Telangana Cyber Security Bureau alerts citizens to malicious New Year greetings that can steal data, control phones, and compromise bank accounts.
The Telangana Cyber Security Bureau (TGCSB) has sent out a terrifying reminder that, in a time when sending a heartfelt greeting from a “friend” is the norm, a simple emoji or a merry GIF might be a digital Trojan Horse.
A sophisticated wave of “Greeting Scams” is sweeping across Telegram and WhatsApp as the city prepares for the 2026 celebrations. These attacks take use of something considerably more dangerous—festival trust—than usual scams, which are based on fear or greed.
An alarmingly straightforward mechanism is highlighted in a TGCSB advisory. A message with a link offering a “special personalised greeting,” a “New Year gift,” or a “SBI year-end reward” is sent to users, frequently by a trusted contact whose own account has already been stolen.
The trap is set up as soon as a user clicks. The link initiates the silent installation of a malicious APK or Android Package Kit file rather than a joyous animation. In addition to stealing data, this spyware “kidnaps” your phone once it has taken up residence.
Cyber specialists claim that these malicious files give hackers almost complete control over the victim’s online activities.
Also read : Tripura Student Murder: NESO Demands Capital Punishment
Hackers can get around two-factor authentication for bank transfers by using the malware’s ability to read incoming SMS texts.
In order to continue the infection cycle, the hackers seize control of the victim’s WhatsApp account and send the same malicious link to every contact on their list.
Remote access to your contacts, photo gallery, and even microphone could result in identity theft or extortion.
This scam’s social engineering is its most successful component. The typical “stranger danger” warning signs are not raised because these URLs are shared within office conversations and family groups.
According to Shikha Goel, the chief of the Bureau, “people think they are opening a greeting card, but in reality, they are handing over the keys to their bank account.”
How the TGCSB Protocol Can Help You Stay Safe
- The TGCSB advises individuals to adhere to following guidelines in order to guarantee that your New Year begins on a positive rather than a legal note:
- Avoid clicking on links at all costs. Steer clear of any unfamiliar links in offers, presents, or greetings—even from friends.
- Block apk files: Avoid installing any apps that have been delivered to you secretly via chat apps.
- Enable 2FA: To guard against account theft, enable WhatsApp’s two-step verification.
- Official update: Only download programs or updates from the official Apple App Store or Google Play Store.
- Disconnect right away by turning off the internet, uninstalling dubious apps, and alerting your bank if you click on any links.
Cybercrime Reporting
The TGCSB emphasizes the “Golden Hour” rule, which states that reporting within the first hour of a transaction improves the likelihood that the assets will be frozen if you or someone you know is the victim of such fraud.
Call 1930 right away, and register complaints at www.cybercrime.gov.in.
Keep an eye out, be safe, and make improved digital hygiene a part of your New Year’s resolutions.