9 lakh cyber attacks detected in India’s banking and healthcare sectors | Bengaluru News


9 lakh cyber attacks detected in India’s banking and healthcare sectors
Cyber attacks being detected and thwarted

Bengaluru: The Indian Computer Emergency Response Team (CERT-In), the nodal agency for responding to cyber security attacks, has detected and successfully mitigated more than 9.2 lakh incidents of malicious scanning, probing and vulnerable services targeting the banking and healthcare sectors in the last one-and-a-half years.According to data shared by union minister of state for electronics and information technology Jitin Prasad in Rajya Sabha on Friday regarding critical information infrastructure breaches, the banking sector accounted for the bulk of the incidents. In 2025, CERT-In detected 5,70,108 incidents involving malicious scanning and probing and vulnerable services in the sector. The figure stood at 3,48,607 incidents during January-June this year.In the healthcare sector, CERT-In detected 34,480 such incidents in 2025, while another 18,855 incidents were detected in the first six months this year.Taken together, the two sectors recorded 6,04,588 incidents in 2025 and 3,67,462 incidents up to June 2026, taking the combined tally to 9,72,050 incidents over the period.The finance sector saw 4,70,445 malicious scanning and probing incidents in 2025, compared with 3,09,288 in the first half of 2026. Vulnerable services (which refer to flaws in the computer systems including misconfigurations, unsecured APIs and unpatched software) accounted for another 99,663 incidents in 2025 and 39,319 during January-June 2026.In healthcare, CERT-In detected 32,297 malicious scanning and probing incidents in 2025 and 18,259 in the first six months of 2026. Vulnerable services accounted for 2,183 incidents in 2025 and 596 incidents in 2026 up to June.Beyond these incidents, CERT-In also detected and mitigated 39 targeted intrusion campaigns in the banking sector in 2025 and another 17 campaigns in the first six months of 2026.CERT-In, designated as the national agency for responding to cyber security incidents under Section 70B of the Information Technology Act, 2000, has stepped up monitoring, threat intelligence sharing and coordinated incident response to counter the expanding cyber threat landscape.The National Cyber Coordination Centre (NCCC), implemented by CERT-In, examines cyberspace to identify cyber security threats and shares relevant information with government departments, state governments and other stakeholders for preventive action. CERT-In also operates an automated cyber threat intelligence exchange platform that sends tailored alerts to organisations across sectors.The agency coordinates responses to cyber incidents, including ransomware attacks, with affected organisations, service providers, regulators and law enforcement agencies. It also regularly issues alerts and advisories on emerging cyber threats, vulnerabilities and ransomware, along with recommended countermeasures.CERT-In has also put in place a Cyber Crisis Management Plan for countering cyber attacks and cyber terrorism, covering central government ministries and departments, state governments and their organisations.Under the Cyber Security Directions issued in April 2022 under Section 70B of the IT Act, corporate entities are required to report specified cyber incidents to CERT-In within six hours of noticing an incident, the minister stated. The govt has also expanded preparedness through cyber security exercises, he said and added that CERT-In has conducted three cyber security exercises for the power sector last year and is now focusing on emerging risks posed by frontier AI models.Pointing to the Cyber Swachhta Kendra initiative, he described it as CERT-In’s botnet cleaning and malware analysis centre, which provides free tools to detect and remove malicious programmes and offers cyber security tips and best practices to citizens and organisations.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *