Op Sindoor cyber threat: 54 govt sites targeted, NIA widens probe

Share:
Audio Loading voice…
Op Sindoor cyber threat: 54 govt sites targeted, NIA widens probe

Synopsis

While Indian forces struck terrorist sites across the border during Operation Sindoor, a Telegram group called Anonsec — led by an 18-year-old from Nadiad — was simultaneously targeting 54 Central government websites with DDoS attacks. The NIA has now expanded its probe to five states, revealing a cyber threat that was more about intent and coordination than technical capability.

Key Takeaways

The NIA conducted searches at 5 locations across Maharashtra, Gujarat, Telangana, Bihar, and Delhi on 24 August as part of its expanded cyber probe linked to Operation Sindoor .
54 Central government websites , including Critical Information Infrastructure (CII) , were targeted with DDoS attacks between March and May 2025 .
Primary accused Jasim Shahnawaz Ansari , 18 , from Nadiad, Gujarat , and a juvenile allegedly operated through a Telegram group called Anonsec .
Investigators confirmed the accused lacked sufficient computing power to cause sustained disruption but are pursuing the case on grounds of intent and coordination .
The NIA filed a charge sheet against Ansari on 14 August last year; the case was registered under Sections 43 and 66(F) of the IT Act — not UAPA.
Investigators found no specific evidence linking Pakistan to the attacks, though the Telegram group reportedly had members from Bangladesh and Palestine .

Even as the Indian Armed Forces executed Operation Sindoor on 7 May 2025, a parallel assault was unfolding in cyberspace — one that investigators have since described as an attempted act of 'cyber terrorism'. Coordinated Distributed Denial-of-Service (DDoS) attacks were directed at 54 Central government websites, including systems classified as Critical Information Infrastructure (CII), in what authorities say was a deliberate attempt to destabilise India's digital backbone during a period of active military engagement.

NIA Widens the Investigation

More than a year after the Gujarat Anti-Terrorist Squad (ATS) first cracked the case, the National Investigation Agency (NIA) has significantly expanded its probe. On 24 August, NIA teams conducted simultaneous searches at five locations spanning Maharashtra, Gujarat, Telangana, Bihar, and Delhi — specifically in Junnar (Pune district), Nadiad (Kheda district), Ramagundam (Karimnagar district), Gopalganj, and Delhi.

The searches yielded three laptops, five mobile phones, pen drives, and documents containing allegedly incriminating material linked to hacking activities. Suspects identified through technical analysis for allegedly providing support to the primary accused were also examined during the operation.

The Anonsec Telegram Network

At the centre of the investigation is Jasim Shahnawaz Ansari, an 18-year-old from Nadiad, and a juvenile — both allegedly members of a Telegram group called Anonsec. The Gujarat ATS had been monitoring anti-national activity on social media and the Dark Web when intelligence pointed to the duo's involvement.

The group had previously operated through Telegram channels named EXPLOITXSEC and ELITEXPLOIT, using handles including @BYTEXPLOIT and @YourMindFvcker. Members reportedly used applications such as Termux and Pydroid3, sourcing DDoS scripts from GitHub, and then verifying site outages through CheckHost.net.

On 7 May 2025 alone — the day Operation Sindoor was launched — the group allegedly planned attacks against 20 Indian government and state government websites. Their Telegram channel carried messages including: 'Several Government sites of India has been touch by AnonSec..!', 'Hi, India we just took down your financial shield and servers', and 'India may have started it, but we will be the ones to finish it.'

What Investigators Found — and What They Did Not

Gujarat ATS SP K. Siddharth told reporters that while the accused ran scripts generating traffic toward targeted sites, their mobile phone-based setup lacked the computational capacity to sustain attacks powerful enough to overpower government infrastructure. 'They were not breaching per se, it was an attempt to take down the websites,' Siddharth said, drawing a clear distinction between a DDoS attempt and a data breach.

A website becoming temporarily inaccessible was interpreted by the accused as evidence of a successful takedown. Investigators, however, said the intent, coordination, and tools were what drove the prosecution. 'The material recovered from the accused's phones, including chats, screenshots and communications, established their intention to target Indian websites,' Siddharth noted.

Notably, the Telegram group reportedly had members from several nationalities, including Bangladesh and Palestine. However, Siddharth was explicit that the Gujarat ATS investigation did not establish a specific conspiracy linking Pakistan to the attacks. 'There was no specific conspiracy which we could figure out that Pakistan was behind this,' he said.

Legal Framework and Profile of the Accused

The case was initially registered under Sections 43 and 66(F) of the Information Technology Act before being taken over by the NIA. On 14 August last year, the NIA filed a charge sheet against Ansari, alleging he conspired with a juvenile to launch multiple DDoS attacks on Central and state government websites between March and May 2025.

Investigators chose not to invoke the Unlawful Activities (Prevention) Act (UAPA), with Siddharth explaining that the accused were not found to have been traditionally radicalised. 'That is why we did not register under UAPA or anything,' he said. The accused were young individuals who had acquired technical knowledge largely through freely available online resources, conducting their operations primarily through mobile phones — a method that made detection by family members difficult.

Broader Security Implications

The cyber campaign unfolded against the backdrop of the 22 April 2025 terror attack in Pahalgam, Jammu and Kashmir, in which 26 people — including a Nepali citizen — were killed. That attack triggered a series of diplomatic and security measures, culminating in Operation Sindoor, during which Indian forces struck nine terrorist infrastructure sites in Pakistan and Pakistan-occupied Kashmir on the intervening night of 6–7 May 2025.

The Ministry of Defence described the strikes as 'focussed and non-escalatory'. A period of escalation followed, including Pakistani drone and missile attempts against Indian military targets and heavy firing along the Line of Control, before both sides agreed on 10 May to halt military actions on land, air, and sea.

The NIA's continuing searches across five states signal that the investigation remains active — focused not just on the original accused but on the broader network that allegedly supported them. Whether the attacks succeeded or not, the case has laid bare a form of digital vulnerability that emerged at one of India's most consequential security junctures in recent memory.

Point of View

The timing, and the cross-border composition of the Telegram group warranted NIA-level attention. What is more troubling than the DDoS attempts themselves is how easily young, non-radicalised individuals can be drawn into acts of digital disruption during moments of national crisis. The decision not to invoke UAPA is legally defensible, but it also signals that India's legal architecture for low-sophistication, high-intent cyber threats remains underdeveloped — a gap that adversaries, state-linked or otherwise, may find increasingly useful to exploit.
NationPress
31 Aug 2026

Frequently Asked Questions

What were the cyber attacks during Operation Sindoor?
During Operation Sindoor in May 2025, a group called Anonsec attempted DDoS attacks on 54 Central government websites, including systems classified as Critical Information Infrastructure. The attacks were timed to coincide with India's military strikes against terrorist sites in Pakistan and Pakistan-occupied Kashmir.
Who is Jasim Shahnawaz Ansari and what is his role in the case?
Jasim Shahnawaz Ansari is an 18-year-old from Nadiad in Gujarat's Kheda district, identified as the primary accused in the NIA's cyber terrorism case. He allegedly conspired with a juvenile to launch multiple DDoS attacks on Central and state government websites between March and May 2025, operating through a Telegram group called Anonsec.
Did the cyber attacks successfully bring down Indian government websites?
According to Gujarat ATS SP K. Siddharth, the accused did not possess sufficient computing power to cause sustained disruption to government infrastructure. Their mobile phone-based setup could generate traffic but not overwhelm the targeted systems; a site becoming temporarily inaccessible was mistaken by the group for a successful takedown.
Why did the NIA conduct searches across five states in August?
The NIA's searches on 24 August across Maharashtra, Gujarat, Telangana, Bihar, and Delhi were aimed at suspects identified through technical analysis as having allegedly provided support to the primary accused. The searches yielded three laptops, five mobile phones, pen drives, and other digital evidence.
Was Pakistan found to be behind the Operation Sindoor cyber attacks?
No. Gujarat ATS SP K. Siddharth explicitly stated that investigators did not establish a specific conspiracy linking Pakistan to the attacks. The Telegram group reportedly included members from Bangladesh and Palestine, but the investigation pointed to a loosely organised network rather than a state-directed operation.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 6 days ago
  2. 4 weeks ago
  3. 9 months ago
  4. 1 year ago
  5. 1 year ago
  6. 1 year ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google