Cyber Incident Victim: Telangana State Southern Power Distribution Company Ltd
Date:
Apr 2019
Location:
India
Summary
A ransomware attack targeted the websites of Telangana State Southern Power Distribution Company Ltd and its counterpart in Andhra Pradesh, disrupting web services including online payments. Hackers demanded ransom, threatening to access consumer data and divert funds, though internal operations such as billing and customer services through alternative channels remained unaffected. The agency maintaining the portals worked with the utility's IT team to restore services, while a complaint was filed with cyber crime authorities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around April 29, 2019, the websites of Telangana State Southern Power Distribution Company Ltd (TSSPDCL) and its Andhra Pradesh counterpart were compromised in a ransomware attack, disrupting web-based services including online payment systems. The hackers infiltrated the portals maintained by Tata Consultancy Services (TCS), impacting all computer-based applications. Attackers issued a ransom demand to the power distribution company, claiming possession of data pertaining to approximately two crore power consumers across Telangana. They further threatened to access online payment information to potentially divert funds, though no evidence confirmed fund diversion occurred. The breach prompted immediate engagement of TCS technicians and TSSPDCL’s internal IT team, who worked continuously to restore services. A formal complaint was lodged with Hyderabad’s Cyber Crime authorities to investigate the intrusion.

Despite the disruption to web portals, TSSPDCL confirmed core operational systems remained unaffected. Day-to-day activities such as billing, internal operations, and physical customer service channels—including bill payments at Meeseva, eSeva centers, departmental counters, and spot collection points—continued without interruption. Services unrelated to the compromised web interfaces, such as new service applications, registrations, and power supply restoration processes, were also fully operational. TSSPDCL Chairman and Managing Director G. Raghuma Reddy publicly emphasized the integrity of the utility’s total data repository and assured customers that critical infrastructure remained secure. Restoration efforts focused exclusively on the hacked websites, with no reported collateral damage to operational technology or financial systems. The incident highlighted vulnerabilities in public-facing web assets while underscoring the segregation between compromised customer portals and protected internal networks.
