Massive DRDO Data Leak, nearly 20 TB of Data on Sale
In Short
• Data leak includes DRDO information, posing security risks
• Ransomware group Babuk Locker 2.0 claims responsibility of leak
• Data linked to former Defence Ministry official Puneet Agarwal
A tranche of sensitive defence data – that includes engineering design of a weapon, details of a new Air Force facility, procurement plans, and India’s strategic collaborations with other countries – was allegedly stolen by a hacker group and put on sale.
The leaked data belongs to the Defence Research and Development Organisation (DRDO), a government agency which doesn’t even allow scientists and staff to carry their personal mobile phones inside certain premises.
The data appeared to have been stolen from the device of a former Defence Ministry official, as per an analysis by cybersecurity firm Athenian Tech. It also included evacuation protocols for the President, the Prime Minister and other VVIPs in case of an aerial attack, posing a serious national security risk.
DRDO officials, however, have denied any breach of the data of the defence research organisation. They said that the data didn't belong to their organisation. However, they didn't provide any further clarification about the alleged leak.
A SERIOUS BREACH
The leak was announced by ransomware group Babuk Locker 2.0 on March 10, 2025. The group said it had exfiltrated 20 terabytes of data from DRDO’s systems, including classified defence documents and a vast repository of credential logs. It publicly released 753 MB of the data leak sample.
Among other sensitive information, the sample also included files related to upgradation of T9 Bhishma Tank and contains details about India’s defence collaborations with countries such as Finland, Brazil, and the United States of America.
Athenian Tech released screenshots of their chat with Babuk Locker 2.0 showing the hackers conversing in Indonesian language, indicating that they could potentially belong to Indonesia.
After an analysis, the firm, however, concluded that the ransomware group’s claims about the scale of the breach could be exaggerated. Its report said much of the leaked data appeared to be linked to Puneet Agarwal, who served as Joint Secretary in the Defence Ministry between 2019 and 2021. Details of his Aadhaar, financial records and personal travel documents were present in the leaked data, suggesting the breach didn’t stem from DRDO’s core IT infrastructure.
SECURITY IMPLICATIONS
Given its sensitive nature, the data leak raises urgent concerns about cybersecurity vulnerabilities, insider threats, and the resilience of India’s critical defence infrastructure against sophisticated cyber adversaries.
"The exposure of confidential defence files — even from a single system — highlights an urgent need for stringent cybersecurity measures, improved access controls, and proactive monitoring to prevent further exposures of critical defence data," said the report.
The presence of sensitive defence files on a personal system indicates potential lapses in endpoint security, inadequate data handling policies or their implementation, and the risks posed by officials storing sensitive information outside secured networks.
The security implication could be severe if the hackers indeed had access to the credential repository. Credentials could be misused to further gain access to other systems and sensitive data.
https://www.indiatoday.in/india/sto...defence-data-leaked-report-2700673-2025-03-28