India Now Absorbs More Than 3,000 Cyberattacks Every Single Day. The Numbers Have Not Stopped Growing

India Now Absorbs More Than 3,000 Cyberattacks Every Single Day. The Numbers Have Not Stopped Growing

Between 2021 and mid-2025 India recorded more than 2.2 million cybersecurity incidents according to CERT-In data, averaging more than 3,000 attacks per day. Financial services, healthcare, telecommunications and government platforms absorbed the largest volumes. The attack methods were consistent: cloud misconfigurations, unpatched servers and weak internal access controls provided the entry points that threat actors exploited repeatedly and successfully.

The 2026 IBM Cost of a Data Breach Report confirmed what Indian security professionals have been observing directly: India now faces 3,195 average weekly attacks per organisation, the highest figure of any country included in the research. That figure sits alongside an average breach cost of 2.51 million US dollars per incident, which is among the lowest of any major economy. The gap between attack volume and breach cost is not a sign of effective defence. It reflects lower regulatory penalties, fewer class action mechanisms and weaker mandatory disclosure regimes compared to the United States and Europe.

The World Economic Forum Global Risk Report 2026 ranks cybersecurity as India’s number one national risk, ahead of economic downturns, climate-related disasters and armed conflict. This is a significant statement from an institution that assesses risk across the full spectrum of national threats. It reflects the reality that India’s rapid and deliberate digital transformation through initiatives including Digital India, UPI and Aadhaar has created a digital attack surface that is both enormous and, in many parts, insufficiently protected.

The CERT-In Incident Trajectory

The chart below tracks CERT-In reported cybersecurity incidents from 2017 through to October 2023. The growth is not gradual. It is exponential across the period and the 2023 figure covers only ten months of the year. Full year totals for 2024 and 2025 are estimated to be higher still, consistent with the broader trend of increasing attack volumes documented by multiple independent researchers.

Chart 1: CERT-In reported cybersecurity incidents per year, India 2017 to October 2023 (Source: CERT-In annual reports)

The Most Damaging Incidents of the Past Three Years

The scale of individual incidents provides context for what the aggregate numbers represent. The 2018 Aadhaar breach affected 1.1 billion residents. The 2023 Indian Council of Medical Research breach exposed the personal and medical records of 815 million individuals. Both exploited API vulnerabilities that lacked proper authentication and rate-limiting controls. The pattern of inadequately secured APIs enabling mass data exposure has recurred across multiple major Indian platforms.

In the first half of 2024 alone India experienced 593 significant cyberattacks including 388 data breaches, 107 data leak operations and 39 ransomware incidents. These were not random events. Threat intelligence observations from that period described a new strategic pattern: attackers targeting supply chains, exploiting systemic weaknesses in widely used platforms and adapting their methods faster than the organisations they targeted could update their defences.

The education sector has been among the most severely affected in 2025 and 2026. Indian educational institutions absorbed approximately 200,000 cyberattacks in a nine-month period, resulting in approximately 400,000 data breaches. The combination of large student and staff databases, limited security budgets and high volumes of personal and financial data makes the sector an attractive and accessible target.

Most Targeted Sectors in India 2024 to 2026

SectorPrimary Attack TypeKey Vulnerability ExploitedTrend vs Prior Year
Financial ServicesCredential theft and fraudWeak API authenticationIncreasing
HealthcareData breach and extortionUnpatched systems and exposed endpointsIncreasing significantly
Government and Public SectorData exfiltrationCloud misconfigurationIncreasing
IT and ITeSSupply chain compromiseThird-party software vulnerabilitiesIncreasing
EducationMass data breachPoor access controls on student databasesSharply increasing
TelecommunicationsInfrastructure probingNetwork equipment vulnerabilitiesStable at high level

Table 1: Most targeted sectors in India 2024 to 2026 with primary attack types and key vulnerabilities (Source: CERT-In; Cyble threat intelligence; sector reports)

What Needs to Change

The gap between attack volume and consequence in India reflects a structural reality that the DPDP Act and strengthened CERT-In reporting requirements are beginning to address. The penalties that previously attached to a data breach were insufficient to drive the level of security investment that the threat environment demands. The new regulatory framework, which is examined in the Learn article in this edition, changes that calculus significantly for organisations handling personal data.

The more immediate challenge is detection capability. India ranks among the highest attack-volume countries globally but many organisations lack the monitoring infrastructure to know when they have been breached. Incidents that would be detected within hours in a well-monitored environment persist undetected for months in organisations without proper log management or security operations capability. The 6-hour CERT-In reporting requirement is meaningful only for organisations that can detect an incident within that window.

Leave a Reply

Your email address will not be published.