<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ransomware attack | IMR</title>
	<atom:link href="https://imrmedia.in/tag/ransomware-attack/feed/" rel="self" type="application/rss+xml" />
	<link>https://imrmedia.in/tag/ransomware-attack/</link>
	<description>Indian Military Review, Defense News, Indian Defence Review</description>
	<lastBuildDate>Sat, 21 Jan 2023 08:27:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://imrmedia.in/wp-content/uploads/2020/04/cropped-IMR-Logo-512x512-px-32x32.jpg</url>
	<title>ransomware attack | IMR</title>
	<link>https://imrmedia.in/tag/ransomware-attack/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>2022 was India’s worst year of cyberattacks</title>
		<link>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/</link>
					<comments>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Fri, 30 Dec 2022 05:26:36 +0000</pubDate>
				<category><![CDATA[Daily Defence News]]></category>
		<category><![CDATA[AIIMS]]></category>
		<category><![CDATA[CERT-IN]]></category>
		<category><![CDATA[Computer Emergency Response Team]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[cyberattacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Data protection Bill]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15091</guid>

					<description><![CDATA[<p>The&#160;high-profile ransomware attack on Delhi’s All-India Institute of Medical Sciences (AIIMS) last month drew attention to holes in the country’s cybersecurity infrastructure, but it was hardly an isolated incident.&#160; Industry data shows that 2022 has been the worst year so far for India when it comes to cyberattacks&#160;— a problem that has only grown with [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/">2022 was India’s worst year of cyberattacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The&nbsp;high-profile ransomware attack on Delhi’s All-India Institute of Medical Sciences (AIIMS) last month drew attention to holes in the country’s cybersecurity infrastructure, but it was hardly an isolated incident.&nbsp;</p>



<p class="wp-block-paragraph">Industry data shows that 2022 has been the worst year so far for India when it comes to cyberattacks&nbsp;— a problem that has only grown with increasing digitalisation. The question now is, what next?&nbsp;</p>



<p class="wp-block-paragraph">According to a&nbsp;study&nbsp;released Tuesday by Indusface, a Tata Capital-funded software-as-a-service (SaaS) security firm, India has become one of the most attacked and breached countries in the world. Among the 829 million cyber-attacks detected and blocked globally by the firm in the fourth quarter of 2022, close to 59 per cent were directed towards India.&nbsp;</p>



<p class="wp-block-paragraph">“Ransomware attacks in India have increased significantly and one of the most distinguishing aspects in 2022 was the involvement of state actors,” Sameer Patil, senior fellow at Observer Research Foundation (ORF), a multi-disciplinary think-tank, told ThePrint.</p>



<p class="wp-block-paragraph">“So, it is not just profit motivation. We saw how police personnel had come out with&nbsp;Chinese links&nbsp;[in AIIMS cyberattack], of how they had a role to play,” he added.&nbsp;</p>



<p class="wp-block-paragraph">Government data, collated by the Ministry of Electronics and Information Technology’s Indian Computer Emergency Response Team (CERT-In), is&nbsp;available&nbsp;only till 2021, but that too shows an increase in cyberattacks in India.</p>



<p class="wp-block-paragraph">In 2019, CERT-In handled close to 3,94,499 incidents in total, in which it suggested remedial measures for organisations and shared notes on “cyber threats and vulnerabilities”. In the same year, CERT-In issued 204 security alerts and 38 advisories.</p>



<p class="wp-block-paragraph">The number of incidents handled by CERT-In surged in 2020 to 11,58,208, a near-tripling over the previous year. This surge continued in 2021, which saw 14,02,809 incidents, a 21 per cent increase.&nbsp;</p>



<p class="wp-block-paragraph">The matters CERT-In looks into include website intrusion and malware propagation, malicious code, phishing, distributed denial-of-service (DDoS) attacks, website defacements, unauthorised network scanning or probing activities, ransomware attacks, data breaches and vulnerable services.</p>



<p class="wp-block-paragraph">In this backdrop, what will the government and companies do differently in the coming year?</p>



<p class="wp-block-paragraph">As the government readies its legislation on cybersecurity, numerous industry-wide surveys and sector experts say that 2023 will see companies spending significant amounts to secure their digital systems from attacks.</p>



<p class="wp-block-paragraph">CERT-In has also laid out a standard operating procedure for data breaches wherein companies and other organisations are supposed to inform the government of any breach within&nbsp;six hours, although this move has received a mixed reaction since compliance may be challenging.</p>



<h3 class="wp-block-heading" id="h-what-will-companies-do-differently">What will companies do differently?</h3>



<p class="wp-block-paragraph">A significant increase in cybersecurity budgets, the advent of a slew of cybersecurity guidelines for companies, and awareness programmes for the public by law enforcement agencies are some of the preventive methods that will be seen more in 2023.</p>



<p class="wp-block-paragraph">According to Sajan Paul, managing director &amp; country manager, India &amp; SAARC, Juniper Networks, there will be a significant increase in cybersecurity budgets in 2023 within organisations, and a more preventive approach will be embraced.</p>



<p class="wp-block-paragraph">“With the ongoing threat of cyberattacks, data security remains a major priority,” he said, citing figures from&nbsp;PwC’s annual Global Digital Trust Insights&nbsp;survey. “Over 82 per cent of business executives in India foresee an increase in their cybersecurity budget in 2023. The survey also reported that 65 per cent of business executives believe cyber criminals will significantly affect their organisation in 2023, more than in 2022,” he explained.</p>



<p class="wp-block-paragraph">He added that a “zero trust” policy will be an “essential security strategy” for India, going forward.&nbsp;</p>



<p class="wp-block-paragraph">“‘Zero trust’ is the essential security strategy in today’s hybrid work environment. Instead of assuming that everything behind the corporate firewall is safe, the ‘zero trust’ model assumes breach and verifies each request as though it originates from an open network,” Paul explained.</p>



<p class="wp-block-paragraph">“Regardless of where the request originates from or what resource it accesses, ‘zero trust’ teaches us to ‘never trust, always verify’. The zero trust network reduces the complexity of securing your assets and makes it much easier to isolate problems,” he added.&nbsp;</p>



<p class="wp-block-paragraph">Even at an individual level, experts have pointed out, there must be an increase in cyber hygiene so that people don’t inadvertently enable breaches to take place.</p>



<p class="wp-block-paragraph">According to ORF’s Patil, lack of awareness about cyber-hygiene in the general populace, remains a challenge. “People don’t know what to click on and what not to in the digital space, and inadvertently become enablers [of breaches],” he said.&nbsp;</p>



<p class="wp-block-paragraph">“Online tools like deepfake have proven themselves useful for recreating videos and content that may spread incorrect information to the public. These may have huge national security implications if not identified immediately,” he added.</p>



<h3 class="wp-block-heading">Data protection Bill and CERT-In rules</h3>



<p class="wp-block-paragraph">India’s IT ministry has come up with the Digital Personal Data Protection Bill, 2022, defining some roles of data fiduciaries and introducing appellate committees that will deal with redressals and grievances. Many have&nbsp;termed it&nbsp;a “step in the right direction” to ensure data security.</p>



<p class="wp-block-paragraph">The draft law, alongside CERT-In rules, has been part of core policy discussions in India. As mentioned earlier, the rules now require companies to report cybersecurity incidents within six hours. While this seems stringent, it might not be practical, some experts believe.&nbsp;</p>



<p class="wp-block-paragraph">According to Akash Karmakar, partner with the Law Offices of Panag &amp; Babu, and who leads its fintech and regulatory advisory practice, the CERT-In rules&nbsp; should have been subject to change as companies may not have the financial bandwidth to recognise breaches.</p>



<p class="wp-block-paragraph">“The CERT-In directions mandating reporting of cyber security incidents [within six hours] was perhaps the most significant development in the cybersecurity domain this year. I’m surprised this has not been challenged since it is onerous to comply with and operationally very difficult to implement. The tightest global equivalent for reporting cybersecurity incidents is 72 hours,” Karmakar told ThePrint.</p>



<p class="wp-block-paragraph">He also highlighted how the way forward could be the prescription of a “cybersecurity insurance”. This, according to him, could “go a long way”.</p>



<p class="wp-block-paragraph">“The other challenge is how monetary loss owing to a cybersecurity incident is remediated. Mandating cybersecurity insurance for certain key risks, akin to a mandated motor vehicle or travel insurance, would go a long way to ensure that impacted entities are in a position to pay out compensation for personal data that is lost,” he said.</p>
<p>The post <a href="https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/">2022 was India’s worst year of cyberattacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/2022-was-indias-worst-year-of-cyberattacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>India’s Vulnerability to Chinese Cyber Attacks</title>
		<link>https://imrmedia.in/indias-vulnerability-to-chinese-cyber-attacks/</link>
					<comments>https://imrmedia.in/indias-vulnerability-to-chinese-cyber-attacks/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Thu, 15 Sep 2022 11:15:09 +0000</pubDate>
				<category><![CDATA[Cyber]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[Chinese Cyber Attackers]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<category><![CDATA[RedEcho]]></category>
		<category><![CDATA[RedFoxtrot]]></category>
		<category><![CDATA[WannaCry]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=15251</guid>

					<description><![CDATA[<p>India has been the target of numerous cyberattacks in recent years. These attacks have targeted various sectors including government, finance, and critical infrastructure. Some of the most notable cyberattacks in India include the WannaCry ransomware attack in 2017, which affected several government and private organizations, and the 2019 cyberattack on the Indian National Stock Exchange. [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/indias-vulnerability-to-chinese-cyber-attacks/">India’s Vulnerability to Chinese Cyber Attacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">India has been the target of numerous cyberattacks in recent years. These attacks have targeted various sectors including government, finance, and critical infrastructure. Some of the most notable cyberattacks in India include the WannaCry ransomware attack in 2017, which affected several government and private organizations, and the 2019 cyberattack on the Indian National Stock Exchange. Additionally, there have been a number of attacks on Indian banks, including a major attack in 2016 that resulted in the loss of millions of dollars. These attacks have highlighted the need for increased cybersecurity measures in India to protect against future attacks.</p>



<p class="wp-block-paragraph">A Chinese hacking group called RedEcho is believed to have attacked Maharashtra&#8217;s electricity grid in March 2021, amidst an ongoing crisis in Ladakh. Hackears from North Korea penetrated the Kundankulam Nuclear Power Plant (KKNPP) in 2019 in a bid to test the cyber security of the plant and steal information about the reactor design.</p>



<h3 class="wp-block-heading" id="h-infrastructure-projects-at-risk">Infrastructure Projects at Risk</h3>



<p class="wp-block-paragraph">India&#8217;s infrastructure projects, particularly those related to the country&#8217;s strategic interests, are considered to be at risk from cyberattacks by Chinese state-sponsored groups. These groups are known to have a significant capability in cyber espionage and have been accused of targeting infrastructure projects in other countries as well. In recent years, there have been a number of reported cyberattacks on Indian infrastructure projects, including attacks on power grids and transportation systems. The Indian government has acknowledged the risk and has taken steps to increase cybersecurity measures to protect its infrastructure projects, but it is a constant battle to stay ahead of the attackers.</p>



<h3 class="wp-block-heading">PLA&#8217;s Cyber Attackers</h3>



<p class="wp-block-paragraph">In some ways, cyber war between India and China is already taking place &#8211; after India banned hundreds of Chinese mobile apps, limiting Chinese investments in the Indian economy and giving a bloody nose to the People&#8217;s Liberation Army on the Line of Actual Control on 15 June 2020.</p>



<p class="wp-block-paragraph">In March 2013, DRDO&#8217;s computers were breached by Chinese hackers, who took files related to Cabinet Committee on Security (CCS), to a server in Guangdong in China and the Indian defence ministry ordered a probe.</p>



<p class="wp-block-paragraph">China-linked hacker group, RedFoxtrot, from their intelligence Unit 69010, targeted India&#8217;s power sector, including conglomerate NTPC, in March 2021. RedFoxtrot&#8217;s predominant targets are sectors like government, defence, and telecommunications across Central Asia, India, and Pakistan.</p>



<p class="wp-block-paragraph">Some Indian targets included Walchandnagar Industries engaged in India&#8217;s Nuclear and Space programmes, and defence manufacturer Alpha Design Technologies and Bharat Sanchar Nigam Limited (BSNL).</p>



<p class="wp-block-paragraph">The Times Group (Feb, Aug 2021), Unique Identification Authority of India (UIDAI), and MP Police Department (June 2021) have been targeted by suspected Chinese state-sponsored threat activity group TAG-28, which used Winnti malware. In June 2021, APT41 was responsible for cyber attack against Air India.</p>



<h3 class="wp-block-heading">Recent Initiatives</h3>



<p class="wp-block-paragraph">The creation of the Defence Cyber Agency in 2019, Cyber Security Coord at the National Security Council (NSC), preparedness for offensive ops by the National Technical Research Organisation (NTRO), defensive measures by National Critical Info Infrastructure Protection Centre (NCIIPC) and the release of India&#8217;s National Cyber Security Policy (NCSP) are steps in the right direction. As roles and responsibilities of the armed forces, other government agencies as well as the private sector are articulated, the nation&#8217;s vulnerability to cyber attacks will decrease.</p>



<p class="wp-block-paragraph">The vulnerabilities facing India&#8217;s Critical Infrastructure (CI) need to be addressed with greater urgency. Cyber attacks against India&#8217;s CI and Strategic Infrastructure (ST), such as nuclear power plants, are not new.</p>



<p class="wp-block-paragraph">Defensive measures like having a cyber security framework, Cyber Security Awareness, Incident Response Tools, Vulnerability Assessment and Penetration Testing, Multi-Factor Authentication and so on are necessary but offensive defence is the key. Along with space, Indian must prepare for “cross-domain” warfare to include cyberspace.</p>



<h3 class="wp-block-heading">Comments</h3>



<p class="wp-block-paragraph">China has been leading a worldwide hacking and economic espionage campaign, using cyber attacks to steal intellectual property in disregard of bilateral and multilateral agreements.</p>



<p class="wp-block-paragraph">China is one of the world&#8217;s pre-eminent players using cyber weapons. Used as methods of espionage, state-sponsored data breaches and server hacks pose a significant threat to global security. China was responsible for worldwide rise of cyber crime by 600% during the Covid-19 pandemic. Even before the virus hit, China had overtaken Russia as the biggest state sponsor of cyber attacks against the West.</p>



<p class="wp-block-paragraph">The People&#8217;s Liberation Army (PLA) of China is known to have trained hackers and offensive cyber groups for operations. These groups are believed to have been involved in a number of cyber espionage and cyber-attacks against various countries, including the United States and India. The PLA&#8217;s cyber units are thought to be well-funded and well-equipped, with a focus on both defensive and offensive capabilities. In addition to targeting government and military organizations, these groups have also been known to target private companies, particularly those in the technology and aerospace sectors. The Chinese government has denied any involvement in cyber-attacks, but evidence suggests otherwise. The US and other countries have accused China of using cyber espionage to gain an economic and strategic advantage.</p>
<p>The post <a href="https://imrmedia.in/indias-vulnerability-to-chinese-cyber-attacks/">India’s Vulnerability to Chinese Cyber Attacks</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/indias-vulnerability-to-chinese-cyber-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>India sees 70 per cent spike in ransomware attacks on critical infrastructure</title>
		<link>https://imrmedia.in/india-sees-70-per-cent-spike-in-ransomware-attacks-on-critical-infrastructure/</link>
					<comments>https://imrmedia.in/india-sees-70-per-cent-spike-in-ransomware-attacks-on-critical-infrastructure/#respond</comments>
		
		<dc:creator><![CDATA[IMR Reporter]]></dc:creator>
		<pubDate>Wed, 27 Apr 2022 06:48:00 +0000</pubDate>
				<category><![CDATA[Miscellaneous]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cyber incidents]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<category><![CDATA[ransomware attacks]]></category>
		<guid isPermaLink="false">https://imrmedia.in/?p=13353</guid>

					<description><![CDATA[<p>Cyber-attacks on critical infrastructure by nation-state bad actors have increased significantly and India observed a 70 per cent increase in ransomware activity in the fourth quarter (Q4) of 2021, a new report said on 27 April. According to the report by cybersecurity company Trellix, over half of adversarial advanced persistent threat actor activity originated from [&#8230;]</p>
<p>The post <a href="https://imrmedia.in/india-sees-70-per-cent-spike-in-ransomware-attacks-on-critical-infrastructure/">India sees 70 per cent spike in ransomware attacks on critical infrastructure</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Cyber-attacks on critical infrastructure by nation-state bad actors have increased significantly and India observed a 70 per cent increase in ransomware activity in the fourth quarter (Q4) of 2021, a new report said on 27 April.</p>



<p class="wp-block-paragraph">According to the report by cybersecurity company Trellix, over half of adversarial advanced persistent threat actor activity originated from Russian and Chinese backed groups and Russian-backed groups like APT29 have continued to greatly increase their activity in 2022.</p>



<p class="wp-block-paragraph">Reports surfaced last week that a Russian malware planted from a server in Nigeria was used for a cyber attack on Oil India&#8217;s (OIL) system in Assam.</p>



<p class="wp-block-paragraph">The state-owned company had suffered a major cyber-attack in its field headquarters in eastern Assam&#8217;s Duliajan, with the hacker demanding $75,00,000.</p>



<p class="wp-block-paragraph">The report found a significant 73 per cent increase in cyber incidents targeting individuals and positioned people as the top attack sector in Q4 2021.</p>



<p class="wp-block-paragraph">Individual consumers are the top target of cybercriminals, closely followed by the healthcare vertical.</p>



<p class="wp-block-paragraph">Additionally, the transportation, shipping, manufacturing and information technology industries showed a sharp increase in threats.</p>



<p class="wp-block-paragraph">&#8220;We are at a critical juncture in cybersecurity and observing increasingly hostile behaviour across an ever-expanding attack surface,&#8221; said Christiaan Beek, lead scientist and principal engineer, Trellix Threat Labs.</p>



<p class="wp-block-paragraph">The fourth quarter signalled the shift out of a two-year pandemic which cybercriminals used for profit and &#8220;saw the Log4Shell vulnerability impact hundreds of millions of devices, only to continue cyber momentum in the new year where we&#8217;ve seen an escalation of international cyber activity,&#8221; he added.</p>



<p class="wp-block-paragraph">Transportation and shipping were the target of 27 per cent of all advanced persistent threat (APT) &#8212; activity by adversarial and stealthy actors &#8212; detections.</p>



<p class="wp-block-paragraph">Healthcare was the second most targeted sector, bearing 12 per cent of total detections.</p>



<p class="wp-block-paragraph">From Q3 to Q4 2021, threats to manufacturing increased 100 per cent, and threats to information technology increased 36 per cent, said the report.</p>



<p class="wp-block-paragraph">APT29, believed to conduct operations for Russian government entities, ranked most active among nation-state groups.</p>



<p class="wp-block-paragraph">Malware was the technique used most often, accounting for 46 per cent of total cyber incidents.</p>
<p>The post <a href="https://imrmedia.in/india-sees-70-per-cent-spike-in-ransomware-attacks-on-critical-infrastructure/">India sees 70 per cent spike in ransomware attacks on critical infrastructure</a> appeared first on <a href="https://imrmedia.in">IMR</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://imrmedia.in/india-sees-70-per-cent-spike-in-ransomware-attacks-on-critical-infrastructure/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
