Saturday , March 29 2025
flowchart

Hacker to sale Indian Gov.t email credentials

Advertisement for selling the credentials of allegedly belonging to Indian government emails surfaced on the dark web marketplace. A hacker on a private forum claims that purchasing access to these government email accounts can make anyone willing to pay a few thousand rupees “become” a government officer.

FBI investigating cyberattack at Oracle, Bloomberg News reports

The Federal Bureau of Investigation (FBI) is probing the cyberattack at Oracle (ORCL.N), opens new tab that has led to...
Read More
FBI investigating cyberattack at Oracle, Bloomberg News reports

OpenAI Offering $100K Bounties for Critical Vulns

OpenAI has increased its maximum bug bounty payout to $100,000, up from $20,000, to encourage the discovery of critical vulnerabilities...
Read More
OpenAI Offering $100K Bounties for Critical Vulns

Splunk Alert User RCE and Data Leak Vulns

Splunk has released a security advisory about critical vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These issues could lead...
Read More
Splunk Alert User RCE and Data Leak Vulns

CIRT alert Situational Awareness for Eid Holidays

As the Eid holidays near, cybercriminals may try to take advantage of weakened security during this time. The CTI unit...
Read More
CIRT alert Situational Awareness for Eid Holidays

Cyberattack on Malaysian airports: PM rejected $10 million ransom

Operations at Kuala Lumpur International Airport (KLIA) were unaffected by a cyber attack in which hackers demanded US$10 million (S$13.4...
Read More
Cyberattack on Malaysian airports: PM rejected $10 million ransom

Micropatches released for Windows zero-day leaking NTLM hashes

Unofficial patches are available for a new Windows zero-day vulnerability that allows remote attackers to steal NTLM credentials by deceiving...
Read More
Micropatches released for Windows zero-day leaking NTLM hashes

VMware Patches Authentication Bypass Flaw in Windows Tool

On Tuesday, VMware issued an urgent fix for a security flaw in its VMware Tools for Windows. CVE-2025-22230 allows a...
Read More
VMware Patches Authentication Bypass Flaw in Windows Tool

IngressNightmare
Over 40% of cloud environments are vulnerable to RCE

Kubernetes users of the Ingress NGINX Controller are advised to fix four newly found remote code execution ( RCE) vulnerabilities,...
Read More
IngressNightmare  Over 40% of cloud environments are vulnerable to RCE

(CVE-2025-29927)
Urgently Patch Your Next.js for Authorization Bypass

Next.js, a widely used React framework for building full-stack web applications, has fixed a serious security vulnerability. Used by many...
Read More
(CVE-2025-29927)  Urgently Patch Your Next.js for Authorization Bypass

Oracle refutes breach after hacker claims 6 million data theft

A hacker known as “rose87168” claims to have stolen six million records from Oracle Cloud servers. The stolen data includes...
Read More
Oracle refutes breach after hacker claims 6 million data theft

The forum post reads, “Once you purchase the access, you will be able to reset the password or do as you please,” reads a post on the hacking forum.

But how exactly could these government emails be misused? India today reported, Take, for example, “digital arrest.” With basic information like a person’s name, phone number, and address–often readily available in public records—cybercriminals posing as law enforcement can “arrest” their victims and extort large sums of money. This tactic, known as “digital arrest,” has become a lucrative form of online fraud.

Consider the potential actions a cybercriminal could take if they had access to a target’s purchase history, payment recipients, online searches, visited websites, and social media chats.

Sale of .gov.in email accounts:

India Today’s OSINT team discovered three ads on a hacking forum, with the latest posted on November 6, promoting the sale of email IDs and their passwords.

The team examined nine email accounts from Tamil Nadu government officials with the @tn.gov.in domain. These accounts were included in a batch of 700 credentials offered by a seller, and one account seemed to belong to an IAS officer.

Although government email accounts require two-factor authentication, the Indian government mandated the use of the Kavach app in 2020 for added security. This app requires users to approve sign-in attempts from new devices. However, hackers seem to have found a way to bypass this security.

A cybercriminal told India Today they sell government email credentials for $150 (around Rs 12,600). They offered to demonstrate their access by logging into one account. The transaction uses an escrow service where forum admins hold the buyer’s payment until the seller successfully logs in.

Other sellers are offering “logs” that contain data which can be further exploited to extract email usernames and passwords. “Today I’ll be selling Indian Government Logs. The file contains over 40,000 lines full of logs,” read a forum post by a cybercriminal in September this year.

In its November 4 advisory, the FBI warned that hacked .gov.in email accounts could be misused to request emergency data from companies under false pretenses, claiming it’s needed for urgent investigations.

The FBI advisory and hacker posts show that hacked government emails could be used to ask telecom companies for call logs, carry out scams, and commit crimes such as digital arrests. They could also be used to get information from social media and cryptocurrency exchanges about their users. For instance, Meta’s “Law Enforcement Online Requests” center allows verified government emails to request user data.

Source: India today, Darkweb

(Media Disclaimer: This report is based on research conducted internally and externally using different ways. The information provided is for reference only, and users are responsible for relying on it. Infosecbulletin is not liable for the accuracy or consequences of using this information by any means)

Cyberattacks increase 105% in third quarter of 2024 in Bangladesh

Check Also

NTLM

Micropatches released for Windows zero-day leaking NTLM hashes

Unofficial patches are available for a new Windows zero-day vulnerability that allows remote attackers to …

Leave a Reply

Your email address will not be published. Required fields are marked *