CERT-In Warns Organisations About Potential Spike in Cyber-Attacks on VPN

With organisations using VPN for business continuity, attackers might finding vulnerabilities to target organisations for various cyber attacks.

Advertisement
By Press Trust of India | Updated: 15 April 2020 12:15 IST
Highlights
  • Organisations these days use VPN to facilitate work from home
  • CERT-In warned about social engineering attacks
  • CERT-In said attackers are finding vulnerabilities to target firms

CERT-In advised against social engineering attacks where cheats pose as genuine back-end support

Federal cyber-agency CERT-In on Tuesday warned of increased cyber-attacks, including ''social engineering hits'', on virtual private networks (VPN) being used by organisations these days to facilitate work from home for their employees in view of the nationwide lockdown to combat the COVID-19 outbreak.

In a fresh advisory, Computer Emergency Response Team of India (CERT-In) warned about social engineering attacks where cheats pose as genuine back-end support and obtain sensitive data from gullible employees.

These trends have emerged due to increase of online activity during the ongoing lockdown to contain the spread of COVID-19.

Advertisement

"The coronavirus pandemic has led many organisations worldwide to restrict their employees from coming to work in office and have advised them to maintain social distancing and to continue working from the safe environment of their homes.

Advertisement

"Organisations are using enterprise VPNs for communicating through emails, video conferencing and other chat tools. A VPN enables communication through secure online servers using encryption of data," the CERT-In said.

With a large number of organisations using VPN for business continuity, it said, attackers are finding vulnerabilities to target organisations for various cyber attacks.

Advertisement

"Therefore, organisations should set up a system in coordination with their information technology staff to secure the VPN service to maintain business confidentiality, integrity and availability," the CERT-In, a federal agency to combat cyber attacks to guard the Indian cyber space, said.

It also suggested that the organisations should sensitise their employees against increased phishing attempts where cyber criminals send emails or text messages posing as genuine person and take sensitive information.

Advertisement

"Pandemics like COVID-19 could lead to social engineering attacks. Employees
need to be alerted about such attacks, wherein fraudsters could pose as a genuine organisation and send emails to obtain sensitive personal or organisation-level information," it said.

It also suggested some counter-measures and best practices for using VPNs, which included increased scrutiny of unauthorised activity using log analysis, detect attacks in a timely manner and respond to incidents.

They should also check their systems for distributed denial of service (DDoS) attacks on VPN servers. In this, a cybercriminal blocks the service of the online system to the intended user by triggering a malicious activity.

"An attacker could conduct various DDoS attacks leading to crashing of the VPN server. Such attacks could also limit or cut-off system administrators from the servers leading to further compromise of the internal attack," it said.

It recommended multi-factor authentication (MFA) for using VPN accounts in order to "avoid any unauthorised activity during work from home, organisations should enable a MFA solution on all VPN accounts leading to better data security".

"In case, MFA cannot be implemented, employees should be advised to use strong passwords to block any account takeover attacks," it said.

The agency reiterated that "latest software patches" should be used and advanced security configurations deployed to keep the VPN safe.

It also advised that all the IT teams of various organisations should test the VPN server for mass usage and encourage "rate limiting so that priority is given to users who require higher bandwidth".

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. This Is How You Can Get ChatGPT Go Subscription for Free
  2. Samsung Galaxy S26 Ultra Said to Get a Major Design Upgrade
  3. Apple's iOS 26.1 Update Rolls Out With New Features, Several Security Fixes
  4. Realme C85 5G, Realme C85 Pro 4G Launched With 7,000mAh Battery
  5. Lava Agni 4 Confirmed to Feature Aluminium Frame, New Dedicated Button
  6. Red Magic 11 Pro Launched in Global Markets With Slightly Smaller Battery
  7. Moto G67 Power 5G Specifications Revealed: See Storage Variants, Features
  8. How to Disable the Liquid Glass Effect After Updating to iOS 26.1
  9. Poco F8 Pro, F8 Ultra Set for Global Launch 'Really Soon', Tipster Claims
  10. Samsung Galaxy A57 Spotted on Company's Test Server With This Model Number
  1. WhatsApp Might Soon Let You Call Other Users By Typing Their Username
  2. Lava Agni 4 Confirmed to Feature Aluminium Frame, Design Teased Ahead of India Launch
  3. Grab Superapp Says AI Models Struggle to Understand Asian Languages
  4. Crypto Market Consolidation Sees Bitcoin Price Drop Under $105,000 as Market Liquidations Cross $1.1 Billion
  5. Moto G67 Power 5G Specifications, Storage Variants Revealed Before Launch in India
  6. Microsoft is Rolling Out ROG Xbox Ally's Xbox Full Screen Experience on MSI Claw Handhelds
  7. Vivo Y500 Pro Launch Date, Key Features Announced; Listed on Geekbench With Dimensity 7400 SoC
  8. Apple Releases iOS 26.1 Update With New Liquid Glass Setting, Several Security Fixes
  9. Samsung Galaxy S26 Ultra Said to Get a Major Design Upgrade, to Be More Ergonomic
  10. Oppo Reno 15 Listed on Geekbench With Dimensity 8450 SoC, Could Launch Soon
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.