Moneycontrol PRO
HomeNewsBusinessEmail attachments from 'bonafide' IDs can be malicious, government alerts officials

Email attachments from 'bonafide' IDs can be malicious, government alerts officials

A cybersecurity circular issued by government asks officials to be careful while opening email attachments or links provided from bonafide gov.in/nic.in email IDs

August 21, 2023 / 14:54 IST
According to Indian Computer Emergency Response Team, India has recorded a 53 per cent increase in ransomware attacks in 2022

Government officials have been advised to be cautious even when they open email attachments coming from official gov.in and nic.in addresses, highlighting the prevalence of cyber attacks.

A cybersecurity circular issued by a government body on July 27 and reviewed by Moneycontrol said, "Users should be careful while opening email attachments or links provided even from bonafide gov.in/nic.in email ids."

The domain names gov.in and nic.in are assigned for official email IDs of government officials across the Union and state governments.

This circular comes in the backdrop of officials being targeted by threat actors through phishing emails laden with harmful virus and malwares.

When attachments are clicked, these threat actors can steal sensitive information pertaining to defence and other government bodies.

As reported by Moneycontrol, the government has detected a "new wave of cyber attack campaign" where China-based threat actors have been targeting government bodies such as the Unique Identification Authority of India (UIDAI) and the All India Institute of Medical Sciences (AIIMS).

The July circular also said that officials should not use internet connected computers to store or draft "classified official documents/correspondence".

Hackers have also been targeting officials by approaching them with domains and websites that are similar to official NIC (National Informatics Centre) IDs and sites.

An advisory listed domain names such as mydrive-nic.online and secure-nic.online, stating that they were being used by Chinese threat actors to perpetrate phishing scams. Other similar domain names include drive-nic.online, files-nic.link, files-nic.space, and nic-files.download.

This latest circular follows a similar advisory that a government body released warning against a cyber-attack campaign, where officials were receiving malware-laden emails disguised as recommendations on how to prevent honey trapping.

Aihik Sur covers tech policy, drones, space tech among other beats at Moneycontrol
first published: Aug 21, 2023 02:54 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347