Scam Links Persist On Indian Government Websites Months After Initial Discovery

Image by Ketut Subiyanto, from Pexels

Scam Links Persist On Indian Government Websites Months After Initial Discovery

Reading time: 2 min

Several Indian government websites continue to host malicious links months after the issue was initially reported, raising concerns about cybersecurity vulnerabilities.

In a Rush? Here are the Quick Facts!

  • Over 90 Indian government website links redirect to betting and scam platforms.
  • CERT-In was alerted but hasn’t confirmed fixing underlying vulnerabilities.
  • Issues likely stem from CMS or server configuration flaws, experts suggest.

TechCrunch recently discovered over 90 compromised “gov.in” website links associated with various government departments, including the Indian Council of Agricultural Research, India Post, and state agencies from Haryana and Maharashtra. These links redirect users to fraudulent betting and investment platforms.

TecCrunch says that the compromised links, indexed by search engines like Google, pose significant risks as unsuspecting internet users may encounter them during routine searches.

In May, TechCrunch had highlighted a similar issue with around four dozen government website links. At that time, India’s Computer Emergency Response Team (CERT-In) was alerted and took steps to address the matter.

The websites in question promote themselves as Asia’s most popular” online betting platform and “the number one online cricket betting app in India,” offering wagers on events like the Indian Premier League.

How these ads ended up on Indian government pages and the duration of the redirects remain unknown. Additionally, TechCrunch says that it remains unclear if the underlying vulnerabilities were resolved, as new compromised links have since surfaced.

Security expert Bob Diachenko explained to TechCrunch that the recurring problem might stem from vulnerabilities in the websites’ content management systems or server configurations.

According to Diachenko, merely removing malicious content without addressing the root cause allows attackers to exploit the same weaknesses repeatedly. TechCrunch reached out to CERT-In for comment, sharing examples of affected links.

Although the agency did not respond, the problematic links began showing “page not found” errors shortly after TechCrunch’s inquiries.

This recurring issue underscores the need for Indian authorities to implement more robust cybersecurity measures. Addressing systemic vulnerabilities will be essential to prevent future incidents and safeguard public trust in official online resources.

Did you like this article? Rate it!
I hated it I don't really like it It was ok Pretty good! Loved it!

We're thrilled you enjoyed our work!

As a valued reader, would you mind giving us a shoutout on Trustpilot? It's quick and means the world to us. Thank you for being amazing!

Rate us on Trustpilot
0 Voted by 0 users
Title
Comment
Thanks for your feedback
Loader
Please wait 5 minutes before posting another comment.
Comment sent for approval.

Leave a Comment

Loader
Loader Show more...