Threat data

The India Cyber Threat Scorecard

Observed cyber threat activity across 23 Indian industry verticals, counted and published at the end of every month.

Most threat reporting tells you what happened to somebody else, once, in prose. This is a count. The same 23 verticals, the same categories and the same rules every month, so that the figure for your sector this month means something against the figure for your sector last month.

No organisation is named in the counts, in any edition. We publish what was seen, in which vertical, in what volume. That is the part that is checkable, and it is the part worth citing. The disclosure check is the one exception, and it names only the company you ask about, from its own filing.

The current scorecard

September 2026, covering 31 August 2026 to 30 September 2026. 67 counted incidents: Data Breach 26 · Ransomware 21 · Underground Activity 16 · APTs 2 · Malware And Hacking 2. 5 of the 23 verticals recorded no observed activity.

67Counted incidents
31 August 2026 to 30 September 2026

Krybit claimed 6 of the 21 incidents attributed to a named groupThe most concentrated single claimant in this edition, out of 67 counted in all. Names a threat group, not a victim — no organisation is identified here or in the dataset.

  • Data Breach 26
  • Ransomware 21
  • Underground Activity 16
  • APTs 2
  • Malware And Hacking 2
Observed incidents by industry vertical in the September 2026 edition. All 23 verticals shown.
VerticalIncidentsActivityCategories
Aerospace/Defense1
Watch
APTs 1
Business Services7
Elevated
Ransomware 2Data Breach 4Underground Activity 1
Consumer Goods1
Watch
Ransomware 1
Credit Union0
No activity observed
—
Education9
Elevated
Ransomware 1Data Breach 7Underground Activity 1
Energy/Resources0
No activity observed
—
Engineering4
Elevated
Ransomware 4
Finance5
Elevated
Ransomware 1Data Breach 2Underground Activity 1Malware And Hacking 1
Food Production1
Watch
Underground Activity 1
Government/Politics12
Elevated
Data Breach 7Underground Activity 5
Healthcare/Wellness1
Watch
Ransomware 1
Insurance2
Active
Data Breach 2
Legal1
Watch
Underground Activity 1
Manufacturing6
Elevated
Ransomware 6
Media/Entertainment0
No activity observed
—
Nonprofit/NGO0
No activity observed
—
Real Estate1
Watch
Ransomware 1
Retail0
No activity observed
—
Technology4
Elevated
Ransomware 1Underground Activity 1APTs 1Malware And Hacking 1
Telecommunications1
Watch
Data Breach 1
Tourism/Hospitality6
Elevated
Ransomware 2Underground Activity 4
Transportation4
Elevated
Ransomware 1Data Breach 3
Utilities1
Watch
Underground Activity 1
  • Aerospace/Defense1
    Watch
    APTs 1
  • Business Services7
    Elevated
    Ransomware 2Data Breach 4Underground Activity 1
  • Consumer Goods1
    Watch
    Ransomware 1
  • Credit Union0
    No activity observed
  • Education9
    Elevated
    Ransomware 1Data Breach 7Underground Activity 1
  • Energy/Resources0
    No activity observed
  • Engineering4
    Elevated
    Ransomware 4
  • Finance5
    Elevated
    Ransomware 1Data Breach 2Underground Activity 1Malware And Hacking 1
  • Food Production1
    Watch
    Underground Activity 1
  • Government/Politics12
    Elevated
    Data Breach 7Underground Activity 5
  • Healthcare/Wellness1
    Watch
    Ransomware 1
  • Insurance2
    Active
    Data Breach 2
  • Legal1
    Watch
    Underground Activity 1
  • Manufacturing6
    Elevated
    Ransomware 6
  • Media/Entertainment0
    No activity observed
  • Nonprofit/NGO0
    No activity observed
  • Real Estate1
    Watch
    Ransomware 1
  • Retail0
    No activity observed
  • Technology4
    Elevated
    Ransomware 1Underground Activity 1APTs 1Malware And Hacking 1
  • Telecommunications1
    Watch
    Data Breach 1
  • Tourism/Hospitality6
    Elevated
    Ransomware 2Underground Activity 4
  • Transportation4
    Elevated
    Ransomware 1Data Breach 3
  • Utilities1
    Watch
    Underground Activity 1

How the bands are set. Elevated is 3 or more incidents in the month, Active is 2 to 2, Watch is one, and no activity observed is none. Nothing here is judged — the band follows from the count.

This is not a security rating. A band measures observed threat activity in a vertical over the period. It says nothing about the security posture, control maturity or risk of any organisation within that vertical.

5 of the 23 verticals recorded no observed activity in this window. That means none was seen, not that none occurred.

What the month showed, what it means for a supplier register, and the disclosure obligations behind it →

Has a listed company disclosed a cyber incident?

Listed companies tell the stock exchange about a cyber incident under Regulation 30 of the SEBI listing regulations, and the clock for one is twelve hours. The disclosure check reads a company's own NSE filings and returns what it disclosed, when it filed, and the gap from the incident time it states. The result prints, or saves as a PDF.

Every edition

  • September 2026 — 31 August 2026 to 30 September 2026, 67 counted incidents. Published 30 September 2026.
  • Baseline edition — 30 May 2026 to 30 August 2026, 36 counted incidents. Published 21 August 2026.

A new edition is published on the last day of each month, covering that month. The next is due 31 October 2026, covering October 2026. The machine-readable current edition is always at latest.json, and schema.json describes the shape, so a consumer can follow the series without scraping this page. It is one of two datasets published under the same licence — the other is the register of what Indian regulators have issued. Both are listed at open data.

How this is compiled

Each edition counts publicly observable cyber threat activity affecting organisations in India, arranged across the same 23 industry verticals every time. An item is counted when the affected organisation is in India, or when the activity specifically targets India. Global vulnerability advisories, commodity malware listings and industry news are excluded from the counts.

Nothing is counted twice and nothing is weighted. A vertical’s figure is the number of distinct observations recorded against it in the window, and the band follows from that figure by a published rule. The window, the vertical list and the category list are held constant between editions, because a count series is worth nothing if what is being counted moves.

What we do not publish

No organisation is named, described or made identifiable, in any edition, in the page or in the dataset. We publish counts. This is a deliberate limit rather than an editorial preference: victim identities in threat reporting are frequently drawn from secondary sources and are frequently wrong, and we are not willing to put a name behind a claim we cannot verify.

Disclaimer

The India Cyber Threat Scorecard reports aggregate counts of publicly observable cyber threat activity affecting organisations in India, across 23 industry verticals.

  • Informational only. Nothing here is legal, regulatory, financial or security advice. Reporting obligations turn on facts specific to an entity and an incident.
  • No organisation is identified. We publish counts, not victims. Nothing here should be read as a statement about any identifiable organisation.
  • Sources and method. Compiled and analysed by BitScore from its threat monitoring of Indian organisations, drawing on commercial cyber threat intelligence, dark-web and leak-site observation, and third-party news reporting. Some source material is processed using AI and large language model techniques. It may therefore contain inaccuracies, including in dates and in the attribution of activity.
  • Observations, not confirmed breaches. An entry counts an observation — a claim made by a threat group, a marketplace listing, or a public report. It is not confirmation that a compromise occurred, nor of its scope.
  • Not a security rating. The bands measure observed threat activity in a vertical over a period. They do not measure the security posture, control maturity or risk of any organisation in that vertical, and they are unrelated to any security rating.
  • Coverage is a sample. What is observable is not everything that happened. A vertical showing no activity means none was observed in the period, not that none occurred.
  • Corrections. If you believe something here is wrong, write to ni.ia.erocstib@ttimin and we will check it and correct the record.
  • No liability. Provided “as is”. BitScore Cybertech LLP accepts no liability for any loss arising from reliance on it.

The published counts are free to reuse under CC BY 4.0 — use them, and credit bitscore.in.

This report counts other people. Find out what yours says.

Your organisation already has a security rating, calculated from signals anyone can see — including the suppliers in the verticals above. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating →See supplier monitoring