New Delhi: India’s national cybersecurity agency, the Indian Computer Emergency Response Team (CERT-In), has issued a high-severity alert warning WhatsApp users of an active account takeover campaign using a new technique known as “GhostPairing," in an advisory released on December 19.
CERT-In said cybercriminals are exploiting WhatsApp’s device-linking feature to gain unauthorised access to user accounts without the need for passwords or SIM card swaps, as reported by The Indian Express. The attackers, the agency warned, deceive users into entering pairing codes, which silently grants control of the account to a malicious device.
ALSO READ: Teen killed in alleged honour killing over inter-community relationship, brother, his friend arrest
According to CERT-In, the GhostPairing method works by tricking victims into approving an attacker’s browser as a trusted linked device. The advisory said, “The attack manipulates users into granting access through a pairing code that appears legitimate." It further added that once access is granted, attackers can fully operate the account through WhatsApp Web.
Last month, the Department of Telecommunications directed messaging platforms such as WhatsApp, Signal and Telegram to implement continuous SIM binding which required accounts to remain linked to an active SIM card. As part of this directive, companion web sessions are expected to be logged out periodically and re-authenticated using QR codes.
CERT-In said the GhostPairing campaign typically begins with a message appearing to come from a trusted contact, often reading, “Hi, check this photo”. The message contains a link designed to mimic a Facebook-style preview, and clicking the link leads users to a fake verification page, where they are prompted to enter their phone number and a code. Victims unknowingly allow attackers to link their WhatsApp account to an external device, by completing these steps,.
Once compromised, attackers can access messages, photos, videos and voice notes in real time, and can impersonate the victim to send messages to individual contacts or groups, the agency said.
The advisory also noted that WhatsApp currently allows multiple devices to be linked to a single account, a feature that is being misused in such attacks. In October, the Indian Cybercrime Coordination Centre under the Ministry of Home Affairs had flagged a related trend involving scammers using social media advertisements to lure users into linking their WhatsApp accounts.
While the government’s SIM-binding push is intended to limit such fraud, it has raised concerns among legal experts and digital rights groups, who argue that constant SIM verification, could affect privacy and disrupt multi-device usage, particularly for professionals.
To reduce risk, CERT-In has urged users to avoid clicking on suspicious links, even if they appear to come from known contacts, and to never enter phone numbers or verification codes on external websites claiming to be linked to WhatsApp or Facebook. Users have also been advised to regularly review the “Linked Devices” section within WhatsApp settings and immediately log out of any unfamiliar sessions.
For organisations relying on WhatsApp for communication, the agency has recommended security awareness training, closer monitoring for phishing attempts, and the establishment of clear response protocols to detect and contain account compromises quickly.
Let the Truth be known. If you read VB and like VB, please be a VB Supporter and Help us deliver the Truth to one and all.
Indore (PTI): The Indore bench of Madhya Pradesh High Court on Tuesday set up a commission of inquiry comprising a former HC judge to probe the issue of water contamination in city's Bhagirathpura, saying the matter requires probe by an independent, credible authority and "urgent judicial scrutiny".
It also directed the commission to submit an interim report after four weeks from the date of commencement of proceedings.
A division bench of Justices Vijay Kumar Shukla and Alok Awasthi constituted the commission while hearing several public interest litigations (PILs) filed simultaneously regarding the deaths of several people in Bhagirathpura due to the consumption of contaminated water.
The HC reserved the order after hearing all the parties during the day, and released it late at night.
The state government on Tuesday told the HC that the deaths of 16 people in Indore's Bhagirathpura area was possibly linked to a month-long outbreak of vomiting and diarrhoea caused by contaminated drinking water.
The government presented an audit report of 23 deaths from the current gastroenteritis epidemic in Bhagirathpura before the bench, suggesting that 16 of these fatalities may have been linked to the outbreak of vomiting and diarrhoea caused by contaminated drinking water.
The report, prepared by a committee of five experts from the city's Government Mahatma Gandhi Memorial Medical College, stated that the deaths of four people in Bhagirathpura were unrelated to the outbreak, while no conclusion could be reached regarding the cause of death of three other people in the area.
During the hearing, the high court sought to know from the state government the scientific basis behind its report.
The division bench also expressed surprise at the state government's use of the term "verbal autopsy" in relation to the report, sarcastically stating that it had heard the term for the first time.
The HC expressed concern over the Bhagirathpura case, stating that the situation was "alarming," and noted that cases of people falling ill due to contaminated drinking water have also been reported in Mhow, near Indore.
In its order, the HC said the serious issue concerning contamination of the drinking water supply in Bhagirathpura area allegedly resulted in widespread health hazards to residents, including children and elderly persons.
According to the petitioners and media reports, death toll is about 30 till today, but the report depicts only 16 without any basis or record, it said.
It is averred that sewage mixing, leakage in the pipeline, and failure of civic authorities to maintain potable water standards have led to the outbreak of water-borne diseases. Photographs, medical reports, and complaints submitted to the authorities prima facie indicate a matter requiring urgent judicial scrutiny, the HC said.
"Considering the gravity of the allegation and affecting the right to life under Article 21 of the Constitution of India and the need for an independent fact-finding exercise, the Court is of the opinion that the matter requires investigation by an independent, credible authority," it said.
"Accordingly, we appoint Justice Sushil Kumar Gupta, former judge of the Madhya Pradesh High Court, a one-man commission of inquiry into the issues relating to water contamination in Bhagirathpura, Indore, and its impact on other areas of the city," the HC added.
As per the order, the commission shall inquire into and submit a report on the cause of contamination -- whether the drinking water supplied to Bhagirathpura was contaminated; and the source and nature of contamination (sewage ingress, industrial discharge, pipeline damage etc).
The panel will also probe the number of actual deaths of affected residents on account of contaminated water; find out the nature of disease reported and adequacy of medical response and preventive measures; suggest immediate steps required to ensure safe drinking water as well as long-term infrastructural and monitoring reforms.
It will also identify and fix responsibility upon the officers and officials found prima facie responsible for the Bhagirathpura water contamination incident, and suggest guidelines for compensation to affected residents, particularly vulnerable sections.
The commission shall have powers of a civil court for the purpose of summoning officials and witnesses; calling up records from the government department, hospitals, laboratories and civic bodies; ordering water quality testing through accredited laboratories; conducting spot inspections.
All state authorities involving district administration, Indore Municipal Corporation, public health engineering department and Madhya Pradesh Pollution Control Board shall extend full co-operation and provide records as sought by the commission, it said.
The state government shall provide office space, staff, and logistical support to the commission, it said.
During the hearing in the day, the state government also presented a status report to the court in this matter.
According to reports, a total of 454 patients were admitted to local hospitals during the vomiting and diarrhea outbreak, of whom 441 have been discharged after treatment, and 11 are currently hospitalised.
According to officials, due to a leak in the municipal drinking water pipeline in Bhagirathpura, sewage from a toilet was also mixed in the water.
