What the month showed
A monthly recap of observed cyber threat activity in India — written for the people who carry the cost of it, not the people who remediate it.
Most threat writing is a list of other people’s bad weeks. This is a monthly read of what was actually observed in India — which sectors took activity, what kind, and why a breach at a company you have never heard of turns up in your numbers two quarters later.
No organisation is named here, in any post. The counts come from the BitScore Threat Monitoring service and the reasoning is ours; the part worth citing is the part that is checkable.
Every post
The first monthly recap publishes in October 2026, covering September. Until then, the counted series is the thing to read: the India Threat Scorecard records observed activity across 23 industry verticals and republishes on the first of every month.
How this is put together
Each post covers one month and states the window it actually covers, which is not always the calendar month — where the two differ, the post says so rather than rounding. An item is counted when the affected organisation is in India or the activity specifically targets India; global advisories, commodity malware and industry news are excluded and the number excluded is published, so the arithmetic reconciles.
A sector that was not covered by the month’s source is reported as unmeasured, not as zero. The two look identical in a table and mean opposite things — “no ransomware in manufacturing” reads as an all-clear when the truth is that nobody looked.
Dates are the dates activity was observed and published, which are not attack dates. Leak sites publish in batches, so several victims can appear to fall on one Wednesday when the compromises were weeks apart and earlier. Anyone republishing this kind of feed as attack dates is wrong.
The posts narrate; the India Threat Scorecard counts. The scorecard carries the grid, the method and the citable dataset for the same month, free to reuse under CC BY 4.0. Each links to the other and neither repeats it.