Blog

In September 2026, a door into an Indian company cost $700

Sixteen listings sold a way in rather than announcing an attack — and access sold this month becomes an incident later, on a date the buyer chooses.

India cyber threat landscape: the $700 gateway. September 2026, BitScore Threat Monitoring: 67 cyber incidents across 23 Indian industry sectors — 26 data breaches, 21 ransomware claims and 16 underground access sales. Government and Education most affected: Government/Politics 12 incidents (7 data breaches, 5 underground access sales), Education 9 (7 data breaches, 1 ransomware, 1 underground access sale), Business Services 7 (4 data breaches, 2 ransomware, 1 underground access sale). Firewall super-admin access listed on underground markets for $700. Access sales precede ransomware. IT providers targeted for downstream access.
Illustration of figures from the BitScore Threat Monitoring service, 31 August to 30 September 2026. The illustration is not a data visualisation — the counts below are the record.

The cheapest thing on sale in India’s threat market in September 2026 was a way into a company.

That matters more to a CFO than the ransomware count. An attack is a cost you can insure and disclose; an access sale is an attack whose date somebody else has already chosen — and when the target is a supplier, the loss lands in your quarter, not theirs.

Between 31 August and 30 September, the BitScore Threat Monitoring service counted 67 incidents affecting Indian organisations across all 23 industry sectors: 26 data breaches, 21 ransomware claims, 16 sales of access or data, two state-backed operations and two malware campaigns.

What a way in costs

Four of the sixteen listings were in hospitality. Super-admin access to a hotel’s firewall was offered at $700. Reservation data from about 2,000 hotels, hostels and villas went for $500, or $2,000 with live access. A property-management system holding more than a million bookings was offered with the company’s messaging and cloud storage attached.

Elsewhere: a shell inside an Indian energy company’s network for $1,500, domain-admin rights on a financial network, administrator access to Microsoft 365 accounts, and a way into a food and beverage manufacturer.

Set those prices against a ransom demand, a fortnight of lost production or a regulator’s penalty. Entry is priced like a commodity; the loss is priced like a crisis.

Ransomware landed on the supply side

Fourteen of the 21 ransomware claims fell in Manufacturing, Engineering, Business Services, Transportation and Technology — the sectors that make, build, move and run things for other companies. Manufacturing carried six. Engineering carried four, all construction and engineering-services firms.

Krybit was the busiest group, with six claims across four sectors. Clop listed three manufacturers on 27 September with identical wording against each: one campaign published in a batch, not three break-ins on the same day. A leak-site date is when a claim was published, not when the network was entered — the compromise is usually weeks older.

For a buyer, the consequence travels both ways at once — upstream into the supplier’s own vendors, downstream into its customers’ delivery dates. Nobody can bound it early, and a private supplier’s outage never carries a listed customer’s name until the quarter misses.

Personal data: this month’s leak, 2027’s liability

Data breaches were the largest category, at 26. Seven were in education — student, parent and staff records from schools, universities and an education-technology platform. Two were in insurance, including health-claims data.

One multi-company dump touched banks, payment apps, e-commerce, telecoms, travel and mobility at once. The source filed it under six sectors; it is counted once.

The DPDP Act’s security and breach-notice duties commence on 13 May 2027, with penalties of up to ₹250 crore for failing to protect personal data. A breach at a processor you hired is still yours to answer for. The contracts that decide who pays are being signed now.

A state group went through an IT provider

Two state-linked operations were observed. APT36, also tracked as Transparent Tribe, ran new Rust-based malware against Indian government and defence targets. Jade Sleet, a North Korean group, was linked to a breach of an Indian IT services provider.

The second is the one for anyone who outsources. An IT provider holds privileged access into its clients; a state group inside one is inside several.

Government/Politics recorded twelve incidents, the most of any sector — classified documents, staff lists, citizen records and administrative access to a public portal, leaked or offered for sale.

What to do with this

Name the ten suppliers whose outage would move revenue within a fortnight, and put a figure against each. Then ask who would learn — and how fast — if access to one of them came up for sale.

What was counted

  • Ransomware 21
  • Data Breach 26
  • Underground Activity 16
  • APTs 2
  • Malware And Hacking 2
  1. Government/Politics12Data Breach 7, Underground Activity 5
  2. Education9Ransomware 1, Data Breach 7, Underground Activity 1
  3. Business Services7Ransomware 2, Data Breach 4, Underground Activity 1
  4. Manufacturing6Ransomware 6
  5. Tourism/Hospitality6Ransomware 2, Underground Activity 4
  6. Finance5Ransomware 1, Data Breach 2, Underground Activity 1, Malware And Hacking 1
  7. Engineering4Ransomware 4
  8. Technology4Ransomware 1, Underground Activity 1, APTs 1, Malware And Hacking 1
  9. Transportation4Ransomware 1, Data Breach 3
  10. Insurance2Data Breach 2
  11. Aerospace/Defense1APTs 1
  12. Consumer Goods1Ransomware 1
  13. Food Production1Underground Activity 1
  14. Healthcare/Wellness1Ransomware 1
  15. Legal1Underground Activity 1
  16. Real Estate1Ransomware 1
  17. Telecommunications1Data Breach 1
  18. Utilities1Underground Activity 1
Counted incidents by sector, 31 August 2026 to 30 September 2026. Source: BitScore Threat Monitoring service. 67 in all.

The full grid for this window — all 23 verticals, the band thresholds and the machine-readable dataset — is in the September 2026 edition of the India Cyber Threat Scorecard, covering 31 August 2026 to 30 September 2026.

This counts other people. Find out what yours says.

Your organisation already has a security rating, calculated from signals anyone can see — including the suppliers counted above. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating →See supplier monitoring