
India recorded over 265 million cyber threat detections in a single year, according to the Seqrite India Cyber Threat Report 2026. The report, based on telemetry from 8 million endpoints, averages out to 505 detections every minute across Indian networks.
The Numbers Behind India’s Threat Landscape
Seqrite’s data shows 265.52 million threat detections during the assessment period, with trojans and file infectors accounting for 70% of all malware activity. Trojans alone hit 88.44 million detections, followed by file infectors at 71.09 million and worms at 13.81 million.
CERT-In, India’s national computer emergency response team, recorded over 29.44 lakh cybersecurity incidents in 2025. The average daily detections crossed 700,000 across protected endpoints.
March 2026 saw the highest detection volume during the reporting period. Mumbai, New Delhi, and Kolkata emerged as the most targeted cities in the country.
Operation Sindoor: APT Campaign Targets India
The report highlights Operation Sindoor as one of the most significant threats. It was a coordinated hybrid warfare campaign combining APT36, SideCopy, and hacktivist attacks targeting India’s defense and government networks.
SideCopy, a persistent APT group, continued evolving its tactics using MSI installers, sideloaded DLLs, and open-source remote access tools to target critical sectors.
Ransomware and Cryptojacking
Ransomware remained active across cloud and on-prem environments. The Xelera ransomware campaign used fake government job notifications as bait, deploying Python-based payloads and Discord-controlled data theft mechanisms.
Cryptojacking detections reached 6.5 million, while network-based exploit scans exceeded 9.2 million. WordPress plugins, Apache Tomcat, and SysAid were among the most frequently targeted systems.
Sector-Wide Impact
Education, healthcare, and manufacturing sectors absorbed 47% of the total threat volume. On-premises environments continued to bear the heaviest load at 91% of all detections.
The report also flags NFC relay attacks, token hijacking in payments, SVG file abuse in stealth attacks, and EDR freeze exploits as emerging threat vectors for 2026.
What Indian Enterprises Should Do
Seqrite recommends deploying zero-trust network access, adopting extended detection and response platforms, and investing in AI-driven threat intelligence. The report also emphasizes that employees remain the first line of defense through security awareness training.
FAQ
How many cyber attacks did India face in 2025?
Seqrite recorded 265.52 million threat detections across 8 million endpoints, averaging 505 detections per minute.
Which cities are most targeted by cyber attacks in India?
Mumbai, New Delhi, and Kolkata were identified as the most targeted cities in the Seqrite report.
What is Operation Sindoor?
A coordinated hybrid warfare campaign combining APT36, SideCopy, and hacktivist groups targeting India’s defense and government networks.
Which malware types are most common in India?
Trojans account for 88.44 million detections, followed by file infectors at 71.09 million. Together they make up 70% of all malware activity.
What sectors are most affected?
Education, healthcare, and manufacturing absorb 47% of the total threat volume in India.
