For technical people who don't know what really happens
end of last year AIIMS hired Bangalore based IT company (MNC) EY solutions to do Vulnerability assessment and penetration testing on them so in first week of penetration testing red cell ( special hacking team) found out that there is so many critical vulnerability due to non upgrades or failed security patches, then they informed the AIIMS management and concluded the penetration testing , fast forwarding may 2022 E&Y done follow-up and find out management sit on the report and never done anything to fix the security issues, then further down 5 months later one sino-Russian cyber froum put nday ( not zero day) exploit for sales for 1k less in usd and sold to one well known ransomware group in SEA, they done mass scanning using shoden and Genesis portals to find out vulnerable server then find out AIIMS also have one server vulnerable to the exploit, they used the exploit to get initial foothold in to the internal network from there they used previously unresolved security issues which gave them free home run on all AIIMS server's, they used leaked conti 0.3 ransomware based ransomware to lock out files and put them as hostage, AIIMS went panic mode and news leaked to media then the media made it look like stuxnet v 2 kind of cyber incident,
So if you read up to this point the normal question will be where is Chinese in this all mess, the reality the real hack was not carried out by Chinese state sponsored hackers or their patriotic hack teams ( yes they also have their own BJP cyber cell but with more advanced capabilities
Jk) it was done from multinational ransomware team which located in SEA mostly Cambodian, Philippines etc, the 100 plus servers NCRt and other incident response team find out where staging or hosting servers used by team using Ali cloud or tencent, how would I know they are cloud servers not gov server's because even Indians can can buy Chinese cloud server's and use them for red teaming exercise ( the holy hacking done by a MNC if amateur done without permission he will end up in jail)
So in conclusion what happened in AIIMS was pure neglect and I'll informed management about cyber security and it's impact and AIIMS is not the first celebrity in this Indian Hall of shame there are several unknown dark horses let me bring them to like light, BPCL yes one of main source for energy is hacked and put in to auction in late 2021 ( if you see Mumbai power plant failure frequently never get surprised because BPCL have small unholy relationship with Bombay power grid), Reliance Group the Reliance fashion group got totally pawned and put in to auction in 2020 but luckily no one brought it and seller who provide accesss later used Reliance group combined CPU for crypto mining ( yes threat actor's some times act like absolute fools)
So if I have to explain the great Indian Cyber land it will be so much similar to the great India in physical world there is companies same or comparable cyber security and capabilities to American multi billion companies and offensive capabilities similar to CIA ( tbh am not exaggerating) but also poor like Dharavi slum dwellers ( am not mocking real slum people but metaphorically giving a picture of how poorly secured some companies are) , If i can write about all cyber incidents happening in India it will look like another India - China thread with 100 of replies, so am concluding this small ted talk as ending note all o have to say
" sambhavami yuge yuge"