Ransomware claims against Indian firms tripled in a month

Ransomware crews have listed 35 Indian organizations on their extortion sites in the past 30 days, more than three times the 11 they listed in the month before. India now sits fourth in the leak-site claims IntelFusions records, behind only the United States, the United Kingdom and Germany, and ahead of Canada, Italy and France.

Fifteen of those 35 claims landed in the last seven days alone. None of them is a confirmed breach. Every figure here comes from posts the extortionists wrote themselves, and that caveat carries through the whole story.

Who is being named

The victims are overwhelmingly mid-market companies rather than names a general reader would recognize. Technology firms account for 10 of the 35 claims and manufacturers for 9, with healthcare providers taking another 5 and financial services 2. The rest are scattered across transport, retail and professional services.

No single crew is driving it

Sixteen different crews are behind the 35 claims, up from nine the month before. The most active, The Gentlemen, accounts for 8, which is still under a quarter of the total. Cl0p follows with 4, then NightSpire, Krybit and Everest with 3 each. The remaining 11 crews posted one or two victims apiece, among them LockBit, Qilin, INC Ransom, DragonForce and KillSec.

That spread is the point. A jump driven by one gang would suggest a single campaign, or an affiliate who happens to be working Indian targets this month. A jump spread across 16 crews, including several that only surfaced this year, points instead at a broad rise in how often Indian companies are ending up on leak sites at all. We saw a comparable regional pattern in Southeast Asia and among Latin America's public bodies in recent weeks.

Read these claims carefully

A leak-site listing is an unverified claim, not a confirmed intrusion. Crews inflate, recycle and occasionally invent victims, and the posts say nothing about how the attackers got in or whether any data was actually taken. The country and sector labels come from the trackers and from our own classification of each named organization, and they are imperfect: at least one company posted in this window and tagged to India is in fact headquartered in Belgium. The underlying posts sit on Tor hidden services, which IntelFusions does not link. Leak-site data also measures what criminals choose to publish, not where attacks actually happen.

Why it matters now

India is in the middle of enforcing the Digital Personal Data Protection Act 2023 and its 2025 Rules, and the Data Protection Board of India is now actively adjudicating breaches. An organization that turns up on a leak site is not only facing an extortion demand; it may also owe its regulator an account of what happened. CERT-In remains the national coordination point for incident response. Our India country profile carries the regulatory detail.

What defenders should do

The exposure here is concentrated in mid-sized Indian firms and their suppliers, many of which sit inside the supply chains of far larger customers abroad. Security teams should be checking the leak sites for their own name and their vendors' names rather than waiting for a ransom note, and should treat a supplier's listing as a live third-party risk question even while the claim is unverified. Confirm that backups are current and restorable, and that incident response and legal contacts are reachable out of hours. If a listing does turn out to be real, regulatory reporting obligations start running alongside the technical response, not after it.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions