AI and Cyber Threats in India: Risks and Safeguards

AI and Cyber Threats in India: Risks and Safeguards

#GS-3 #Science & Technology #Cyber Security #Artificial Intelligence #Current Events #National

Key takeaways

  • Cyber intelligence firm CloudSEK ranked India as the 2nd most cyber-attacked nation globally in 2024 and 6th in 2025.
  • Generative AI reached 1 billion global users in 3 years, expanding offensive cyber capabilities far faster than past technologies.
  • Pakistan-backed threat group APT36 targeted strategic institutions like DRDO and NIC during Operation Sindoor.
  • Frontier AI models like Claude Mythos can autonomously identify software zero-day bugs across millions of lines of code in minutes.
  • India remains vulnerable due to its reliance on imported tech components and an underdeveloped domestic sovereign AI ecosystem.

Why in News

  • A recent cybersecurity analysis highlights how Artificial Intelligence is converting cyber attacks against India into automated, large-scale, and self-running campaigns.

Understanding AI and Cyber Threats

  • The combination of Artificial Intelligence and cyber threats involves using advanced Large Language Models (LLMs), machine learning, and autonomous AI agents for malicious attacks.
  • Attackers use AI to search for targets, create shifting malware code, generate deepfakes, and find hidden software flaws at machine speed.

Key Statistics on Cyber Threats in India

  • Cyber intelligence firm CloudSEK ranked India as the 2nd most cyber-attacked nation globally in 2024 and 6th in 2025.
  • Ransomware groups like World Leaks recently claimed to have stolen blueprints from India's largest nuclear facility, the Kudankulam Nuclear Power Plant.
  • During Operation Sindoor, Pakistan-backed group APT36 targeted key institutions such as the Ministry of Defence, DRDO, NIC, and BOSS Linux.
  • Generative AI reached 1 billion global users in just 3 years, whereas the Internet took 15 years to reach the same milestone.

How AI Transforms Cyber Warfare

  • LLMs scan social media and corporate portals to generate convincing spear-phishing messages and deepfakes without human intervention.
  • AI creates polymorphic malware that alters its own code continuously, allowing it to pass through standard antivirus firewalls.
  • State-backed groups deploy autonomous AI agents, like the Chinese group GTG-1002, to run full cyber espionage operations across networks.
  • Advanced models like Claude Mythos can analyze millions of lines of source code to discover zero-day flaws in systems like OpenBSD within minutes.
  • AI-driven cyber attacks directly threaten critical industrial control systems that manage power grids, oil refineries, and chemical plants.

Challenges Facing India

  • India lacks a fully developed sovereign AI stack, falling behind the United States and China in advanced GPUs, chip design, and foundational models.
  • Heavy reliance on foreign hardware, proprietary operating systems, and overseas cloud servers creates deep security risks for Indian infrastructure.
  • Traditional security tools like basic firewalls cannot stop self-evolving AI malware that adapts to changing environments.
  • The rapid spread of smart grids and urban IoT devices expands the digital attack surface for automated AI tools.
  • India faces a critical shortage of skilled experts who can handle machine-learning threat hunting and automated security responses.

Government Initiatives

  • CERT-In has launched AI-based threat detection systems and issued guidelines to shield critical digital assets from frontier AI risks.
  • MeitY is drafting rules for consent-based synthetic content, safety boundaries for autonomous AI, and legal duties for model developers.
  • CERT-In conducts national cyber drills on frontier AI risks and supports certified courses like CSPAI.

Way Forward

  • India must invest in sovereign AI models, domestic chip manufacturing, and local data centers to end foreign tech dependencies.
  • Organizations need to shift toward automated defensive systems that can detect network threats and deploy security fixes at machine speed.
  • Authorities must enforce zero-trust security and strict air-gapping across nuclear facilities, power grids, and defense networks.
  • Laws should require AI creators to conduct thorough red-team vulnerability testing before releasing software tools to the public.
  • India should participate in global alliances like Pax Silica to share threat intelligence and secure hardware supply chains.

Conclusion

  • Weaponized AI has transformed cyber warfare by enabling fast and automated attacks on national infrastructure. India can safeguard its digital sovereignty by building native AI tools, automating its defense systems, and enforcing strict security guidelines.