Op Sindoor cyber threat: 54 govt sites targeted, NIA widens probe
Synopsis
Key Takeaways
Even as the Indian Armed Forces executed Operation Sindoor on 7 May 2025, a parallel assault was unfolding in cyberspace — one that investigators have since described as an attempted act of 'cyber terrorism'. Coordinated Distributed Denial-of-Service (DDoS) attacks were directed at 54 Central government websites, including systems classified as Critical Information Infrastructure (CII), in what authorities say was a deliberate attempt to destabilise India's digital backbone during a period of active military engagement.
NIA Widens the Investigation
More than a year after the Gujarat Anti-Terrorist Squad (ATS) first cracked the case, the National Investigation Agency (NIA) has significantly expanded its probe. On 24 August, NIA teams conducted simultaneous searches at five locations spanning Maharashtra, Gujarat, Telangana, Bihar, and Delhi — specifically in Junnar (Pune district), Nadiad (Kheda district), Ramagundam (Karimnagar district), Gopalganj, and Delhi.
The searches yielded three laptops, five mobile phones, pen drives, and documents containing allegedly incriminating material linked to hacking activities. Suspects identified through technical analysis for allegedly providing support to the primary accused were also examined during the operation.
The Anonsec Telegram Network
At the centre of the investigation is Jasim Shahnawaz Ansari, an 18-year-old from Nadiad, and a juvenile — both allegedly members of a Telegram group called Anonsec. The Gujarat ATS had been monitoring anti-national activity on social media and the Dark Web when intelligence pointed to the duo's involvement.
The group had previously operated through Telegram channels named EXPLOITXSEC and ELITEXPLOIT, using handles including @BYTEXPLOIT and @YourMindFvcker. Members reportedly used applications such as Termux and Pydroid3, sourcing DDoS scripts from GitHub, and then verifying site outages through CheckHost.net.
On 7 May 2025 alone — the day Operation Sindoor was launched — the group allegedly planned attacks against 20 Indian government and state government websites. Their Telegram channel carried messages including: 'Several Government sites of India has been touch by AnonSec..!', 'Hi, India we just took down your financial shield and servers', and 'India may have started it, but we will be the ones to finish it.'
What Investigators Found — and What They Did Not
Gujarat ATS SP K. Siddharth told reporters that while the accused ran scripts generating traffic toward targeted sites, their mobile phone-based setup lacked the computational capacity to sustain attacks powerful enough to overpower government infrastructure. 'They were not breaching per se, it was an attempt to take down the websites,' Siddharth said, drawing a clear distinction between a DDoS attempt and a data breach.
A website becoming temporarily inaccessible was interpreted by the accused as evidence of a successful takedown. Investigators, however, said the intent, coordination, and tools were what drove the prosecution. 'The material recovered from the accused's phones, including chats, screenshots and communications, established their intention to target Indian websites,' Siddharth noted.
Notably, the Telegram group reportedly had members from several nationalities, including Bangladesh and Palestine. However, Siddharth was explicit that the Gujarat ATS investigation did not establish a specific conspiracy linking Pakistan to the attacks. 'There was no specific conspiracy which we could figure out that Pakistan was behind this,' he said.
Legal Framework and Profile of the Accused
The case was initially registered under Sections 43 and 66(F) of the Information Technology Act before being taken over by the NIA. On 14 August last year, the NIA filed a charge sheet against Ansari, alleging he conspired with a juvenile to launch multiple DDoS attacks on Central and state government websites between March and May 2025.
Investigators chose not to invoke the Unlawful Activities (Prevention) Act (UAPA), with Siddharth explaining that the accused were not found to have been traditionally radicalised. 'That is why we did not register under UAPA or anything,' he said. The accused were young individuals who had acquired technical knowledge largely through freely available online resources, conducting their operations primarily through mobile phones — a method that made detection by family members difficult.
Broader Security Implications
The cyber campaign unfolded against the backdrop of the 22 April 2025 terror attack in Pahalgam, Jammu and Kashmir, in which 26 people — including a Nepali citizen — were killed. That attack triggered a series of diplomatic and security measures, culminating in Operation Sindoor, during which Indian forces struck nine terrorist infrastructure sites in Pakistan and Pakistan-occupied Kashmir on the intervening night of 6–7 May 2025.
The Ministry of Defence described the strikes as 'focussed and non-escalatory'. A period of escalation followed, including Pakistani drone and missile attempts against Indian military targets and heavy firing along the Line of Control, before both sides agreed on 10 May to halt military actions on land, air, and sea.
The NIA's continuing searches across five states signal that the investigation remains active — focused not just on the original accused but on the broader network that allegedly supported them. Whether the attacks succeeded or not, the case has laid bare a form of digital vulnerability that emerged at one of India's most consequential security junctures in recent memory.