Cyber attacks in India continued to affect financial services, technology, manufacturing, healthcare, and cryptocurrency, and attacks against critical infrastructure in India continued in 2025-2026. Major ransomware attacks, credential theft, cloud breaches, data theft, and malicious attacks against companies such as Tata Technologies, Raymond, KiranaPro, Tata Electronics, and Bajaj Auto show how serious these attacks can be for any business.
The actual number of attacks is not the true measure. Recent Indian cyberattacks show how each attack can unfold differently. One company might suffer minor disruption, another might lose data, and another might discover sensitive files on the dark web.
Here are some of the biggest events that are known to be public or well documented in 2025 and 2026. If the threat actor’s impact has not been verified separately, this is documented rather than assumed to be true.
Major Cyber Attacks in India During 2025–2026

| Organization / Incident | Period | Attack / Incident Type | Reported Impact |
| Tata Technologies | Jan 2025 | Ransomware | Some IT assets affected |
| Raymond | Feb 2025 | Ransomware | Critical user data encrypted; brief disruption |
| Angel One | Feb 2025 | Cloud/Data Breach | Some AWS resources compromised |
| Niva Bupa | Feb 2025 | Data Security Incident | Unauthorized access/data leak investigated |
| Nippon India Mutual Fund | Apr 2025 | Cybersecurity Incident | Systems affected; response measures activated |
| Operation Sindoor Cyber Campaign | May 2025 | Coordinated Cyber Threats | Multiple attempted attacks against Indian targets |
| KiranaPro | May 2025 | Destructive Cyberattack | AWS/GitHub resources and data deleted |
| Delhi Hospitals | Jun 2025 | Cyberattacks | Hospital systems targeted |
| Tata Electronics | Jun 2026 | Data Breach | Systems affected; data appeared on dark web |
| Bajaj Auto | Jun 2026 | Ransomware | Company and subsidiary systems affected |
| Kudankulam-Related Exposure | Jul 2026 | Third-Party Data Exposure | Project-related files exposed |
| Bank of Baroda | Jul 2026 | Data Breach | Certain customer/internal data leaked |
1. Tata Technologies Ransomware Attack
- Date: January 31, 2025
- Sector: Engineering & Technology Services
- Attack Type: Ransomware
- Impact: Limited IT assets affected; some IT services temporarily suspended
- Business Operations: Client delivery services remained operational
According to Tata Technologies, ransomware attacked a couple of its IT assets. The company temporarily suspended some of its IT services as a precaution before reopening them. Client deliveries continued throughout. Tata Technologies sought expert advice to identify the cause and rectify the issues.
Security Takeaway: Network segmentation and business continuity plans are important, as this case illustrates. A customer-facing or operational system should not be taken down if it is the target of an attack on corporate IT systems. At Drona Cyber Solutions, our ransomware negotiation services have saved many businesses’ data and serve as a shield against cybercriminals.
2. Raymond Ransomware Incident
- Date: February 11–16, 2025
- Sector: Manufacturing & Consumer Business
- Attack Type: Ransomware / Credential Compromise
- Initial Access: Compromised local VPN credentials
- Impact: Critical user data encrypted and temporary operational disruption
Raymond reported that stolen credentials from a local VPN user let attackers into its network. A small proportion of operations were disrupted for a short period by the ransomware, but users’ critical data was encrypted. The company shut down impacted systems and brought in cybersecurity experts to contain, restore, and clean up.
Security Takeaway: Ransomware isn’t always introduced via malware that’s directly downloaded onto a network. Stolen remote access credentials could be the first step, which is why MFA, VPN monitoring, and privileged access controls remain crucial. To prevent such incidents, rely on Drona Cyber Solutions for quick ransomware response, leaving no room for attackers to damage business data or finances.
3. Angel One Cloud Security Breach
- Date: February 2025
- Sector: Stockbroking & Financial Services
- Attack Type: Cloud Resource Compromise / Data Exposure
- Environment Affected: Amazon Web Services resources
- Detection: Dark-web monitoring alert
- Customer Assets: Company said client funds, securities, and credentials were unaffected
Angel One said some AWS resources were compromised after its dark-web monitoring partner spotted a data-leakage post. The company reset the relevant cloud and application credentials and hired an external forensic specialist to dig into the incident.
This case stands out because the first warning came from outside the company’s own systems.
Security Takeaway: Internal monitoring alone does not cover everything. Dark web monitoring can flag stolen information, exposed credentials or breach claims that need immediate internal checks.
4. Niva Bupa Cybersecurity Incident
- Date: February 2025
- Sector: Health Insurance
- Attack Type: Unauthorized Access / Cyber Extortion
- Information at Risk: Customer-related information
- Response: Investigation and containment initiated
Niva Bupa has been hit by a cybersecurity breach when a threat actor called, claiming access to its customers’ information and demanding payment.
The difference matters: Companies confirmed the security incident occurred, but businesses shouldn’t assume all claims from extortion actors about stolen data are true.
Security Takeaway: These days, cyber extortion doesn’t always mean locking systems, it means stealing information. For businesses that handle sensitive customer data, it is important to have in place a data-loss monitoring solution, forensic analysis and a data-extortion response plan.
5. Nippon India Mutual Fund Cyberattack
- Date: April 9, 2025
- Sector: Asset Management / Financial Services
- Attack Type: Cyberattack on IT Infrastructure
- Impact: Affected systems shut down; online services experienced disruption
- Response: External cybersecurity specialists engaged
Late on April 9, a cyberattack was experienced by the IT infrastructure of Nippon Life India Asset Management, according to them. The business deactivated the affected systems while assessing the extent of the incident. Investor login services stayed offline for several days after the attack. (Nippon India Mutual Fund)
Security Takeaway: In financial services, keeping systems available is almost as important as keeping data private. Incident response plans need to cover customer access, communication, service continuity, and safe restoration.
6. Cyberattacks During Operation Sindoor
- Date: May 2025
- Sector: Government, Defence & Critical Infrastructure
- Attack Type: Coordinated Cyber Campaign
- Techniques Reported: DDoS, malware, website attacks and intrusion attempts
- Targets: Indian government and critical infrastructure environments
The military confrontation around Operation Sindoor brought a sharp rise in hostile cyber activity aimed at Indian digital infrastructure.
Unlike the company incidents in this list, this was not one successful breach. It was a wider cyber campaign with multiple threat actors, targets, and attack methods.
Security Takeaway: Cyber risk can escalate rapidly in a geopolitical event. Geopolitical threat intelligence should be integrated into security monitoring for critical infrastructure providers and companies in strategic industries. At Drona Cyber Solutions, our Malware Analysis Service team detects and eliminates harmful code and any segment that lets cyber criminals launch attacks on your business. Reach out before it’s too late.
7. KiranaPro Destructive Cyberattack
- Date: May 24–26, 2025
- Sector: E-commerce / Grocery Technology
- Attack Type: Destructive Cloud Attack
- Systems Affected: AWS and GitHub environments
- Impact: Servers and application data deleted; ordering functionality disrupted
KiranaPro took one of the most destructive cyber hits in India in 2025. Attackers got unauthorized access to the company’s AWS and GitHub accounts and wiped cloud resources, application code and servers that held customer information.
The application stayed reachable, but customers could no longer place orders.
This was not standard ransomware. The main damage came from destructive access to critical cloud infrastructure.
Security Takeaway: Cloud administrator accounts are high-value targets. Companies need MFA, limited admin privileges, backups that attackers cannot wipe with compromised production credentials, logging and recovery setups that stay out of reach.
8. Sant Parmanand Hospital Cyberattack
- Date: June 10–11, 2025
- Sector: Healthcare
- Location: Delhi
- Attack Type: Server Compromise
- Data at Risk: Patient, administrative, and financial information
- Investigation: Delhi Police registered a case
Servers at Sant Parmanand Hospital were hit during a cyberattack in June. Staff first thought it was a technical glitch before the investigation pointed to deliberate attack.
The incident was part of a wider problem hitting healthcare systems in north Delhi. (The Times of India)
Security Takeaway: Hospitals need fast anomaly detection because delays in telling an IT failure from a real attack can give attackers more time inside critical systems.
9. NKS Super Speciality Hospital Cyberattack
- Date: June 10–11, 2025
- Sector: Healthcare
- Location: Delhi
- Attack Type: Server Compromise
- Operational Impact: OPD and IPD operations disrupted
- Response: Hospital shifted affected activities to manual processes
NKS Super Specialty Hospital was also hit in the June attack. The disruption was severe enough that the hospital temporarily handed over some outpatient and inpatient work to manual processes, as systems remained offline. Police lodged an FIR, and cybersecurity experts were involved in the investigation.
Security Takeaway: Computer fixes are only part of healthcare incident response. Hospitals need a continuity plan in the event of a technology failure to ensure critical patient services continue.
Major Cyber Attacks in India in 2026
Cyber Attacks in India in 2026 were similar in scale but more focused on supply-chain data, manufacturing processes, ransomware, and third-party infrastructure.
11. Tata Electronics Data Breach
- Date: June 2026
- Sector: Electronics & Semiconductor Manufacturing
- Attack Type: Data Breach / Cyber Extortion
- Threat Actor: World Leaks claimed responsibility
- Claimed Data: More than 200,000 files, approximately 630 GB
- Operations: Tata Electronics said business operations were unaffected
Tata Electronics stated it suffered a cybersecurity attack on some of its systems.
World Leaks later posted a large dataset it said came from Tata Electronics. Samples suggested some files held commercially sensitive documents linked to companies in Tata Electronics’ wider business network.
Still, the confirmed breach and the threat actor’s claims need to be kept separate. Tata acknowledged the security incident, but that doesn’t necessarily mean everything the attackers alleged about the volume or contents of the stolen information was correct.
Manufacturers often have commercially confidential data owned by customers or suppliers. A breach can therefore turn into a supply-chain security problem even when production keeps running.
12. Bajaj Auto Ransomware Attack
- Date: June 23, 2026
- Sector: Automotive Manufacturing
- Attack Type: Ransomware
- Affected Organizations: Bajaj Auto and Bajaj Auto Technology Ltd
- Impact: Internal systems affected
- Response: Technical and cybersecurity teams activated
In a press release, Bajaj Auto has said that it and its wholly owned subsidiary, Bajaj Auto Technology Limited, were targeted by ransomware.
Cybersecurity experts and engineering teams quickly stepped in and mitigated the impact. At the time, no detailed information on possible data exposure had been published.
Security Takeaway: Connected subsidiaries can widen an organization’s attack surface. Cybersecurity monitoring and incident response therefore need to cover the whole enterprise rather than treating each business unit as a separate island.
13. Kudankulam-Related Third-Party Data Exposure
- Date: July 15, 2026
- Sector: Nuclear Energy / Critical Infrastructure
- Attack Type: Third-Party Data Breach
- Compromised Environment: Reliance Group data hosted on a Yotta server
- Claimed Leak: Approximately 19,000 files / 14.3 GB
- Core Nuclear Systems: No evidence they were compromised
World Leaks shared approximately 19,000 documents it alleged were connected to the Kudankulam Nuclear Power Plant project, including project documentation, suppliers, inspection material, and alleged blueprints.
The technical difference is important.
The nuclear power plant itself was not reported as breached. Reliance Group, a contractor working on Units 3 and 4, confirmed a partial breach of its data stored on a third-party server hosted by Yotta.
CERT-In and the Nuclear Power Corporation of India looked into the incident.
Security Takeaway: Critical infrastructure security reaches beyond operational technology. Contractors, engineering partners, cloud providers and data-center vendors can hold information that creates risk even without direct access to operational control systems.
14. Bank of Baroda Data Exposure
- Date: July 2026
- Sector: Banking & Financial Services
- Attack Type: Unauthorized Data Access / Account Compromise
- Initial Compromise: Employee email account
- Data Reported: Customer and internal banking documents
- Core Banking Systems: Reported as unaffected
Bank of Baroda investigated unauthorized data access after an employee email account was compromised. Customer-related and internal information later appeared online.
The incident stands out because the reported entry point was not the bank’s core banking systems. A compromised employee account was enough to create a serious data security problem.
Security Takeaway: Protecting high-value infrastructure is not enough if attackers can reach sensitive documents through email, collaboration tools, or ordinary employee accounts.
What Do These Cyber Attacks Reveal About India?
These cyberattack case studies in India show there is no single attack pattern businesses can prepare for.
Ransomware hit organizations such as Tata Technologies, Raymond and Bajaj Auto. Cloud and account compromises hit companies such as Angel One. KiranaPro faced destructive deletion, while Bank of Baroda dealt with unauthorized data access after an email account compromise.
Three broader patterns stand out.
Credentials Remain a Major Weak Point
Several incidents show how compromised accounts can give attackers access without needing a highly advanced technical exploit. Strong authentication and access management therefore stay fundamental.
Data Theft Can Be as Damaging as Encryption
Modern attackers increasingly steal information instead of, or before, locking systems. This makes dark web monitoring, threat intelligence and digital forensic investigation more important alongside traditional ransomware protection.
Third-Party Risk Cannot Be Ignored
Businesses increasingly rely on cloud providers, contractors, technology partners and linked supply chains. Security therefore needs to reach beyond systems the organization directly controls.
How Hiring Drona Cyber Solutions Helps Businesses Prevent and Respond to Cyber Attacks?
Preventing every cyberattack is unrealistic, but businesses can significantly reduce their exposure, detect threats earlier, and limit damage when an incident occurs. Choosing an experienced cyber security company gives organizations access to continuous monitoring, threat intelligence, specialist investigation, and incident response capabilities that are difficult to maintain through basic security tools alone.
Drona Cyber Solutions provides an integrated cybersecurity approach designed to protect businesses before, during, and after an attack.
24/7 Threat Detection with Managed SOC
Drona Cyber Solutions’ Managed SOC Services continuously monitor networks, endpoints, logs, and security events for suspicious activity. Instead of waiting for ransomware or unauthorized access to become obvious, security teams can identify warning signs, investigate alerts, and respond to potential threats earlier.
Ransomware Protection and Response
Ransomware requires both preparation and rapid action. Drona supports organizations with Ransomware Response Services, helping contain affected systems, investigate the attack path, understand the scope of compromise, and support secure recovery. Incident findings can also be used to strengthen controls against future ransomware attempts.
Digital Forensics and Incident Response
When suspicious activity is discovered, knowing exactly what happened is critical. Drona’s Digital Forensics Services and Incident Response Services help businesses preserve evidence, reconstruct attack timelines, identify compromised systems, investigate entry points, contain active threats, and determine whether unauthorized access remains.
Dark Web Monitoring for Exposed Data
Not every threat is visible inside the corporate network. Credentials, confidential documents, employee information, and company data can appear on underground forums or marketplaces following a breach. Drona’s Dark Web Monitoring Services help identify such exposure so businesses can take corrective action before compromised information is exploited further.
Threat Intelligence for Proactive Security
Drona’s Threat Intelligence Services help organizations understand emerging ransomware groups, malicious infrastructure, attack campaigns, and threats relevant to their industry. This intelligence gives security teams additional context to prioritize risks and strengthen defenses before known threats reach critical systems.
Takedown Services for External Cyber Threats
Fake domains, phishing websites, fraudulent social profiles, and brand impersonation can deceive customers and employees. Drona’s Takedown Services help identify and act against malicious online assets, extending cybersecurity protection beyond an organization’s internal infrastructure.
Complete Cybersecurity Under One Partner
The biggest advantage of working with Drona Cyber Solutions is that these capabilities are not treated as disconnected services. Managed SOC, Ransomware Response, Digital Forensics, Incident Response, Dark Web Monitoring, Threat Intelligence, Takedown Services, malware analysis, VAPT, and broader cybersecurity services can work together as part of a coordinated security strategy.
For businesses evaluating a cyber security company in India, Drona Cyber Solutions provides both proactive protection and specialist incident capabilities. The objective is not to make an unrealistic promise that cyberattacks will never happen. It is to reduce attack opportunities, detect suspicious activity sooner, contain incidents faster, investigate them accurately, and help businesses recover securely when an attack does occur.
Conclusion
The cyber attacks in India during 2025 and 2026 hit organizations across technology, finance, healthcare, manufacturing, cryptocurrency and critical infrastructure.
More importantly, the incidents were not the same. Some involved ransomware; others compromised credentials, cloud resources, data, or caused destructive activity. That makes relying on one security control unrealistic.
Indian businesses need continuous monitoring, stronger identity protection, tested backups, threat intelligence, and a clear incident response plan. When an attack does happen, digital forensic investigation becomes critical for understanding its real scope and root cause.
With Drona Cyber Solutions, organizations can build a more comprehensive cybersecurity approach that covers 24/7 monitoring, ransomware preparedness, cyber incident response, digital forensics, dark web monitoring, and threat intelligence, helping them move from reactive cybersecurity to stronger cyber resilience. Report an Incident today and uncover all the details at Drona Cyber Solutions to protect your business even from lethal cybercriminal groups.