ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

India's defence ministry says no evidence of active cyberattack after reports of DRDO data breach

India’s Ministry of Defence has pushed back on media reports of a major data breach at the Defence Research and Development Organisation, saying the material in question is outdated and unverifiable.

Linked InXFacebook
bookmark_borderSave to Library

India’s Ministry of Defence said an investigation has found no evidence of an active cyberattack, unauthorized network intrusion or ongoing data exfiltration involving the Defence Research and Development Organisation (DRDO), disputing media reports that described a significant breach at the agency.

 

DRDO, which operates under the Ministry of Defence and is responsible for developing advanced defense technologies and military systems, had been the subject of reports earlier in the week alleging that a threat actor was attempting to sell a large volume of stolen data on the dark web.


The reports had described roughly 31 gigabytes of data offered for sale for $8,000, with sample files said to include details of the internal electronics architecture of an advanced guidance sensor used in precision-guided missiles and smart munitions. The ministry said in a statement that reports of the alleged incident carried by some media outlets were incorrect and unverified.


According to the ministry, the bulk of the material alleged to have been leaked is unclassified and carries no confidentiality. Officials said some of the unclassified data being characterized as critical actually originated from a separate breach dating to between 2020 and 2022, and said threat actors had deliberately altered the documents to make them appear current and sensitive.


The ministry also said the documents cited in the alleged leak are outdated, having gone through multiple revisions since their creation, and no longer reflect current configurations, adding that their relevance had been assessed and found inapplicable, which the ministry said makes the underlying claims unverifiable.


Officials said the investigation found the same dataset being offered for sale by multiple threat actors, with no current relevance to the department or the ministry. The ministry said the data had been deliberately fabricated for financial gain and to generate panic, with the intent of extracting larger payments from buyers while giving the material an appearance of authenticity.


A senior intelligence official told THE WEEK that the material could stem from an older breach, noting that ransomware groups often steal data and release it in stages as a method of extortion.


The episode followed earlier warnings from India’s intelligence agencies flagging a possible breach connected to the agency, and investigators had previously said establishing a timeline for the alleged threat would require a full analysis of the dataset and all available evidence. Intelligence officials had also said repeated advisories had been issued on the need to follow cybersecurity protocols. The incident drew attention to broader concerns over data governance at critical government agencies.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543