NIA probes cyberterror bid to cripple govt websites during Operation Sindoor
The National Investigation Agency (NIA) has launched an inquiry into a cyberterror case linked to attempted Distributed Denial of Service (DDoS) attacks on government websites during Operation Sindoor. As part of the investigation, the agency conducted coordinated searches across five states, officials familiar with the matter confirmed.
The case pertains to efforts by unidentified individuals or groups to overwhelm and disable official government web portals during the period of Operation Sindoor, a counter-terror operation conducted by Indian security forces. The searches were carried out at multiple locations in the five states, with teams of NIA officials and local police acting on intelligence inputs.
A DDoS attack works by flooding a website with an overwhelming volume of traffic, rendering it inaccessible to legitimate users. Such attacks, if successful, can disrupt crucial public services, including citizen-facing portals and emergency communication systems. In this case, the attempts were apparently thwarted or failed to cause major disruption, as the operation itself remained unaffected.
Operation Sindoor, named after the traditional vermilion mark, was aimed at neutralising terror infrastructure and sending a strong message against cross-border terrorism. During the operation, government websites became a target for cyber-activity designed to undermine public confidence and create chaos. While the identity and motive of the attackers are still under investigation, the NIA has registered a case under relevant sections of the Indian Penal Code and the Information Technology Act, including provisions related to cyberterrorism and waging war against the nation.
The NIA, which serves as the central counter-terrorism law enforcement agency, has been increasingly focused on cybersecurity threats in recent years. This investigation is seen as part of a broader effort to safeguard the country’s digital infrastructure from state-sponsored and non-state actors alike. Officials have indicated that the searches were part of an evidence-gathering exercise, with digital devices and documents being examined for potential leads.
The five states where the searches were conducted have not been officially named, but the operation underscores the pan-India reach of the investigation. The agency is believed to be coordinating with the Indian Computer Emergency Response Team (CERT-In) and other cybersecurity bodies to trace the origin of the attacks and identify the individuals involved.
This case also highlights the growing importance of cybersecurity in national defence. As the military operates on land, sea, and air, the digital frontier has become a key battleground. The attempted DDoS attacks during a sensitive military operation serve as a reminder that state and non-state actors may attempt to exploit vulnerabilities in public infrastructure to achieve their aims.
Further details about the investigation are awaited. The NIA has not yet issued a formal statement, and officials have urged the public to refrain from speculation. The agency is expected to release more information as the probe progresses, including any arrests made or connections established with overseas handlers.
In the meantime, cybersecurity experts have called for enhanced vigilance and stronger protective measures for government websites, especially during times of heightened national security operations. The incident has reignited discussions on the need for a dedicated cyber defence framework to protect critical information infrastructure.