Between 2021 and mid-2025 India recorded more than 2.2 million cybersecurity incidents according to CERT-In data, averaging more than 3,000 attacks per day. Financial services, healthcare, telecommunications and government platforms absorbed the largest volumes. The attack methods were consistent: cloud misconfigurations, unpatched servers and weak internal access controls provided the entry points that threat actors exploited repeatedly and successfully.
The 2026 IBM Cost of a Data Breach Report confirmed what Indian security professionals have been observing directly: India now faces 3,195 average weekly attacks per organisation, the highest figure of any country included in the research. That figure sits alongside an average breach cost of 2.51 million US dollars per incident, which is among the lowest of any major economy. The gap between attack volume and breach cost is not a sign of effective defence. It reflects lower regulatory penalties, fewer class action mechanisms and weaker mandatory disclosure regimes compared to the United States and Europe.
The World Economic Forum Global Risk Report 2026 ranks cybersecurity as India’s number one national risk, ahead of economic downturns, climate-related disasters and armed conflict. This is a significant statement from an institution that assesses risk across the full spectrum of national threats. It reflects the reality that India’s rapid and deliberate digital transformation through initiatives including Digital India, UPI and Aadhaar has created a digital attack surface that is both enormous and, in many parts, insufficiently protected.
The CERT-In Incident Trajectory
The chart below tracks CERT-In reported cybersecurity incidents from 2017 through to October 2023. The growth is not gradual. It is exponential across the period and the 2023 figure covers only ten months of the year. Full year totals for 2024 and 2025 are estimated to be higher still, consistent with the broader trend of increasing attack volumes documented by multiple independent researchers.

Chart 1: CERT-In reported cybersecurity incidents per year, India 2017 to October 2023 (Source: CERT-In annual reports)
The Most Damaging Incidents of the Past Three Years
The scale of individual incidents provides context for what the aggregate numbers represent. The 2018 Aadhaar breach affected 1.1 billion residents. The 2023 Indian Council of Medical Research breach exposed the personal and medical records of 815 million individuals. Both exploited API vulnerabilities that lacked proper authentication and rate-limiting controls. The pattern of inadequately secured APIs enabling mass data exposure has recurred across multiple major Indian platforms.
In the first half of 2024 alone India experienced 593 significant cyberattacks including 388 data breaches, 107 data leak operations and 39 ransomware incidents. These were not random events. Threat intelligence observations from that period described a new strategic pattern: attackers targeting supply chains, exploiting systemic weaknesses in widely used platforms and adapting their methods faster than the organisations they targeted could update their defences.
The education sector has been among the most severely affected in 2025 and 2026. Indian educational institutions absorbed approximately 200,000 cyberattacks in a nine-month period, resulting in approximately 400,000 data breaches. The combination of large student and staff databases, limited security budgets and high volumes of personal and financial data makes the sector an attractive and accessible target.
Most Targeted Sectors in India 2024 to 2026
| Sector | Primary Attack Type | Key Vulnerability Exploited | Trend vs Prior Year |
| Financial Services | Credential theft and fraud | Weak API authentication | Increasing |
| Healthcare | Data breach and extortion | Unpatched systems and exposed endpoints | Increasing significantly |
| Government and Public Sector | Data exfiltration | Cloud misconfiguration | Increasing |
| IT and ITeS | Supply chain compromise | Third-party software vulnerabilities | Increasing |
| Education | Mass data breach | Poor access controls on student databases | Sharply increasing |
| Telecommunications | Infrastructure probing | Network equipment vulnerabilities | Stable at high level |
Table 1: Most targeted sectors in India 2024 to 2026 with primary attack types and key vulnerabilities (Source: CERT-In; Cyble threat intelligence; sector reports)
What Needs to Change
The gap between attack volume and consequence in India reflects a structural reality that the DPDP Act and strengthened CERT-In reporting requirements are beginning to address. The penalties that previously attached to a data breach were insufficient to drive the level of security investment that the threat environment demands. The new regulatory framework, which is examined in the Learn article in this edition, changes that calculus significantly for organisations handling personal data.
The more immediate challenge is detection capability. India ranks among the highest attack-volume countries globally but many organisations lack the monitoring infrastructure to know when they have been breached. Incidents that would be detected within hours in a well-monitored environment persist undetected for months in organisations without proper log management or security operations capability. The 6-hour CERT-In reporting requirement is meaningful only for organisations that can detect an incident within that window.

Leave a Reply