Home India Ministry of Commerce and Industry Cyber fraud complaints from Indian Exporters - Trade Advisor...
Date: 2021-01-04 Category: Not Applicable State: Union Government Country: India

Cyber fraud complaints from Indian Exporters - Trade Advisory reg

Issued by Ministry of Commerce and Industry · Directorate General Of Foreign Trade

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: This trade notice addresses the rise in email spoofing/phishing cyber frauds causing bilateral trade disputes, where Indian exporters lose goods and payment. It advises implementing security protocols like SPF, DKIM, and DMARC to combat these frauds. Exporters are urged to take precautionary measures to protect payments, and RAs are instructed to inform trade. Key Points / Main Content: * **Problem:** Email spoofing/phishing cyber frauds are increasing, leading to trade disputes and financial losses for Indian exporters. * **Solution:** Implementing security protocols SPF, DKIM, and DMARC can largely resolve these issues. * All three protocols (SPF, DKIM, and DMARC) must be implemented for best deliverability and to ensure sender legitimacy. * These protocols are based on the Domain Name System (DNS). * **SPF (Sender Policy Framework):** * Certifies that the issuing IP is authorized to send emails, preventing fraudulent use of the domain name and phishing attacks. * Specifies allowed IP addresses/servers for sending emails from a particular domain. * **DKIM (Domain Keys Identified Mail):** * Ensures email content integrity and verifies the sender's domain ownership using cryptographic protocol and public keys in the DNS. * Protects against "man in the middle" attacks. * **DMARC (Domain-based Message Authentication, Reporting & Conformance):** * Ties SPF and DKIM together with consistent policies. * Provides attack indications and verifies that emails are protected by both SPF and DKIM. * Allows reporting back to the sender about messages that pass/fail DMARC evaluation. * **Additional Advice:** * Follow better password practices. * Confirm bank details via a secure voice line or other secure channel. * **Action Items:** * EPCs/Traders: Take all precautionary measures to protect payments from cyber frauds. * RAs: Inform trade about these issues as part of their outreach efforts. Impact Analysis: * **Indian Exporters/Traders:** * *Impact:* Increased security against cyber fraud, protecting them from financial losses and trade disputes. * *Action Required:* Implement SPF, DKIM, and DMARC security protocols, improve password practices, and verify bank details through secure channels. * **Export Promotion Councils (EPCs):** * *Impact:* Reduced risk of trade disputes and improved trust in export transactions. * *Action Required:* Advise and support members in implementing security measures. * **Regional Authorities (RAs) of DGFT:** * *Impact:* Play a role in disseminating critical information. * *Action Required:* Inform trade about the cyber fraud risks and the recommended security protocols during outreach activities.

Key Entities Referenced

Ministry of Commerce and Industry: The Indian government ministry responsible for international trade and commerce. Directorate General of Foreign Trade: A department of the Ministry of Commerce and Industry responsible for implementing the foreign trade policy. New Delhi: The location of the Udyog Bhawan, the office of the Directorate General of Foreign Trade. Export Promotion Councils: Organizations in India that promote and support exports from specific sectors. Ministry of External Affairs: The Indian government ministry responsible for India's foreign relations. Sender Policy Framework: An email authentication method designed to detect spoofing by verifying the IP address of the sender. Domain Keys Identified Mail: An email authentication method that uses cryptographic signatures to verify the sender and ensure the message hasn't been altered. Domain-based Message Authentication, Reporting Conformance: An email authentication protocol that builds on SPF and DKIM to provide policy enforcement and reporting mechanisms.
Official Source Record View Original Source →
See Full Document Text
Government of India Ministry of Commerce & Industry Directorate General of Foreign Trade Udyog Bhawan, New Delhi — 110011 wh Dated: January 4, 2021 Trade Notice No.2.6/2020-21 To All Export Promotion Councils All members of the trade All RAs of DGFT Sub: Cyber fraud complaints from Indian Exporters - Trade Advisory -reg Ministry of External Affairs has informed that email spoofing/phishing cyber frauds are causing increased bilateral trade disputes. Though this is registered as a cybercrime in the respective jurisdictions of the country, the authorities cannot do much to reverse the transaction. The victims end up being Indian exporters who having supplied the goods. They neither have the goods in their possession nor have received the payment. 2. The matter was examined and such problems can be largely resolved by implementing security protocols such as Sender Policy Framework (SPF), Domain Keys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting & Conformance (DMARC). SPF, DKIM, and DMARC are protocols for standard email signatures which meet various safety issues and all three must be implemented in order to ensure the best possible deliverability. All three prove that the sender is legitimate, that their identity has not been compromised and that they're not sending email on behalf of someone else. They are all based on the Domain Name System (DNS) of the domain. 3: SPF protocol based on the DNS of the domain name, certifies that the issuing IP has the right to send emails. This protocol is used to prevent fraudulent use of the domain name and prevents phishing attacks. It specifies which IP addresses and/or servers are allowed to send email “from” that particular domain. It lets the recipient know who has sent the communication. 4. DKIM is a cryptographic protocol based on the use of public keys that are published in the DNS. It ensures that the content of emails remains trusted and have not been tampered with or compromised and the headers of the message have not changed and that the sender of the email actually owns the domain that has the DKIMrecord attached to it. The protocol allows the sender to sign the email with the domain name. The recipient of your email will then be sure that the email has been sent by the sender and has not been altered during transmission. This protocol is particularly effective against "man in the middle" attacks. 2) DMARC provides indications in case there is an attack, ties the first two protocols (SKM and DKIM) together with a consistent set of policies. It is possible to be notified if someone tries to steal the identity of the sender. It verifies that a sender’s email messages are protected by both SPF and DKIM. It also tells the receiving mail server what to do if neither of those authentication methods passes, and provides a way for the receiving server to report back to the sender about messages that pass and/or fail the DMARC evaluation. 6. It is also suggested that better password practices be followed on both the sender's and the receivers’ email IDs and to avoid this completely, exporters may like to confirm bank details by another channel such as a secure voice line. TG EPCs/Traders are advised to take all precautionary measures to protect their payments from cyber frauds. 8. RAs are advised to inform trade as part of the outreach exercise. 9. This issues with the approval of the Competent Authority. Ve wy (Manoj Kumar Singh) Joint Director General of Foreign Trade Email: singh.mk@nic.in Ph: 23061562 Extn: 343 (01/36/218/25/AM20/Coordination)

Continue your research