1 hr ago
Cyberattack Cripples West Bengal Government Data Centre
Hackers attacked a computer centre that stores important West Bengal government information.
The harmful software may have stayed inside the system for five days before anyone found it.
Several government websites stopped working after the attack.
Investigators think information from several departments may have been copied or destroyed.
The information could include records about government programs, births and deaths, businesses, and money.
The government has not recovered the data so far.
At least 50 virtual computers were connected when the attack happened.
Experts are also asking why security systems did not identify the problem sooner.
An investigation is continuing.
A malware attack disrupted West Bengal government websites from September 13 after remaining active for five days.
Investigators fear data from at least four departments, including Finance, may have been stolen or destroyed.
Affected information may include government schemes, birth and death registrations, small-industry records, and financial transactions.
The main server remains nonfunctional, disrupting departmental websites and some backend government operations.
Authorities have not recovered the allegedly stolen data and are examining whether separate backups were compromised.
- Who
- Cybercriminals are suspected of attacking the West Bengal State Data Centre; government investigators and forensic experts are examining the incident.
- What
- A malware attack disrupted the main server, disabled multiple government websites, and may have stolen or destroyed data.
- Where
- The attack affected the West Bengal State Data Centre and connected departmental websites.
- When
- The attack reportedly began on September 9 and was detected on September 13; forensic investigators examined it the following day.
- Why
- Investigators suspect a professional cybercriminal group carried out the attack for a specific objective, but no motive has been confirmed.
Authorities and Investigators
Experts and Critics
Cause and scope
Authorities and Investigators
Investigators are examining a malware attack and suspect a professional cybercriminal group may have targeted the repository.
Experts and Critics
Cyber experts warn that a large volume of records, including beneficiary and financial information, may have been stolen or destroyed.
Security response
Authorities and Investigators
Authorities disconnected departmental servers and are checking whether separate backups were also compromised.
Experts and Critics
Experts question why layered safeguards and alerts from the Security Operations Centre did not identify the breach for five days.
Responsibility and preparedness
Authorities and Investigators
The investigation is ongoing, and the government has not yet issued a public statement confirming the full impact.
Experts and Critics
Critics have raised concerns about cybersecurity staffing, including the training and competence of contractual employees.
Key facts
- Attack period
- Malware was reportedly active from September 9 through September 13.
- Detection
- Staff reportedly discovered the breach on September 13, and a cyber-forensics team investigated it the following day.
- Affected websites
- Sites linked to Public Works, Housing, Municipal Affairs and Urban Development, and the State Police were reported unavailable.
- Potentially affected data
- Investigators are examining records involving government schemes, birth and death registrations, micro and small industries, and financial transactions.
- Systems exposed
- At least 50 virtual machines were active when the attack occurred.
- Data recovery
- The allegedly stolen information had not been recovered at the time of reporting.
- Finance systems
- Experts stated that the Finance Department’s internal systems remained unaffected, although data stored at the repository may be at risk.








