data of millions remains at risk of exploitation. Authorities are investigating the breach to determine how attackers accessed such large volumes of sensitive citizen information and what protective measures are needed. Source: Cybersecurity publication.

via RSS: Dark ReadingRead source
Cyberabad Police Arrest 10 in Multi-State Cybercrime Crackdown
Cyber Law (India)

Cyberabad Police Arrest 10 in Multi-State Cybercrime Crackdown

Telangana's Cyberabad Cybercrime Police concluded a week-long operation targeting online criminals across multiple states. The coordinated effort resulted in the detection of six distinct criminal cases and the arrest of ten accused individuals. The crackdown reflects ongoing efforts by law enforcement to combat organized cybercriminal networks operating across state boundaries. Authorities coordinated with law enforcement agencies in other states to apprehend suspects and gather evidence. The operation highlights the growing coordination between state police forces to address interstate cybercrime. Further details about the specific nature of offences and accused profiles are expected as the investigation progresses. Source: The Hindu.

via GoogleNews: job scam IndiaRead source
AI-powered cyber threats escalating globally, warns UK spy chief
Cyber Law (India)

AI-powered cyber threats escalating globally, warns UK spy chief

Britain's chief cyber intelligence officer, Anne Keast-Butler, has raised alarm over artificial intelligence being weaponized for cyber attacks threatening national security worldwide. She emphasizes that nations exist in an undefined space between peace and war due to escalating digital threats. Russia is actively targeting critical infrastructure and democratic institutions, necessitating urgent coordination among allied nations to strengthen cybersecurity defenses and counter evolving AI-driven threats effectively. Source: Reuters.

via Economic Times TechRead source
CISA Lists Three New Security Flaws Under Active Exploitation
Malware

CISA Lists Three New Security Flaws Under Active Exploitation

The US Cybersecurity and Infrastructure Security Agency (CISA) has identified three vulnerabilities being actively exploited by cyber attackers: CVE-2026-8398 in Daemon Tools Lite, CVE-2026-45321 in TanStack, and CVE-2026-48027 in Nx Console. All three contain embedded malicious code or unspecified security issues. CISA maintains a Known Exploited Vulnerabilities catalog to track threats affecting government systems. While federal agencies must patch these flaws urgently, CISA recommends all organizations prioritize fixing these vulnerabilities as part of their security practices. Regular monitoring and timely updates remain critical for protecting networks from active cyber threats. Source: CISA.

via RSS: CISA AlertsRead source
WhatsApp launches five security features to combat scams
Social Engineering

WhatsApp launches five security features to combat scams

WhatsApp has introduced multiple anti-scam tools to protect users from fraudulent activities. The features include Silence Unknown Callers, which blocks calls from numbers not in your contact list, Context Cards that display caller information, and Device Linking alerts to notify users of unauthorized access attempts. These tools aim to reduce scam-related incidents by providing users with better visibility and control over incoming communications. The platform continues enhancing its security infrastructure to combat social engineering attacks and fraudulent schemes targeting Indian users. Source: MobiGyaan.

via GoogleNews: WhatsApp scamRead source
Does cybercrime insurance cover Mythos threats?
Malware

Does cybercrime insurance cover Mythos threats?

Cybercrime insurance policies are being examined for their effectiveness against Mythos-related threats. As cyber attacks evolve, businesses in India are questioning whether existing insurance coverage adequately protects against emerging malware variants and sophisticated cyber threats. Insurance providers are reassessing policy terms and coverage limits to address modern cybersecurity challenges. Understanding policy exclusions and claim procedures is crucial for Indian organizations seeking comprehensive protection. Experts recommend reviewing coverage details and working with insurers to ensure adequate protection against current threats. Source: Forbes India.

via GoogleNews: data breach IndiaRead source