Menu
Browse

Cyber Incident Victim: Indian Armed Forces

Date:

Dec 2019

Location:

India

Summary

The Indian Armed Forces experienced a targeted phishing attack involving malicious emails with the subject line "Notice" and an attached Excel file named HNQ Notice File.xls, distributed from the sender [email protected]. Emergency alerts were issued instructing personnel to avoid accessing the emails, delete them immediately, and report incidents. Military cyber units attributed the attack to threat actors based in Pakistan or China, noting a broader pattern of escalating cyber intrusions against critical infrastructure. Defense cyber teams remained on high alert following the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 6, 2019, the Indian Armed Forces experienced a targeted phishing attack against their personnel. The attack occurred late Friday night, prompting the tri-services cyber wings to issue an emergency warning on December 7. Malicious emails with the subject line "Notice" were distributed to defense personnel, containing a hyperlink labeled "HNQ Notice File.xls download." These emails originated from the address [email protected], which authorities identified as fraudulent. The cyber wings immediately instructed all personnel to avoid accessing any emails matching this description and to either report or delete them upon receipt. No specific details regarding the number of recipients, successful compromises, or data exfiltrated were disclosed in available reports.

Cyber Incident Image

Indian Army officials attributed the attack to threat actors operating from Pakistan or China, noting a pattern of cyber assaults against India's critical infrastructure. A senior officer confirmed that military cyber units had heightened their alert status in response to escalating attack frequency. The incident underscored ongoing cybersecurity challenges faced by defense networks, though no operational disruptions or classified system breaches were explicitly confirmed. Response actions focused on rapid threat notification and reinforcing defensive protocols across all service branches. The coordinated tri-service alert demonstrated institutional awareness of phishing tactics targeting military communications channels. Historical context provided by officials indicated persistent targeting of Indian defense assets by foreign adversaries, with this incident representing another attempted intrusion vector.

Sources
Sources available to members
1 source