News

Banking and Healthcare Sectors Saw Over 9.7 Lakh Cyber Incidents: Parliament

Banks and healthcare institutions faced over nine lakh attempts to scan systems, probe weaknesses and exploit vulnerable services over 18 months

AI generated
Banking, Healthcare Sectors Face 9.7 Lakh Cyber Incidents Photo: AI generated
info_icon
Summary

Summary of this article

  • Banking sector recorded the highest number of cyber incidents.

  • Healthcare institutions also faced thousands of cyber security incidents.

  • RBI and government agencies are strengthening cyber fraud safeguards.

On Friday, the Parliament was informed that more than 9.7 lakh cyber security incidents were recorded across India's banking and healthcare sectors during 2025 and the first half of 2026.

Union Minister of State for Electronics and Information Technology Jitin Prasad shared data related to incidents detected and mitigated by the Indian Computer Emergency Response Team (CERT-In). The data was presented in the Rajya Sabha in response to a question on breaches involving critical information infrastructure.

The banking and healthcare sectors together recorded 6,04,588 incidents in 2025 and another 3,67,462 between January and June 2026. The incidents covered malicious scanning, probing and vulnerable services.

Banking Sector Bears The Brunt

In the healthcare sector, CERT-In detected 34,480 incidents in 2025 and 18,855 cases between January and June 2026. Malicious scanning and probing accounted for 32,297 incidents in 2025 and 18,259 cases in the first half of 2026.

On the other hand, the banking sector accounted for the highest number of incidents, with CERT-In detecting 5,70,108 cases in 2025 and 3,48,607 between January and June 2026.

The finance sector suffered 4,70,445 incidents of malicious scanning and probing in 2025. In January-June 2026, as many as 3,09,288 such cases were reported.

Incidents involving vulnerable services stood at 99,663 in 2025 and 39,319 in the first six months of 2026. These incidents involved weaknesses caused by incorrect system settings, unsecured application programming interfaces (APIs) and outdated software.

Separately, CERT-In detected 39 targeted intrusion campaigns in the banking sector during 2025 and another 17 between January and June 2026.

Six-Hour Reporting Requirement

CERT-In is the national agency for responding to cybersecurity incidents under Section 70B of the Information Technology Act, 2000. It monitors threats, exchanges cyber intelligence and works with organisations, regulators and law enforcement agencies during incident responses.

The National Cyber Coordination Centre monitors cyberspace for threats and passes relevant information to government departments, state governments and other stakeholders.

Under cyber security directions issued in April 2022, companies must report specified cyber incidents to CERT-In within six hours of noticing them.

CERT-In also conducted three cybersecurity exercises for the power sector in 2025. The agency is now examining cyber risks linked to frontier artificial intelligence models.

The Cyber Swachhta Kendra provides tools for detecting and removing malicious programs and publishes cyber security guidance for citizens and organisations.

Government Cyber Security Measures

The government and regulators have taken several steps recently to deal with rising cyber threats. In March 2026, the Reserve Bank of India (RBI) revised rules for unauthorised digital banking transactions. The changes include measures to improve fraud detection and check the use of mule accounts.

CERT-In has also issued new guidelines on cyber risks linked to artificial intelligence. The guidelines cover vulnerabilities that could be exploited with the help of AI and measures organisations can take to respond to such attacks.

Published At:
CLOSE