DRDO Data Leak Raises Cybersecurity Questions
In March 2025, a hacker group named Babuk Locker 2.0 announced that it had hacked the system of DRDO and that it had 20 terabytes of classified military information with it, which included a document...
In March 2025, a hacker group named Babuk Locker 2.0 announced that it had hacked the system of DRDO and that it had 20 terabytes of classified military information with it, which included a document related to some strategic defense initiative. It had asked for a ransom of $25,000 but within days lowered its ransom from $25,000 to $5,000, a very strange action on behalf of a group claiming to have such important information. When journalists and investigators examined the sample files, they found no evidence of an actual DRDO breach at all. The files traced back not to any DRDO system, but to the internet-connected personal computer of a former joint-secretary-level IAS officer. In other words, India’s premier defense research organization was dragged into a panic over a leak that never involved its own networks, because nobody had bothered to secure the data once it left them.
History Repeats Itself
Once again, investigators are looking into an almost identical case. On July 25, 2026, a cybersecurity firm named Alibi Global, which keeps track of dark web forums on behalf of law enforcement agencies, spotted a newly placed offer of 31 GB of stolen data from DRDO, costing only $8,000, way less than the price demanded by the earlier group. The sample files reportedly displayed technical details of missile guidance sensor electronics. Alibi Global immediately alerted the Intelligence Bureau. Days later, the Defence Ministry rejected the reports, calling them “incorrect and unverified,” and traced most of the material to an older 2020–2022 breach.
That explanation should reassure no one. If true, it means sensitive defense electronics data has been circulating on criminal marketplaces for as long as six years without the Ministry noticing, tracking, or containing it, and the public only found out because a private contractor happened to be scanning the right forum.
What Actually Happened This Time
The confirmed facts remain narrow, and that narrowness is itself an indictment. A threat actor listed the data for sale, claiming DRDO origin. The sample documents bore a 2020 date stamp. A senior intelligence official told reporters that ransomware groups routinely steal data once and drip-feed it out over years to extract repeated payments, a plausible explanation, but also a convenient one that requires no admission of a fresh institutional failure. Investigators admit they have not finished analyzing the full 31 GB dataset, meaning the government issued its denial before it could possibly know whether the denial was true.
This is now a recognizable script: a threat actor makes a dramatic claim, attaches an alarming price tag, releases a handful of genuine-looking documents, and Indian authorities respond not with a forensic timeline, but with a hurried statement designed to make the story go away.
Why the Panic Still Matters
Analysts should resist the temptation to file this away as noise, because the recurrence itself is the story. If genuine 2020-era DRDO documents are still trading hands on criminal forums six years later, that is not evidence the threat has faded, it is evidence the original leak was never actually contained. Old blueprints and internal architecture diagrams still expose how an organization designs, tests, and revises sensitive systems, regardless of how outdated the final specifications have since become. An adversary studying missile guidance sensor architecture does not need current documents to learn something useful.
India’s own incident data makes clear this is not a one-off embarrassment but a symptom of systemic neglect. CERT-In logged over 29.44 lakh (2.94 million) cybersecurity incidents in 2025, a roughly 44 percent jump from the 20.41 lakh recorded in 2024. Unauthorised network scanning and probing alone accounted for nearly 83 percent of that total, 24.36 lakh incidents, meaning adversaries are relentlessly testing India’s digital defenses and, evidently, finding enough gaps to keep coming back. Parliament has been told that government-linked systems alone absorbed more than 2 lakh reported incidents in a single recent year. Separately, Check Point recorded over 3,195 attacks per week against the average Indian organization in 2025. Set against that backdrop, a single 31 GB listing isn’t an isolated scare, it’s the visible tip of a much larger failure the government has allowed to compound year after year.
The Real Failure Isn’t the Hack
The public should worry less about whether DRDO suffered a fresh breach this week and more about the fact that, days after the listing surfaced, the government still could not say when the underlying leak happened, how it happened, or whether it was ever fully contained. The same senior intelligence official who tried to calm nerves also admitted that investigators can only establish a real timeline once the entire dataset has been analyzed, an analysis still unfinished at the time the Ministry issued its confident denial. That is not transparency. That is a government reassuring the public before it has done the work needed to justify that reassurance.
This reactive posture is the actual scandal. A nuclear-armed nation’s premier defense research body should not be learning about years-old leaks of its own sensitive data from a private threat-intelligence firm that happened to be scanning dark-web forums for unrelated clients. That is a failure of basic institutional responsibility. These are the questions Indian authorities have consistently failed to answer, this time and the last: What data left DRDO’s networks? When did it leave? Through which route? Six years on from the apparent source breach, the government still cannot say.
What Needs to Change
Three concrete steps could break this cycle, and the fact that none of them are yet in place after two nearly identical incidents says something damning on its own. First, defense and research bodies should run continuous, proactive dark-web monitoring of their own rather than outsourcing situational awareness to third parties who stumble onto listings by accident. Second, officials should back every claim that leaked material is “old” or “no longer relevant” with a published forensic timeline, not a one-line press statement, so Parliament and the public can actually hold the process accountable instead of taking the Ministry’s word for it. Third, policymakers should match India’s rapid digital expansion, internet connections grew from 25.15 crore in March 2014 to over 100.29 crore in 2025, with proportional investment in cyber hygiene at sensitive institutions, rather than treating connectivity growth as an achievement in itself while security lags years behind.
The Bottom Line
The Defence Ministry may well be right that this particular listing poses no fresh danger today but “no active breach right now” is an embarrassingly low bar for a nuclear-armed nation’s premier defense research organization to clear, and it is not the same as “we know what happened and have fixed it.” India should be asking why 2020-era defense documents are still trading on criminal marketplaces in 2026, why the government keeps discovering these stories after the fact instead of before, and why denial has repeatedly substituted for evidence. Until Indian authorities can answer those questions with published facts rather than reassuring statements, every “unverified” claim should be treated as exactly that, unverified, not disproven. Denial without evidence doesn’t offer reassurance. It just distributes the same risk more quietly, and lets the same failure repeat itself again in another year.


