India's cyber threat desk
Signal before noise.
CyberShitty.com tracks the breaches, fraud waves, ransomware crews and exploited vulnerabilities hitting India — and the global threats Indian teams need to know — with every claim linked to its source.
01 / India desk
What's hitting India
Deepfake investment ads in India: what they are, who has been faked, and how to spot one
Data breach reporting in India: CERT-In's six-hour rule and the DPDP timeline explained
Mule accounts: why renting out your bank account can end in arrest
Fake job offers, real compounds: how Indians end up trafficked into Southeast Asian scam hubs
CBI's Operation Chakra-VI targets the money trail behind India's digital arrest scams
Digital arrest scams in India: complaints fall, but the Supreme Court and CBI keep up pressure
02 / Global
Beyond India
Ransomware in August 2026: trackers log a record month as Qilin leads
Citrix patches two NetScaler zero-days already exploited; CISA sets 30 September deadline
AdaptHealth reports 4.1 million patients affected by June data theft
Boston Scientific says cyberattack will hit 2026 results as systems are restored
Scams
Scams hitting India right now
SCAM EXPLAINER
Digital arrest scam
Red flags & what to doSCAM EXPLAINER
Investment and trading scam
Red flags & what to doSCAM EXPLAINER
Task and part-time job scam
Red flags & what to doSCAM EXPLAINER
UPI, QR code and collect-request fraud
Red flags & what to doSCAM EXPLAINER
Sextortion video call scam
Red flags & what to doSCAM EXPLAINER
Fake customer care number scam
Red flags & what to doSCAM EXPLAINER
KYC update, SIM swap and eSIM fraud
Red flags & what to doSCAM EXPLAINER
Illegal loan app harassment
Red flags & what to do03 / Threat pulse
Latest on the wire
04 / Signal, not noise
India's cybercrime, in numbers
lost to cyber fraud reported on NCRP (₹ crore, 2025)
ThePrint — MHA data: Indians lost Rs 22,495 crore to cyber fraud in 2025 (21 Feb 2026)
saved via I4C's CFCFRMS across 32.80 lakh complaints (₹ crore, 2021 to 30 Jun 2026)
MHA — Lok Sabha Unstarred Question No. 251, National Cyber Crime Data (21 Jul 2026)
cyber security incidents handled by CERT-In (2025)
PIB — CERT-In: India's Frontline Defender against Cyber Threats (23 Jan 2026)
bank and FI fraud cases of ₹1 lakh+ reported, involving ₹48,021 crore (RBI, FY2025-26)
Outlook Business (PTI) — RBI Annual Report 2025-26 fraud data (29 May 2026)
04 / Anatomy
How a modern extortion attack unfolds
Stage 01
Initial access: stolen credentials, a phished help desk, or an unpatched edge device
Access
Stage 02
Quiet reconnaissance and privilege escalation using legitimate admin tools
Discovery
Stage 03
Backups located and disabled or deleted
Impact prep
Stage 04
Data staged and exfiltrated to attacker-controlled storage
Theft
Stage 05
Encryption deployed — or skipped entirely in favour of pure data extortion
Extortion
# Latest report / 2026-0929-DF Report / 2026-0929-DF Published / 29 SEP 2026 Region / INDIA Category / THREATS Severity / HIGH Sources / 11 LINKED # Defensive record. No victim data.
05 / Malware watch
Capability, not hype
MALWARE / 01
Ransomware
Extortion malware that encrypts systems, and increasingly steals data first, to force a payment after attackers have already gained access.
Detection guidanceMALWARE / 02
Infostealers
Malware that harvests saved passwords, session cookies, tokens and crypto wallets from browsers and apps, then sells them as ready-made access.
Detection guidanceMALWARE / 03
Loaders
Small first-stage malware that gets a foothold, profiles the victim and delivers the next payload, often a stealer, remote access tool or ransomware.
Detection guidanceMALWARE / 04
Remote access tools
Legitimate remote-management software (RMM) and remote access trojans abused to control machines while blending into ordinary IT activity.
Detection guidanceMALWARE / 05
Phishing kits
Rentable phishing-as-a-service kits that proxy real sign-in pages to steal passwords and session cookies, bypassing common MFA.
Detection guidance06 / Reports
More from the desk
2026 / Analysis
Data breach reporting in India: CERT-In's six-hour rule and the DPDP timeline explained
Open report2026 / Analysis
Mule accounts: why renting out your bank account can end in arrest
Open report2026 / Analysis
Ransomware in August 2026: trackers log a record month as Qilin leads
Open report2026 / Analysis
Fake job offers, real compounds: how Indians end up trafficked into Southeast Asian scam hubs
Open report07 / Tools
Trackers and guides
CISA KEV / DAILY
CISA KEV 27 Sep 2026: 2 exploited flaws in Citrix
Open KEV digestTRACKER / 39 ENTRIES
Data breaches 2026: the running list
Open trackerGUIDE / WHAT TO DO
Aadhaar or PAN leaked in a data breach? How to lock it down and check for misuse
Read guideGUIDE / WHAT TO DO
Bank account frozen by cyber police? What to do if you received tainted money without knowing
Read guide08 / Coverage
Where the desk is reporting
sourced reports on file
coverage regions
Verify
Claims are separated from confirmed facts.
Attribute
Every report links to the primary sources it relies on.
Protect
Victim data is never reproduced for spectacle.
Explain
Threat reporting should make the reader harder to attack.