• Send Us A Tip
  • Calling all Tech Writers
  • Advertise
Monday, June 15, 2026
  • Login
TechStory
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to
No Result
View All Result
TechStory
No Result
View All Result
Home India News

Govt agency CERT-In warns Net Banking users against phishing attack

by Balraj
August 12, 2021
in India News
Reading Time: 3 mins read
0
Hands of anonymous hackers holding credit card

Courtesy: boonchai wedmakawand via Getty Images

TwitterWhatsappLinkedin

The Indian Computer Emergency Response Team (CERT-In), a cybersecurity regulatory authority, has issued a warning to internet banking customers about phishing attempts, which are being exploited not only to steal crucial user data but also to execute fraudulent transactions online.

You might also like

Inside L&T’s ₹45,000 Crore Push Into Data Centres, Chips, and Clean Energy

Reliance Jio Prepares for a Landmark IPO Filing: Targets a Raise of 50,000 Crores

India AI Impact Summit 2026: Rival CEOs, Missing Speakers, and a Nation’s AI Ambition on Display

Hands of anonymous hackers holding credit card
Courtesy: boonchai wedmakawand via Getty Images

The agency has identified that Indian banking users are indeed being targeted by a unique type of phishing attack that leverages the ‘ngrok’ framework platform. Some cybercriminals simulate Indian banks in an attempt to duplicate the login credentials of net banking users, resulting in fraudulent payments.

The aforementioned ‘ngrok’ framework platform is being used to broadcast phishing websites that harvest sensitive credentials from users, such as Internet Banking passwords, phone numbers, and One Time Passwords (OTPs). Initially, the victim will receive an SMS that pretends to be a message from the bank. Suspicious links with embedded phishing hyperlinks ending in ngrok.io/xxxbank will be highlighted in the SMS. Here is an example of that:

“Dear customer your xxx bank account will be suspended! Please Re KYC Verification Update click here link http://446bdf227fc4.ngrok.io/xxxbank”

When the recipient opens the URL and enters it with their Internet banking credentials, they are redirected to a phishing website. The malicious actor then generates a two-factor authentication (OTP) token, which is sent to the victims’ phone numbers. The recipient thereafter inputs the received OTP into the phishing webpage, which is recorded by the attacker. Eventually, the attacker uses the recorded OTP to get control of the victims’ bank accounts then initiates fraudulent transactions to transfer all the funds.

In addition, In-CERT has published certain best practices that one should follow in order keep protected against such malicious actors:

Do not visit untrustworthy websites or follow suspicious links or be careful when you click on the link in spammy emails or SMS

Always check for numbers that do not seem to be genuine mobile phone numbers.

Scammers commonly use email-to-text tools to conceal their identity and avoid handing out your personal phone number. Authentic SMS messages from banks typically include a sender ID (consisting of the bank’s short name) rather than a phone number in the sender information box.

If you receive a text that pretends to be from your bank or some other financial institution, you immediately call that bank to verify if you have received a genuine request.

Whenever accessing email attachments, be cautious. Only click on URLs that precisely disclose the domain of the website. Although in doubt, individuals can use search engines to verify the organization’s website to confirm that the websites they visited are trustworthy.

Install as well as update anti-virus and anti-spyware applications alongside use the latest Operating system with the latest security patch whether it’s your smartphone or computer. Also, update your web browsers regularly as it’s the most vulnerable piece of application.

Use precautions when accessing shortened URLs, such as those from bit.ly or TinyURL. Users should hover their mouse pointer over the abbreviated URLs (if possible) to see the actual website domain they are accessing, or use a URL checker to enter a short URL and verify the full URL.

Before providing any sensitive information such as personal information or account login credentials, pay close attention to any misspellings and/or substitutions of alphabets in the URLs of the websites you are going to visit. Look for legitimate encryption certificates by verifying for the green lock in the browser’s address bar.

Restrict your app downloads to the official app stores, such as the smartphone’s manufacturer or the operating system’s app store like Apple App Store or Google Play store, to reduce the chance of downloading potentially dangerous applications. Or use open-source app marketplaces like Aurora App store or F-droid.

Customers must notify their bank as soon as they see any suspicious activity within their account. CERT-In should be notified about phishing websites and malicious messages.

Tags: CERT-Incyber crimeCyber fraudHackingngrokPhishingPhishing Attacks
Tweet54SendShare15
Previous Post

Frostpunk 2 Announced For PC

Next Post

Diablo 2: Resurrected Open Beta Is Starting on 13th August

Balraj

Balraj writes about Startup, Business, Technology related news on Techstory... For Business Enquires related to TechStory; Get in touch on: info@techstory.in...

Recommended For You

Inside L&T’s ₹45,000 Crore Push Into Data Centres, Chips, and Clean Energy

by Thomas Babychan
May 9, 2026
0
Inside L&T’s ₹45,000 Crore Push Into Data Centres, Chips, and Clean Energy

For years, Larsen & Toubro built its name on highways, refineries, ports, factories, and giant engineering contracts that most people only notice when delays pile up or ribbon-cutting...

Read more

Reliance Jio Prepares for a Landmark IPO Filing: Targets a Raise of 50,000 Crores

by Afeefa Ansari
April 19, 2026
0
Jio

Reliance Jio is preparing for what is shaping up to be the most significant initial public offering in Indian history. The numbers are high and would blow your...

Read more

India AI Impact Summit 2026: Rival CEOs, Missing Speakers, and a Nation’s AI Ambition on Display

by Thomas Babychan
February 20, 2026
0
India AI Impact Summit 2026: Rival CEOs, Missing Speakers, and a Nation’s AI Ambition on Display

At a summit meant to showcase India’s growing clout in artificial intelligence, the loudest conversations this week were not only about new language models or computing capacity, but...

Read more
Next Post
Diablo 2: Resurrected Open Beta Is Starting on 13th August

Diablo 2: Resurrected Open Beta Is Starting on 13th August

Please login to join discussion

Techstory

Tech and Business News from around the world. Follow along for latest in the world of Tech, AI, Crypto, EVs, Business Personalities and more.
reach us at info@techstory.in

Advertise With Us

Reach out at - info@techstory.in

Aviator Game India 2026

BROWSE BY TAG

#Crypto #howto 2024 acquisition AI amazon Apple Artificial Intelligence bitcoin Business China cryptocurrency e-commerce electric vehicles Elon Musk Ethereum facebook funding Gaming Google India Instagram Investment ios iPhone IPO Market Markets Meta Microsoft News OpenAI samsung Social Media SpaceX startup startups tech technology Tesla TikTok trend trending twitter US

© 2025 Techstory.in

No Result
View All Result
  • News
  • Crypto
  • Gadgets
  • Memes
  • Gaming
  • Cars
  • AI
  • Startups
  • Markets
  • How to

© 2025 Techstory.in

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?