DRDO Refutes Claims of 31 GB Data Breach for Sale on Dark Web

ALN NEWS DESK
ALN NEWS DESK
Updated : Jul 29, 2026, 12:12 PM IST
5 min read
  • linkedin
  • twitter
  • facebook
  • instagram
  • whatsapp

The Defence Research and Development Organisation (DRDO) has denied allegations of a 31 GB data breach, asserting that the claims are false and based on outdated information.

Thiruvananthapuram: The Defence Research and Development Organisation (DRDO) on Wednesday denied reports claiming that around 31 GB of its data had been stolen and put up for sale on the dark web, describing the claims as false and unverified.

The clarification came after the Thiruvananthapuram-based Alibi Global Threat Intelligence Group claimed that approximately 31 GB of DRDO data, including sensitive information, was being offered for sale on the dark web. This assertion raised alarm bells within both the defense community and the general public, as any potential breach of sensitive government data could have far-reaching implications for national security.

In the age of digital warfare and cyber espionage, governments and organizations are increasingly vulnerable to cyber threats. The rise of the dark web has made it easier for malicious actors to sell stolen data, which can include anything from personal information to classified government documents. The DRDO, being a pivotal organization in India's defense research, is often a target for such attacks, making the integrity and security of its data a matter of utmost importance.

Responding to the claims, DRDO stated that a detailed investigation had found that the data 'alleged to be leaked' was unclassified and did not contain confidential information. This distinction is crucial, as unclassified data, while potentially sensitive, does not carry the same weight of risk as classified information. The organization emphasized that the integrity of its data protection measures remains intact.

"Certain unclassified data that is being shown as critical is from an old data breach of 2020-2022 vintage," the organisation said in a statement. This statement suggests that the data in question may not be new or relevant, but rather a rehash of previously compromised information. Such situations are not uncommon in the realm of cybersecurity, where old data breaches can resurface, often misrepresented as new threats.

DRDO further elaborated that some documents had been fabricated to make the data appear confidential. Fabrication of documents is a tactic often employed by cybercriminals to enhance the perceived value of stolen data. By presenting outdated or irrelevant documents as current and critical, these actors aim to instill fear and urgency, thereby increasing the likelihood of financial gain through ransom or sale. The organization also added that the documents being circulated were outdated and no longer relevant. "The relevance of this outdated documentation has been evaluated and is no longer applicable. The claims, therefore, made are unverifiable," it said.

According to DRDO, its investigation found that the same dataset was being offered for sale by multiple threat actors. This indicates a coordinated effort among cybercriminals to exploit perceived vulnerabilities within the organization. "The data being sold is the same across these threat actors and bears no current relevance to the department and the ministry," DRDO said. The repeated mention of the data's irrelevance underscores the organization's commitment to ensuring that its operations and data management practices are secure and robust against potential cyber threats.

Financial motives, DRDO said, may be behind such a move. The intersection of cybersecurity and financial crime is a growing concern, as cybercriminals increasingly target organizations not just for data theft but for monetary gain. "The allegedly leaked data has been deliberately fabricated by the threat actors, motivated by financial gains, to cause panic, collect larger sums of money for the data and appear authentic," the statement said. This revelation highlights the need for organizations to remain vigilant and proactive in their cybersecurity measures, as the motivations of cybercriminals can often drive them to create elaborate schemes to exploit fear.

DRDO reiterated that there is no evidence of any active cyber attack, unauthorized network intrusion, or ongoing data exfiltration. This assertion is significant, as it not only reassures stakeholders of the organization's security posture but also reflects the effectiveness of its internal monitoring and response mechanisms. In an era where cyber threats are constantly evolving, the ability to detect and respond to potential breaches is crucial for any organization, particularly one involved in national defense.

The incident underscores the importance of cybersecurity awareness and education within organizations. As cyber threats continue to evolve, so too must the strategies employed to combat them. Organizations like DRDO must invest in robust cybersecurity frameworks that include regular training for employees, updated security protocols, and the use of advanced technologies to detect and mitigate threats.

Moreover, the situation raises questions about the role of threat intelligence firms, like Alibi Global Threat Intelligence Group, in reporting potential breaches. While their work is invaluable in identifying and alerting organizations to potential threats, the accuracy and reliability of their claims are paramount. False reports can lead to unnecessary panic and resource allocation, diverting attention from genuine threats.

As the digital landscape continues to expand, the implications of data breaches extend beyond immediate financial losses. They can impact public trust in institutions, especially those tasked with national security. The DRDO's swift response to these claims not only aims to protect its reputation but also to maintain public confidence in its ability to safeguard sensitive information.

In conclusion, while the claims of a data breach at DRDO have been categorically denied, the incident serves as a reminder of the persistent threat posed by cybercriminals. It highlights the need for continuous vigilance, proactive cybersecurity measures, and the importance of verifying information before it is disseminated. As organizations navigate the complexities of the digital age, the balance between innovation and security will remain a critical focus for entities like the DRDO.

Get More Updates

To learn more about the latest developments in Crime & Law, stay updated with our exclusive reports and analyses on AiLensNews.

Related News