DRDO cybersecurity breach reports false, says Defence Ministry
Synopsis
Key Takeaways
The Ministry of Defence on Tuesday, 28 July categorically rejected media reports alleging a cybersecurity incident at the Defence Research and Development Organisation (DRDO), stating that a thorough internal investigation found no evidence of any active cyberattack, unauthorised network intrusion, or ongoing data exfiltration. The denial aims to counter what officials described as fabricated and misleading claims circulating in sections of the media.
What the Investigation Found
According to the Ministry of Defence, the data being circulated as part of the alleged leak is largely unclassified and carries no confidentiality designation. Officials noted that some material being presented as sensitive is actually linked to an older breach dating back to 2020–2022 — not a fresh incident.
Investigators determined that threat actors had deliberately fabricated and manipulated these documents to make them appear recent and operationally relevant. The Ministry confirmed that all documents referenced in the purported leak have since undergone multiple revisions and no longer reflect current configurations or operational details of DRDO.
A Coordinated Disinformation Attempt
The investigation also revealed that the same set of outdated data is being offered for sale by multiple threat actors simultaneously — a pattern consistent with financially motivated disinformation rather than a genuine intelligence operation. Officials said the actors appear to be attempting to inflate the perceived value of the data by presenting it as authentic and classified, with the goal of causing public panic and commanding a higher price in cybercriminal markets.
Notably, this is not the first time adversarial actors have attempted to repackage old or fabricated data as fresh breaches targeting Indian defence institutions. Cybersecurity researchers have previously flagged similar tactics used against other government agencies.
DRDO Systems Remain Secure
The Ministry of Defence underscored that DRDO's systems remain secure and that no sensitive or classified information has been compromised. The statement was framed as a direct reassurance to the public and the defence establishment, countering speculation that India's premier defence research body had suffered a significant breach.
This clarification comes at a time when cybersecurity incidents targeting government and defence infrastructure are under heightened global scrutiny, with state-sponsored and financially motivated threat actors increasingly deploying disinformation alongside technical intrusions.
Ministry's Warning to Media
The Ministry of Defence reiterated its commitment to safeguarding national security and maintaining robust cyber defences. It also issued a pointed advisory urging media organisations to independently verify claims before publication, particularly those involving sensitive national security matters. Officials warned that unverified reporting on alleged defence breaches can itself become a tool for adversaries seeking to amplify panic.
With the official denial now on record, the narrative of a major fresh breach at DRDO has been firmly dismissed. The Ministry's response signals that India's defence cyber infrastructure remains resilient, though the episode highlights the growing threat of data manipulation and disinformation as instruments of hybrid warfare.