India Cyber Threat Scorecard · September 2026

Nine of India’s 23 verticals ran Elevated in September 2026

31 August 2026 to 30 September 2026 — observed cyber threat activity across 23 Indian industry verticals, counted for the month.

India Cyber Threat Scorecard, September 2026. Context: 67 incidents dominated by data breaches and low-cost access sales. Data breaches lead with 26 incidents, ahead of ransomware claims (21) and underground access listings (16). Government and Education hardest hit: Government/Politics 12, Education 9. Supply-chain verticals face ransomware: 14 of 21 ransomware attacks targeted core supplier sectors. Network entry sold for $700: hotel firewall admin access at $700, energy network shells at $1,500. Krybit dominates ransomware claims: the threat group claimed 6 ransomware incidents, the most of any group.
Every figure in the illustration is drawn from the counts below. The artwork is an illustration, not a data visualisation — the grid is the record.

Fourteen of the month’s 21 ransomware claims fell in Manufacturing, Engineering, Business Services, Transportation and Technology — the verticals that make, build, move and run things for other companies.

That is where a listed buyer’s exposure sits. A supplier that stops takes a delivery date, a production line or a project milestone with it, and the disruption runs upstream and downstream at once. Nobody involved can size it while it is happening.

The scorecard

67Counted incidents
31 August 2026 to 30 September 2026

Krybit claimed 6 of the 21 incidents attributed to a named groupThe most concentrated single claimant in this edition, out of 67 counted in all. Names a threat group, not a victim — no organisation is identified here or in the dataset.

  • Data Breach 26
  • Ransomware 21
  • Underground Activity 16
  • APTs 2
  • Malware And Hacking 2
Observed incidents by industry vertical in the September 2026 edition. All 23 verticals shown.
VerticalIncidentsActivityCategories
Aerospace/Defense1
Watch
APTs 1
Business Services7
Elevated
Ransomware 2Data Breach 4Underground Activity 1
Consumer Goods1
Watch
Ransomware 1
Credit Union0
No activity observed
—
Education9
Elevated
Ransomware 1Data Breach 7Underground Activity 1
Energy/Resources0
No activity observed
—
Engineering4
Elevated
Ransomware 4
Finance5
Elevated
Ransomware 1Data Breach 2Underground Activity 1Malware And Hacking 1
Food Production1
Watch
Underground Activity 1
Government/Politics12
Elevated
Data Breach 7Underground Activity 5
Healthcare/Wellness1
Watch
Ransomware 1
Insurance2
Active
Data Breach 2
Legal1
Watch
Underground Activity 1
Manufacturing6
Elevated
Ransomware 6
Media/Entertainment0
No activity observed
—
Nonprofit/NGO0
No activity observed
—
Real Estate1
Watch
Ransomware 1
Retail0
No activity observed
—
Technology4
Elevated
Ransomware 1Underground Activity 1APTs 1Malware And Hacking 1
Telecommunications1
Watch
Data Breach 1
Tourism/Hospitality6
Elevated
Ransomware 2Underground Activity 4
Transportation4
Elevated
Ransomware 1Data Breach 3
Utilities1
Watch
Underground Activity 1
  • Aerospace/Defense1
    Watch
    APTs 1
  • Business Services7
    Elevated
    Ransomware 2Data Breach 4Underground Activity 1
  • Consumer Goods1
    Watch
    Ransomware 1
  • Credit Union0
    No activity observed
  • Education9
    Elevated
    Ransomware 1Data Breach 7Underground Activity 1
  • Energy/Resources0
    No activity observed
  • Engineering4
    Elevated
    Ransomware 4
  • Finance5
    Elevated
    Ransomware 1Data Breach 2Underground Activity 1Malware And Hacking 1
  • Food Production1
    Watch
    Underground Activity 1
  • Government/Politics12
    Elevated
    Data Breach 7Underground Activity 5
  • Healthcare/Wellness1
    Watch
    Ransomware 1
  • Insurance2
    Active
    Data Breach 2
  • Legal1
    Watch
    Underground Activity 1
  • Manufacturing6
    Elevated
    Ransomware 6
  • Media/Entertainment0
    No activity observed
  • Nonprofit/NGO0
    No activity observed
  • Real Estate1
    Watch
    Ransomware 1
  • Retail0
    No activity observed
  • Technology4
    Elevated
    Ransomware 1Underground Activity 1APTs 1Malware And Hacking 1
  • Telecommunications1
    Watch
    Data Breach 1
  • Tourism/Hospitality6
    Elevated
    Ransomware 2Underground Activity 4
  • Transportation4
    Elevated
    Ransomware 1Data Breach 3
  • Utilities1
    Watch
    Underground Activity 1

How the bands are set. Elevated is 3 or more incidents in the month, Active is 2 to 2, Watch is one, and no activity observed is none. Nothing here is judged — the band follows from the count.

This is not a security rating. A band measures observed threat activity in a vertical over the period. It says nothing about the security posture, control maturity or risk of any organisation within that vertical.

5 of the 23 verticals recorded no observed activity in this window. That means none was seen, not that none occurred.

Nine verticals sit in Elevated, led by Government/Politics on twelve and Education on nine. Five recorded no observed activity — none was seen, which is not the same as none occurring. All 23 verticals were queried this month, so none is unmeasured. The window runs from 31 August, the day after the baseline edition closed, to 30 September, so the series has no gap. The source set held 113 listings: 67 are counted; 31 failed the India counting rule; 13 repeated an item already counted under another vertical, and are counted once — one multi-company data dump alone appeared under six; and 2 were requests to buy Indian data rather than evidence of a compromise. Three items the source filed under Business Services or Education concern government and defence data, and are counted under Government/Politics. The baseline covered a quarter and was compiled differently, so read it beside this edition as context, not as the start of a trend.

What the month showed

  • Data breaches led, not ransomware. Twenty-six data breaches, 21 ransomware claims and sixteen underground listings. Seven of the breaches were in Education — student, parent and staff records from schools, universities and an education-technology platform.
  • Krybit was the busiest claimant. Six ransomware claims across four verticals, three of them engineering and construction firms. GSG and Clop claimed three each; six other groups shared the remaining nine.
  • Three manufacturers, one group, one day. Clop listed three Indian manufacturers on 27 September with the same wording against each. That reads as one campaign published in a batch — a leak-site date is when a claim appeared, not when a network was entered.
  • Access was priced below a laptop. Sixteen listings sold a way in, or the data, rather than announcing an attack. Super-admin access to a hotel’s firewall was offered at $700 and a shell inside an energy company’s network at $1,500. Four of the sixteen were in hospitality.
  • Government and defence data was the largest cluster. Twelve incidents in Government/Politics, the most of any vertical — classified documents, staff lists, citizen records and administrative access to a public portal, offered for sale or leaked.
  • A state group went through an IT provider. Two APT operations were observed. APT36 ran new malware against Indian government and defence targets; Jade Sleet, a North Korean group, was linked to a breach of an Indian IT services provider — the kind of firm with privileged access into its clients.

What the month meant for a business, rather than what it counted, is in the blog: In September 2026, a door into an Indian company cost $700.

Why it reaches your numbers before it reaches the news

Most of the 21 are private. Their customers often are not. A contractor, a logistics firm or a component maker that goes dark for a fortnight turns up in a listed buyer’s quarter as a delayed project, a missed shipment or a margin note — with no cyber incident in the buyer’s own disclosure to explain it.

Access sales are the leading indicator. A network sold in September is an incident in October or November, on a date the buyer of that access chooses. When entry costs $700, the question is not whether a supplier is a target but whether anyone would notice the sale.

And the disclosure that follows

Incident type seen in this monthWho it bindsThe obligation
Ransomware at a listed companySEBI LODR, Reg. 30(6) and Reg. 27(2)(ba)12 hours if the KMP judges it material; the quarterly governance report either way
Ransomware at an urban co-operative bankRBI Cyber Directions, 2026 — urban co-operative banksReport on DAKSH within 6 hours of detection
Health-insurance data offered for saleIRDAI Information and Cyber Security Guidelines, 2026CERT-In within 6 hours, copied to IRDAI
Government or defence data exposedEveryone — s.70B(6), IT Act 2000CERT-In, 6 hours from noticing
Customer personal data exposedDPDP Act 2023 and Rules 2025Breach intimation commences 13 May 2027
Incident types observed in this month, and what each one obliges.

Five questions for the board

  • Which ten suppliers would stop your revenue within a fortnight? Fourteen of the month’s 21 ransomware claims fell in Manufacturing, Engineering, Business Services, Transportation and Technology. Start the list there.
  • What does a two-week outage at each of them cost? If there is no figure against each of the ten, that is the gap.
  • Would you know if access to one of them were for sale? Sixteen listings this month sold a way in. Listings like these are found by watching for them, not by waiting for the news.
  • Whose systems hold your customers’ personal data? Twenty-six breaches this month, most of them personal data. A breach at a processor you hired is still yours under the DPDP Act, whose security and breach-notice duties commence on 13 May 2027.
  • Can you evidence supplier security to an insurer, an auditor or an acquirer? An annual questionnaire says nothing about a supplier listed on a leak site last week.

The numbers behind this edition

67 counted incidents across the month of 31 August 2026 to 30 September 2026, by category: Data Breach 26 · Ransomware 21 · Underground Activity 16 · APTs 2 · Malware And Hacking 2. A further 31 items in the source set were global advisories or industry news with no India nexus, and are excluded from every figure on this page.

Claiming groupIncidents
Krybit6
GSG3
Clop3
thegentlemen, DOOMMAGEDDON and Emperador, two each6
Three other named groups, one each3
Ransomware incidents by claiming group. Groups are named; organisations are not.

Download this edition

Generated from the same source this page renders from, so the files and the grid cannot disagree. Aggregate counts only — there are no incident-level records in either file.

How this is compiled

Each edition counts publicly observable cyber threat activity affecting organisations in India, arranged across the same 23 industry verticals every time. An item is counted when the affected organisation is in India, or when the activity specifically targets India. Global vulnerability advisories, commodity malware listings and industry news are excluded from the counts.

Nothing is counted twice and nothing is weighted. A vertical’s figure is the number of distinct observations recorded against it in the window, and the band follows from that figure by a published rule. The window, the vertical list and the category list are held constant between editions, because a count series is worth nothing if what is being counted moves.

What we do not publish

No organisation is named, described or made identifiable, in any edition, in the page or in the dataset. We publish counts. This is a deliberate limit rather than an editorial preference: victim identities in threat reporting are frequently drawn from secondary sources and are frequently wrong, and we are not willing to put a name behind a claim we cannot verify.

Disclaimer

The India Cyber Threat Scorecard reports aggregate counts of publicly observable cyber threat activity affecting organisations in India, across 23 industry verticals.

  • Informational only. Nothing here is legal, regulatory, financial or security advice. Reporting obligations turn on facts specific to an entity and an incident.
  • No organisation is identified. We publish counts, not victims. Nothing here should be read as a statement about any identifiable organisation.
  • Sources and method. Compiled and analysed by BitScore from its threat monitoring of Indian organisations, drawing on commercial cyber threat intelligence, dark-web and leak-site observation, and third-party news reporting. Some source material is processed using AI and large language model techniques. It may therefore contain inaccuracies, including in dates and in the attribution of activity.
  • Observations, not confirmed breaches. An entry counts an observation — a claim made by a threat group, a marketplace listing, or a public report. It is not confirmation that a compromise occurred, nor of its scope.
  • Not a security rating. The bands measure observed threat activity in a vertical over a period. They do not measure the security posture, control maturity or risk of any organisation in that vertical, and they are unrelated to any security rating.
  • Coverage is a sample. What is observable is not everything that happened. A vertical showing no activity means none was observed in the period, not that none occurred.
  • Corrections. If you believe something here is wrong, write to ni.ia.erocstib@ttimin and we will check it and correct the record.
  • No liability. Provided “as is”. BitScore Cybertech LLP accepts no liability for any loss arising from reliance on it.

The published counts are free to reuse under CC BY 4.0 — use them, and credit bitscore.in.

This edition covers 31 August 2026 to 30 September 2026. Counts are of observations recorded in that window; an observation date is the date activity became visible, which is not the date it began.

This report counts other people. Find out what yours says.

Your organisation already has a security rating, calculated from signals anyone can see — including the suppliers in the verticals above. Request the complimentary Cyber Risk Rating Report and find out what it says — as little as 45 minutes for publicly listed entities, up to 48 hours for all others. No agent, no system access, no questionnaire.

Request my rating →See supplier monitoring