Fake DigiYatra Website Targeting Indian Flyers
Threat actors are using the name of a trusted Indian government initiative to impersonate DigiYatra and harvest personal data through a fake travel-themed website.
By ThreatWatch360 Research Team
📅 March 29, 2025
Summary
Threat actors were operating a deceptive phishing site impersonating the trusted DigiYatra Foundation to target unsuspecting Indian air travelers. The fraudulent domain digiyatra[.]in is still live at the time of reporting and was being used to harvest personal user data under the false appearance of offering official services. While the name matched the government-backed application, the site design and behavior were inconsistent with the legitimate platform.
This website is actively misleading the public by exploiting trust in a digital public infrastructure initiative promoted by the Government of India.
Detection and Monitoring Context
ThreatWatch360 continuously monitors domains registered with keywords tied to digital brands, such as “DigiYatra.” This is part of our Early Warning Threat Detection feature, which alerts clients when suspicious domains are being registered or activated leveraging the brand’s identity related keyword.
The domain digiyatra[.]in had triggered a flag due to its exact keyword match, and upon review, was being identified as an unauthorized and malicious impersonation. Alerts were being shared with Ministry of Civil Aviation, Adani Airports and national partners Cert-In for immediate review and action.
What the Fake Website Was Doing
Although the domain name was directly matching the government’s DigiYatra brand, the website content and structure were not aligned with any official service. The design, layout, and user interface were resembling a flight ticket booking platform, which was not part of the DigiYatra Foundation’s offerings.
Upon visiting the page, our threat research team was noticing the presence of:
- A user form asking for name, phone number, and email

Despite presenting itself as a booking interface, no actual ticket sales or transactions were being completed. Instead, the interface appeared to be designed purely for data harvesting, luring users into entering PII by imitating a legitimate service experience.

Details and Indicators of Compromise (IOCs)
- Domain Name:
digiyatra[.]in
- IP Address:
167[.]172[.]151[.]164(also accessible directly athxxp://167[.]172[.]151[.]164:3000)
- WHOIS Registrant: Ali Sajil (Kerala, India – remaining details redacted for privacy)
- Domain Creation Date: July 21, 2022
- Domain Expiry Date: July 21, 2025
- SSL Certificate: The site was being configured with a Let’s Encrypt SSL certificate — a free and automated encryption solution
Risk Assessment
The ongoing operation of this phishing domain was posing significant threats across multiple vectors:
- Data Privacy Risk: Sensitive user data was being collected under false pretenses.
- Public Deception: Users were believing the service to be affiliated with DigiYatra or the Government of India.
- Reputational Damage: Misuse of a trusted government program's identity was undermining public confidence.
- Lack of Awareness: The design mismatch (flight portal) was subtle enough to mislead non-technical users.
ThreatWatch360 assessed the domain as a high-severity impersonation threat, particularly due to its keyword use, trust abuse, and unverified data collection.
ThreatWatch360 Response Actions
Our Cyber Threat Intelligence team was taking immediate steps:
- Sharing early-warning alerts with brand protection clients
- Escalating the domain to CERT-In and relevant government entities
- Submitting a takedown request to the domain registrar
- Initiating monitoring for related impersonating domains using variant keyword patterns
- Advising DNS-level blocks for
digiyatra[.]inand167[.]172[.]151[.]164
Conclusion
The domain digiyatra[.]in was actively exploiting public trust by imitating a government initiative’s name while masquerading as a travel service. This campaign was a clear example of how attackers were using legitimate branding and misleading design to compromise user data.
We strongly advise all users to only use the official DigiYatra Foundation site at hxxps://www[.]digiyatrafoundation[.]com and to remain cautious of lookalike websites — even those that appear secure through HTTPS.
ThreatWatch360 remains committed to defending the integrity of digital public infrastructure through real-time detection, investigation, and coordinated response.
Mitigating the Risk
Organizations operating public-facing digital services — especially those aligned with government initiatives — were being strongly encouraged to adopt proactive brand protection and impersonation detection strategies. In an era where attackers were increasingly leveraging official-sounding names and government-trusted branding, staying reactive was no longer sufficient.
ThreatWatch360’s Brand Protection Suite was continuously helping organizations reduce exposure to such attacks by offering:
- 24/7 Domain Abuse Monitoring for keyword, typo-squatted, and DNS registrations
- Real-Time Phishing Site Detection and Early-Warning Alerts to prevent widespread damage
- Executive and Brand Misuse Monitoring, including impersonation of leadership and institutions
- Automated and Manual Takedown Coordination with registrars and hosting providers
For incident response support, takedown assistance, or to subscribe to early-warning alerts, contact the ThreatWatch360 Cyber Threat Intelligence Team at [contact@threatwatch360.com].




