India is one of the most cyber-attacked nations. Here’s how AI adds another layer to the threat
India is one of the most cyber-attacked nations. Here's how AI adds another layer to the threat How is AI transforming cyber threats, in both speed and scale?
India is one of the most cyber-attacked nations. Here's how AI adds another layer to the threat How is AI transforming cyber threats, in both speed and scale?
Article outline
- What happened
- The key numbers
- Background
- Why it matters
- Official response
- The bottom line
Key points
- 6 min read New Delhi Aug 24, 2026 06: 06 AM IST.
- Cyber intelligence firm CloudSEK's 2024 report placed India as the second-most cyber-attacked nation after the US; its 2025 report placed India sixth.
- It discovered a 27-year-old vulnerability in OpenBSD, an operating system reputed to be highly security-hardened and widely employed to run firewalls and critical infrastructure.
- Countries with leading AI ecosystems gain a greater ability both to conduct sophisticated cyber campaigns and to defend against them.
- More significantly, AI is developing the ability to act as an autonomous agent that can identify, plan, adapt and carry out offensive cyber operations.
Countries with leading AI ecosystems gain a greater ability both to conduct sophisticated cyber campaigns and to defend against them. Photo: Generated using AI. Written by Anubha Gupta.
While ChatGPT did so in three, artificial Intelligence (AI) has reached mass adoption faster than any prior technology – the Internet took 15 years to reach a billion users.
This rapid adoption has major consequences for cybersecurity. AI is amplifying cyber threats at unprecedented speed, scale and sophistication throughout the cyber kill chain, from automated vulnerability discovery to AI-generated deepfakes and AI-enabled social engineering (using AI to trick/persuade residents to take harmful actions). More significantly, AI is developing the ability to act as an autonomous agent that can identify, plan, adapt and carry out offensive cyber operations.
But AI capabilities remain concentrated in particularly few countries. This raises pressing questions for India: how prepared is it to address AI-enabled cyber threats? What should India do to build the AI capabilities needed to secure its cyberspace? AI is transforming cybersecurity.
Cybersecurity was already lopsided, with a few countries holding far superior capabilities than the rest. Advances in frontier AI systems have pushed this further.
Reconnaissance, once dependent on humans gathering information regarding a target, is now automated and faster: research indicates ChatGPT models being applied to mine social media for precise details to craft AI-generated spear-phishing emails. AI is additionally generating real-time deepfakes, deepening confusion concerning what online content is authentic.
More dangerous capabilities have emerged at the weaponisation and command-and-control stage. One novel method is LLM-generated polymorphic malware – code that sizeable language models can autonomously generate, modify and restructure to suit the situation, unlike traditional malware. It relies on fixed signatures and predictable patterns. In September 2025, Anthropic asserted a Chinese state- group, "GTG-1002, " had allegedly employed Claude Code as an autonomous cyber agent throughout multiple stages of an attack – what Anthropic called the first noted case of an AI-orchestrated cyber-espionage campaign. Expert Explains AI is reshaping warfare: How India can keep pace.
Perhaps most consequential is the emerging ability of frontier AI models to autonomously identify software vulnerabilities at scale. Anthropic's latest frontier model, Claude Mythos Preview, has identified thousands of zero-day vulnerabilities – flaws previously unknown to developers – throughout major operating systems and browsers, numerous of them critical, and developed related exploits largely without human intervention.
Such vulnerabilities are especially dangerous for the Operational Technology and Industrial Control Systems that govern nuclear facilities, energy grids, pharmaceutical manufacturing, chemical processing, oil refineries and communication networks – infrastructure that grows more exposed as it integrates further with AI.
Old cyber defences will not hold against these new threats. Traditional antivirus, which looks for known malware fingerprints, and static security patches for known vulnerabilities are far less effective against malware that constantly changes and adapts.
Geopolitical imbalances in the global AI ecosystem. AI in cybersecurity, by contrast, enables real-time threat detection, automated response and large-scale data analysis, mitigating risks faster than traditional approaches.
Meanwhile, the real AI divide, then, is not only regarding who uses AI but who builds it, and which countries control its development.
Last month, the ransomware group World Leaks asserted to have stolen and posted data related to India's largest nuclear plant, Kudankulam, including blueprints of facility parts and supplier details. Cyber intelligence firm CloudSEK's 2024 report placed India as the second-most cyber-attacked nation after the US; its 2025 report placed India sixth.
Expert Explains As modern warfare transforms, the lessons now for Indian defence.
During Operation Sindoor, Pakistan-backed threat actors such as APT36 targeted India's critical sectors, including the Ministry of Defence, Army, Navy and DRDO, and for the first time, Bharat Operating System Solutions (BOSS) Linux. They additionally disrupted administration IT infrastructure such as the National Informatics Centre and targeted state-level educational and administration portals – exposing the vulnerability of India's critical infrastructure to coordinated offensive cyber operations.
Yet India's indigenous AI ecosystem remains incremental, lagging well behind the US and China throughout the AI stack – foundational models, GPUs, chip design and large-scale data-centre infrastructure – leaving it heavily dependent on the US and other technologically advanced countries.
Indian policymakers are aware of these stakes and have begun taking steps. Since 2025, adopted AI-driven threat detection, cyber resilience measures, trusted AI frameworks and citizen-centric malware mitigation, agencies like CERT-In have. In April, it issued an advisory for organisations to defend against AI-driven cyber risks. Some of the recommendations were regarding "removing unnecessary internet-facing services" and treating every newly discovered vulnerability as something that "could be exploited within hours, not weeks."
Taken together, the developments around india is one of the most cyber-attacked nations. Here's how AI adds point to a situation that is still moving, and the coming days should bring more clarity.




