2 days ago
NIA Widens Probe Into DDoS Attacks on Government Websites
During Operation Sindoor, some people tried to make Indian government websites difficult to reach.
This kind of attack is called a Distributed Denial-of-Service attack, or DDoS.
The attackers sent large amounts of computer traffic toward websites.
Investigators say they used phones, online tools and a Telegram group called Anonsec.
An 18-year-old and a juvenile were identified in the Gujarat investigation.
The group claimed online that it had taken websites down.
However, investigators said the attackers did not have enough computer power to keep the websites offline for long.
India’s National Investigation Agency has now searched locations in five states and Delhi to find people who may have helped.
Officials said they found evidence of the attackers’ intentions but no specific link to Pakistan.
The National Investigation Agency searched five locations over alleged DDoS attacks on 54 Central government websites during Operation Sindoor.
Searches in Maharashtra, Gujarat, Telangana, Bihar and Delhi produced three laptops, five mobile phones, pen drives and documents.
Gujarat Anti-Terrorist Squad investigators linked 18-year-old Jasim Shahnawaz Ansari, a juvenile and the Telegram group Anonsec to the alleged activity.
The group allegedly used mobile-based tools, GitHub scripts and CheckHost.net while planning attacks on 20 websites on May 7, 2025.
Investigators said the attacks showed intent but lacked the computing power to cause sustained disruption, and found no specific conspiracy linking Pakistan to them.
- Who
- The National Investigation Agency, Gujarat Anti-Terrorist Squad, 18-year-old Jasim Shahnawaz Ansari, a juvenile and other alleged associates linked to the Anonsec Telegram group.
- What
- An investigation into attempted Distributed Denial-of-Service attacks against 54 Central government websites and more than 50 government and state-government websites.
- Where
- The targeted websites were Indian government sites; searches took place in Junnar, Nadiad, Ramagundam, Gopalganj and Delhi.
- When
- The alleged activity occurred mainly between March and May 2025, including May 7, 2025; searches were conducted on August 24, and the National Investigation Agency registered the case on June 25 of the previous year.
- Why
- Investigators said the alleged attacks were intended to disrupt government infrastructure, compromise national security and unity, and incite public fear.
Investigators’ Assessment
Attackers’ Online Claims
Extent of disruption
Investigators’ Assessment
The Gujarat Anti-Terrorist Squad said the mobile-phone-based setup lacked enough computing or server capacity to keep government websites offline for a sustained period.
Attackers’ Online Claims
The Telegram group posted messages claiming that Indian government websites, servers and a financial system had been taken down.
Nature of the activity
Investigators’ Assessment
Officials characterized the activity as attempted DDoS attacks rather than successful breaches, emphasizing that no data-access breach was established.
Attackers’ Online Claims
The group used temporary website inaccessibility, verified through CheckHost.net, as evidence that its attacks had succeeded.
Possible foreign involvement
Investigators’ Assessment
Gujarat Anti-Terrorist Squad SP K. Siddharth said investigators found no specific conspiracy linking Pakistan to the attacks.
Attackers’ Online Claims
The Telegram group included members from several nationalities, including Bangladesh and Palestine, but the articles do not establish a foreign government role.
Key facts
- Targeted websites
- 54 websites belonging to Central government entities, including critical computer resources and Critical Information Infrastructure.
- Main suspects identified
- Jasim Shahnawaz Ansari, 18, from Nadiad, and a juvenile.
- Telegram group
- Anonsec, which had previously operated through EXPLOITXSEC and ELITEXPLOIT.
- Alleged tools
- Termux, Pydroid3, DDoS scripts obtained from GitHub and CheckHost.net.
- May 7 activity
- The group allegedly planned attacks against 20 Indian government and state-government websites.
- Search recoveries
- Three laptops, five mobile phones, pen drives, other digital devices and documents were seized.
- Legal provisions
- The Gujarat Anti-Terrorist Squad initially registered the case under Sections 43 and 66(F) of the Information Technology Act.
Quotes
K. Siddharth
Gujarat ATS superintendent of police
“The material recovered from the accused's phones, including chats, screenshots and communications, established their intention to target Indian websites”
freepressjournal.in
thehansindia.com
“There was no specific conspiracy which we could figure out that Pakistan was behind this”
freepressjournal.in
thehansindia.com











