Credential theft hits Indian IT firms with 265.52 mn detections: Seqrite

Share:
Audio Loading voice…
Credential theft hits Indian IT firms with 265.52 mn detections: Seqrite

Synopsis

Seqrite's latest report reveals 265.52 million credential theft detections across Indian IT endpoints — a scale that signals the sector is under sustained, automated attack. With trojans dominating at 43% of detections and stolen credentials freely traded on the dark web, India's IT firms face a compounding risk: technical breach plus regulatory liability under the new data protection law.

Key Takeaways

265.52 million detections of credential theft recorded across more than 8 million endpoints in Indian IT firms, per Seqrite .
Trojans accounted for nearly 43% of all detections, primarily used to harvest login credentials.
Stolen credentials are being traded on dark-web marketplaces , enabling lateral movement, privilege escalation, and ransomware deployment.
Indian IT firms are especially vulnerable due to heavy reliance on cloud platforms , remote access systems , and third-party integrations .
Breaches may trigger compliance failures under India's Digital Personal Data Protection Act, 2023 .
Seqrite recommends zero-trust frameworks , multi-factor authentication , and continuous dark-web credential monitoring.

Credential theft and identity compromise has emerged as the primary entry point for large-scale cyberattacks targeting Indian IT firms, with 265.52 million detections recorded across more than 8 million endpoints, according to a new report by cybersecurity firm Seqrite, the enterprise security arm of Quick Heal Technologies Limited, released on Monday, 4 May 2025. The findings paint a picture of continuous, automated attack activity directed at India's technology sector, which has become a high-value target for credential harvesting and identity compromise on a global scale.

Scale of the Threat

Seqrite's report identified trojans as the dominant threat vector, accounting for nearly 43 per cent of all detections. These malicious programmes frequently serve as the primary payload for harvesting login credentials. Attackers reportedly combine phishing campaigns, malware, and compromised applications to capture credentials, which are then circulated across dark-web marketplaces where stolen login data is traded and weaponised at scale.

The report noted that stolen credentials enable attackers to move laterally within networks, escalate privileges, and carry out data exfiltration or ransomware campaigns — significantly amplifying the potential damage from a single breach.

Why Indian IT Firms Are Particularly Exposed

According to Seqrite, India's IT sector faces heightened exposure due to its extensive reliance on cloud platforms, remote access systems, and third-party integrations. The report warned that a single compromised credential can provide access to multiple environments simultaneously, given the interconnected nature of enterprise networks used by Indian IT firms. Their access to global systems and intellectual property makes them especially attractive targets for threat actors operating on the dark web.

This comes amid a broader global surge in identity-based attacks, where credential theft has displaced traditional vulnerability exploitation as the preferred method of initial access in enterprise breaches.

Regulatory and Compliance Implications

The report also flagged significant legal exposure under India's Digital Personal Data Protection Act, 2023, which holds organisations responsible for safeguarding personal and sensitive data. A credential compromise event can trigger breaches involving customer information, employee records, and intellectual property, potentially resulting in compliance failures and financial penalties under the new framework. Notably, this is among the first major cybersecurity reports to assess enterprise risk specifically through the lens of India's evolving data protection legislation.

What Organisations Must Do

Seqrite urged Indian enterprises to adopt an identity-first security framework as a matter of priority. The firm recommended implementing zero-trust architectures, enforcing multi-factor authentication (MFA) across all access points, and actively monitoring for credential exposure beyond organisational boundaries — including on dark-web forums and breach databases. The report stressed that perimeter-based defences are no longer sufficient given the volume and sophistication of current attack patterns.

As India's digital economy expands and IT firms deepen their integration with global enterprise systems, the window for undetected credential compromise is likely to narrow only if organisations invest proactively in identity security infrastructure.

Point of View

But the more consequential detail is structural: Indian IT firms are being targeted not because of weak security in isolation, but because of their privileged position as gateways to global enterprise systems. A single compromised credential at an Indian IT vendor can cascade into breaches across multinational clients — a supply-chain risk that the report gestures at but that deserves far sharper regulatory attention. The Digital Personal Data Protection Act, 2023 adds a new compliance dimension, but enforcement mechanisms remain untested. Until DPDP penalties are actually imposed and publicised, the compliance incentive for enterprises to invest in identity security will remain theoretical rather than operational.
NationPress
5 Aug 2026

Frequently Asked Questions

What did the Seqrite cybersecurity report on Indian IT firms find?
The Seqrite report found 265.52 million credential theft detections across more than 8 million endpoints in Indian IT firms, identifying credential theft and identity compromise as the primary entry point for large-scale cyberattacks. Trojans accounted for nearly 43% of all detections.
Why are Indian IT firms a prime target for credential theft?
Indian IT firms are heavily targeted due to their extensive use of cloud platforms, remote access systems, and third-party integrations, which give attackers access to multiple environments through a single stolen credential. Their access to global systems and intellectual property makes them especially attractive to threat actors.
How are stolen credentials being used by attackers?
Stolen credentials are traded on dark-web marketplaces and used to move laterally within enterprise networks, escalate privileges, and launch data exfiltration or ransomware campaigns. A single compromised login can provide access to multiple interconnected systems.
What are the legal risks for Indian companies under the DPDP Act?
Under the Digital Personal Data Protection Act, 2023, organisations are legally responsible for protecting personal and sensitive data. A credential-based breach involving customer information, employee records, or intellectual property can trigger compliance failures and financial penalties under the Act.
What security measures does Seqrite recommend for Indian IT firms?
Seqrite recommends adopting an identity-first security framework that includes zero-trust architecture, multi-factor authentication across all access points, and active monitoring for credential exposure on dark-web forums and breach databases beyond organisational boundaries.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 2 days ago
  2. 2 months ago
  3. 2 months ago
  4. 4 months ago
  5. 6 months ago
  6. 8 months ago
  7. 11 months ago
  8. 1 year ago
Google Prefer NP
On Google