The digital revolution has transformed how we communicate, work, and live. But this transformation has a darker side. As India accelerates its digital adoption, cybersecurity threats have evolved into sophisticated attacks that compromise individual privacy, disrupt critical infrastructure, and challenge national security. Understanding these security challenges is essential for anyone navigating today’s interconnected world.
Table of Contents
The rising tide of cyber threats in India
India’s rapidly digitized critical infrastructure sectors, from finance to government systems and from manufacturing to healthcare, now face increased cyberattacks and cyber threats . The numbers paint a sobering picture. Cyber incidents against finance handled by the national CERT team jumped to some 16 million incidents in 2023, up from 53,000 in 2017 , according to the Reserve Bank of India’s recent report.
This surge is not random. Cyberattacks on banks and financial firms more than doubled in 2024, with attacks manifesting as large ransomware strikes and sophisticated frauds like Business Email Compromise . The healthcare sector has also become a prime target, with 21% of all reported cyber incidents in India in 2024 targeting healthcare , exploiting outdated technology and limited security budgets.
Hacking and unauthorized access
Hacking remains one of the most prevalent cyber threats. In early March 2024, researchers uncovered a cyber-espionage campaign targeting Indian government agencies and the country’s energy sector, employing a modified information stealer designed to collect browser login credentials, cookies, and history . The attackers successfully exfiltrated sensitive data including internal documents, private emails, and confidential information from both government and private energy companies.
Pakistan-backed Advanced Persistent Threat groups and regional hacktivist organizations have been linked to malware campaigns disseminated via social media platforms , posing significant risks to data security across civilian and official sectors. These sophisticated attacks often exploit weak API security, outdated systems, and unpatched software vulnerabilities.
Cyberstalking and online harassment
The anonymity of the internet has given rise to cyberstalking, a form of harassment that can have devastating psychological impacts on victims. According to data from the Jaipur Cyber Support Centre, cases of online abuse have risen sharply in recent years, with nearly 30% of reported victims being women .
After the Delhi Gang Rape case in 2012, the Indian Penal Code was amended by the Criminal Law (Amendment) Act, 2013 that added Section 354D to the IPC, which provides stalking laws in India and lays down the punishment for committing the crime of stalking . The Bharatiya Nyaya Sanhita (BNS), which replaces the IPC, retains and updates provisions related to cyberstalking, with Section 77(1) defining and penalizing stalking in both physical and electronic forms.
Cyberstalkers employ multiple tactics including repeated unwanted messages, identity theft, impersonation through fake profiles, doxxing, and posting obscene content on social media platforms. The legal framework now recognizes these acts as serious offenses warranting criminal prosecution.
Child sexual exploitation material
Among the most disturbing cyber threats is the creation, distribution, and consumption of child sexual exploitation and abuse material. In September 2024, the Supreme Court of India delivered a landmark judgment clarifying that mere possession of child pornography, unless deleted, destroyed, or reported by the accused, is an offense under the POCSO Act .
The Protection of Children from Sexual Offences (POCSO) Act provides comprehensive protection. Section 15(1) of the POCSO Act states that any person who stores or possesses child pornography and fails to delete, destroy, or report it can be punished with a fine of up to โน5,000 . The Supreme Court also recommended replacing the term with “Child Sexual Exploitative and Abuse Material” to better reflect the gravity of these crimes.
The Act is gender-neutral, both for children and for the accused, and criminalizes watching or collection of pornographic content involving children . Social media intermediaries and online platforms now have mandatory reporting obligations under the law.
Denial of service attacks
Distributed Denial of Service attacks have emerged as a powerful weapon for disrupting critical infrastructure. According to CERT-In observations, hacktivist groups have used DDoS to attack websites and ICT infrastructure in India and other countries, leveraging various open-source, widely available utilities to conduct attacks at different network layers .
The impact can be severe. The average cost of a DDoS attack in India was estimated at โน1.1 crore in 2023, factoring in lost sales, overtime pay, and recovery efforts . Following the Pahalgam terrorist attack, India faced over 10 million intrusion attempts, consisting of a mix of DDoS floods, website defacements, phishing campaigns, and exploit attempts targeting the public, critical infrastructure, and defence portals .
These attacks work by overwhelming a target’s network or server with massive amounts of fake traffic, rendering services unavailable to legitimate users. A DDoS attack is a malicious attempt to disrupt the normal traffic of a targeted server, service or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic , utilizing multiple compromised computer systems as sources of attack traffic.
Malware dissemination and ransomware
Malicious software continues to evolve in sophistication and impact. In 2024, major Indian companies including Polycab, boAt, and Angel One suffered ransomware attacks and data breaches . The boAt breach alone compromised data of 7.5 million customers, with information accessible on the dark web for minimal amounts.
The LockBit ransomware group targeted domestic brokerage firms, threatening to release stolen data unless a ransom was paid, reflecting the increasing targeting of financial institutions where stakes are higher due to sensitive customer data and financial transactions . State-owned telecommunications giant BSNL also suffered a data breach, with attackers accessing confidential information including IMSI numbers and SIM card details.
The broader implications
These security challenges extend far beyond individual victims. Indian organizations are most concerned about cloud-related threats, attacks on connected devices, hack and leak operations, and software supply chain compromises . The adoption of emerging technologies like artificial intelligence and increased interconnectivity between IT and operational technology environments have created new attack surfaces.
The threat landscape highlights the urgent need for advanced, integrated, and proactive cybersecurity strategies, with organizations needing to invest in threat intelligence, adopt comprehensive frameworks, and implement robust protection measures . However, technology alone cannot solve the problem.
Human error still drives a significant percentage of breaches through phishing, credential theft, and misconfigurations. Security awareness training, role-based access controls, and regular security assessments are just as critical as technical defenses. Organizations must build a security culture where every employee understands their role in protecting digital assets.
Moving forward
Addressing these multifaceted security challenges requires coordinated efforts across multiple stakeholders. The Indian Computer Emergency Response Team has issued comprehensive advisories outlining preventive measures for web intrusion attacks, DDoS attacks, and malware attacks. Law enforcement agencies have established dedicated cyber crime cells to investigate and prosecute offenders.
But the responsibility extends to individuals as well. Practicing good cyber hygiene, maintaining updated software, using strong authentication, and reporting suspicious activities can significantly reduce vulnerability to attacks. Educational institutions and workplaces must prioritize cybersecurity awareness programs to equip people with the knowledge to recognize and respond to threats.
The digital age has brought unprecedented opportunities, but it has also introduced complex security challenges that threaten privacy, economic stability, and national security. Only through vigilance, collaboration, and continuous adaptation can we build a safer cyberspace for everyone.
What do you think? How can India strengthen its cybersecurity posture to protect critical infrastructure while balancing innovation and digital growth? What role should individuals play in creating a more secure digital ecosystem?
Leave a Reply