All Exams Test series for 1 year @ ₹349 only

Supreme Court Warns Of Fake Website, Phishing Attack

Relevance: GS2 - Structure, organization, and functioning of the Executive and the Judiciary GS3 - Awareness in the fields of IT and Computers

(Source: The Hindu, 09/01/2023)

Click here for Daily Current Affairs

Why in the news?

  • Recently, the Supreme Court Registry issued a notice about fake websites impersonating the Supreme Court’s website to gain access to personal and confidential information from unsuspecting users.
  • Phishing is when attackers attempt to trick users into unsuspectingly clicking dangerous links or direct them to dodgy websites and steal their data.

Fake Website

What did the notice issued by the Supreme Court mention?

  • The Supreme Court Registry issued a public interest notice warning about two websites - (http://cbins/scigv.com and https://cbins.scigv.com/offence) - impersonating the official website of the Court (www.sci.gov.in).
  • According to the Registry, the website was duping unsuspecting people of their personal and confidential information.
  • The public was advised not to
    • Share their personal and confidential information
    • Click or share links without verifying their authenticity.
  • The Registry described the attack as a “phishing attack” and alerted law enforcement agencies about their concerns especially as there has been an increase in a number of court watchers via the official website recently.

Supreme court registry

  • The Supreme Court registry is the back-end office that receives and processes all documents.
  • It is also responsible for making allocations of matters to benches based on the orders of the Chief Justice of India.
  • The registry is composed of six registrars and is headed by a Secretary-General.
  • The officers at the registry are judicial officers of the rank of a district judge.
    • They are mostly on deputation to the apex court and return to their home cadres after their term.
    • In some instances, they are appointed as judges of high courts.
  • The registry staff manages a range of tasks from maintaining case files to translating judgments.

What is a phishing attack?

  • Phishing is a cybercrime in which targets are contacted by email, telephone, or text message and other social engineering techniques.
  • The perpetrators pose as legitimate and trustworthy institutions and lure individuals into revealing their sensitive data such as personal information, banking details, and passwords.
  • The recipients are tricked into believing that the message is authentic, such as a request from their bank, or an official message from their workplace, and that it is necessary to click the URL or download an attachment.
  • It’s one of the oldest and most common forms of cyberattacks with phishing methods and techniques becoming more advanced and sophisticated.
  • The most common motives behind phishing attacks are financial access, identity theft, misinformation and disinformation, sexual exploitation of minors and psychological warfare.

Types of phishing

  • Spear Phishing: Here, criminals obtain information about the individuals from websites or social networking sites, and then customize phishing schemes to target the individual.
  • Whaling: Whaling is a highly targeted phishing attack that is usually aimed at senior executives.
    • It masquerades as a legitimate email and is designed to encourage victims to perform actions such as initiating a wire transfer of funds.
  • Catfishing/Catphishing: Catfishing refers to the practice of creating fake online accounts to trick, scam, or steal the victim's identity.
    • Catfishers build relationships with their victim to gather sensitive personal information via social media or online dating apps.
  • Clone Phishing: Clone phishing is a scam where cybercriminals replicate legitimate emails or websites to trick victims into revealing their personal information.
    • Clone phishing is more difficult to spot than other phishing attacks as the sites or emails are very similar and may include legitimate details.
  • Voice Phishing: Voice phishing or Vishing is the use of fraudulent phone calls to trick people into transferring money or revealing personal information.
    • Criminals pretend to represent a trusted institution, company, or government agency for monetary gain, or other objectives, such as political, competitive, or retaliatory activities.
  • Link Manipulation: Link manipulation is a technique in which phishers send links to malicious websites masquerading as other websites.
  • Content Injection: Content injection is the technique where phishers change portions of the content on the page of reliable websites to mislead the user to go to an external page and enter personal information.

How can phishing attacks be identified?

  • Phishing attacks via email or texts are usually from unknown senders or senders whose name has been concealed.
  • These messages have alarmist language that aims to create a sense of urgency in the victim.
  • It may also have unexpected or unusual attachments such as malware or ransomware.
  • It is possible to identify illegitimate links by hovering over the link.
  • While genuine messages do not ask for personal information or bank details, fake emails promise unexpected rewards and ask for personal information such as banking and card details, Aadhar numbers, PAN numbers, address, etc.

What steps can be taken to tackle Phishing Attacks?

  • Cyber Awareness: Banks, corporate entities, NGOs, and government agencies must conduct large-scale awareness campaigns on the dangers of phishing and the need for proper cyber security.
  • Security:
    • Adopt two-factor authentication technology.
    • Do not store account details in shared devices.
    • Delete sensitive files stored on computers.
    • Do not accept requests from unknown accounts or share personal information.
    • Report instances of cybercrimes at the earliest with the proper authorities such as the National Cyber Crime Reporting Portal/Police.
  • Technological innovations:
    • Use DomainKeys Identified Mail (DKIM), which is an email authentication technique that allows receivers to check that an email was indeed sent and authorized by the owner of that domain using a digital signature.
    • Use Sender Policy Framework (SPF), an email-authentication technique that is used to prevent spammers from sending messages on behalf of the company or individual’s domain.

Government Initiatives for Cybersecurity

  • In 2004, the Government of India established the Indian Computer Emergency Response Team (CERT-In) under the Ministry of Electronics and Information Technology.
    • It is the national nodal agency for protecting Indian cyberspace and deals with cyber security incidents as and when they occur.
  • The Information Technology Act, 2000 provides a legal framework for the regulation of computers, computer systems, computer networks, and data and information in electronic formats.
  • The National Cyber Security Strategy 2020 was formulated by the Office of National Cyber Security Coordinator at the National Security Council Secretariat with the objective of improving cyber awareness and cybersecurity in the country through stringent audits.
  • The Cyber Surakshit Bharat Initiative was launched in 2018 to spread awareness about cybercrime and build capacity for safety measures for frontline IT staff and Chief Information Security Officers (CISOs) across government departments.
  • The Cyber Swachhta Kendra was launched in 2017 to assist internet users in cleaning their computers and devices of viruses and malware.
  • The Information Security Education and Awareness Project (ISEA) was launched in 2015 to raise awareness and provide education, research, and training in Information Security.
  • The Ministry of Home Affairs launched an Online cybercrime reporting portal under the National Mission for the safety of women to facilitate easier online reporting of cybercrimes.
  • The Indian Cyber Crime Coordination Centre (I4C) was launched in 2018 by the Ministry of Home Affairs (MHA) for the effective and coordinated combatting of cybercrime in the country.

(*Click this link to read prelims specific weekly current affairs articles)

FAQs

Question: What is cybersecurity?

Answer:

Cybersecurity refers to the protection of cyberspace and critical information infrastructure from attack, damage, misuse, and economic espionage. It is the practice of protecting networks, computers, data, and programs from unauthorized attacks. In 2013, India introduced the National Cyber Security Policy to build safe and robust cyberspace.

Question: What is malware?

Answer:

Malware or malicious software refers to software that is designed to perform illegal acts via a computer network. It can be further classified as worms, viruses, hoaxes, trojans, etc.

UPSC Mains Practice Question:
  1. Discuss the advantages and security implications of cloud hosting of servers vis-a-vis in-house machine-based hosting for government businesses. (UPSC GS3 2015)
  2. How can institutions and individuals identify and protect themselves against phishing attacks, considering the evolving techniques and motives behind such cybercrimes?
  3. What measures should government agencies, organizations, and the general public take to enhance cybersecurity awareness and response, particularly in the context of phishing attacks and their potential consequences?

MCQs

Question: The terms 'WannaCry, Petya, and Eternal Blue' sometimes mentioned in the news recently are related to (UPSC CSE 2018)

(a) Exoplanets

(b) Cryptocurrency

(c) Cyber attacks

(d) Mini satellites

Answer: (c) See the Explanation

  • The terms WannaCry, Petya, and Eternal Blue are all terms associated with cyber attacks.
  • WannaCry is ransomware that locks the victim's devices and prevents him/her from using them unless a ransom is paid to the perpetrator.
  • Petya is a family of malware that targets Microsoft Windows-based devices.
  • Eternal Blue is a software vulnerability in Microsoft Windows-based devices.

Therefore, option (c) is the correct answer.

Question: In India, it is legally mandatory for which of the following to report on cyber security incidents?

  1. Service providers
  2. Data centers
  3. Body corporate

Select the correct answer using the codes given below:

(a) 1 only

(b) 1 and 2 only

(c) 3 only

(d) 1, 2 and 3

Answer: (d) See the Explanation

  • According to the CERT-In rules, it is mandatory for service providers, intermediaries, data centers, and corporate bodies to report cyber security incidences to CERT-In within a reasonable time of occurrence of the incident.

Therefore, option (d) is the correct answer.

*The article might have information for the previous academic years, please refer the official website of the exam.
How likely are you to recommend Prepp.in to a friend or a colleague?
Not so likely
Highly likely

Comments

No comments to show
UPSC CSE (IAS) 2027 Prelims Mock Test Series
Live Quizzes
Free
• Live
UPSC IAS : Culture of India: Indian Literature
12 Minutes
10 Questions
20 Marks
English, Hindi
HARD
Test will end in 07:32:45
View More
Quizzes
Free
24 July 2026 Daily CA Quiz for UPSC & State PSCs
8 Minutes
5 Questions
10 Marks
English, Hindi, Telugu +7 More
MEDIUM
Attempted by 437 aspirants in 12 hours
Free
23 July 2026 Daily CA Quiz for UPSC & State PSCs
8 Minutes
5 Questions
10 Marks
English, Hindi, Telugu +7 More
MEDIUM
Attempted by 428 aspirants in 12 hours
View More
Live Tests
Free
• Live
UPSC IAS : GS - Indian Economy - Subject Knowledge Test
35 Minutes
30 Questions
60 Marks
English, Hindi
Test will end in 15:32:45
plus
• Live
Live Test : UPSC CSE Prelims CSAT (Paper-II) (July 22 - 25)
120 Minutes
80 Questions
200 Marks
English, Hindi
MEDIUM
Test will end in 16:32:45
View More
Full Tests
Free
Full Test - 01: UPSC CSE Prelims CSAT (Paper-II)
120 Minutes
80 Questions
200 Marks
English, Hindi
MEDIUM
Attempted by 14 aspirants in 12 hours
Free
Full Test - 01: UPSC CSE Prelims GS 2027
120 Minutes
100 Questions
200 Marks
1,007 Attempted
English, Hindi
MEDIUM
Attempted by 12 aspirants in 12 hours
Previous Year Papers
plus
UPSC CSE Prelims 2026 GS Paper 1 Question Paper (24-May-2026)
120 Minutes
100 Questions
200 Marks
12,987 Attempted
English, Hindi
MEDIUM
Attempted by 108 aspirants in 12 hours
plus
UPSC CSE Prelims 2026 CSAT Paper 2 Question Paper (24-May-2026)
120 Minutes
80 Questions
200 Marks
12,979 Attempted
English, Hindi
MEDIUM
Attempted by 108 aspirants in 12 hours
View More