Skip to content

Cyber Security: Threats, Architecture & Regulatory Overview

1. SPECTRUM OF CYBER THREATS
Cue WordsNotes
State-Sponsored & Critical Infrastructure Attacks
  • **Cyber Warfare on CII**: Geopolitically-motivated offensives target Critical Information Infrastructure — e.g., malware targeting nuclear-plant IT networks, power-grid disruption attempts, and DDoS attacks on government ministries.
  • **Ransomware**: Encrypts hospital/enterprise systems to extort cryptocurrency payments; the AIIMS Delhi attack paralysed digital hospital operations for weeks, exposing healthcare-sector vulnerability.
  • **APTs & Zero-Click Spyware**: Stealthy, state-backed espionage; zero-click exploits (e.g., Pegasus-class spyware) compromise devices without any user interaction.
Transnational Financial Cybercrime
  • Organised syndicates, often operating out of Southeast Asian scam compounds, run **"digital arrest"** extortion scams and fake investment/trading apps — now the dominant share of India's cyber-fraud financial losses.
  • **CERT-In** logs well over **3.4 million+** reported cyber incidents annually, reflecting the scale of the threat surface.
> **Summary**: Cyber threats to India now span two distinct tracks — state-sponsored attacks on critical infrastructure/espionage, and mass-scale transnational financial fraud — requiring both defensive-technical capacity and cross-border law-enforcement cooperation.
2. INDIA'S CYBER SECURITY INSTITUTIONAL ARCHITECTURE
Cue WordsNotes
Nodal Agencies
  • **CERT-In** (under MEITY): responds to cyber incidents, tracks threats, runs mock security drills; mandates incident reporting within **6 hours** of detection and 180-day retention of security logs by regulated entities.
  • **NCIIPC** (under NTRO, Section 70A IT Act 2000): protects **7 critical sectors** — Energy, Transport, Banking & Financial Services, Telecom, Space, Strategic & Public Enterprises, Government — whose disruption would harm national security or public health.
  • **I4C (Indian Cyber Crime Coordination Centre)**: MHA initiative running the **1930 Helpline** and National Cyber Crime Reporting Portal (NCRP) to freeze fraudulent transactions in real time; has blocked/saved several thousand crore rupees in fraud funds cumulatively.
> **Summary**: India's cyber architecture is functionally divided — CERT-In for incident response, NCIIPC for critical-infrastructure protection, and I4C for citizen-facing cybercrime/fraud interdiction — giving the system institutional depth but also requiring tight inter-agency coordination.
3. STATUTORY & REGULATORY FRAMEWORK
Cue WordsNotes
IT Act, 2000 & Cyber Terrorism
  • The Information Technology Act, 2000 remains the primary legal framework; Section 66F prescribes life imprisonment for cyber terrorism.
DPDP Act, 2023 and the 2025 Rules
  • The Digital Personal Data Protection (DPDP) Act, 2023 creates "Data Fiduciary" obligations, mandates informed consent, and establishes the Data Protection Board of India (DPBI) for dispute resolution.
  • The DPDP Rules, 2025 were notified in November 2025, operationalising the DPBI, but substantive obligations (consent architecture, breach notification, data-principal rights) carry a phased compliance runway extending toward May 2027 — meaning enforcement is only now transitioning from a grace period into an active operational phase.
  • DPDP breach-notification duties run parallel to, not in place of, CERT-In's separate 6-hour incident-reporting mandate — organisations face dual reporting tracks.
Proposed Digital India Act
  • The Digital India Act (proposed) aims to replace the outdated IT Act 2000, addressing AI accountability, dark patterns, deepfakes/misinformation, and social-media intermediary safe-harbour limits — reflecting the gap between 2000-era law and present-day platform-scale harms.
> **Summary**: India's cyber-legal framework is mid-transition — the IT Act's narrow, incident-response focus is being supplemented by the DPDP Act's rights-based data-protection layer (now entering active enforcement) and, prospectively, a broader Digital India Act to govern AI and platform-era harms.
4. SCADA WARFARE, ATTRIBUTION & EMERGING DEFENSES
Cue WordsNotes
SCADA/ICS Attacks & Attribution Challenges
  • **SCADA (Supervisory Control and Data Acquisition)** systems govern power generation, railways, pipelines, and water filtration; the **Stuxnet** worm demonstrated that specialised malware can physically damage industrial machinery (uranium centrifuges) by silently altering equipment behaviour, and **BlackEnergy**-class malware has tripped circuit breakers and wiped control-server OS to delay grid recovery.
  • **Attribution Bottleneck**: Attackers route traffic through proxy nodes and VPNs across jurisdictions, making real-time source identification difficult and giving hostile states plausible deniability via proxy hacker syndicates.
  • **Budapest Convention on Cybercrime**: The main international treaty harmonising cybercrime law and cross-border evidence sharing; India remains a non-signatory over sovereignty concerns about foreign agencies directly accessing domestic data without routing through mutual legal assistance treaties, even as domestic law aligns with its technical standards.
Zero Trust Architecture & Quantum-Safe Cryptography
  • **Zero Trust Architecture (ZTA)** rests on three principles: explicit verification of every access request, least-privilege/just-in-time access, and "assume breach" network segmentation with encryption of data-in-transit and at-rest.
  • **National Cyber Coordination Centre (NCCC)**: An apex metadata-analysis and traffic-screening layer that generates early warnings on systemic malware campaigns, functioning above CERT-In's incident-response role.
  • **Quantum-Safe Cryptography**: Research is underway to replace RSA/ECC asymmetric encryption with lattice-based post-quantum algorithms before quantum computing renders legacy encryption obsolete — a forward-looking priority for defence and critical-infrastructure communications.
> **Summary**: Beyond institutional architecture and statute, the harder technical frontier is securing physical-world control systems (SCADA/ICS) against state-linked attribution-proof attacks, while next-generation defenses — Zero Trust design and quantum-safe cryptography — are still in early deployment relative to the scale of the threat.
5. RECENT TRENDS: FINANCIAL CYBERCRIME, QUANTUM RISK & REGULATORY GAPS (2025–26)
Cue WordsNotes
Crypto Exchange Breaches Expose Custodial Risk
  • **WazirX (2024, $230M loss)** and **CoinDCX (2025)** breaches show that even FIU-registered, KYC-compliant exchanges remain exposed via operational/hot-wallet architecture and third-party partner integrations, not just weak retail-user security — highlighting a supervisory gap for virtual digital asset custodians beyond FIU registration.
  • Global stablecoin regulation (US GENIUS/CLARITY Acts) and de-dollarisation anxieties post-Russia sanctions signal that financial cyber-resilience is now intertwined with monetary/geopolitical strategy, not merely a technical IT concern.
Quantum Computing as a Long-Horizon Cryptographic Threat
  • The MeitY-CERT-In-SISA whitepaper on quantum readiness flags Harvest Now, Decrypt Later (HNDL) attacks — adversaries are already exfiltrating and storing RSA-encrypted data for future decryption once quantum capability matures, making today's "secure" data a future liability.
  • This creates urgency for migrating Critical Information Infrastructure to post-quantum/lattice-based cryptography well before quantum decryption becomes operational, rather than waiting for the threat to materialise.
Regulatory Vacuum: Cyberbullying, Doxxing, and Deepfake NCII Abuse
  • Existing BNS and IT Act provisions were not drafted with persistent, anonymous, non-obscene online harassment or AI-generated deepfake abuse in mind, leaving doxxing and Non-Consensual Intimate Image (NCII) abuse in a legal grey zone.
  • The DPDP Act's undefined "publicly available data" exemption risks being exploited for data-aggregation-based harassment, showing friction between data-protection carve-outs and platform-safety enforcement.
  • Reflects a broader pattern: India's cyber-legal architecture (IT Act 2000, BNS, DPDP 2023) is reactive and fragmented across statutes rather than offering a unified personal-safety-in-cyberspace framework — reinforcing the case for a comprehensive Digital India Act.
> **Summary**: The 2025–26 threat picture shows cyber risk expanding along three fronts simultaneously — custodial failures in regulated crypto platforms, a long-horizon quantum-decryption threat demanding pre-emptive cryptographic migration, and a persistent legal vacuum around individual-targeted harms (doxxing, deepfake NCII) that current IT Act/BNS provisions do not squarely address.
5. RECENT CYBER THREAT VECTORS (2025-26)
Cue WordsNotes
Physical-Infrastructure Spillover: GPS Spoofing & GhostPairing
  • **GPS/GNSS Spoofing**: Aircraft over Delhi have faced "severe" GPS spoofing causing false position/terrain data — normally seen only in border/conflict zones; onboard Inertial Reference Systems provide up to 5 hours of safe fallback navigation.
  • **WhatsApp GhostPairing**: A CERT-In-flagged campaign exploiting the "Linked Devices" feature to hijack accounts without passwords or SIM swaps, granting attackers real-time chat/media access.
Quantum Threats & Global Legal Cooperation
  • **Harvest Now, Decrypt Later (HNDL)**: MeitY-CERT-In-SISA whitepaper flags that adversaries are storing RSA-encrypted data today to decrypt once quantum computing matures — a forward-dated national-security risk.
  • **UN Convention against Cybercrime**: First universal cybercrime treaty (Hanoi); India has not signed despite the Supreme Court urging the Centre to consider ratification for stronger cross-border law-enforcement cooperation.
Financial-Crime Layer: Mule Accounts & VPN Data-Localisation Friction
  • **Mule Accounts**: Cybercriminals launder digital-arrest/investment-scam proceeds through layered mule-account transactions; RBI's **MuleHunter.AI** uses ML to flag mule-account networks at scale.
  • **VPN Log Mandate**: CERT-In's 2022 direction requiring VPN providers to retain Indian user logs led major firms (ExpressVPN, NordVPN) to relocate "India" servers to Singapore while still marketing India-tagged IP blocks — illustrating the limits of unilateral data-localisation enforcement against globally-routed services.
> **Summary**: The 2025-26 threat landscape shows cyberattacks increasingly spilling into physical-infrastructure domains (aviation GPS spoofing) and messaging-platform account takeovers (GhostPairing), even as India navigates unresolved multilateral gaps (non-signatory to the new UN Cybercrime Convention) and enforcement friction (VPN data-localisation workarounds) alongside forward-looking quantum-era risks like HNDL.
Quantum Security & Advanced Threats (2025-26)
Cue WordsNotes
Quantum Key Distribution for National Security
  • IIT-Delhi and DRDO successfully demonstrated QKD over 1 km free space (first India achievement); entanglement-based QKD where eavesdropping attempts instantly alter quantum state, alerting users; achieved secure key rate 240 bits/second with <7% error rate (acceptable for real-world application)
  • QKD enables safe encryption-key sharing using quantum physics (not message encryption itself); two types—prepare-and-measure QKD (single photons in known states) and entanglement-based QKD (entangled photon pairs)
  • Quantum entanglement ensures measurements on one photon instantly affect entangled pair, offering ultra-secure communication; any eavesdropping introduces detectable errors providing real-time breach detection
  • National Quantum Mission (NQM) launched 2023 with ₹6,000 crore budget running till 2031; applications: banking, telecom, defence where data integrity/secure channels paramount
  • Free-space QKD faces challenges: air turbulence, pollution, photon beam divergence increasing error rates vs. stable fibre-optic channels; China achieved satellite-based QKD 2017/2020 covering 1,000-1,700 km; India could achieve satellite-based quantum communication by 2030
Post-Quantum Cryptography & RSA Threat
  • U.S. NIST standardized post-quantum cryptography algorithms: CRYSTALS-Kyber (encryption), Dilithium (digital signatures) relying on mathematical problems resisting classical-quantum attacks
  • Breaking RSA-2048 needs millions logical qubits, ~5-8 years; RSA depends on large prime factorization difficulty (classical computers need billions years); current quantum computers (Google Willow, IBM Condor) have only hundreds noisy qubits; fault-tolerant quantum computers need millions logical error-corrected qubits far beyond current capability
  • Shor's algorithm converts factoring into repeating-pattern finding via Quantum Fourier Transform; scaling enables exponentially faster RSA-number factoring
  • "Harvest now, decrypt later" risk: data intercepted/stored today could be decrypted once quantum computers mature—forward-dated national-security risk requiring post-quantum cryptography transition
U.S.-China Semiconductor Export Restrictions & AI Security
  • Trump announced Chinese firms can import Nvidia H200 GPUs subject to 25% U.S. revenue surcharge; Nvidia H200 used for AI workloads, one generation behind Blackwell (B200) chips with CUDA software ecosystem performance boost
  • Since 2018, U.S./allies (Japan, South Korea, Netherlands) restricted advanced chip exports to China due to dual-use (civil-military) concerns and technological/commercial leadership preservation
  • Restrictions pushed China accelerating indigenous R&D, firms like Huawei developing domestic chips; allowing limited H200 sales seen as strategic compromise: lets U.S. firms access Chinese market while reducing China's urgency developing cutting-edge alternatives
  • Gaps persist in China despite successes like cost-efficient AI models (DeepSeek)
AI Security Implications
  • AI-powered autonomous satellites pose security risks; dual-use (civilian+military) AI satellites require strict liability frameworks, insurance models similar to 1996 HNS Convention (hazardous substances), 1999 Montreal Convention (international air carriage)
  • Outer Space Treaty (1967) and Liability Convention (1972) assume human control; AI hallucinations/misjudgements in space result in misclassification/unintended manoeuvres
UPSC Mains PYQs
  • National Cyber Security Strategy: What are the different elements of cyber security? Examine the extent to which India has developed a comprehensive National Cyber Security Strategy. (15 Marks, 250 Words)
  • Cross-Border Cyber Attacks: Keeping in view India's internal security, analyze the impact of cross-border cyber-attacks. Discuss defensive measures against these sophisticated attacks. (15 Marks, 250 Words)
  • State-Sponsored Cyber Warfare: Discuss how state-sponsored cyber warfare (e.g., ransomware attacks on public utilities, zero-click spyware) poses a threat comparable to conventional terrorism. Outline India's preparedness, including the role of the DPDP Act and CERT-In. (15 Marks, 250 Words)
  • Cyber Warfare on Critical Infrastructure: "Cyber warfare has emerged as an asymmetric and deniable form of conflict in the 21st century." Discuss how hostile state actors utilize cyber tools (including SCADA-targeted malware) against critical infrastructure, and evaluate India's stance on the Budapest Convention. (15 Marks, 250 Words)

Current Affairs Facts (May-Dec 2025)

  • Banks must put in place risk mitigation measures such as transaction limits (per transaction, daily, weekly, monthly), transaction velocity limits, and fraud checks, depending on their risk perception.

Current Affairs Facts (May-December 2025)

  • Banks must put in place risk mitigation measures such as transaction limits (per transaction, daily, weekly, monthly), transaction velocity limits, and fraud checks, depending on their risk perception.

Current Affairs Additions (Nov 2025 Extraction)

Cue WordsNotes
Line 12761
  • FM chaired cybersecurity preparedness review India's financial institutions
Line 12763
  • DDoS attempt disrupt targeted server/service/network overwhelming internet traffic; unlike DoS uses multiple compromised systems (botnet)
Line 12765
  • DDoS leverages multiple compromised systems generating traffic collectively known botnet
Line 12767
  • Bot detection technologies CAPTCHA identify/block automated tools/bots
Line 12771
  • India lacks dedicated law addressing online hate speech & sustained trolling
Line 12773
  • BNS Section 74 (outraging modesty), 75 (sexual harassment), 351 (criminal intimidation), 356 (defamation), 196 (promoting enmity)
Line 12775
  • IT Act 2000 Section 66C (identity theft), 66D (impersonation), 67 (obscene material)
Line 12777
  • Laws don't explicitly criminalize persistent, non-obscene, anonymous online abuse
Line 12779
  • Section 69A IT Act government block content public order/national security, non-compliant platforms lose safe harbour Section 79
Line 12781
  • 2023 Delhi HC acknowledged doxxing serious threat; DPDPA exempts "publicly available data" but fails define, potentially enabling cyber harassment
Line 12783
  • Non-Consensual Intimate Image Abuse (NCII) algorithms generate deepfake pornographic images without knowledge/control; urgent legal/policy imperative
Line 12787
  • CoinDCX disclosed internal operational account hacked; 1.6 crore users, FIU-registered
Line 12789
  • CoinDCX operational hot wallet partner exchange compromised server breach
Line 12791
  • WazirX hack 2024 N.Korean attackers exploited multi-signature wallet, stole $230M
Line 12793
  • CoinDCX hack 2025 internal liquidity wallet affected; no customer funds compromised
Line 12795
  • GENIUS Act, CLARITY Act, Anti-CBDC Act US passed; GENIUS enables stablecoin issuance—asset-backed cryptocurrency indexed US dollar/Treasury bills
Line 12797
  • Trump sees stablecoins strengthen US dollar role amid de-dollarization fears after 2022 Russia-Ukraine war/US asset freezes
Line 12799
  • Countries increasing gold purchases, diversifying away US dollar protecting reserves potential asset freezes
Line 12803
  • MeitY/CERT-In/SISA launched "Transitioning Quantum Cyber Readiness" whitepaper addressing quantum technologies cybersecurity impact
Line 12805
  • Quantum computers threaten current encryption—especially RSA can solve complex problems, ML/optimization far faster
Line 12807
  • Harvest Now, Decrypt Later (HNDL) attacks store encrypted data decrypt later
Line 12811
  • India surge APK fraud malicious apps mimic official portals trick users granting permissions, spread malware
Line 12813
  • National Cyber Crime Reporting Portal launched 2019, officially dedicated 2020 I4C MHA, enabling online cybercrimes reporting
Line 12817
  • Covers financial frauds/ransomware/cyberbullying/child pornography/stalking/social crimes, evidence upload, anonymous sensitive filing
Line 12823
  • Two-Factor Authentication (2FA) adds second security layer widely Google Authenticator/TOTP (Time-based One-Time Password) implemented
Line 12825
  • First factor something know (password), second something have (authenticator app)
Line 12827
  • Uses One-Time Passwords (OTPs) valid ~30 seconds
Line 12829
  • TOTP uses cryptographic function (HMAC-SHA-256) generate short numeric code
Line 12831
  • Both device/server compute same code match = authenticated
Line 12833
  • Hash function one-way giving fixed-length output, sensitive small changes
Line 12835
  • HMAC (Hash-based Message Authentication Code) combines secret key + message hash
Line 12839
  • HMAC-based OTP (HOTP) uses counter instead time
Line 12841
  • Push-based 2FA apps send notifications approval
Line 12843
  • Hardware tokens (e.g. YubiKeys) generate codes physical device
Line 12847
  • Modern frauds phishing fake emails/SMS, remote access malicious apps, job/loan scams, OTP/UPI frauds, identity theft Aadhaar/PAN/bank, digital arrests
Line 12849
  • Section 66D IT Act cheating impersonation communication device/computer punishable 3 years imprisonment, ₹1 lakh fine
Line 12851
  • Karnataka accounted 1/4 all cybercrime cases nationwide 2023
Line 12853
  • Cybercrime Section 66D includes deepfake offences & digital impersonation scams
Line 12855
  • Karnataka first State India dedicated city-level cybercrime police station
Line 12859
  • ~500 Indian citizens fled KK Park cyber crime hub Myawaddy Myanmar set repatriation Indian government
Line 12861
  • One notorious "scam cities" Myanmar-Thailand border—purpose-built junta-allied Border Guard Force (BGF) compound
Line 12863
  • Most infamous scam "pig butchering"—investment + romance fraud using fake cryptocurrency platforms
Line 12865
  • Cambodia major hub (Sihanoukville, Bavet, O'Smach)
Line 12870
  • Supreme Court underlined importance international cooperation combating cybercrimes, Centre call UN Convention Cybercrime ratifying
Line 12872
  • World's first universal legislative cybercrime framework moved legally binding; 72 of 193 UN member states signed Hanoi Vietnam; India (October) not signed
Line 12874
  • Treaty proposes legislative framework boost international law enforcement cooperation, technical assistance countries lacking cybercrime infrastructure
Line 12876
  • "Digital Arrest" scam fraudsters impersonate law enforcement video calls threatening fake arrests extort money
Line 12878
  • Cybercrime cases surged 31.2% 2023 compared 2022
Line 12880
  • Fraud/extortion/sexual exploitation accounted majority cybercrime cases India
Line 12888
  • Aircraft flying Delhi experiencing "severe" GPS spoofing, false navigation data incorrect positions/terrain warnings
Line 12890
  • GNSS spoofing transmits counterfeit satellite signals incorrect position data, higher pilot workload, potential safety risks
Line 12892
  • Such interference rare inland metropolitan airspace, border areas/conflict zones seen
Line 12894
  • Common GPS spoofing India-Pakistan border, incidents Delhi unusual
Line 12896
  • Spoofing cyberattack type transmits false GPS signals mislead navigation systems
Line 12898
  • Delhi emerged top 10 global hotspots incidents
Line 12900
  • GPS spoofing doesn't hamper aircraft safety, systems built several redundancies including Inertial Reference System
Line 12906
  • NavIC (Navigation Indian Constellation) independent navigation satellite system ISRO developed
Line 12908
  • Per I4C rackets digital arrest, trading scam, investment scam, romance/dating scam
Line 12910
  • Section 70B IT Act 2000 CERT-In designated national agency responding cyber security incidents
Line 12912
  • CERT-In vital role controlling cybersecurity incidents, coordinating incident response, central incident response/vulnerability/security management agency
Line 12914
  • Cyber Swachhta Kendra initiative detecting/removing malicious botnet programs; free tools malware analysis, system security improvement
Line 12918
  • Mule bank accounts launder investment scams/gaming apps/QR frauds/digital arrests, obscuring money trails layered transactions
Line 12920
  • RBI launched MuleHunter.AI detection
Line 12924
  • Modern Wi-Fi beamforming uses unencrypted Beamforming Feedback Information (BFI) devices broadcast help routers steer efficiently
Line 12926
  • Karlsruhe study BFI alone identify individuals moving room purely body Wi-Fi signal disruption
Line 12928
  • Unlike Channel State Information (CSI) specialized hardware/firmware needs, BFI accessible off-shelf Wi-Fi, greater real-world privacy risk
Line 12930
  • BFI outperformed CSI identification accuracy despite CSI higher time resolution
Line 12932
  • No network access/Wi-Fi password required; attacker needs listening device radio range
Line 12934
  • Hidden surveillance risk Wi-Fi access points enable covert tracking unlike visible CCTV, "inverse panopticon" creating
Line 12936
  • Identities inferred gait, other Wi-Fi sensing (activity/occupancy) linked same individuals time, compounding harm
Line 12938
  • Existing mitigation weak, often CSI focus, may require special hardware, leaving regulatory/design gaps wireless privacy protection
Line 12942
  • Authorities suspended virtual private network Poonch/Rajouri districts two months
Line 12944
  • VPN traffic encrypted creates point-to-point tunnel, masks IP, sidesteps website blocks/firewalls, sensitive data vulnerable cyberattacks
Line 12946
  • CERT-In issued advisory active threat campaign WhatsApp users targeting
Line 12948
  • GhostPairing technique hijack WhatsApp accounts without passwords/SIM swaps
Line 12950
  • GhostPairing exploits WhatsApp "Linked Devices" trick victims authorize attacker's browser "ghost" device, full real-time access chats/media/contacts
Line 12952
  • 2022 CERT-In directions VPN providers maintain logs Indian users
Line 12954
  • VPN providers marketing services avoid tracking refused comply requests
Line 12956
  • Large paid VPN firms ExpressVPN/NordVPN shifted "India" servers Singapore
Line 12958
  • VPN firms bought Internet Protocol (IP) blocks associated India serving traffic Singapore
Line 12962
  • National Intelligence Grid police/investigating agencies securely access government/private databases real time
Line 12964
  • Instead security agencies seeking data multiple sources, NATGRID provides single platform information
Line 12966
  • NATGRID linked National Population Register (NPR) family-wise details 119 crores residents India
Line 12978
  • NATGRID access Superintendent Police-rank officers; earlier only 10 Central agencies
Line 12980
  • Organized Crime Network Database developed NATGRID IT platform facilitate NIA/State Anti-Terror Squads (ATS) secure data-sharing
Line 12982
  • Upgraded NATGRID tools "Gandiva" supporting multi-source data collection/analysis (facial recognition)