Credential theft hits Indian IT firms with 265.52 mn detections: Seqrite
Synopsis
Key Takeaways
Credential theft and identity compromise has emerged as the primary entry point for large-scale cyberattacks targeting Indian IT firms, with 265.52 million detections recorded across more than 8 million endpoints, according to a new report by cybersecurity firm Seqrite, the enterprise security arm of Quick Heal Technologies Limited, released on Monday, 4 May 2025. The findings paint a picture of continuous, automated attack activity directed at India's technology sector, which has become a high-value target for credential harvesting and identity compromise on a global scale.
Scale of the Threat
Seqrite's report identified trojans as the dominant threat vector, accounting for nearly 43 per cent of all detections. These malicious programmes frequently serve as the primary payload for harvesting login credentials. Attackers reportedly combine phishing campaigns, malware, and compromised applications to capture credentials, which are then circulated across dark-web marketplaces where stolen login data is traded and weaponised at scale.
The report noted that stolen credentials enable attackers to move laterally within networks, escalate privileges, and carry out data exfiltration or ransomware campaigns — significantly amplifying the potential damage from a single breach.
Why Indian IT Firms Are Particularly Exposed
According to Seqrite, India's IT sector faces heightened exposure due to its extensive reliance on cloud platforms, remote access systems, and third-party integrations. The report warned that a single compromised credential can provide access to multiple environments simultaneously, given the interconnected nature of enterprise networks used by Indian IT firms. Their access to global systems and intellectual property makes them especially attractive targets for threat actors operating on the dark web.
This comes amid a broader global surge in identity-based attacks, where credential theft has displaced traditional vulnerability exploitation as the preferred method of initial access in enterprise breaches.
Regulatory and Compliance Implications
The report also flagged significant legal exposure under India's Digital Personal Data Protection Act, 2023, which holds organisations responsible for safeguarding personal and sensitive data. A credential compromise event can trigger breaches involving customer information, employee records, and intellectual property, potentially resulting in compliance failures and financial penalties under the new framework. Notably, this is among the first major cybersecurity reports to assess enterprise risk specifically through the lens of India's evolving data protection legislation.
What Organisations Must Do
Seqrite urged Indian enterprises to adopt an identity-first security framework as a matter of priority. The firm recommended implementing zero-trust architectures, enforcing multi-factor authentication (MFA) across all access points, and actively monitoring for credential exposure beyond organisational boundaries — including on dark-web forums and breach databases. The report stressed that perimeter-based defences are no longer sufficient given the volume and sophistication of current attack patterns.
As India's digital economy expands and IT firms deepen their integration with global enterprise systems, the window for undetected credential compromise is likely to narrow only if organisations invest proactively in identity security infrastructure.