'No sensitive DRDO info was leaked': Defence Ministry rules out reports of major data breach
All the documents referred to in the alleged data leak are outdated, the Defence Ministry said
The Defence Ministry has categorically denied reports of a serious data breach involving the Defence Research and Development Organisation (DRDO). A comprehensive investigation by the ministry has revealed no evidence of any active cyber attack, unauthorized network intrusion, or ongoing data exfiltration. The ministry further clarified that the majority of the data claimed to be leaked is unclassified and bears no confidentiality. Investigations also indicated that no information relevant to the DRDO or the Defence Ministry was compromised, suggesting the reported leaked data was fabricated for financial gain and to sow panic.
The Defence Ministry has categorically denied reports of a serious data breach involving the Defence Research and Development Organisation (DRDO). A comprehensive investigation by the ministry has revealed no evidence of any active cyber attack, unauthorized network intrusion, or ongoing data exfiltration. The ministry further clarified that the majority of the data claimed to be leaked is unclassified and bears no confidentiality. Investigations also indicated that no information relevant to the DRDO or the Defence Ministry was compromised, suggesting the reported leaked data was fabricated for financial gain and to sow panic.
The Defence Ministry has categorically denied reports of a serious data breach involving the Defence Research and Development Organisation (DRDO). A comprehensive investigation by the ministry has revealed no evidence of any active cyber attack, unauthorized network intrusion, or ongoing data exfiltration. The ministry further clarified that the majority of the data claimed to be leaked is unclassified and bears no confidentiality. Investigations also indicated that no information relevant to the DRDO or the Defence Ministry was compromised, suggesting the reported leaked data was fabricated for financial gain and to sow panic.
The Defence Ministry has categorically denied reports of a serious data breach concerning the Defence Research and Development Organisation (DRDO). A thorough investigation has revealed that there "is currently no evidence of any active cyber attack, unauthorised network intrusion, or ongoing data exfiltration," the Defence Ministry said in a statement.
Most of the data that was claimed to be leaked by these reports was unclassified in nature "and bears no confidentiality," the MoD release said. There is also no evidence of data exfiltration, network intrusion, or any other cyber attack, it added.
On the alleged sale of data on the dark web, the ministry said that its probe found that no information with relevance to the DRDO or the Defence Ministry was compromised. The so-called leaked data was deliberately fabricated for financial gains as well as to sow the seeds of panic, it maintained.
"All the documents referred to in the alleged data leak are outdated, having undergone multiple revisions, and are no longer representative of current configurations. The relevance of this outdated documentation has been evaluated and is no longer applicable. The claims, therefore, made are unverifiable," the Defence Ministry said.
"Most of the data alleged to be leaked is of unclassified nature and bears no confidentiality. Certain unclassified data that is being shown as critical is from an old data breach of 2020–2022 vintage. The threat actors have deliberately and evidentially fabricated the documents to make them appear as recent and confidential," the statement added.
It was earlier this week that India's intelligence agencies had flagged a data breach concerning the DRDO. It was alleged that 31 GB of allegedly stolen sensitive data was for sale on the dark web for $8,000.
Sample files posted by the actor include details of the internal electronics architecture of an advanced guidance sensor used in precision-guided missiles and smart munitions.
"What we are seeing now could even be from an old data breach. Ransomware groups often steal data and release it in phases to extort money," a senior intelligence official told THE WEEK.
Full MoD statement:
Reports in certain sections of media on alleged cybersecurity incident involving the Defence Research & Development Organisation (DRDO) are incorrect and unverified. Thorough investigation into the alleged breach has been carried out by the relevant agencies at the level of Ministry of Defence. It is clarified that there is currently no evidence of any active cyber attack, unauthorised network intrusion, or ongoing data exfiltration.
Most of the data alleged to be leaked is of unclassified nature and bears no confidentiality. Certain unclassified data that is being shown as critical is from an old data breach of 2020-2022 vintage. The threat actors have deliberately and evidentially fabricated the documents to make them appear as recent and confidential.
All the documents referred to in the alleged data leak are outdated, having undergone multiple revisions, and are no longer representative of current configurations. The relevance of this outdated documentation has been evaluated and is no longer applicable. The claims, therefore, made are unverifiable.
The investigation reveals the data to be on sale by several threat actors. However, the data being sold is same across these threat actors and bears no current relevance to the department and the ministry. Additionally, the allegedly leaked data has been deliberately fabricated by the threat actors, motivated by financial gains, to cause panic, collect larger sums of money for the data and appear authentic.