On August 13, the Supreme Court of India issued a public warning regarding a new fake website. The website, sp-court-in.com, impersonates the court’s official website. Cybercriminals could use the website to steal personal and financial information through phishing.
The advisory asks users not to share sensitive information on suspicious websites. It says the Supreme Court’s official domain is sci.gov.in. The Supreme Court also advises users to verify URLs before clicking them. Users should change their passwords and alert their banks if they suspect a data breach.
“Cybercriminals through the aforementioned link may attempt to solicit sensitive personal data and confidential credentials of the public,” the Supreme Court Registry said.
Repeated Supreme Court warnings: The latest notice is part of a continuing series of warnings from the court. In April 2026, the Registry flagged scigovjudicial.com for impersonating the Supreme Court. In July 2025, it listed 16 fake domains, including supremecourtofindiagov.com, scigoin.com and judiciarycheck. in. Those notices followed earlier warnings issued in January 2025 and August 2023. This continues despite authorities identifying individual domains and reporting them to law enforcement.
Fake websites are a wider problem: The problem is not limited to the Supreme Court. In 2019, a Bengaluru woman searching Google for Zomato customer support reached a fake customer-care website. Fraudsters persuaded her to install AnyDesk by promising a refund and then withdrew money from her bank account. Zomato later said its customer support was available only through its app and email.
Government websites have also been compromised for other kinds of fraud. In June 2026, cybersecurity firm FalconFeeds said attackers had hijacked more than 100 Indian government and public-sector domains. The attackers used these domains to push gambling content through Google Search.
According to FalconFeeds, attackers used server-side cloaking. They allegedly showed Google’s crawler gambling-related content while redirecting mobile users from search results to offshore betting services; administrators, meanwhile, saw a normal page or an error. This made the compromise harder to detect.
Similar risks extend to financial services. On August 11, the Employees’ Provident Fund Organisation warned members about fake websites, phishing links and fraudulent messages. These scams seek information linked to EPF accounts. These include UANs, Aadhaar and PAN details, bank information and OTPs.
Is repeatedly warning users enough? Public advisories can help users identify known scams. However, they remain largely reactive. Authorities usually issue warnings only after discovering a fake domain or phishing campaign.
The larger policy question concerns domain registration. Should registration involve stronger identity checks? This could make it easier to trace people who register websites for fraud.
India has already moved in that direction for .in domains. In 2025, registrars informed customers about new KYC requirements. Customers would need to complete KYC to register or renew .in domains. The revised rules came under a Registrar Accreditation Agreement issued by the National Internet Exchange of India (NIXI).
The framework requires registrants to submit identity documents. It also allows authorities to require foreign entities to demonstrate a legitimate connection with India.
The policy builds on a 2022 government notification. The notification authorised MeitY and NIXI to conduct voluntary Aadhaar authentication. It also allowed other forms of KYC for .in domain registrations.
Supporters of such checks argue that verified identities can help authorities trace people behind fraudulent domains. But critics have questioned whether requiring KYC from every registrant is proportionate when bad actors can also use domains outside the .in ecosystem.
Sijo Kuruvilla George, Executive Director of the Alliance of Digital India Foundation, spoke to MediaNama in 2022. He said, “The internet used to have anonymity as the basis of how things used to happen. But having said that, we are getting to a point in time where anonymity itself is creating a lot of unique problems.”
He also warned about the limits of such a system: “However, having said that, the internet is a very decentralised construct. So even if you say that you have to disclose everything, there is simply no way you can track everything.”
KYC push meets its limits: The debate widened further in December 2025. The Delhi High Court held that e-KYC should be mandatory for domain name registrations in India. The case involved fraudulent websites impersonating established brands. The court also directed registrars to retain verified identity information and certain technical records. Registrars must make these records available to authorities when formally required.
The challenge is therefore broader than taking down one fake Supreme Court website at a time. Phishing domains, compromised government websites and fake customer-care portals rely on different technical methods and can operate across different domain extensions.
The Supreme Court’s latest advisory adds another domain to a growing list. However, the repeated warnings leave a larger question unresolved. Can better user awareness, stronger registrar checks, faster takedowns and improved website security work together? Can they do so without imposing disproportionate restrictions on legitimate internet users?
Read more: