
Within days, two of India's biggest manufacturers faced significant cybersecurity challenges. According to reports from Business Standard, Bajaj Auto disclosed that a ransomware attack had disrupted parts of its IT systems, while Tata Electronics reportedly suffered a cyberattack that allegedly exposed sensitive data linked to global clients, including Apple and Tesla. These incidents demonstrate how cybercriminals are increasingly targeting businesses where a single successful attack can halt operations, expose valuable data, and potentially fetch much larger payouts than traditional individual attacks. Latest developments show two Indian companies have collectively lost nearly ₹3.5 crore in a sophisticated cyber fraud involving malicious zip files and impersonation tactics. Scammers gained remote access to employees' mobile phones, altered contact lists and posed as senior company officials on WhatsApp to authorise fraudulent fund transfers, with one company losing ₹1.98 crore and another duped of ₹1.5 crore.
India's national cybersecurity watchdog has issued a new warning about a sophisticated malware campaign targeting WhatsApp web and desktop users. On June 25, CERT-In warned that a large-scale malware distribution campaign is targeting WhatsApp Desktop and WhatsApp Web users, distributing malicious Visual Basic Script (VBScript) files through direct messages. According to CERT-In's advisory based on Kaspersky and Securelist findings, threat actors leverage compromised WhatsApp accounts to send malicious attachments directly to victims, making the messages appear legitimate and significantly increasing the likelihood of successful compromise. The latest developments reveal that the malicious files are disguised as routine business documents, including invoices, bank statements, payment records, account statements and debt notices. As per Upstox News Desk, the filenames are localised in several languages, including English, Portuguese, French, German and Malay, indicating what CERT-In described as "a broad targeting strategy." The cybersecurity watchdog emphasizes that "WhatsApp is a cross-platform instant messaging application that enables users to exchange messages, files, images, videos and other content across desktop and web platforms. Attackers use previously compromised WhatsApp accounts to send malicious VBScript (vbs) files to existing contacts." CERT-In advises users to "do not open attachments you were not expecting, even if they come from a friend, colleague, or family member" and suggests cross-checking with the sender before opening any unexpected files.
The malware campaign demonstrates sophisticated technical capabilities designed to evade detection. According to CERT-In's latest advisory, once a victim opens the malicious attachment, the VBScript executes on the system, creates a working directory under the public documents folder, downloads additional scripts from attacker-controlled infrastructure and installs a Remote Monitoring and Management (RMM) package. As reported by Upstox News Desk, the malware also includes comments and metadata designed to imitate legitimate Microsoft Windows Update components, helping it evade suspicion. The cybersecurity agency warns that successful exploitation may result in "unauthorized remote access to endpoints," "credential theft," deployment of additional malware, data exfiltration, lateral movement within organisational networks, business disruption and financial losses. CERT-In urges users to "be cautious with unexpected attachments" and "contact the sender through a phone call or separate message to confirm they intentionally sent the file" while avoiding opening executable file types such as .vbs, .vbe, .exe, .bat, .cmd, .js and .ps1 received through messaging platforms.
The Indian Computer Emergency Response Team (CERT-In) has issued a stark warning about the evolving cybersecurity landscape. In its Advisory CIAD-2026-0020, CERT-In warns that advances in frontier AI systems are significantly enhancing cyber capabilities, with these systems now able to identify software vulnerabilities, analyse source code, plan multi-stage attacks, and automate exploitation workflows. The advisory also cautions that AI can generate increasingly convincing phishing emails and social-engineering content, lowering barriers for cybercriminals and increasing the need for stronger security controls. As a result, enterprises are shifting cybersecurity spending from compliance and perimeter defence to identity protection, AI governance, cloud security, and continuous threat monitoring. The Sophos Active Adversary Report 2026 identifies identity attacks as one of the dominant techniques used by cybercriminals, with exploited vulnerabilities remaining the leading technical root cause of ransomware incidents for the third consecutive year, accounting for 32 per cent of attacks.
Modern corporate cyberattacks combine multiple sophisticated techniques rather than relying on single methods. According to Pankit Desai, Co-founder and CEO of Sequretek, as reported by Business Standard, business email compromise (BEC) has become one of the fastest-growing threats where attackers impersonate senior executives or vendors to trick employees into transferring funds or sharing confidential information. Credential theft has emerged as another preferred entry point where attackers log in using stolen usernames and passwords through phishing campaigns or compromised cloud accounts. A new trend called "double extortion" involves stealing sensitive corporate information before threatening to publish it if victims refuse to pay, with Swapna Bapat of Palo Alto Networks noting that "attackers skip encryption altogether in some cases and rely solely on data theft for leverage." The latest sophisticated "Boss Scam" targets Indian companies by hijacking executives' WhatsApp accounts to authorise fraudulent payments, with cybercriminals impersonating regulators and tricking leaders into downloading malware that grants access to their communication.
The banking, financial services, and insurance (BFSI) sector is leading cybersecurity investments as AI adoption accelerates. According to the DSCI-BCG report published in May, 67 per cent of Indian BFSI organisations said AI is driving additional cybersecurity spending, with 64 per cent of chief information security officers (CISOs) identifying deepfakes and AI-enabled social engineering as their top security priority. However, investment levels remain concerning - 62 per cent of Indian BFSI organisations allocate less than 10 per cent of their IT budgets to cybersecurity, while 89 per cent of global organisations spend more than 10 per cent. The healthcare sector is also strengthening cybersecurity as hospitals digitise services, with the Indian cybersecurity market for healthcare valued at $2.5 billion, driven by increasing digitalisation and the Digital Personal Data Protection (DPDP) Act requirements. The IT and telecom sector is projected to reach $6.30 billion by 2033, with the services segment expected to record the fastest growth as operators expand cloud infrastructure and 5G networks.