CERT-In Warns Organisations About Potential Spike in Cyber-Attacks on VPN

With organisations using VPN for business continuity, attackers might finding vulnerabilities to target organisations for various cyber attacks.

Advertisement
By Press Trust of India | Updated: 15 April 2020 12:15 IST
Highlights
  • Organisations these days use VPN to facilitate work from home
  • CERT-In warned about social engineering attacks
  • CERT-In said attackers are finding vulnerabilities to target firms

CERT-In advised against social engineering attacks where cheats pose as genuine back-end support

Federal cyber-agency CERT-In on Tuesday warned of increased cyber-attacks, including ''social engineering hits'', on virtual private networks (VPN) being used by organisations these days to facilitate work from home for their employees in view of the nationwide lockdown to combat the COVID-19 outbreak.

In a fresh advisory, Computer Emergency Response Team of India (CERT-In) warned about social engineering attacks where cheats pose as genuine back-end support and obtain sensitive data from gullible employees.

These trends have emerged due to increase of online activity during the ongoing lockdown to contain the spread of COVID-19.

Advertisement

"The coronavirus pandemic has led many organisations worldwide to restrict their employees from coming to work in office and have advised them to maintain social distancing and to continue working from the safe environment of their homes.

Advertisement

"Organisations are using enterprise VPNs for communicating through emails, video conferencing and other chat tools. A VPN enables communication through secure online servers using encryption of data," the CERT-In said.

With a large number of organisations using VPN for business continuity, it said, attackers are finding vulnerabilities to target organisations for various cyber attacks.

Advertisement

"Therefore, organisations should set up a system in coordination with their information technology staff to secure the VPN service to maintain business confidentiality, integrity and availability," the CERT-In, a federal agency to combat cyber attacks to guard the Indian cyber space, said.

It also suggested that the organisations should sensitise their employees against increased phishing attempts where cyber criminals send emails or text messages posing as genuine person and take sensitive information.

Advertisement

"Pandemics like COVID-19 could lead to social engineering attacks. Employees
need to be alerted about such attacks, wherein fraudsters could pose as a genuine organisation and send emails to obtain sensitive personal or organisation-level information," it said.

It also suggested some counter-measures and best practices for using VPNs, which included increased scrutiny of unauthorised activity using log analysis, detect attacks in a timely manner and respond to incidents.

They should also check their systems for distributed denial of service (DDoS) attacks on VPN servers. In this, a cybercriminal blocks the service of the online system to the intended user by triggering a malicious activity.

"An attacker could conduct various DDoS attacks leading to crashing of the VPN server. Such attacks could also limit or cut-off system administrators from the servers leading to further compromise of the internal attack," it said.

It recommended multi-factor authentication (MFA) for using VPN accounts in order to "avoid any unauthorised activity during work from home, organisations should enable a MFA solution on all VPN accounts leading to better data security".

"In case, MFA cannot be implemented, employees should be advised to use strong passwords to block any account takeover attacks," it said.

The agency reiterated that "latest software patches" should be used and advanced security configurations deployed to keep the VPN safe.

It also advised that all the IT teams of various organisations should test the VPN server for mass usage and encourage "rate limiting so that priority is given to users who require higher bandwidth".

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival 2025 Sale Will Begin on This Date
  2. Top OTT Releases of the Week (Sept 1 - Sept 7): Know What to Watch
  3. Flipkart Big Billion Days Sale Date Revealed, Will Compete With Amazon Sale
  4. Amazon Great Indian Festival 2025: Smartphone Deals Teased Ahead of Sale
  5. Samsung Galaxy S25 FE Launched With Exynos 2400 SoC: See Price
  6. Lava Bold N1 5G Launches in India Under Rs. 7,500 With These Features
  7. Oppo Reno 14 FS 5G Launches in Select Global Markets With These Features
  8. Motorola G06 to Debut With MediaTek Helio SoC, IP64 Rating: Report
  9. Samsung Galaxy S24 5G With Snapdragon 8 Gen 3 Chip to Launch in India Soon
  10. Samsung Launches Galaxy Tab S11 Series With Galaxy AI, These Features
  1. Moto Book 60 Pro Launched in India With Up to Intel Core Ultra 7 CPU, 14-Inch OLED Screen
  2. OpenAI to Challenge LinkedIn With New AI-Powered Jobs Platform in 2026
  3. Samsung Galaxy S24 5G With Snapdragon 8 Gen 3 Chip Confirmed to Launch in India, Will Go on Sale via Flipkart
  4. Huawei FreeBuds 7i Launched With ANC, Spatial Audio Support: Price, Specifications
  5. Bitcoin Holds Steady As Ethereum Gains From Strong ETF Demand
  6. Lava Bold N1 5G Launched in India With 90Hz HD+ Display and 13-Megapixel Rear Camera: Price, Specifications
  7. Hollow Knight: Silksong's Massive Launch Crashes Steam, PlayStation, Xbox and Nintendo Storefronts
  8. Amazon Great Indian Festival 2025: Deals on Samsung Galaxy S24 Ultra, iPhone 15, OnePlus 13s Teased Ahead of Sale
  9. Adobe Premiere App for iOS Introduced With Desktop-Like Controls, Generative AI Tools
  10. Motorola G06 to Reportedly Debut With MediaTek Helio G81 Extreme SoC; Check Expected Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.