#FactCheck: Phishing Scam on Jio is offering a ₹700 Holi reward through a promotional link
Executive Summary:
A viral post currently circulating on various social media platforms claims that Reliance Jio is offering a ₹700 Holi gift to its users, accompanied by a link for individuals to claim the offer. This post has gained significant traction, with many users engaging in it in good faith, believing it to be a legitimate promotional offer. However, after careful investigation, it has been confirmed that this post is, in fact, a phishing scam designed to steal personal and financial information from unsuspecting users. This report seeks to examine the facts surrounding the viral claim, confirm its fraudulent nature, and provide recommendations to minimize the risk of falling victim to such scams.
Claim:
Reliance Jio is offering a ₹700 reward as part of a Holi promotional campaign, accessible through a shared link.

Fact Check:
Upon review, it has been verified that this claim is misleading. Reliance Jio has not provided any promo deal for Holi at this time. The Link being forwarded is considered a phishing scam to steal personal and financial user details. There are no reports of this promo offer on Jio’s official website or verified social media accounts. The URL included in the message does not end in the official Jio domain, indicating a fake website. The website requests for the personal information of individuals so that it could be used for unethical cyber crime activities. Additionally, we checked the link with the ScamAdviser website, which flagged it as suspicious and unsafe.


Conclusion:
The viral post claiming that Reliance Jio is offering a ₹700 Holi gift is a phishing scam. There is no legitimate offer from Jio, and the link provided leads to a fraudulent website designed to steal personal and financial information. Users are advised not to click on the link and to report any suspicious content. Always verify promotions through official channels to protect personal data from cybercriminal activities.
- Claim: Users can claim ₹700 by participating in Jio's Holi offer.
- Claimed On: Social Media
- Fact Check: False and Misleading
Related Blogs
.webp)
Introduction
The advent of frontier AI has significantly widened the range of actors who can launch cyberattacks, extending beyond state actors with immense capabilities or organized professional cybercriminal rings. In its most critical advisory, CIAD-2026-0020, titled "Defending against frontier AI-driven cyber risks," which was released on April 26, 2026, the Indian Computer Emergency Response Team (CERT-In) officially stated that AI can now carry out autonomous cyber activities of unprecedented scale and speed. The advisory highlights that these frontier AI models can perform automated reconnaissance, phishing, malware creation, vulnerability identification, and social engineering with minimal human involvement, thus "lowering the barrier to orchestrating complex cyber attacks." The risks that such AI models pose are not restricted to state actors and corporate entities anymore and also extend to MSMEs, public organizations, and individuals.
India’s Escalating Cybercrisis
The Indian digital economy has been developing at a very fast pace, but the same cannot be said about its cybersecurity. Having a base of over 850 million internet users and a digital payment sector that records a massive 22,495 crore in monthly transaction volumes, coupled with the fastest-growing cloud sector in the world, India continues to remain a lucrative prey for cybercriminals. There were over 265 million attempts reported in the last year, 2025, alone, where close to 46% of all incidents detected were in enterprises with fewer than 1,000 employees, a very grave reality for MSMEs. MHA confirmed there were 28.15 lakh reported cybercrime complaints in 2025 as compared to 2024, with a jump of 24%. In this worsening environment the advisory is a breakthrough in Indian cyber governance. Where previously advisories covered only conventional threats like phishing and malware, the new warning names frontier agentic AI systems as autonomous multipliers of threats, capable of conducting operations at scale and speed with significantly reduced human oversight.
What is “Frontier AI” and why does it matter?
CERT-In’s decision to adopt the term "Frontier AI" is deliberate and meaningful. The advisory’s scope is a new category of agentic AI, which moves well beyond traditional chatbot-style AI, having the capacity to reason, plan, perform multiple actions in a single task autonomously, and carry out complicated tasks with minimal or no human guidance. CERT-In highlights that these tools now possess the capabilities that were "previously carried out by a coordinated team of skilled cybersecurity professionals." The advisory clearly flags the risk that these advanced models have the capability to generate malicious code, conduct network scans, probe systems for vulnerabilities, and even orchestrate intricate multi-stage cyberattacks in a single session. Their capacity to analyse a vast number of source code libraries to identify vulnerabilities, even unknown zero-day ones, and then develop proof-of-concept exploits at high speed. This means that the historical lead time to turn a vulnerability discovery into an exploit tool has reduced from weeks to just hours.
Six Core Threat Vectors identified by CERT-In
- AI-driven Automatic Zero-Day Discovery: AI-based solutions discover zero-day vulnerabilities and automatically create exploits in minutes, reducing the time taken by defenders.
- AI-driven Autonomous Reconnaissance: AI-driven agents scan cloud infra, APIs, and enterprise networks and outline attack vectors.
- AI-driven phishing & deepfakes: Multilingual, highly targeted phishing emails, deepfake audio, and deepfake voice/video calls bring sophistication to social engineering.
- Deepfake Financial Fraud: AI creates deepfake executives for high-value money transfers. For example, reports have indicated crore-level fund loss cases in India.
- AI-powered Autonomous Attack Chains: Advanced AI models are able to automatically perform multiple malicious stages like privilege escalation, lateral movement, data exfiltration, and data extraction.
- Cascading failures of interconnected systems: A single AI-supported security breach can have catastrophic domino effects on connected digital systems and critical infrastructures.
Why are MSMEs a target?
CERT-In’s warning is specifically targeted toward the weakness of the Indian MSMEs. Contributing almost 30% to India's GDP and employing over 110 million individuals, most MSMEs have failed to adequately prepare themselves against contemporary cyber threats. While a large corporation would have a full-time cybersecurity team, a security operation centre, and frequent vulnerability assessments, the majority of MSMEs lack such infrastructure due to budget constraints, out-of-date software, etc. This lack of security has proved to be quite disadvantageous for smaller businesses, as India was identified as one of the top global targets for cyberattacks, where approximately 46% of the total breaches worldwide targeted organizations having fewer than 1000 employees. The advisory claims that frontier AI systems have significantly increased the threats, for the skills necessary to carry out advanced cyberattacks have dramatically decreased. Ransomware, phishing and data exfiltration can be executed by even unsophisticated attackers. The aftermath could result in critical financial, operational, and compliance impact on these MSMEs.
The Global Context
These developments seem to validate CERT-In's warning about threats posed by frontier AI. In its 2026 State of Cybersecurity Report, ISACA listed AI-related threats as the top concern of cybersecurity professionals; 61% of those surveyed reported generative AI/large language models as the top technology trend impacting cyber risk. Worryingly, in 2026 only 7% were confident in their organizations' defenses against ransomware. Check Point Software's Cyber Security Report 2026 corroborates this; in 2025 the report stated that in a single year, the trend of combined social engineering-based campaigns with automated operational execution has risen considerably. In all phases of the lifecycle of a cyberattack reconnaissance, social engineering, and tactical decision-making AI is being applied. KPMG is warning of deepfake-enabled fraud now "spreading at a faster rate than that experienced at the beginning of the phishing era, which is currently still the leading type of attack in the world."
CERT-In Recommendations
For Large Organisations:
- The use of security monitoring, threat detection, and log analysis should be increased.
- DDoS protection systems and multi-factor authentication (MFA) should be implemented on all internet-facing devices and assets.
- Critical security patches should be installed within 24 hours of release.
- Old VPN and remote-access infrastructure should be updated or replaced.
- AI-driven cyber drills and incident response simulations should be regularly performed.
For MSMEs:
- Software and security updates should be automatically enabled on all devices and systems.
- MFA should be enabled on organisational accounts and sensitive platforms.
- MSMEs should utilize MSSPs for specialized support and monitoring.
- Detailed inventories of IT assets and system logs should be kept for fast incident response.
- Staff should be educated about identifying AI-generated phishing, deepfakes, and scams.
For Individuals:
- Independent communication channels should be used to verify any dubious message or money request.
- Software from unverified sources or unauthorised channels should not be downloaded.
- The use of strong and unique passwords along with MFA wherever possible should be enforced.
From Advisory to Action
The May 2026 cybersecurity road map released by CERT-In signals a departure from identification of threats to enabling operations against frontier AI-led cyber threat landscapes. This initiative builds on their April advice and delineates a clearly articulated three-phase roadmap comprising immediate cyber readiness, AI governance controls, and deep integration of AI-driven defenses. It also provides for the establishment of a focused AI Cyber Defense Center and various multisector governance provisions. A prominent area is the increased threat of impersonation via deepfakes, and companies are encouraged to institute executive verification procedures prior to approving high-value transactions. The framework also emphasizes the establishment of an AI asset register requiring formal accounting and governance of all AI systems utilized in an enterprise. Meanwhile, CERT-In also recognizes the twin-use nature of frontier AI: for every threat, the same technology can bolster security with automated threat detection, phishing, and log analysis in real time. However, the deployment of state-of-the-art defenses is uneven, especially with MSMEs, where there isn’t the requisite domain expertise and funding for this infrastructure. Accordingly, the road map puts the emphasis on immediate and stronger cyber hygiene, compulsory incident reporting, enhancing AI literacy, and proper implementation of the Digital Personal Data Protection Act for long-term security investment and resilience.
Conclusion
The CERT-In advisory CIAD-2026-0020 signifies a vital acknowledgment of AI's transformational impact on the cybersecurity ecosystem. Capabilities formerly exclusive to elite state actors are being deployed by low-skilled users, leveraging state-of-the-art frontier AI tools. India’s MSMEs, enterprises, and digital citizens are experiencing a rapidly accelerating threat milieu. In this context, the CERT-In advisory and the ensuing blueprint can no longer be dismissed as ordinary government pronouncements but as critical operational imperatives. It is the country’s ability over the next few years to shore up its collective cyber resilience to the ever-increasing scale and sophistication of AI-powered attacks that will prove crucial.
References:
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2026-0020
- https://www.zeebiz.com/technology/news-cert-in-flags-high-severity-ai-cyber-risks-amid-claude-mythos-concerns-394448
- https://www.business-standard.com/technology/tech-news/cert-in-warning-ai-scams-frontier-models-mythos-gpt-5-5-what-it-means-126042800988_1.html
- https://www.businesswire.com/news/home/20251020612551/en/
- https://corporate.indiamart.com/2025/07/29/staying-ahead-of-cyber-threats/
- https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2025/deepfakes-real-threat.pdf

Introduction
India’s telecommunications infrastructure is one of the world’s largest and most complex, serving over a billion users across urban and rural landscapes. With rampant digitisation and mobile penetration, the vulnerability of telecom networks to cyber threats has grown exponentially. On April 24, 2025, the Ministry of Communications (MOC) released a draft of the “Telecommunications (Telecom Cyber Security) Amendment Rules, 2025,” to update the prior Telecommunications (Telecom Cyber Security) Rules, 2024, to improve cybersecurity in India's telecom industry and fortify network security. Public comments and recommendations regarding these draft rules can be sent to the department by July 24, 2025, after they have been made available for public comment. These rules are enacted under the Telecommunications Act, 2023, to enhance national cybersecurity in the telecom domain. These rules aim to prevent misuse of telecom networks and reinforce data and infrastructure protection mechanisms across service providers.
Safeguarding the Spectrum: Unpacking the 2025 Cybersecurity Revisions
The menace of fraudulent SIM cards deals the issue of cyber threats a fresh hand. The rising number of digital scams can also be attributed to unverified or fake mobile numbers. Fraudulent SIM cards have often been linked to various cybercrimes such as phishing, vishing, SIM swapping and identity theft. The situation has worsened in the face of easy availability of pre-activated SIM cards and weak KYC enforcement. In a recent example, as per reports of June 28, 2025, the Special Task Force (STF) found that the accused was operating a criminal nexus where he utilised fake documents and the Aadhaar credentials of law-abiding locals to activate numerous SIM cards. Following activation, the SIMs were either transferred to other telecom carriers for additional exploitation or sold illegally. This poses a serious concern for the data protection of vulnerable individuals, especially those in rural areas, whose credentials have been compromised.
Given the adverse state of cybersecurity in the telecom industry, the Telecommunications (Telecom Cyber Security) Rules, 2024, were passed on 22nd November, 2024, which put various telecom entities under an obligation to actively prevent cybersecurity threats by adopting such policies that mitigate cybersecurity risks and notify the same to the Central Government. The 2024 Telecom Cybersecurity Rules were a significant step in fortifying India’s telecom infrastructure against cyber threats, but they primarily focused on licensed telecom service providers, leaving behind a large segment of digital platforms operating outside the traditional telecom framework largely unregulated.
Expanding the Net: Key Revisions Under the 2025 Cybersecurity Amendment Rules
The amended rules of 2025 adequately address the regulatory blind spot that is created by the rapid expansion of online services, fintech apps, OTT platforms and social media networks, as these platforms often rely on telecom identifiers such as mobile numbers for user onboarding and service delivery. This regulatory blind spot was exploited for fraud, impersonation and other cybercrimes, especially in the absence of standardised identity verification mechanisms. The proposed regulations would give the government the authority to require private companies’ clients to provide identification if they use a mobile number. For a fee, businesses can also undertake this kind of verification on their own. “ The draft rules introduce a new category called “Telecommunication Identifier User Entities’ (TIUEs), extending cybersecurity compliance obligations to a broad category that now captures any entity using telecom identifiers to deliver digital services. It also creates a unified, government-backed verification framework, enabling better interoperability and uniform user identification norms across sectors.
While strengthening national digital security is the goal of the Telecom Cybersecurity (Amendment) Rules, 2025, the proposed rules create a great deal of uncertainty and compliance difficulties, especially for private digital platforms. A broad definition of Telecommunication Identifier User businesses (TIUEs) may include a variety of businesses, including e-commerce services, fintech apps and OTT platforms, under the purview of required mobile number verification. Given that many platforms already have advanced internal processes in place to verify users, this scope uncertainty creates significant concerns regarding operational clarity.
Conclusion
The Telecommunications (Telecom Cyber Security) Amendment Rules, 2025, represent a necessary evolution in India’s quest to secure its telecom ecosystem amid growing cyber threats. The draft regulations recognise the evolving landscape of digital services by broadening the legal scope to encompass Telecommunication Identifier User Entities (TIUEs). Though the goal of creating a strong, transparent and accountable framework is admirable, more clarification and stakeholder involvement are required due to the scope’s vagueness and the possible compliance burden on digital platforms. A truly durable telecom cybersecurity regime will require striking the correct balance between security, viability and privacy.
References
- https://www.cyberpeace.org/resources/blogs/the-government-enforces-key-sections-of-the-telecommunication-act-2023
- https://www.cyberpeace.org/resources/blogs/govt-notifies-the-telecommunications-telecom-cyber-security-rules-2024
- https://the420.in/uttarakhand-stf-busts-fake-sim-racket-linked-to-cyber-crimes-and-nepal-network/
- https://www.thehindu.com/business/dot-puts-out-draft-rules-to-enable-mobile-user-validation/article69741367.ece
- https://www.scconline.com/blog/post/2025/06/28/dot-telecom-cyber-security-draft-policy-update/

Introduction
The most recent cable outages in the Red Sea, which caused traffic to slow down throughout the Middle East, South Asia, and even India, Pakistan and several parts of the UAE, like Etilasat and Du networks, also experienced comparable internet outages, serve as a reminder that the physical backbone of the internet is both routine and extremely important. Cloud platforms reroute traffic, e-commerce stalls, financial transactions stutter, and governments face the fragility of something they long believed to be seamless when systems like SMW4 and IMEWE malfunction close to Jeddah. Concerns over the susceptibility of undersea information highways have been raised by the incident. Given the ongoing conflict in the Red Sea region, where Yemen’s Houthi rebels have been waging a campaign against commercial shipping in retaliation for the Israel-Hamas war in Gaza. The effects are seen immediately. The argument over whether global connection is genuinely robust or just operating on borrowed time was reignited by these recent failures, which compelled key providers to reroute flows.
A geopolitical signal is what looks like a “technical glitch.” Accidents in contested waters are rarely simply accidents, and the inability to quickly assign blame highlights how brittle this ostensibly flawless digital world is.
The Paradox of Essential yet Exposed Infrastructure
This is not an isolated accident. Undersea cables, which carry more than 97% of all internet traffic worldwide, connect continents at the speed of light, and support the cloud infrastructures that contemporary societies rely on, are the brains of the digital economy., as cautioned by NATO’s Cooperative Cyber Defence Centre of Excellence. In a sense, they are our unseen electrical grid; without them, connectivity breaks down. However, they continue to be incredibly fragile in spite of their significance. Anchors and fishing gear frequently damage cables, which are no thicker than a garden hose, and they break more than a hundred times annually on average. Most faults can be swiftly fixed or relocated, but when several cuts happen in strategic areas, like the 2022 Tonga eruption or the current Red Sea crisis, nations and economies are exposed to being isolated for days.
The geopolitical risks are far more urgent. Subsea cables traverse disputed waters, land in hostile regimes, and cross oceans without regard for political boundaries. This makes them appealing for espionage, where state actors can tap or alter flows covertly, as well as sabotage, when service is interrupted to prevent access. Deliberate cable strikes have been likened by NATO specialists to the destruction of bridges or highways: if you choke the arteries, you choke the economy. Ironically, the most susceptible locations are not far below the surface but rather where cables emerge. These landing sites, which handle billions of dollars’ worth of trade, can have less security than a conventional bank office.
The New Theatre of Geopolitics
Legal frameworks exist, but they are patchwork. Intentional damage is illegal under the UN Convention on the Law of the Sea and previous agreements, but attribution is still infamously challenging. Covert sabotage and intelligence operations are examples of legal grey areas in hybrid warfare scenarios. Even during times of peace, national governments that rely on their continuous operation but find it difficult to extend sovereignty into international waters, private telecom consortia, and content giants like Google and Amazon that now finance their own cables share the burden of protection.
Cables convey influence in addition to data. Strategic leverage belongs to whoever can secure them, tap them or cut them during a fight. Even though landing stations are the entry points for billions of dollars’ worth of international trade, they frequently offer less security than a commercial bank branch.
India at the Crossroads of Digital Geopolitics
India’s reliance on underwater cables presents both advantages and disadvantages. India presents a classic single-point-of-failure danger, with more than 95% of its international data traffic being routed through a 6-km coastal stretch close to Versova, Mumbai. Red Sea disruptions have previously demonstrated how swiftly chokepoints located far from India’s coast may impede its digital arteries, placing a burden on government functions, defence communications, and financial flows. However, this same vulnerability also makes India a crucial player in the global discussion around digital sovereignty. It is not only an infrastructure exercise; it is also a strategic and constitutional necessity to be able to diversify landing places, expedite clearances, and develop indigenous repair capability.
India’s geographic location also presents opportunities. India’s location along East-West cable lines makes it an ideal location for robust connectivity as the Indo-Pacific region becomes the defining region of geopolitics in the twenty-first century. India may change from being a passive recipient of connectivity to a shaper of its governance by investing in distributed cable architecture and strengthening partnerships through initiatives like Quad and IPEF. Its aspirations for global influence must be balanced with its home regulatory lethargy. By doing this, India can secure not only bandwidth but also sovereignty itself by converting subsea cables from hidden liabilities into tools of economic might and geopolitical leverage.
CyberPeace Insights
If cables are considered essential infrastructure, then their safety demands the same level of attention that we give to ports, airports, and electrical grids. Stronger landing station defences, redundancy in route, and sincere public-private collaborations are now a necessity rather than an option.
The Red Sea incident is a call to action rather than a singular disruption. The robustness of underwater cables will determine whether the internet is a sustainable resource or a brittle luxury susceptible to the next outage as reliance on the cloud grows and 5G spreads.
References
- https://forumias.com/blog/answered-assess-the-strategic-significance-of-undersea-cable-networks-for-indias-digital-economy-and-national-security-discuss-the-vulnerabilities-of-this-infrastructure-and-suggest-measures-to-e/
- https://www.reuters.com/world/middle-east/red-sea-cable-cuts-disrupt-internet-across-asia-middle-east-2025-09-07/
- https://pulse.internetsociety.org/blog/what-can-we-learn-from-africas-multiple-submarine-cable-outages