India’s Cyberwarfare Capabilities and Doctrine: Jointness, Resilience and Regional Competition

An evidence-led journey through Indian cyber power—from the Defence Cyber Agency and 2025 joint doctrine to India-nexus espionage clusters, commercial operators, Operation Sindoor, critical-infrastructure defense, digital sovereignty, and regional competition with Pakistan and China.

Begin in the fog of May 2025: when every outage became a weapon

Evidence cutoff: 18 September 2026. In the days surrounding India’s Operation Sindoor and Pakistan’s response in May 2025, the digital conflict seemed immense. Hacktivist channels claimed power failures, satellite disruption, stolen banking data, military-system compromise, website defacement, and attacks on critical infrastructure. Old videos returned with new captions. Screenshots became proof without provenance. Routine outages were assigned strategic intent. Claims traveled faster than incident responders could validate them.

The kinetic events were real and dangerous. India launched strikes on 7 May after the 22 April Pahalgam attack killed 26 civilians; India attributed responsibility to Pakistan-backed terrorism, while Pakistan rejected India’s account and the two nuclear-armed states exchanged military action before a ceasefire. Cyberespionage, phishing, denial-of-service activity, defacements, hacktivist claims, platform manipulation, and rapid fact-checking accompanied the crisis. Yet the public record does not validate most claims of strategic digital damage.

India’s later Operation Sindoor official review says the operation was conducted across land, maritime, air, cyber, space, and information-warfare domains. That statement is evidence that the government places cyber within the campaign. It does not disclose an Indian cyber target, access, tool, method, authority, duration, or effect. Pakistan made its own cyber claims, while pro-state and independent groups on both sides sought attention. A claim of participation is not a battle-damage assessment.

This is the right place to begin because India’s cyber capability is easier to exaggerate than to observe. India has a published joint doctrine, a Defence Cyber Agency, service cyber organizations, intelligence bodies, a large technology industry, incident-response institutions, and a growing security ecosystem. Researchers track multiple India-nexus espionage clusters. Foreign governments have begun publicly assessing Indian state-sponsored activity. At the same time, India rarely acknowledges offensive operations and reveals little about military command relationships, force size, access, budgets, or effects.

The analytical journey must therefore resist two errors. One is to infer that secrecy means India lacks capability. The other is to treat every patriotic hacker, India-based contractor, security-vendor label, or neighboring-state allegation as an arm of New Delhi. Apply the practical definition of cyberwarfare: establish authority, objective, target, mechanism, effect, and conflict context. During a fast crisis, add a seventh question—who benefits from persuading the audience that the effect occurred?

Operation Sindoor was not publicly demonstrated as a decisive “cyber war.” It was a multi-domain crisis in which intelligence, network defense, digital influence, operational communications, and unverified offensive claims interacted with missiles, drones, air defense, diplomacy, and mass media. That more careful description is also more useful to students and practitioners.

The doctrine emerges: from securing cyberspace to creating military advantage

India’s 2013 National Cyber Security Policy was principally a civilian security and resilience document. It sought a secure computing environment, protection of information and infrastructure, workforce development, public-private cooperation, incident response, and indigenous capability. It did not provide a mature public account of military cyberspace operations. The gap between national cybersecurity and military campaigning remained visible for years.

Organizational change came first. The government approved a Defence Cyber Agency (DCA) as one of three new tri-service agencies alongside space and special operations. By August 2021, an official Defence Cyber Agency record described it as fully functional and noted that the Army, Navy, and Air Force had their own Computer Emergency Response Teams. Another parliamentary response said the DCA and service cyber groups had charters to protect defense ICT assets and deter adversary cyberwarfare. Public language showed mission expansion, but not the agency’s authorities or force structure.

In June 2024, the Chief of Defence Staff announced a Joint Doctrine for Cyberspace Operations. The 2024 doctrine announcement calls cyberspace a global common with shared sovereignty and says operations must be woven into national security to develop ends, ways, and means that create advantage and influence events in other operational environments and across instruments of power. It frames cyber as both a domain and an enabler.

A declassified version, JP 2.01 (U), was formally released on 7 August 2025. The government’s 2025 Joint Doctrine release identifies five public themes: a unified approach to national cyberspace interests; integration of offensive and defensive capabilities; synchronized operations across the three services; threat-informed planning and resilience; and real-time intelligence integration with joint-capability development.

Those themes move India beyond a purely defensive vocabulary. Offensive capability is acknowledged as part of credible posture, but the public summary does not say when it may be used, who authorizes an operation, how intelligence access is deconflicted, what thresholds govern response, or how civilian effects are assessed. “Deterrence” can include denial through resilience, punishment through response, exposure, diplomacy, law enforcement, or the communicated possibility of cyber and non-cyber costs. It should not be reduced to hacking back.

Jointness is the central problem. The Army, Navy, and Air Force depend on different mission systems, operational tempos, vendors, spectrum conditions, and command relationships. A joint cyber capability must support land formations, fleets, air defense, logistics, satellites, intelligence, and national leadership without creating a single brittle network. The doctrine’s emphasis on real-time intelligence means collection, targeting, defense, and operations must exchange information rapidly. Its emphasis on self-reliance reflects concern that foreign hardware, software, cloud services, and supply chains can create strategic dependence.

India’s 2025 Joint Doctrine for Multi-Domain Operations and later Integrated Communication Architecture work reinforce this trajectory. Official descriptions of 2026 military education link cyber with cognitive warfare, AI, autonomous systems, space, and electronic activity. These documents reveal intended integration; they do not demonstrate that organizational seams, incompatible systems, talent shortages, or service competition have been solved.

A federation of missions: map the institutions before judging the capability

India’s cyber system is distributed because its missions are different. Military operations, foreign intelligence, domestic security, cybercrime, civilian incident response, critical-infrastructure protection, government networks, sector regulation, and diplomacy cannot be assigned to one command without confusing authorities.

At the strategic level, the National Security Council Secretariat and National Cyber Security Coordinator coordinate policy across departments. The Defence Cyber Agency provides the visible tri-service military center, while service cyber groups and CERTs protect and support their respective forces. The precise relationship between the DCA, Integrated Defence Staff, service commands, theater structures, and intelligence agencies is not explained publicly in operational detail.

The National Technical Research Organisation (NTRO) is a technical intelligence body. Within it, the National Critical Information Infrastructure Protection Centre (NCIIPC) is the statutory national nodal agency under section 70A of the Information Technology Act for critical information infrastructure. Its mission is protective: coordination, risk assessment, guidance, exercises, and resilience for sectors whose incapacitation would debilitate national security, the economy, public health, or safety.

CERT-In, under the Ministry of Electronics and Information Technology, is the national incident-response agency under section 70B. It issues alerts and directions, exchanges threat information, coordinates mitigation, supports investigations, conducts exercises, and runs programs including the Cyber Swachhta Kendra. The National Cyber Coordination Centre (NCCC), implemented by CERT-In, uses metadata and other sources for national situational awareness. The National Informatics Centre provides technology to central, state, and district government.

The Ministry of Home Affairs’ Indian Cyber Crime Coordination Centre (I4C) focuses on cybercrime and law-enforcement coordination. A December 2025 2025 national cyber architecture also describes the Cyber Multi Agency Centre (CyMAC), bringing together intelligence, defense, telecom, CERT-In, NCIIPC, NIC, and law-enforcement participants for real-time monitoring, intelligence sharing, and coordinated response. Sectoral CSIRTs and regulators cover power, finance, telecommunications, transportation, and other functions.

Intelligence is the least transparent layer. Public reporting assumes roles for external and domestic intelligence organizations, but India does not publish a reliable offensive cyber order of battle. It is analytically unsafe to assign an observed campaign to the Research and Analysis Wing, Intelligence Bureau, NTRO, DCA, or a military service because the target aligns with that institution’s interests. Mission fit is a lead, not proof of tasking.

Industry and academia complete the system. India has a large software workforce, global IT-service companies, cybersecurity firms, telecommunications providers, defense laboratories, universities, start-ups, and a substantial vulnerability-research community. These assets can supply talent, tools, training, managed services, intelligence, and indigenous technology. They also expand the supply chain and create competition with government for skilled personnel.

Coordination is therefore a capability in its own right. A national incident may cross military, intelligence, crime, privacy, sector-regulatory, diplomatic, and state-government boundaries. Overlap can provide resilience, but unclear leadership can delay warning, containment, public communication, and evidence preservation. The organizational question is not “Who owns cyber?” It is “Who leads this mission, under which authority, with what information and handoff?”

The visible operators: India-nexus espionage is real, exact sponsorship is harder

India’s offensive record is most visible through threat-intelligence clusters, not government acknowledgment. SideWinder, Patchwork, Bitter, DoNot Team, Confucius, and related names recur in reporting about South Asian espionage. Their targets often include Pakistani military and government bodies, Chinese organizations, diplomatic missions, nuclear and maritime entities, and institutions across Bangladesh, Sri Lanka, Nepal, Afghanistan, and the wider region.

SideWinder is among the most prolific. Kaspersky’s Kaspersky SideWinder research documents attacks on military, government, maritime, logistics, telecommunications, and nuclear-related targets across Asia, the Middle East, and Africa. Bangladesh’s national CIRT issued a 2026 Bangladesh SideWinder advisory describing active spear-phishing against government organizations and calling the group “suspected India-nexus.” That wording is appropriately limited: nexus is stronger than geographic coincidence but weaker than a proven government chain of command.

Patchwork, also called Mahabusa or White Elephant in some reporting, has targeted Pakistan and China with document lures, credential theft, and remote-access malware. Pakistan’s Pakistan Patchwork advisory calls Patchwork and several other clusters Indian state-sponsored. It is an official victim-state attribution and includes indicators and defensive guidance. It does not publicly show the intelligence behind the sponsor judgment, so analysts should record both its authority and its evidentiary limitation.

Bitter, tracked by Proofpoint as TA397, has operated for years against governments, defense organizations, diplomatic bodies, and telecommunications targets. In 2025, the company’s Proofpoint Bitter assessment judged it highly likely to be state-backed and collecting in the interests of the Indian state. Vendor confidence can be informed by extensive telemetry, but “in the interests of” does not identify an agency, contract, or legal authority.

DoNot Team and Confucius have used phishing, malicious documents, Android surveillance tools, and custom malware against regional political, defense, diplomatic, and civil-society targets. Researchers disagree about whether some India-nexus names describe distinct operators, shared suppliers, related teams, or overlapping activity. Infrastructure reuse and code similarity can indicate collaboration, common training, copying, or a commercial tool—not necessarily common command.

Canada’s Canadian threat assessment marked an important evolution in official attribution. It assesses that India seeks a modern indigenous cyber program, likely uses commercial vendors, and that Indian state-sponsored actors likely conduct espionage against Canadian government networks. Canada connected the likely activity to deteriorating bilateral relations. The assessment draws partly on classified sources but does not name the actor, incident, or technical evidence publicly.

Taken together, the evidence supports a cautious conclusion: India possesses or benefits from state-linked espionage capacity focused heavily on regional and national-security targets, with an expanding reach. It does not support assigning every India-nexus cluster to DCA, NTRO, R&AW, or another agency. A professional cyber attribution assessment should separate activity clustering, operator location, beneficiary, institutional sponsorship, direction or control, and state responsibility.

The commercial edge: hack-for-hire, surveillance and the attribution trap

India’s technology sector gives the state a large pool of expertise, but it also supports private intrusion markets whose customers and motives are not always governmental. Conflating the two produces bad intelligence and can shield abuse behind national-security language.

Citizen Lab’s 2020 Dark Basin investigation linked a large phishing operation with high confidence to BellTroX InfoTech Services, an India-based company. Targets included advocacy organizations, journalists, lawyers, investors, financial firms, and parties to legal disputes across multiple countries. Citizen Lab used shared URL shorteners, phishing-kit characteristics, infrastructure, testing behavior, and links to individuals to reach the company-level assessment. The case demonstrated industrialized intrusion-for-hire, not a single geopolitical mission.

Commercial operators can provide plausible deniability and flexible capacity to a state client, corporation, law firm, investigator, private intelligence service, or abusive individual. They can purchase infrastructure, acquire credentials, develop lures, broker data, or supply spyware. The same provider may serve lawful defensive customers and unlawful intrusion customers. A country of incorporation does not prove state direction, just as a target beneficial to India does not prove Indian authorization.

The ecosystem nevertheless matters to national capability. Canada’s threat assessment explicitly judges that India likely leverages commercial cyber vendors. India’s doctrine emphasizes partnership, indigenous toolchains, industry, academia, and self-reliance. Those goals can accelerate defensive products, military research, training, and secure supply chains. Without strong oversight, the same market can enable unauthorized surveillance, political targeting, export abuse, and operators whose activity creates diplomatic cost for the state.

Researchers should build a relationship ledger. Record corporate registration, personnel, infrastructure payment, malware development, victim selection, customer communication, procurement, and benefit as separate propositions. Ask whether the evidence shows a service provider, an operator, a government customer, government tasking, or merely co-location. Do not turn a commercial employee into an intelligence officer because the story feels coherent.

This distinction is operationally important. A state unit may value quiet, persistent access and avoid publicity. A hack-for-hire firm may reuse infrastructure across customers. A hacktivist may claim an intrusion it did not perform. A criminal may sell the same stolen access twice. Their defensive signatures and escalation implications differ even when all use spear-phishing and target a ministry.

Pakistan, China and the crisis cycle: espionage before the missiles, noise after them

India’s cyber priorities cannot be separated from two enduring security relationships. Pakistan is the immediate crisis competitor, with recurring military confrontation, terrorism allegations, Kashmir, nuclear risk, and intense information competition. China is the larger strategic and technological challenge, with a disputed border, military modernization, deep links to Pakistan, and far greater publicly assessed cyber scale. The China’s cyberwarfare capabilities page explains that asymmetry.

Espionage is continuous because crises are intermittent. India-nexus actors seek military plans, diplomatic positions, nuclear and maritime information, telecommunications access, political intelligence, and credentials. Pakistan-linked clusters such as Transparent Tribe/APT36 and SideCopy repeatedly target Indian defense personnel, government bodies, and researchers through themed documents, fake applications, and social engineering. China-linked operators have targeted Indian government, power, telecom, technology, and border-related interests. Each side studies the other’s collection habits and copies effective lures.

A crisis changes tempo. News creates convincing pretexts. Personnel open urgent documents. Administrators loosen change control. Public websites become symbolic targets. Patriotic volunteers and established operators share a crowded environment. During the April–May 2025 crisis, researchers observed Pakistan-linked phishing and malware, while hacktivists on both sides claimed defacements and denial-of-service attacks. Most activity was espionage, harassment, or propaganda rather than infrastructure destruction.

The Stimson Center’s South Asian attribution study explains why restraint in public attribution has sometimes served both states: evidence is incomplete, technical indicators can be manipulated, and leaders may wish to avoid escalation or conceal intelligence sources. Neither country has consistently exposed a transparent public attribution framework. During a military exchange, a premature sponsor judgment can transform a criminal outage or hacktivist boast into a perceived act of state retaliation.

Operation Sindoor also shows how cyber-enabled influence operations merge with conventional conflict. False videos, recycled images, fake documents, exaggerated loss claims, official rebuttals, and platform amplification competed to shape domestic confidence and international perception. Some messages came from anonymous accounts; others moved through broadcasters, officials, or influencers. Information dominance was not a clean victory condition. Both societies encountered material that confirmed what audiences already wanted to believe.

For planners, cyber activity should support a defined operational problem: warning, force protection, intelligence, communications availability, deception, logistics, or an effect against an adversary system. A target list without a theory of effect is not cyber campaign design. Nor does a disabled public website demonstrate degradation of military command. The relevant questions are whether the action changed a decision, protected a force, delayed a sortie, denied intelligence, preserved command, or created a recoverable nuisance.

Crisis-management mechanisms are therefore cyber capabilities too. Secure military communications, protected hotlines, shared incident facts, rapid malware exchange, disciplined official messaging, and pre-agreed attribution thresholds can prevent misinterpretation. In a nuclear dyad, accurately identifying what did not happen may be as strategically valuable as discovering an intrusion.

The country as target: Kudankulam, digital public infrastructure and concentrated trust

Cyber power includes the ability to absorb attack. India’s digital transformation has connected public services, identity, payments, telecommunications, health, rail, energy, and government at extraordinary scale. This creates economic and administrative strength, but also national cyber key terrain. Aadhaar identity, Unified Payments Interface transactions, telecom networks, state data centers, cloud and software providers, grid control, and the administrators who connect them can become strategic dependencies.

Kudankulam provides a concrete lesson. In 2019, malware was discovered on the administrative network of the nuclear power station. The government’s Kudankulam official account said the infected system contained administrative data and that plant control and instrumentation networks were isolated and unaffected. Researchers associated the malware with a North Korea-linked toolkit, but India did not publicly confirm the operator in that statement.

The incident is neither proof that a reactor was hacked nor a harmless office infection. Administrative networks contain personnel, procurement, technical correspondence, schedules, credentials, and supplier relationships. They can provide intelligence for later targeting even when safety systems remain separated. Initial public denial followed by acknowledgment also demonstrated how communication affects trust. Air gaps reduce pathways; they do not remove removable media, maintenance laptops, engineering suppliers, shared personnel, or data-flow risk.

Supply-chain exposure resurfaced in July 2026 when a contractor reported a partial breach involving a third-party server and documents related to Kudankulam construction appeared in a leak. NPCIL said the exposed material did not relate to nuclear safety, security, or plant operation. The event again placed the boundary between operator, contractor, data center, design information, and critical system at the center of risk. Even when operational control remains safe, stolen drawings and vendor information can assist espionage, fraud, physical reconnaissance, or later social engineering.

Power has received more structured attention. India established CSIRT-Power in 2023 alongside sectoral teams for thermal, hydro, transmission, distribution, grid operation, and renewable energy. The government’s power-grid security measures describe security operations centers, audits, exercises, network segregation, and monitoring across national and regional load-dispatch functions. These measures are capabilities, but public summaries do not establish uniform implementation across thousands of operators and vendors.

Scale complicates metrics. The 2026 CERT-In review says CERT-In handled more than 2.944 million cyber incidents in 2025, issued 1,530 alerts, ran 122 exercises involving roughly 1,570 organizations, and maintained a large audit ecosystem. “Incidents handled” is not the same as successful state attacks, unique victims, or severe breaches. The figures demonstrate monitoring and workload, not by themselves resilience or failure.

Defensive maturity must be tested through mission continuity. Can payments operate in a degraded mode? Can a hospital retrieve essential records without central identity? Can a grid operator communicate after telecom loss? Can military logistics proceed when a civilian supplier is compromised? Are backups independent of cloud administration? Does incident command include state governments and private owners? The objective is not zero intrusion; it is to prevent access from becoming intolerable civilian harm and reverberating effects.

The 2026 assessment: a rising cyber power whose operational record remains deliberately incomplete

By September 2026, India can credibly be described as a rising cyber power. It has moved from a predominantly civilian security policy to a public joint military doctrine that integrates offense, defense, intelligence, and resilience. It maintains a functioning tri-service cyber agency and service organizations, a broad national defensive architecture, sectoral protection mechanisms, a deep technology workforce, international partnerships, and a growing indigenous defense ecosystem. Regional espionage reporting and Canada’s assessment support the conclusion that state-sponsored Indian cyber activity exists beyond defense.

The public evidence does not justify claims that India can reliably penetrate any Pakistani or Chinese target, disable a national grid, control military satellites, or produce decisive strategic effects on demand. Operation Sindoor proves political willingness to integrate emerging domains and communicate a multi-domain posture. It does not publicly demonstrate the offensive cyber portion. Vendor research demonstrates campaigns and tradecraft but usually cannot expose the complete authorization chain.

India’s advantages are substantial: a large technical talent base; globally connected IT and telecommunications industries; experience defending enormous digital platforms; a growing startup and research sector; intelligence requirements focused by persistent regional competition; partnerships with the United States, France, Israel, Japan, Australia, and others; and a political emphasis on strategic autonomy. International cooperation can provide exercises, intelligence, standards, investigation, and supply-chain diversification without requiring alliance-style integration.

Its constraints are equally real. Responsibilities are distributed across ministries and levels of government. Public doctrine is newer than long-established service structures. The state competes with private employers for talent. Imported hardware, software, cloud, and security products create dependencies even as “Atmanirbhar Bharat” seeks self-reliance. Legacy systems and uneven capacity span central government, states, municipalities, public enterprises, and small suppliers. Secrecy protects operations but limits external evaluation and public accountability. Commercial surveillance and hack-for-hire markets create diplomatic and human-rights risks.

India’s diplomatic position adds obligations. In its India UN sovereignty statement, India said that cyber operations against information systems in another state or producing extraterritorial effects may breach sovereignty, and that states aware of wrongful activity from their territory should take reasonable steps consistent with international law. The U.S.–India cyber framework recognizes the applicability of international law and the UN Charter, voluntary norms, human rights, multistakeholder governance, and practical cooperation. These are diplomatic commitments against which operations and oversight can be evaluated.

A strong analytic brief should use four evidence bins:

  1. Demonstrated: institutions, exercises, incident response, defensive programs, published doctrine, observed campaigns, and effects supported by reliable telemetry.
  2. Assessed: foreign-government or vendor judgments about Indian sponsorship, purpose, commercial support, and likely targets, with confidence and sourcing stated.
  3. Declared: offensive integration, deterrence, self-reliance, multi-domain synchronization, and lessons claimed by Indian officials but not publicly tested in detail.
  4. Unknown: access, tool quality, force size, agency tasking, wartime authorities, intelligence deconfliction, destructive reliability, collateral-risk controls, and strategic effect.

For daily defense, prioritize the patterns visible across the region: spear-phishing tailored to current affairs; malicious documents and mobile applications; credential theft; exposed internet services; contractor and cloud trust; telecom and defense identities; nuclear, maritime, diplomatic, and research information; and influence activity surrounding crises. Preserve logs, use phishing-resistant authentication, restrict administrative paths, segment mission systems, verify software and suppliers, rehearse alternate communications, and establish an attribution ledger before an emergency.

Finally, measure outcomes. A defacement that trends online may have no operational value. An unnoticed credential can provide years of intelligence. A protected command network can enable every aircraft, ship, and formation without producing a public cyber story. Use cyber effects assessment to ask what changed compared with the likely baseline, for how long, at whose cost, with what confidence, and whether recovery or adaptation erased the advantage.

India’s cyber journey is therefore not a march toward a mythical digital superweapon. It is the slower construction of institutions, doctrine, intelligence, joint command, indigenous capacity, international partnerships, and national resilience under pressure from two capable rivals and a vast domestic attack surface. The decisive test will be whether those pieces work together during a crisis—without mistaking secrecy for success, activity for effect, or information dominance for truth.

Frequently asked questions

What are India’s principal cyberwarfare capabilities?

Public evidence supports a growing tri-service military cyber organization, national incident response and critical-infrastructure protection, threat-intelligence collection, cyber exercises, indigenous research and tool development, and regional cyberespionage activity attributed with varying confidence to India-nexus actors. India’s 2025 doctrine explicitly integrates offensive and defensive capabilities. Specific military accesses, tools, targets, authorities, and operational effects remain largely undisclosed.

Does India have a published military cyber doctrine?

Yes. A doctrine was first announced in June 2024, and the declassified Joint Doctrine for Cyberspace Operations, JP 2.01 (U), was formally released in August 2025. Official descriptions emphasize joint operations across the Army, Navy and Air Force, integrated offensive and defensive capabilities, threat-informed planning, resilience, real-time intelligence integration, and development of joint cyber capabilities.

Is the Defence Cyber Agency India’s equivalent of U.S. Cyber Command?

Not directly. The Defence Cyber Agency is a tri-service organization under India’s Ministry of Defence and was described as fully functional in 2021. Public evidence indicates a coordinating and operational role, but its scale, command authorities, force-generation model and relationship with intelligence agencies are not disclosed in enough detail to equate it with U.S. Cyber Command or another foreign organization.

Are SideWinder, Patchwork, Bitter and DoNot proven Indian government units?

No. Security researchers associate these clusters with India through targeting, infrastructure, language, working patterns and other telemetry. Some vendors assess state backing, Pakistan officially calls several of them Indian state-sponsored, and Canada assesses that Indian state-sponsored actors conduct espionage. These sources do not establish that every named cluster is a permanent government unit or reveal its exact command relationship. Vendor aliases also overlap.

What cyber role did India play during Operation Sindoor in 2025?

India’s Ministry of Defence later said the operation was conducted across conventional domains and the emerging domains of cyber, space and information warfare. It has not publicly identified an Indian cyber target, technique, access or measured effect. Pakistan-linked actors and hacktivists conducted phishing, defacement, denial-of-service and influence activity, while both sides circulated contested claims. The episode demonstrates cyber-enabled crisis competition but does not publicly prove a decisive Indian offensive cyber effect.