Data breach claims: DRDO says threat actors repackaged old data as confidential

#News Desk
Representative Image | Photo: Facebook/ DRDO
Representative Image | Photo: Facebook/ DRDO

New Delhi: The Ministry of Defence has dismissed media reports claiming a cybersecurity breach at the Defence Research and Development Organisation (DRDO), saying an investigation has found no evidence of an active cyber attack, unauthorised network intrusion or ongoing data theft.

The clarification came after reports in some sections of the media claimed that a threat actor was attempting to sell a large volume of DRDO data on the dark web following a suspected breach.

A senior official said the reports were "incorrect and unverified". Relevant agencies under the Ministry of Defence carried out a detailed investigation into the alleged incident before issuing the clarification.

Probe finds leaked data outdated and unclassified

According to officials, most of the data claimed to have been leaked is unclassified and does not contain confidential information.

They said some of the material being portrayed as "critical" actually originated from an older data breach dating back to 2020–2022. Threat actors had allegedly altered the documents to make them appear recent and confidential, the official added.

Officials also said all the documents linked to the alleged leak are outdated, have undergone multiple revisions and no longer reflect current systems or configurations.

The investigation further found that several threat actors were offering the same dataset for sale. However, officials said the material being circulated is identical across those listings and has no current relevance to either the DRDO or the Ministry of Defence.

They alleged that the documents had been deliberately fabricated or repackaged by threat actors seeking financial gain, with the aim of creating panic, increasing the perceived value of the data and making the claims appear authentic.