CSIDB logo
Incident

Bajaj Auto

Incident posture

Attack window
Jun 2026
Location
India
Status
Unknown
CIA posture
Available to members
Updated
2026-08-29 00:05

Linked entities

Victim
Bajaj Auto
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Pending
Resolved
Pending

Summary

Bajaj Auto disclosed that a ransomware attack affected systems at the parent company and its wholly owned technology subsidiary. The intrusion was detected and the company’s internal technical team, external cybersecurity experts, and senior management responded to contain the incident, initiating precautionary actions that have so far mitigated impact. The company said the attack affected its IT infrastructure and the subsidiary’s systems but has not disclosed the full scope, including whether sensitive data was stolen, manufacturing operations were affected, supply chain systems were disrupted, or business continuity was materially impacted. The firm notified the Indian Computer Emergency Response Team and filed a disclosure under SEBI Listing Obligations and Disclosure Requirements Regulations, while no ransomware group has been attributed to the attack.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Bajaj Auto disclosed that it was hit by a ransomware attack affecting systems at both the parent company and its wholly owned technology subsidiary, Bajaj Auto Technology Ltd. The intrusion was detected at approximately 8:00 AM IST on June 23, 2026. The company confirmed the breach in a regulatory filing and stated that the attack affected its IT infrastructure and the systems of Bajaj Auto Technology Ltd. After detection, Bajaj Auto’s internal technical team, external cybersecurity experts, and senior management responded to contain the incident. The company said it initiated precautionary actions and protocols to reduce the impact of the ransomware.

Bajaj Auto reported that its containment efforts have so far been successful in mitigating the impact, although it has not disclosed the full scope of the disruption. The company has not yet indicated whether sensitive data was stolen, whether manufacturing operations were affected, whether supply chain systems were disrupted, or whether business continuity was materially impacted. In accordance with legal obligations, Bajaj Auto formally notified the Indian Computer Emergency Response Team under India’s Information Technology Act, 2000, and disclosed the incident under Regulation 30 of the SEBI Listing Obligations and Disclosure Requirements Regulations, 2015. As of the disclosure, no ransomware group or threat actor had been attributed to the attack.

The article notes that the incident highlights the ransomware exposure facing large manufacturers and automotive companies, emphasizing that even when operational impact is not immediately confirmed, ransomware affecting IT infrastructure can create risk for production planning, supply chain coordination, logistics, finance, and customer-facing services. It also observes that for CISOs, the involvement of both the parent company and its technology subsidiary is especially important because technology subsidiaries often support digital systems, development work, shared platforms, or operational services, making them valuable targets during ransomware campaigns. The regulatory disclosure is noted as notable, showing how ransomware incidents now intersect with cybersecurity reporting, investor transparency, and corporate governance. The lack of confirmed details about data theft, manufacturing impact, and threat actor attribution should not reduce urgency, and organizations need to investigate both encryption and exfiltration risk while maintaining business continuity.

Sources

Sources available to members: 1 source.

CSIDB