The Indian Railways has issued a cybersecurity advisory to all zonal railways and other key railway organisations after a script-based cyber incident was reported in Central Railway on August 11 this year. Authorities warned that messaging applications, particularly WhatsApp Web, can be exploited to deliver malicious files and potentially compromise computers connected to railway networks.
According to a root-cause analysis cited by the authorities, the incident occurred when a user received a malicious “E-statement.vbs” file in a WhatsApp group. The file was downloaded onto the user’s computer through the WhatsApp Web application and was subsequently opened by double-clicking it.
“The incident has prompted the Railway Board to direct its units to strengthen endpoint protection and user awareness against malware campaigns exploiting messaging platforms. It is also consistent with a CERT-In warning about a wider campaign in which malicious VBScript files are distributed through WhatsApp, including through compromised accounts to make the messages appear trustworthy,” said the railway official.
Indian Railways cybersecurity measures
Railway units have been asked to ensure that all endpoints connected to railway networks are covered by cyber-security solutions, including ITSM and Endpoint Detection and Response (EDR). Employees have been advised to avoid opening files with extensions such as .vbs, .vbe, .exe, .bat, .cmd, .js and .ps1 unless their authenticity and necessity have been independently verified.
Staff were also told to exercise caution when opening unexpected attachments, even when they appear to come from known contacts. They should verify the identity of the sender before opening suspicious files or clicking links, and keep operating systems, browsers and messaging applications updated.

