India entered 2026 with cyber risk already operating at an enormous scale. In 2025 alone, CERT-In handled 29,44,248 cyber security incidents. That figure covers incidents reported to and tracked by the agency, so it should not be read as 29.44 lakh confirmed data breaches.
What makes Cyber Attacks in India worth watching now is not just the volume. Attackers are finding more ways to get inside organisations, from stolen credentials and ransomware to compromised suppliers, malicious messages, espionage activity, and misuse of trusted cloud services.
Some 2026 incidents are fully confirmed. Others come from security researchers or claims made by threat groups. We will keep those distinctions clear.
Ahead, we look at the attacks that matter, what they reveal about current threats, and what you can do before the next incident reaches your business.
Recent Cyber Attacks in India 2026: Quick Overview
| Incident | Date | Sector | Attack Type | Confirmed Impact | Data Exposure | Verification |
| Tata Electronics | June 2026 | Manufacturing | Cyber incident | Some systems affected | Large leak claimed | Incident confirmed, leak claim unverified |
| Bajaj Auto | June 23, 2026 | Automotive | Ransomware | Some systems affected | Not confirmed | Confirmed by company |
| Bank of Baroda | July 2026 | Banking | Account compromise | Certain data accessed | Scope under review | Confirmed by bank |
| Kudankulam contractor | July 2026 | Critical infrastructure | Third party breach | Project files exposed | Nuclear systems not shown as affected | Contractor breach confirmed |
| Mustang Panda | May to June 2026 | Government | Cyber espionage | Systems compromised | Espionage activity reported | Researcher attributed |
| WhatsApp campaign | June 2026 | Cross sector | Malware | Malicious attachments spread | No single breach dataset | CERT-In confirmed campaign |
Major Cyber Attacks in India in 2026

1. Tata Electronics Cyberattack and World Leaks Data Claims
Tata Electronics confirmed a cybersecurity incident in June 2026 that affected some of its systems. The company said its operations remained unaffected. World Leaks later claimed responsibility and published more than 200,000 files totalling over 630 GB. Reuters reviewed portions of the material and found documents apparently connected to Apple and Tesla, including manufacturing specifications, engineering information, supplier records, emails, logs, and employee documents.
Further reporting found files linked to unreleased Apple products, component supplier information, and confidential engineering material. Following the incident, Tata Electronics restricted access to critical systems and brought in an external consulting firm to support the forensic investigation.
| Detail | Information |
| Date | June 2026 |
| Sector | Electronics manufacturing |
| Attack | Cyber intrusion and data extortion |
| Threat group | World Leaks |
| Claimed leak | 200,000 plus files, over 630 GB |
| Operational impact | No reported disruption |
| Verification | Incident confirmed by Tata. Full leak scope remains unverified |
The breach shows how one compromised supplier can expose information belonging to several companies at once. Tata Electronics works with major technology and automotive companies, which means its systems can contain:
- Customer designs
- Production documents
- Supplier information
- Quality records
- Intellectual property
- Internal communications.
This creates a wider supply chain blast radius. Attackers may reach sensitive information about several businesses without compromising each company separately.
Security Measures Businesses Should Review
- Limit supplier access to the systems and files required for a specific project.
- Separate customer and project data so one compromised account cannot reach unrelated information.
- Apply least privilege to employees, contractors, and external partners.
- Monitor unusual downloads, bulk file transfers, and access to sensitive repositories.
- Review third-party security controls before sharing confidential information.
- Remove customer files when there is no business or regulatory reason to retain them.
- Test supplier-facing applications and access paths for exploitable weaknesses.
2. Bajaj Auto Ransomware Attack
Bajaj Auto reported a cybersecurity incident to the stock exchange on June 23, 2026. The disclosure identified ransomware and said systems belonging to Bajaj Auto Limited and Bajaj Auto Technology Limited, its wholly owned technology subsidiary, were affected. NSE recorded the filing on the same date.
The company brought in cybersecurity specialists and started containment and recovery work. A later update said manufacturing, sales, service, dealer support, customer services, and other major functions were operating normally.
There is no public confirmation that customer data was stolen. Bajaj Auto confirmed ransomware, but the disclosures available so far do not establish data theft.
The part companies with subsidiaries should pay attention to
Two related companies were involved in the same incident. That makes shared technology and access between group companies worth a closer look.
Parent companies and subsidiaries often connect through:
- Administrator accounts
- Shared applications
- Cloud services
- Network access
- Backup systems
- Security monitoring
A compromise can travel further when those connections carry more access than they need.
Worth checking: Can an administrator or service account used in one group company reach systems in another? If the answer is yes, that access needs a clear business reason, tighter privileges, monitoring, and segmentation.
3. Bank of Baroda Cyber Incident
Bank of Baroda confirmed in July 2026 that an employee email account had been compromised and used to access certain data without authorisation. The bank said it contained the incident, started a forensic investigation, and informed the relevant authorities. Its core banking systems were not accessed and remained secure.
Separately, a threat actor claimed to have released a much larger collection of Bank of Baroda data online. Reports mentioned more than 700 GB, while other claims placed the figure close to 1 TB. Those numbers have not been confirmed by the bank, so they should remain separate from the facts the bank has acknowledged.
One mailbox can open more doors than expected
An employee email account rarely contains only messages. Depending on the user’s permissions, it may lead to attachments, shared drives, cloud folders, collaboration tools, customer correspondence, and internal documents.
That is why identity attacks deserve as much attention as network attacks. Stolen credentials, session tokens, cloud IAM access, and OAuth permissions can let an attacker enter through a legitimate account rather than forcing their way through the perimeter.
For security teams, the controls worth reviewing include:
- MFA across employee accounts
- Phishing-resistant authentication for privileged users
- Conditional access based on device, location, and login risk
- Alerts for unusual sign-ins and session behaviour
- Rapid revocation of stolen sessions and tokens
- Tighter limits on what a single account can access
Among the biggest cyber attacks in india, this case stands out because the bank said its core banking environment remained secure while data was still accessed through an employee identity. That makes account access itself part of the attack surface, not just the systems sitting behind it.
4. Kudankulam Related Third Party Data Exposure
In July 2026, files linked to the Kudankulam Nuclear Power Project in Tamil Nadu appeared online after a breach involving Reliance Infrastructure-related data.
Reliance Group confirmed a partial breach on a server hosted by Yotta. Reuters found about 19,000 Kudankulam-related files in the leaked material, totalling 14.3 GB. The documents reportedly included engineering drawings, supplier lists, meeting notes, insurance records, and infrastructure details for Units 3 and 4.
| What was affected | What was not shown as compromised |
| Contractor-related project data | Reactor controls |
| Engineering and infrastructure files | Nuclear safety systems |
| Supplier and project records | Nuclear security systems |
| Data stored on third-party infrastructure | Operational plant controls |
NPCIL clarified that the leaked information concerned conventional Balance of Plant facilities. It did not relate to nuclear safety or nuclear security systems.
The concern here is the information around the plant. Engineering drawings, supplier details, and infrastructure records can still reveal useful information about equipment, support systems, and project dependencies.
The data also sat several steps away from NPCIL itself. It involved a contractor, a hosting provider, and project information tied to critical infrastructure. For organisations in energy and other sensitive sectors, third-party storage and contractor systems need the same level of scrutiny as internal repositories.
5. Mustang Panda Campaign Targeting Government and Hydropower Organisations
In May and June 2026, attackers used hydropower and government-themed files to infect systems linked to Indian government entities. Acronis later found active communication from multiple compromised government devices, including systems associated with senior administrative personnel. The researchers linked the activity to Mustang Panda with high confidence.
The attacks began with compressed spear phishing files. Once a victim opened them, a legitimate signed program was abused to load a malicious DLL. That launched SHARDLOADER, which then installed either MINIRECON or ZOHOMURK.
Zoho WorkDrive was used to hide attacker traffic
ZOHOMURK connected to Zoho WorkDrive to receive commands, send results back, and upload stolen information. It authenticated through Zoho OAuth and communicated through normal WorkDrive APIs.
That kind of traffic can be easy to miss because the destination itself is legitimate.
Security teams need to watch for:
- Unusual OAuth activity
- Unexpected cloud integrations
- Abnormal SaaS uploads
- Excessive API calls
- Unfamiliar token use
- Logins from unusual locations
- Unapproved cloud services
This campaign was focused on espionage rather than quick financial gain. Acronis assessed that the attackers were collecting intelligence linked to India’s hydropower initiatives and government cooperation with Taiwan.
6. CERT-In WhatsApp Malware Campaign
On June 25, 2026, CERT-In warned WhatsApp Desktop and Web users about a malware campaign spreading through compromised accounts. Attackers were sending .vbs files to people already saved in the victim’s contacts.
The files were dressed up as documents people regularly exchange at work, such as invoices, payment records, bank statements, and account statements. Once opened on a Windows device, the script downloaded more files and installed remote management software, giving the attacker remote access to the system.
The real advantage for the attacker was the sender. A file arriving from a colleague, vendor, customer, or friend is far less likely to raise suspicion than the same attachment from an unknown number.
For businesses that use WhatsApp every day, a few habits matter:
- Confirm unexpected documents with the sender before opening them
- Treat .vbs, .exe, .bat, .cmd, .js, and similar executable files with caution
- Keep WhatsApp, browsers, Windows, and endpoint security software updated
- Review linked WhatsApp devices and remove anything unfamiliar
- Enable two-step verification on business accounts
CERT-In also warned that a successful infection could lead to credential theft, data exfiltration, more malware being installed, and movement into other systems on the same network.
A trusted contact can still send a malicious file if their account has already been taken over.
What Recent Cyber Attacks in India Reveal About 2026
The six incidents above show that attackers do not always need to breach the main organisation directly. Suppliers, contractors, employee accounts, and trusted cloud services can provide another route to valuable systems and data.
Supply Chain and Third Party Exposure
Tata Electronics reportedly held sensitive information connected to several customers, while the Kudankulam case involved project files stored through a contractor and third-party hosting provider. Both incidents show how much business data can sit outside the company that originally owns it.
A supplier may store customer IP, engineering files, credentials, personal data, infrastructure records, or confidential project documents. If that supplier is breached, the blast radius can extend across several organisations.
Vendor assessments should therefore check:
- Which systems the supplier can access
- What sensitive information it stores
- How long that information is retained
- Whether access is limited to what the supplier actually needs
A vendor with little system access can still create serious exposure if it holds years of confidential data.
Ransomware Is Increasingly an Extortion Problem
Ransomware is not always just about locked files anymore. Attackers may steal data first, encrypt systems later, and then threaten to publish the stolen files if the company refuses to pay. CISA refers to this as double extortion.
Backups can help a company restore encrypted systems. They cannot undo a data leak. Once attackers have copied sensitive files, the company may still have to deal with exposure of customer data, internal documents, credentials, or other confidential information.
Identity Has Become a Primary Attack Surface
The Bank of Baroda incident started with a compromised employee email account. The bank said its core banking systems were not accessed, yet certain data was still reached through that identity.
That is the risk with modern identity-based attacks. An attacker may go after:
- Passwords
- Session tokens
- API keys
- VPN credentials
- Privileged accounts
- Oauth tokens
Once one of these is stolen, the attacker may be able to open email, cloud storage, SaaS tools, shared files, or internal applications without touching the main transaction system.
Microsoft also warns that stolen session tokens can let attackers reuse an already authenticated session and reach sensitive data without signing in again.
Trusted Cloud Platforms Can Hide Malicious Activity
Mustang Panda used Zoho WorkDrive to receive commands and move stolen data during its 2026 campaign against Indian targets. Because the traffic went through a legitimate SaaS platform, it could blend in with normal business activity. Acronis also found that the malware used Zoho OAuth credentials and WorkDrive APIs for communication.
Security teams need to look beyond the domain name and check how cloud services are being used. OAuth activity, sudden file transfers, unusual API use, unfamiliar apps, and unexpected access patterns can point to abuse. SaaS telemetry, anomaly detection, data loss prevention, and better cloud visibility can help spot activity that would otherwise look ordinary.
AI Is Speeding Up Technical and Social Attacks
AI is being used in 2 very different parts of cybercrime. One is technical. The other is aimed at people.
Technical Attacks
CERT-In issued a high-severity advisory in April 2026 warning that advanced AI systems can help attackers work through technical tasks much faster. Reported capabilities include:
- Scanning internet-facing systems
- Analysing large amounts of source code
- Finding known and previously unknown vulnerabilities
- Speeding up exploit development
- Probing APIs and cloud services
- Planning attacks that involve several stages
This can leave security teams with less time to patch an exposed weakness once attackers know about it.
Social Engineering
AI can also make scams harder to spot. Attackers can produce convincing phishing messages in several languages, clone voices, create fake videos, impersonate executives, or pose as customer support staff.
The two problems need different responses. Technical attacks call for faster patching and better API security. Social engineering needs stronger identity checks and staff awareness for payments or other sensitive requests.
Cyber Espionage and Critical Infrastructure Risk
India faces ransomware and DDoS attacks. Hacktivism and espionage add risk too. Mustang Panda’s 2026 campaign showed why sensitive sectors need separation between IT and engineering and operational systems.

How Common Are Cyber Attacks in India?
Seqrite recorded more than 156.3 million malware detections across over 7.7 million protected endpoints between October 2025 and May 2026. March 2026 had the highest detection volume during that period.
The same report recorded:
- 888 plus ransomware incidents
- 421,000 plus ransomware detections
- More than 700,000 detections a day on average
These are detection numbers, not confirmed breach numbers. One device can trigger several alerts, and many attacks may be blocked before anyone gets into the system.
So the figures show how much malicious activity companies are dealing with. They do not mean that every detection became a successful attack.
How Businesses Can Protect Against Cyber Attacks in India
Secure Identity and Privileged Access
A stolen account can be enough to expose email, cloud apps, VPN access, or admin tools. Keep access tight:
- Require MFA across critical systems
- Use phishing-resistant MFA for privileged users
- Remove unused accounts
- Limit admin rights
- Revoke active sessions after suspicious activity
- Block risky sign-ins with conditional access
Prioritise Internet-Facing Vulnerabilities
Know exactly what your organisation exposes to the internet. Start with VPNs and firewalls. Then check remote access tools, web apps, APIs, cloud workloads, identity systems, and admin panels.
Segment High Value Systems
Do not let one compromised account open the door to everything else. Keep corporate IT separate from privileged admin systems. Production and operational technology should sit behind tighter controls. Backups, development environments, vendor access, and subsidiary networks also need clear boundaries.
Good segmentation limits how far an attacker can move after the first compromise.
Maintain Recoverable and Isolated Backups
Keep three copies of critical data across two types of storage, with one copy kept elsewhere. Protect at least one backup offline or with immutability.
Use separate credentials for backup systems. Test full restores regularly. A backup that has never been restored successfully should not be treated as a reliable recovery option.
Reduce Third Party Blast Radius
Tata Electronics and the Kudankulam-related exposure showed how much sensitive information can sit with suppliers and contractors.
Before giving a vendor access, check:
- What customer or partner data it keeps
- Who holds privileged credentials
- Whether subcontractors are involved
- How activity is logged
- How long data is retained
- What network connections exist
- When incidents must be reported
- Whether recent security testing exists
Cyber Incident Reporting and Data Protection Rules Indian Businesses Should Know
CERT-In Six-Hour Cyber Incident Reporting Requirement
For certain cyber incidents, companies cannot wait until the investigation is finished before reporting them. CERT-In requires service providers, intermediaries, data centres, body corporates, and government organisations to report listed incidents within six hours of noticing them or being informed about them.
The list covers incidents such as ransomware, unauthorised access, data breaches, data leaks, serious intrusions, DDoS attacks, and attacks affecting cloud or critical systems.
CERT-In also makes one point clear in its FAQ. If all the details are not available within six hours, the organisation can send what it knows at that time and provide the remaining information later.
That means the reporting process should already have a clear owner. Companies also need a designated CERT-In point of contact and an internal route for getting the first report approved quickly.
DPDP Act and DPDP Rules Timeline in 2026
The Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025, but the rules do not all start on the same date. Rules 3 and 5 through 16 begin 18 months after publication.
That places their commencement on May 13, 2027.
Rule 7 sits in that later group. It covers personal data breach notices to affected individuals and the Data Protection Board. The rule sets out what those notices must contain and requires further details to reach the Board within 72 hours once the rule is in force.
So, as of September 2026, those later DPDP breach notification duties are not yet operational. CERT-In’s six-hour cyber incident reporting rule is already active and should be treated separately.
How Qualysec Helps Businesses Identify Security Weaknesses Before Attackers Do
Many breaches start with weaknesses that already exist inside an application, API, cloud setup, or external network.
Qualysec specialises in advanced penetration testing and tests areas such as:
- Web applications
- Mobile applications
- APIs
- Cloud environments
- External networks
- IoT devices
- AI applications
Its testing combines automated techniques with manual analysis. The assessment can cover authentication, business logic, technical vulnerabilities, and attack paths that automated scanners may miss.
The report gives technical teams confirmed findings, risk details, and practical remediation guidance. Qualysec also offers retesting to check whether fixes have worked.
Penetration testing can support your existing patching, monitoring, and vulnerability management by finding exploitable weaknesses before attackers use them.
You can review Qualysec’s sample report or speak with the security team about a penetration testing engagement.
Conclusion
The 2026 incidents make one point clear. A serious breach does not always begin with an obvious attack on a core system. Access can come through an employee account, a supplier, an exposed service, or software people already trust.
Companies also need to separate confirmed facts from claims made by attackers when judging the real impact of an incident.
The next challenge is speed. CERT-In warns that AI can make reconnaissance and vulnerability discovery much faster. Businesses that find exposed systems early and fix weak controls before they are exploited will be in a stronger position.
FAQs
What is a supply chain cyberattack?
A supply chain cyberattack starts with a trusted third party rather than the main target. Attackers may breach a supplier or contractor first. From there, they can reach customer data, shared systems, credentials, or other connected organisations.
How can businesses protect themselves from ransomware?
Start with identity controls and fast patching. Keep critical systems segmented. Use EDR and protected backups, then test recovery regularly. Good monitoring and a rehearsed incident response plan help contain ransomware before it spreads further.
What should I do if my personal data is leaked?
If your personal data is leaked, change affected passwords and turn on MFA. Sign out active sessions. Watch your bank accounts for unusual activity and expect phishing attempts. Report any misuse to the service involved or relevant authority.
How quickly must a cyber incident be reported to CERT-In?
Incidents covered by CERT-In directions must be reported within six hours of noticing them or being informed about them. If all details are not ready, organisations can send the available information first and add more later.
Can malware spread through WhatsApp?
Yes. CERT-In warned in June 2026 that compromised WhatsApp accounts were sending malicious VBScript files to existing contacts. The campaign targeted Desktop and Web users, with malware installed after a recipient opened the attachment.
How can penetration testing help prevent cyber attacks?
Penetration testing uses real attacker techniques to find weaknesses that can be exploited. Testing can cover applications, APIs, cloud environments, networks, infrastructure, and other agreed systems, giving teams clear issues to fix before criminals find them.







