In September 2026, a door into an Indian company cost $700
Sixteen listings sold a way in rather than announcing an attack — and access sold this month becomes an incident later, on a date the buyer chooses.

The cheapest thing on sale in India’s threat market in September 2026 was a way into a company.
That matters more to a CFO than the ransomware count. An attack is a cost you can insure and disclose; an access sale is an attack whose date somebody else has already chosen — and when the target is a supplier, the loss lands in your quarter, not theirs.
Between 31 August and 30 September, the BitScore Threat Monitoring service counted 67 incidents affecting Indian organisations across all 23 industry sectors: 26 data breaches, 21 ransomware claims, 16 sales of access or data, two state-backed operations and two malware campaigns.
What a way in costs
Four of the sixteen listings were in hospitality. Super-admin access to a hotel’s firewall was offered at $700. Reservation data from about 2,000 hotels, hostels and villas went for $500, or $2,000 with live access. A property-management system holding more than a million bookings was offered with the company’s messaging and cloud storage attached.
Elsewhere: a shell inside an Indian energy company’s network for $1,500, domain-admin rights on a financial network, administrator access to Microsoft 365 accounts, and a way into a food and beverage manufacturer.
Set those prices against a ransom demand, a fortnight of lost production or a regulator’s penalty. Entry is priced like a commodity; the loss is priced like a crisis.
Ransomware landed on the supply side
Fourteen of the 21 ransomware claims fell in Manufacturing, Engineering, Business Services, Transportation and Technology — the sectors that make, build, move and run things for other companies. Manufacturing carried six. Engineering carried four, all construction and engineering-services firms.
Krybit was the busiest group, with six claims across four sectors. Clop listed three manufacturers on 27 September with identical wording against each: one campaign published in a batch, not three break-ins on the same day. A leak-site date is when a claim was published, not when the network was entered — the compromise is usually weeks older.
For a buyer, the consequence travels both ways at once — upstream into the supplier’s own vendors, downstream into its customers’ delivery dates. Nobody can bound it early, and a private supplier’s outage never carries a listed customer’s name until the quarter misses.
Personal data: this month’s leak, 2027’s liability
Data breaches were the largest category, at 26. Seven were in education — student, parent and staff records from schools, universities and an education-technology platform. Two were in insurance, including health-claims data.
One multi-company dump touched banks, payment apps, e-commerce, telecoms, travel and mobility at once. The source filed it under six sectors; it is counted once.
The DPDP Act’s security and breach-notice duties commence on 13 May 2027, with penalties of up to ₹250 crore for failing to protect personal data. A breach at a processor you hired is still yours to answer for. The contracts that decide who pays are being signed now.
A state group went through an IT provider
Two state-linked operations were observed. APT36, also tracked as Transparent Tribe, ran new Rust-based malware against Indian government and defence targets. Jade Sleet, a North Korean group, was linked to a breach of an Indian IT services provider.
The second is the one for anyone who outsources. An IT provider holds privileged access into its clients; a state group inside one is inside several.
Government/Politics recorded twelve incidents, the most of any sector — classified documents, staff lists, citizen records and administrative access to a public portal, leaked or offered for sale.
What to do with this
Name the ten suppliers whose outage would move revenue within a fortnight, and put a figure against each. Then ask who would learn — and how fast — if access to one of them came up for sale.
What was counted
- Ransomware 21
- Data Breach 26
- Underground Activity 16
- APTs 2
- Malware And Hacking 2
- Government/Politics12Data Breach 7, Underground Activity 5
- Education9Ransomware 1, Data Breach 7, Underground Activity 1
- Business Services7Ransomware 2, Data Breach 4, Underground Activity 1
- Manufacturing6Ransomware 6
- Tourism/Hospitality6Ransomware 2, Underground Activity 4
- Finance5Ransomware 1, Data Breach 2, Underground Activity 1, Malware And Hacking 1
- Engineering4Ransomware 4
- Technology4Ransomware 1, Underground Activity 1, APTs 1, Malware And Hacking 1
- Transportation4Ransomware 1, Data Breach 3
- Insurance2Data Breach 2
- Aerospace/Defense1APTs 1
- Consumer Goods1Ransomware 1
- Food Production1Underground Activity 1
- Healthcare/Wellness1Ransomware 1
- Legal1Underground Activity 1
- Real Estate1Ransomware 1
- Telecommunications1Data Breach 1
- Utilities1Underground Activity 1
The full grid for this window — all 23 verticals, the band thresholds and the machine-readable dataset — is in the September 2026 edition of the India Cyber Threat Scorecard, covering 31 August 2026 to 30 September 2026.