S shape representing Sattrix
We Serve, We Prove, We Repeat
25 Major Cyber Attacks in India That Shocked the Nation

Cyber attacks have become a significant threat in India, impacting individuals and organizations alike. With the rapid digital transformation, vulnerabilities in systems have increased, leading to numerous high-profile breaches. Cybersecurity service providers play a crucial role in addressing these challenges. Understanding these incidents is essential for developing effective strategies to combat cyber threats.

This blog highlights the 25 biggest cyber attacks in India, examining their impact and the lessons learned. By exploring these events, readers can gain valuable insights into the current cybersecurity landscape and the importance of safeguarding sensitive information.

1. BharatPay Hacked: August 2022

In August 2022, BharatPay, a digital financial services provider, experienced a serious data breach exposing the personal data of around 37,000 users. The leaked information included sensitive details such as usernames, hashed passwords, and transaction data from its backend database. The incident, which spanned several years of data, underscores the vulnerabilities in the fintech sector and the critical need for enhanced security measures to protect customer information.

2. Swachhta Platform Hacked: September 2022

In September 2022, the Swachh City platform, associated with the Swachh Bharat Mission, was hacked, compromising the data of approximately 16 million users. The attackers, known as LeakBase, accessed critical information such as email addresses, password hashes, and phone numbers, which were later offered for sale on the Dark Web. The breach poses risks for phishing attacks and other cybercrimes, showcasing vulnerabilities in government platforms that handle citizen data.

3. Cyberattack on AIIMS: December 2022

In December 2022, the All India Institute of Medical Sciences (AIIMS) suffered a significant cyberattack, leading to the encryption of about 1.3 terabytes of data across five servers. The incident was attributed to unauthorized network access, exacerbated by inadequate network segmentation. While no ransom was demanded, the attack underscored vulnerabilities in critical healthcare infrastructure. Fortunately, e-Hospital data was restored from an unaffected backup, and application functionalities were reinstated within two weeks.

4. RailYatri Data Breach: December 2022

RailYatri, an e-booking service for Indian Railways, faced a data breach in December 2022 that resulted in over 30 million user records being compromised. The breach was revealed when a threat actor leaked the data on a cybercrime forum, although RailYatri claimed that no sensitive customer data was accessed. This incident highlighted the ongoing cybersecurity challenges faced by online platforms in the transportation sector.

5. CloudSEK Data Breach: December 2022

In December 2022, CloudSEK, an Indian cybersecurity firm, suffered a targeted breach aimed at damaging its reputation within the cyber threat intelligence community. The attackers claimed to have accessed sensitive information, including source codes and client data, although CloudSEK denied these allegations. The breach revealed vulnerabilities in the company’s internal security practices and served as a reminder of the constant threats faced by organizations in the cybersecurity sector.

6. Zivame Data Breach: 2022

Zivame, a popular online platform for women’s wear in India, experienced a major data breach affecting around 1.5 million customers. The personal information, including names, email addresses, and phone numbers, was offered for sale online for $500 in cryptocurrency. Investigations revealed the seller provided a sample dataset as proof of the breach, emphasizing the risks associated with personal data exposure in e-commerce platforms.

7. Motilal Oswal Cyber Incident: 2023

Motilal Oswal Financial Services experienced a cyber incident linked to the LockBit group, known for extortion tactics. Although the attack involved malicious activities detected on employee systems, the company reported no disruption to operations. The issue was promptly addressed, and services continued as normal, emphasizing the resilience of its IT environment.

8. Polycab Ransomware Attack: 2023

Polycab India Limited, a leading wires and cables manufacturer, reported a ransomware attack targeting its IT infrastructure. Compliant with SEBI regulations, Polycab confirmed that while the attack occurred, its core systems and manufacturing operations remained unaffected. The company is collaborating with cybersecurity experts and law enforcement to enhance its security measures and investigate the incident further.

9. Sun Pharma Cyber Attack: 2023

Sun Pharmaceutical Industries, a major player in the Indian pharmaceutical sector, faced a cyberattack that disrupted its operations. While the company disclosed the breach to stock exchanges, details regarding the perpetrator and extent of the data compromised remain unclear. This incident marked the third significant attack on an Indian drugmaker, raising concerns about the security of critical healthcare infrastructure and the potential impact on patient safety and data integrity.

10. MoChhatua Data Breach: May 2023

In May 2023, the MoChhatua app, aimed at digitizing ration distribution in Odisha, was reportedly breached, exposing sensitive user data such as names, emails, and passwords. A hacker claimed responsibility on a forum, sharing screenshots of the compromised data. Despite attempts to verify the breach with the Odisha state government, no official confirmation was provided, raising concerns about the security of government applications and the sensitive data they handle.

11. Cyberabad Police Data Leak: April 2023

In April 2023, a massive data breach affected over 66.9 crore individuals and organizations, prompting the Cyberabad Police to investigate. Notices were issued to 11 organizations, including banks and IT firms, linked to the unauthorized access and theft of personal and confidential data. The breach raised alarms about the security practices of various sectors and highlighted the need for stringent measures to protect sensitive information.

12. Rentomojo Cyber Attack: April 2023

In April 2023, Rentomojo, an online rental platform, fell victim to a data breach, risking the personal information of its users. Although the company assured that financial data was not compromised, reports surfaced of a hacking group claiming access to sensitive personal information. The breach, attributed to cloud misconfiguration, highlights the escalating threats faced by businesses in the digital rental space and the importance of robust security practices.

13. SPARSH Data Breach: 2023

The SPARSH portal, developed by Tata Consultancy Services for managing pension processes for defense personnel, suffered a data breach that exposed sensitive information, including usernames and pension numbers. The compromised data, reportedly sold on the dark web, raised significant privacy concerns and led to scrutiny over the portal’s security protocols.

14. Hathway ISP Data Breach: 2023

Hathway, a major ISP and cable operator in India, was hit by a massive data breach that exposed personal data of over 41.5 million customers. A hacker named ‘dawnofdevil’ exploited a vulnerability in the company’s content management system, resulting in the leak of over 200GB of sensitive information, which was subsequently made available on a breach forum.

15. Telangana Police’s Hawk Eye App Data Breach: 2023

The Telangana police’s Hawk Eye app experienced a data breach, exposing sensitive information of approximately 200,000 citizens. The breach, attributed to hacker “Adm1nFr1end[1],” involved personal data such as phone numbers and addresses. The police were able to track the hacker and make an arrest, highlighting the importance of proactive cybersecurity measures.

16. Tamil Nadu’s Facial Recognition Portal Data Breach: 2023

Tamil Nadu’s police Facial Recognition Software portal was breached using compromised credentials, exposing data of over 6 million records. Although the breach did not directly compromise the data, it raised significant concerns regarding security practices within the department. Investigations are ongoing, with relevant authorities alerted to the incident.

17. National Disaster Management Authority (NDMA) Data Breach: 2023

The NDMA of India faced a data breach that compromised the personal data of 93,000 volunteers. The hacker, using the alias “infamous,” claimed to have accessed and offered the data for sale on the dark web. Although NDMA’s website showed no signs of a breach, volunteers were advised to be vigilant against identity theft and fraud.

18. boAt India Data Breach: 2023

Consumer electronics brand boAt experienced a significant data breach, revealing the personal information of over 7.5 million users. Allegedly executed by a hacker known as ‘ShopifyGUY[2],’ the breach involved the leak of sensitive data, including names and email addresses, which was subsequently shared on dark web forums. boAt has acknowledged the incident and initiated an investigation.

19. Hyundai Motor India Data Leak: 2023

Hyundai Motor India recently rectified a data breach linked to vulnerabilities in web links shared via WhatsApp. The exposed data included customers’ personal information and vehicle details. The company has since addressed the issue and reaffirmed its commitment to protecting customer data.

20. Burger Singh Website Hack: February 2023

On February 27, Burger Singh’s website was hacked by the group ‘Team Insane PK,’ leading to a defacement incident fueled by a controversial promo code, ‘FPAK20.’ In an unexpected twist, Burger Singh decided to embrace the graffiti for a day, playfully calling it an “open mic night for hackers,” showcasing a unique response to the cyberattack.

21. WazirX Crypto Exchange Breach: Early 2024

In early 2024, WazirX, a prominent Indian cryptocurrency exchange, faced a significant data breach when one of its multisig wallets, managed by Liminal’s custody services, was compromised, resulting in the theft of over $230 million. Despite strong security measures, attackers exploited discrepancies in transaction data to gain unauthorized access. WazirX has since halted deposits and initiated recovery efforts for the stolen funds.

22. Multiple Cyberattacks on Indian Governments: 2024

The hacker group Transparent Tribe targeted critical sectors within India’s government and defense industries, using phishing emails to gain access to sensitive systems. The attacks were particularly focused on the Department of Defense Production, highlighting ongoing vulnerabilities within vital sectors.

23. BSNL Data Breach: May 2024

Bharat Sanchar Nigam Limited (BSNL) suffered a major data breach, exposing sensitive information of millions of users, including IMSI numbers and SIM card details. The attack, attributed to a hacker named ‘kiberphant0m,’ involved the theft of over 278 gigabytes of data, which was offered for sale on the dark web. The government has since formed an inter-ministerial committee to audit telecom networks and bolster security.

24. Hackers Targeting the Indian Energy Sector: Early 2024

In early 2024, an espionage campaign aimed at the Indian energy sector was uncovered, utilizing modified malware to collect sensitive data. The attackers exfiltrated 8.81GB of information, indicating a serious threat to the infrastructure of government and private energy companies, showcasing the importance of robust cybersecurity measures in critical sectors.

25. UP Marriage Assistance Scheme Fraud: 2024

A cyber fraud involving over Rs.1 crore occurred after hackers compromised the Uttar Pradesh Marriage Assistance Scheme website. By exploiting the ID of the Additional Labour Commissioner, unauthorized payments were made to ineligible candidates. Authorities have launched an investigation to recover the funds and prevent future breaches.

Lessons Learned from These Attacks

The cyber attacks that have plagued India serve as stark reminders of the vulnerabilities that exist within our digital infrastructure. Each incident has revealed critical lessons that organizations and individuals can apply to bolster their cybersecurity measures:

  1. Importance of Robust Security Protocols: Organizations must prioritize the implementation of strong security protocols, including firewalls, encryption, and intrusion detection systems. Regular updates and patches to software can help close vulnerabilities before they are exploited.
  2. Need for Comprehensive Employee Training: Human error remains a leading cause of data breaches. Regular training on cybersecurity awareness can empower employees to recognize phishing attempts and other malicious activities, reducing the likelihood of successful attacks.
  3. Data Backup and Recovery Plans: Incidents like the AIIMS attack demonstrate the necessity of maintaining reliable data backups. Organizations should ensure that backups are stored securely and can be easily accessed in case of a breach, minimizing downtime and data loss.
  4. Incident Response Preparedness: Having a well-defined incident response plan in place can significantly reduce the impact of a cyber attack. Organizations should regularly test and update these plans to adapt to evolving threats.
  5. Regular Security Audits: Continuous evaluation of security measures through regular audits can help identify weaknesses within an organization’s infrastructure. Proactive assessments allow for timely remediation before an attack occurs.
  6. Collaboration with Cybersecurity Experts: Engaging with cybersecurity firms and experts can provide organizations with advanced insights into emerging threats and effective defense strategies. Partnerships can enhance overall security posture and preparedness.
  7. Regulatory Compliance: Organizations must adhere to local and international cybersecurity regulations. Compliance not only mitigates risks but also builds trust with customers regarding the handling of their sensitive information.
  8. Public Awareness and Transparency: Transparency regarding data breaches fosters trust among stakeholders. Organizations should communicate openly about incidents, including the steps taken to address vulnerabilities and protect users’ data.

Recommendations for Enhanced Cybersecurity

To combat the growing threats posed by cyberattacks, organizations, particularly in critical sectors, must adopt a proactive approach to enhance their cybersecurity posture. Here are essential recommendations that Sattrix InfoSec advocates for bolstering security measures:

  1. Implement Robust Security Frameworks: Adopt comprehensive security frameworks like NIST or ISO 27001. These frameworks establish baseline practices that can significantly improve your security posture.
  2. Regular Security Audits: Conduct frequent security assessments and audits to identify vulnerabilities and ensure compliance with security policies. This practice not only helps in mitigating risks but also reinforces trust with stakeholders.
  3. Advanced Threat Detection: Utilize AI and machine learning tools for proactive threat detection and response. These technologies can help identify emerging cyber threats before they become critical issues.
  4. Incident Response Plan: Develop and regularly update an incident response plan. A well-structured plan ensures quick recovery and minimal disruption during a cyber incident, protecting your organization’s reputation.
  5. Employee Training Programs: Provide ongoing cybersecurity training for employees. By raising awareness about phishing attacks and safe online practices, organizations can empower their staff to be the first line of defense.
  6. Multi-Factor Authentication (MFA): Enforce MFA across all systems to add an additional layer of security. This reduces the likelihood of unauthorized access to sensitive information.
  7. Data Encryption: Ensure sensitive data is encrypted both at rest and in transit. This protective measure guards against unauthorized access and data breaches.
  8. Network Segmentation: Segment networks to limit access to critical systems. This strategy reduces the potential impact of a breach by confining access to sensitive data.
  9. Regular Software Updates: Keep all software and systems up to date with the latest security patches. Regular updates protect against known vulnerabilities that cybercriminals may exploit.
  10. Incident Reporting Mechanism: Establish a clear process for reporting cybersecurity incidents. Prompt reporting facilitates quick action and thorough analysis, improving response times.

Final Note

Cybersecurity is not just a technical issue; it’s a critical business imperative. The cyberattacks faced by various sectors in India serve as stark reminders of the vulnerabilities that exist. By adopting the recommendations discussed, organizations can take proactive steps to enhance their cybersecurity measures and protect against future threats.

FAQs

1.What are the top 5 cyber crimes in India?

The top five cyber crimes in India include:

  • Phishing
  • Ransomware Attacks
  • Identity Theft
  • Online Scams
  • Data Breaches

2.What is the most recent cyber attack in India?

The latest significant attack targeted WazirX in early 2024, resulting in the theft of over $230 million from its multisig wallet.

3.What is the biggest cyber attack ever?

The WannaCry ransomware attack in May 2017 is the largest, affecting hundreds of thousands of computers across 150 countries.

4.What rank is India in cyber attacks?

India is the third most targeted country for cyber attacks globally, following the US and China, with thousands of incidents occurring daily.

Footnote

Adm1nFr1end

ShopifyGUY

Share It Now: