Suspected DRDO data breach: Stolen missile sensor files reportedly listed for sale on dark web
RNA illustration for representation.
New Delhi: A threat actor is offering 31 gigabytes of data allegedly stolen from the Defence Research and Development Organisation (DRDO) for sale on a dark web forum. The listing, priced at $8,000, has raised fresh questions about data security at India’s premier defence research body, the Week reported.
According to the report, the seller has published sample files said to detail the internal electronics architecture of an advanced guidance sensor used in precision-guided missiles and smart munitions. If genuine, such documentation would offer insight into how India’s guided weapons find and track their targets.
Agencies flag breach
Intelligence agencies picked up on the listing last Saturday and have since begun assessing its authenticity and scope. DRDO itself is yet to issue a public statement confirming or denying the breach, according to the Week.
Complicating the assessment is the age of the sample material. The documents put up for sale are dated 2020, meaning the underlying data could have been sitting with the threat actor, or changing hands among cybercriminals, for years before surfacing now.
A senior intelligence official told the Week that what has surfaced now could even stem from an old breach, noting that ransomware groups often steal data and release it in phases to extort money. The official spoke on condition of anonymity.
Investigators say establishing exactly when the exfiltration occurred – and whether it originated from DRDO’s own networks or from a third party with access to its files – will require a full forensic examination of the dataset, not merely the sample documents released so far. Staggered releases of this kind are a familiar tactic among ransomware and extortion groups.
Such groups often hold back the bulk of stolen material to sustain leverage over a victim, or to test buyer interest before a fuller sale.
Pattern of DRDO-linked leaks
This is not the first time material purportedly linked to DRDO has surfaced on dark web marketplaces. In March 2025, a group calling itself Babuk Locker 2.0 claimed to have exfiltrated 20 terabytes of data from DRDO, including engineering drawings and details of India’s defence partnerships with several countries, according to reports at the time by ThePrint, VarIndia and Indian Defence News.
DRDO denied any breach of its own systems at the time. A subsequent assessment cited by ThePrint, attributed to the cybersecurity firm Athenian Tech, traced that leak instead to a former defence ministry official’s personal device rather than to DRDO’s secured infrastructure.
Whether the present listing is connected to that episode, or is an entirely separate incident, has not been established.
Also read: Kudankulam nuclear project data leaked online, but reactors safe, says NPCIL
Cybersecurity gaps persist
The latest episode has reopened concerns about data governance across India’s critical government establishments. Repeated advisories on cybersecurity protocol compliance appear to have had uneven effect, intelligence officials told the Week.
A senior cyber intelligence expert, also cited by the Week, said that if a breach had indeed occurred, it would likely point to serious lapses. The expert added that while cybersecurity has improved over the years, there is no such thing as perfect security, and organizations must remain constantly vigilant and keep strengthening their defences.
The same expert noted that authorities are separately examining a suspected major data breach at a leading public sector bank. This suggests the DRDO episode is not an isolated case but part of a broader pattern of attempted intrusions into Indian institutional systems.
The expert further observed that although awareness of cybersecurity is improving, organizations and their boards must invest far more in cyber resilience. IT infrastructure needs continuous upgrades, and software must be kept fully patched – the expert questioned how many organizations were actually doing that.
For now, the central unresolved question is provenance: whether genuine DRDO material has actually been compromised, or whether older, previously circulated files are being repackaged and resold to credulous buyers on the dark web. Cybersecurity researchers say this practice is common among opportunistic threat actors seeking quick payouts.
A fuller picture is likely to emerge only once investigators have examined the complete 31GB dataset rather than the curated sample currently in circulation.