New Delhi, June 2026 — The National Investigation Agency (NIA) carried out coordinated searches at five locations across Maharashtra, Gujarat, Telangana, Bihar, and Delhi on Monday as part of a high-profile cyber-terrorism investigation. The raids target individuals or groups allegedly involved in attempted distributed denial-of-service (DDoS) attacks on 54 Indian government websites and critical information infrastructure (CII) during last year’s Operation Sindoor.
The operation marks one of the most extensive cyber-terrorism probes in recent years, underscoring the escalating threat to India’s digital security apparatus. While the NIA has not yet disclosed the identities of those under investigation, the case has raised urgent questions about the country’s preparedness against sophisticated cyber threats.
—
What Happened
On Monday morning, NIA teams, accompanied by local law enforcement, conducted simultaneous searches at residential and commercial premises in Mumbai (Maharashtra), Ahmedabad (Gujarat), Hyderabad (Telangana), Patna (Bihar), and New Delhi. The raids were authorized under the Unlawful Activities (Prevention) Act (UAPA) and the Information Technology Act, reflecting the gravity of the alleged offenses.
According to official sources, the investigation centers on a series of attempted DDoS attacks targeting 54 government websites between October and December 2025. These attacks, which aimed to overwhelm servers with excessive traffic, were allegedly timed to coincide with Operation Sindoor—a large-scale military exercise conducted by the Indian Armed Forces along the northern borders. While the attacks did not result in significant disruptions, they exposed vulnerabilities in India’s cyber defenses, particularly in sectors classified as critical information infrastructure (CII), including power grids, financial systems, and defense networks.
The NIA has not yet revealed whether any arrests were made during the raids or whether digital evidence, such as servers, hard drives, or communication devices, was seized. However, the agency has indicated that the investigation is in its “advanced stages” and that further actions, including potential charges, are expected in the coming weeks.
—
Why It Matters
The NIA’s raids come at a time of heightened global concern over state-sponsored and non-state cyber threats. India, which has rapidly digitized its governance and critical infrastructure, has become an increasingly attractive target for cyber adversaries. The attempted attacks on government websites and CII during Operation Sindoor suggest a deliberate effort to test India’s cyber resilience during a period of heightened national security activity.
Key Implications:
1. National Security Vulnerabilities – The attempted DDoS attacks, even if unsuccessful, highlight potential gaps in India’s cyber defenses. Critical infrastructure, such as power grids and financial systems, remains a prime target for adversaries seeking to disrupt economic and military operations. The fact that the attacks were timed with Operation Sindoor raises concerns about foreign intelligence agencies or proxy groups attempting to gather intelligence or create distractions during sensitive military maneuvers.
2. Legal and Diplomatic Ramifications – If the NIA’s investigation links the attacks to foreign actors, it could trigger diplomatic tensions. India has previously accused China and Pakistan of orchestrating cyber espionage campaigns, though both countries have denied involvement. The use of UAPA in this case suggests the NIA is treating the matter as a national security threat, which could lead to extradition requests or international legal actions if foreign nationals are implicated.
3. Cybersecurity Policy Reforms – The case may accelerate ongoing efforts to strengthen India’s cybersecurity framework. The government has been pushing for the implementation of the National Cyber Security Policy 2023, which aims to establish a unified cyber command, enhance threat intelligence sharing, and mandate stricter compliance for CII operators. The NIA’s findings could provide impetus for faster adoption of these measures.
4. Public and Corporate Awareness – The raids serve as a stark reminder to both government agencies and private enterprises about the importance of cyber hygiene. DDoS attacks, while often dismissed as low-level disruptions, can serve as smokescreens for more sophisticated intrusions, such as data breaches or ransomware attacks. The case may prompt organizations to reassess their cybersecurity protocols, particularly in sectors handling sensitive data.
—
Background and Context
# Operation Sindoor: A Timeline of Events
Operation Sindoor, conducted in late 2025, was one of the largest military exercises in recent years, involving the Indian Army, Air Force, and Navy. The drills, held near the Line of Actual Control (LAC) with China, were designed to test India’s preparedness for high-altitude warfare and integrated battlefield operations. The exercise coincided with a period of heightened tensions between India and China, following skirmishes in the eastern Ladakh region.
During the same period, cybersecurity agencies detected a surge in malicious activity targeting Indian government and military networks. While the attempted DDoS attacks did not cause major disruptions, they were part of a broader pattern of cyber intrusions observed since 2020, when India banned several Chinese apps and imposed stricter scrutiny on foreign investments in critical sectors.
# India’s Cyber Threat Landscape
India has faced a growing number of cyber threats in recent years, with both state and non-state actors implicated in attacks. Key incidents include:
– 2021: AIIMS Cyberattack – A ransomware attack on the All India Institute of Medical Sciences (AIIMS) in New Delhi disrupted healthcare services for weeks, leading to delays in patient care and data breaches. The attack was later attributed to a China-linked hacking group.
– 2022: Power Grid Intrusions – A report by cybersecurity firm Recorded Future revealed that Chinese state-sponsored hackers had targeted India’s power grid infrastructure, raising concerns about potential sabotage.
– 2023: Mumbai Power Outage – A major power outage in Mumbai was initially suspected to be the result of a cyberattack, though later investigations suggested technical failures. The incident underscored the vulnerability of India’s energy infrastructure to digital threats.
– 2024: Defence Ministry Breach – Unidentified hackers gained access to sensitive documents from the Ministry of Defence, leading to a temporary suspension of certain digital operations. The breach highlighted the need for stronger encryption and access controls.
# Legal Framework for Cybersecurity in India
India’s response to cyber threats is governed by several laws and policies, including:
– Information Technology Act, 2000 (Amended 2008) – Provides the legal framework for cybersecurity, including provisions for data protection, hacking, and cyber terrorism. Section 66F of the Act specifically addresses cyber terrorism, with penalties including life imprisonment.
– Unlawful Activities (Prevention) Act (UAPA), 1967 – Used in cases involving national security threats, including cyber terrorism. The NIA’s use of UAPA in this case suggests the agency is treating the attacks as a serious offense with potential links to terrorist organizations or foreign states.
– National Cyber Security Policy, 2023 – Aims to create a secure cyber ecosystem by establishing a National Cyber Coordination Centre (NCCC), enhancing threat intelligence sharing, and mandating cybersecurity audits for critical infrastructure operators.
– Critical Information Infrastructure (CII) Protection – The National Critical Information Infrastructure Protection Centre (NCIIPC), under the Prime Minister’s Office, is responsible for safeguarding sectors such as power, banking, telecommunications, and defense.
Despite these measures, cybersecurity experts have criticized India’s preparedness, citing a lack of skilled personnel, slow adoption of advanced technologies, and inadequate coordination between government agencies and private sector stakeholders.
—
What to Watch Next
1. NIA’s Next Moves – The agency is expected to file formal charges in the coming weeks, which could provide clarity on the identities of the suspects and their alleged motives. If foreign actors are implicated, the case could escalate into a diplomatic standoff, particularly with China or Pakistan.
2. Government Response – The raids may prompt the government to fast-track the implementation of the National Cyber Security Policy 2023. Key areas to watch include:
– The establishment of a unified cyber command to coordinate responses to cyber threats.
– Stricter compliance requirements for CII operators, including mandatory cybersecurity audits.
– Increased funding for cybersecurity research and development, particularly in areas such as artificial intelligence and quantum encryption.
3. Private Sector Reactions – Companies operating in critical sectors, such as banking, energy, and telecommunications, may face heightened scrutiny from regulators. The case could lead to:
– Mandatory cybersecurity insurance for businesses handling sensitive data.
– Stricter penalties for organizations that fail to report cyber incidents.
– Increased collaboration between the government and private sector on threat intelligence sharing.
4. International Fallout – If the NIA’s investigation points to foreign involvement, India may seek assistance from international cybersecurity alliances, such as the Quad Cybersecurity Partnership or Interpol’s Cybercrime Unit. Diplomatic pressure on countries accused of harboring cyber criminals could also intensify.
5. Public Awareness Campaigns – The government may launch new initiatives to educate citizens and businesses about cyber hygiene, including:
– Phishing awareness programs to prevent social engineering attacks.
– Guidelines for secure remote work, particularly in the wake of the COVID-19 pandemic’s lasting impact on digital workforces.
– Public-private partnerships to train cybersecurity professionals and address the skills gap in the sector.
—
Conclusion
The NIA’s raids across five states mark a critical juncture in India’s battle against cyber terrorism. While the attempted DDoS attacks during Operation Sindoor did not result in major disruptions, they serve as a stark reminder of the vulnerabilities in India’s digital infrastructure. As the investigation unfolds, the case is likely to have far-reaching implications for national security, cybersecurity policy, and international relations.
For India, the challenge lies not only in identifying and prosecuting those responsible but also in fortifying its defenses against future threats. The raids underscore the need for a proactive, multi-layered approach to cybersecurity—one that combines robust legal frameworks, advanced technological defenses, and public-private collaboration. In an era where cyber warfare is increasingly becoming a tool of statecraft, India’s ability to safeguard its digital sovereignty will be a defining factor in its national security strategy.
As the NIA’s investigation progresses, all eyes will be on the agency’s findings—and the government’s response. The stakes could not be higher: in the digital age, a nation’s resilience is only as strong as its weakest cyber link.
—
Sources:
– [Hindustan Times: NIA searches five locations in cyberattack case during Op Sindoor](https://www.hindustantimes.com/india-news/nia-searches-five-locations-in-cyberattack-case-during-op-sindoor-101787598911084.html)
Corrections
If you believe this article contains an error, contact Herald Express with the source URL and supporting evidence.
Story synopsis gathered from: Hindustan Times – India News — source