Hindustan Times (Jalandhar)

Phishing attacks around Aarogya Setu app on the rise, says Cert-In

- Neeraj Chauhan neeraj.chauhan@htlive.com

NEWDELHI: India’s cyber security agency CERT-In has issued an alert saying phishing attacks centered around the government’s contact tracing applicatio­n — Aarogya Setu — are spiking as cyber criminals try to take advantage of the pandemic.

The advisory states that “Aarogya Setu app-focused phishing (attacks) have seen a high rise . Scammers impersonat­e as HR department, CEO, or any other known person and target users by spreading messages like ‘your neighbour is affected’, ‘see who all are affected’, ‘someone who came in contact with you tested positive’, ‘recommenda­tions to self-isolate’, ‘guidelines to use Aarogya Setu’ among others”.

The advisory, however, fails to mention the number of such phishing cases or the rise thereof.

Phishing is a cybercrime in which a target is contacted by email, telephone or text message by someone posing as a legitimate institutio­n and are lured into providing sensitive data such as banking and credit card details.

The CERT-In or Indian Computer Emergency Response System is a government-mandated informatio­n technology (IT) security organisati­on whose purpose it is to respond to computer security incidents, report on vulnerabil­ities and promote effective IT security practices throughout the country.

“New phishing domains are created which are centered around subjects like ‘relief package’, ‘safety tips during corona’, ‘corona testing kit’, ‘corona vaccine’, ‘donation during corona,” CERT-In advisory said. CERT-In says people should beware spelling errors in emails, websites and unfamiliar email senders .

Pavan Duggal, one of the top cyber experts in the country, said, “Aarogya Setu is an insecure app. It doesn’t have the basic parameters of cyber security. We don’t have strong laws on cyber security and things like phishing are not directly covered by IT Act. The Act needs to be amended.”

Newspapers in English

Newspapers from India