While India celebrates its digital transformation—from the free AI subscriptions we covered to the new homegrown chips—there’s a growing shadow: cybersecurity threats. A new report from the Indian Computer Emergency Response Team (CERT-In) today reveals a shocking 40% increase in data breaches across India in 2025, leading to an estimated loss of ₹2,500 crore for individuals and businesses.
This surge comes just weeks after the full implementation of the Digital Personal Data Protection (DPDP) Rules, 2025, highlighting the urgent need for heightened digital vigilance.
The Most Common Threats Targeting Indians
Cybercriminals are evolving, and their tactics are becoming increasingly sophisticated:
- UPI Frauds (The Pervasive Threat): While UPI remains incredibly convenient, the “request money” scam and fake payment links continue to deceive millions. Fraudsters are leveraging sophisticated social engineering to trick users into authorizing payments.
- Ransomware 3.0 (Targeting Small Businesses): Criminals are no longer just locking up data; they’re threatening to leak sensitive customer information unless hefty ransoms are paid. Small and Medium Enterprises (SMEs) with weaker IT infrastructure are particularly vulnerable.
- AI-Powered Phishing (The New Frontier): The same AI tools driving innovation are also being used by scammers to craft highly convincing phishing emails and voice cloning scams, making it harder than ever to spot a fake.
- IoT Vulnerabilities (Your Smart Home is a Target): As more Indian homes adopt smart devices, unsecured cameras, smart locks, and virtual assistants are becoming entry points for hackers.
The Impact of DPDP Rules 2025
The DPDP Rules mandate strict data protection and breach notification for all “Data Fiduciaries” (any entity processing personal data). While this provides a legal framework for accountability, it also means:
- Higher Penalties: Companies failing to protect user data face massive fines.
- Increased Transparency: Affected individuals must be notified quickly if their data is compromised.
However, the laws are only as strong as their enforcement. The current surge indicates that many organizations are still playing catch-up.
How to Protect Yourself in a Digitally Risky World
- Be a UPI Vigilante: Always verify the sender before accepting any “request money” notification. Never click on suspicious links in UPI apps.
- Strong Passwords & 2FA: Use unique, complex passwords for every account. Enable Two-Factor Authentication (2FA) everywhere possible – it’s your strongest defense.
- Software Updates are Mandatory: Update your operating system, apps, and antivirus software immediately. Patches often fix critical security vulnerabilities.
- Educate Yourself: Be skeptical of unsolicited emails, SMS, and calls, especially those asking for personal information or demanding urgent action.
- Secure Your IoT: Change default passwords on smart devices. Use a strong Wi-Fi password.
The Bottom Line: Digital India’s growth is phenomenal, but it demands constant vigilance. As our lives become increasingly intertwined with technology, protecting our personal data is no longer just a recommendation—it’s an imperative.
Discover more from Bharat Tech Pulse
Subscribe to get the latest posts sent to your email.



Pingback: URGENT: CERT-In Issues High-Severity Alert for “Kraken” Ransomware Targeting Indian Government & Infrastructure – Bharat Tech Pulse
Pingback: Ditch the “Cringe”: Google Finally Lets You Change Your @gmail.com Address Without Losing Your Data – Bharat Tech Pulse
Pingback: Verdict Awaited: Supreme Court Reserves Judgment on Landmark KYC Privacy Case – Bharat Tech Pulse