B Swaminathan
India’s cybersecurity landscape in 2025 is marked by escalating threats, technological advancements, and urgent calls for systemic reform. Artificial Intelligence is being leveraged by cybercriminals to craft highly sophisticated phishing attacks, including deepfakes and AI-generated content. Conversely, defenders are adopting AI for enhanced threat detection and response. However, 51% of IT decision-makers anticipate a successful cyberattack attributed to Gen AI within the upcoming year . In a quick chat, Bishwajit Sutradhar, Co-Founder & Director Sales and Alliances of NativeDefence Tech speaks on the trends, opportunities and avenues in the cyber security.
How are fake QR codes being used by cybercriminals to defraud digital payment users in India?
Ans- Cybercriminals in India are increasingly exploiting fake QR codes to defraud digital payment users, employing various deceptive tactics to siphon off funds.
- Tampering with Physical QR Codes
Scammers often replace legitimate QR codes at shops, petrol stations, or public places with their own. Unsuspecting customers scanning these fake codes unknowingly authorize payments to the fraudsters’ accounts. - Quishing (QR Code Phishing)
Fraudsters send QR codes via messages or emails, directing victims to counterfeit websites resembling legitimate banking or e-commerce platforms. Here, users are tricked into entering sensitive information, granting scammers access to their bank accounts. - Social Engineering Scams
Scammers pose as buyers on online marketplaces, sending QR codes under the guise of making a payment. Victims are led to believe they are receiving money but end up authorizing a transfer to the fraudster’s account instead. - Fake Reward or Urgent Action Scams
Users receive unsolicited messages claiming they’ve won a prize or need to act urgently, accompanied by a QR code. Scanning the code leads to fraudulent websites designed to steal personal and banking information.
What are the primary cybersecurity vulnerabilities in India’s healthcare sector that have made it a top target for attacks?
Ans- India’s healthcare sector has become a prime target for cyberattacks due to several critical vulnerabilities. Here’s an overview of the primary cybersecurity challenges contributing to this heightened risk:
Legacy Systems and Outdated Infrastructure
Many healthcare institutions in India continue to rely on legacy systems that lack modern security features. These outdated infrastructures are more susceptible to exploits, making them attractive targets for cybercriminals.
Proliferation of Internet of Medical Things (IoMT)
The increasing use of connected medical devices has expanded the attack surface. Many IoMT devices lack robust security measures, making them vulnerable entry points for cyberattacks.
Phishing and Business Email Compromise (BEC)
Phishing attacks remain prevalent, with cybercriminals impersonating trusted entities to deceive healthcare professionals into revealing sensitive information. Such attacks can lead to unauthorized access to critical systems and data breaches.
Insider Threats
Employees or contractors with access to sensitive information can intentionally or unintentionally compromise data security. Insider threats have led to significant data breaches in various healthcare institutions.
Insufficient Cybersecurity Awareness and Training
A lack of comprehensive cybersecurity training among healthcare staff increases the likelihood of successful attacks. Educating personnel on recognizing threats and adhering to security protocols is crucial in mitigating risks.
In what ways are cybercriminals in India leveraging AI and deepfake technologies for phishing and identity fraud?
Ans- Cybercriminals in India are increasingly leveraging AI and deepfake technologies to execute sophisticated phishing and identity fraud schemes. Here’s how these technologies are being exploited:
Voice Cloning for Impersonation
Scammers use AI to replicate voices of trusted individuals, such as family members, friends, or public figures. These cloned voices are employed in vishing (voice phishing) attacks to deceive victims into transferring money or divulging sensitive information. For instance, a 72-year-old man in Lucknow lost ₹81,747 after receiving a call from a fraudster impersonating a known acquaintance using voice modulation technology.
Video Deepfakes for Social Engineering
AI-generated deepfake videos are used to impersonate individuals in video calls, creating a false sense of authenticity. These videos are often combined with AI-generated voice synthesis to mimic the appearance, mannerisms, and voice of the impersonated person, enhancing the illusion of a genuine conversation. Such tactics have been reported in Tamil Nadu, where scammers used deepfake technology to deceive victims into transferring money.
Synthetic Identity Creation for Fraudulent Activities
Cybercriminals create synthetic identities by combining real and fabricated information, often using deepfake technology to generate realistic images and videos. These synthetic identities are then used to bypass Know Your Customer (KYC) and biometric verification systems, facilitating fraudulent activities such as opening bank accounts or applying for loans. This method has been identified as a significant challenge in combating AI-enhanced fraud.
Personalized Phishing Attacks
AI enables cybercriminals to scrape data from social media profiles and other online sources to craft highly personalized phishing emails. These emails mimic legitimate communications from banks, e-commerce platforms, or government services, making them more convincing and harder to detect. This evolution from generic to personalized phishing is a growing concern in India’s cybersecurity landscape.
Smishing Campaigns Using Generative AI
Generative AI chatbots, like ChatGPT, can be exploited to create smishing (SMS phishing) messages. Attackers can craft prompt injection attacks to generate convincing text messages that deceive recipients into clicking malicious links or sharing personal information. This emerging threat highlights the dual-use nature of AI technologies and their potential misuse in cyberattacks.
What is the phenomenon of cyber slavery, and how are Indian recruiters linked to its rise in Southeast Asia?
Ans- Cyber slavery refers to a form of modern-day enslavement where individuals are trafficked or coerced into performing illegal online activities—such as scamming, money laundering, and identity fraud—under duress. These victims are often lured by fraudulent job offers and are subjected to harsh conditions, including physical abuse, confiscation of passports, and threats of violence. In Southeast Asia, countries like Myanmar, Cambodia, Laos, and Thailand have become hotspots for such operations, with many victims originating from India.
How Indian Recruiters Facilitate Cyber Slavery in Southeast Asia
Indian recruiters play a pivotal role in the proliferation of cyber slavery by:
- Promising False Employment Opportunities: Recruiters advertise lucrative jobs in data entry, call centers, or IT sectors in Southeast Asia, often using social media platforms and job portals.
- Facilitating Travel and Documentation: They assist victims in obtaining tourist visas and provide necessary documentation, such as SIM cards and bank accounts, to facilitate the scam operations.
- Coordinating with International Syndicates: Some recruiters collaborate with overseas criminal networks, including those based in China, to traffic individuals into exploitative situations.
How are fake share trading schemes being executed via messaging platforms like WhatsApp to scam Indian investors?
Fake share trading schemes executed via messaging platforms like WhatsApp have become a prevalent method for scamming Indian investors. These scams often involve fraudulent entities posing as legitimate investment opportunities, leading to significant financial losses for unsuspecting individuals.
How the Scam Operates
Initial Contact via WhatsApp: Scammers initiate contact by sending unsolicited messages offering lucrative stock market investment opportunities. These messages often include links to join WhatsApp groups or download trading apps.
Building Trust: Once the victim joins the group, they are presented with fake success stories, fabricated trading reports, and testimonials from other ‘members’ who allegedly earned substantial profits. This is designed to build trust and encourage further investment.
Encouraging Investments: Victims are persuaded to invest significant amounts, often starting with smaller sums and gradually increasing as they are shown fabricated returns.
Withdrawal Difficulties: When victims attempt to withdraw their funds, they encounter various obstacles, such as requests for additional payments under the guise of taxes or processing fees. Eventually, access to the platform is denied, and the scammers disappear with the invested money.
What types of malware are currently targeting India’s power and energy sector, and how are they typically spread?
India’s power and energy sector has become a prime target for sophisticated cyberattacks, with adversaries employing a range of malware to compromise critical infrastructure. Here’s an overview of the most concerning malware types and their common propagation methods:
Common Malware Targeting India’s Power Sector
- ShadowPad
- Description: A modular backdoor trojan linked to China’s APT41 group, ShadowPad has been used in cyber-espionage campaigns targeting power grid systems.
- Notable Incident: In April 2022, ShadowPad was employed to breach electrical dispatch centers in Ladakh, India, though the attacks were thwarted due to robust cybersecurity measures.
- Industroyer (CrashOverride)
- Description: A malware framework designed to disrupt electrical grids by targeting Industrial Control Systems (ICS).
- Relevance: While not directly attributed to attacks in India, its capabilities pose a significant threat to power infrastructure globally.
- BlackEnergy
- Description: A malware suite used in cyberattacks against critical infrastructure, including power grids.
- Capabilities: It can facilitate Distributed Denial of Service (DDoS) attacks and deploy additional malicious payloads.
- LogicLocker
- Description: Ransomware targeting Programmable Logic Controllers (PLCs) in ICS environments.
- Potential Impact: It can lock out legitimate users and manipulate industrial processes, posing risks to power generation and distribution.
- Triton (TRISIS)
- Description: Malware capable of disabling safety instrumented systems in industrial settings.
- Implications: While primarily used in petrochemical sectors, its potential to disrupt power plants underscores the need for comprehensive cybersecurity measures.e cybersecurity challenges faced by organizations in India. Their involvement spans various facets, from enhancing security posture to providing localized solutions and support.
Role of Channel Partners in Cybersecurity
- Bridging Global Solutions with Local Needs
Channel partners act as intermediaries between international cybersecurity vendors and Indian businesses, ensuring that advanced solutions are tailored to local requirements. They adapt global tools to fit India’s diverse infrastructure and varying levels of digital literacy, making them accessible to companies of all sizes.
- Expanding Reach and Accessibility
With extensive partner networks, including system integrators, resellers, and managed service providers (MSPs), channel partners extend cybersecurity solutions into regional areas and smaller cities (Tier 2 and Tier 3). This decentralized approach ensures that even businesses in less urbanized regions have access to robust cybersecurity measures.
- Providing Managed Security Services
MSPs offer continuous monitoring, threat detection, and incident response, acting as trusted advisors to help organizations build and maintain a robust security posture. They manage cybersecurity operations, allowing businesses to focus on core activities while ensuring protection against evolving threats.
- Enhancing Customer Education and Awareness
Channel partners conduct regular training, webinars, and seminars to educate businesses about emerging threats, new solutions, and best practices. These educational initiatives empower organizations to make informed decisions about cybersecurity investments and promote safer digital habits.
- Offering Tailored Solutions and Support
By understanding the unique challenges faced by businesses, channel partners offer customized cybersecurity solutions that are practical, effective, and scaled appropriately for different environments. They provide localized support, maintenance, and rapid response to cyber incidents, ensuring that businesses can recover swiftly from attacks.