CSIDB logo
Threat actor

AnonOpsIndia

Attribution profile

Type
Hacker
Location
India
Known incidents
2 incidents
First seen
2015-04-27
Last seen
2015-07-03
Updated
2026-08-28 17:29
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

AnonOpsIndia is a hacktivist group that operates under the alias Anonymous India and is based in India. The group describes itself as inspired by the broader Anonymous collective and uses the name AnonOpsIndia in its communications, including a Twitter account (@opindia_revenge) that has claimed responsibility for actions against Indian government entities. In its statements the group frames its activities as protests against government surveillance programs, the handling of net neutrality consultations, and the Digital India initiative, arguing that its goal is to expose systemic vulnerabilities rather than to manipulate or profit from data. It explicitly states that it does not tamper with the information it accesses and that its actions are intended to demonstrate the insecurity of national digital infrastructure.

The group’s observed targeting focuses on Indian governmental and critical infrastructure sectors, specifically telecommunications, tax identification systems, and energy‑related websites. It has claimed to breach the Bharat Sanchar Nigam Limited (BSNL) website, inject documents containing demands, and replicate a database alleged to hold over thirty million user records. Prior to the BSNL incident the group reported hacking the national PAN database and a coal‑sector website, noting in each case that it copied data without altering it. In addition to website defacement and data exfiltration, AnonOpsIndia has claimed responsibility for a denial‑of‑service disruption of the Telecom Regulatory Authority of India’s site following the accidental publication of personal data from a net neutrality consultation. The referenced tactics include website injection, database replication, and public claims of DDoS activity; no specific malware families, initial‑access vectors, or tooling details are described in the available sources.

Attribution to a state sponsor or criminal consortium is not evident in the material; the group’s public references are limited to its self‑identification with Anonymous and its use of social media to claim actions. Its most frequently cited operations are the BSNL website breach and document injection, the PAN database copy, and the coal‑sector website intrusion, which it presents as part of a series of hacks undertaken to highlight perceived failures in India’s digital governance and security practices. These actions are consistently framed as demonstrative rather than destructive, with the group emphasizing that it seeks to prompt improved security measures rather than to achieve financial gain, espionage, or prolonged disruption.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB