ICAI issues Cyber Security advisory against Unauthorized Access

ICAI Issues Cyber Security Advisory Against Unauthorized Access to Its Digital Platforms
The Institute of Chartered Accountants of India (ICAI) has issued a public advisory after detecting repeated attempts to gain unauthorized access to its digital platforms and information technology systems.
ICAI manages a wide range of digital services, including its official website, online portals, web and mobile applications, application programming interfaces (APIs), databases, and other technology infrastructure used by members, students, and stakeholders. The Institute has clarified that any unauthorized attempt to access, interfere with, manipulate, disrupt, extract data from, or misuse these systems is illegal and may attract action under applicable laws, including the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023.
According to the advisory, prohibited activities may include:
- Accessing computer systems or digital resources without authorization.
- Hacking, modifying, deleting, or tampering with electronic records or computer source code.
- Stealing, altering, or misusing digital information and databases.
- Identity theft, online impersonation, cyber fraud, and cheating through computer resources.
- Attempts to compromise protected computer systems or other critical digital infrastructure.
ICAI has reiterated that it follows a strict zero-tolerance approach towards cybercrime. The Institute stated that its digital ecosystem is protected through multiple security controls, continuous monitoring, audit mechanisms, and other technical and administrative safeguards. Any attempt to breach or misuse its systems may be investigated and appropriate legal action may be initiated against those responsible.
The Institute has also advised members, students, and the general public to access ICAI’s online services only through its official website and other authorized digital applications. Users should remain alert against phishing emails, fake websites, fraudulent mobile applications, and other deceptive methods designed to impersonate ICAI or steal login credentials.
ICAI further cautioned that it cannot be held responsible for losses resulting from the use of unauthorized platforms or from sharing account credentials with unauthorized persons.
The advisory concludes with a warning that all unauthorized access attempts are subject to security monitoring and audit logging. Any individual involved in compromising, interfering with, or misusing ICAI’s digital infrastructure may face legal proceedings and other remedies available under the applicable laws.
Read More Updates on ICAI

