Cyber

Suspected DRDO data breach: Stolen missile sensor files reportedly listed for sale on dark web, organization rejects claims

A threat actor is selling 31GB of data allegedly stolen from DRDO on the dark web for $8,000, including files said to detail missile guidance sensor electronics, although investigators are yet to confirm the breach or establish when the data was exfiltrated.
Suspected DRDO data breach: Stolen missile sensor files reportedly listed for sale on dark web, organization rejects claims

RNA illustration for representation.

Avatar photo
  • Published July 28, 2026 10:20 am
  • Last Updated July 29, 2026

New Delhi: A threat actor is offering 31 gigabytes of data allegedly stolen from the Defence Research and Development Organisation (DRDO) for sale on a dark web forum. The listing, priced at $8,000, has raised fresh questions about data security at India’s premier defence research body, the Week reported.

According to the report, the seller has published sample files said to detail the internal electronics architecture of an advanced guidance sensor used in precision-guided missiles and smart munitions. If genuine, such documentation would offer insight into how India’s guided weapons find and track their targets.

Agencies flag breach

Intelligence agencies picked up on the listing last Saturday and have since begun assessing its authenticity and scope. DRDO itself is yet to issue a public statement confirming or denying the breach, according to the Week.

Complicating the assessment is the age of the sample material. The documents put up for sale are dated 2020, meaning the underlying data could have been sitting with the threat actor, or changing hands among cybercriminals, for years before surfacing now.

A senior intelligence official told the Week that what has surfaced now could even stem from an old breach, noting that ransomware groups often steal data and release it in phases to extort money. The official spoke on condition of anonymity.

Investigators say establishing exactly when the exfiltration occurred – and whether it originated from DRDO’s own networks or from a third party with access to its files – will require a full forensic examination of the dataset, not merely the sample documents released so far. Staggered releases of this kind are a familiar tactic among ransomware and extortion groups.

Such groups often hold back the bulk of stolen material to sustain leverage over a victim, or to test buyer interest before a fuller sale.

Pattern of DRDO-linked leaks

This is not the first time material purportedly linked to DRDO has surfaced on dark web marketplaces. In March 2025, a group calling itself Babuk Locker 2.0 claimed to have exfiltrated 20 terabytes of data from DRDO, including engineering drawings and details of India’s defence partnerships with several countries, according to reports at the time by ThePrint, VarIndia and Indian Defence News.

DRDO denied any breach of its own systems at the time. A subsequent assessment cited by ThePrint, attributed to the cybersecurity firm Athenian Tech, traced that leak instead to a former defence ministry official’s personal device rather than to DRDO’s secured infrastructure.

Whether the present listing is connected to that episode, or is an entirely separate incident, has not been established.


Also read: Kudankulam nuclear project data leaked online, but reactors safe, says NPCIL


Cybersecurity gaps persist

The latest episode has reopened concerns about data governance across India’s critical government establishments. Repeated advisories on cybersecurity protocol compliance appear to have had uneven effect, intelligence officials told the Week.

A senior cyber intelligence expert, also cited by the Week, said that if a breach had indeed occurred, it would likely point to serious lapses. The expert added that while cybersecurity has improved over the years, there is no such thing as perfect security, and organizations must remain constantly vigilant and keep strengthening their defences.

The same expert noted that authorities are separately examining a suspected major data breach at a leading public sector bank. This suggests the DRDO episode is not an isolated case but part of a broader pattern of attempted intrusions into Indian institutional systems.

The expert further observed that although awareness of cybersecurity is improving, organizations and their boards must invest far more in cyber resilience. IT infrastructure needs continuous upgrades, and software must be kept fully patched – the expert questioned how many organizations were actually doing that.

For now, the central unresolved question is provenance: whether genuine DRDO material has actually been compromised, or whether older, previously circulated files are being repackaged and resold to credulous buyers on the dark web. Cybersecurity researchers say this practice is common among opportunistic threat actors seeking quick payouts.

A fuller picture is likely to emerge only once investigators have examined the complete 31GB dataset rather than the curated sample currently in circulation.

Update: DRDO calls cyber-breach reports ‘incorrect and unverified’

The Defence Research and Development Organisation (DRDO) has rejected reports of a fresh cyberattack on its systems, calling media coverage of an alleged data breach “incorrect and unverified”.

In a statement issued on Wednesday, DRDO said a “thorough investigation” into the alleged breach had been carried out by relevant agencies at the level of the Ministry of Defence. It found no evidence of any active cyberattack, unauthorized network intrusion or ongoing data exfiltration.

What the investigation found

According to the statement, most of the data alleged to have been leaked is unclassified and carries no confidentiality. Some of the material being presented as sensitive, it said, actually dates back to an older breach from 2020-22, with threat actors having “deliberately and evidentially fabricated” the documents to make them look recent and confidential.

DRDO added that all the documents cited in the alleged leak are outdated, have gone through multiple revisions since, and no longer reflect current configurations, making the claims around them unverifiable.

The organization said its investigation traced the data to several threat actors, all offering identical material. DRDO assessed that this data holds no current relevance to the department or the ministry, and that the actors involved were financially motivated – fabricating the leak to generate panic, inflate its perceived value and make it appear authentic to prospective buyers.

Avatar photo
Written By
RNA Desk

RNA Desk is the collective editorial voice of RNA, delivering authoritative news and analysis on defence and strategic affairs. Backed by deep domain expertise, it reflects the work of seasoned editors committed to credible, impactful reporting.

Leave a Reply

Your email address will not be published. Required fields are marked *