Wednesday , June 25 2025
flowchart

Hacker to sale Indian Gov.t email credentials

Advertisement for selling the credentials of allegedly belonging to Indian government emails surfaced on the dark web marketplace. A hacker on a private forum claims that purchasing access to these government email accounts can make anyone willing to pay a few thousand rupees “become” a government officer.

WhatsApp banned on all US House of Representatives devices

The U.S. House of Representatives has banned congressional staff from using WhatsApp on government devices due to security concerns, as...
Read More
WhatsApp banned on all US House of Representatives devices

Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

Kaspersky found a new mobile malware dubbed SparkKitty in Google Play and Apple App Store apps, targeting Android and iOS....
Read More
Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

OWASP has released its AI Testing Guide, a framework to help organizations find and fix vulnerabilities specific to AI systems....
Read More
OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

In a major milestone for the country’s digital infrastructure, Axentec PLC has officially launched Axentec Cloud, Bangladesh’s first Tier-4 cloud...
Read More
Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

Hackers Bypass Gmail MFA With App-Specific Password Reuse

A hacking group reportedly linked to Russian government has been discovered using a new phishing method that bypasses two-factor authentication...
Read More
Hackers Bypass Gmail MFA With App-Specific Password Reuse

Russia detects first SuperCard malware attacks via NFC

Russian cybersecurity experts discovered the first local data theft attacks using a modified version of legitimate near field communication (NFC)...
Read More
Russia detects first SuperCard malware attacks via NFC

Income Property Investments exposes 170,000+ Individuals record

Cybersecurity researcher Jeremiah Fowler discovered an unsecured database with 170,360 records belonging to a real estate company. It contained personal...
Read More
Income Property Investments exposes 170,000+ Individuals record

ALERT (CVE: 2023-28771)
Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

GreyNoise found attempts to exploit CVE-2023-28771, a vulnerability in Zyxel's IKE affecting UDP port 500. The attack centers around CVE-2023-28771,...
Read More
ALERT (CVE: 2023-28771)  Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

CISA Flags Active Exploits in Apple iOS and TP-Link Routers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included two high-risk vulnerabilities in its Known Exploited Vulnerabilities (KEV)...
Read More
CISA Flags Active Exploits in Apple iOS and TP-Link Routers

10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

SafetyDetectives’ Cybersecurity Team discovered a public post on a clear web forum in which a threat actor claimed to have...
Read More
10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

The forum post reads, “Once you purchase the access, you will be able to reset the password or do as you please,” reads a post on the hacking forum.

But how exactly could these government emails be misused? India today reported, Take, for example, “digital arrest.” With basic information like a person’s name, phone number, and address–often readily available in public records—cybercriminals posing as law enforcement can “arrest” their victims and extort large sums of money. This tactic, known as “digital arrest,” has become a lucrative form of online fraud.

Consider the potential actions a cybercriminal could take if they had access to a target’s purchase history, payment recipients, online searches, visited websites, and social media chats.

Sale of .gov.in email accounts:

India Today’s OSINT team discovered three ads on a hacking forum, with the latest posted on November 6, promoting the sale of email IDs and their passwords.

The team examined nine email accounts from Tamil Nadu government officials with the @tn.gov.in domain. These accounts were included in a batch of 700 credentials offered by a seller, and one account seemed to belong to an IAS officer.

Although government email accounts require two-factor authentication, the Indian government mandated the use of the Kavach app in 2020 for added security. This app requires users to approve sign-in attempts from new devices. However, hackers seem to have found a way to bypass this security.

A cybercriminal told India Today they sell government email credentials for $150 (around Rs 12,600). They offered to demonstrate their access by logging into one account. The transaction uses an escrow service where forum admins hold the buyer’s payment until the seller successfully logs in.

Other sellers are offering “logs” that contain data which can be further exploited to extract email usernames and passwords. “Today I’ll be selling Indian Government Logs. The file contains over 40,000 lines full of logs,” read a forum post by a cybercriminal in September this year.

In its November 4 advisory, the FBI warned that hacked .gov.in email accounts could be misused to request emergency data from companies under false pretenses, claiming it’s needed for urgent investigations.

The FBI advisory and hacker posts show that hacked government emails could be used to ask telecom companies for call logs, carry out scams, and commit crimes such as digital arrests. They could also be used to get information from social media and cryptocurrency exchanges about their users. For instance, Meta’s “Law Enforcement Online Requests” center allows verified government emails to request user data.

Source: India today, Darkweb

(Media Disclaimer: This report is based on research conducted internally and externally using different ways. The information provided is for reference only, and users are responsible for relying on it. Infosecbulletin is not liable for the accuracy or consequences of using this information by any means)

Cyberattacks increase 105% in third quarter of 2024 in Bangladesh

Check Also

NFC

Russia detects first SuperCard malware attacks via NFC

Russian cybersecurity experts discovered the first local data theft attacks using a modified version of …

Leave a Reply

Your email address will not be published. Required fields are marked *