Science and Technology › Computing and AI
हिन्दी — Read in HindiCyber security and data protection
Data protection under the Digital Personal Data Protection Act, 2023, how cyber attacks work, including those on artificial intelligence systems and critical infrastructure, cyber crime, and the agencies that respond. It serves GS3 answers on cyber security.
Foundation note: The Digital Personal Data Protection Act, 2023
All 5 articles shown; the 2 that changed from 1 to 30 June 2026 are marked.Show only these
Prompt injection and ASCII smuggling
Copy link to Prompt injection and ASCII smugglingPrelims
Unicode extends ASCII to the world's scripts, keeping ASCII itself as its own first 128 characters. It also carries tag characters, which copy those 128 but never show on screen, and hiding them inside ordinary text is what ASCII smuggling means.
Hide
Tag characters are slipped into a message, inside a word such as funding or as hidden instructions
Software reads them
A spam filter reads fun and ding instead of funding, and an AI tool obeys the hidden instructions
Human sees nothing odd
The reader sees only funding and ordinary text
What changed
3 Jun 2026BriefAttackers manipulated Meta's AI support chatbot into linking Instagram accounts to attacker controlled emails and resetting passwords, without proving ownership. The risk is greatest when a model is given tools to act for users: crafted instructions in language, not code, make it act outside its rules. The Indian Express, 3 Jun 2026: How hackers used Meta's own AI to break into Instagram accounts (opens in a new tab) · The Hindu, 6 Jun 2026: Did Meta's own AI help hack into Instagram users' accounts? | Explained (opens in a new tab) · The Indian Express, 6 Jun 2026: OpenAI rolls out Lockdown Mode to protect against prompt injection attacks (opens in a new tab)
Kudankulam data leak
Copy link to Kudankulam data leakPrelims and Mains
LeadCyber security of critical infrastructure: the Kudankulam leakJuly 2026
Why in news
A ransomware group published about 19,000 files relating to the Kudankulam nuclear power plant in July 2026. The files were taken from a contractor's data held with a third party provider, and not from the plant's own network.
Background
- Critical information infrastructure is the computer systems whose failure would harm national security, the economy, public health or safety: power, banking, telecom, transport.
- Critical information infrastructure
- Computer systems whose incapacitation would harm national security, the economy, public health or safety.
- Under the Information Technology Act, 2000, the National Critical Information Infrastructure Protection Centre (NCIIPC) protects such systems.
- The Indian Computer Emergency Response Team (CERT-In) is the national agency that responds to cyber incidents.
- Ransomware is malicious software that locks or steals data, after which the attackers demand payment.
- Ransomware
- Malicious software that encrypts or steals data so that the attackers can demand payment.
- Kudankulam, in Tamil Nadu, is India's largest nuclear power station, with reactors of Russian design.
- Balance of plant
- The supporting systems of a power station other than the reactor or generator.
What happened
- The attackers reached a server used by a contractor that held an engineering contract for the plant.
- The operator says the files concern the conventional, non nuclear support systems of Units 3 and 4, and not nuclear safety systems.
- The concern is that such documents let an adversary map the support systems and look for weak points.
- The plant had an earlier incident in 2019, when malware infected its administrative network.
The lesson: the supply chain
- An organisation is only as secure as its weakest vendor.
- A nuclear plant keeps its control systems cut off from the internet, an air gap. Its contractors' offices are not so protected.
- Air gap
- Keeping a computer system physically separate from outside networks.
- Supply chain attacks are a standard way into well defended targets.
- Supply chain attack
- An attack that reaches a target through a supplier or contractor.
The new risk: artificial intelligence
- A government threat report for banking and payments names AI asymmetry as the defining risk: work that once needed a skilled team is now done at machine speed by attackers with few resources.
- CERT-In's guidelines of June 2026 require equipment makers and technology providers to use AI assisted security testing, monitoring and patching.
- The duty is shifting from the user to the manufacturer.
The way forward
- Extend security rules and audits to contractors of critical infrastructure.
- Require prompt reporting of breaches by vendors, as CERT-In requires of others.
- Keep sensitive engineering data on controlled servers in India.
- Build skilled staff in each critical sector, with regular drills.
Prelims facts
- CERT-In works under the Ministry of Electronics and Information Technology; NCIIPC protects critical information infrastructure.
- Both draw their mandate from the Information Technology Act, 2000.
- Kudankulam is in Tamil Nadu and uses Russian VVER pressurised water reactors.
The Kudankulam plant is India's largest nuclear power station, and the files published on it by a ransomware group came from a contractor's data held by a third party, which is the supply chain weakness typical of attacks on critical infrastructure.
What changed
CERT-In and AI driven threats
Copy link to CERT-In and AI driven threatsPrelims and Mains
The Indian Computer Emergency Response Team is the national agency for cyber incidents.
Sanchar Saathi, ASTR and Chakshu
Copy link to Sanchar Saathi, ASTR and ChakshuPrelims
Sanchar Saathi is the Department of Telecommunications portal against telecom fraud, ASTR is its artificial intelligence tool for finding suspicious connections, and Chakshu is its channel for citizens to report fraud calls and messages.
What changed
23 Jul 2026BriefASTR, an AI tool of the Department of Telecommunications, flags suspicious mobile connections, which are disconnected if they fail fresh verification. Chakshu lets citizens report suspected fraud calls and messages on the Sanchar Saathi portal. PIB, 23 Jul 2026: Measures Taken to Tackle Cyber Frauds (opens in a new tab)
Digital arrest scams
Copy link to Digital arrest scamsPrelims
In a digital arrest scam, callers posing as police or officials keep a victim on a video call under threat of arrest until money is transferred.
- Many large scams originate in Southeast Asian scam compounds using mule accounts and telecom infrastructure.
- Callers have shifted to internet calling platforms.
What changed
10 Jun 2026BriefThe National Human Rights Commission said Indians lost about ₹52,976 crore to cyber fraud over six years. It recommended making digital arrest a distinct offence, criminalising mule account renting and circuit breakers for high value transfers. The Hindu, 10 Jun 2026: NHRC flags ₹52,976 crore cyber fraud losses, seeks urgent action against 'digital arrest' scams (opens in a new tab)
Also filed elsewhere
- Agentic AI: the 2026 incidents and "pacing the frontier" · on AI governance, safety and ethics
An AI agent is software that takes a series of actions towards a goal with little human intervention: it browses, writes code, logs in and pays.
- C-DOT quantum security products · on Quantum science and technology
C-DOT's quantum security products protect communications against a quantum computer able to break today's encryption.