CERT-In’s October awareness campaign launched a MyGov cyber-hygiene quiz while researchers questioned election software fix timelines flagged to the poll body and the agency in July.
Mumbai Crime Branch’s Property Cell arrested a Madhya Pradesh software developer accused of building 2,805 malicious APK files linked to pension-verification scams that police say touched 9,673 victims nationwide.
Youth-led Cockroach Janta Party organizers called another nationwide day of action after police ended an INDIA bloc protest over voter-roll revisions, keeping pressure on Election Commission chief Gyanesh Kumar.
Wanwadi police secured remand of five men allegedly tied to fake bank accounts that channelled ₹1.80 crore from 19 cyber fraud complaints across India.
Union Home Ministry officials say Hashim Musa’s elimination ends a four-man Lashkar module, while agencies tighten checks on markets, religious sites and migrant workers after Pakistan-based handlers were rattled.
Mumbai Police’s cyber cell arrested three men accused of running a Telegram channel that coached shopkeepers to accept fake payment screenshots, draining kirana ledgers across western suburbs before Diwali stocking.
Chief Minister Himanta Biswa Sarma said Assam police detained a former soldier still on contract work and a second man after intelligence agencies flagged suspected passing of army movement information to Pakistan.
MeitY’s Monday session with Razorpay, PhonePe and Yes Bank is meant to clear refund queues after the 2025 online real-money gaming ban left wallets and chargebacks in limbo.
Union Home Minister Amit Shah said Singh ran heroin and methamphetamine networks from abroad under the alias Navab Virk before Indian agencies secured his return Saturday.
The Securities and Exchange Board of India issued a Gujarat-focused alert on unregistered equity research cold calls that mimic SEBI registration numbers.
Security forces killed Lashkar commander Mohammad Asif, alias Hashim Musa, in Kashmir, ending a two-year hunt for the cell behind the April 2025 Pahalgam tourist attack.
NPCI suspended 14,200 UPI merchant handles linked to fake Diwali cashback pages that tricked users into approving collect requests, the highest festive-season purge the switch has disclosed.
A joint sea-air pursuit west of Lakshadweep netted 526 kilograms of heroin and methamphetamine; five crew members are headed to Mumbai under escort for questioning.
Home Minister Amit Shah told a Delhi counter-terror conference that more than 40 Shahzad Bhatti-linked modules are broken up, 350 people are held and the cross-border ring is now a UAPA-listed terrorist organisation.
MeitY ordered major app stores to delist screen-sharing remote-access packages linked to digital-arrest fraud, telling wallet providers to block sideloaded Android bundles that mimic bank login pages.
Kharun river floodwater has pushed villagers out of low-lying hamlets on Raipur's southern edge and in parts of Durg district, with IMD holding orange alerts over both districts after a week of heavy monsoon rain across Chhattisgarh.
Four civilians from Pilong village in Manipur's Kamjong district were killed in a cross-border attack, officials said, hours after the Centre extended AFSPA. Police have not named the attackers, and it is unclear whether Indian agencies had prior intelligence.
With no verified September 2026 takedown circular on file, this desk piece tracks CBIC and GSTN alerts on fake refund links, cloned portals and DIN forgery—and how Delhi taxpayers should verify only at gst.gov.in and verifydocument.cbic.gov.in.
Union ports minister Sarbananda Sonowal said an Indian crew member from Uttar Pradesh died of head injuries after a missile struck the Antigua-flagged bulk carrier MV Cape Dao off Oman, as New Delhi condemned another attack on commercial shipping in the Gulf corridor.
East Region Cyber Police registered an FIR after a 70-year-old Mulund teacher lost ₹70,000 to a fake Florida doctor’s customs-duty ruse, then ₹14.38 lakh to a bogus recovery firm advertised online, Hindustan Times reported.
Hyderabad City Cyber Crime arrested eleven people for cloning the EPFO unified member portal login and OTP pages on Telugu-language domains, draining provident fund advances from 340 salaried accounts after victims entered Aadhaar-linked OTPs on lookalike hosts.
NPCI ordered banks and UPI apps to attach device fingerprints and step-up authentication on collect requests above ₹1 lakh from 1 October, after fraud desks traced mule rings abusing high-value merchant QR collect flows during Trump–Xi FX volatility week.
India’s Supreme Court held Monday that police must give arrested people written grounds they can understand—even under special statutes such as UAPA and PMLA—and that a prior illegal arrest cannot be cured by a quick re-arrest on the same facts.
Mumbai Police Cyber Cell froze more than 140 mule accounts tied to fake IPO allotment lottery sites, after investors paid “stamp duty” through UPI to claim shares they never held.
CERT-In warned that fraudsters are pushing UPI collect requests through look-alike NHAI Fastag recharge pages, with losses clustering around highway toll plazas and fleet operators who bulk-top wallets.
The institute stripped Suryanarayana Doolla of his deanship and apologised for earlier statements after Sahil Wakode’s death sparked campus protests and a Mumbai Police Crime Branch investigation.
C-DAC Pune published a firmware conformance calendar for AePS micro-ATM vendors ahead of the Kisan Mela season, tying PIN-entry devices and Luna-class HSMs to NPCI micro-ATM 1.5.1 checks before rural cash-withdrawal traffic peaks.
UIDAI has booked pre-Diwali conformance labs for Aadhaar masking and authentication API clients as banks and fintechs rush seasonal onboarding, with auditors checking eight-digit redaction, vault reference keys, and staging certificates that expire in 2026.
PhonePe forced password resets and tightened merchant-dashboard SSO after a credential-stuffing wave hit payout consoles during Ganesh festival settlements, with NPCI dispute tickets rising at sponsor banks.
CERT-In told payment aggregators and large merchant acquirers to file six-hour incident notices and full breach summaries before the Navratri–Diwali UPI surge, tightening clocks that many fintechs still treat as back-office paperwork.
Yes Bank tightened beneficiary name-matching on inbound UPI collect requests after a September wave of spoofed merchant handles fooled customers who saw plausible display names but paid shell accounts.
MeitY told state-run data centers to patch lingering Log4j forks and Apache Struts-adjacent libraries before Navratri week spikes e-governance traffic, after CERT-In logged unpatched instances on NIC-hosted portals.