Case Studies

Real-world instances of cyber incidents which showcase how we detect deepfakes, expose cyber breaches, and neutralise high-impact cyber fraud.

Deepfake of Narayan Murthy Surfaces
Deepfake

Deepfake of Narayan Murthy Surfaces

In August 2025 a coordinated financial fraud campaign which leveraged AI-generated deepfake technology to impersonate Infosys Founder Narayana Murthy, falsely portraying him as endorsing a fictitious government-backed investment platform surfaced across social media platforms. The manipulated video circulated across Facebook, Instagram, and WhatsApp, claimed that citizens could earn over ₹1.9 lakh per month by making a one time investment of ₹ 21,000 through an “AI-powered automated smart investing” scheme.

Read More
BSNL
Telecom

Breach at Telecom Major BSNL

On 20 May 2024, government owned telecom major BSNL and a critical part of India’s national communications infrastructure, was hit by a major cybersecurity incident. The same day, a threat actor—kiberphant0m—claimed responsibility of the attack and advertised the sale of approximately 278 GB of sensitive telecom data on the dark web. The exposed data included IMSI numbers, SIM subscriber details, Home Location Register (HLR) records, and internal Solaris server snapshots, all of which are vital for telecom operations and subscriber identity management.

Read More
Breach in the Department of Defence
Cybercrime

Breach in the Department of Defence

On 10 March 2025, Athenian Tech (AT) identified a significant security breach affecting a sensitive national defence division after the ransomware group Babuk Locker 2.0 claimed to have exfiltrated nearly 20TB of classified defence data. The leaked dataset reportedly included sensitive information like VVIP evacuation procedures.

Read More
Remote Unauthenticated RCE in OpenSSH Exploitation
Cybercrime

Remote Unauthenticated RCE in OpenSSH Exploitation

In August 2024, Athenian Tech (AT) uncovered a critical security risk during a routine digital‑risk assessment conducted for a European holding company. One of the organisation’s publicly exposed servers was found running OpenSSH 8.9p1 on Ubuntu — a version vulnerable to the high‑severity “regreSSHion” flaw (CVE‑2024‑6387). This vulnerability, caused by a race condition in sshd’s signal handler, allowed remote unauthenticated attackers to repeatedly trigger LoginGraceTime and potentially execute arbitrary code as root. If exploited, the flaw could have enabled a complete system takeover, deployment of persistent backdoors, data exfiltration, and lateral movement into the company’s wider IT infrastructure, posing material operational and financial risks.

Read More
Deepfake of Gautam Adani Detected
Deepfake

Deepfake of Gautam Adani Detected

In June 2025, Athenian Tech (AT) noticed a sophisticated scam campaign impersonating the chairperson of a major Indian conglomerate. The attackers used AI‑generated deepfake videos and a fabricated news article styled to resemble a leading national media publication. The video falsely linked the executive and several well‑known figures from the corporate sector and the government to a false government‑backed investment platform.

Read More
Deepfake of Prime Minister Narendra Modi Surfaces
Deepfake

Deepfake of Prime Minister Narendra Modi Surfaces

In July 2025, Athenian Tech (AT) identified a coordinated AI generated deepfake campaign of Prime Minister Narendra Modi, which showed him promoting a fraudulent online investment platform which was circulated on Facebook. The manipulated video falsely portrayed the PM Modi endorsing an automated wealth‑generation scheme, while additional synthetic assets misused the identities of senior public figures, including Nirmala Sitharaman, Narayana Murthy, and Sudha Murty, to create a further perception of legitimacy. Paid advertisements amplified the operation, directing users to scam websites hosted on .top domains that harvested personal and financial information before funnelling victims into organised investment‑fraud networks.

Read More
Early-stage Breach Detection
Cybercrime

Early-stage Breach Detection at a leading Hotel Group

In November 2023, Athenian Tech (AT) uncovered a data‑exposure incident affecting a major international hotel group thereby identifying early signs of a breach that compromised approximately 1.5 million customer records of the said hotel. The leaked dataset included PII, such as names, contact numbers, residential addresses, and detailed booking histories, with notable exposure of EU nationals, thereby increasing regulatory and compliance obligations under global data‑protection frameworks. The breach surfaced on the Dark Web marketplaces and closed Telegram channels frequented by data‑brokers and extortion groups, signalling the initial phase of a high‑value criminal operation aimed at monetising hospitality‑sector customer data.

Read More
Zero Day Exploitation
Industry

Zero Day Exploitation Microsoft Follina by Athenian Tech

The MSDT “Follina” zero‑day (CVE‑2022‑30190) emerged as a high‑severity exploitation vector in which attackers weaponised Microsoft Office documents to execute code via the Microsoft Support Diagnostic Tool. The vulnerability enabled remote code execution without macros, triggering when a user opened—or even previewed—a malicious file.

Read More
Predicted Cyber Attacks
Cybercrime

Predicted Cyber Attacks Around Independence Day 2025

Around end of July and early August 2025, Athenian Tech (AT) got wind of preparations of cyberattacks targeting India ahead of its 79th Independence Day. AT intercepted chatter across Telegram, Signal and Atox which revealed heightened activity by multiple hacktivist groups operating under the “Allied Muslim Hacktivist Coalition.” These groups planned synchronised strikes across sectors around 15th August 2025. AT’s threat‑intelligence platform, Prime, combined with analyst‑led infiltration of closed channels, enabled early threat detection. The team engaged in the following activities to get more information about the planned activities.

Read More

Get the next one in your inbox.

The Month in Threats, Read by the People Who Have to Answer for It.

Free. Unsubscribe any time. We never sell or share your address.