A suspected major data breach has hit the Defence Research and Development Organisation (DRDO), with a threat actor offering 31 GB of allegedly stolen sensitive data for sale on the dark web for $8,000. Sample files posted by the actor include details of the internal electronics architecture of an advanced guidance sensor used in precision-guided missiles and smart munitions.
Intelligence agencies had flagged the breach last Saturday. However, the sample documents are dated 2020, and investigators are yet to determine when the data was actually exfiltrated.
"What we are seeing now could even be from an old data breach. Ransomware groups often steal data and release it in phases to extort money," a senior intelligence official told THE WEEK.
Investigators say the timeline can be established only after analysing the entire dataset and examining all the available evidence.
The incident has once again raised concerns over data governance in critical government agencies. Intelligence officials say repeated advisories have been issued on adhering to cybersecurity protocols.
"If a breach has indeed occurred, it would likely point to serious lapses. Cybersecurity has improved over the years, but there is no such thing as perfect security. Organisations must remain constantly vigilant and keep strengthening their defences," said a senior cyber intelligence expert.
The expert added that authorities also suspect a major data breach at a leading public sector bank. "These incidents show that while awareness of cybersecurity is improving, organisations and their boards must invest far more in cyber resilience. IT infrastructure needs continuous upgrades, and software must be kept fully patched. The question is: how many organisations are actually doing that?" the expert said.