Data breach at DRDO? 31 GB of allegedly stolen sensitive data for sale on dark web for $8,000
The sample documents posted on dark web are dated 2020, and investigators are yet to determine when the data was actually exfiltrated
A major data breach is suspected at the Defence Research and Development Organisation (DRDO), with a threat actor attempting to sell 31 GB of sensitive defense data, including missile guidance sensor architecture, on the dark web for $8,000. While intelligence agencies are investigating, the age of sample documents suggests a possible phased release from an older incident. This event intensifies concerns over data governance and cybersecurity within critical government bodies, underscoring the perpetual need for robust defenses and investment in cyber resilience.
A major data breach is suspected at the Defence Research and Development Organisation (DRDO), with a threat actor attempting to sell 31 GB of sensitive defense data, including missile guidance sensor architecture, on the dark web for $8,000. While intelligence agencies are investigating, the age of sample documents suggests a possible phased release from an older incident. This event intensifies concerns over data governance and cybersecurity within critical government bodies, underscoring the perpetual need for robust defenses and investment in cyber resilience.
A major data breach is suspected at the Defence Research and Development Organisation (DRDO), with a threat actor attempting to sell 31 GB of sensitive defense data, including missile guidance sensor architecture, on the dark web for $8,000. While intelligence agencies are investigating, the age of sample documents suggests a possible phased release from an older incident. This event intensifies concerns over data governance and cybersecurity within critical government bodies, underscoring the perpetual need for robust defenses and investment in cyber resilience.
A suspected major data breach has hit the Defence Research and Development Organisation (DRDO), with a threat actor offering 31 GB of allegedly stolen sensitive data for sale on the dark web for $8,000. Sample files posted by the actor include details of the internal electronics architecture of an advanced guidance sensor used in precision-guided missiles and smart munitions.
Intelligence agencies had flagged the breach last Saturday. However, the sample documents are dated 2020, and investigators are yet to determine when the data was actually exfiltrated.
"What we are seeing now could even be from an old data breach. Ransomware groups often steal data and release it in phases to extort money," a senior intelligence official told THE WEEK.
Investigators say the timeline can be established only after analysing the entire dataset and examining all the available evidence.
The incident has once again raised concerns over data governance in critical government agencies. Intelligence officials say repeated advisories have been issued on adhering to cybersecurity protocols.
"If a breach has indeed occurred, it would likely point to serious lapses. Cybersecurity has improved over the years, but there is no such thing as perfect security. Organisations must remain constantly vigilant and keep strengthening their defences," said a senior cyber intelligence expert.
The expert added that authorities also suspect a major data breach at a leading public sector bank. "These incidents show that while awareness of cybersecurity is improving, organisations and their boards must invest far more in cyber resilience. IT infrastructure needs continuous upgrades, and software must be kept fully patched. The question is: how many organisations are actually doing that?" the expert said.