The National Investigation Agency (NIA) has intensified its investigation into alleged cyberattacks on Indian government websites during Operation Sindoor, carrying out searches at five locations across Maharashtra, Gujarat, Telangana, Bihar and Delhi.
The searches were conducted as part of an ongoing cyber-terrorism investigation concerning alleged attempts to launch sophisticated Distributed Denial-of-Service (DDoS) attacks against 54 government websites. Investigators are examining whether the attacks were intended to disrupt critical digital infrastructure and threaten national security.
The searches took place at premises in Junnar in Maharashtra’s Pune district, Nadiad in Gujarat’s Kheda district, Ramagundam in Telangana’s Karimnagar district, Gopalganj in Bihar and Delhi. The operation followed the identification of additional suspects during the investigation.
Investigation into attacks on 54 government websites
The case concerns alleged DDoS attacks targeting websites belonging to Indian government entities during Operation Sindoor. According to investigators, the targeted systems included critical computer resources and Critical Information Infrastructure.
A DDoS attack typically involves sending an overwhelming volume of traffic or requests to a digital service with the intention of making it slow, inaccessible or unavailable to legitimate users. When government systems or critical infrastructure are targeted, such attacks can potentially disrupt essential services and create wider security concerns.
Investigators are examining whether the alleged attacks were intended to compromise India’s sovereignty, security and unity and to create fear among the public.
Searches conducted across five states and Delhi
NIA teams carried out the searches after obtaining warrants from a competent court. The action followed a detailed investigation into individuals suspected of having links with those already arrested in the case.
The searches covered multiple locations, indicating that investigators are examining a wider network connected to the alleged cyberattack preparations.
The locations searched were:
- Junnar in Pune district, Maharashtra
- Nadiad in Kheda district, Gujarat
- Ramagundam in Karimnagar district, Telangana
- Gopalganj in Bihar
- Delhi
During the searches, investigators also questioned suspects about their alleged association with the two individuals who have already been arrested.
Digital devices seized during searches
The NIA seized several electronic devices and documents that investigators believe may contain material relevant to the alleged hacking activities.
The agency recovered three laptops, five mobile phones and other digital devices, including pen drives. The seized material is expected to undergo further examination as investigators attempt to establish the nature and extent of the alleged cyber network.
Digital forensic examination can help investigators identify communications, files, online activity and other technical evidence that may establish connections between suspects. Such evidence could also assist authorities in determining whether the individuals allegedly provided technical support or participated in preparations for the attacks.
Two accused already arrested
Two accused persons have already been arrested in connection with the case.
The investigation was initially registered by the Gujarat Anti-Terrorist Squad before being taken over by the NIA. The case was registered on June 25, 2025, and investigators subsequently expanded their probe using technical analysis.
According to the investigation agency, this analysis helped identify individuals who allegedly provided support and assistance to the arrested accused. The suspects are alleged to have helped with preparations for the DDoS attacks and with developing or improving the technical capabilities required to carry them out.
The latest searches are therefore aimed at determining the extent of these alleged connections and whether additional individuals were involved.
Operation Sindoor forms the backdrop
The alleged cyberattacks took place during the period of heightened national security following the April 22, 2025, terror attack in Pahalgam, Jammu and Kashmir.
India launched Operation Sindoor on May 7, 2025, in response to the Pahalgam attack. The military action targeted terrorist infrastructure in Pakistan and Pakistan-occupied Kashmir.
The alleged attempts to disrupt government websites during this sensitive period have consequently become part of a wider national security investigation. Authorities are examining whether the cyber activity was intended to exploit the heightened tensions and interfere with government digital systems.
Technical evidence could determine next stage of probe
The digital devices recovered during the searches are expected to play a significant role in the next stage of the investigation.
Forensic examination could potentially help investigators establish when and how the alleged activities were planned, identify communications between suspects and determine whether the individuals searched had direct involvement in the attempted attacks.
Investigators may also examine whether the suspects were connected to other people who could have provided technical assistance, infrastructure or other resources for the alleged cyber operations.
The agency’s focus on technical analysis highlights the increasingly important role of digital forensics in investigating complex cybercrime and national security cases.
Investigation remains underway
The latest searches do not by themselves establish criminal liability against every person questioned. Their alleged involvement will depend on the evidence collected during the investigation and the findings of forensic examination of the seized material.
The NIA is continuing to analyse the evidence gathered from the five locations. Further arrests or legal action could follow if investigators establish additional links to the alleged cyberattack conspiracy.
The case also highlights the growing security challenges posed by attacks against government digital infrastructure. As public administration and essential services increasingly rely on interconnected computer systems, attempts to disrupt such infrastructure can have implications extending beyond temporary website outages.
The investigation into the alleged DDoS attacks during Operation Sindoor remains ongoing, with authorities examining the suspected network, the technical evidence seized during the searches and the possible role of additional individuals.
