Blog

What the month showed

A monthly recap of observed cyber threat activity in India — written for the people who carry the cost of it, not the people who remediate it.

Most threat writing is a list of other people’s bad weeks. This is a monthly read of what was actually observed in India — which sectors took activity, what kind, and why a breach at a company you have never heard of turns up in your numbers two quarters later.

No organisation is named here, in any post. The counts come from the BitScore Threat Monitoring service and the reasoning is ours; the part worth citing is the part that is checkable.

Every post

The first monthly recap publishes in October 2026, covering September. Until then, the counted series is the thing to read: the India Threat Scorecard records observed activity across 23 industry verticals and republishes on the first of every month.

How this is put together

Each post covers one month and states the window it actually covers, which is not always the calendar month — where the two differ, the post says so rather than rounding. An item is counted when the affected organisation is in India or the activity specifically targets India; global advisories, commodity malware and industry news are excluded and the number excluded is published, so the arithmetic reconciles.

A sector that was not covered by the month’s source is reported as unmeasured, not as zero. The two look identical in a table and mean opposite things — “no ransomware in manufacturing” reads as an all-clear when the truth is that nobody looked.

Dates are the dates activity was observed and published, which are not attack dates. Leak sites publish in batches, so several victims can appear to fall on one Wednesday when the compromises were weeks apart and earlier. Anyone republishing this kind of feed as attack dates is wrong.

The posts narrate; the India Threat Scorecard counts. The scorecard carries the grid, the method and the citable dataset for the same month, free to reuse under CC BY 4.0. Each links to the other and neither repeats it.

This counts other people. Find out what yours says.

Your organisation already has a security rating, calculated from signals anyone can see — including the suppliers counted above. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating See supplier monitoring