Cyber Incident Victim: Government of India
Date:
Feb 2019
Location:
India
Summary
Following heightened geopolitical tensions, government websites and critical infrastructure systems were targeted in a coordinated cyberattack originating from Pakistan-based actors, utilizing infrastructure in Bangladesh. The attacks focused on financial networks and power grid management but were thwarted by defensive measures. In response, offensive cyber operations were deployed, causing unspecified damage to the attackers' infrastructure. After failing to breach systems, the perpetrators shifted tactics to disinformation campaigns, spreading false claims about military leadership changes and fabricated casualty reports to sow confusion. Authorities successfully countered these efforts and initiated investigations to identify those responsible for the malicious activities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Following the Pulwama suicide attack on February 14, 2019, which killed 40 Indian Central Reserve Police Force personnel, hackers linked to Pakistan launched coordinated cyber assaults against Indian government infrastructure. Within hours of the physical attack, over 90 Indian government websites and critical systems experienced an unusual surge in breach attempts, described by security officials as "ferocious." The attackers specifically targeted financial systems and power grid management networks, though Indian defensive measures prevented successful breaches of these critical systems. Officials noted the attacks originated from infrastructure in Bangladesh, a detail interpreted as evidence of deliberate obfuscation by hostile actors. India responded with undisclosed "offensive measures" in the cyber domain, which security professionals acknowledged helped contain the situation and reportedly caused reciprocal damage to Pakistani systems.

After failing to penetrate critical networks, attackers shifted tactics to disrupt information ecosystems. A coordinated disinformation campaign spread false narratives across social media platforms, including a fabricated report about the removal of Western Air Command chief Air Marshal C Hari Kumar and baseless claims of significant Indian military casualties in Rajouri. Indian authorities identified these rumors as deliberate attempts to create chaos and confusion amid heightened military tensions. The Indian army initiated investigations to trace the individuals or groups responsible for propagating these false claims. Throughout the incident cycle, the Indian government issued alerts to all departments emphasizing strict adherence to cybersecurity protocols and heightened vigilance, which contributed to mitigating further attacks. The scale and persistence of the cyber operations reflected an escalation of digital conflict paralleling the kinetic military engagements between the two nations during this period.
