3 weeks ago
Hackers dodge digital nets as India faces cyberattack surge
India uses lots of computers, phones and internet services for money, health and government work.
Because so much happens online, bad people called hackers are trying to break into these systems more and more.
In 2023, India found about 11.46 lakh cyber problems, and by 2025 that number grew to 24.39 lakh.
Hackers have attacked big Indian companies like Bank of Baroda, Tata Electronics and the crypto exchange WazirX.
Some hackers use smart computer programs called AI to trick people or find weaknesses very quickly.
Experts studied attacks that stole data in just 72 minutes.
A data leak is very expensive, and IBM says one leak costs an Indian organisation about ₹25.5 crore on average.
To help protect people, the government now asks companies to be checked by outside security experts every year.
A new law, the Digital Personal Data Protection Act, says companies that leak data after May 13, 2027 could pay a fine of up to ₹250 crore.
Experts say India is getting better at cyber security but still has a long way to go.
India's detected cyber incidents rose from 11.46 lakh in 2023 to 18.73 lakh in 2024 and 24.39 lakh in 2025.
CERT-In logged more than 3.6 lakh cyber threats in banking and healthcare in the first six months of 2026, including 17 targeted intrusion campaigns against banks.
IBM's 2026 report says the record average cost of a data breach in India has reached ₹25.5 crore.
Recent attacks hit Bank of Baroda, Tata Electronics, Angel One, Niva Bupa Health Insurance and WazirX, exploiting employee credentials, cloud resources and digital assets.
Attackers moved from initial access to data exfiltration in as little as 72 minutes, and CERT-In now mandates annual third-party cybersecurity audits.
- Who
- Hackers and cybercriminals targeting India; CERT-In and other government agencies track incidents, while companies such as Bank of Baroda, Tata Electronics, Angel One, Niva Bupa Health Insurance and WazirX were attacked.
- What
- A sharp surge in cyberattacks and cybersecurity incidents across India's government, financial, healthcare and other key sectors.
- Where
- India
- When
- Incident counts cover 2023 to 2025 and the first six months of 2026, with data presented to Parliament in July 2026 and a government report in August 2026.
- Why
- India's rapid shift towards a connected digital economy, including cloud platforms, AI, digital payments and connected systems, has widened the attack surface for cybercriminals.
Official measures
Expert concerns
Mandatory cybersecurity audits
Official measures
CERT-In has mandated that private and public-sector organisations owning or operating digital systems undergo a comprehensive third-party cybersecurity audit at least once a year, with stricter recurring audits for regulated sectors.
Expert concerns
Sandeep Sengupta says most companies select auditors based on the lowest tender without checking competency, so security loopholes remain, and 'the best hackers today are more competent than the worst auditors.'
India's cyber security maturity
Official measures
Detection and monitoring have expanded, with Gartner expecting pre-emptive cybersecurity solutions to account for 50 per cent of IT security spending by 2030, compared with less than 5 per cent in 2024.
Expert concerns
Gartner analyst Apeksha Kaushik warns India's digital success story should not outpace security maturity, and Sengupta says India still has a long way to go in resilience and self-reliance in software and hardware.
Key facts
- Detected cyber incidents (2023)
- 11.46 lakh
- Detected cyber incidents (2024)
- 18.73 lakh
- Detected cyber incidents (2025)
- 24.39 lakh
- Banking & healthcare threats (H1 2026)
- 3.6 lakh+
- Targeted intrusion campaigns against banks (H1 2026)
- 17
- Record average data breach cost in India
- ₹25.5 crore (IBM 2026)
- Seqrite Labs detections (Oct 2024-May 2026)
- 156.3 million
- DPDP Act compliance deadline / maximum penalty
- May 13, 2027 / ₹250 crore
Quotes
Harish Kumar GS
CEO, Quick Heal Tech
“Between October 2024 and May 2026, Seqrite Labs, India’s largest malware analysis facility, recorded 156.3 million detections across more than 7.7 million endpoints, an average of 700,000-plus detections every day.”
telegraphindia.com
“In the fastest incidents we investigated within our 2026 Global Incident Response Report, attackers moved from initial access to data exfiltration in just 72 minutes, four times faster than the previous year.”
telegraphindia.com









