
India’s Cyber Battlefield Reloaded: A Three-Year Analysis of CERT-In’s Threat Data (2022–2024)
Behind the rise of Digital India lies an invisible war. This blog decodes the evolving cyber threat landscape based on three years of data from CERT-In.
Executive Summary
India's rapid digitization is a double-edged sword—driving innovation but also amplifying cyber risks. This blog analyzes publicly available CERT-In data from 2022 to 2024, as reported in the APCERT Annual Report 2024, to highlight key trends in cyber incidents. With over 2 million incidents reported in 2024, scanning, malware, and outdated services are dominant threats. However, underreporting remains a serious concern. This post outlines pressing issues and offers context-sensitive recommendations for enterprises, MSMEs, and public entities.
Introduction
As India's digital infrastructure expands, so do opportunities for malicious actors. The evolution of APIs, online services, and smart city frameworks has made the nation a high-value cyber target. This blog evaluates three years of CERT-In incident data to uncover shifts in adversary behavior and advise on strengthening cyber resilience.
CERT-In Data: Year-over-Year Comparison
Year | Total Incidents | Unauthorized Scanning/Probing | Vulnerable Services | Virus/Malware | Phishing | Web Defacements |
2022 | 1,391,457 | 324,620 | 875,892 | 161,757 | 1,714 | 19,793 |
2023 | 1,592,917 | 447,720 | 941,592 | 184,131 | 869 | 10,665 |
2024 | 2,041,360 | 1,610,608 | 294,908 | 119,763 | 785 | 5,496 |

Key Insight: India witnessed a 47% rise in reported cyber incidents between 2022 and 2024.
Source: APCERT Annual Report 2024
Beyond the Numbers: The Invisible Threats
While CERT-In data provides a useful baseline, many attacks remain unreported due to:
- MSMEs lacking monitoring tools or cybersecurity literacy
- Organizations avoiding disclosure for reputational reasons
- Undetected breaches by advanced persistent threats (APTs)
Reports from DSCI and NASSCOM in 2024 reinforce the issue of significant underreporting. The DSCI–Seqrite India Cyber Threat Report 2025 states that India saw over 369 million malware detections in just one year, while highlighting underreporting among MSMEs and sectors with weak cyber hygiene. The CERT-In Digital Threat Report (2024) for BFSI also cites lack of reporting as a barrier to effective national defense. Though exact multipliers are not quantified, experts widely agree that the true scale of incidents may be significantly higher than official figures suggest.

Trends Breakdown: What’s Rising, What’s Falling
Threat Type | 2022 | 2023 | 2024 | Trend |
Unauthorized Scanning | 324,620 | 447,720 | 1,610,608 | ↑ Explosive Rise |
Vulnerable Services | 875,892 | 941,592 | 294,908 | ↓ Sharp Decline |
Malware Infections | 161,757 | 184,131 | 119,763 | ↓ Gradual Drop |
Phishing Attacks | 1,714 | 869 | 785 | ↓ Slow Decline |
Website Defacements | 19,793 | 10,665 | 5,496 | ↓ Steady Drop |

Interpretation: The surge in scanning suggests a rise in reconnaissance activity, while declines in phishing and defacements point toward more sophisticated, stealthy attacks.
What’s Fueling the Spike?
1. Unauthorized Scanning and Probing
- Increased use of bots and automation tools to identify vulnerable endpoints
- Often the precursor to ransomware, DDoS, or credential-stuffing attacks

2. Malware and Malicious Code
- Despite reduced volume, malware is becoming more evasive and persistent
- Newer variants include remote access trojans (RATs), keyloggers, and infostealers
Sector Spotlight: Web Applications Under Fire
India’s public-facing web apps—used by fintechs, government portals, and e-commerce—are being actively targeted. Common attack vectors include:
- Scanning & Probing: Exposed APIs, unprotected endpoints
- Vulnerable Services: Unpatched software components like Apache, PHP
- Malware Injections: Web shells, rogue scripts
- Phishing Pages: Spoofed login pages hosted on compromised domains
- Defacements: Exploiting CMS flaws or weak admin credentials
Key Insight: Many threats labeled as "network-based" begin with web app exploitation.
Recommendations for a Resilient Future
A. For All Organizations
- Deploy a Web Application Firewall (WAF):Choose tools with AI/ML-based detection and support for virtual patching
- Conduct Regular VAPT:Identify exploitable flaws before attackers do
- Monitor for Recon Activity:Detect early-stage probing and scanning
- Implement an Incident Response Plan (IRP):Clearly define roles, response protocols, and escalation paths
B. For MSMEs
- Leveragemanaged security providers to bridge skill gaps
- Useopen-source monitoring tools (e.g., Suricata, Snort)
- JoinCERT-In awareness programs and regional trainings
C. For Smart Cities and Public Sector
- Prioritizezero-trust architecture and segmented networks
- Secure IoT deployments and citizen-facing apps
- Engage inCERT-In simulations and joint exercises
Demystifying the Jargon
- WAF (Web Application Firewall):Filters and monitors HTTP traffic to and from a web service
- VAPT (Vulnerability Assessment and Penetration Testing):Evaluation process to find and fix security flaws
- L7 Attacks:Application-layer attacks targeting APIs, login pages, etc.
Final Thoughts: From Awareness to Action
India’s cyber threats are growing in complexity and frequency. With a strategic mix of visibility, automation, and awareness, organizations can defend against current and emerging risks. Proactive defense isn’t just good IT—it’s a national imperative.
Call to Action
Stay informed, stay secured. Refer to CERT-In's official website and partner with trusted cybersecurity advisors. Whether you’re an MSME, large enterprise, or public sector agency—cyber readiness starts with visibility and a plan.
References & Resources
- CERT-Inhttps://www.cert-in.org.in/
- India Cyber Security Report (NASSCOM-DSCI)
- Cyber Swachhta Kendra (CSK)
- OWASP Top 10 for Web App Security
- Source for 2024 data: APCERT Annual Report 2024, CERT-In Activity Report
- DSCI-Seqrite India Cyber Threat Report 2025
- CERT-In Digital Threat Report 2024 (BFSI)




