Indian Authorities Break Up Cybercriminals Ring Posing as Microsoft Tech Support

India’s Central Bureau of Investigation (CBI) executed targeted raids at 19 locations across the country, successfully dismantling a sophisticated cyber-enabled financial fraud network exploiting tech support scams.

The syndicate, which specialized in impersonating Microsoft technical support, primarily targeted older adults in Japan with fraudulent schemes.

As a result of this operation, CBI arrested six pivotal operatives, shut down two illegal call centers, and seized critical digital and physical infrastructure, including computers, storage devices, digital video recorders, and mobile phones.

Multi-Stakeholder Intelligence

The crackdown was the culmination of an extensive intelligence-sharing effort between the Japan Cybercrime Control Center (JC3) a nonprofit committed to cybercrime prevention Microsoft’s Digital Crimes Unit (DCU), and law enforcement agencies, including Japan’s National Police Agency (NPA).

Microsoft’s DCU initially identified the malicious ecosystem orchestrating these scams and alerted both the JC3 and the CBI, facilitating timely law enforcement action.

This initiative marked a pivotal evolution in DCU’s strategy against cyber-enabled financial fraud.

With cybercriminals increasingly operating as interconnected, global enterprises leveraging cybercrime-as-a-service models the DCU has shifted from targeting individual call centers to disrupting high-level operators and their technical infrastructure.

This approach is crucial as perpetrators employ advanced technology, such as generative AI, to scale their operations, identify potential victims, automate malicious pop-up creation, and deploy language translation tools to deceive Japanese users.

AI-Powered Tactics

During the investigation, JC3 provided real-time intelligence on malicious pop-ups, mostly mimicking Microsoft security alerts and written in Japanese, that tricked users into contacting fake technical support lines.

Microsoft Tech Support
Examples of malicious pop-ups impersonating Microsoft. 

Microsoft’s Threat Intelligence Center (MSTIC) further analyzed this data, leading to the takedown of approximately 66,000 malicious domains and URLs worldwide since May 2024.

The intelligence was also integrated into Microsoft security services to fortify defenses against similar attacks.

The analysis and disruption extended beyond front-line scammers to the entire criminal ecosystem, including pop-up creators, search-engine optimizers, lead generators, logistics providers, payment processors, and talent recruiters.

Many of these actors relied on generative AI to identify victims, automate phishing content, and evade traditional language-based detection mechanisms, reflecting a notable escalation in technical sophistication.

Tech support scams continue to disproportionately impact older adults. According to the FBI’s Internet Crime Complaint Center, tech support fraud was the most frequently reported scam category among Americans over 60 in 2023, resulting in nearly $590 million in losses.

Parallel findings from the Global Anti-Scam Alliance indicate that most scams in Japan target individuals over 45, and in this operation, about 90% of roughly 200 identified victims were aged 50 or older.

Microsoft’s DCU, in partnership with global law enforcement, has long spearheaded efforts to disrupt such criminal networks.

Hundreds of arrests and stiffer sentences illustrate the progress made, but the landscape is rapidly evolving, driven by new technologies and international collaboration among threat actors.

Microsoft emphasizes that it will never make unsolicited calls or requests for personal information to resolve technical issues.

Individuals who suspect contact from fraudulent support representatives masquerading as Microsoft are encouraged to report incidents via the official Microsoft scam reporting portal (microsoft.com/reportascam) to aid ongoing investigations and enhance consumer protection technologies.

This operation underscores the necessity for continued cross-sector collaboration and technological innovation to stay ahead of increasingly sophisticated cybercrime tactics and safeguard the most vulnerable populations.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Update

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories