Breach in the Department of Defence

Breach in the Department of Defence

On 10 March 2025, Athenian Tech (AT) identified a significant security breach affecting a sensitive national defence division after the ransomware group Babuk Locker 2.0 claimed to have exfiltrated nearly 20TB of classified defence data. The leaked dataset reportedly included sensitive information like VVIP evacuation procedures.

On 10 March 2025, Athenian Tech (AT) identified a significant security breach affecting a sensitive national defence division after the ransomware group Babuk Locker 2.0 claimed to have exfiltrated nearly 20TB of classified defence data. The leaked dataset reportedly included sensitive information like VVIP evacuation procedures.

Upon deeper investigation, the breach was traced not to the core defence infrastructure but to the personal device of a former senior official, exposing a critical endpoint‑security lapse. Although the primary systems remained uncompromised, the scale and sensitivity of exposed data posed severe national‑security, diplomatic, and regulatory risks.

AT’s AI‑powered intelligence platform, Prime, analysed the leaked dataset across Dark Web and closed‑channel ecosystems, profiling Babuk Locker 2.0 and mapping their TTPs to confirm the nature of the attack. Prime’s investigation identified the breach’s origin and provided actionable intelligence to help authorities understand the exposure pathway, the attack behaviour, and the severity of the data loss.

Impact

AT’s independent findings were formally acknowledged by the Ministry of Defence, CERT‑In, and the PMO. The organisation requested a comprehensive research and remediation report from AT to help address systemic vulnerabilities, strengthen endpoint security practices, and prevent recurrence of similar high‑impact breaches.

Share

Related Case Studies

Deepfake of Narayan Murthy SurfacesDeepfake
CASE STUDY01 August 2025

Deepfake of Narayan Murthy Surfaces

In August 2025 a coordinated financial fraud campaign which leveraged AI-generated deepfake technology to impersonate Infosys Founder Narayana Murthy, falsely portraying him as endorsing a fictitious government-backed investment platform surfaced across social media platforms. The manipulated video circulated across Facebook, Instagram, and WhatsApp, claimed that citizens could earn over ₹1.9 lakh per month by making a one time investment of ₹ 21,000 through an “AI-powered automated smart investing” scheme.

Read Case Study →
BSNLTelecom
CASE STUDY20 May 2024

Breach at Telecom Major BSNL

On 20 May 2024, government owned telecom major BSNL and a critical part of India’s national communications infrastructure, was hit by a major cybersecurity incident. The same day, a threat actor—kiberphant0m—claimed responsibility of the attack and advertised the sale of approximately 278 GB of sensitive telecom data on the dark web. The exposed data included IMSI numbers, SIM subscriber details, Home Location Register (HLR) records, and internal Solaris server snapshots, all of which are vital for telecom operations and subscriber identity management.

Read Case Study →
Remote Unauthenticated RCE in OpenSSH ExploitationCybercrime
CASE STUDY

Remote Unauthenticated RCE in OpenSSH Exploitation

In August 2024, Athenian Tech (AT) uncovered a critical security risk during a routine digital‑risk assessment conducted for a European holding company. One of the organisation’s publicly exposed servers was found running OpenSSH 8.9p1 on Ubuntu — a version vulnerable to the high‑severity “regreSSHion” flaw (CVE‑2024‑6387). This vulnerability, caused by a race condition in sshd’s signal handler, allowed remote unauthenticated attackers to repeatedly trigger LoginGraceTime and potentially execute arbitrary code as root. If exploited, the flaw could have enabled a complete system takeover, deployment of persistent backdoors, data exfiltration, and lateral movement into the company’s wider IT infrastructure, posing material operational and financial risks.

Read Case Study →

Get the next one in your inbox.

The Month in Threats, Read by the People Who Have to Answer for It.

Free. Unsubscribe any time. We never sell or share your address.