HomeLatest NewsCyber SecurityWeb-based cyberattacks on Indian businesses surge 10 per cent in 2025

Web-based cyberattacks on Indian businesses surge 10 per cent in 2025

Kaspersky Lab blocked over 50 lakh threats as Indian organisations face growing exposure from rapid digitalisation

Preferred Source of Google

Key Points

  • Kaspersky blocked 50.31 lakh web-based attacks on Indian businesses in 2025
  • CERT-In handled 29.44 lakh cyber incidents during the same period
  • Web-based threats rose 10 per cent year-on-year targeting Indian organisations

Web-based cyberattacks targeting Indian businesses rose 10 per cent in 2025, with security firm Kaspersky Lab blocking more than 50 lakh threat incidents across the year. The firm recorded 50,31,065 attacks through compromised websites, malicious downloads and other online vectors that can lead to unauthorised system access and data exposure.

The surge reflects the expanding attack surface as Indian organisations accelerate digital adoption faster than they can secure their systems, according to , general manager for India at Kaspersky Lab.

Advertisement
Saksham Bharat 2026
Saksham Bharat 2026
A multi-stakeholder dialogue on skilling gap in Cybersecurity, Data Resilience and AI — and the roadmap to a Saksham Bharat.
Register Now →
VeeamON 2026 Tour India - Mumbai
VeeamON 2026 Tour India - Mumbai
A VeeamON 2026 India Leadership Series Mumbai for senior public sector and government technology leaders.
Register Now →
Cyber Surakshit Uttar Pradesh
Cyber Surakshit Uttar Pradesh
Find out strategies, frameworks and solutions for building a resilient and secure digital ecosystem across Uttar Pradesh.
Register Now →
VeeamON 2026 Tour India - Bengaluru
VeeamON 2026 Tour India - Bengaluru
A VeeamON 2026 India Leadership Series Bengaluru for senior public sector and government technology leaders.
Register Now →
VeeamON 2026 Tour India - Delhi
VeeamON 2026 Tour India - Delhi
A VeeamON 2026 India Leadership Series Delhi for senior public sector and government technology leaders.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →

“What makes this even more pressing is the role AI now plays in the hands of threat actors, enabling attacks that are more targeted, more adaptive, and increasingly difficult to detect,” Singh said.

Regulatory response and compliance gaps

The threat data arrives as Indian regulators intensify their focus on cybersecurity enforcement. The Indian Emergency Response Team () handled 29.44 lakh cyber incidents in 2025, Singh noted, citing the agency’s figures.

However, readiness remains uneven. Many Indian businesses are in the early stages of compliance and governance, leaving significant exposure windows, according to Kaspersky’s assessment.

Advertisement

“Organisations here must treat cybersecurity not as a checkbox but as a business imperative,” Singh said. “Keeping systems updated, enforcing strong access controls and investing in 24/7 threat monitoring are no longer optional.”

By the numbers

50.31 lakh
web-based attacks blocked by Kaspersky in 2025
10%
year-on-year increase in cyberattacks
29.44 lakh
cyber incidents handled by CERT-In in 2025

How web-based threats compromise organisations

Web-based threats use the internet to target users and computer systems through several methods. These include phishing websites that mimic legitimate services to steal login credentials, drive-by downloads that install harmful software without user consent and compromised web pages that redirect visitors to malicious servers.

Advertisement

Such attacks can result in denial of access to computer networks, unauthorised entry into private systems and exposure of sensitive personal or data. The growth of internet-connected devices across Indian homes and offices has expanded the potential entry points for attackers.

To reduce exposure, Kaspersky Lab recommends that organisations keep operating systems and applications updated to patch known security flaws. The firm also suggests using strong unique passwords and enabling two-factor authentication — where users verify their identity through a second device or code — to limit damage from compromised credentials.

Your Questions, Answered

How many cyberattacks did Kaspersky block on Indian businesses in 2025?

Kaspersky blocked 50,31,065 web-based threat incidents targeting Indian businesses in 2025, marking a 10 per cent increase from the previous year.

How many cyber incidents did CERT-In handle in 2025?

The Indian Computer Emergency Response Team handled 29.44 lakh cyber incidents in 2025, according to figures cited by Kaspersky.

What types of web-based threats are targeting Indian organisations?

Common threats include phishing websites that steal credentials, drive-by downloads that install malware without consent and compromised web pages that redirect users to malicious servers.

How can Indian businesses protect themselves from web-based cyberattacks?

Organisations should keep systems updated, use strong unique passwords, enable two-factor authentication and invest in continuous threat monitoring services.

Get the day's headlines from Tech Observer straight in your inbox

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
- Advertisement -
Powered By Veeam Logo
- Advertisement -

Subscribe to our Newsletter

By subscribing you agree to our Privacy Policy, T&C and consent to receive newsletters and other important communications.
- Advertisement -

AI agents break legacy security models, Veeam CEO warns at VeeamON

Veeam Software CEO Anand Eswaran says zero-trust security models built for human users have broken down as autonomous AI agents move inside enterprises at machine speed, and that recovery, identity and data governance can no longer be treated as separate problems.

RELATED ARTICLES