
Mint Explainer: The truth behind Pakistan-linked cyberattacks on India
India's Operation Sindoor that targeted Pakistani terror camps triggered a wave of disinformation campaigns and claims of cyberattacks on India by Pakistani hackers. But the claims may not hold much water, say security firms.
Consider this. On Friday, a day before a ceasefire between India and Pakistan was announced, the Indian Press Information Bureau debunked a viral post that claimed ATMs across India would shut down due to a ransomware attack. The bureau simultaneously dismissed another claim that a video titled 'Dance of the Hillary' was a virus that would wipe all data on mobile phones.
Pakistan-linked hackers claim they have launched more than 100 cyberattacks on Indian government, education, and infrastructure websites so far in May. However, a detailed analysis by security firm CloudSEK reveals many of these claims to be 'exaggerated or entirely fabricated".
Data breaches have been reported in key government platforms, including that of the ministries of defence and external affairs, and the Election Commission of India. Digital public services such as UMANG, Digital Police, and the National Informatics Centre, too, were allegedly compromised, along with the Indian President and Prime Minister's top administrative websites.
Judicial systems also allegedly faced disruptions, as did the education sector with cyberattacks on the digital platforms of universities, medical institutions, and testing agencies. The digital infrastructure of the Indian Railways, India Post, RailTel Corporation of India, and major banks like Punjab National Bank and Indian Overseas Bank, were also targeted.
However, according to CloudSEK, the data breaches often involved outdated or publicly available information, while distributed denial-of-service (DDoS) attacks and defacement attempts 'caused negligible disruption—some lasting barely five minutes". (In a DDoS attack, cybercriminals flood a server with internet traffic to prevent users from accessing connected online services and sites.)
Mint explains the authenticity of the claims and the real cyber threats India faces.
Also read | Operation Sindoor: India on high alert for cyber attacks
Did Pakistan-linked cyberattacks on India cause any major damage?
Pakistan-linked hacker groups such as Nation Of Saviors, KAL EGY 319, and SYLHET GANG-SG have claimed high-profile hits on India, including cyberattacks on the digital platforms of the Election Commission and the Prime Minister's Office.
But CloudSEK's investigations show minimal impact: the Election Commission data breach was a repackaged 2023 leak, and the National Informatics Centre breach was limited to marketing files. Even coordinated DDoS attacks on government platforms resulted in barely noticeable outages.
Consider these examples.
On 8 May, Team Azrael–Angel Of Death claimed it breached the Election Commission's digital platform, allegedly exposing over a million citizen records. However, verification revealed that the data—though containing real personally identifiable information such as names, ages, phone numbers, and addresses—was originally leaked in 2023.
This reflects a common hacker tactic: repackaging old data to simulate a fresh, high-impact breach, according to CloudSEK. Team Azrael's claim appears aimed more at generating alarm and publicity than signaling a new compromise of India's democratic institutions, CloudSEK added.
On 8-9 May, KAL EGY 319 claimed a widespread defacement campaign targeting about 40 Indian educational and medical websites, followed by a shift to new targets. However, investigation showed all named websites were operational, indicating that the attacks were either not carried out as claimed or had little real impact.
Similarly, SYLHET GANG-SG and DieNet claimed to have exfiltrated more than 247 GB of data from India's National Informatics Centre. However, analysis of a 1.5 GB sample shared as 'proof" revealed only publicly available marketing content and media files, indicating the claim to be largely unsubstantiated and lacking evidence of compromised sensitive data.
Also read | Cyberattacks fresh in mind, India raises grid security after Pahalgam
So are there no major cyberthreats to India?
While the noise from Pakistan-linked hacker groups has been mostly superficial, advanced persistent threats (APTs)—sophisticated, sustained cyberattacks by hackers that have managed to establish an undetected presence in a network—underscore the real risks, according to security firms.
APT36, also known as Transparent Tribe or Mythic Leopard, is a Pakistan-linked cyber espionage group active since at least 2013. It primarily targets Indian military, government, and defence-related sectors, often using spear-phishing emails laced with malware disguised as official documents—such as fake Indian Army recruitment forms or covid-19 advisories.
The group's main tool is the Crimson RAT (Remote Access Trojan), which enables surveillance through file theft, screen capture, and keystroke logging. APT36, according to CloudSEK, used the Crimson RAT malware to infiltrate Indian defense systems following the Pahalgam terror attack last month. The malware had been delivered via phishing emails disguised as official government documents.
Once installed, Crimson RAT allowed attackers to capture screenshots, exfiltrate sensitive data, and maintain long-term access, according to CloudSEK.
Security firm Check Point Research, too, has been tracking the persistent use of ElizaRAT, a custom implant deployed by APT36 in targeted attacks on high-profile entities in India.
To deploy the Crimson RAT malware, APT36 used spoofed domains resembling Indian government websites and a payload masked as an image file to evade detection, targeting government and defense networks with precision.
APT36 has also deployed Android malware, including CapraRAT, via fake dating and chat apps to infiltrate mobile devices of military personnel and activists. Considered highly dangerous due to its persistent and stealthy operations, APT36 adapts quickly, refining its tactics and reusing infrastructure to avoid detection.
CloudSEK's report also flagged that Pakistan-linked accounts like P@kistanCyberForce and CyberLegendX (@cyber4982) were spreading unverified cyberattack claims, often tied to events like Operation Sindoor. Targets included Bharti Airtel and the Manohar Parrikar Institute, though evidence of real damage is lacking.
Top 5 Pakistan-linked hacker groups
Nation of Saviors: 32 claimed attacks
Claimed disruptions across digital platforms of Indian central and state government departments, financial institutions, and educational bodies. High-profile targets included India's Central Bureau of Investigation, Election Commission of India, and National Portal of India.
KAL EGY 319: 31 claimed attacks
Focused on defacing the websites of Indian colleges, universities, and healthcare institutions. Claimed about 40 websites compromised in a widespread campaign.
SYLHET GANG-SG: 19 claimed attacksTargeted Indian government websites, media outlets, and educational institutions. Notable claims included a data breach of the Andhra Pradesh High Court and theNational Informatics Centre.
Lực Lượng Đặc Biệt Quân Đội Điện Tử & affiliates: 18 claimed attacks
Concentrated on Indian courts and government services. Judicial and law enforcement websites, including district and high courts, were key targets.
Vulture: 16 claimed attacksFocused on Indian government and educational sites. Claimed hits on the websites of the Digital Police, President of India, and the Prime Minister's Office. Often involved in joint hacking operations.
Does this mean all is hunky-dory?
As geopolitical tensions rise, India finds itself on the brink of an evolving cyberwar with Pakistan. Recent attacks, including the breach of Pakistan's Habib Bank by the Indian Cyber Force and retaliatory phishing campaigns by Pakistan-linked APT36, as cited above, signal a new threat to India's critical digital infrastructure.
India's financial systems are on high alert. BSE and NSE recently restricted overseas access to their websites in a rare preemptive move, hinting at credible cyber threats. These measures reflect broader vulnerabilities in India's digital ecosystem—ranging from legacy systems to inconsistent cyber hygiene across institutions.
Yet, India lacks a publicly defined doctrine for cyber retaliation, unlike the US and China. India relies heavily on regulatory defenses via the Indian Computer Emergency Response Team (CERT-In), the Reserve Bank of India's frameworks, and mandates from the Securities and Exchange Board of India, though smaller financial institutions remain exposed.
With rising hacker activity, espionage, and digital subversion, India's cyber defense remains reactive and fragmented. Experts argue that a transparent, coordinated national cyber strategy—defensive and offensive—is now a strategic necessity. Is India ready for the next digital war? The answer may depend on how quickly it can bridge the policy-practice gap.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


India.com
19 minutes ago
- India.com
Turkey threatening India's friend, not Armenia, Modi govt may hit back at Erdogan by...
(File) Ankara: Bankrupt Pakistan is not refraining from spreading propaganda despite facing a humiliating loss to India. However, this terror state is getting the full support of its allies. Countries like China and Turkey are openly amplifying Pakistan's propaganda. Turkey, in particular, has now started threatening India's allies. Pakistan claims to have shot down Indian fighter jets. While India has acknowledged the loss of its aircraft, it has not disclosed how the jets were downed or how many were lost. Turkey is now threatening Greece—India's close ally. Turkish media is using Pakistan's statements to intimidate Greece. Greece, like India, has also purchased 24 Rafale fighter jets from France. Turkish conservative media platform TR Haber has launched new propaganda, claiming that Greece is uncertain about the capabilities of the French fighter jets it recently acquired. The main objective of TR Haber's report is to portray that if Pakistan can target Indian aircraft using China-made JF-17 jets and PL-15 missiles, then Greece's reliance on Rafale fighter jets could be dangerous for it. Tensions between Turkey and Greece have existed for decades, and it is evident from Turkish media reports that Turkey is trying to intimidate Greece. In essence, Turkey wants to use the India-Pakistan conflict to serve its own agenda. Meanwhile, Turkish media conveniently omits reports about how India destroyed Turkish drones as easily as slicing vegetables.


Economic Times
22 minutes ago
- Economic Times
This deal can trigger a new India-China power play
Chagos and the colonial legacy India's stakes in Mauritius Live Events China's expanding footprint Chagos, India's strategic leverage? (You can now subscribe to our (You can now subscribe to our Economic Times WhatsApp channel The recent agreement between the UK and Mauritius , where the UK has agreed in principle to cede sovereignty of the Chagos Archipelago to Mauritius, marks a watershed moment in post-colonial geopolitics. While India has officially hailed the move as the completion of Mauritius's decolonisation process, the implications go far beyond historical justice or moral diplomacy. For India, this development opens new possibilities in its ongoing strategic contest with China for influence across the Indian Ocean region. On this wider maritime chessboard, the Chagos Islands may prove to be a crucial Chagos Archipelago, a group of over 60 small islands in the central Indian Ocean, has been under British control since the 1960s, when it was separated from Mauritius prior to the latter's independence. The United Kingdom then leased the largest island, Diego Garcia, to the United States, which turned it into a major military base. For decades, the Chagos issue remained a sticking point in Mauritius's decolonisation narrative, and its legal claim was supported by international courts and the United has consistently backed Mauritius's claims, both out of principle and geopolitical calculation. The transfer of sovereignty to Mauritius — albeit with the U.S. base likely to continue operating under existing arrangements — allows New Delhi a more open and potentially influential role in shaping the future security architecture of the central Indian stakes in Mauritius are not new. The two countries enjoy strong diplomatic, economic, and cultural ties, underpinned by a shared history and a large Indo-Mauritian population. Nearly 70% of Mauritians are of Indian origin. Under a unique tradition, only Indian citizens, often top officials of Indian security and defence services, are appointed Mauritius' national security adviser and the head of the coast is among the top trading partners and investors in Mauritius, and it has strategically extended lines of credit, development assistance, and infrastructure investment to maintain its influence. India is building a Metro in Mauritius and also built its new Supreme Court building. Recently, the Indian government asked Indian airlines to bail out loss-hit Air 2015, India built a new airstrip and other military infrastructure on Agalega Island, another Mauritian territory. While officially described as supporting civilian use and improving connectivity, the facility is widely understood to have strategic value, potentially allowing India to monitor key maritime chokepoints and naval activity in the region. This development complements India's broader Indian Ocean strategy, which includes military agreements with Seychelles, Madagascar, and Oman, and a growing naval presence in the however, is not standing still. China's presence in the Indian Ocean has been growing rapidly through its Belt and Road Initiative (BRI), naval deployments, port development, and strategic partnerships. In 2019, China signed a Free Trade Agreement (FTA) with Mauritius — its first FTA with an African country — giving it a crucial economic and legal foothold in the island addition, China has funded infrastructure projects in Mauritius, including smart city projects and port modernization. While these developments are framed in economic terms, they potentially serve dual-use purposes, a hallmark of Chinese strategic investments. This expanding influence has naturally caused unease in New Delhi, which views China's Indian Ocean ambitions with deep the Chagos Islands possibly coming under the sovereignty of a friendly and closely aligned Mauritius, India gains several advantages in its strategic calculus. Control over the Chagos archipelago by Mauritius — a pro-India partner — alters the balance of influence in the central Indian Ocean. India could gain access or leverage over these islands to enhance its maritime domain awareness and patrol Diego Garcia will remain under US military use, Mauritius's sovereignty introduces a third actor into strategic dialogues. India, which shares robust defense ties with the US, could benefit from this triangle, facilitating intelligence sharing and operational Beijing establishing port access and naval agreements across the Indian Ocean — including Gwadar in Pakistan, Hambantota in Sri Lanka, and Djibouti — India needs strategic outposts of its own. The Chagos Islands, along with Agalega and other island partnerships, can serve as a counterweight. India has positioned itself as a net security provider in the IOR. Having influence over Chagos enhances its ability to counter piracy, trafficking, and other non-traditional threats, while also projecting hard power if strategic opportunity presented by the Chagos handover is significant, but it is not without challenges. First, the degree of India's access to or use of Chagos territory will depend on the terms Mauritius establishes, particularly in the context of the existing US lease of Diego Garcia. Second, India must be cautious not to provoke unnecessary tension with China, especially in a region where both nations are vying for influence through economic as well as military means. Moreover, the local sensitivities, especially surrounding the displaced Chagossian population and ongoing human rights concerns, mean that any Indian role must be diplomatically nuanced and development-oriented.


News18
31 minutes ago
- News18
Will Germany's Strict Immigration Rules Impact Indians? Citizenship Criteria To Curbs Explained
Last Updated: The government has abolished the fast-track route to citizenship that previously allowed well-integrated migrants to apply for citizenship after three years of residency German Chancellor Friedrich Merz's cabinet on May 28 approved sweeping changes to the country's immigration rules. Among the major changes is a temporary two-year suspension of family reunification rights for those with subsidiary protection — refugees not granted full refugee status, such as many Syrians. During this period, these migrants are not allowed to bring their spouses or children to Germany. Interior Minister Alexander Dobrindt said that Germany's urban systems have reached their 'breaking point" and cannot handle the inflow without causing challenges for public services. Migration is among German voters' biggest concerns and Merz won the election in February pledging a crackdown on migration. NO FAST TRACK The government also abolished the fast-track route to citizenship that previously allowed well-integrated migrants to apply for citizenship after three years of residency. The new rules now require a minimum of five years of residency for German citizenship. However, foreigners married to German citizens can still apply after three years, provided they have been married for at least two years. WHAT IT MEANS FOR INDIANS Most of the Indian professionals and students in Germany are not under subsidiary protection. The changes, however, may impact vulnerable migrants and delay long-term settlement plans. India remains a key contributor to Germany's skilled labor pool, with initiatives such as the ' Opportunity Card ' being expanded to address labour shortages. Merz recently said that a court ruling against the expulsion by border police of three Somali asylum seekers could restrict his government's migration crackdown but would not stop it. People would continue to be turned away at the German border, he said. A Berlin administrative court last week said the expulsion of the three unnamed Somalis, who were sent back to Poland after arriving at a train station in eastern Germany, was 'unlawful". It said that under the European Union's Dublin Regulation, Germany should have determined which country was responsible for processing their claim before sending them back, in a ruling that Merz's interior minister contested. That marks a big shift since Germany's 'Refugees Welcome" culture during Europe's migrant crisis in 2015 under Merz's conservative predecessor, Angela Merkel. Merz's government issued an order in May to reject undocumented migrants, including asylum seekers, at Germany's borders. Dobrindt defended the expulsions, saying he would provide justifications for banning entry and portraying the ruling as an isolated case. 'I have made it clear several times that this is about being overwhelmed, and I see this overburdening," he told reporters. With Agency Inputs First Published: June 08, 2025, 16:45 IST