CERT-In: Cyber threats for fin, healthcare stay elevated

India’s Critical Sectors Face Persistent Cyber Threats; AI Risks Integrated into Preparedness Drills

The healthcare sector recorded another 18,855 instances in the first six months, equivalent to nearly 55% of the 34,480 detected and mitigated during all of 2025.

NEW DELHI: India’s critical finance and healthcare sectors continue to grapple with a high volume of cyber threat activity in the first half of 2026. Data presented by the government in Parliament reveals that detections for this period have already surpassed 60% of the total levels recorded throughout the entirety of the previous year, underscoring the persistent and evolving landscape of cyber risks facing the nation.

Finance Sector Under Constant Barrage

The Computer Emergency Response Team – India (CERT-In) reported a staggering almost 3.5 lakh instances of malicious scanning, probing, and vulnerable services detected and mitigated within the finance sector between January and June 2026. This figure represents a significant portion when compared to the 5.7 lakh instances observed during the whole of 2025, indicating that the sector remains a prime target for cyber adversaries.

Healthcare Sector: A Vulnerable Target

The healthcare sector also experienced a substantial number of incidents, with CERT-In recording 18,855 instances in the first six months of 2026. This volume alone constitutes nearly 55% of the 34,480 instances detected and mitigated throughout all of 2025. Combined, the finance and healthcare sectors accounted for just under 3.7 lakh cyber threat instances in the first half of the current year, highlighting their heightened vulnerability.

Key Data Points (H1 2026 vs. Full Year 2025):

  • Finance Sector: ~3.5 lakh instances (H1 2026) vs. 5.7 lakh instances (2025)
  • Healthcare Sector: 18,855 instances (H1 2026) vs. 34,480 instances (2025)
  • Total (Finance + Healthcare): Just under 3.7 lakh instances (H1 2026)

Interestingly, while general cyber threat activity escalated, targeted intrusion campaigns against banks did not exhibit a similar increase. CERT-In detected and mitigated 17 such campaigns during January-June 2026, a decrease when compared to the 39 campaigns reported during the entire year of 2025. This suggests a potential shift in attacker tactics or a more diffuse, broader scanning approach rather than highly specialized, persistent bank-specific intrusions for this period.

Bolstering Critical Infrastructure Cybersecurity Preparedness

In response to the persistent threat landscape, the government data also shed light on extensive cybersecurity preparedness exercises for critical infrastructure. CERT-In conducted two significant exercises for the power sector in H1 2026. These drills involved a remarkable 274 participants from 103 organizations, encompassing vital entities such as utilities, system operators, and generation, transmission, and distribution companies.

This represents a substantial expansion in participation and scope compared to 2025, when CERT-In conducted three power-sector cybersecurity exercises involving 150 participants from 30 organizations. The increased engagement underscores a growing recognition of the interconnectedness and systemic importance of the power grid.

Addressing Frontier AI Risks

A particularly significant development in these preparedness efforts is the integration of emerging cybersecurity risks posed by frontier AI models. One of the power sector exercises specifically focused on countering these advanced AI-linked threats. This inclusion signals a forward-looking approach by Indian cybersecurity authorities, acknowledging that sophisticated AI systems, while offering immense potential, also introduce new and complex vulnerabilities that require proactive defense strategies.

The proactive step to incorporate AI-related threats into critical infrastructure preparedness drills highlights India’s commitment to staying ahead of the evolving cyber threat landscape, ensuring resilience against not only current but also future sophisticated attacks.

Source: Government data shared in Parliament.

Leave a Reply

Your email address will not be published. Required fields are marked *